← SecOT+ practice hubEnter Meridian

DOMAIN 5.0 · 22% draft

OT Security Operations

Operate the day-to-day controls: visibility, monitoring, maintenance, vulnerability handling, logging, and change discipline.

Paraphrased, versioned draft mapping from CompTIA SecOT+ SOT-001 V1 draft objectives v1.3. This independent page is not CompTIA content.

5.1covered

Summarize the purpose of asset management tasks

Freshness, topology, historian, and communication evidence are inspectable in Meridian.

Meridian crosswalkOTC-01OTC-10OTR-08
5.2covered

Given a scenario, analyze data in support of security operations

Learners request evidence, form hypotheses, and verify recovery through the event ledger.

Meridian crosswalkOTC-01OTC-10robot-comms-001
5.3partial

Explain the role of vulnerability remediation in an OT security program

Change authority exists; patch-window and compensating-control depth is a coverage gap.

Meridian crosswalkOTCY-02OTR-05
5.4gap

Given a scenario, apply the appropriate techniques to facilitate vulnerability management

No released scenario currently tests passive/active discovery, SBOM/NVD triage, and remediation verification end to end.

Meridian crosswalkNo released scenario mapped yet.
5.5gap

Explain the importance of portable device security in OT environments

Removable media, mobile device, calibration equipment, and sanitization controls are not yet a released Meridian task.

Meridian crosswalkNo released scenario mapped yet.

Turn this domain into a decision.

The free R8 incident exposes evidence, safety, coordination, and recovery behavior through the canonical OT-Praxis runtime.

Practice in Meridian →