Glossary
/
Standards & Regulation

NIST

Also known as:
NIST Cybersecurity Framework · CSF 2.0 · NIST SP 800-82 · NIST IR 8576 · Transit CSF Community Profile

NIST, the US National Institute of Standards and Technology, publishes the cybersecurity frameworks and guidelines that US transit and rail operators most often build their programs on: the Cybersecurity Framework (CSF), the OT security guide SP 800-82 and the Transit CSF Community Profile (NIST IR 8576) that applies the CSF to transit agencies.

How it works

The NIST Cybersecurity Framework, now in version 2.0, organises security outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is technology-neutral and used to structure programs, assess maturity and communicate with executives and regulators. Community profiles tailor it to a sector. For transit, NIST's National Cybersecurity Center of Excellence (NCCoE) developed the Transit Cybersecurity Framework Community Profile, published as NIST IR 8576, together with transit agencies, industry and federal partners. It is a voluntary, risk-based baseline that maps transit mission needs, including operational technology and safety, onto CSF 2.0 outcomes and existing sector guidance, so agencies can prioritise and tailor their programs.

NIST SP 800-82, Guide to Operational Technology Security, is the detailed companion for OT environments. Its third revision broadens the scope from industrial control systems to all OT, covers architecture, network segmentation, monitoring and incident response, and provides an OT-tailored overlay of the SP 800-53 security controls that federal and many state-funded agencies must follow.

Why it matters for security

The TSA security directives for rail and the guidance of the Federal Transit Administration draw on NIST vocabulary and expect operators to demonstrate a program consistent with the CSF. Being able to map OT assets, detections and evidence to CSF functions and SP 800-82 recommendations is therefore a practical requirement for US rail operators, not only a best practice.

Because NIST publications are freely available and widely understood outside the rail sector, they also serve as the common ground between rail OT teams and enterprise security and audit teams. Rail-specific standards such as IEC 62443 and IEC 63452 complement rather than replace them.

Related solution

Aligning rail OT security with NIST CSF and SP 800-53 / 800-82

Mapping OT visibility, detection and evidence to the CSF functions and SP 800-82 recommendations.

See the solution →

Related terms

Ready to protect your rail?

Our specialists will help you back on track

Talk with an Expert