Industry Coalition Presses US Agency to Set Mandatory Security Rules for Building and Facility Technology
The Operational Technology Cybersecurity Coalition (OTCC) has urged the US Cybersecurity and Infrastructure Security Agency (CISA) to set mandatory security requirements for operational technology (OT) in federal civilian agencies. OT includes the systems that run heating and cooling, power, access control, water and building automation. The coalition says agencies use it in more than 8000 General Services Administration-managed facilities, such as laboratories, hospitals and ports of entry. Its report, published on October 6, argues that no directive sets minimum practices for federal OT and that CISA lacks visibility into the risks.
The call follows a Government Accountability Office report from September 30. It found that only seven of 22 civilian agencies reviewed had fully met requirements to inventory their networked OT and Internet of Things devices. Those inventories were due by September 2024. The proposed directive would require a senior official or office to be responsible for OT security, bring OT risk into enterprise risk management, and set baselines for asset inventory, network segmentation, remote access, configuration management, incident preparedness and verified recovery.
Not everyone thinks the proposal goes far enough. John Gallagher of Viakoo said remediation is missing, warning that without automated patch and configuration management, agencies would face backlogs that overwhelm operational teams. The OTCC's priority controls include changing default passwords, multifactor authentication, segmentation and backups, but the report does not call for patching or firmware updates. Gallagher said attackers routinely get in through unmanaged default passwords and obsolete firmware.