CISA Urges Critical Infrastructure Operators to Implement Zero Trust in OT Networks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive to operators of operational technology (OT) networks, urging them to adopt zero trust principles. This guidance is aimed at enhancing the security of critical infrastructure sectors such as power, water, transportation, building automation, and weapons-support systems. CISA, in collaboration with the Department of War, the Department of Energy, the FBI, and the Department of State, has released a 28-page document titled 'Adapting Zero Trust Principles to Operational Technology.' The document advises OT operators to assume that adversaries may already be present within their networks. It emphasizes the need for validating every access request based on identity, context, and risk, rather than relying on network location. This approach is intended to mitigate potential threats and enhance the resilience of critical infrastructure systems.