Why: Naming who must approve safety-relevant and security-relevant changes — and bringing vendor changes inside that gate — is the definition-and-approval part of restricting who may change OT systems.
What this does not claim: Defining who may approve a change is not enforcing who can make one: the requirement also demands enforced physical and logical restrictions — permissions on engineering workstations, locked panels, controlled controller access — which a review process does not itself configure. The relationship should be evaluated within the organization's defined system boundary, where much OT may sit outside scope.
- Document who may approve and who may perform each class of OT change
- Route vendor and remote changes through the same approval gate as internal ones
- The written approver and performer definitions per change class
- Change records demonstrating the gate applied to vendor work
Review status: Pending OT SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06