Why: Restricting engineering functions — the ability to alter control logic — to authorized staff is limiting the types of functions authorized users may execute, which is this requirement's substance applied to production systems.
What this does not claim: Applies only to OT systems inside the CUI boundary, and only to the function classes OT platforms expose; many legacy controllers cannot distinguish operator from engineer at all, leaving physical and procedural limits to carry the intent. Transaction and function limits across business applications and file systems are entirely outside this practice.
- Restrict engineering and configuration functions to named, authorized individuals
- Separate operator, engineering, and administrative roles where the platform allows it
- Role or privilege configuration exports from OT platforms that support them
- The documented list of personnel authorized for engineering functions
Where this holds: Holds only for OT systems within the organization's CUI boundary.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06