Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Ot Asset Inventory Guidance topic

No spam. Unsubscribe anytime.

CISA publishes OT asset-inventory guidance to help operators prioritize cybersecurity and resilience

The Cybersecurity and Infrastructure Security Agency (CISA) · December 8, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Cybersecurity and Infrastructure Security Agency released "Foundations for Operational Technology Cybersecurity: Asset Inventory Guidance" to help owners and operators build practical OT inventories. CISA and partners outline five steps — scope, discovery, taxonomy, stewardship and lifecycle — and stress starting with a pilot.

The Cybersecurity and Infrastructure Security Agency (CISA) on a webinar introduced new guidance, "Foundations for Operational Technology Cybersecurity: Asset Inventory Guidance," intended to help critical-infrastructure owners and operators create and maintain actionable operational-technology (OT) asset inventories that support detection, response and long-term resilience.

CISA’s Joint Cyber Defense Collaborative (JCDC) framed the guidance as a public-private effort. "Knowing what assets you have ... is a fundamental step to protecting these environments," said Clayton Romans, Associate Director of JCDC. He said the guidance was developed with federal partners including the Department of Energy, the Environmental Protection Agency, the National Security Agency and the FBI, as well as international and private-sector contributors to ensure applicability across operator sizes and sectors.

Why it matters: Presenters said a current inventory underpins vulnerability prioritization, detection of unauthorized devices, proper network segmentation and faster incident response. "A robust OT asset inventory can improve operational continuity," Romans said, noting smaller operators often face resource constraints and that guidance was designed to be actionable for those organizations.

What the guidance recommends: Derek Hittie of CISA’s JCDC outlined five steps the guidance details — (1) define scope and objectives and establish governance; (2) discover assets via logical surveys and physical walkdowns; (3) build a taxonomy by function and criticality and map zones and conduits; (4) centralize and protect the inventory as a stewarded repository; and (5) embed inventory updates in asset lifecycle management so the record stays current. Hittie emphasized starting with a pilot and scaling iteratively.

Partnership and implementation: The guidance draws on eight working sessions with 12 industry stakeholder organizations and incorporates examples and visualizations produced in partnership with the Department of Energy’s Energy Threat Analysis Center and the National Renewable Energy Laboratory. The document is technology neutral, the presenters said, and applies whether an operator uses advanced passive-discovery platforms or begins with paper records and interviews.

Context from exercises and advisories: Michael Toecker of DOE CESER described how inventories accelerate incident response in real-world exercises such as DOE’s Liberty Eclipse and referenced recent CISA advisories (for example, emergency directives addressing vulnerable remote-access devices) as examples of why inventory visibility matters.

Next steps: CISA invited feedback from operators on the guidance and encouraged adopting a phased approach: define a pragmatic scope, gather a credible baseline using surveys and walkdowns, validate a taxonomy with stakeholders, and institutionalize processes that keep the repository current.

The webinar closed with a call to action to begin with small, achievable pilots and iteratively expand inventories to strengthen OT cybersecurity, safety and operational continuity.