Skip to main content
Compliance

Coalition Urges CISA to Mandate OT Security Standards for Agencies

Control panel and industrial computers in a neutral, institutional environment.

"One, it does make sure that the government is taking its own medicine," said Michael Garcia, policy director of the Operational Technology Cybersecurity Coalition.

What the Operational Technology Cybersecurity Coalition wants

A coalition of cyber firms and critical infrastructure operators this week set out a clear recommendation: the Cybersecurity and Infrastructure Security Agency (CISA) should issue a binding operational directive (BOD) specifically focused on operational technology (OT) across federal civilian executive branch agencies (FCEBs). The group, calling itself the Operational Technology Cybersecurity Coalition, argues the directive should assign clear responsibility for OT cybersecurity inside each agency, draw on existing federal guidance, and set minimum cybersecurity practices for OT deployments.

Why a binding operational directive, now

The coalition framed its recommendation against a backdrop of recent, high-impact incidents in the water sector and a finding from the Government Accountability Office. GAO published a report last month concluding that most FCEBs have not implemented Office of Management and Budget requirements issued in 2023 for networked Internet of Things and OT devices. The paper cites CISA’s lack of a “holistic view of the assets managed by the FCEB” and warns that inconsistent OT policies and incomplete agency visibility raise the risk that an attack on federal OT could have severe consequences.

Core requirements the coalition recommends

The coalition’s paper lays out several concrete items it believes a CISA BOD should include:

  • Formal designation of an officer in charge of cybersecurity for OT at each agency, to bridge what the paper describes as a "government gray zone" between chief information officers and facilities managers.
  • An examination of past National Security Agency OT guidelines to determine whether and how they should apply to federal civilian agencies.
  • Alignment of any BOD requirements with CISA’s cybersecurity performance goals that the agency first issued in 2022.
  • Minimum cybersecurity practices for OT devices, informed by existing federal guidance and by the coalition’s assessment of current agency shortfalls.

Why the coalition says a BOD could matter to the private sector

Michael Garcia emphasized a second purpose for a federal BOD beyond improving agency posture. “Second, it sends a very strong signal to the private sector that, ‘This is what we think is important: As an OT partner, owner or operator or critical infrastructure owner or operator, [this is what] you should ask other providers to do,’” he said. The coalition frames the federal government acting as an exemplar: if agencies apply consistent OT security rules internally, private owners and operators will have clearer expectations for vendors and partners.

Consequences for federal property managers and agency roles

The paper notes scale: the General Services Administration owns and leases roughly 8,000 properties, many of which include OT systems for power, heating, ventilation and air conditioning. Some OT assets the coalition describes as “trivial,” but it warns that connected programmable logic controllers and other devices create exposure that CISA currently cannot view comprehensively. Given that OT responsibilities often sit between CIOs and facilities managers, the coalition insists the BOD should make agency accountability explicit.

The coalition does not argue a BOD would necessarily have prevented the summer attacks on water utilities. It also acknowledges CISA has already incorporated OT security requirements into prior directives — listing BODs 23-01, 23-02, and 26-04 — and calls this new directive “an encompassing BOD solely focused on OT security,” especially as it expects artificial intelligence to lower the technical barriers for sophisticated cyber operations. As the paper puts it, “as AI reduces the technical barriers to sophisticated cyber operations, enabling adversaries to identify weaknesses, accelerate reconnaissance, and move laterally through poorly segmented operational environments with greater speed and scale, it is time for an encompassing BOD solely focused on OT security.”

What this means for technologists, policymakers, and critical-infrastructure owners

  • Technologists and security teams: Expect a push for formalized ownership of OT security inside agencies and for alignment with CISA’s 2022 performance goals; the coalition highlights a need for better asset visibility and segmentation to slow lateral movement.
  • Policymakers and regulators: GAO’s recent finding that most FCEBs have not enacted 2023 OMB requirements creates pressure to translate existing guidance into enforceable obligations; the coalition wants CISA to incorporate past NSA guidance and to codify responsibilities through a BOD.
  • Critical-infrastructure owners and procurement leaders: The coalition intends the federal BOD to serve as a benchmark for private-sector expectations, signaling what owners and operators should require from vendors and partners when OT is involved.

CISA did not respond to a request for comment on Monday before the coalition published its paper. Garcia said discussions with CISA give him reason to believe the agency “increasingly… understand[s] that there might be a need” for an OT-specific BOD. The next concrete steps are left to CISA and to how agencies translate a directive — if issued — into designated roles, NSA-aligned controls, and minimum practices across thousands of federal properties.

Source: https://cyberscoop.com/cisa-ot-cybersecurity-directive/