Answer yes if all remote access to OT systems is controlled through secure access technologies and formal access management processes, such as MFA, PAM, or jump hosts. Accounts used for OT remote access must be uniquely assigned to individuals and separate from standard enterprise accounts. Describe the controls in place, including any exceptions, in the notes. Upload supporting documentation as evidence.
Remote access into the OT environment, whether used by internal staff, vendors, or third-party support providers, is one of the most common routes an attacker uses to reach OT systems from outside the network, since it's specifically designed to cross the boundary that segregation and network controls otherwise try to maintain. This risk is compounded where privileged OT accounts aren't uniquely assigned to individuals, or where staff use the same account for both OT and standard enterprise access, since this makes it difficult to attribute actions to a specific person, increases the impact if a single credential is compromised, and means a compromise of a standard enterprise account could directly grant privileged OT access. Ensuring remote access is secure, managed, and monitored, and that privileged OT accounts are unique to individuals and separate from their standard enterprise identity, closes off two of the most direct paths by which a compromise elsewhere in the environment could translate into unauthorised access or control over OT systems.
Route all remote access to the OT environment through a controlled, managed path such as a jump host or dedicated gateway, with MFA required for every session, time-bound or approval-gated access for vendors and third parties, and active logging and monitoring with alerting on unusual access. Privileged OT accounts should be uniquely assigned to named individuals, kept entirely separate from their standard enterprise accounts, restricted to least privilege, and protected with MFA wherever technically feasible, with access reviewed periodically as roles change. Where legacy OT systems can't support these controls (for example, no MFA support), document the compensating controls in place, such as tighter network restriction or enhanced monitoring, so the residual risk is understood and managed.