Model the proposed change iOnly inputs that materially change the future state are used in this comparison. Change title i Change category iConnectivity ChangeConfiguration ChangeIdentity / Security ChangeOT Control ChangeApplication / Firmware ChangeAsset / Architecture ChangeThird-Party / Dependency ChangeData / Integration ChangeFacility / Physical Security ChangeVendor / Contractual ChangeEmergency / Temporary ChangeDecommission / Removal Change Asset criticality i1 - Low2 - Moderate3 - Important4 - High5 - Critical Hourly operational value ($) i Credible outage duration (hours) i Internet exposure iNoYes Remote access iNoYes Security control maturity i1 - Limited2 - Basic3 - Established4 - Strong5 - Optimized External dependencies iNoneOne dependencyMultiple dependencies Baseline risk override (optional) i Baseline exposure override ($, optional) i Change risk points i Exposure multiplier i Calculated baselineRisk and exposure are calculated from the current-state facts above. Proposed controls i Require MFAReduce account compromise probability. Use a jump hostKeep vendor access outside the OT trust boundary. Restrict source IP and maintenance windowReduce reachability and duration of exposure. Enable IDS monitoringImprove detection and response readiness. Test rollback and validate backupsReduce recovery and execution risk.