Join our Newsletter — 33% off our NHI Course

Identity Governance Across IT And OT

Identity governance across IT and OT is the coordinated control of who can access business systems and industrial systems, under what conditions, and for how long. It helps close visibility gaps between enterprise networks and plant-floor environments, supporting stronger accountability, cleaner reviews, and tighter control over privileged and third-party access.

Expanded Definition

identity governance across IT and OT extends identity lifecycle control into environments where business applications, remote support, engineering workstations, historians, PLC-adjacent tools, and cloud-connected control services must all be governed with different risk tolerances. In practice, it is not just access administration; it is the discipline of approving, reviewing, time-limiting, and revoking human and non-human access across domains that were historically managed separately.

Definitions vary across vendors, especially when OT access is bundled into broader PAM, IGA, or zero trust programs, but the core requirement is consistent: access decisions must reflect operational safety, production continuity, and security accountability. NIST guidance such as the NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls both reinforce that identity and access controls must be traceable, reviewed, and proportionate to risk, even when implemented across mixed environments.

NHI Management Group research shows how weak identity visibility compounds this problem: only 5.7% of organisations have full visibility into service accounts, and 92% expose NHIs to third parties in some form, which matters equally in OT-adjacent supply chains and remote operations. The most common misapplication is treating OT access as a one-time network exception, which occurs when temporary vendor or engineer access is granted without a governed expiry, review, or revocation path.

Examples and Use Cases

Implementing identity governance across IT and OT rigorously often introduces approval latency and tighter operational change control, requiring organisations to weigh production uptime against the security value of least privilege and time-bound access.

  • A plant operator is granted time-limited access to a cloud dashboard and an engineering workstation, with access automatically revoked after the maintenance window closes.
  • A third-party integrator receives segmented access to an OT remote support portal, with approvals logged and reviewed under a formal access recertification cycle.
  • A service account used by a historian or telemetry pipeline is inventoried, scoped, and rotated under the lifecycle practices described in the Ultimate Guide to NHIs.
  • A security team maps privileged access in a mixed environment to the principles in NIST Cybersecurity Framework 2.0, then reconciles active entitlements against plant-floor vendor contracts.
  • An incident review uses the 52 NHI Breaches Analysis to identify whether a forgotten support credential or over-broad exception enabled lateral movement from IT into OT.

These use cases show why identity governance in mixed environments must be designed around workflows, not just accounts. The point is not to restrict operations, but to ensure that every access path has an owner, a purpose, and a revocation condition.

Why It Matters in NHI Security

When IT and OT identities are governed separately, organisations lose the ability to answer basic questions about who can reach critical systems, which credentials still work, and whether third-party access is still justified. That gap is especially dangerous for non-human identities, where standing credentials and service accounts can persist long after a project ends or a vendor relationship changes.

NHI Management Group data shows why this matters operationally: 71% of NHIs are not rotated within recommended time frames, 97% carry excessive privileges, and 79% of organisations have experienced secrets leaks. Those same patterns become more consequential in OT because an over-privileged credential can affect availability, safety, and production continuity, not just data exposure. The Regulatory and Audit Perspectives section of the Ultimate Guide to NHIs is a useful reference when governance evidence must stand up to scrutiny.

Identity governance also supports cleaner incident response. Once an access anomaly is detected, the team needs a reliable way to locate the account, understand the approval trail, and remove access without destabilising operations. Organisations typically encounter this consequence only after a vendor connection, maintenance exception, or compromised service account is abused, at which point identity governance across IT and OT becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 Covers lifecycle and governance gaps that arise when non-human access spans IT and OT.
NIST CSF 2.0 PR.AA Identity and access management functions map directly to governed access across mixed environments.
NIST SP 800-63 Provides identity assurance concepts that inform trust decisions for human access in sensitive workflows.
NIST Zero Trust (SP 800-207) AC-6 Least privilege and continuous verification are essential when OT access crosses trust boundaries.
NIST AI RMF GOVERN Governance principles apply to automated access decisions and identity workflows in AI-assisted environments.

Inventory IT and OT NHIs, assign owners, and enforce expiry, review, and revocation for every credential.