SOURCES AND REFERENCES
What source documents, regulations, and standards does this guide reference?
Source documents used in Part 2:
- BifrostConnect, Security Documentation, Version 2.2.2 (February 2026).
- BifrostConnect, AccessGuard product description.
- BifrostConnect, SessionGuard product description.
- Part 1: OT Best Practice Guide, Part 1 (June 2026).
Regulatory sources (shared with Part 1):
- Directive (EU) 2022/2555, OJ L 333, 14 December 2022.
- Act No. 434 of 6 May 2025 on measures to ensure a high level of cybersecurity (Danish NIS2 Implementation Act).
- Styrelsen for Samfundssikkerhed (SAMSIK), Vejledning til NIS 2-loven, June to August 2025.
- IEC 62443 series: DS/EN IEC 62443-3-3:2019 (system security requirements), DS/EN IEC 62443-2-4:2024 (service provider security programme), DS/EN IEC 62443-2-1:2024 (asset owner cybersecurity programme).
- Executive Order No. 260 of 6 March 2025, Danish Ministry of Climate, Energy and Utilities.
- Bekendtgørelse om modstandsdygtighed og beredskab i energisektoren (Danish Executive Order on resilience and preparedness in the energy sector).
- ISO/IEC 27001:2022.
- NIST SP 800-82 Revision 3, Guide to Operational Technology (OT) Security, September 2023.
- NIST SP 800-207, Zero Trust Architecture, August 2020.
- NIST SP 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations.
- Joint NCSC, ASD ACSC, CCCS, CISA, FBI, BSI, NCSC-NL, NCSC-NZ, Secure Connectivity Principles for Operational Technology, 18 March 2024.
- Joint CISA, DoW, DOE, FBI, DOS with NIST contributions, Adapting Zero Trust Principles to Operational Technology, 29 April 2026.
- Directive (EU) 2022/2557, OJ L 333, 14 December 2022.
- Regulation (EU) 2016/679 (GDPR).
Co-deployment references:
- OT-IDS platforms: referenced for deep packet inspection on OT protocols. Co-deployment, not API-integrated.
- Data diode category: unidirectional gateway, file security gateway (multi-engine malware scanning, content disarm/reconstruction), one-way log export, one-way Historian/database replication. Referenced for compensating controls.
- Auth0: identity and multi-factor authentication layer used by BifrostConnect Service.
- Netbird: open-source WireGuard-based tunnelling component used by Direct Tunnel Access.
Threat intelligence:
- MITRE ATT&CK for ICS. Volt Typhoon: CISA Advisory AA24-038A. Sandworm: Mandiant ‘APT44: Unearthing Sandworm’ (April 2024).
- SektorCERT, Threat Assessment: The Danish Energy Sector, November 2023.
- CISA ICS-CERT Advisories: Colonial Pipeline (AA21-131A), Oldsmar (AA21-042A, attribution disputed), TRITON (Dragos ‘TRISIS malware analysis’).
- CISA Advisory AA23-335A (CyberAv3ngers): IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors.
Disclaimer:
This document is a companion to the Part 1 best-practice framework. Product features described here are accurate as of the publication date (June 2026). Regulatory citations reflect the legal text as of the publication date. Customers should validate enforcement of every stated control during rollout through acceptance testing.
Published by BifrostConnect. Part 2 of a two-part publication. Version 1.21, June 2026. Web: bifrostconnect.com.
Where VPNs end, BifrostConnect.