CyberzSOC

Publication detail
← Back to advisories & guidance

Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture ↗ source

September 29, 2025 FBI Alert
Co-sealed by: ASD/ACSC, BSI, CCCS, CISA, FBI, NCSC-NL, NCSC-NZ, NCSC-UK

Summary

It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management. Principle 1: Define processes for establishing and maintaining the definitive record Principle 2: Establish an OT information security management programme Principle 3: Identify and categorise assets to support informed risk-based decisions Principle 4: Identify and document connectivity within your OT system Principle 5: Understand and document third-party risks to your OT system This guidance has been developed with contributions from partnering agencies and is part of a series of publications aiming to draw attention to the importance of cyber security in Operational Technology. It is produced by the UK National Cyber Security Centre (NCSC) in partnership with the Security Agency (CISA), the US Federal Bureau of Investigation (FBI), Germany’s Federal Office for Information Security (BSI), Netherlands National Cyber Security Centre (NCSCNL), and New Zealand’s National Cyber Security Centre (NCSC-NZ).

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.