Access
Identity & Privileged Access
Ensure every action in OT is attributable to a person and privileges are minimal and time-bound.
Defensive guide
Why should I care?
Credential abuse features repeatedly in documented OT intrusions.
How to implement it
- Named accounts for engineers and administrators; role accounts for operators only where the console model requires it
- Separate OT identity from enterprise identity where the operating model allows
- Tiered administration and privileged access management for OT servers
What good looks like
- No shared administrative credentials
- MFA on all human remote access
- Joiner/mover/leaver process covers OT
Common failure modes
- One 'engineer' account shared by a team
- Enterprise domain admins implicitly administering OT
How to verify it
- Review privileged group membership
- Test that a departed contractor's access is gone