PACKROSE ASSOCIATES

TRAINING

PROCESS CONTROL CYBERSECURITY

Designed for learning. Built for impact.

Objective:

  • Identify critical process control assets and understand the importance of protecting industrial control systems
  • Understand the current industrial cyber security landscape and emerging threats to process control environments
  • Apply the principles and requirements of the IEC 62443 cyber security standard for Industrial Automation and Control Systems (IACS)
  • Conduct risk assessments and implement effective cyber security countermeasures to protect industrial operations
  • Perform application diagnostics, troubleshooting, incident response, and system recovery to maintain secure and reliable operations

Content:

Introduction to Process Control Cyber Security

  • Introduction to process control cyber security
  • Understanding the current industrial security environment
  • Comparing Information Technology (IT) and Operational Technology (OT)
  • Overview of process control systems
  • Industrial communication systems and network architecture
  • Understanding cyber threats, vulnerabilities, and attack methods
  • Asset identification and impact assessment

IACS Cyber Security Lifecycle and IEC 62443

  • Understanding the IACS cyber security lifecycle
  • Identification and assessment phase
  • Design and implementation phase
  • Operations and maintenance phase
  • Limitations of conventional IT security approaches
  • Applying the IEC 62443 security framework and standards
  • Risk identification, classification, and assessment
  • Cyber Security Assurance Levels (CAL)
  • Functional requirements of IEC 62443

Managing Security Risks in Process Control Systems

  • Implementing antivirus and anti-spyware protection
  • Using firewalls and network traffic analysis tools
  • Applying encryption and Virtual Private Networks (VPNs)
  • Managing authentication and password security
  • Implementing access control and intrusion detection/prevention systems
  • Applying network segmentation for enhanced security

Application Diagnostics and System Troubleshooting

  • Interpreting device alarms and event logs
  • Identifying early warning indicators of system issues
  • Using network intrusion detection systems
  • Applying network management and monitoring tools
  • Interpreting operating system and application event logs
  • Managing application whitelisting and endpoint protection
  • Using Security Information and Event Management (SIEM) tools

IACS Operating Procedures and Incident Response

  • Developing and implementing IACS management of change procedures
  • Using IACS configuration management tools
  • Managing patch deployment, antivirus updates, and cyber security audits
  • Applying patch management and application whitelisting tools
  • Conducting cyber security audits using specialized tools
  • Developing and implementing an IACS incident response plan
  • Performing incident investigation and system recovery

For Whom:

  • Process Control Operators, Engineers, and Supervisors
  • Operations and Maintenance Personnel
  • Process, Plant, and Project Managers
  • Instrumentation Engineers and Technicians
  • System Integrators and Automation Engineers
  • IT/OT Engineers, Cyber Security Professionals, and Industrial Network Administrators
  • Plant Safety, Security, and Risk Management Professionals
  • Anyone responsible for securing Industrial Automation and Control Systems (IACS)