Scanning, patch management, and the vulnerability lifecycle — adapted for the real constraints of an OT environment.
Vulnerability management is a lifecycle — discover, assess, prioritize, remediate, verify — not a single action, which is why "we patch on schedule" never covers the full picture. This module covers CVE/CVSS scoring, the practical difficulty of scanning live OT equipment that can't tolerate an unplanned reboot, and the compensating-control approach (segmentation, monitoring) used when a vulnerable legacy system genuinely cannot be patched.
By the end of this module you should be able to explain why a critical CVSS score doesn't automatically mean "patch immediately" in an OT context, and what a defensible compensating-control plan looks like instead — a judgment call Module 14's water-utility SCADA hardening project has to make explicitly.