Answer yes if your organisation has a documented OT Security Policy. This may be a separate policy or a distinct section within your Cybersecurity or Information Security Policies. Upload the policy as evidence.
OT environments often have different acceptable use requirements and risk tolerances to standard corporate IT, patching windows shaped by uptime and safety needs rather than convenience, and unauthorised changes carrying consequences that go beyond data loss to safety and availability impacts. A generic corporate Information Security Policy is rarely written with these constraints in mind, so applying it unmodified to OT risks being either too restrictive to reflect how OT actually needs to operate, or too permissive because it was never designed with OT-specific risks in view. A documented OT security policy, whether standalone or a distinct section within your existing policy, makes clear who is responsible for OT security decisions, and what counts as acceptable use, specifically in the context OT operates in.
Document an OT Security Policy, either as a standalone policy or a distinct, clearly identifiable section within your existing Cybersecurity or Information Security Policy, so OT-specific expectations aren't left to be inferred from a policy written for a different environment.
Your policy should typically define who holds responsibility for OT security decisions (which may sit with different people to your standard IT ownership), acceptable use guidelines specific to OT devices and networks (such as constrained patching windows and restrictions on general enterprise use), and how OT security roles interact with your wider organisation's security governance, so OT isn't managed in isolation from your overall security posture.