Legal Cyber Academy
Standard or guidanceFreeCurrent

Digital Forensics and Incident Response (DFIR) Framework for Operational Technology (OT)

Eran Salfati, Michael Pease · National Institute of Standards and Technology · NISTIR 8428, 22 June 2022 · 2022

Identifier: NISTIR 8428

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.

Who it is for, and when

Read it before an engagement involving ICS, SCADA or plant networks, where you cannot take a device offline and the safety case constrains every forensic decision. It is the right citation for explaining to a client or court why standard IT acquisition steps were not available.

What it does not cover

It is a framework rather than a protocol-level manual: no PLC memory acquisition procedures, no vendor-specific controller instructions, and no treatment of Modbus/DNP3/S7 artefact parsing. It also does not cover safety-instrumented-system engineering or regulatory reporting duties.

Go to the source

Open at nist.gov (opens in a new tab)

https://www.nist.gov/publications/digital-forensics-and-incident-response-dfir-framework-operational-technology-ot

Details

Type
Standard or guidance
Written for
AdvancedAdvanced
Author
Eran Salfati, Michael Pease
Publisher
National Institute of Standards and Technology
Version verified
NISTIR 8428, 22 June 2022
Year
2022
Identifier
NISTIR 8428
Topics
incident-response, iot, network, evidence-handling, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.

  • The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.

  • A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.

  • A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.

  • Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.