![]() Use active defense concepts such as threat intelligence consumption, network security monitoring, malware analysis, and incident response to safeguard the ICS.Examine ICS networks and identify the assets and their data flows in order to understand the network information needed to identify advanced threats.Use proper procedures during ICS incident response.Establish collection, detection, and response strategies for your ICS networks.Analyze ICS-specific threats and take proper courses of action to defend the industrial control systems.How to use multiple security disciplines in tandem to leverage an active defense and safeguard an ICS, all reinforced with hands-on labs and technical concepts.How to operate through an attack and gain the information necessary to instruct teams and decision-makers on whether operations must shut down or it is safe to respond to the threat and continue operations.How to analyze ICS threats and extract the most important information needed to quickly scope the environment and understand the nature of the threat.The course will introduce and reinforce methodologies such as ICS network security monitoring and approaches to reducing the control system threat landscape. How to identify ICS assets and their network topologies and how to monitor ICS hotspots for abnormalities and threats.The analysis skills you learn will enable you to critically analyze and apply information from ICS threat intelligence reports on a regular basis. ![]() How ICS threat intelligence is generated and how to use what is available in the community to support ICS environments.How to perform ICS incident response focusing on security operations and prioritizing the safety and reliability of operations.The strategic and technical skills presented in this course serve as a basis for ICS organizations looking to show that ICS defense is do-able. Frameworks such as the ICS Cyber Kill Chain, Collection Management Framework, and Active Cyber Defense Cycle will be taught to give students repeatable frameworks and models to leverage post class. Students will gain a practical and technical understanding of defining an ICS cybersecurity strategy, leveraging threat intelligence, performing network security monitoring, and performing incident response. Students will spend roughly half the course performing hands on skills across more than 25 technical exercises and an all day technical capstone. Students will also interact with and keep a programmable logic controller (PLC), physical kit emulating electric system operations at the generation, transmission, and distribution level, and virtual machine set up as a human machine interface (HMI) and engineering workstation (EWS). The course uses a hands-on approach with numerous technical data sets from ICS ranges and equipment with emulated attacks and real world malware deployed in the ranges for a highly simulated experience detecting and responding to threats. Students can expect to come out of this course with core skills necessary for any ICS cybersecurity program. In addition, the efforts are also critical to understanding and running a modern day complex automation environment and achieving root cause analysis for non cyber-related events that manifest over the network. This approach is important to being able to counter sophisticated threats such as those seen with malware including STUXNET, HAVEX, BLACKENERGY2, CRASHOVERRIDE, TRISIS/TRITON, and ransomware. The course will empower students to understand their networked ICS environment, monitor it for threats, perform incident response against identified threats, and learn from interactions with the adversary to enhance network security. ICS515: ICS Visibility, Detection, and Response will help you gain visibility and asset identification in your Industrial Control System (ICS)/Operational Technology (OT) networks, monitor for and detect cyber threats, deconstruct ICS cyber attacks to extract lessons learned, perform incident response, and take an intelligence-driven approach to executing a world-leading ICS cybersecurity program to ensure safe and reliable operations. Immediately apply the skills and techniques learned in SANS courses, ranges, and summits
0 Comments
Leave a Reply. |