| ZT Pillar | Immediate Action | Strategic Fix | Framework / Top 10 |
|---|---|---|---|
|
Identity
Top 10 #1, #4, #9, #10
|
Separate OT Active Directory from enterprise AD. Enforce MFA on all jump hosts. Audit break-glass account scope and expiry. | Deploy Zero Standing Privilege for OT: per-session, scoped access only. No standing administrative credentials. Time-limited break-glass accounts with automatic alerts on use. | NIST SP 800-207 §3.3 · CISA ZTMM Identity |
|
Devices
Top 10 #2
|
Deploy network TAPs at IT/OT boundaries for passive asset discovery. Do not use active scanning — it can crash legacy PLCs and RTUs. | Build incremental OT asset inventory from passive traffic data. Add ZT requirements (logging, SBOM, ICAM) to all new OT procurement specifications. | NIST SP 800-207 Tenet 6 · CISA ZTMM Devices |
|
Networks
Top 10 #5, #7
|
Treat the IT/OT boundary as a hard enforcement point. Log all cross-boundary traffic. Restrict enterprise accounts from OT systems immediately. | Deploy data diodes for unidirectional OT-to-IT data flows. Harden jump hosts as single authorized remote access entry — MFA, session recording, minimum-scope access. Pre-plan soft segmentation procedures for incident containment. | NIST SP 800-207 Tenet 2 · CISA ZTMM Networks |
|
Apps & Workloads
Top 10 #3, #6
|
Audit OT engineering workstations for unnecessary software. Enable application allowlisting on HMIs where feasible (WDAC for Windows-based systems). | Wrap legacy OT protocols (Modbus, DNP3, EtherNet/IP) in TLS-enabled gateways at zone boundaries. Apply SSVC framework to prioritize OT patches by actual exploitation risk vs. downtime cost. | NIST SP 800-207 Tenet 1 · CIS Controls v8 #2, #4 |
|
Data
Top 10 #8
|
Concentrate logging at IT/OT junction points and jump hosts — where visibility is feasible and value is highest. Deploy CISA's open-source Malcolm SIEM for industrial protocol parsing. | Build OT-specific backups: engineering logic, ladder diagrams, I/O lists, configuration, startup values. Validate via checksum before needed. Know your OT recovery time objective from a known-good state. | NIST SP 800-207 Tenet 7 · CISA ZTMM Visibility |
| Timeframe | Priority Actions |
|---|---|
| Days 1–7 | Deploy TAPs at IT/OT boundaries · Enforce MFA on jump hosts · Audit vendor remote access · Export 90 days of IT/OT boundary logs |
| Days 8–30 | Passive asset discovery · Separate or restrict OT AD accounts · Table-top OT IR plan with soft segmentation · Enable full vendor session logging |
| Days 31–90 | Deploy Malcolm SIEM for industrial protocol visibility · Implement SSVC-based OT patch prioritization · Add ZT and SBOM requirements to OT procurement specs · Validate OT-specific backups |
The complete OZTP advisory includes all five ZT pillars with NIST and CISA framework citations, the full OZTP Top 10 mapping for OT environments, and access to Agent Zeta — our free AI Zero Trust advisor.