A formal approach manages security vulnerabilities in OT systems where traditional patching is not possible
This policy control defines a written approach for handling vulnerabilities in systems that cannot be patched normally, including when compensating measures apply, one of the operating procedures A.5.37 requires documented.
This policy facet defines a documented approach for OT vulnerabilities that cannot be patched on normal IT timelines, the compensating leg A.8.8 anticipates for production systems.