A utility compares its plan to practice after an event hit both billing and the control network. Which governance gap is most likely to slow the response?
- A.No documented list of approved vendor laptop models
- B.No retention schedule for the historian archive tables
- C.No second approver for firewall rule change tickets
- D.No named decision owner when IT priorities clash with OT
Why D is correct
When IT wants to isolate to protect data while operations wants to keep the process running a plan with no named decision owner stalls. The other gaps are real but minor next to a leadership conflict in the middle of an incident.
Know someone studying for OT Security Fundamentals? Send them this one.