← SecOT+ practice hubEnter Meridian

DOMAIN 2.0 · 17% draft

OT Risk Management

Frame risk around safety, availability, reliability, people, process, and the consequences of change.

Paraphrased, versioned draft mapping from CompTIA SecOT+ SOT-001 V1 draft objectives v1.3. This independent page is not CompTIA content.

2.1partial

Explain the importance of governance, risk, and compliance

Operational consequences and escalation are present; a full GRC workflow is not yet released.

Meridian crosswalkXOT-01
2.2gap

Explain the elements of cybersecurity program management

No released scenario currently tests risk registries, RACI, program metrics, or cybersecurity documentation.

Meridian crosswalkNo released scenario mapped yet.
2.3partial

Explain risk assessment concepts

Incident isolation and consequence reasoning are strong; dedicated asset-risk assessment needs depth.

Meridian crosswalkOTC-01XOT-01
2.4partial

Explain risk monitoring and disposition

Operational consequences and escalation are present; a full risk-register workflow is not yet released.

Meridian crosswalkXOT-01
2.5partial

Explain the importance of the change management process

Authorization and rollback thinking are represented; planned-change documentation needs a dedicated lab.

Meridian crosswalkOTCY-02robot-comms-001

Turn this domain into a decision.

The free R8 incident exposes evidence, safety, coordination, and recovery behavior through the canonical OT-Praxis runtime.

Practice in Meridian →