An internal audit of water-utility OT finds no defined vulnerability-management cadence for controllers and HMIs even though IT servers are scanned monthly. How should this audit result feed vulnerability management?
Select an answer to reveal the explanation.
Short Explanation
Audits are the flashlight on missing routines—if OT has no vuln cadence while servers get monthly scans, the fix is to extend the process, not shrug or stop scanning IT. Feed that audit finding straight into vuln-mgmt improvements.
Full Explanation
System and process audits identify gaps in vulnerability-management coverage, such as OT assets lacking a defined scan/remediation cadence. Those findings should drive process improvements appropriate to platform constraints rather than abandoning IT scanning or unmanaged mass firmware changes. OT environments still require vulnerability management adapted to safety and availability needs.