Industrial (ICS/OT) Cyber Security Certifications

preview_player
Показать описание
One of the most common questions I get is on ICS/OT cyber security certifications.

I am very fortunate to work for a company that has invested in me to take the ISA IEC 62443 and SANS courses.

And yes, I have all the certs.

A few things to remember about certifications:

- Do not replace experience
- Not all require you to take a course
- Can accelerate the learning curve for you
- Can help you demonstrate your knowledge
- Can assist in you standing out for hiring managers

Here is how I explain the main ones:

1. ISA 62443 Cybersecurity Expert Series

The ISA 62443 standard is considered the gold framework for securing ICS OT networks.

ISA (International Society of Automation) put together a course to help others:

- Understand how to implement ISA 62443
- The fundamentals of cyber security in ICS OT

Passing all four ISA courses will reward you with the “ISA IEC 62443 Cybersecurity Expert” certification.

The Expert certification is seen by some as the "CISSP of the ICS OT world."

NOTE: The cert does not make you an expert, but it is a great place to start!

Unfortunately, you must take each course before taking the corresponding exam.

These are often considered more affordable and cost effective than...

2. SANS ICS OT Certifications
The heavy weight of the ICS - OT cyber security space in terms of knowledge.

Sadly, each course and exam cost ~$10,000 USD to take.

The price puts these courses out of reach for a lot of people.

Each of the courses provide great value, depending on where you are at in your career:

- GICSP: Focuses on the fundamentals of ICS OT cyber security
- GRID: Built by Rob Lee to help others understand how to defend their ICS OT networks
- GCIP: Covers how cyber security regulation is met in the North American power industry

NOTE #2: Rob Lee still teaches the GRID course occasionally. Be sure to take it with him!

(No offense to the other instructions, but I’m sure they would agree with me).

3. Other Provider Certifications
Other providers make more affordable options available.

The providers I hear about the most in this space are Exida and TUV.

I do not have any experience with either.

Yet!

What else am I missing in the ICS OT cyber certification world?
Рекомендации по теме
Комментарии
Автор

Great summary, Mike. Thank you for all that you do for the ICS/OT world!

MauricedelPrado
Автор

Thanks for this Mike, I followed you here from LinkedIn as I'm about to branch into a ICS/OT career and saw a couple of your posts talking about OT cyber security.

kayobGH
Автор

Sir thanks for the video please make more videos for electrical engineers who has experience in the electrical and want to transition to ics/ot

LoneWolf-rohn
Автор

Thank you Mike, This is absolute helpful.. i have some in my mind to complete this year like ISC2'24, N.W Security and 63443

adityaarya
Автор

Mike, minor typo in your description / write-up above... you have...

"- GRID: Built by Rob Lee to help others understand how to defender their ICS OT networks"

I think you meant "defend" and not "defender".

MauricedelPrado
Автор

Thanks for the info. What’s duration of these courses ISA & SANS ??

mohammedkhaja
Автор

Thank you Mike ! Very nice content! What people that have experience and skills in both IT & ICS but dont still take any certification, should they do ?

ahmedt
Автор

Good evening Sir. I just would like to ask what do you recommend a chemical engineer should do out of all the cybersecurity modules, projects and certifications ? A career that unites both the fields?

MOLEFIJOHANNESNETE
Автор

I was hoping to take the fundamental course without the exam, i infer this is not possible.

rodneydias
welcome to shbcf.ru