OT security

Make vendor remote access a controlled work session

Document the purpose, approved route, time window and closeout evidence for a maintenance connection.

Authorize a task, not an indefinite connection

Describe the machine, requested action, expected duration and operational owner. Separate observation from changes to logic or configuration. Confirm whether production must stop and which backup is required. An approved remote-access route does not make every action within the session automatically approved.

Check identity and the permitted route

Use the organization’s approved access method and individually attributable identities. Confirm authentication, the target scope and session expiry before the window begins. Keep access to the minimum systems needed for the job. Have the local owner available to confirm the machine state and terminate the session if necessary.

Preserve operational evidence

Record the start time, approved work reference and configuration baseline. Capture changes through the organization’s normal process and record any deviation. If the session fails halfway through, the local team should know the current state and the recovery action. Do not depend on the vendor’s memory for the handover.

Close access and verify the result

At completion, validate the agreed operational checks, store the changed project where appropriate and close temporary access. Review whether any new accounts or connectivity remain. Keep the work record linked to the device inventory and backup reference. A closed ticket should explain both what changed and how normal operation was confirmed.

Put it into practice

Use the related tool to check your assumptions, then bring the results to your project discussion.

Further reference

NIST SP 800-82 Rev. 3

THE NEXT STEP

From calculation to implementation.

Let’s look at your machine, your data flow or your production goal together.

Talk to ASP Dijital ↗