Operationalizing Deception Technology in ICS/OT: A Control Mapping Framework for Critical Infrastructure Cybersecurity

Main Article Content

Daniel Ward

Abstract

Deception technologies, including honeypots, decoy devices, honeytokens, and simulated industrial assets, are increasingly relevant to industrial control systems and operational technology (ICS/OT) security because they can generate high-confidence alerts when adversaries interact with assets that legitimate operators should not use. Prior dissertation research on deception technology adoption in U.S. manufacturing and critical infrastructure identified persistent barriers, including compatibility concerns, limited resources, inadequate professional knowledge, infrastructure constraints, and the absence of policy structures that enable practitioners to make deception technology actionable. This paper extends that work without collecting new human-subject data. Using design science and qualitative document analysis, the study maps ICS/OT deception technology use cases to recognized cybersecurity frameworks and control objectives, including the NIST Cybersecurity Framework 2.0, NIST SP 800-82 Revision 3, NIST SP 800-53 Revision 5, IEC 62443-2-1:2024 security program requirements, CISA Cross-Sector Cybersecurity Performance Goals, and MITRE ATT&CK for ICS. The result is the Deception Technology Integration Control Framework (DTICF). This practitioner-oriented artefact translates deception technology from a novel security tool into an auditable set of governance, architecture, monitoring, response, and continuous improvement practices. The framework provides a control crosswalk, an implementation model, a maturity model, and a set of metrics that organisations can use to evaluate deception readiness and plan low-risk deployment in safety-sensitive OT environments.

Downloads

Download data is not yet available.

Article Details

Section

Articles

How to Cite

[1]
Daniel Ward, “Operationalizing Deception Technology in ICS/OT: A Control Mapping Framework for Critical Infrastructure Cybersecurity”, IJSCE, vol. 16, no. 3, pp. 1–9, Jul. 2026, doi: 10.35940/ijsce.C3723.16030726.

References

D. Ward, "Enhancing security: A comprehensive study on deception technology integration in manufacturing and critical infrastructure," Doctoral dissertation, University of the Cumberlands, 2025. [Online]. Available: https://www.proquest.com/openview/ebf38e1aa599115548a9f7486917e669/1. Accessed: Jun. 8, 2026.

K. Stouffer, M. Pease, C. Y. Tang, T. Zimmerman, V. Pillitteri, S. Lightman, A. Hahn, S. Saravia, A. Sherule, and M. Thompson, "Guide to operational technology (OT) security," NIST Special Publication 800-82, Rev. 3, National Institute of Standards and Technology, 2023. [Online]. Available: DOI: https://doi.org/10.6028/NIST.SP.800-82r3.

National Institute of Standards and Technology, "The NIST Cybersecurity Framework (CSF) 2.0," NIST Cybersecurity White Paper 29, 2024. [Online]. Available: DOI: https://doi.org/10.6028/NIST.CSWP.29.

Joint Task Force, "Security and privacy controls for information systems and organizations," NIST Special Publication 800-53, Rev. 5, National Institute of Standards and Technology, 2020. [Online]. Available: DOI: https://doi.org/10.6028/NIST.SP.800-53r5.

International Electrotechnical Commission, "IEC 62443-2-1:2024: Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners," IEC Webstore, 2024. [Online]. Available: Accessed: Jun. 8, 2026.

https://webstore.iec.ch/en/publication/62883.

The MITRE Corporation, "ATT&CK for ICS matrix," MITRE ATT&CK v19.1, 2026. [Online]. Version history: Accessed: Jun. 8, 2026. Available: https://attack.mitre.org/matrices/ics/.

https://attack.mitre.org/resources/versions/.

Cybersecurity and Infrastructure Security Agency, "Cross-Sector Cybersecurity Performance Goals, Version 2.0," U.S. Department of Homeland Security, 2025. [Online]. Accessed: Jun. 8, 2026. Available: https://www.cisa.gov/sites/default/files/2025-12/CPG_Report_2.0_508c.pdf.

Most read articles by the same author(s)

1 2 3 4 5 6 7 8 9 > >>