{"id":1862,"date":"2026-10-04T14:52:25","date_gmt":"2026-10-04T11:52:25","guid":{"rendered":"https:\/\/zerontek.com\/zt\/?p=1862"},"modified":"2026-10-04T14:52:25","modified_gmt":"2026-10-04T11:52:25","slug":"nist-sp-800-82-rev-4-what-ot-security-practitioners-really-need-to-know","status":"publish","type":"post","link":"https:\/\/zerontek.com\/zt\/2026\/10\/04\/nist-sp-800-82-rev-4-what-ot-security-practitioners-really-need-to-know\/","title":{"rendered":"NIST SP 800-82 Rev. 4: What OT Security Practitioners Really Need to Know"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">NIST recently released the <strong>Initial Public Draft of SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I went through the new revision mainly with one question in mind:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What has actually changed from Rev. 3, and what should OT practitioners pay attention to?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a completely new OT security model.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is more of an evolution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rev. 4 brings SP 800-82 closer to <strong>NIST Cybersecurity Framework 2.0<\/strong>, strengthens governance and enterprise risk management, expands practical guidance around asset visibility and monitoring, and gives more attention to modern OT architectures and Zero Trust principles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST also continues to emphasize something very important for anyone working in OT:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>security controls and security testing must respect operational requirements, reliability, and safety.<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The biggest change: CSF 2.0 and GOVERN<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the clearest changes is the alignment with <strong>NIST CSF 2.0<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The familiar functions are now:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Govern \u2192 Identify \u2192 Protect \u2192 Detect \u2192 Respond \u2192 Recover<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For OT, I think the addition and stronger emphasis on <strong>Govern<\/strong> is important.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity in industrial environments cannot remain only a technical discussion between engineers and security teams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It has to connect with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>business objectives<\/li>\n\n\n\n<li>operational risk<\/li>\n\n\n\n<li>responsibilities and accountability<\/li>\n\n\n\n<li>supply chain<\/li>\n\n\n\n<li>investment decisions<\/li>\n\n\n\n<li>enterprise risk management<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This is an important direction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A firewall, IDS, EDR platform, or segmentation project is not the objective by itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The real question is:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What operational risk are we trying to reduce?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rev. 4 makes this connection much clearer.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">OT continues to expand beyond traditional ICS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Rev. 3 already made an important change by moving from an ICS-centered view toward the broader term <strong>Operational Technology<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rev. 4 continues in that direction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST now explicitly discusses environments including industrial control systems, building automation and control systems, water and wastewater, transportation, maritime systems, Industrial Internet of Things, and cloud-connected OT environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This matters because OT security is no longer only about PLCs inside a refinery or manufacturing plant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber-physical systems are everywhere.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the boundary between traditional IT, OT, IIoT, and cloud services continues to become less clear.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">More emphasis on knowing what you actually have<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Another useful improvement is the expanded guidance around <strong>asset management, network monitoring, and detection<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This sounds basic, but it remains one of the biggest practical problems in OT security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before asking:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How do we protect the environment?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">we still need to answer:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What exactly is in the environment?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rev. 4 provides more guidance around asset visibility and monitoring and recognizes the different approaches that may be required in operational environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also expands guidance around network monitoring and detection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For defenders, this reinforces the importance of understanding normal communications, asset relationships, network architecture, and what is happening between different parts of the OT environment.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Zero Trust comes further into OT<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Rev. 4 also provides more guidance on applying <strong>Zero Trust principles<\/strong> to OT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This should not be interpreted as taking an enterprise Zero Trust architecture and simply dropping it into a plant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many OT devices cannot support the same identity, authentication, endpoint, or policy technologies we expect in modern IT environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, the principles become more interesting:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>limit access, reduce unnecessary trust, control privileged access, segment systems, authenticate where possible, and continuously monitor communications.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technology used to achieve this may be different in OT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The principle is still useful.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST specifically identifies security architecture guidance around protecting management functions and applying Zero Trust principles as one of the important additions to Rev. 4.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What does Rev. 4 say about penetration testing?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This part caught my attention because I have been spending more time recently on <strong>OT penetration testing<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rev. 4 does not introduce a new OT penetration testing methodology.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But it reinforces an important distinction between traditional IT penetration testing and testing industrial environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST says penetration testing can be used as part of vulnerability assessment, <strong>provided that the testing does not adversely impact the production environment<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That qualification is critical.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OT systems can have timing constraints, limited resources, legacy equipment, and direct interaction with physical processes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A technique that is routine in IT may have very different consequences inside OT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST therefore recommends caution when performing penetration testing on operational systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where possible, testing may be performed using:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>replicated, virtualized, or simulated systems.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Testing of production systems may sometimes need to be coordinated with planned outages or other operational windows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST also highlights another important point:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>effective OT penetration testing requires OT-specific knowledge and skills.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is something I think deserves much more attention as interest in OT penetration testing grows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Knowing Kali Linux, Metasploit, Nmap, or industrial protocol tools is not enough.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The tester needs to understand the environment being tested and the possible operational consequences of the test.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">This reminded me of Duggan\u2019s 2005 paper<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This section of Rev. 4 immediately reminded me of an <a href=\"https:\/\/zerontek.com\/zt\/2026\/09\/29\/penetration-testing-industrial-control-systems-a-2005-paper-that-still-reads-like-modern-ot-security-guidance\/\">article<\/a> I recently wrote about the 2005 Sandia report <strong>\u201cPenetration Testing of Industrial Control Systems\u201d<\/strong> by David Duggan and his colleagues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The paper was published more than 20 years ago.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Interestingly, much of the terminology we use today was not yet established in the same way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The industry was not having today&#8217;s discussions around \u201cOT security,\u201d \u201cZero Trust for OT,\u201d or modern cyber-physical security programs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the core testing problem was already very clear.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Duggan and his colleagues were already discussing the fact that penetration testing industrial control systems is different because the tester must consider the consequences to the process itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That makes Rev. 4 an interesting follow-up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technology has changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The architectures have changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The frameworks have matured.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The terminology has changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the basic principle remains:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>You cannot test an industrial environment exactly like a normal IT network.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Twenty years later, NIST is still emphasizing the same operational reality, but now within a much broader OT cybersecurity framework.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For me, there is an important lesson here for penetration testers entering OT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is not to prove how aggressive your tools can be.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is to understand security weaknesses <strong>without allowing the security test itself to become an operational incident.<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">My main takeaway<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If I had to summarize the evolution:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Rev. 2:<\/strong> Secure ICS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Rev. 3:<\/strong> Think broader \u2014 secure OT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Rev. 4:<\/strong> Connect OT cybersecurity more closely with governance, enterprise risk, visibility, modern architecture, monitoring, and CSF 2.0.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And for penetration testers, the message remains consistent with what researchers were already saying two decades ago:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>understand the process before you test the technology.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That may sound obvious.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In OT, it is fundamental.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One final point: Rev. 4 is currently an <strong>Initial Public Draft<\/strong>, published on September 21, 2026. NIST is accepting public comments until November 30, 2026, so the final version may still change.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Want to go deeper into OT security and penetration testing?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you are new to OT security and want a practical introduction, you can start with my <strong>OT security fundamentals and penetration testing course<\/strong>, where I introduce the OT environment and basic hands-on testing using LabShock:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/alhasawi.gumroad.com\/l\/OT-P2P\" target=\"_blank\" rel=\"noopener\">https:\/\/alhasawi.gumroad.com\/l\/OT-P2P<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I am also developing a more detailed <strong>Practical OT\/ICS Penetration Testing<\/strong> course covering OT architecture, scoping and rules of engagement, industrial protocols, enumeration, vulnerability assessment, and safe penetration testing techniques.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are interested in joining the next cohort, you can register here:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/forms.gle\/EyjHPzMwaKLqxBok8\" target=\"_blank\" rel=\"noopener\">https:\/\/forms.gle\/EyjHPzMwaKLqxBok8<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">References<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">NIST, <em>SP 800-82 Rev. 4 \u2014 Guide to Operational Technology (OT) Security<\/em>, Initial Public Draft, September 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">David P. Duggan, Michael Berg, John Dillinger, and Jason Stamp, <em>Penetration Testing of Industrial Control Systems<\/em>, Sandia National Laboratories, 2005.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NIST recently released the Initial Public Draft of SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security. I went through the new revision mainly with one question in mind: What has actually changed from Rev. 3, and what should OT practitioners pay attention to? This is not a completely new OT security model. It [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1863,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,3,144,48,106],"tags":[306,307],"class_list":["post-1862","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","category-ics-security","category-nist","category-ot-security","category-penetration-testing","tag-duggan","tag-nist-sp-800-82-rev-4"],"_links":{"self":[{"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/posts\/1862","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/comments?post=1862"}],"version-history":[{"count":3,"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/posts\/1862\/revisions"}],"predecessor-version":[{"id":1866,"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/posts\/1862\/revisions\/1866"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/media\/1863"}],"wp:attachment":[{"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/media?parent=1862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/categories?post=1862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zerontek.com\/zt\/wp-json\/wp\/v2\/tags?post=1862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}