Zero Trust Architecture for Manufacturing OT Remote Access: What to Verify
Data

Zero Trust Architecture for Manufacturing OT Remote Access: What to Verify

NIST SP 800-207 defines zero trust architecture as a set of concepts and principles, not a product or checklist. Applying it to OT remote access requires verifying prerequisites the guide does not cover, including IDMZ boundaries, legacy equipment, and flat networks.

3 min read
Back to News
TL;DR
  • -NIST SP 800-207 defines zero trust architecture as a set of concepts and principles for continuous improvement of access control, not a product or compliance checklist.
  • -There is no single approach for migrating to ZTA that is best for all enterprises, and OT environments introduce constraints the NIST guide does not cover.
  • -ZTAs for industrial control systems and OT environments are explicitly out of scope for NIST SP 1800-35, and many critical infrastructure organizations operate on legacy systems without modern cybersecurity controls.

What Zero Trust Architecture Means

NIST SP 800-207 is the definitive source of ZTA concepts and principles. The model is not a product or a compliance checklist. ZTA is a set of concepts and principles, not a set of technical specifications that can be complied with. The objective is continuous improvement of access control processes and policies in accordance with those principles.

An identity is any subject requesting access. A resource is anything that requires protection.

How the Access Decision Works

The NIST guidance describes enhanced identity governance, software-defined perimeter, microsegmentation, and secure access service edge (SASE) as distinct implementation approaches. Each maps to the same underlying principles but uses different technical mechanisms.

Access is granted based on attributes of both the subject and the resource, including location, authentication method, user role, and other variables such as time of day.

There is no single approach for migrating to ZTA that is best for all enterprises.

Remote Access During Equipment Failures

That access path crosses a boundary between IT systems and production systems.

Rockwell Automation describes this boundary as an Industrial Demilitarized Zone (IDMZ).

Deploying an IDMZ to separate business systems from production operations is a best practice for helping protect industrial control systems (ICS).

This boundary helps prevent breaches in IT from accessing OT networks and controllers. Zero trust microsegmentation can then further guard business-critical assets using firewalls, highly granular access and identity policies, and other steps. The combination addresses the risk that threat actors can leverage excess trust to breach networks, often using stolen credentials.

What the NIST Guide Does Not Cover

One boundary matters here. ZTAs for industrial control systems, OT environments, and Internet of Things (IoT) devices are explicitly out of scope for the NIST SP 1800-35 project. The guide's scope covers conventional enterprise IT infrastructure, including laptops, desktops, servers, mobile devices, and other systems with credentials.

That distinction is material.

Operating Constraints That Must Be Verified

Production continuity and downtime exposure. A connected enterprise requires a comprehensive approach to network segmentation, including IDMZ, and an expert partner who understands how to apply strategies such as Zero Trust in industrial environments.

Flat networks and legacy equipment. Many critical infrastructure organizations operate on legacy systems without modern cybersecurity controls in place, such as network segmentation, multi-factor authentication, frequent asset inventories, or effective OT patching. Where OT and IT traffic share a flat network, that boundary does not yet exist.

Enterprises will need to define policies that determine under what set of conditions subjects will be given access to each resource based on attributes of both the subject and the resource.

Incomplete asset inventories. Enterprises that want to migrate gradually to ZTA may want to inventory and prioritize all resources that require protection based on risk. In OT environments, asset discovery may be constrained by the age of the equipment or other operational factors.

Cross-functional ownership. OT security crosses IT, operations, and engineering. Rockwell Automation notes that applying Zero Trust in industrial environments requires expertise around modern industrial security practices and industry-accepted standards like ISA/IEC 62443.

What Zero Trust Is Not

The NCCoE and its collaborators built 19 interoperable, open standards-based ZTA implementations using commercially available technology. No single vendor or platform defines the architecture.

The NIST principles describe how access decisions should be made. They do not prescribe a specific network topology, a specific enforcement product, or a specific sequence for OT environments. A risk-based approach to setting and prioritizing milestones for gradual adoption is the recommended path, not a single deployment event.

The NIST model provides the framework for answering those questions.

Sources and supporting resources
Previous
Zero Trust for OT Remote Access: Prerequisites to Verify First
Next
Requirements for a Governed Software and Systems Modernization Plan

Get Business Technology Updates

Practical guidance on complex operations, integration, portals, analytics, automation, custom software, trusted records, and fit-for-purpose engineering.

No spam. Unsubscribe anytime.