NIST 800-82r3 Guide to OT Security: A Call to Action for OT Continuous Monitoring
NIST SP 800-82r3, the Guide to OT Security, is the most current federal guidance for protecting operational technology. It makes continuous monitoring central to OT risk management. Read it for OT risk strategy, defensible architecture, stakeholder roles, monitoring best practices, and how Nozomi Networks helps you comply.

WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
Table of Contents
1. Introduction 1
2. Considerations for OT Risk Management Strategy 1
3. Security Drivers for OT Operations 2
4. Responsibility for Securing OT Operations 3
5. Overview of the NIST 800-82 Rev. 3 Guide to OT Security 4
5.1. Highlight: Managing Risk in an OT Environment 5
5.2. Highlight: Network Security and Monitoring 6
5.3. Highlight: Security Continuous Monitoring 7
6. Nozomi Networks Continuous Monitoring and Detection Capabilitie 8
6.1. Nozomi Networks Asset Management 9
6.2. Nozomi Networks Vulnerability Mapping 9
6.3. Nozomi Networks Threat Detection 10
6.4. Nozomi Networks Anomaly Detection 10
6.5. Nozomi Networks Predictive Analytics 11
7. Conclusion 11
1 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
The newly updated NIST 800-82 Rev. 3, published in September 2023, suggests that organizations should implement continuous monitoring as part of their organizational risk management strategy to monitor the effectiveness of protective measures. The NIST guide suggests technical approaches at length, including capabilities for building defensible OT network architectures, and continuously defending those network architectures.
This Nozomi Networks overview outlines key considerations for an organization’s OT risk management strategy, security drivers for OT operations, risks and threats to OT operations, and which stakeholders are responsible for securing OT operations. It also provides an excerpt of the NIST Guide’s considerations for continuous monitoring, as well as what to monitor and why, demonstrating how Nozomi Networks delivers continuous security monitoring for OT networks and risk mitigation.
No organization is immune to cyberattacks; however,
many organizations are focused on limiting the
severity of impacts and making their operations less
attractive targets. Regardless of whether a cyber
incident originates on the IT side of the business or was
introduced intentionally or accidentally on the OT side, a
single firewall separating the boundary between IT and
OT is not doing enough. Organizations require more
sophisticated and holistic OT cybersecurity programs
that still focus on the basics: defensible architectures,
monitoring, and resilience.
The main design elements for building a defensible
architecture (crown jewel analysis, segmentation,
hardening and access controls, etc.) do not monitor or
analyze communications traffic in real time or at scale.
Encryption and secure protocols are caveats to consider
for continuous monitoring and detection. While
encryption and cryptographic hashes should be applied
to OT data storage and communications as often as
possible, in reality this functionality is often limited.
Many systems may not have the desired features or rely
on protocols that are considered insecure.
Intrusion prevention systems and intrusion detection
systems are considered robust additions to reinforce
network segmentation. However, these solutions
do not cover the full visualization of network traffic,
known vulnerabilities, and potential threat indicators.
Continuous monitoring and detection can
dynamically visualize traffic to bolster segmentation
and can be used as a risk mitigation measure for groups
of devices with the same criticality to evaluate and
prioritize vulnerabilities and remediation.
Continuous monitoring and detection provides the
capability to navigate, sort, filter, and analyze traffic to,
from, and within critical networks based on:
1. Introduction
2. Considerations for OT Risk Management Strategy
Nodes Links
Zones Sessions
Topology Traffic
Subnets Protocols
Network Segments Open TCP connections
https://csrc.nist.gov/pubs/sp/800/82/r3/final https://www.nozominetworks.com/blog/ot-network-segmentation-for-cyber-resiliency https://www.nozominetworks.com/blog/ot-network-segmentation-for-cyber-resiliency
2 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
Without effective OT network segmentation,
ransomware and other cyber threats can easily move
laterally through an organization to hold critical assets
and networks at risk. Without continuous monitoring
and detection, threat actors and criminal groups can
establish persistent access to systems and networks
to exploit at will. Without impact analysis to build
resilience from the crown jewels to the board room,
cyber incidents will continue to result in business
disruption and downtime.
3. Security Drivers for OT Operations OT/ICS technologies encompass a wide range
of machines and configurations, to include
pumps, compressors, valves, turbines, and similar
equipment, interface computers and workstations,
programmable logic controllers and many
diagnostics, safety, metering, and monitoring and
control systems that enable or report the status of
variables, processes, and operations.
Where IT systems face many more known vulnerabilities
that are likely to be exploited in similar ways across
mainstream and ubiquitous systems, OT security
is often a proprietary, case-by-case distinction
with potential configurations often analogous with
multiple combinations of LEGO blocks (hardware
permutations) and Rubik’s Cubes (software and
configuration permutations).
Risks to OT systems include:
y the use of legacy technologies with well-known
vulnerabilities
y the widespread availability of technical information
about control systems
y the connectivity of control systems to other networks
y constraints on the use of existing security
technologies and practices
y insecure remote connections
y a lack of visibility into network connectivity
y complex and just-in-time supply chains
y human error, neglect, and accidents
Threats to OT systems can come from numerous
sources, including hostile governments, terrorist
groups, disgruntled employees, malicious intruders,
complexities, natural disasters, malicious actions by
insiders, and unintentional actions such human error or
failure to follow established policies and procedures.
Attack Sophistication
Non-Targeted Attacks by IT- Savvy People
Targets Attacks by IT - Savvy People
Targets Attacks by ICS - Savvy People
U n
m it
ig at
ed L
ik el
ih oo
d o
f a n
In ci
d en
t
U n
m it
ig at
ed C
os t
of a
n In
ci d
en t
Threat Actor Capabilities & Resources
General Hackers
Cyber Criminals Terrorists Unfriendly
NationsHacktivist
INSIDER THREATS
3 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
4. Responsibility for Securing OT Operations OT is increasingly network connected and a top priority
in risk management discussions for stakeholders in
board rooms, facility managers and informed engineers.
Security leaders are pressed to do more with less,
addressing thousands of vulnerabilities in hundreds of
systems while deploying and maintaining numerous
security products.
Regardless of who owns OT security, three broad
responsibilities exist for maturing OT security programs:
Government regulations, standards bodies,
and compliance mandates are increasing
across industrial and critical infrastructure
sectors, to include OT, and enforcement
mechanisms for information sharing about
cyber incidents continues to emerge (already
passed in the U.S. and Europe).
IT risk management leaders and CISOs
are increasingly required to demonstrate
clear understanding of OT threats, risks, and
vulnerabilities, dedicating new authorities
to teams and leaders to get a handle on all
operational assets and networks, supply chains
and third-party vendor risks.
Prevention and remediation of incidents
increasingly require the capability to parse logs
for forensic and protocol information ahead of
exploitation. This level of granular data is often
not recorded or analyzed for OT systems and
networks, introducing the need for continuous
monitoring, vulnerability management, and
threat detection capabilities.
Across the market—from competitive intelligence to
innovation to live ‘bake-offs’—trust and verification
matter more today for OT cybersecurity than ever
before. OT cybersecurity stakeholders, concerned
with physical safety, environmental impacts, the
provision of goods, services, and resources, micro and
macroeconomics, continue to look for strategies and
tools to bolster proactive security measures.
The cybersecurity team should coordinate closely with site management and the company’s Chief Information Officer or Chief Security Officer, who – along with the Chief Executive Officer or Chief Operating Officer – accepts complete responsibility and accountability for the cybersecurity of the OT system and for any safety incidents, reliability incidents, or equipment damage caused directly or indirectly by cyber incidents.
According to NIST:
4 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
5. Overview of the NIST 800-82 Rev. 3 Guide to OT Security Governments, public-private-partnerships, insurance
providers, and international standards bodies are
increasingly aware of the significance of cyber concerns
across critical infrastructure, industrial sectors and
hyperconnected facilities. The NIST 800-82 Revision 3
“Guide to Operational Technology (OT) Security,” updated in
September 2023, continues the U.S. federal government’s
drive to realize cybersecurity as essential to the safe and
reliable operation of modern industrial processes.
NIST is responsible for developing information security
standards and guidelines, including minimum
requirements for federal information systems. The Guide
to OT document provides guidance on how to secure
operational technology while addressing their unique
performance, reliability, and safety requirements in a
vendor agnostic way that recognizes the importance of
solutions that are tailored to specific OT environments.
The NIST document is divided into the following
major sections:
Overview of OT
The development and deployment
of an OT cybersecurity program to
mitigate risk for the vulnerabilities
OT security risk management and
applying the Risk Management
Framework to OT systems
Recommendations for integrating security
into network architectures typically found in
OT systems, with an emphasis on network
segmentation and separation practices
Guidance on applying the Cybersecurity
Framework to OT systems
The guide suggests that organizations should
implement continuous monitoring as part of the
organizational risk management strategy to monitor
the effectiveness of protective measures.
The following sections highlight NIST’s guidance on monitoring OT environments.
The most successful method for securing OT systems is to gather industry-recommended practices and engage in a proactive, collaborative effort between management, the OT engineers and operators, the IT organization, and a trusted OT advisor. This team should draw upon the wealth of information available from the ongoing Federal Government, industry group, vendor, and standards activities.
According to NIST:
5 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
HIGHLIGHT
5.1. Managing Risk in an OT Environment
Chapter 4 of the NIST Guide focuses on managing risk in OT systems, with section 4.1.1 framing OT-specific recommendations and guidance.
Organizations should consider incorporating an analysis of cybersecurity effects on OT
systems that impact personnel safety and the environment, as well as mitigating controls.
More specifically, organizations may want to consider employing a comprehensive process
to systematically predict or identify the operational behavior of each safety-critical failure
condition, fault condition, or human error that could lead to a hazard or potential human harm.
Organizations may also want to consider the impact of legacy systems and components
on their environment. Specifically, legacy systems may be unable to adequately support
cybersecurity to prevent risks from exceeding organizational tolerance levels. Another major
concern for OT system operators is the availability of services provided by the OT system. The
OT system may be part of critical infrastructure (e.g., water or power systems), where there is a
significant need for continuous and reliable operations.
As a result, OT systems may have strict requirements for availability or recovery. Organizations
should understand and plan for the levels of redundancy required to achieve the desired
resilience for their operating environments and incorporate these requirements into their risk
framing. This will help organizations make risk decisions that avoid unintended consequences
on those who depend on the services provided.
More specifically, organizations should consider identifying interdependent OT systems that
pose cybersecurity risks that threaten system availability.
NIST Guide to OT Rev. 3, 4.1.1 Framing OT Risk
6 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
HIGHLIGHT
5.2. Network Security and Monitoring
Section 5.2.3 of the NIST Guide recommends applying the network architecture principles of segmentation and isolation, centralizing logging, network monitoring, and malicious code protection in an organization’s cybersecurity strategy to optimize data collection and analysis.
Network monitoring involves reviewing alerts and logs and analyzing them for signs of possible
cybersecurity incidents. Tools and capabilities that support behavior anomaly detection (BAD),
security information and event management (SIEM), intrusion detection systems (IDS), and
intrusion prevention systems (IPS) can assist organizations with monitoring traffic throughout
the network and generate alerts when they identify anomalous or suspicious traffic. Some
other capabilities to consider for network monitoring include:
y Asset management, including discovering and inventorying devices connected to the network
y Baselining typical network traffic, data flows, and device-to-device communications
y Diagnosing network performance issues
y Identifying misconfigurations or malfunctions of networked devices
Organizations may also want to consider incorporating additional services and capabilities,
such as threat intelligence monitoring, to assist with establishing and maintaining an effective
network monitoring capability. Organizations should understand the normal state of the OT
network as a prerequisite for implementing network security monitoring to help distinguish
attacks from transient conditions or normal operations within the environment. Implementing
network monitoring in a passive (e.g., listen or learning) mode and analyzing the information
to differentiate between known and unknown communication may be a necessary first step in
implementing network security monitoring.
In OT environments, network-based monitoring capabilities are typically deployed on boundary
protection devices using switched port analyzer (SPAN) ports or passive network taps. Organizations
should also consider deploying host-based monitoring capabilities on compatible OT devices –
such as HMIs, SCADA servers, and engineering workstations – to improve monitoring capabilities,
provided that the addition of the tools does not adversely impact operational performance or safety.
NIST Guide to OT Rev. 3, 5.2.3.3 Network Monitoring
7 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
HIGHLIGHT
5.3. Security Continuous Monitoring
A continuous monitoring solution is one that includes capabilities such as asset management, network security management, identity and access management, data protection management, and dashboards to receive, aggregate, and display information.
In Section 6.3.2, the NIST guide offers more technical guidance on continuous monitoring specific to OT domains, suggesting how passive scanning technologies and additional security features can be deployed for proper risk management for OT assets and networks.
“Continuous monitoring can be achieved using automated tools, through passive scanning, or
with manual monitoring performed at a frequency deemed commensurate with the risk. For
example, a risk assessment may determine that the logs from isolated (i.e., non-networked),
non-critical devices should be reviewed monthly by OT personnel to determine whether
anomalous behavior is occurring. Alternatively, a passive network monitor might be able to
detect vulnerable network services without having to scan the devices.
When organizations implement a sampling methodology, the criticality of the components
should be considered. For example, the sampling methodology should not inadvertently
exclude higher risk devices, such as Layer 3 or Layer 4 firewalls.
When using third parties to continuously monitor security controls, ensure that the personnel
involved have the appropriate skillset to analyze OT environments.
NIST Guide to OT Rev. 3, 6.3.2 Security Continuous Monitoring (DE.CM)
8 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
6. Nozomi Networks Continuous Monitoring and Detection Capabilities The Nozomi Networks platform delivers continuous
security monitoring for OT networks and risk mitigation.
Our suite of products and features enables earlier
discovery of security events and incidents across the
industrial attack surface, delivering real-time situational
awareness for critical decision making and remediation.
Our tool captures an asset inventory and network
characteristics before performing security functions like
vulnerability mapping and threat detection.
Though new weaknesses like zero-day vulnerabilities are
being identified every day, the most common avenue of
disruption we see is the exploitation of weak passwords,
bad security practices, and misconfigurations. Situations
caused by human error or a lack of security procedures –
which are preventable with proper assessment and care –
are often the main culprits exposing industrial operations
to hazardous scenarios. The first security item to consider
in a real operation is if the network is properly set up.
Before risk can be managed, a current asset inventory
and clear network topology are necessary. Are switches
configured properly, using features like safety ports so
that unique MAC addresses are bound to specific ports?
If ports are restricted, this type of access to industrial
systems is blocked. Are firewalls used in higher levels
of the Purdue model? The port of an industrial protocol
should be blocked when used in the wrong VLAN, and
communications that pass through to lower levels can
be allow listed.
Unlike other solutions on the market, our platform uses
a variety of methods to collect vulnerability information,
including network monitoring, endpoint monitoring
and smart polling to provide continuous visibility into
all your assets and their vulnerabilities, even when they
aren’t actively communicating. The Nozomi Networks
Threat Intelligence feeds are updated with the newest
IOCs and are delivered continuously in near-real time.
Threat risk indicators include Yara rules, packet rules,
STIX indicators, threat definitions, vulnerabilities, and an
extensive threat knowledge base.
The Nozomi Networks solution helps you get a complete
view of communicating network devices and traffic
patterns to build a visualization map that can accelerate
investigations and quickly identify ways to better segment
networks and monitor assets and communications.
Asset discovery in OT environments can be completely
passive based on observing mirrored traffic to not
disrupt critical processes, trigger alarms or generate
additional traffic. The value is earlier notification and
remediation of issues and concerns, ultimately reducing
the attack vectors and mean time to recover from any
security incident in your OT environment.
Nozomi Networks Platform
Asset Management
Vulnerability Mapping
Threat Detection
Anomaly Detection
Predictive Analytics
9 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
The Nozomi Networks platform provides discovered
asset data like IP addresses, vendors, installed firmware
and zones, while a maintenance management system
provides supplemental data not visible to the Nozomi
Networks platform like asset IDs, locations, managers,
criticality ratings, and maintenance schedules. By
merging this data in our platform, security teams can
access production context for OT assets to improve
risk prioritization and use standardized language when
collaborating with maintenance teams.
Some examples of merged data fields in the Nozomi
Networks platform might be:
y Asset ID: The maintenance system ID for the asset
y Location: Where the asset is physically installed
y Manager: Responsible maintenance contact for the asset
y Criticality: Production criticality rating (1-5)
y Last/Next Maintenance: Upcoming scheduled
maintenance
y Downtime Cost: Estimated hourly production loss if
asset fails
For examples of risk mitigation, a user can query data
using this data to sort by highest criticality from most to
least critical. Another query could be on downtime cost
by showing assets with downtime cost greater than zero,
displaying the IP, label, asset ID, description, manager,
location, criticality, and hourly downtime cost, sorted by
highest downtime cost to identify assets with the largest
financial impacts if they experience unplanned downtime.
Industrial sectors and hyper-connected facilities have
unique interdependencies between physical and
cyber infrastructure which makes them vulnerable
to exploitation, from billing fraud to manipulation
of IoT sensors, the commandeering of operational-
technology (OT) systems to stop processes and cause
business interruptions and/or physical destruction.
While each vulnerability is published with an associated
common vulnerability scoring system (CVSS) score, it is
impossible to immediately understand how severe the
vulnerability will be for one entity’s risk profile based off
of the designated severity of the vulnerability.
Nozomi Networks’ vulnerability management
capability automatically identifies and scores open
vulnerabilities on your devices. Utilizing NIST’s NVD
(National Vulnerability Database) for standardized
naming, description and scoring, it rapidly determines
which devices are at risk and helps you respond with
actionable intelligence. To help your security team
prioritize high level exposure points, our solution
displays all vulnerabilities by vendor, severity level and
more in a dedicated view. Plus, it offers drilldown on
each vulnerability for deeper troubleshooting and
remediation assistance.
6.1. Nozomi Networks Asset Management
6.2. Nozomi Networks Vulnerability Mapping
Asset ID Location Manager Criticality Last/Next Maintenance Downtime Cost
10 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
Scanning may identify vulnerabilities, but many
steps are then required to access and exploit these
vulnerabilities. Nozomi Networks Threat Intelligence,
continuously updated with the latest malware
signatures and indicators of compromise, categorizes
known TTPs and code signature from previous
incidents and is used to build out detection capabilities
for alerting security teams to a potential recognized TTP
or signature detected somewhere in the network.
Asset Intelligence enriches OT device profiles with
detailed asset information to accelerate the learning
process for OT environments and to provide accurate
asset inventory. This enhancement leverages both internal
and third-party data to curate the most up to date profiles
available on the market - including the latest updates,
recalls, configurations and known vulnerabilities.
Alerts can be grouped by incidents to provide a clear,
consolidated view of what’s happening on the network.
Critical alerts can be addressed immediately to minimize
disruption to operations. Threat feeds are available as an
add-on to Nozomi Networks sensor-based products, and
can also be ingested into third-party security solutions
such as firewalls and orchestration solutions for any
platform that supports STIX.
While network diagrams offer a high-level map of
static configurations, they lack the ability to continually
monitor traffic and timestamp network or data changes.
Meanwhile, components and connections continue to
increase with multiple OT vendor systems and integrations.
Reliance on patches that might not be feasible, given the
environment and its dependence on legacy technologies,
produces inadequate security coverage.
Simply having and storing reams of data is not particularly
useful for any risk mitigation. Behavioral analysis and
anomaly detection for network operations can augment
threat intelligence and overall security postures. Anomaly
detection can alert on both deviations from normal
communications patterns, as well as variables within the
process – like sensor readings and flow parameters.
Data analysis in Nozomi Networks’ product engine
correlates threat intelligence information with broader
environmental behavior to deliver maximum security
and operational insight. Our solution immediately
baselines and profiles every device and its behavior,
including process variables, to quickly pinpoint
abnormal activities.
6.3. Nozomi Networks Threat Detection
6.4. Nozomi Networks Anomaly Detection
11 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
7. Conclusion OT network segmentation along with continuous
monitoring and detection help prevent ransomware
and other cyber threats from moving laterally through
an organization to establish persistent access to
systems and hold critical assets and networks at risk.
The Nozomi Networks platform ensures that you can
rapidly identify OT/IoT network risks, assess vulnerabilities,
and prioritize responses. You’ll also get automated
vulnerability assessment functionality, thanks to more
detailed risk information including security alerts,
missing patches and more. Additionally, real-time asset
information with up-to-date configuration data provides
the latest device configuration details.
Nozomi Networks delivers deep knowledge of your environment through monitoring of critical processes, plus the ability to leverage AI/ML techniques to correlate root cause analysis with observed anomalies. This allows you to understand what’s happening, explain why it’s occurring, and recommend the best way to respond.
If OT network activity is not monitored in real time,
the status of assets is largely unknown, and whether
they have vulnerabilities or not, these assets cannot
be protected without the necessary visibility into their
day-to-day functionality. Modern organizations have
hundreds of OT/IoT assets deployed across multiple
sites. Managing them can be time-consuming. Nozomi
Networks’ cloud offering and add-on analytics leverage
the scalability of the cloud to deliver unmatched
security and visibility across sites, regions and teams.
Our platform scales with organizations as they grow,
without compromising on performance and with minimal
increased costs. Multi-site deployments are simplified
as fewer administrative resources are required to
manage multiple sites and the large number of sensors.
We offer the industry’s first AI and machine learning
engine that can emulate the acquired knowledge
of experienced security administrators to automate
tedious tasks of reviewing, correlating, and prioritizing
the multitude of alert data to provide insights to threats
and how to remediate it quickly.
This capability offers powerful customizable queries
to answer common questions in human readable
language, and provide users with a better understanding
of their environment and security posture. This
automation reduces the need for data analytics skill sets
and allows security teams to spend more time focusing
on priority issues they are equipped to remediate.
6.5. Nozomi Networks Predictive Analytics
Take the next step. To learn more about how our solution delivers continuous monitoring and risk management, book a demo today.
Book a demo
nozominetworks.com/demo
https://www.nozominetworks.com/demo https://www.nozominetworks.com/demo
12 WHITE PAPER
NIST 800-82r3 Guide to Operational Technology (OT) Security: A Call to Action for OT Continuous Monitoring
nozominetworks.com
Cybersecurity for OT, IoT and Critical Infrastructure Nozomi Networks protects the world’s critical infrastructure from cyber
threats. Our platform uniquely combines network and endpoint visibility,
threat detection, and AI-powered analysis for faster, more effective
incident response. Customers rely on us to minimize risk and complexity
while maximizing operational resilience.
NN-NIST-800-82-WP-8.5x11-001
© 2023 Nozomi Networks, Inc. | All Rights Reserved.
1. Introduction 2. Considerations for OT Risk Management Strategy 3. Security Drivers for OT Operations 4. Responsibility for Securing OT Operations 5. Overview of the NIST 800-82 Rev. 3 Guide to OT Security 5.1. Managing Risk in an OT Environment 5.2. Network Security and Monitoring 5.3. Security Continuous Monitoring
6. Nozomi Networks Continuous Monitoring and Detection Capabilitie 6.1. Nozomi Networks Asset Management 6.2. Nozomi Networks Vulnerability Mapping 6.3. Nozomi Networks Threat Detection 6.4. Nozomi Networks Anomaly Detection 6.5. Nozomi Networks Predictive Analytics
7. Conclusion