Why: A jump host in a controlled zone that all vendor and remote OT sessions must traverse is a managed access control point by definition — the practice's core architecture is the routing this requirement names.
What this does not claim: Covers the OT pathways only; the enterprise's own remote entry points need the same consolidation under separate work. The relationship also weakens wherever legacy links — modems, cellular gateways, vendor tunnels added at commissioning — still bypass the broker, which is precisely the population hardest to find and the reason the practice's pathway inventory must precede any coverage claim.
- Establish the jump host in a DMZ or controlled zone and block remote paths that do not traverse it
- Hunt and remove the bypass links: standing tunnels, modems, and cellular connections outside the broker
- Firewall rules forcing remote OT access through the broker
- The pathway inventory showing bypass links found and closed
Where this holds: Holds only where OT systems fall within the organization's CUI boundary.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06