Start with the access paths that touch shared devices, third-party contractors and legacy OT assets, because those areas combine weak traceability with high operational dependence. Then verify who can authenticate, what they can do and whether the access still matches current production needs. That sequence exposes the most likely governance gaps fastest.
Why a manufacturing access review should begin with shared devices, contractors, and legacy OT
Manufacturing access review are most effective when they start with the access paths that combine broad blast radius with weak day-to-day visibility. Shared devices, third-party contractors, and legacy OT systems usually fit that profile, so they often reveal stale accounts, inherited access, and brittle approval chains before the rest of the programme does.
The practical question is not only who has a badge, login, or remote path, but where that access lands in production. A shared panel, kiosk, engineering workstation, or plant-floor interface can hide multiple people behind one session, which makes ownership and accountability harder to prove. That is why IAM and IGA Basics is useful when teams need to separate authentication from authorisation and map the actual access path, not just the named account.
Legacy OT assets deserve early attention because they often remain operational long after the original access model was designed. If an HMI, historian, PLC support account, or engineering jump path still depends on old exceptions, the review should treat that access as production-critical until proven otherwise. For OT-specific context, NIST SP 800-82 Rev 3, OT Security Guide is the clearest reference for understanding why control-system access must be reviewed with availability and safety in mind.
Contractor access should also be early in the queue because it is usually time-bound, business-dependent, and easier to overgrant than internal access. When the access model has drifted away from the work order, the review should ask whether the contractor still needs direct access, whether the path is still monitored, and whether the privilege was meant to be temporary. For programmes that need a tighter account of entitlement drift, Access Reviews and Certification Guide helps structure reviews around remediation rather than rubber-stamping.
What to verify before expanding the review scope
Once the highest-risk paths are identified, the next step is to verify who can authenticate, what they can do, and whether the permission still matches current production needs. In practice, that means checking whether the account is shared or individual, whether authentication is still strong enough for the asset it reaches, and whether the entitlements match the job, vendor role, or maintenance ticket that justified access in the first place.
At this stage, privilege is often the hidden problem. A review can look complete while still leaving excessive standing access in place, especially for engineering, maintenance, and vendor support accounts that were added for speed and never tightened. Teams that need a deeper control model for standing privilege and break-glass access should align the review with Privileged Access Management Guide, because the key decision is whether the access is still justified, not whether it is merely functioning.
Ownership is the other verifier that matters early. If nobody can name the business owner, system owner, or approver for a production access path, then the review has already found a governance gap. That is especially important where production continuity makes teams reluctant to remove anything, because unowned access tends to become permanent by default. When teams need a lifecycle view of access and entitlement drift, NHI Lifecycle Management Guide provides a practical model for provisioning, rotation, and offboarding discipline.
What usually falls out of the first pass
The first pass usually surfaces three patterns: access that is broader than the job, access that no longer matches the production need, and access that cannot be traced cleanly to a current owner. Those are not minor hygiene findings. In a manufacturing environment, they are often the shortest route to unnecessary operational risk because they sit closest to live assets and hardest-to-change workflows.
That is why the review should be sequenced as a triage exercise, not a full inventory exercise. Start with the access paths most likely to combine weak traceability and high dependency, then use the findings to decide where deeper recertification, reengineering, or removal is needed. If the programme spans humans and machine-linked accounts, the same logic applies to service-style access paths as well, and Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is relevant where the access model includes non-human production actors.
Risk and Threat Considerations
Manufacturing access programmes often fail when shared operational access, contractor access, and legacy OT exceptions are treated as normal rather than exceptional. That creates a blend of weak accountability, excessive privilege, and difficult-to-detect misuse, which can turn a routine access issue into a production disruption or a foothold for lateral movement.
Failure mechanism: Shared accounts and legacy exceptions obscure who actually authenticated, contractors retain access beyond the work need, and old OT paths persist because no one wants to disturb production. That combination makes review evidence incomplete and lets stale or overbroad access survive.
Impact: The result can be unauthorized actions on live equipment, unneeded standing privilege, and a review process that misses the very access paths most likely to be abused or accidentally misused.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Covers who can authenticate to manufacturing systems and control paths. |
| AC-6 — Least Privilege | Access reviews should remove excess production privilege and standing access. | |
| AU-2 — Event Logging | Shared devices and legacy OT paths need traceability to support review decisions. | |
| Recommendation — Verify only approved users can authenticate to production access paths. Reduce each account to the minimum access needed for current production work. Log authentication and privileged actions on shared and production-critical systems. | ||
| CIS Controls v8 | CIS-5 — Account Management | Manufacturing access programmes hinge on finding stale, shared, and contractor accounts. |
| Recommendation — Inventory and review accounts that can reach production systems. | ||
Practitioner Guidance
What to prioritise: Review the access paths that can change production state first, especially shared workstations, vendor remote paths, engineering accounts, and legacy OT exceptions. Those are the places where a single approval failure or stale entitlement can create outsized operational exposure.
What to verify: For each high-risk path, confirm the active owner, the current business need, and the actual scope of action the account can perform. If you cannot tie those three elements together quickly, the access should be treated as suspect until the owner proves otherwise.
Practitioner takeaway: In manufacturing, the first review should focus on access that is both hard to trace and hard to replace, because that is where governance gaps become operational risk fastest.
Related resources from NHI Mgmt Group
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?
- How should security teams govern API keys used for generative AI access?
- What should security teams review first in an identity provider programme?