Group Purchasing
Group Purchasing

ICS410: ICS/SCADA Security Essentials

ICS410Industrial Control Systems Security
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Justin Searle
Justin Searle
Course authored by:
Justin Searle
Justin Searle
  • GIAC Global Industrial Cyber Security Professional (GICSP)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Essential Skill Level

    Course material is for individuals with an understanding of IT or cyber security concepts

  • 15 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Reinforce critical cybersecurity skills to secure industrial control systems and operational technology against emerging threats while maintaining operational resilience in industrial environments.

Course Overview

Operational Technology (OT) environments face a growing wave of sophisticated cyber threats, yet many organizations rely on IT-centric security measures ill-suited to the distinct challenges of Industrial Control Systems (ICS) and SCADA systems. The absence of specialized knowledge and practical expertise in ICS/OT cybersecurity leaves critical infrastructure exposed, increasing the risk of operational disruptions, financial losses, and safety incidents.

This course builds on foundational ICS cybersecurity principles to provide industrial cybersecurity professionals with the advanced skills necessary to secure OT environments effectively. By focusing on the unique demands of industrial systems, the SCADA security training course equips both IT and OT cybersecurity professionals to address emerging threats, ensuring the safety, security, and resilience of critical infrastructure with minimal operational impact. This course is also a key preparation path for individuals pursuing the GICSP certification (Global Industrial Cyber Security Professional), a leading ICS cyber security certification that validates real-world, cross-disciplinary expertise in securing industrial systems.

This is the ICS/OT-specific training needed to defend the critical systems the world relies on.

Critical infrastructure and key resource sectors face a rapidly evolving threat landscape, where cyberattacks can disrupt essential services, compromise safety, and cause significant economic and operational harm. Professionals who operate, manage, design, implement, monitor, and defend control systems are at the forefront of this challenge. This course is designed specifically for these practitioners, providing the essential skills and knowledge needed to secure and support control systems in high-stakes environments. Whether you're new to the field or looking to advance your career with an ICS cyber security certification, ICS410 equips professionals to address the day-to-day security needs of critical infrastructure—ensuring resilience, safety, and operational continuity. It's also an excellent foundation for those seeking SCADA security certification to validate their specialized skills in this space.

This course will provide you with:

  • An understanding of industrial control system components, purposes, deployments, significant drivers, and constraints
  • Hands-on lab learning experiences to control system attack surfaces, methods, and tools
  • Control system approaches to system and network defense architectures and techniques
  • Incident-response skills in a control system environment
  • Governance models and resources for industrial cybersecurity professionals

With the dynamic nature of industrial control systems, many professionals in these environments do not fully understand the features and risks of many devices. In addition, IT support personnel who provide the communications paths and network defenses do not always grasp the systems' operational drivers and constraints. This course is designed to help traditional IT personnel fully understand the design principles underlying control systems and how to support those systems in a manner that ensures availability and integrity. In parallel, the course addresses the need for control system engineers and operators to better understand the important role they play in cybersecurity. This starts by ensuring that a control system is designed and engineered with cybersecurity built into it, and that cybersecurity has the same level of focus as system reliability throughout the system lifecycle.

When these different groups of professionals complete this course, they will have developed an appreciation, understanding, and common language that will enable them to work together to secure their industrial control system environments. The course will help develop cyber-secure-aware engineering practices and real-time control system IT/OT support carried out by professionals who understand the physical effects of actions in the cyber world. Completing this course also supports preparation for the GICSP certification, a globally recognized ICS cyber security certification that strengthens your professional standing in both IT and OT domains.

Skills Acquired

  • Understand industrial control systems, their components, communications (including IP and industrial protocols), and dependencies across the ICS lifecycle
  • Design secure ICS network architectures using principles from IEC 62443, the Purdue Model, and other foundational frameworks
  • Analyze host and network activity using Windows and Linux command-line tools, and automate monitoring with basic scripting
  • Detect and respond to ICS-specific threats using intrusion detection systems, logging, and network monitoring techniques
  • Implement effective incident response and handling methodologies tailored for industrial control systems
  • Apply information assurance principles and map ICS/OT technologies, threats, and defenses to key cybersecurity frameworks (NIST CSF, ISA/IEC 62443, CIS Controls, ISO/IEC 27001, NIST SP 800-53, COBIT 5)
  • Evaluate and improve the security posture of ICS environments through governance, standards alignment, and lifecycle management

Author Statement

"This course provides students with the essentials for conducting cybersecurity work in industrial control system environments. After spending years working with industry, we believe there is a gap in the skill sets of industrial control system personnel, whether it be cybersecurity skills for engineers or engineering principles for cybersecurity experts. In addition, both information technology and operational technology roles have converged in today's industrial control system environments, so there is a greater need than ever for a common understanding between the various groups who support or rely on these systems. Students in ICS410 will learn the language, the underlying theory, and the basic tools for industrial control system security in settings across a wide range of industry sectors and applications."

- Justin Searle

What You'll Learn

  • Understand ICS components and protocols
  • Design secure ICS network architectures
  • Analyze activity with command-line tools
  • Detect and respond to ICS threats
  • Handle ICS-specific incidents effectively
  • Map ICS to cybersecurity frameworks
  • Improve ICS security through governance

Business Takeaways

  • Protect industrial and critical infrastructure systems against emerging threats
  • Bridge gaps between IT security and operational technology
  • Reduce risk of operational disruption from cyberattacks
  • Comply with industry regulations and best practices
  • Secure industrial networks without compromising function
  • Implement effective incident response for OT environments
  • Develop comprehensive industrial security programs

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in ICS410: ICS/SCADA Security Essentials.

Section 1ICS Overview

Develop a common understanding of ICS cybersecurity with emphasis on cyber-to-physical operations. Students receive programmable logic controller (PLC) devices to keep, allowing practical exploration of the cyber-physical interface. This section covers essential terminology, architectures, methodologies, and devices used across different industrial sectors.

Topics covered

  • Global Industrial Cybersecurity Professional (GICSP) Overview
  • ICS processes, roles, and industries
  • Controllers and field devices
  • HMIs, historians, and SCADA systems
  • IT and ICS differences

Labs

  • Learning from industry peers
  • Programming a PLC
  • Programming an HMI
  • Analyzing physical and cyber security

Takeaway

Students will develop and reinforce a common language and understanding of Industrial Control System (ICS) cybersecurity as well as the important considerations that come with cyber-to-physical operations within these environments. Each student will receive a programmable logic controller (PLC) device to keep. The PLC contains physical inputs and outputs that will be programmed in class and mapped to an operator interface, or HMI, also created in class. This improved hardware-enabled approach provides the necessary cyber-to-physical knowledge that allows students to better understand important ICS operational drivers and constraints that require specific safety protection, communications needs, system management approaches, and cybersecurity implementations. Essential terms, architectures, methodologies, and devices are all covered to build a common language for students from a variety of different roles.

Full Topic Details

  • Day 1 ICS Overview
  • Global Industrial Cybersecurity Professional (GICSP) Overview
  • Overview of ICS
    • Processes & Roles
    • Industries
    • Exercise: Learning from Peers
  • Purdue Levels 0 and 1
    • Controllers and Field Devices
    • Programming Controllers
    • Exercise: Programming a PLC
  • Purdue Levels 2 and 3
    • HMIs, Historians, Alarm Servers
    • Specialized Applications and Master Servers
    • Control Rooms and Plants
    • SCADA
    • Exercise: Programming an HMI
  • IT & ICS Differences
    • ICS Life Cycle Challenges
  • Physical and Cyber Security

Section 2Architectures and Processes

Learn defensive approaches by understanding adversarial tactics against ICS environments. Examine attack vectors specific to industrial systems, particularly at Purdue Levels 0 and 1. Investigate technologies and communications that distinguish control systems from IT networks, with hands-on experience capturing fieldbus traffic from PLCs.

Topics covered

  • ICS attack surface analysis
  • Secure network architectures
  • Purdue Level 0/1 technologies
  • Fieldbus protocol families
  • Safety Instrumented Systems (SIS)

Labs

  • Identifying external attack surfaces
  • Architecting secure ICS sites
  • Finding passwords in EEPROM dumps
  • Exploring fieldbus protocols
  • Implementing defensive controls

Takeaway 

If you know the adversary's approaches to attacking an ICS environment, you will be better prepared to defend that environment. Numerous attack vectors exist within an ICS environment. Some are similar to traditional IT systems, while others are more specific to ICS. During Day 2, students will develop a better understanding of where these specific attack vectors exist and more defensible architectures for OT/ICS. Students will look at different technologies and communications used in Perdue Levels 0 and 1, the levels that are the most different from an IT network. Students will capture fieldbus traffic from the PLCs they programmed in day 1 and look at what other fieldbus protocols used in the industry.

Full Topic Details

  • Day 2: Field Devices and Controllers
    • ICS Attack Surface
      • Threat Actors and Reasons for Attack
      • Attack Surface and Inputs
      • Vulnerabilities
      • Threat/Attack Models
      • Information Leakage
      • Exercise: Identifying External Attack Surfaces
    • Secure ICS Network Architectures
      • ICS410 Reference Model
      • Larger ICS Sites
      • Remote Access
      • Regional SCADA
      • Exercise: Architecting a Secure ICS Site
    • Purdue Level 0 and 1
      • Purdue Level 0 and 1 Attacks
      • Control Things Platform
      • Exercise: Passwords in EEPROM Dumps
      • Purdue Level 0 and 1 Technologies
      • Fieldbus Protocol Families
      • Exercise: Exploring Fieldbus Protocols
      • Purdue Level 0 and 1 Defenses
      • Safety Instrumented Systems (SIS)

Section 3Communications and Protocols

Analyze network communication protocols and examine network captures of control protocols traversing Ethernet and TCP/IP networks. Learn segmentation methods and traffic flow control for industrial networks. Explore cryptographic concepts for protecting communications and sensitive data, plus wireless technologies used in control systems.

Topics covered

  • Ethernet and TCP/IP concepts
  • ICS protocols and wireshark analysis
  • Enforcement zone devices
  • Basic cryptography for ICS
  • Wireless technologies and defenses

Labs

  • Network capture analysis
  • Enumerating Modbus TCP
  • Setting up NextGen firewalls
  • Manual cryptography
  • Wireless security assessment

Takeaway

Day 3 will take students through the communication protocols often found throughout control networks. Students will analyze network captures containing other control protocols that traverse Ethernet-only networks and TCP/IP networks, set up a simulated controller, and interact with it through a control protocol. Students will learn about different methods to segment and control the flow of traffic through the control network. Students will explore cryptographic concepts and how they can be applied to communications protocols and on devices that store sensitive data. Students will learn about the risks of using wireless communications in control networks, which wireless technologies are commonly used, and available defenses for each.

Full Topic Details

  • Day 3: Supervisory Systems
    • Ethernet and TCP/IP
      • Ethernet Concepts
      • TCP/IP Concepts
      • Exercise: Network Capture Analysis
      • ICS Protocols over TCP/IP
      • Wireshark and ICS Protocols
      • Attacks on Networks
      • Exercise: Enumerating Modbus TCP
    • Enforcement Zone Devices
      • Firewalls and NextGen Firewalls
      • Modern Data Diodes
      • NIDS/NIPS and Netflow
      • USB Scanning and Honeypots
    • Understanding Basic Cryptography
      • Crypto Keys
      • Encryption, Hashing, and Signatures
      • Exercise: Manual Cryptography
    • Wireless Technologies
      • Satellite and Cellular
      • Mesh Networks and Microwave
      • Bluetooth and Wi-Fi
    • Wireless Attacks and Defenses
      • 3 Eternal Risks of Wireless
      • Sniffing, DoS, Masquerading, Rogue AP

Section 4Supervisory Systems

Explore essential server and workstation operating systems for ICS environments. Perform network forensics to track attackers from phishing to HMI breach. Examine technologies at Purdue Levels 2 and 3, including HMI and historian systems. Learn to create baselines and secure Windows-based workstations and servers in industrial environments.

Topics covered

  • Supervisory server attacks
  • HMI and UI vulnerabilities
  • Windows defense strategies
  • Patching decision frameworks
  • Security policy implementation

Labs

  • Bypassing auth with SQL injection
  • Password fuzzing techniques
  • Baselining with PowerShell
  • Host firewall configuration
  • Windows event log analysis

Takeaway

Students will learn essential ICS-related server and workstation operating system capabilities, implementation approaches, and system management practices. After a hand-on network forensics exercise where students follow an attacker from phishing campaign to HMI breach, students will look at HMI, historian, and user interface technologies used in the middle to upper levels of the control network, namely Perdue Levels 2 and 3, while performing attacks on HMI web technologies and interfaces susceptible to password brute force attacks. In the afternoon, Students will learn about how to create baselines and secure Windows-based workstation and servers.

Full Topic Details

  • Day 4: Workstations and Servers
    • Supervisory Servers
      • Supervisory Attacks
      • Historians and Databases
      • Exercise: Bypassing Auth with SQL Injection
    • User Interfaces
      • HMI and UI Attacks
      • Web-based Attacks
      • Password Defenses
      • Exercise: Password Fuzzing
    • Defending Microsoft Windows
      • Windows Services
      • Windows Security Policies and GPOs
      • Host Firewalls
      • Exercise: Baselining with PowerShell
    • Patching ICS Systems
      • Patch Decision Tree
      • Vendors, CERTS, and Security Bulletins

Section 5ICS Security Governance

Explore system hardening for Linux-based industrial systems, examining log management and audit approaches. Learn about common applications used across multiple industrial sectors. Study governance models and industry-specific regulations for critical infrastructure protection, focusing on risk assessment, disaster recovery, and contingency planning.

Topics covered

  • Unix and Linux defense strategies
  • Endpoint protection and SIEMS
  • ICS security program frameworks
  • Security policy development
  • Risk measurement approaches

Labs

  • Hardening Linux for ICS
  • Analyzing Windows event logs
  • ICS security policy review
  • Tabletop incident response
  • Industry-specific compliance testing

Takeaway

Day 5 will further explore baselines and hardening, but his time on Linux-based workstations and servers. Students will examine concepts that benefit ICS systems such as system hardening, log management, monitoring, alerting, and audit approaches, then look at some of the more common applications and databases used in ICS environments across multiple industries. Finally, students will learn about the various models, methodologies, and industry-specific regulations that are used to govern what must be done to protect critical ICS systems. Key business processes that consider risk assessments, disaster recovery, business impact analysis, and contingency planning will be examined from the perspective of ICS environments.

Full Topic Details

  • Day 5: ICS Security Governance
    • Defending Unix and Linux
      • Differences with Windows
      • Daemons, SystemV, and SystemD
      • Lynis and Bastille
      • Exercise: Hardening Linux
    • Endpoint Protection and SIEMS
      • Application Runtime and Execution Control
      • Configuration Integrity and Containers
      • Logs in Windows and Linux
      • Exercise: Windows Event Logs
    • Building an ICS Cyber Security Program
      • Starting the Process
      • Frameworks: ISA/IEC 62443, ISO/IEC 27001, NIST CSF
      • Using the NIST CSF
    • Creating ICS Cyber Security Policy
      • Policies, Standards, Guidance, and Procedures
      • Culture and Enforcement
      • Examples and Sources
      • Exercise: ICS Security Policy Review
    • Measuring Cyber Security Risk
      • Risk Approaches and Calculations
      • DR and BC Planning
    • Incident Response
      • Six Step Process
      • Table Top Exercises
    • Final Thoughts and Next Steps

Section 6Capstone CTF

Apply knowledge gained throughout the course in a capture-the-flag exercise based on incident response. Identify indicators of compromise, determine appropriate containment actions, and adapt to changing adversary tactics as they progress through an ICS/OT network. Leave with industry-specific resources and be well prepared to pursue the GICSP.

Students will work through a capture-the-flag (CTF) game based on an incident response exercise. Students must use the knowledge they gained throughout the week to identify indicators of compromise (IoCs), determine actions that should be taken to limit the attacker's ability to compromise additional assets and react to changes in the attacker's tactics, techniques, and procedures (TTPs) as they progress deeper into the OT/ICS network. Students will leave with various resources for multiple industries and be well prepared to pursue the GICSP, the internationally accepted and industry-leading ICS-focused professional certification.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 8GB of RAM or more is required.
  • 70GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

ICS410 training is recommended for a diverse range of individuals, including:

The course is designed for the range of individuals who work in, interact with, or can affect industrial control system environments, including asset owners, vendors, integrators, and other third parties. These personnel primarily come from four domains:

  • IT (includes operational technology support)
  • IT security (includes operational technology security)
  • Engineering
  • Corporate, industry, and professional standards

The Global Industrial Cyber Security Professional (GICSP) certification is a vendor-neutral, practitioner focused certification that bridges IT, engineering, and cyber security to achieve security throughout the industrial control systems lifecycle. The GICSP assesses a diverse set of professionals who engineer or support control systems and share responsibility for the security of these environments.

  • Industrial control system components, purposes, deployments, significant drivers, and constraints
  • Control system attack surfaces, methods, and tools
  • Control system approaches to system and network defense architectures and techniques
  • Incident-response skills in a control system environment
  • Governance models and resources for industrial cybersecurity professionals

More Certification Details

  • Electronic Download Package contining ICS cybersecurity related posters, whitepapers, use cases, and cheat sheets
  • A virtual machine of the Control Things Platform, an opensourced, linux-based distribution designed for performing security assessments on ICS systems
  • A virtual machine of Windows 10 for course exercises
  • MP3 audio files of the complete course lecture
  • A hardware PLC for students to use in class and take home with them

Course participants need to have a basic understanding of networking and system administration, TCP/IP, networking design/architecture, vulnerability assessment, and risk methodologies. ICS410 covers many of the core areas of security and assumes a basic understanding of technology, networks, and security. For those who are brand new to the field and have no background knowledge, ICS310: ICS Cybersecurity Foundations would be the recommended starting point. While ICS310 is not a prerequisite, it provides introductory knowledge that will help maximize a student's experience with ICS410.

With your purchase of this ICS Security course, you’ll receive complimentary OnDemand access to ICS310: ICS Cybersecurity Foundations. This course is a great way to reinforce key concepts or fill gaps in your ICS/OT security knowledge, whether you complete it in full or focus on what’s most relevant to you. Within 14 business days, you’ll receive a non-transferable access code via your SANS account email.

Professionals new to the field should begin with ICS310: ICS Cybersecurity Foundations to build introductory knowledge. ICS410 requires basic understanding of networking, system administration, TCP/IP, network design/architecture, vulnerability assessment, and risk methodologies. After completing ICS410, students can progress to advanced industrial cybersecurity courses focused on specific skill areas like incident response, active defense, and penetration testing. Such courses include ICS515: ICS Visibility, Detection, and Response, ICS612: ICS Cybersecurity In-Depth, and ICS613: ICS/OT Penetration Testing & Assessments.

Industrial Control System (ICS) security involves protecting critical infrastructure systems and operational technology (OT) environments that manage physical processes in industries like energy, water, manufacturing, and transportation. It addresses unique challenges where cybersecurity impacts physical operations, requiring specialized knowledge of control systems, protocols, and operational requirements to prevent disruption and safety incidents.

This course positions professionals as specialists in the high-demand field of ICS security, bridging the gap between IT and OT. Participants gain practical skills with actual industrial hardware, understand security architectures specific to critical infrastructure and non-critical sector industrial environments, and prepare for the prestigious GICSP certification, opening career paths in industries requiring protection of operational technology.

Relevant Job Roles

Systems Security Analyst (DCWF 461)

DoD 8140: Software Engineering

Ensures systems and software security from development to maintenance by analyzing and improving security across all lifecycle phases.

Explore learning path

Technical Support Specialist (DCWF 411)

DoD 8140: Cyber IT

Delivers technical support to users, helping them resolve issues with client hardware/software according to organizational service processes.

Explore learning path

Vulnerability Assessment Analyst (DCWF 541)

DoD 8140: Cybersecurity

Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.

Explore learning path

Process Control Engineering

Industrial Control Systems

Tests, programs, troubleshoots, and oversees changes of existing processes or implements new engineering processes through the deployment and operations of engineering systems and automation devices.

Explore learning path

ICS Security Architect

Industrial Control Systems

Ensures control system network security compliance and best practices for control networks.

Explore learning path

Information Systems Security Developer (DCWF 631)

DoD 8140: Cybersecurity

Designs and evaluates information system security throughout the software lifecycle to ensure confidentiality, integrity, and availability.

Explore learning path

Cyber Defense Infrastructure Support Specialist (DCWF 521)

DoD 8140: Cybersecurity

Deploys, configures, maintains infrastructure software and hardware to support secure and effective IT operations across organizational systems.

Explore learning path

Network Operations Specialist (DCWF 441)

DoD 8140: Cyber IT

Implements and maintains network services, including hardware and virtual systems, ensuring operational support for infrastructure platforms.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 26

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources