Cybersecurity Fundamentals & OT/IT Segmentation
This course covers cybersecurity fundamentals aligned to CompTIA Security+ objectives, applied specifically to the operational technology (OT) that runs a data center's building management system, electrical switchgear, and mechanical plant. It is not a generic IT-security survey. Students apply the Purdue Enterprise Reference Architecture to classify BMS, DCIM, and SCADA-class controllers into levels 0 through 5, then design IEC 62443 zones and conduits with security-level targets for a representative data-center control network. NIST SP 800-82 Rev. 3 guidance on OT risk assessment, network segmentation, and the industrial DMZ is applied to a mock BMS network, including firewall and data-diode placement between operations and enterprise tiers. Students also cover core Security+ domains — threats, cryptography, identity and access management, and incident response — and configure segmentation controls on a training network. The course culminates in a segmented network design exercise defended in an oral review, distinguishing this course from general IT helpdesk security training.
What you'll be able to do
- Classify data-center control-system assets into Purdue model levels 0 through 5.
- Define IEC 62443 zones and conduits for a data-center BMS network with target security levels.
- Configure a firewall rule set to enforce an industrial DMZ between the operations-management level and the enterprise network per NIST SP 800-82 Rev. 3 guidance. Safety-critical
- Segment a BMS VLAN from the corporate IT VLAN on a managed switch to enforce least-privilege communication. Safety-critical
- Conduct an OT-specific risk assessment scoring safety, production, and environmental impact per NIST SP 800-82 Rev. 3 Section 4 methodology.
- Configure multi-factor authentication and role-based access control for a DCIM administrative account.
- Identify indicators of compromise in OT network traffic logs distinct from typical IT network anomalies.
- Apply symmetric and asymmetric cryptography concepts to secure BMS-to-cloud telemetry transport.
- Draft an incident-response runbook step for isolating a compromised BMS segment without disrupting safety-critical control loops. Safety-critical
- Escalate a suspected OT security incident to the correct internal and external parties per a documented incident-response plan. Safety-critical
- Harden a BMS controller configuration by disabling unused services and default credentials. Safety-critical
- Interpret a vulnerability scan report against OT-specific patching constraints and prioritize remediation.
- Design a segmented network diagram for a full data-center site integrating IT, BMS, and physical-security subsystems.
- Verify segmentation control effectiveness through a supervised penetration test against the training BMS VLAN. Safety-critical
Train the team that runs the factory.
The Institute travels with every SAVRN campus.