Why: Keeping controller configuration and safety-system access behind a small set of named privileged identities is this requirement's restriction of privileged accounts, applied where its failure hurts most.
What this does not claim: The requirement's second half — privileged users switching to non-privileged accounts for nonsecurity work — collides with the shared consoles and always-logged-on HMIs common in plants; where the pattern cannot hold, the deviation needs a documented compensating measure such as dedicated engineering workstations. Privileged accounts on the IT estate are separate work the practice does not reach.
- Restrict controller and safety-system administration to named roles on dedicated engineering workstations
- Keep browsing and email off engineering workstations so privileged sessions stay single-purpose
- Privileged OT role membership lists
- Engineering-workstation configuration showing restricted use
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06