Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.5.09 Installing OT patches

Control Overview

This control mandates that the organization establishes, assigns, and implements formal processes for the timely deployment of essential security patches and firmware updates to systems operating within Operational Technology (OT) networks. Due to the high availability demands of industrial processes, patching OT assets is uniquely complex. However, to eliminate vulnerabilities that could result in production downtime, physical disruptions, or safety hazards, the control requires systematic asset visibility, routine vulnerability scanning, rigorous testing, and clear assignment of patch responsibilities.


Applicability Status

  • Applicable for anDREa: NO

Justification & Strategic Approach

This control focuses specifically on managing risks within cyber-physical environments where systems (such as legacy HMIs, PLCs, and SCADA engines) interact with the physical world and often operate continuously under strict uptime constraints.

As a fully remote, cloud-native SaaS/PaaS provider, anDREa hosts and manages its data and analytics platform (myDRE) entirely within the virtualized public cloud infrastructure of Microsoft Azure.

Because anDREa's corporate structure and product delivery are exclusively software-defined:

  • The organization owns, manages, or controls no physical industrial networks, factory environments, or manufacturing systems.
  • There are no embedded OT systems, physical logic controllers, or industrial automation loops requiring specialized maintenance windows or out-of-band firmware patching.
  • Managing vendor maintenance agreements for industrial hardware or coordinating patch cycles for cyber-physical equipment is outside our scope.

Consequently, all requirements under the NIS 2 Operational Technology (OT) patch management domain are formally classified as Not Applicable.

All software maintenance, application lifecycle hardening, and system vulnerability management for anDREa's cloud assets and remote user endpoints are instead governed strictly under our IT infrastructure controls. These are executed via our automated CI/CD pipeline quality gates, centralized Mobile Device Management (MDM) update baselines, and structured patch management SLAs under Controls N.4.07 (Keeping Software Up to Date) and N.4.14 (Detecting and Repairing Technical Vulnerabilities).


Audit Summary

  • Compliance Status: Not Applicable (Exempt via Architecture)
  • Gaps Identified: None. The justification for non-applicability is logically absolute and aligns completely with anDREa's pure-cloud software delivery architecture. No further mapping or remediation is required.