Why: Vendor sessions provisioned per engagement, time-bound, and supervised or recorded are how remote execution of privileged commands gets authorized in practice — remote OT work is almost always privileged work, so the practice's brokering discipline lands directly on this requirement's subject.
What this does not claim: Brokering and recording sessions is not the same as the written authorization the requirement centers on: which privileged operations may be performed remotely, by whom, must still be documented as a deliberate decision. The requirement also spans remote privileged work across the whole boundary — IT servers, identity infrastructure, security tooling — which this OT-focused practice does not reach.
- Document which remote privileged operations are permitted per vendor engagement and who may perform them
- Supervise or record privileged remote sessions where warranted, with the records retained
- Per-engagement authorization records for vendor remote work
- Session recordings or supervision logs for privileged remote sessions
Where this holds: Holds only where OT systems fall within the organization's CUI boundary.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06