Answer yes if technical or procedural controls ensure OT-specific devices are managed separately from enterprise user devices and restricted from standard enterprise activities where appropriate.
Engineering workstations, configuration tools, and other privileged devices used to interact with Operational Technology (OT) systems carry a level of access and influence that standard enterprise user devices don't have, often including the ability to reprogram controllers, push configuration changes, or otherwise directly affect physical processes. When these devices are managed the same way as standard enterprise devices, and permitted to carry out everyday tasks like general web browsing or email, they inherit all the risks associated with that everyday use, phishing, malicious downloads, drive-by compromise, while also holding privileged access into OT. Managing these devices separately, and restricting them to their intended purpose, removes this route by ensuring that a device capable of affecting OT is never exposed to the everyday risks that come with general enterprise use.
Identify every engineering workstation, configuration tool, and other privileged device used to interact with, configure, or maintain OT systems, and confirm each one is managed distinctly from standard enterprise user devices including restrictions on general enterprise activities such as web browsing or email.