Asset owner maintains an incident response capability tailored to IACS, including detection, triage, containment, eradication, recovery, lessons learned, communication with regulators, and exercises that include OT-specific scenarios such as ransomware on engineering workstation or malicious PLC logic change.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.