NIST has released Revision 4 of its operational technology security guide for public comment, with feedback accepted until November 30. The draft updates earlier guidance on securing OT systems, reflecting evolving threats and best practices for critical infrastructure.
Separately, CISA and the FBI have published advice aimed at industrial control system integrators. The advisory highlights security concerns that can arise when third-party integrators are involved in OT environments, pointing to supply chain risks that organizations should address.
The two actions are complementary rather than conflicting: NIST offers broad, foundational guidance for OT security, while the CISA/FBI advisory focuses on a specific part of the OT supply chain. No disagreements between the documents are noted in the source.