Keep essential operations within authority.
High-consequence changes and continued operations when trust is uncertain.
Discuss a workflow ↗
Operational access may be necessary while authority for a particular change remains unresolved. The workflow below illustrates how organizational requirements can vary by result and operating condition.
Evaluate authority before operational changes take effect.
The workflow is illustrative. Each organization defines its own authority, evidence requirements, exceptions, and operating conditions.
Operational-technology configuration change before production execution
A proposed configuration change may affect safety, reliability, protection settings, remote operation, authentication, logging, emergency controls, or physical process behavior.
Authority Control point. After the proposed change, target system, operating purpose, safety implications, and required evidence are assembled, but before the configuration is applied to the operational environment.
Workflow references: NERC CIP-010 and NIST guidance on operational technology security. Applicable requirements and revisions must be established for the selected environment.
Sources and evidence →Illustrative workflow adapted from public regulatory, standards, acquisition, and operational sources. It identifies a recognizable operating sequence and a possible Authority Control point; compliance obligations and sector requirements are determined separately.
Exceptions follow the organization’s review process. A result requiring additional authority, evidence, or review may be deferred and reevaluated when the requirements are resolved. The determinations remain Permit, Defer, and Block.