OT Security – Fundamentals

0 Enrolled
5 jours
  • 5 day
  • 63
  • 0
  • no
3,500.00€

Aperçu du cours

According to Gartner, OT security is defined as « the set of practices and technologies used to (a) Protect people, resources, and information, (b) Monitor and/or control devices, processes, and events, and (c) Initiate change within enterprise OT systems. » OT security solutions span a wide range of security technologies, from next-generation firewalls to SIEM systems, and deploy different layers of protection.
Historically, OT-specific cybersecurity was not necessary, since OT systems were not connected to the Internet. Therefore, they were not exposed to external threats. As digital innovation initiatives progress, and IT and OT networks converge, companies have tended to deploy standalone tools to address specific issues. These approaches to OT security have resulted in a complex network that no longer shares information or provides the necessary visibility.
Often, IT and OT networks operate separately, resulting in a duplication of security efforts and a lack of transparency in operations. These IT/OT networks cannot track what is happening across the entire attack surface. Because of different referees in security organization of both platforms, this results in two separate security teams protecting their respective network perimeters.
When looking into OT, the biggest subset is ICS. ICS (Industrial Control System) is a broad term that embodies both SCADA and DCS.

Prérequis

  • Basic understanding of IT systems (Linux/Windows)
  • Basic networking knowledge
  • Basic system administration

Fonctionnalités

  • Understand ICS components
  • Understand the different layers/levels
  • Enhance threat handling

Public ciblé

  • Cybersecurity expert
  • OT expert in charge of the security

Détails

  • 21 Sections
  • 63 Lessons
  • 5 Days
Expand all sectionsCollapse all sections
  • 2
    • 1.1
      Processes & Roles
    • 1.2
      Industries
  • 6
    • 2.1
      Levels 0 and 1 : Controllers and Field Devices
    • 2.2
      Levels 0 and 1 : Programming Controllers
    • 2.3
      Levels 2 and 3 : HMIs, Historians, Alarm Servers
    • 2.4
      Levels 2 and 3 : Specialized Applications and main Servers
    • 2.5
      Levels 2 and 3 : Control Rooms and Plants
    • 2.6
      Levels 2 and 3 : SCADA
  • 1
    • 3.1
      ICS Life Cycle Challenges
  • 1
    • 4.1
      Design example
  • 4
    • 5.1
      Threat Actors and Reasons for Attack
    • 5.2
      Attack Surface and Inputs
    • 5.3
      Vulnerabilities
    • 5.4
      Threat/Attack Models
  • 5
    • 6.1
      Attacks Schemes
    • 6.2
      Control Things Platform
    • 6.3
      Technologies
    • 6.4
      Fieldbus Protocol Families
    • 6.5
      Defenses
  • 5
    • 7.1
      Ethernet Concepts
    • 7.2
      TCP/IP Concepts
    • 7.3
      ICS Protocols over TCP/IP
    • 7.4
      Wireshark and ICS Protocols
    • 7.5
      Attacks on Networks
  • 3
    • 8.1
      Firewalls and NextGen Firewalls
    • 8.2
      Data Diodes and Unidirectional Gateways
    • 8.3
      NIDS/NIPS and Netflow
  • 2
    • 9.1
      Crypto Keys
    • 9.2
      Encryption, Hashing, and Signatures
  • 4
    • 10.1
      Historians and Database
    • 10.2
      HMI and UI Attacks
    • 10.3
      Web-based Attacks
    • 10.4
      Password Defenses
  • 3
    • 11.1
      Satellite and Cellular
    • 11.2
      Mesh Networks and Microwave
    • 11.3
      Bluetooth and Wi-Fi
  • 2
    • 12.1
      Risks of Wireless
    • 12.2
      Sniffing, DoS, Masquerading, Rogue AP
  • 2
    • 13.1
      Patch Decision Tree
    • 13.2
      Vendors, CERTS, and Security Bulletins
  • 4
    • 14.1
      Microsoft : Windows Services
    • 14.2
      Microsoft : Windows Security Poolicies and GPOs
    • 14.3
      Linux : Differences with Windows
    • 14.4
      Linux Daemons, SystemV, and SystemD
  • 3
    • 15.1
      Application Runtime and Execution Control
    • 15.2
      Configuration Integrity and Containers
    • 15.3
      Logs in Windows and Linux
  • 2
    • 16.1
      Windows Event Logs and Audit Policies
    • 16.2
      Syslog and Logrotate
  • 2
    • 17.1
      Honeypots
    • 17.2
      Attacks on the perimeter
  • 3
    • 18.1
      Starting the Process
    • 18.2
      Frameworks: ISA/IEC 62443, ISO/IEC 27001, NIST CSF
    • 18.3
      Using the NIST CSF
  • 3
    • 19.1
      Policies, Standards, Guidance, and Procedures
    • 19.2
      Culture and Enforcement
    • 19.3
      Examples
  • 2
    • 20.1
      Quantitative vs Qualitative
    • 20.2
      Traditional Models
  • 4
    • 21.1
      Digital forensics
    • 21.2
      Key focus
    • 21.3
      Key sources
    • 21.4
      Analyze digital evidence

Instructeur

Avatar de l’utilisateur

bprigent

0.0
0 commentaire
0 Students
840 Courses