Why: The practice builds and exercises the response-and-recovery capability for the operational side of the house — named roles, containment options pre-agreed with process owners so a response action does not trip a process or create a safety hazard, and identified recovery sources for controller logic and configuration. That is the requirement's preparation-through-recovery arc, applied to the plant.
What this does not claim: The practice is deliberately OT-scoped, while this requirement covers the organization's entire in-scope environment — the enterprise incident-handling capability has to exist independently of anything this practice does. It applies at all only where OT systems fall within the CUI boundary, which is the exception rather than the rule.
- Write the OT response plan with safe containment options agreed with the process owner in advance
- Identify and test recovery sources — controller logic and configuration backups — for critical lines
- Establish joint IT/OT response roles so the two sides act on one plan under pressure
- The OT incident response plan with named roles and reachable contacts
- Restore-test records for controller configurations
- After-action records from exercises and real events
Where this holds: Holds only where OT equipment or its data sits inside the CUI boundary; the organization-wide capability the requirement demands is separate work.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06