NIST drafts updated OT security guide, CISA and FBI warn on ICS integrators

Summary

NIST has published a draft update to its operational technology (OT) security guide, aiming to enhance the security protocols across various critical infrastructure sectors, including building automation and water systems, with comments on the draft due by November 30, 2026. This update reflects NIST's efforts to align with the NIST Cybersecurity Framework 2.0 and incorporates expanded guidance on implementing security controls and zero trust principles. Concurrently, CISA and the FBI released a fact sheet warning critical infrastructure operators about the risks associated with third-party industrial control system (ICS) integrators, emphasizing the importance of applying the principle of least privilege and incorporating cybersecurity measures into contracts to safeguard against potential cyber threats.

Analysis

FBI: The Federal Bureau of Investigation is the US lead agency for investigating cyber intrusions and protecting against foreign threats to critical infrastructure. In this news, the FBI contributed technical analysis from a prior intrusion incident to support the joint fact sheet on ICS integrator risks. CISA: The Cybersecurity and Infrastructure Security Agency is a US Department of Homeland Security component dedicated to protecting the nation's critical infrastructure from cyber threats. In this news, CISA partnered with the FBI to issue a fact sheet advising critical infrastructure operators on managing risks from third-party ICS integrators. NIST: The National Institute of Standards and Technology is a US Department of Commerce agency that develops cybersecurity standards and guidelines for public and private sector use. In this news, NIST released a draft revision of its OT security guide, expanding coverage to additional critical infrastructure sectors and aligning it with the Cybersecurity Framework 2.0 while seeking public comments. Regulation: NIST is updating its operational technology security guidance to better address performance, reliability, safety requirements, and zero trust principles in critical infrastructure sectors. Supply Chain: US agencies recommend that critical infrastructure operators apply the principle of least privilege and include cybersecurity requirements in contracts with third-party ICS integrators to mitigate exposure to malicious actors.

Categories

techpolitics
View Original Tweet