Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Zero Trust Architecture for Operational Technology in North American Critical Infrastructure: A Framework for Implementation and Resilience Optimization

Mubarak Olayiwola Ahmed1, Mayokun Philips Adegbite2, Abolaji Adebayo3, Mayokun Philips Adegbite

Abstract

Zero trust architecture has emerged as a guiding principle for modern information security, replacing implicit network trust with continuous verification of identity, device posture, and contextual signals. Its application to operational technology in North American critical infrastructure presents both opportunity and friction because legacy industrial control systems were engineered for availability, determinism, and long operational lifecycles rather than for cryptographic identity and granular policy enforcement. This conceptual paper proposes a framework for implementing zero trust principles within operational technology environments without sacrificing safety, reliability, or compliance with sector specific regulations. The framework identifies eight architectural pillars that correspond to the National Institute of Standards and Technology Special Publication 800 207 tenets while accounting for the operational realities of substations, generation facilities, control rooms, and field devices. The eight pillars cover asset and identity inventory, segmentation and microperimeters, secure remote engineering access, continuous device and process posture monitoring, policy decision and enforcement, encrypted operational data flows where feasible, automated response to confirmed violations, and governance and measurement. The paper analyzes the integration of these pillars with the North American Electric Reliability Corporation Critical Infrastructure Protection standards, the Department of Energy cybersecurity capability maturity model, and federal zero trust strategy documents. Implementation pathways for greenfield, brownfield, and mixed asset environments are proposed, with emphasis on resilience and graceful degradation. The framework supports a phased migration strategy that preserves operational continuity while progressively reducing implicit trust across operational technology networks.

Keywords

zero trust; operational technology; critical infrastructure; identity and access management; micro segmentation; resilience; North American electric utilities; conceptual framework.

References

Abdallah, A., Maarof, M.A. and Zainal, A. (2016). Fraud detection system: A survey. Journal of Network and Computer Applications, 68, 90 to 113. Ackerman, P. (2017). Industrial Cybersecurity: Efficiently Secure Critical Infrastructure Systems. Packt Publishing, Birmingham. Adebayo, A. (2020). Wireless internet service provider network reliability frameworks for emerging markets. International Journal of Network and Communication Research, 5(2), 88-103. Tizeti Inc., Nigeria. Adebayo, A. (2021a). Network access control patterns for distributed wireless internet service deployments. International Journal of Information Security Research, 11(4), 215-232. Tizeti Inc., Nigeria. Adebayo, A. (2021b). Secure last-mile connectivity architectures for Sub-Saharan African internet service providers. Journal of African Information Systems, 12(3), 145-162. Tizeti Inc., Nigeria. Adepu, S. and Mathur, A. (2016). An investigation into the response of a water treatment system to cyber attacks. HASE 2016, 141 to 148. Adepu, S., Brasser, F., Garcia, L., Rodler, M., Davi, L., Sadeghi, A.R. and Zonouz, S. (2020). Control behavior integrity for distributed cyber physical systems. ACM/IEEE ICCPS 2020. Adesuyi, M. O., Walawalkar, G., & Kalu, A. (2021). Decision-centric financial analytics for executive-level strategy formulation. Journal of Accounting and Financial Management, 7(5), 152 to 173. Adeyoyin, O., Awanye, E. N., Morah, O. O., & Ekpedo, L. (2020). A Conceptual Framework Linking Financial Strategy and Operational Excellence in Manufacturing Firms. Adeyoyin, O., Awanye, E. N., Morah, O. O., & Ekpedo, L. (2021). A Conceptual Framework for Integrating ESG Priorities into Sustainable Corporate Operations. Agbabiaka, J., Okonkwo, C.S., Ogunwole, O., Mayo, W. & Okeke, O.T. (2019). Supply Chain Risk Management Model for EPC and Gas Processing Projects. IRE Journals, 3(2), 968 to 980. DOI: 10.64388/IREV3I2-1713124. Aggarwal, C.C. (2017). Outlier Analysis (2nd ed.). Springer, Cham. Ahmed, M., Mahmood, A.N. and Hu, J. (2016). A survey of network anomaly detection techniques. Journal of Network and Computer Applications, 60, 19 to 31. Ahmed, K.S. & Odejobi, O.D. (2018). Conceptual Framework for Scalable and Secure Cloud Architectures for Enterprise Messaging. IRE Journals, 2(1), 1-15. Ahmed, K. S., Odejobi, O. D., & Oshoba, T. O. (2019). Algorithmic model for constraint satisfaction in cloud network resource allocation. IRE Journals, 2(12). ISSN: 2456-8880. Ahmed, K.S., Odejobi, O.D. & Oshoba, T.O. (2020). Predictive Model for Cloud Resource Scaling Using Machine Learning Techniques. Journal of Frontiers in Multidisciplinary Research, 1(1), 173-183. DOI: 10.54660/.Ijfmr.2020.1.1.173-183. Ahmed, K. S., Odejobi, O. D., & Oshoba, T. O. (2021). Certifying algorithm model for Horn constraint systems in distributed databases. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 7(1), 537-554. Aifuwa, S. E., Oshoba, T. O., Ogbuefi, E., Ike, P. N., Nnabueze, S. B., & Olatunde-Thorpe, J. (2020). Predictive analytics models enhancing supply chain demand forecasting accuracy and reducing inventory management inefficiencies. International Journal of Multidisciplinary Research and Growth Evaluation, 1(3), 171-181. DOI: 10.54660/.IJMRGE.2020.1.3.171-181. www.iiardpub.org Akeju, B., Edivri, J., Ogbole, J. I., Okoruwa, P. O., Fadayomi, O., & Abolaji, T. O. (2018). Conceptual model for insider threat classification and risk modeling in complex digital systems. IRE Journals, 1(9). https://doi.org/10.64388/IREV1I9-1713778 Akhtar, N. and Mian, A. (2018). Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access, 6, 14410 to 14430. Akinlade, O. F., Filani, O. M., & Nwachukwu, P. S. (2021a). Applied Statistics Models Optimizing Global Supply Chain Networks Under Uncertainty Conditions. Akinlade, O. F., Filani, O. M., & Nwachukwu, P. S. (2021b). Cross-Functional Framework using AI-Enhanced Analysis for Supplier Selection Accuracy. Akinleye, O. K., & Adeyoyin, O. (2021). Process Automation Framework for Enhancing Procurement Efficiency and Transparency. Akinola, A. S., Adesanya, O. S., Okafor, C. M., & Farounbi, B. O. (2018). Automated Payroll Compliance Assurance: Linking Withholding Algorithms to Financial Statement Reliability. IRE Journals, 1(7). Akinola, A. S., Farounbi, B. O., Onyelucheya, O. P., & Okafor, C. M. (2020a). Translating finance bills into strategy: Sectoral impact mapping and regulatory scenario analysis. Journal of Frontiers in Multidisciplinary Research, 1(1), 102-111. Akinola, A. S., Okafor, C. M., Dako, O. F., & Adesanya, O. S. (2020b). Evidence-informed Advisory for Ultra-High-Net-Worth Clients: Portfolio Governance and Fiduciary Risk Controls. Journal of Frontiers in Multidisciplinary Research, 1(2), 112-120. Aldaraani, N. and Begum, Z. (2018). Understanding the impact of ransomware: A survey on its evolution, mitigation and prevention techniques. NCC 2018, 1 to 5. Alexander, O., Belisle, M. and Steele, J. (2020). MITRE ATT&CK for Industrial Control Systems: Design and Philosophy. MITRE Corporation, McLean, VA. Alladi, T., Chamola, V. and Zeadally, S. (2020). Industrial control systems: Cyberattack trends and countermeasures. Computer Communications, 155, 1 to 8. Allodi, L. and Massacci, F. (2014). Comparing vulnerability severity and exploits using case control studies. ACM TISSEC, 17(1), 1 to 20. Almorsy, M., Grundy, J. and Muller, I. (2016). An analysis of the cloud computing security problem. arXiv preprint arXiv:1609.01107. Alsentzer, E., Murphy, J.R., Boag, W., Weng, W.H., Jin, D., Naumann, T. and McDermott, M. (2019). Publicly available clinical BERT embeddings. Proceedings of the 2nd Clinical Natural Language Processing Workshop, 72 to 78. Ambali, K.B., Eyetsemitan, R.A., Oyeleye, A.O. & Fadayomi, O. (2021). Lean Six Sigma for Small Enterprises: A Systematic Review and Lite-DMAIC Adaptation Framework for Resource-Constrained Organizations. IRE Journals, 5(5), 562 to 583. DOI: 10.64388/IREV5I5 to 1716957 Amebleh, J., Igba, E. & Ijiga, O. M. (2021). Graph-Based Fraud Detection in Open-Loop Gift Cards: Heterogeneous GNNs, Streaming Feature Stores, and Near-Zero-Lag Anomaly Alerts International Journal of Scientific Research in Science, Engineering and Technology Volume 8, Issue 6 DOI: https://doi.org/10.32628/IJSRSET214418 Amin, M. and Wollenberg, B.F. (2005). Toward a smart grid: Power delivery for the 21st century. IEEE Power and Energy Magazine, 3(5), 34 to 41. Aminu-Ibrahim, A. Y., Ogbete, J. C., & Ambali, K. B. (2018). Developing sustainable diagnostic laboratory infrastructure models for emerging and resource constrained health systems. www.iiardpub.org Iconic Research and Engineering Journals, 1(8), 118 to 132.https://doi.org/10.64388/IREV1I8 to 1713586 Aminu-Ibrahim, A.Y., Ogbete, J.C. & Ambali, K.B. (2019). Capital Project Delivery Models for High Risk Healthcare Infrastructure in Developing National Health Systems. Iconic Research and Engineering Journals, 2(10), 626 to 649. DOI: 10.64388/IREV2I10 to 1713588. Aminu-Ibrahim, A.Y., Ogbete, J.C. & Ambali, K.B. (2020). Infrastructure Driven Expansion of Diagnostic Access Across Underserved and Rural Healthcare Regions. International Journal of Multidisciplinary Research and Growth Evaluation, 1(5), 691 to 706. DOI: 10.54660/IJMRGE.2020.1.5.691 to 706. Anderson, R. (2008). Security Engineering: A Guide to Building Dependable Distributed Systems (2nd ed.). Wiley, Indianapolis, IN. Ani, U.P.D., He, H. and Tiwari, A. (2017). Review of cybersecurity issues in industrial critical infrastructure: Manufacturing in perspective. Journal of Cyber Security Technology, 1(1), 32 to 74. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2019). Global marketing law and consumer protection challenges: a strategic framework for multinational compliance. IRE Journals, 3(6), 325-333. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2020). Designing ethics and compliance training frameworks to drive measurable cultural and behavioral change. Int J Multidiscip Res Growth Eval, 1(3), 205-20. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2021a). Blockchain-based architectures for tamper-proof regulatory recordkeeping and real-time audit readiness. Int J Multidiscip Res Growth Eval, 2(6), 485-504. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2021b). Digital Marketing Compliance Risk Mitigation: Balancing Growth Objectives with Multi-Jurisdictional Regulations. Anioke, S. C., & Atima, M. E. (2018). Regulatory Analytics Approaches for Improving Occupational Health Safety Outcomes Across Public and Private Workplaces. Anioke, S. C., & Atima, M. E. (2019). Digital Employer Risk Rating Frameworks Supporting Public Health Oriented Social Insurance Compliance Systems. Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J. et al. (2017). Understanding the Mirai botnet. USENIX Security 2017, 1093 to 1110. Anwar, S. and Soltesz, B. (2016). Securing the smart grid. International Journal of Advanced Research in Computer Science, 7(1). Apruzzese, G., Colajanni, M., Ferretti, L., Guido, A. and Marchetti, M. (2018). On the effectiveness of machine and deep learning for cyber security. CyCon 2018, 371 to 390. Apruzzese, G., Colajanni, M., Ferretti, L. and Marchetti, M. (2019). Addressing adversarial attacks against security systems based on machine learning. International Conference on Cyber

More Articles from INTERNATIONAL JOURNAL OF ENGINEERING AND MODERN TECHNOLOGY