Answer yes if your organisation tests security patches, firmware updates, and other changes in a representative non-production environment before deployment, assessing compatibility, stability, operational impact, and safety. Describe the testing and approval process in the notes. Upload supporting documentation as evidence.
Patches that behave fine in standard IT environments can cause unexpected disruption in OT, where stability and availability are often safety-critical. This risk is heightened by the fact that many OT systems run continuously and cannot tolerate unplanned disruption in the way a typical IT system might. Testing patches in a segregated or separate test network before recommending or applying them to a client's production environment allows you to confirm both applicability, that the patch is actually relevant and compatible with the specific system and configuration in use, and stability, that applying it doesn't introduce unintended side effects, before that risk is carried into a live environment. Skipping this step means the production OT environment effectively becomes the test environment, which is a significant risk given the potential consequences of an OT disruption.
Establish a segregated test environment representative of your production OT systems, and route all patches and firmware updates through it before deployment, assessing compatibility, stability, operational impact and safety.