Why: Monitoring systems and communications traffic to detect attacks is this practice's whole outcome on the OT network: passive sensors baseline normal industrial traffic and surface deviations, on segments where passive detection is often the only safeguard production tolerates.
What this does not claim: May partially address the requirement, for the OT slice only and only where OT assets sit inside the assessed boundary. The requirement covers organizational systems broadly — the IT estate's monitoring is separate work — and a passive sensor sees the network, not the host: engineering workstations and historians still need endpoint-level visibility that many OT environments cannot safely run, which is a gap to record, not assume away.
- Deploy passive network monitoring on OT segments via span or tap, never inline without qualification
- Baseline normal traffic and alert on deviation
- Route alerts to people who can distinguish a process anomaly from an attack
- Sensor coverage map against OT network segments
- Alert records with triage outcomes
- Baseline documentation and tuning history
Where this holds: Holds for OT segments inside the CUI boundary; the practice contributes nothing to monitoring of the IT estate, which this requirement equally covers.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06