Why: Access restrictions for change start with someone deciding who may change what and writing it down — and the practice's review process makes exactly that decision for the OT estate, then keeps the record of who changed what under whose approval.
What this does not claim: Deciding and recording approvers is not enforcing physical and logical access restrictions: engineering-workstation lockdown, management-network isolation, and panel access hardware are implementation work outside this practice. Contributes the governance the requirement's enforcement relies on rather than the restrictions themselves.
- Name the roles authorized to approve and to perform OT changes
- Keep the change record as the audit trail attributing changes to authorized individuals
- The documented approver and performer roles
- Change records attributing changes to authorized individuals
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06