Pentagon zero trust guidance for IoT and OT coming in September

Originally published Pentagon zero trust guidance for IoT and OT coming in September on by https://defensescoop.com/2025/06/06/dod-zero-trust-guidance-iot-ot-operational-technology/ at DefenseScoop


Pentagon zero trust guidance for IoT and OT coming in September | DefenseScoop

Skip to main content

Advertisement

Advertisement

The new IoT and OT guidance are expected sometime in September, DOD’s zero-trust sherpa Randy Resnick said.


Listen to this article

0:00

Learn more.

This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.

Randy Resnick speaks at the 2023 Zero Trust Summit. (FedScoop photo)

As the Department of Defense races to shore up its cyber defenses with zero-trust security architectures by 2027, it will issue key guidance for how industry partners should enlist the security framework for Internet of Things and operational technology systems by the end of the fiscal year.

Randy Resnick, senior advisor of the Zero Trust Portfolio Management Office in the DOD, said Wednesday that the department is developing those guidance documents as expansions and variations of the 91 baseline “target-level” zero-trust activities it has already released for industry models to meet.

The new IoT and OT guidance are expected sometime in September, Resnick said at the GDIT Emerge: Edge Forward event, produced by FedScoop.

DOD uses what it refers to as “fan charts,” Resnick said, to lay out the various security controls vendors must build into their zero-trust solutions to meet the baseline for military services and defense agencies. In total, there are 152 controls — 91 at the target level and 61 at the advanced level, which “offer the highest level of protection,” the department said in guidance from 2024.

Advertisement

Resnick said that the fan chart for operational technology is “different” than that of the 91 activities needed to meet target-level compliance, though “there’s a lot of overlap.”

“The number of activities to hit target-level OT is different,” he explained.

For securing IoT systems with zero trust, Resnick said it’s essentially the same 91 target-level activities, plus two additional controls.

Explaining why it was necessary to build out additional overlays for OT and IoT systems, he said the way you respond to an incident is quite different, especially for operational technology.

With OT, Resnick said, “You want to have it fail open, or you want to have it fail in a way that doesn’t disturb or cause more mischief or harm than you want.”

Advertisement

Once those pieces of guidance arrive in September, just one more such directive remains for the DOD to issue: zero-trust overlays for weapons systems, said Resnick.

With the 2027 deadline looming, Resnick said he feels like “we’re in good shape,” especially after his office was spared in recent DOGE cuts, he said.

He explained that the department continues to experience successful pilots with industry that meet target or advanced levels of zero trust. And with more of those solutions taking shape, it’s getting closer to the point where DOD organizations will be able to “just buy it, implement it, install it, and pretty much get there before the end of [2027],” Resnick said.

The hard part will then be installing the solutions, he explained.

“We’re talking professional services and a whole army of people that are probably going to be required,” Resnick said. “We’re talking about full swap-outs and new infrastructures. This is not a small problem … I certainly hope that industry is thinking like that.”

Advertisement

Billy Mitchell

Written by Billy Mitchell

Billy Mitchell is Senior Vice President and Executive Editor of Scoop News Group’s editorial brands.

He oversees operations, strategy and growth of SNG’s award-winning tech publications, FedScoop, StateScoop, CyberScoop, EdScoop and DefenseScoop.

Prior to joining Scoop News Group in early 2014, Billy embedded himself in Washington, DC’s tech startup scene for a year as a tech reporter at InTheCapital, now known as DC Inno.

After earning his degree at Virginia Tech and winning the school’s Excellence in Print Journalism award, Billy received his master’s degree from New York University in magazine writing while interning at publications like Rolling Stone.

Latest Podcasts

Advertisement

Originally published DefenseScoop

Related Posts

COLUMN: Leading with Character: Honoring Commitments

Lately, my blogs have addressed coping strategies for navigating turbulent times. We usually can’t change what’s happening around us, but we can and should control our own responses and actions.
The post COLUMN: Leading with Character: Honoring Commitments appeared first on HSToday.

AFCEA Coffee & Community

Originally published AFCEA Coffee & Community on June 6, 2025 15:42 by http://www.govevents.com/details/87225/afcea-coffee-and-community/

About Us
woman wearing glasses

To assist commercially facing small and startup technology companies, and help determine if there is value in engaging with defense, intelligence community.

Let’s Socialize

Popular Post