Run a configuration/patch management program built on an accurate baseline and asset inventory, prioritising PC-architecture machines (HMI, database server, engineering workstation roles). Limit connection of external laptops, prefer known-good vendor laptops, and test updates on an isolated system with malware detection before operational deployment. Obtain updates from authenticated vendor sites and validate authenticity via digital signatures or out-of-band hashes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.