Official intent
Manage known vulnerabilities in OT — patch, or apply compensating controls, on a schedule production can accept. The official source remains authoritative.
Read the official campaign ↗Why it matters
OT vulnerabilities are long-lived and widely published, and adversaries know these systems are rarely patched. But blind patching can break a validated process or void a warranty. A disciplined program — patch where you safely can, compensate where you cannot — closes real exposure without gambling with uptime or safety.
Patching or updating firmware on live OT can disrupt a validated process or trip safety functions. Apply vendor-approved patches only, test in a lab or during an approved maintenance window with the process owner present, and keep a tested rollback. When a patch is too risky, a documented compensating control is the correct answer — not forcing the update.
Minimum / Strong / Advanced
Known vulnerabilities on OT assets are identified, and the highest-risk ones have either a patch plan or a documented compensating control.
Vulnerabilities are ranked by exposure and process impact; patching follows vendor guidance and maintenance windows, with compensating controls where patching is unsafe.
Exposure is tracked continuously against the OT inventory, vendor advisories are monitored, and patch-or-compensate decisions are logged and reviewed.
Implementation timeline
- Cross-reference the OT inventory against known-exploited and vendor advisories
- Flag any internet-reachable OT device
- Rank findings by exposure and process impact
- Apply compensating controls (isolation, access limits) to the worst that cannot be patched now
- Schedule vendor-approved patches into the next maintenance windows
- Test patches in a lab or on non-critical units first
- Document each patch-or-compensate decision
- Subscribe to vendor and ICS advisories for ongoing coverage
Implementation steps
- Map known vulnerabilities to the validated OT inventory using vendor advisories and ICS sources.
- Rank each by real risk — exposure, reachability, and impact on the process — not raw score.
- For each, decide patch or compensate with the process owner, honoring vendor certification.
- Apply patches through vendor guidance and maintenance windows, tested first and with rollback.
- Where patching is unsafe, apply and document compensating controls, and review decisions on a cadence.
Validation
- Confirm every high-risk OT vulnerability has either an applied patch or a documented compensating control.
- Verify no OT device with a known-exploited vulnerability is reachable from outside its zone.
- Check that patches were vendor-approved and applied in an authorized window with a rollback on hand.
Evidence to retain
OT vulnerability/patch policy including compensating-control criteria
Vulnerability-to-asset mapping and applied compensating controls
Maintenance-window patch records with test and rollback notes
Decision log of patch-or-compensate with review dates
Common failure modes
Patching a controller mid-shift and halting the line, treating an unfixable device as acceptable with no compensating control, and ignoring advisories because “we can't patch anyway.” Unpatchable is not the same as unmanaged.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.