Official intent
Review every change to OT for safety and security before it is made. The official source remains authoritative.
Read the official campaign ↗Why it matters
Most OT disruptions come from changes, not attacks — a misconfiguration, an untested update, an undocumented tweak. Reviewing changes for safety and security together catches the modification that would break the process or weaken a control before it ships, and the record it produces is what keeps your inventory, segmentation, and baselines honest over time.
Minimum / Strong / Advanced
Changes to OT systems, networks, and configurations require review and approval before they are made.
Review explicitly assesses both safety and security impact, changes are tested and documented, and emergency changes are reviewed after the fact.
Change review is integrated with inventory, segmentation, and monitoring, and change records drive continuous verification of the environment.
Implementation timeline
- Confirm whether OT changes currently require any review
- Identify who must approve safety- and security-relevant changes
- Define a simple change-review process with safety and security checks
- Require documentation for every OT change
- Add testing and rollback expectations to the process
- Define how emergency changes are handled and reviewed afterward
- Tie change records to inventory and segmentation updates
- Audit recent changes for compliance with the process
Implementation steps
- Require that every change to OT systems, networks, and configurations goes through review.
- Assess each change for both safety and security impact, with the right approvers involved.
- Test changes and define rollback before they are applied to production.
- Document every change — including emergency changes, reviewed after the fact.
- Feed change records into inventory, segmentation, and monitoring so the environment stays accurate.
Validation
- Pick a recent OT change and confirm it was reviewed, approved, tested, and documented.
- Verify the review explicitly considered safety and security, not just functionality.
- Confirm emergency changes were captured and reviewed after the fact.
Evidence to retain
OT change-management policy covering safety and security review
Change records with approvals, testing, and rollback notes
Emergency-change log and post-change reviews
Audit of recent changes against the process
Common failure modes
A change process that checks function but not security, undocumented “quick fixes” on the floor, and emergency changes that are never reviewed once the fire is out. Every unreviewed change quietly ages your inventory and baselines out of date.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.