View Resource
Zero Trust Guidance for Critical Infrastructure: Applying Zero Trust to Operational Technology (OT) and Industrial Control System (ICS) Environments
Release Date: 10/29/2024
Organization: CSA
Content Type: Guidance
Solution Provider Neutrality: Neutral
This document delves into the critical and nuanced application of Zero Trust (ZT) principles within Operational Technology (OT) and Industrial Control Systems (ICS). It aims to bridge the gap between traditional information technology (IT) security methodologies and the unique demands of OT/ICS in Critical Infrastructure (CI) sectors. Recognizing the distinct challenges and architectures inherent in these environments, the paper not only clarifies the foundational concepts of ZT but also provides a tailored roadmap for implementing these principles effectively in OT/ICS settings. This roadmap employs a systematic approach from defining Protect Surfaces to continuous monitoring and maintenance based on the five-step process outlined in the NSTAC Report to the President on Zero Trust and Trusted Identity Management, ensuring resilience and security in CI amidst a rapidly evolving digital technology and threat landscape.