Answer yes if your organisation maintains any certifications or aligns with best practices regarding OT security practices. Provide any relevant documentation, such as certificates, as evidence.
Operational Technology (OT), the systems controlling physical processes such as industrial control systems (ICS), Supervisory Control and Data Acquisition (SCADA) control technologies, and programmable logic controllers (PLC), carries different risk considerations to standard IT, particularly around safety and availability. Aligning with recognised OT-specific standards such as IEC 62443, or broader frameworks like ISO 27001 or the NCSC Cyber Assessment Framework, gives assurance that your OT security practices are being managed against an established baseline rather than an ad hoc approach.
Start by identifying which of your systems fall within scope of OT, distinguishing them clearly from your IT estate, since OT often requires a different risk model and different controls (for example, prioritising availability and safety over confidentiality, and requiring more caution around active scanning or patching).
Identify which recognised standards or frameworks are most relevant to the OT systems and services you provide, and formally align your practices, or seek certification, against them.