Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Digital Forensics and Incident Response (DFIR) Framework for Operational Technology (OT)



Eran Salfati, Michael Pease


This document provides a new Incident Handling framework dedicated to Operational Technology. This framework expands the traditional technical steps by giving an Incident Response procedure based on the event escalation and provides techniques for OT Digital Forensics. It includes an overview with general terms explanation and a list of unique properties of OT DFIR, the preparation that should be done to establish an OT Incident Response Team, and finally, the suggested OT Incident Handling framework in detail.
NIST Interagency/Internal Report (NISTIR) - 8428
Report Number


Active Defense, Digital Forensics, Incident Handling, Incident Response, Industrial Control Systems, Operational Technology


Salfati, E. and Pease, M. (2022), Digital Forensics and Incident Response (DFIR) Framework for Operational Technology (OT), NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed May 24, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created June 22, 2022, Updated November 29, 2022