The NCCoE has published the draft Project Description Asset Management as a Foundation for OT Cybersecurity, outlining the proposed scope, challenges, and technical approach for the project.
Operational Technology Asset Management
Organizations face challenges in maintaining an up-to-date understanding of their OT assets, including devices, systems, and configurations. As organizations modernize OT environments, adapt to AI-driven cybersecurity threats and vulnerabilities, and adopt cybersecurity practices such as zero trust, effective asset management and visibility have become increasingly important foundational capabilities.
Demonstrating practical approaches to achieve and maintain asset management and visibility for OT environments.
Operational Technology (OT) is essential for managing the physical processes that power modern industry and ensuring the safe operation of essential services. A comprehensive OT asset management system allows an organization to better understand its OT systems, hardware, and software, which is vital for defining and documenting system boundaries and accurate device security statuses. By having this information, an organization can conduct risk assessments to perceive gaps in their security, understand the interconnections and dependencies between assets, track vulnerabilities, and implement specific security measures to protect their OT environments. Without such a program, organizations lack the visibility needed to effectively secure and safeguard their assets.
The NCCoE plans to collaborate with asset owners, operators, and technology providers to demonstrate real-world technologies for OT asset management and visibility using commercially available products. Through this effort, this project will showcase practical implementation approaches and produce example architectures aligned with the NIST Cybersecurity Framework 2.0. The project will implement common architectures from different industrial environments to demonstrate a variety of commercial products, implementation approaches, and techniques for multiple aspects of asset management. The laboratory demonstration will allow NCCoE to develop source code, scripts, architectures, procedures, and guidelines to help organizations achieve the visibility necessary to detect and respond to modern cyber threats in their OT environments.
Join the Community of Interest
A Community of Interest (COI) is a group of professionals and advisors who share business insights, technical expertise, challenges, and perspectives to guide NCCoE projects. COIs often include experts, innovators, and everyday users of cybersecurity and privacy technologies. Share your expertise and consider becoming a member of this project's COI.