Overview
NIST SP 800-82 is the US guidance for securing operational technology, the control systems that run physical processes. It adapts mainstream security controls to the realities of OT, where availability and safety come first, legacy protocols are common, and network architecture and segmentation do much of the work. It is widely referenced in public-sector and critical-infrastructure tenders. ControlBird provides controls that fit an 800-82-aligned OT deployment; the network architecture, segmentation, and monitoring programme around it are the operator’s.
Key requirements
- Network architecture and segmentation
- Separate OT from IT and control the conduits between zones.
- Access control and least privilege
- Restrict who and what can interact with control systems.
- Secure communications
- Protect control traffic, especially across untrusted links.
- Availability, monitoring, and recovery
- Prioritise uptime and safe recovery, and retain records so problems can be detected.
How ControlBird aligns
- Fits a segmented OT architecture
- ControlBird runs inside the zones you define rather than enforcing network policy itself, and its protocol guidance is explicit that legacy or serial protocols which cannot be encrypted belong in a trusted segment or behind a VPN. That matches 800-82’s emphasis on segmentation as a primary control.
- Access control and least privilege
- Least-privilege access control enforced in the data layer, with role- and attribute-based permission rules granular to the entity, field, and branch level and conditions evaluated at access time, plus sign-in through native accounts, LDAP and Active Directory, or OAuth 2.0.
- Secure communications
- TLS 1.2 and 1.3 for the web and API and for OPC UA, MQTT, Modbus TCP, and DNP3, managed through the Certificate Manager. Serial Modbus and EtherNet/IP have no transport encryption and DNP3 transport TLS is not end-to-end, so segment or tunnel those links.
- Availability and recovery first
- Leader election, multi-node replication, and failover keep the control layer running, and snapshots with write-ahead-log replay restore it. This reflects the OT priority on availability and safe recovery.
- What the operator owns
- 800-82 is guidance for the operator’s OT security programme. The network architecture, the segmentation, the continuous monitoring, and incident response are designed and run by your team; ControlBird provides controls that support them, including user-attributed writes that can be retained as a queryable change history for accountability. Forward logs to your monitoring stack for cross-system correlation. 800-82 is guidance, not a certification.
Need this for a tender?
We can provide deployment-specific detail and supporting documentation for procurement and security reviews.