Group Purchasing
Group Purchasing

ICS310: ICS Cybersecurity Foundations

ICS310Industrial Control Systems Security
  • 12 Hours (Self-Paced)
Course authored by:
Tim ConwayRobert M. LeeJeffrey Shearer
Tim Conway, Robert M. Lee & Jeffrey Shearer
Course authored by:
Tim ConwayRobert M. LeeJeffrey Shearer
Tim Conway, Robert M. Lee & Jeffrey Shearer
  • 12 CPEs

    Apply your credits to renew your certifications

  • Self-paced

    Train at your own pace from wherever you are

  • Beginner Level

    Course content applicable to people with limited or no cyber security experience

  • 3 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Gain foundational ICS and OT security knowledge and hands-on experience in this one-day course.

Course Overview

ICS310: ICS Cybersecurity Foundations builds foundational knowledge of ICS systems and explores how automation works across industries. Students analyze real-world cyberattacks to uncover defense strategies and learn five key ICS controls adaptable to any environment.

Hands-On ICS Security Training

In this ICS course, students will begin by developing a necessary understanding of mechanical and operational systems, then expand upon this knowledge to better understand how asset owners and operators automate these environments. We explore multiple sectors to highlight the commonalities across process environments from various industries. Understanding the common building blocks and operational criteria that exist in numerous sectors will help defenders support the larger operational mission by knowing to focus risk-based prioritized cybersecurity actions on essential areas.

We will reference case studies from multiple sectors around the world that highlight cyber events in which adversaries employed a variety of tactics to achieve their goals. These case studies cover IT attacks that impacted operations, attacks on operational targets based heavily on adversary manual activity, and attacks on operational targets that incorporated ICS-enabled malware. Analyzing these case studies, we will uncover lessons learned and recommendations for successful defense strategies, including defender-focused actions to prioritize and pursue.

Sectors worldwide will face unique regulatory requirements and standards, while some lack any guidance. Practitioners and leaders alike will learn about the five ICS critical controls that can be customized and implemented across any environment.

Author Statement

“This course represents SANS’s and our commitment to the community by providing a low-cost, fast-paced course that is perfect for introducing people to OT/ICS cybersecurity. It is our hope that people take this course to learn the fundamentals of automation and industrial environments while also gaining exposure to the latest cyber threats and security efforts. Students that take this course will be empowered to immediately apply what they learned and continue their journey to help protect our communities from the jerks that mean them harm.”

– Robert M. Lee

“I believe a foundational course like ICS310 has been needed for a very long time in our community. Early on, some great introductory resources were made available to industry, and as we have seen expanding job roles and growing training needs for individuals entering the field of ICS/OT, we felt it was time to introduce a course that provided fundamental learning topics, informed by the work experiences of an author team with a diversity of perspectives on the topic of ICS/OT cybersecurity.”

– Tim Conway

“You can’t be expected to defend what you don’t understand. With the right instruction, you can quickly understand the basic ICS building blocks that will serve you well as you move forward with more in-depth and complex ICS topics. It’s much like learning a language: Your foundation starts by learning the letters associated with the language. You then learn how letters form words, which lead to the creation of sentences, which are used to create paragraphs and eventually books. Just like learning a language, you shouldn’t assume you can skip the fundamentals of industrial control systems as they are applied to control mechanical and process systems and successfully secure them. Everyone wants to jump into discussions about technical controls like firewalls or how ICS protocols work without understanding how an industrial control system works. It’s where everyone should start their journey as an ICS security professional to get grounded in how industrial control systems work. Once you gain this knowledge, you’ll be standing on a solid foundation to apply security controls in an industrial environment.”

– Jeffrey Shearer

What You’ll Learn

  • Master the Five ICS Cybersecurity Critical Controls, the key security measures to protect industrial systems
  • Gain insights into IEC 62443, NIST 800-82, and NERC CIP frameworks
  • Learn core ICS concepts, common industry terms, system components, and digital vs. analog operations
  • Understand key IT/OT trends, device fundamentals, and system inputs/outputs in OT environments
  • Analyze real-world case studies to see how ICS principles apply to real industry challenges

Business Takeaways

  • Equip employees with the knowledge to identify common ICS components
  • Implement effective cybersecurity measures across your operations
  • Prepare your workforce to counter adversarial tactics
  • Leverage insights from global case studies and proven defense strategies
  • Enable your team to implement customizable ICS controls
  • Address industry-specific and regulatory challenges, improving overall resilience

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in ICS310: ICS Cybersecurity Foundations.

Section 1Why ICS310 and ICS Curriculum View

ICS310 is a foundational course for those new to ICS/OT. This section explains who the course is for, how it fits into a broader ICS cybersecurity training program, its development by multiple experts, and its role as a starting point for advanced SANS ICS Security courses.

Topics covered

  • Foundational Industrial Control System (ICS)
  • SANS and ICS history
  • Where ICS 310 Fits
  • Content Focus Areas
  • Lab and Exercise

Full Topic Details

  • Meet the author team
  • Foundational Industrial Control System (ICS) course topic areas
    • ICS and automation topics
    • ICS trends and case study lessons learned
    • Guidance and approaches for system defenders
  • SANS and ICS history
  • Where does ICS310 fit across the broader curriculum?
  • Content focus areas
  • Lab and exercise

Section 2ICS and Automation Topics

Section two introduces the basic building blocks of industrial control systems, their purpose, and their key design concepts. We explore how ICS/OT systems connect and depend on each other, emphasizing the need for thoughtful design and reliable operations.

Topics covered

  • Brief History of Automation
  • Automation System Building Blocks
  • Human Brain, Sensory and Muscle Reference
  • Main Components of ICS
  • Digital vs. Analog

Labs

  • Ladder Logic Investigation

Full Topic Details

  • Brief History of Automation
  • What are the basic building blocks of an automation system?
  • Human Brain, Sensory and Muscle Reference
  • What are the main components found in ICS?
  • What is digital vs. analog?
    • Types of Digital Inputs
    • Types of Digital Outputs
    • Types of Analog Inputs
    • Types of Analog Outputs
  • Product development lifecycle
  • What is a system of systems?

Section 3ICS Trends and Threats

Section three focuses on cybersecurity, exploring challenges faced by offensive and defensive teams in ICS/OT. Students examine security considerations across critical sectors and understand key differences between IT and OT systems, terms, and trends.

Topics covered

  • Critical Infrastructure Sectors
  • IT and OT Focus Areas
  • Common Terms
  • IT/OT Trends

Section 4ICS Case Studies and World Events

Section four uses real-world case studies and events to highlight key lessons for improving operational security. Even if the cases are not from your sector, understanding shared devices, threats, and responses will help defenders focus on actions that truly matter.

Topics covered

  • Case Study: Colonial Pipeline
  • Case Study: Ukraine 2015
  • Case Study: Ukraine 2016
  • Case Study: World Events

Labs

  • Wireshark Analysis Basics

Section 5ICS Cybersecurity Standards and Guidelines

Section five introduces common ICS/OT security regulations, guidelines, and standards commonly encountered across systems and sectors worldwide. This section provides a broad overview to build familiarity and serve as a reference point, equipping students with fundamental knowledge that they might later deepen with courses on specific standards.

Topics covered

  • ICS / OT Community Security Standards
  • European Union regulation NIS2
  • Industry Approach

Labs

  • tbd 5 limit

Overview

For those working in ICS/OT environments, there are often references to regulations, standards, or guidelines for a particular country, sector, or technology.  Section five introduces the topic of security guidelines and standards you will commonly encounter across industrial control systems anywhere, in any sector across the globe. While students may later pursue full dedicated courses and suites of courses for some standards, this section provides familiarity and points of reference, highlighting the different types of standards.

Full Topic Details

  • Security Guidelines and Standards commonly encountered within the ICS / OT community
  • Top three
    • IEC62443
    • NIST 800-82
    • NERC CIP
  • European Union regulation NIS2
  • Industry approach

Section 6ICS Five Critical Controls

Section six provides guidance on the SANS Five ICS Cybersecurity Critical Controls to help students prioritize actions in their organizations’ ICS/OT security programs. Modeled after IT controls but tailored for OT, these threat-informed controls focus on practical, proven steps to strengthen ICS/OT cybersecurity.

Topics covered

  • The Five Critical ICS Security Controls
  • Leadership Role
  • Resources and Contact Information

Labs

  • Network Visualization

Overview

With so many options to pursue across standards, regulations, guidelines, and industry recommendations, often organizations and leadership are looking for a clear path to what to do.  Section six addresses this question and provides guidance on the five ICS critical controls.  The authors of this course considered existing controls frameworks and asked, “If we wrote the critical controls (like the SANS 20 critical controls for IT) for OT, what would they be?”  You will consider the prioritization, implementation, and customization of the critical controls for your organization. You will also gain background knowledge on how these controls were selected. The Five Critical ICS Security Controls are the minimum preventive and detective controls that are threat-informed, identified based on real-world attacks, and adapted to the capabilities available to system defenders.

Full Topic Details

  • The Five Critical ICS Security Controls
    • ICS Incident Response
    • Defensible Architecture
    • ICS Network Visibility and Monitoring
    • Secure Remote Access
    • Risk Based Vulnerability Management
  • Leadership Role
  • Resources and contact information

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.
  • 64-bit processor with 64-bit operating system
  • At least eight (8) GB of RAM
  • At least seventy (70) GB of free hard drive space
  • At least one USB port

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • VT or other 64-bit virtualization settings enabled in your BIOS to run 64-bit VMs
  • Access to an account with administrative permissions and the ability to disable all security software on their laptop such as Antivirus and/or firewalls if needed for the class
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are responsible for configuring it to work with the course materials and/or VMs.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts). This tool is also included in your downloaded course materials.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

ICS310 training is recommended for a diverse range of individuals, including:

  • New to ICS students
  • Future ICS curriculum students
  • OT security professionals from regulated industries and critical infrastructure
  • OT security professionals from non-regulated industries
  • Vendor / Integrator professionals

Critical Infrastructure / Key Resource industries – electric, water, nuclear, telecom, oil, natural gas, manufacturing, chemical, rail, transportation, etc… specifically, the Operational Technology environments within these organizations. In addition, the DoD interests in operational environments that utilize or support cyber to physical assets.

  • Printed and electronic courseware
  • Electronic Download Package containing ICS cybersecurity related posters, whitepapers, use cases, and cheat sheets
  • A virtual machine of the RELICS Platform, an open-sourced, Linux-based distribution designed for performing Research, Education, Labs for ICS.
  • Exercise workbook with detailed step-by-step instructions

There are no prerequisites. This course will help provide foundational knowledge for other SANS ICS Security curriculum courseware.

Note: When you purchase any SANS ICS Security course, you will receive complimentary access to ICS310: ICS Cybersecurity Foundations at no additional cost. While not a prerequisite for other ICS courses, ICS310 is a great way to reinforce key concepts or fill gaps in your ICS/OT security knowledge, whether you complete it in full or focus on what is most relevant to you. With your purchase, you will receive a non-transferable access code via your SANS account email within 14 business days.

The ICS310 course is a part of the “Industrial Control Systems Security” Learning Path, which gives cybersecurity professionals the skills needed to safeguard critical infrastructure for the sake of operations, national security, and the safety of human life.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Industrial Control Systems (ICS) are the backbone of non-critical sector organizations as well as critical infrastructure, managing the physical processes behind essential services like electricity, water, transportation, and manufacturing. Systems like SCADA (Supervisory Control and Data Acquisition), DCS (Distributed Control Systems), and PLCs (Programmable Logic Controllers) are used to automate and control these environments.

ICS Security focuses on protecting these systems from cyber threats, physical attacks, and exploitation. Defenders rely on strategies like network segmentation, strict access controls, continuous monitoring, vulnerability management, and incident response to keep operations safe and reliable.

As cybercriminals and state-sponsored actors increasingly target ICS environments, robust security has become vital. A successful attack on ICS does not just disrupt business—it can endanger public safety by affecting utilities, transportation, or supply chains. Strong ICS security helps protect infrastructure, minimize downtime, and safeguard the communities that rely on these critical services.

ICS310: ICS Cybersecurity Foundations can open valuable career opportunities for professionals working in or entering the industrial control systems (ICS) and operational technology (OT) space. As cyber threats increasingly target critical infrastructure, organizations need skilled defenders who understand both the technical and operational sides of ICS environments. This course equips you with essential knowledge, practical skills, and a security-first mindset that will help you stand out in the field.

Benefits of this course include:

  • Build a strong foundation in ICS/OT security concepts and terminology
  • Learn how real-world cyber threats impact industrial environments
  • Gain practical strategies to protect critical infrastructure
  • Prepare for more advanced ICS cybersecurity training and certifications
  • Enhance your value to employers in industries like energy, water, transportation, and manufacturing
  • Support career growth in cybersecurity roles focused on protecting physical operations and national security

Relevant Job Roles

ICS Security Leader

Industrial Control Systems

Builds and maintains business relationships with engineering staff and C-suite stakeholders by communicating and managing cyber-to- physical risks while reducing security risk to engineering operations and simultaneously prioritising safety.

Explore learning path

Process Control Engineering

Industrial Control Systems

Tests, programs, troubleshoots, and oversees changes of existing processes or implements new engineering processes through the deployment and operations of engineering systems and automation devices.

Explore learning path

ICS Security Architect

Industrial Control Systems

Ensures control system network security compliance and best practices for control networks.

Explore learning path

Operational Technology (OT) Cybersecurity Engineering (OPM 652)

NICE: Design and Development

Responsible for working within the engineering department to design and create systems, processes, and procedures that maintain the safety, reliability, controllability, and security of industrial systems in the face of intentional and incidental cyber-related events. Interfaces with Chief Information Security Officer, plant managers, and industrial cybersecurity technicians.

Explore learning path

ICS/OT Security Pen Tester

Industrial Control Systems

Discovers system vulnerabilities and works with asset owners and operators to mitigate discoveries and prevent exploitation from adversaries.

Explore learning path

ICS Security Incident Responder

Industrial Control Systems

Executes specific industrial incident response for incidents that threaten or impact control system networks and assets, while maintaining the safety and reliability of operations.

Explore learning path

ICS Security Analyst Training, Salary, and Career Path

Industrial Control Systems

Acquires and manages resources, supports, and performs key industrial security protection while adhering to safety and engineering goals.

Explore learning path

Course Schedule and Pricing

Looking for Group Purchasing Options?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $499 USD*Prices exclude applicable local taxes
    Registration Options
Showing 1 of 1

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources