Summary
- NIST published the initial public draft of SP 800-82 Rev. 4 on 21 September 2026 and seeks comments by 30 November. It is proposed guidance, not a final revision or a finding about any operator.
- A reviewer note says threat and research appendices C and D are to become web resources in the final publication, while the OT control overlay and RMF appendices E and F are to become separate documents. All four still appear in this draft.
- Version custody is the editorial issue: an operator should be able to reconstruct the guide, resource snapshot, companion document and local constraints behind a risk decision. NIST does not prescribe the record proposed here.
Two water-system operators could cite “SP 800-82” and still reach different monitoring choices. One might have read a later online threat resource; the other might have worked from an earlier snapshot and a different revision of the OT overlay. This is a hypothetical comparison, not a reported failure. It shows why a citation to a guide, by itself, is a poor description of what an engineer or risk owner actually considered.
NIST’s 21 September initial public draft of Guide to Operational Technology (OT) Security covers systems that monitor or change the physical environment. Its examples extend beyond conventional industrial controls to building automation, water and wastewater, transport and other settings. NIST says the revision is organized around the Govern function of CSF 2.0, gives more attention to enterprise-risk alignment, and expands guidance on asset management, network monitoring, protection of system-management functions and zero trust principles. None of that is evidence that a particular plant has adopted or failed a control.
The more easily missed change is in the note to reviewers. NIST says appendices C and D, on threats, incidents, organizations and research, are to move to web-based resources in the final publication so they can be updated more promptly. The OT overlay in appendix E and the OT application of the Risk Management Framework in appendix F are to become separate documents. This is a stated publication plan. The appendices remain inside the 321-page initial draft, and the final form may change after comments.
The separation has a sensible reason. Threat examples and research pointers age at a different rate from a guide’s core risk architecture. Appendix D itself warns that its descriptions of organizations have not been verified and directs readers to the organizations for current information. A more current web resource may be more useful than a frozen list. But freshness and traceability solve different problems. A revised reference can improve today’s analysis while making yesterday’s decision harder to reconstruct if its earlier state was not kept.
A small decision record would name the draft or final guide revision, the date and stable copy of any web resource consulted, the overlay and RMF companion revisions if used, the asset or process boundary, the safety and availability constraints, the decision owner, and the reason for accepting or declining a safeguard. It should distinguish NIST guidance from a local engineering judgement and from any separate binding requirement. A document hash or archived snapshot can help prove which text was consulted; it cannot prove that a control was effective or that all relevant plant conditions were captured.
The draft does not supply a ready-made plant control set. Appendix E describes a partial tailoring of SP 800-53 Rev. 5 controls and baselines, not a universal OT prescription. Appendix F describes OT-specific RMF application and marks some tasks optional. A facility therefore still has to explain what it selected, what it adapted and who accepted residual risk. Treating the guide’s title as the decision itself would erase precisely that local accountability.
The comment window closes on 30 November, not the standard’s finalization date. Comments could ask NIST how future web-resource versions and companion-document cross-references will be identified and retained. Operators need not wait for a final edition to ask the corresponding internal question: if this decision is challenged later, can we show the exact evidence landscape that existed when it was made?
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
