The Operational Technology Cybersecurity Coalition (OTCC) called on the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue a binding operational directive establishing mandatory, enforceable cybersecurity requirements for operational technology (OT) across Federal Civilian Executive Branch (FCEB) agencies.

OTCC said existing directives address some OT security requirements but do not establish consistent minimum practices across federal agencies, limiting CISA’s visibility into their security posture.

CISA has folded some OT requirements into earlier directives, but no BOD yet sets consistent minimum security practices for federal OT.

The OT Cyber Coalition argues that CISA should issue a binding operational directive focused solely on operational technology security.

The Coalition recommends that CISA establish an OT BOD requiring Federal Civilian Executive Branch entities with OT systems and assets to achieve specific cybersecurity goals.