Digital Forensics and Incident Response (DFIR) Framework for Operational Technology (OT)
Eran Salfati, Michael Pease
This document provides a new Incident Handling framework dedicated to Operational Technology. This framework expands the traditional technical steps by giving an Incident Response procedure based on the event escalation and provides techniques for OT Digital Forensics. It includes an overview with general terms explanation and a list of unique properties of OT DFIR, the preparation that should be done to establish an OT Incident Response Team, and finally, the suggested OT Incident Handling framework in detail.
and Pease, M.
Digital Forensics and Incident Response (DFIR) Framework for Operational Technology (OT), NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8428, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=934922
(Accessed February 4, 2023)