Answer yes if your organisation performs periodic vulnerability assessments, threat modelling, or equivalent security reviews designed for OT environments, accounting for their unique operational, safety, availability, and legacy technology requirements. Describe the frequency, methodology, and scope in the notes or upload supporting documentation as evidence.
Vulnerability assessments and threat modelling designed for IT environments don't translate directly to Operational Technology (OT), since OT systems have different priorities (availability and safety over confidentiality), different failure modes, and often can't tolerate the intrusive scanning techniques commonly used in IT assessments without risking disruption. OT-specific vulnerability assessments and threat modelling are designed to work within these constraints, using techniques and tools appropriate to OT (such as passive network monitoring rather than active scanning where necessary), while specifically considering the threats and attack paths relevant to industrial control systems, such as compromise via engineering workstations, vendor remote access, or the IT/OT boundary.
Establish a programme of OT-specific vulnerability assessments or threat modelling, using methodologies and tools appropriate for OT (rather than standard IT vulnerability scanning), at a regular cadence. Document the scope, methodology, and outcome of each assessment, including any limitations (such as systems that couldn't be safely assessed), so that this evidence demonstrates a considered, OT-appropriate approach to identifying and managing vulnerabilities.