Security1 publisher2 min readPublished
The new Foundations for OT Cybersecurity guidance treats an asset inventory plus a taxonomy as the precondition for everything else in a defensible architecture. It sets no deadline and names no auditor.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
CISA's taxonomy asks for a field no discovery scan produces: a classification of each asset by function and by criticality [4]. The guidance points that classification at three consumers, in this order: risk identification, vulnerability management, incident response [4]. The third one is where responders live. During an incident you do not need a list of the boxes on the affected segment, you need to know which of them carries the process and which is a spare HMI. The guidance puts that judgement upstream, as a data model built in advance rather than a phone call made at 3am.
The threat section is worth reading as a scoping argument rather than a warning. Five ways cyber actors cause OT incidents are enumerated: outdated software or firmware, weak authentication, insufficient segmentation allowing IT-to-OT and OT-to-OT lateral movement, insecure OT protocols that permit interception and malicious command injection, and insecure remote access points used for lateral movement or command and control [11]. Three of those five are architectural rather than per-device [12]. You cannot size a segmentation project or enumerate remote access paths against an inventory you do not have, and the other two, patch state and authentication, are per-asset questions that only exist once the asset is on the list.
On the compliance question, the text is narrower than the framing around it. Creating an asset inventory is already one of CISA's Cybersecurity Performance Goals [10], and the definition of a modern defensible architecture includes compliance with regulatory requirements alongside reliability, continuity and safety [13]. Beyond that, the document as published sets no deadline, names no enforcement body, and does not assert that any of it is mandatory [15]. What it does fix is scope: six steps to build the inventory and taxonomy, from defining objectives through asset life cycle management [5][6], then five sustaining activities including maintenance and reliability, performance monitoring and reporting, and training [7].
The conceptual taxonomies came out of working sessions with energy and water and wastewater organisations, and CISA labels them non-authoritative [8][9]. They are still the only published worked examples attached to the guidance. An operator asked to show its classification scheme will reach for Appendix C before it invents one.
The cost sits in step six. Life cycle management of an OT inventory is a staffing line and a process owner [5], not a scan, and it lands on the utilities whose device list is currently a spreadsheet maintained by the maintenance team.
Ranked by verification strength, evidence, and original report placement.
CISA published guidance titled "Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators".
The guidance states that when building a modern defensible architecture it is essential for OT owners and operators across all critical infrastructure sectors to create an OT asset inventory supplemented by an OT taxonomy.
CISA defines an asset inventory as an organized, regularly updated list of an organization's systems, hardware, and software.
CISA defines an OT taxonomy as a categorization system that organizes and prioritizes OT assets by classifying them based on function and criticality, and says it aids risk identification, vulnerability management, and incident response.
The guidance outlines a process comprising defining scope and objectives for the inventory, identifying assets, collecting attributes, creating a taxonomy, managing data, and implementing asset life cycle management.
For maintaining, improving and using the inventory, the guidance lists OT cybersecurity and risk management, maintenance and reliability, performance monitoring and reporting, training and awareness, and continuous improvement.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary, single-sourced, untested
Everything here traces back to a single document: the issuing agency itself. That makes it a strong source for what CISA recommends, though it offers nothing on whether the recommendation actually works. Definitions, the six build steps, the sustainment list and the sector appendices are all quotable from the guidance itself. The causal premise beneath it, that an inventory and a taxonomy reduce the risk of an OT incident, is asserted as foundational with no measurement offered and nobody else in our coverage to check it.
Nothing measurable yet
Two events are visible: the guidance went out, and CISA convened energy and water organizations to draft the sample taxonomies. Neither tells us how many owners and operators keep an inventory today, how many will follow this six-step process, or what tooling they use to do it. With no operator disclosure anywhere in the reporting, any adoption figure would be invented.
Restrained document, unproven premise
CISA refuses to make its own sector appendices authoritative, which is more modest than agency guidance usually is. Pulling the other way, "essential" and "foundational" carry the weight of the whole document with no efficacy data behind them, and with no date and no enforcer attached, the strongest word in the text is still advice. The gap is small, and it is a framing gap.
Author owns the program it cites
CISA wrote both this guidance and the Cybersecurity Performance Goals it invokes as justification, so the document reinforces a program its author owns and measures. The co-seals from the EPA, NSA, FBI and the allied cyber agencies extend jurisdictional reach without adding independence; every signatory's institutional interest points the same direction, toward operators doing more security work. No vendor is named and nothing is being sold, which keeps this in the middle of the range rather than the top.
Firm on text, soft on effect
What was published, by whom, and in what words is beyond dispute. The two counts we lean on -- six build steps, and three of five exploitation paths being architectural -- come from reading the document closely rather than from CISA stating them. The softest point is the finding that nothing here is mandatory or dated: it rests on the framing sections as published, and the appendices those sections point to are not in front of us.
product
The UK plant that went dark for four days was too small to have to tell anyone1 publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 publishers
security
Public exploit code for CVE-2026-62911 is outpacing patching on 21,899 exposed Exchange servers3 publishers
product
After Arup, a face on a video call is not a credential1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026