Why: Limiting what each identity may do on production systems — operator versus engineer versus vendor — is authorization enforcement on the assets the practice covers.
What this does not claim: Many OT components cannot enforce per-user authorization at all: legacy controllers with one shared password, HMIs without role support. Where the device cannot enforce, enforcement moves to compensating layers — physical access, network position, supervised sessions — and those must be documented as the enforcement mechanism rather than assumed. Enterprise-side enforcement is outside the practice's scope.
- Use role separation (view, operate, engineer) where OT platforms support it
- Document compensating enforcement for devices that cannot distinguish users
- Role configuration exports from OT platforms that support them
- Compensating-measure documentation for legacy components
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06