
Contents of course and what we will learn in this course!
Will learn about types of OT systems and there interdependencies, also will see one use case of interdependent system.
About basic network and communication of SCADA systems.
This chapter includes details of DCS and its basic communication architecture.
This chapter includes details of PLC and its basic communication architecture.
This chapter includes details of BACS and its basic communication architecture.
This chapter includes details of physical access control system and its basic communication architecture.
In this chapter we will learn about SIS and Safety Systems
This chapter includes details of IIOT and its basic communication architecture.
To mitigate cybersecurity risk to their OT systems, organizations need to develop and deploy an OT cybersecurity program. We will learn bout program.
A charter for a cybersecurity program is a plain-language high-level description that establishes clear ownership and accountability for protecting the OT resources . We will learn about charter.
What are benefits of cybersecurity program? Lets learn!
Learn about contents of a cybersecurity program.
The risk management process and framework outlined in this section can be applied to managing safety, information security, and cyber supply chain risk. Lets learn about it.
We will learn about framing cybersecurity risk!
We will learn about the assessing risk.
How to respond the cybersecurity incident, that we will learn in this chapter.
Continuously monitor risk by tracking asset changes and selecting suitable monitoring techniques, balancing active and passive approaches. Prioritize threats by likelihood and impact to guide security measures and protect availability.
In this chapter we will learn about application of risk management in the OT cybersecurity enviroment.
Lets see what is prepare pahse!
Develop a company-wide risk management strategy by creating a plan to identify, assess, and establish risk tolerance, especially for machinery control systems and proprietary computers, while aligning safety regulations.
Review and update the organization's risk assessment, checking the entire company for risks and refreshing any existing risk list to serve as a health check of safety.
Develop organizationally tailored control baselines and cybersecurity framework profiles to create customized safety guidelines aligned with a company's technologies, infrastructure, and business requirements.
Identify and rank systems by criticality ratings for PLCs and network devices, define impact levels, and prioritize actions based on safety and essential services.
Define the system’s mission by listing goals, operations, and processes, then map ot–it connections and how information flows under guiding rules to support inventory, maintenance, and supply chains.
Identify and list all system stakeholders with vested interest, including plant manager, process control engineer, operator, functional safety engineer, and process safety manager, ensuring their input and needs are considered.
Identify OT assets vital to stakeholders and rank them by significance using a criticality rating, then compile a physical and software asset list including I/O cards and DCS.
Identify and categorize operational technology information types, including process data and historian data. Determine whether confidentiality or integrity is priority and apply protections such as encryption or signature-based authentication.
Understand the information life cycle from creation to disposition, detailing processing, storage, transmission, use, and disposal, while aligning retention time with data security, integrity, and availability.
Conduct a comprehensive risk assessment of OT systems, evaluating vulnerabilities and potential threats. Update or create a new risk assessment, and include performance, loading, penetration tests, or audits where feasible.
Assess whether a system fits the enterprise architecture by categorizing components by function and data sensitivity, and implement the Purdue model from level zero to four to apply security controls.
Now once we are prepared , lets move to categorize!!
Determine a system’s security level through categorization based on the information it handles. Align findings with the company’s risk strategy and assign labels for operator, engineering, calibration, and grid-related systems.
Time to select the initial set of cybersecurity controls for implementation in the OT enviroment
Allocate security controls across the system, ensuring suitable protection for all zones and aligning with enterprise architecture levels, then assess and allocate controls at both system and component levels.
Document planned control implementations with formal records and versioning for security controls and their customizations. Track changes such as antivirus upgrades or siem parsers to support security assessment.
Implement a continuous monitoring strategy as a periodic, continuous audit of system risk, focusing on new vulnerabilities and critical, high-availability systems via centralized security dashboards.
Time to implement the selected controls!
Now assess again what is working what is not!
Select an independent assessor or assessment team with OT expertise to evaluate controls and ensure credibility. Prefer a third-party, oil and gas experienced assessor, supported by operators, engineers, and technicians.
Define and execute the assessment plan for ICS/OT cybersecurity by documenting scope and system context, developing and reviewing a detailed plan with stakeholders, and setting success criteria and roadmaps.
Craft a plan of action and milestones to remediate unacceptable risks, detailing antivirus updates, centralized application whitelisting for additional systems, and maintenance and shutdown constraints within the risk framework.
Authorisation is required for all the activities, lets learn about it!
Analyze risk and determine risk tolerance to shape the organization's risk management strategy. In a factory example, defend against unauthorized remote access with firewalls, two-factor authentication, and regular vulnerability assessments.
Continuous monitoring is required for continuous improvent in the risk management.
Implement continuous 24/7 monitoring of systems and environments with dedicated personnel to detect changes and unusual activities. Ensure secure, correct operation across control networks, exemplified by water treatment plant software.
Monitor systems continuously to enable ongoing risk response, detect anomalies or deviations from baseline, and act using risk checks, threat hunting, and incident correlation informed by security camera alerts.
Establish a method to report security and privacy performance to top management, showing how well we keep information secure and private, with a weekly, biweekly, or monthly cadence.
Task M6 on ongoing authorization uses continuous monitoring to inform risk-based approval decisions, enabling risk managers to adjust controls and ensure safe cybersecurity operation of the plant.
Plan and execute safe disposal or replacement of legacy systems, software, licenses, credentials, and hardware. Prepare long-term parts stock to mitigate security risks and environmental impact.
We will leanr about, what is defense in depth and how it can be done.
We will learn about Layer 1 security requirements.
We will learn about the Layer 2 requirements for defense in depth architecture.
We will learn about the Layer 3 requirements for defense in depth architecture.
We will learn about the Layer 3 requirements for defense in depth architecture.
We will learn about the central logging requirements for defense in depth architecture.
We will learn about the network monitoring for defense in depth architecture.
We will learn about the Zero trust architecture.
We will learn about the Layer 4 requirements for defense in depth architecture.
We will learn about the Layer 5 requirements for defense in depth architecture.
We will learn about the additional consideration requirements for defense in depth architecture.
We will learn about the the transformation of DCS architecture with defense in depth principles.
We will learn about the the transformation of DCS /PLC architecture with defense in depth principles.
We will learn about the the transformation of SCADA architecture with defense in depth principles.
ABout firewall and type of firewall.
Have you heard about datadiode, lets learn!
Everyone knows VLAN, so just revise it!
What is software define networking? How it works?
Anomaly detection? Data loass prevention: Lets learn!
Learn about network monitoring and deception technologies?
Lets continue learning data security!
We can use digital signatures as well for security requiremnet and validation!
What we learn in past few hours , lets see!
*LEARN NIST 800-82 STANDARDS FOR IACS*
CAUTION: "DO NOT BUY IF YOU DON'T LIKE THEORETICAL COURSE"
Industrial cybersecurity is based on the NIST guidelines. OT is critical to the operation of critical infrastructures, which are often highly interconnected, mutually dependent systems. It is important to note that while federal agencies operate many of the nation’s critical infrastructures, many others are privately owned and operated.
This course was created after thoroughly understanding and practically implementing it in the OT environment, so this 6-hour course is a summarized version of the NIST 800-82 standard. It will help to understand what it contains and how it should be understood. So, the following are the basic topics that we will cover in this course:
1. OT Overview: DCS/PLC/PLC/BACS/PACS
2. About Cybersecurity program development
3. Risk Management for OT systems
4. OT Cybersecurity Architecture
5. Cybersecurity Framework
6. OT Security capabilities and tools
After finishing this course, you will have the following understanding:
1. Good grasp of NIST 800-82 Standard
2. What technologies are required for securing an OT infrastructure.
3. What is the cybersecurity framework
4. What to do to achieve defense in depth architecture
5. Why cybersecurity program is required and how to set up
6. Feel confident about referring standards in professional discussions
7. Will help in cracking interviews
This course provides guidance for establishing secure operational technology (OT) while addressing OT’s unique performance, reliability, and safety requirements. OT encompasses a broad range of programmable systems and devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems and devices detect or cause a direct change through monitoring and/or control of devices, processes, and events.
* If video seems fast try playing at 0.75x speed
* Connect to me on Linkedin/ or visit cyberotsecure{dot}com website to get discounts.*