Public Comment on NIST SP 800-82 Revision 4 (Initial Public Draft), Guide to Operational Technology (OT) Security: Pipelines, Vulnerability Triage Inputs, and Remote Field-Station Security
Public comment submitted by email to the National Institute of Standards and Technology (NIST) on October 4, 2026, during the public comment period (September 21 – November 30, 2026) for NIST Special Publication 800-82 Revision 4, Initial Public Draft, Guide to Operational Technology (OT) Security (https://doi.org/10.6028/NIST.SP.800-82r4.ipd). Submitted in the author's individual capacity. The submission consists of a three-page cover letter and ten line-referenced comments in the NIST comment template. It recommends: (1) adding a sector-specific subsection for oil and natural gas pipelines to Section 2.5, parallel to the freight rail subsection; (2) naming the inputs to the draft's Now/Next/Later patch triage in Sections 4.1.3.3 and 4.2.3.1.3, including CISA Known Exploited Vulnerabilities, FIRST EPSS, CISA SSVC, OT consequence, and exposure, and documenting deferred vulnerabilities; (3) extending zero trust guidance in Sections 5.3.1 and 5.2.2.3 to remote-station communication gateways and adding network monitoring options for constrained remote sites in Section 4.3.1.4; and (4) publishing informative mappings from Revision 4 outcomes to sector regulatory requirements via NIST CPRT or OLIR. One editorial correction is also noted. This is a public comment, not a peer-reviewed publication. Page and line references are to the initial public draft.
Authors
- Friday Ogochukwu Ikwuogu (ORCID: https://orcid.org/0009-0009-2222-1318)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-05
- DOI
- https://doi.org/10.5281/zenodo.23149940
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00