Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CISA, UK NCSC Release Joint Guidance on Operational Technology Security

by Kristen Smith
October 2, 2025
in Cybersecurity, DHS, News
CISA logo. CISA and partners issued guidance to help organizations create a definitive view of their OT architecture.

CISA, the UK NCSC and international partners issued joint guidance to help organizations create and maintain a definitive view of their operational technology architecture.

The United Kingdom’s National Cyber Security Centre, in partnership with the Cybersecurity and Infrastructure Security Agency, the FBI and other international partners, has published new joint guidance aimed at helping organizations secure their operational technology environments.

Table of Contents

    • You might also like
    • DHS S&T Opens AI Prize Challenge to Detect Biological Threats
    • GSA, OpenAI Reach OneGov Deal for Discounted ChatGPT Access
    • Department of War Seeks AI Tools to Track Space & Missile Threats
  • Building a Definitive OT Record
  • Architectural Controls and Standards Alignment
  • Enabling Risk Reduction and Resilience

You might also like

DHS S&T Opens AI Prize Challenge to Detect Biological Threats

GSA, OpenAI Reach OneGov Deal for Discounted ChatGPT Access

Department of War Seeks AI Tools to Track Space & Missile Threats

The document, titled “Creating and Maintaining a Definitive View of Your Operational Technology Architecture,” builds on the recent Foundations for OT Cybersecurity: Asset Inventory Guidance and provides actionable steps to strengthen defenses against cyberthreats, CISA said.

CISA is a DHS agency. Potomac Officers Club’s 2025 Homeland Security Summit offers an inside look at the latest programs, technologies and strategies shaping America’s defense against evolving threats. Register to be part of the homeland security conversation.

CISA, UK NCSC Release Joint Guidance on Operational Technology Security

Building a Definitive OT Record

The guidance emphasizes that a central, authoritative record of an organization’s OT architecture is essential for effective risk management. The record should incorporate data from multiple sources, including asset inventories, vendor documentation and software bills of materials, to ensure accuracy and visibility across systems. Maintaining the record allows operators to identify vulnerabilities, understand interdependencies and prioritize protections for the most critical and exposed assets.

Architectural Controls and Standards Alignment

According to the guidance, organizations should implement strong architectural controls such as segmentation, zoning and access restrictions to protect critical OT systems. The measures should align with international standards like International Electrotechnical Commission 62443 for industrial control system security and International Organization for Standardization/IEC 27001 for information security management.

The document also highlights the need to manage third-party and supply chain risks by integrating supplier-provided data and patching requirements into the OT record.

CISA and its partners note that OT security is not a one-time exercise. To remain effective, the definitive OT record must be continuously updated through configuration management, monitoring and change management processes.

The guidance recommends fostering collaboration between IT and OT teams to align governance, security policies and incident response procedures.

Enabling Risk Reduction and Resilience

By maintaining an accurate and comprehensive view of OT environments, organizations are meant to be able to conduct more thorough risk assessments, address cost asymmetries between threats and defenses, and implement security controls more effectively.

According to the guidance, establishing a definitive OT record is a critical step toward reducing risk and strengthening resilience. It urges operators to adopt a proactive approach to safeguarding systems that are essential to national infrastructure.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

NOAA Taps Raytheon for NEON Stratus Project Study

Next Post

Army Taps GDMS, Pacific Defense for CMFF Prototype Development

Recommended For You

CISA-FBI Alert Calls for Elimination of SQL Injection Vulnerabilities in Software

by Jane Edwards
April 22, 2024
coding hacking software_272x270

The Cybersecurity and Infrastructure Security Agency and the FBI have released a joint alert urging technology manufacturers to eliminate SQL injection vulnerabilities in software. The Secure by Design...

Read moreDetails

GAO Assesses DLA Contractors’ Reverse Engineering Capabilities

by Matthew Nelson
August 19, 2022
GAO Assesses DLA Contractors' Reverse Engineering Capabilities

The Government Accountability Office assessed and validated Defense Logistics Agency contractors that specialize in reverse engineering techniques. GAO found in a report published Wednesday that 124 companies conducted...

Read moreDetails

Ellen Lord Details DoD Plans to Attract More Industry Partners

by Darwin McDaniel
December 20, 2018
Ellen Lord Details DoD Plans to Attract More Industry Partners

Ellen Lord, the top acquisition officer at the Department of Defense, has said the agency plans to simplify some processes in buying technologies for the military in 2019,...

Read moreDetails

NSA Issues Cybersecurity Advisory on AI-Generated Attacks Against Siemens PLCs

by Miles Jamison
August 20, 2026
NSA seal. The National Security Agency issued a cybersecurity advisory warning for cyberthreats targeting Siemens S7 Series programmable logic controllers.

The NSA and co-sealing agencies have urged programmable logic controller operators to patch systems and limit internet exposure.

Read moreDetails

VA, Startup Accelerator to Host Health Care Tech Pitch Competition

by Angeline Leishman
July 12, 2021
VA, Startup Accelerator to Host Health Care Tech Pitch Competition

The Department of Veterans Affairs (VA) has partnered with California-based startup accelerator Founder Institute to identify emerging health care technologies through a pitch competition scheduled for Aug. 26th....

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!