NIST SP 800-82
NIST SP 800-82 is a guidance document published by the U.S. National Institute of Standards and Technology that helps organizations secure the technology used to run physical and industrial operations, such as factory equipment and utility control systems. It explains common system layouts, the threats these environments typically face, and recommended protective measures. It is guidance rather than a mandatory regulation or certification standard, so following it supports better security but does not by itself prove compliance.
NIST Special Publication 800-82 is a NIST guidance publication addressing the security of Operational Technology (OT) environments, with earlier revisions scoped specifically to Industrial Control Systems (ICS), including SCADA systems. Revision 2 (2015) was titled Guide to Industrial Control Systems (ICS) Security; Revision 3 (published September 2023, superseding Rev. 2) was retitled Guide to Operational Technology (OT) Security, and a Revision 4 pre-draft call for comments has been initiated to incorporate lessons learned and align with related updates. The document provides an overview of OT and typical system topologies, identifies typical threats to organizational mission and business functions, and offers recommended safeguards. In a virtual or fractional CISO context, SP 800-82 typically informs OT/ICS risk assessment, program strategy, and governance recommendations; it is advisory guidance rather than an audited certification standard, and it does not, on its own, establish compliance or accountability, which remain with the client organization.
Why it matters
Operational Technology environments, such as factory equipment, utility control systems, and SCADA systems, present risk considerations that differ meaningfully from traditional IT. These systems often prioritize availability and safety over confidentiality, may run for long lifecycles, and can have physical consequences when compromised. NIST SP 800-82 gives organizations a structured reference for understanding typical OT system topologies, the threats these environments face, and recommended safeguards, which is valuable in sectors where security failures can affect physical operations rather than only data.
For security leaders, SP 800-82 matters because it provides a common vocabulary and a credible baseline when assessing and improving OT security posture. Because it is authored and maintained by NIST, with Revision 3 published in September 2023 superseding Revision 2 from 2015, and a further revision underway to incorporate lessons learned, it reflects an evolving understanding of OT risk that organizations can point to when justifying program priorities to boards and stakeholders.
It is important to be precise about what following SP 800-82 does and does not accomplish. It is guidance rather than a mandatory regulation or an audited certification standard, so aligning to it supports better security but does not by itself demonstrate compliance or transfer accountability. Legal and organizational accountability for OT security decisions remains with the client organization and its officers.
Who it's relevant to
Inside NIST SP 800-82
Common questions
Answers to the questions practitioners most commonly ask about NIST SP 800-82.