Why: Unauthorized use in a plant looks like a connection or command with no business existing — a new device on the control network, a workstation talking to a PLC it never touched, a write from an unexpected source. Baseline-deviation monitoring is built to surface exactly that.
What this does not claim: May partially address the requirement. Separating unauthorized use from authorized-but-unusual operations takes process knowledge the sensor lacks — a contractor laptop during a shutdown may be entirely legitimate — so the practice yields candidates for review, not determinations, and identification of unauthorized use across the IT estate (accounts, applications, data access) is untouched by OT network monitoring.
- Alert on new devices and never-before-seen conversations on OT segments
- Review anomalies against work orders and maintenance schedules before declaring misuse
- New-device and anomaly alerts with dispositions
- Review records tying anomalies to authorized work, or escalating them
Where this holds: OT segments inside the assessed boundary only; the requirement's reach across business systems needs its own mechanisms.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06