The Operational Technology Cybersecurity Coalition (OTCC) is calling on the US Cybersecurity and Infrastructure Security Agency (CISA) to establish mandatory security requirements for operational technology (OT) across all federal civilian agencies. In a report released on October 6, the coalition emphasized the need for a binding operational directive (BOD) due to the current lack of minimum security practices and CISA's limited visibility into OT-related risks, according to a recent report by Infosecurity Magazine.
The OTCC's proposal stems from a Government Accountability Office (GAO) report indicating that many federal agencies are failing to meet existing requirements for inventorying networked OT and IoT devices. The coalition advocates for a directive that would mandate senior official responsibility for OT security, integrate OT risk into enterprise risk management, and establish baselines for asset inventory, network segmentation, remote access, configuration management, incident preparedness, and verified recovery.
While the proposed directive includes controls like changing default passwords, implementing multi-factor authentication, and ensuring segmentation and backups, some experts note that it does not explicitly call for patching or firmware updates, which are crucial for addressing vulnerabilities exploited by attackers. The directive aims to complement existing resilience initiatives by setting pre-incident baselines to prevent cyberattacks from causing physical consequences, influencing best practices beyond federal agencies.
Source: Infosecurity Magazine