Partial implementation supportModerate confidence
Why: The practice's combined review assesses safety and security impact together before a change is approved — the pre-implementation analysis this requirement asks for, applied where a wrong change stops production.
What this does not claim: The review's security-impact depth depends on who the plant names as the security approver; a safety-led review can pass changes whose security consequences nobody was qualified to see. Scope is also limited to the OT estate within the assessed boundary — impact analysis for IT changes is untouched by this practice.
Practice-side activities- Assess safety and security impact in the same review, by approvers qualified to judge each
- Defer changes with no viable maintenance window rather than forcing them
Evidence this produces- Change records showing security impact assessed before approval
- An example of a change modified or deferred on impact grounds
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06
Partial implementation supportModerate confidence
Why: Pre-merge security scanning and review examine a change's security consequences before it ships — impact analysis performed where it is cheapest, in the pipeline rather than in production.
What this does not claim: Automated scanners assess the code in front of them, not the architectural consequences of a change — a new external integration can pass every gate while altering the boundary. The analysis also covers only changes that flow through the pipeline; infrastructure and configuration changes made elsewhere need their own impact review.
Practice-side activities- Run static analysis and dependency checks as required gates before merge
- Escalate boundary-touching and identity-touching changes to human security review
Evidence this produces- Pipeline configuration showing security gates as required checks
- A change record where a gate finding altered or blocked the change
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06