What you need to know
NIST explicitly includes physical access-control systems in OT and frames their security around mapped data flows, segmentation, controlled remote access, and availability.
Potentially affected
Networked physical access-control servers, controllers, readers, management workstations, building-system integrations, cloud connections, and temporary or persistent vendor access.
DSE recommendation
Map access-system dependencies and required flows, build risk-based zones, limit remote access, and test security changes against door availability and emergency operations.
Physical access control is within NIST’s OT scope
Source fact: NIST SP 800-82 Rev. 3 defines operational technology broadly and explicitly lists physical access-control systems as an example. Its PACS description includes credentials, readers or keypads, door controllers, an access-control server, rules and privileges, and audit logs. The server can be on premises or managed in the cloud.
The OT framing changes how controls are introduced. NIST explains that rebooting may be unacceptable where availability is required, outages may need to be planned well in advance, redundancy can be necessary, and high-availability designs need extensive predeployment testing. A security improvement that unexpectedly prevents authorized entry or emergency work is not a successful deployment.
Segment from documented flows
NIST recommends segmentation or zoning by factors such as function, criticality, trust, location, management authority, or data flow. Segmentation can use physically separate infrastructure or logical VLANs. Mapped data flows should identify required communications, while firewalls, gateways, switches, routers, or other enforcement devices allow only explicitly authorized traffic between segments. A DMZ can serve as a boundary where appropriate.
Remote access should be provided only when justified and limited to the business need. It should not bypass safety or security controls. NIST says multi-factor authentication should be considered and that temporary vendor-maintenance access still needs secure procedures. Remote-access disablement is important, but its operation must not disrupt the OT process.
Current-publication boundary
Rev. 3, finalized September 28, 2023, remains NIST’s current final SP 800-82 publication as of this review. NIST has begun a Rev. 4 pre-draft process, but a pre-draft is not final guidance. SP 800-82 is also architecture-level material, not a configuration manual for a particular access-control platform.
DSE architecture checklist
DSE recommendation: This is DSE operational synthesis and must be reconciled with product, facility, egress, and emergency requirements.
- Inventory readers, controllers, servers, workstations, directories, databases, switches, cloud services, and vendor paths.
- Assign owners and criticality, including the consequence of each component or dependency being unavailable.
- Document normal, emergency, offline, update, backup, monitoring, and support data flows.
- Create zones and enforcement rules from those flows; do not rely on a VLAN name as proof of isolation.
- Remove unjustified remote paths and make required sessions named, approved, limited, monitored, and time-bound.
- Use strong authentication and encryption where supported, with compensating controls documented for legacy limitations.
- Test controller autonomy, door operation, alarms, audit, emergency workflows, remote-access disablement, and recovery.
- Review the architecture after integration, cloud, identity, site, or vendor-support changes.
Official references
- NIST SP 800-82 Rev. 3 — the current final OT scope and security guidance.
- Guide to Operational Technology Security — PACS architecture, availability, segmentation, and remote-access details.
- NIST Operational Technology Security publications — current final and draft status tracking.
Review the official source
NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security · Published September 28, 2023
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE