What are the OT cybersecurity standards/guidelines and are they mandatory?
Here’s a list of 10 global guidelines and standards related to OT Security, along with their mandatory nature and regional categorization:
1. Global OT Security Guidelines & Standards
| Standard/Guideline | Issuing Body | Mandatory? |
|---|---|---|
| IEC 62443 (Industrial Automation & Control System Security) | IEC (International Electrotechnical Commission) | No (but widely adopted in regulations) |
| NIST SP 800-82 (Guide to Industrial Control Systems Security) | NIST (U.S.) | No (but referenced in regulations) |
| ISO/IEC 27019 (Security for Industrial Control Systems) | ISO/IEC | No (supports ISO 27001 compliance) |
| MITRE ATT&CK for ICS | MITRE | No (framework, not a standard) |
| ISA-99 (Industrial Automation Security) | ISA (International Society of Automation) | No (forms basis for IEC 62443) |
| NERC CIP (Critical Infrastructure Protection) | NERC (North America) | Yes (mandatory for power utilities in N. America) |
| EU NIS2 Directive | European Union | Yes (penalties for non-compliance) |
| CISA ICS Best Practices | CISA (U.S. Cybersecurity & Infrastructure Security Agency) | No (guidance, but referenced in regulations) |
| GDPR (General Data Protection Regulation) | European Union | Yes (fines for non-compliance in data protection) |
| ISO/IEC 27001 (Information Security Management) | ISO/IEC | No (but often required for compliance) |
2. Regional Categorization of Specialized OT Security Guidelines
Americas (AMS)
- NERC CIP – Mandatory for North American power utilities
- NIST SP 800-82 – U.S. Industrial Control Systems Security Guide
- CISA ICS Best Practices – U.S. ICS security recommendations
Europe, Middle East, and Africa (EMEA)
- EU NIS2 Directive – Mandatory cybersecurity directive for critical infrastructure
- GDPR – Applies to data protection in ICS environments
- IEC 62443 – Widely adopted in European industries
Asia-Pacific (APAC)
- Japan METI Cybersecurity Framework for Critical Infrastructure
- Singapore OT Cybersecurity Masterplan (CSA)
- Australia’s Critical Infrastructure Security Act (CIS Act) – Mandatory for critical infrastructure
- China’s Cybersecurity Law & MLPS 2.0 – Strict regulations for ICS security
- South Korea has several OT security regulations and guidelines, mainly enforced by government agencies like the Korea Internet & Security Agency (KISA) and the Ministry of Science and ICT (MSIT). *Remark: Act on the Protection of Critical Infrastructure (Draft & Proposed)expected to be Mandatory (currently under discussion).
#CPS #OT #XIoT #IoT #IIoT #IoMT #CPSSecurity #OTSecurity #IoTSecurity #CPS보안 #OT보안 #IoT보안

Comments
Post a Comment