BSE 103: OT/SCADA Security Fundamentals

Current Status

Not Enrolled

Price

Free

Get Started

How to read this course. BSE 103 (OT/SCADA Security Fundamentals) is written for the community’s utility and water leads at the moment a resilience program starts asking how safe the control systems are. BSE 105 (Shadow Grid & Energy Independence) taught the community to build and operate its own generation, storage, and islanding — the power architecture. This course teaches something adjacent and distinct: the security of the controls, sensors, and relays that run that equipment. Operational technology (OT) is the computing that senses and acts on the physical world — the programmable logic controllers (PLCs), the supervisory control and data acquisition (SCADA) systems, the sensors and actuators — and its security follows different rules than the information technology (IT) security most people know. You will learn why those rules invert, where the trusted inputs live in the Purdue model, why putting the OT network behind a boundary both protects it and hides it from IT, why the sensor layer is the gap most defenders miss, what the landmark attacks actually teach, how undocumented functionality reaches the hardware, why weak and unchangeable credentials persist, and what a defensive program looks like at planning depth. The governing doctrine is awareness, not access, and its load-bearing boundary is that no security testing, intrusion attempt, or incident response outside qualified, authorized OT-security engagement, ever. This course does not teach you to test or operate on live control systems; it teaches you to understand, specify, segment, procure, and route. Everything here is planning-depth understanding — what the pieces are, why the exposures exist, and what the architecture must specify. None of it is instruction to perform an attack or to test a live system.

Control-system exposure, default-credential failures, and the hardening that keeps utilities and water systems running (Energy / Utility domain module; hard prerequisites: the 099 -> 100 -> 101 -> 102 foundation chain and the Common Paid Core of BSE 104 and GOV 106/107/108 — the Track B pattern; BSE 105 (Shadow Grid & Energy Independence) is advisory, not required: its power-architecture fundamentals are the natural companion, and this course secures the very equipment 105 teaches communities to field). Written for the community’s utility and water leads, the course teaches why operational technology (OT) security is different from information technology (IT) security, where the trusted inputs live in the Purdue model, why segmentation both protects the OT network and blinds IT to it, why Level 0 sensor trust is the gap most defenders miss, what the landmark attacks (Stuxnet and Aurora) actually teach, how supply-chain and undocumented functionality reach the equipment, why default and unchangeable credentials remain a live failure, and what a community defensive program looks like at planning depth. The governing doctrine is awareness, not access: this course builds defensive awareness, architecture, and planning, and it never teaches attack technique; its taught corollary is report, don’t respond — a suspected incident is reported and routed, never self-handled. The load-bearing boundary is that no security testing, intrusion attempt, or incident response happens outside qualified, authorized OT-security engagement, ever: security engineering, penetration testing, and incident response route to qualified OT-security professionals, and the course teaches the community to specify, procure, segment, and route — not to operate on live control systems. The governing rule is that no security testing, intrusion attempt, or incident response outside qualified, authorized OT-security engagement, ever. Audience: utility and water leads. Even-handedness is a design property: Level 0 is taught with the reasonable counter-position that network and Level 1/2 controls deserve first priority, the contested supply-chain episodes are presented as contested, and out-of-band monitoring is taught as a concept class with a government and engineering-doctrine anchor, never as a product endorsement.

Before any assessment, testing, or response on a live control system. This course teaches defensive awareness, architecture, and planning only. It is not instruction to test, probe, or operate on any operational technology (OT) or supervisory control and data acquisition (SCADA) system, and it does not teach attack technique. The governing boundary is that no security testing, intrusion attempt, or incident response outside qualified, authorized OT-security engagement, ever: security engineering, penetration testing, and incident response belong to qualified, authorized OT-security professionals and the asset owner’s established processes. Awareness, not access: a suspected incident is reported and routed, never self-handled. Where a decision touches law, contracts, or a live utility or water system, it routes to counsel and to the qualified professionals named throughout this course.

Course Content

BSE 103 · L1: Why OT Security Is Its Own Discipline
BSE 103 · L3: Segmentation and the Visibility Boundary 1 Quiz
BSE 103 · L7: Supply Chain and Undocumented Functionality 1 Quiz
BSE 103 · L10: Capstone — Harden the Island 1 Quiz
BSE 103 – Comprehensive Final