NSA proposes common-sense fixes to OT security standards

|
Updated

In April of 2025, the US National Security Agency (NSA) Cybersecurity Directorate published a cybersecurity technical report (CTR), “Operational Technology Assurance Partnership: Smart Controller Security within National Security Systems” aimed at updating ISA 62443-4-2 with six new common-sense controls.

ISA 62443-4-2 itself is a proprietary standards document available from the International Society of Automation, and for use by designers of operational technology and industrial control systems (OT/ICS), and specifically those components that are part of defined National Security Systems (NSS).

The Six Common-Sense Requirements #

The NSA looked at this set of standards, and noted six common-sense security controls that are lacking specific callouts in the current version of ISA 62443-4-2. Specifically, the NSA’s investigation is focused on the security of “smart controllers,” those components of OT/ICS systems that automate functionality and often have their own computing, storage, and networking capabilities.

The NSA flagged the following for standardization:

  1. Disable Wireless Interfaces - Prevents unauthorized wireless access vectors.
  2. Disable SSID Broadcasting - Avoids passive network discovery by adversaries.
  3. Pattern-Hiding Displays – Protects sensitive on-screen info from shoulder surfing or remote observation.
  4. Restrict Removable Media Devices - Reduces infection risks from USB drives and similar attack vectors.
  5. Encrypt Data in Transit - Ensures secure communication across networked environments.
  6. Use NSA-Approved Cryptography - Enforces strong, vetted encryption standards appropriate for NSS.

Anyone familiar with the basics of cybersecurity will note, fairly immediately, that these are not particularly exotic new requirements, and so the folks who are tasked with the regular care and feeding of OT/ ICS in their environments should be on the lookout for these features to become commonplace for vendors that follow ISA 62443-4-2.

More importantly, if you have OT/ICS devices in your network that don’t already enforce things like physically disabling Wi-Fi capabilities or use normal cryptographic standards for encrypting local data, it’s probably time to start making some noise with your vendors.

I don’t see any reason why the ISA wouldn’t adopt these new required controls for OT/ICS smart controllers. The recommendations are backed by pretty solid research — looking at recent CVEs and the MITRE ATT&CK framework, and conducted by none other than the NSA. Check out the NSA’s report if you want to get down in the weeds, especially if your job involves securing your OT/ICS footprint.

What Comes Next #

The NSA plans to:

  • Incorporate these requirements into an OT conformance pilot program

  • Propose formal adoption through future revisions of ISA 62443‑4‑2

  • Extend this analysis to other OT components beyond smart controllers

While the focus is on NSS, the recommendations are broadly applicable to public and private infrastructure alike. Organizations managing industrial automation, utilities, or ICS environments should take note.

How runZero Can Help #

In the meantime, runZero can help you ferret out those stragglers that are using deprecated cryptographic libraries and unexpected multi-homed controllers, to name but two likely violations of these new suggested requirements, as well as the likely avalanche of end-of-life / end-of-service devices that don’t support internal controls like systems that don’t support sensible screen locks or allow for USB drives to be plugged in all willy-nilly.

Furthermore, runZero combines proprietary active scanning with passive discovery — a method the U.S. Department of Energy (DOE) has validated as safe for sensitive OT and ICS environments.

Kick off your free trial in minutes, or request a demo to get expert answers tailored to your environment.

Written by todb

Tod Beardsley is VP of Security Research at runZero, where he "kicks assets and fakes frames." Prior to 2025, he was the Section Chief for the Vulnerability Response section for CSD/VM/VRC at CISA, the Cybersecurity and Infrastructure Security Agency, part of the US government, and a seasonal Travis County Election Judge in Texas. He's also a founder and CNA point of contact for AHA!. Tod spends much of his time involved in vulnerability research and coordinated vulnerability disclosure (CVD). He has over 30 years of hands-on security experience, stretching from in-band telephony switching to modern ICS/OT implementations. He has held IT ops, security, software engineering, and management positions in large organizations such as the US Government, Rapid7, 3Com, Dell, and Westinghouse, as both an offensive and defensive practitioner. Tod is a CVE Board member, has authored several research papers, and is an internationally-tolerated horror fiction expert.

More about todb
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 5.0: Exposure management built to outpace AI-driven attacks
When you're up against AI, every minute counts. Get deep, actionable intelligence across your entire attack surface to close the gaps and hold the...
Product Videos
runZero 5.0: Platform Demo
With the new 5.0 release, runZero is giving defenders the edge they need to succeed in the AI-attack era.
runZero Perspective
BOD 26-04: A new era of prioritized remediation
A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...
Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.