Operational Technology
Pages
Page 2 of 37
Creating and maintaining a definitive view of your OT architecture

In this guidance
Principle 1: Define processes for establishing and maintaining the definitive record
Principle 2: Establish an OT information security management programme
Principle 3: Identify and categorise assets to support informed risk-based decisions
Principle 4: Identify and document connectivity within your OT system
Principle 5: Understand and document third-party risks to your OT system.
This guidance defines a principles-based approach for how operational technology (OT) organisations should build, maintain and store their systems understanding. It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management.
This guidance has been developed with contributions from partnering agencies and is part of a series of publications aiming to draw attention to the importance of cyber security in Operational Technology. It is produced by the UK National Cyber Security Centre (NCSC) in partnership with the Australian Signals Directorate Australian Cyber Security Centre (ASD's ACSC), US Cybersecurity and Infrastructure Security Agency (CISA), the Canadian Centre for Cyber Security (Cyber Centre), the US Federal Bureau of Investigation (FBI), New Zealand’s National Cyber Security Centre (NCSC-NZ), Netherlands National Cyber Security Centre (NCSC-NL) and Germany’s Federal Office for Information Security (BSI). |