Cybersecurity Fundamentals & OT/IT Segmentation

Advanced · SEC
128Total hours
48Lecture
80Hands-on lab
SEC 1701; CORE 1003Prerequisite
CompTIA Security+Credential
80 lab hours 48 lecture hours

This course covers cybersecurity fundamentals aligned to CompTIA Security+ objectives, applied specifically to the operational technology (OT) that runs a data center's building management system, electrical switchgear, and mechanical plant. It is not a generic IT-security survey. Students apply the Purdue Enterprise Reference Architecture to classify BMS, DCIM, and SCADA-class controllers into levels 0 through 5, then design IEC 62443 zones and conduits with security-level targets for a representative data-center control network. NIST SP 800-82 Rev. 3 guidance on OT risk assessment, network segmentation, and the industrial DMZ is applied to a mock BMS network, including firewall and data-diode placement between operations and enterprise tiers. Students also cover core Security+ domains — threats, cryptography, identity and access management, and incident response — and configure segmentation controls on a training network. The course culminates in a segmented network design exercise defended in an oral review, distinguishing this course from general IT helpdesk security training.

What you'll be able to do

  1. Classify data-center control-system assets into Purdue model levels 0 through 5.
  2. Define IEC 62443 zones and conduits for a data-center BMS network with target security levels.
  3. Configure a firewall rule set to enforce an industrial DMZ between the operations-management level and the enterprise network per NIST SP 800-82 Rev. 3 guidance. Safety-critical
  4. Segment a BMS VLAN from the corporate IT VLAN on a managed switch to enforce least-privilege communication. Safety-critical
  5. Conduct an OT-specific risk assessment scoring safety, production, and environmental impact per NIST SP 800-82 Rev. 3 Section 4 methodology.
  6. Configure multi-factor authentication and role-based access control for a DCIM administrative account.
  7. Identify indicators of compromise in OT network traffic logs distinct from typical IT network anomalies.
  8. Apply symmetric and asymmetric cryptography concepts to secure BMS-to-cloud telemetry transport.
  9. Draft an incident-response runbook step for isolating a compromised BMS segment without disrupting safety-critical control loops. Safety-critical
  10. Escalate a suspected OT security incident to the correct internal and external parties per a documented incident-response plan. Safety-critical
  11. Harden a BMS controller configuration by disabling unused services and default credentials. Safety-critical
  12. Interpret a vulnerability scan report against OT-specific patching constraints and prioritize remediation.
  13. Design a segmented network diagram for a full data-center site integrating IT, BMS, and physical-security subsystems.
  14. Verify segmentation control effectiveness through a supervised penetration test against the training BMS VLAN. Safety-critical

Train the team that runs the factory.

The Institute travels with every SAVRN campus.

Engage SAVRN → Open the catalog