What are the OT cybersecurity standards/guidelines and are they mandatory?



Here’s a list of 10 global guidelines and standards related to OT Security, along with their mandatory nature and regional categorization:


1. Global OT Security Guidelines & Standards

Standard/GuidelineIssuing BodyMandatory?
IEC 62443 (Industrial Automation & Control System Security)IEC (International Electrotechnical Commission)No (but widely adopted in regulations)
NIST SP 800-82 (Guide to Industrial Control Systems Security)NIST (U.S.)No (but referenced in regulations)
ISO/IEC 27019 (Security for Industrial Control Systems)ISO/IECNo (supports ISO 27001 compliance)
MITRE ATT&CK for ICSMITRENo (framework, not a standard)
ISA-99 (Industrial Automation Security)ISA (International Society of Automation)No (forms basis for IEC 62443)
NERC CIP (Critical Infrastructure Protection)NERC (North America)Yes (mandatory for power utilities in N. America)
EU NIS2 DirectiveEuropean UnionYes (penalties for non-compliance)
CISA ICS Best PracticesCISA (U.S. Cybersecurity & Infrastructure Security Agency)No (guidance, but referenced in regulations)
GDPR (General Data Protection Regulation)European UnionYes (fines for non-compliance in data protection)
ISO/IEC 27001 (Information Security Management)ISO/IECNo (but often required for compliance)


2. Regional Categorization of Specialized OT Security Guidelines

Americas (AMS)

  • NERC CIP – Mandatory for North American power utilities
  • NIST SP 800-82 – U.S. Industrial Control Systems Security Guide
  • CISA ICS Best Practices – U.S. ICS security recommendations

Europe, Middle East, and Africa (EMEA)

  • EU NIS2 Directive – Mandatory cybersecurity directive for critical infrastructure
  • GDPR – Applies to data protection in ICS environments
  • IEC 62443 – Widely adopted in European industries

Asia-Pacific (APAC)

  • Japan METI Cybersecurity Framework for Critical Infrastructure
  • Singapore OT Cybersecurity Masterplan (CSA)
  • Australia’s Critical Infrastructure Security Act (CIS Act) – Mandatory for critical infrastructure
  • China’s Cybersecurity Law & MLPS 2.0 – Strict regulations for ICS security
  • South Korea has several OT security regulations and guidelines, mainly enforced by government agencies like the Korea Internet & Security Agency (KISA) and the Ministry of Science and ICT (MSIT). *Remark: Act on the Protection of Critical Infrastructure (Draft & Proposed)expected to be Mandatory (currently under discussion).

#CPS #OT #XIoT #IoT #IIoT #IoMT #CPSSecurity #OTSecurity #IoTSecurity #CPS보안 #OT보안 #IoT보안

Comments

Popular posts from this blog

Don't confuse DCS, PLC and SCADA in front of OT specialists

Top 20 Threat Scenarios & Playbooks for OT Security

Let's create our own ICS Labs in the VMs!