Why: The practice is change control: every OT change tracked in a record, reviewed by named approvers, approved or deferred, and logged — including vendor-performed and emergency changes, the two places change discipline usually fails.
What this does not claim: May partially address the requirement, and only for the OT estate where it falls within the assessed CUI boundary; changes to IT systems need their own process. The requirement also expects the discipline across organizational systems broadly, so an assessor will look well beyond the plant floor.
- Operate the minimum change record: what changed, who approved, what was tested, how to roll back
- Capture and review emergency changes after the fact within an agreed window
- Bring vendor-performed changes inside the process
- Completed OT change records including vendor and emergency changes
- Periodic audits of change records against what monitoring observed
Where this holds: Holds where OT assets are within the assessed boundary; contributes method and habit, but not records, for the IT estate.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06