Compliance

Comply with the DoW Zero Trust for OT Activities and Outcomes

The Nozomi Networks platform provides the OT-native visibility, behavior analytics and threat detection that Zero Trust for OT requires, while integrating tightly with ICAM, PAM, NAC, EDR/XDR and SIEM/SOAR system for a total solution.

What Is Zero Trust for OT?

The U.S. Department of War (DoW) has published guidance for the adoption of zero trust (ZT) cybersecurity principles for operational technology (OT) systems. The ZT for OT guidance adapts ZT principles to industrial environments and organizes requirements into activities and outcomes across seven pillars: User, Device, Applications & Workload, Data, Network, Visibility & Analytics and Automation & Orchestration. It specifies 105 activities and capability outcomes to implement in OT environments, including:

  • 84 Target Activities: The minimum set of ZT capability outcomes and activities intended to collectively prevent lateral movement in the environment
  • 21 Advanced Activities: Additional long-term goals that provide adaptive responses and comprehensive ZT functionality but will not be held to the Target timeline.

Independently, the Nozomi Networks platform addresses 33 of the 84 Target Activities and eight of the 21 Advanced Activities, or 41 of the total 105 activities across six of the seven pillars.  

Why Zero Trust for OT Compliance Matters for DoW Components

Complying with the ZT for OT requirements is not a checkbox exercise; it's a foundational shift in how DoW Components protect their OT environments from nation-state actors, ransomware, supply chain attacks and insider threats. OT systems differ significantly from IT. They include legacy equipment, proprietary protocols, safety critical functions and environments where downtime is unacceptable.

As the ZT for OT guidance explains, applying traditional IT controls blindly can disrupt operations and endanger physical processes. It provides an OT-specific roadmap that ensures:

Operational Continuity

Explicitly accounts for safety and reliability as primary constraints in design and deployment.

Risk Reduction

Mitigates threats that could lead to outages, environmental hazard or compromised mission execution.

Interoperability

Ensures safe integration with enterprise IT security tools to improve readiness and reduce blind spots.

Future-proofing

Provides a scalable architecture that reduces technical debt and prevents fragmentation.

How Nozomi Supports the Zero Trust for OT Pillars

Nozomi Networks aligns well with the ZT for OT guidance because our platform was built specifically for operational technology, not retrofitted from an enterprise IT security solution. This gives it several advantages:

The OT Visibility Choice of DIB SIs, Technology Partners and Distributors

The Nozomi Networks platform is a key component of solutions from leading defense industrial base systems integrators tailored to meet the requirements within the distinct environments of various military departments and agencies.

OT Zero Trust Alliance

Nozomi is a founding member of the Operational Technology Zero Trust Alliance (OTZTA), a group of cybersecurity solution providers seeking to accelerate the deployment of comprehensive ZT solutions for OT networks worldwide. Our platform was part of the Alliance’s Project BlastWave pilot program at a water treatment facility on Spangdahlem Air Base, Germany. The pilot was funded by the DoD’s Zero-Trust PMO and became fully operational in 2023.

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.