ICS/SCADA › Module 2 › Lesson 1
ICS Overview
ICS overview literacy names sensors, controllers, historians, and supervisory layers on YOUR $OT_LAB — defensive OT literacy only; no real-plant attacks, unauthorized OT scans, or exploit cookbooks.
Visual · t38_ics_overview
ICS Overview literacy. $OT_LAB only. Original Cyberlium.
Opening
You cannot defend what you have not named — map Purdue levels on YOUR fictional plant before claiming OT expertise.
Industrial Control Systems combine field devices, PLCs/RTUs, HMIs, historians, and enterprise interfaces across Purdue Model levels 0–5. Label fictional components in YOUR OT lab — never enumerate live employer OT assets without authorization. Cyberlium Topic 38 practices on $OT_LAB — YOUR fictional OT templates, zone diagrams, and labeled checklists under $HOME/cyberlium-lab/t38-ot/ no real-plant attacks, unauthorized OT scans, or exploit cookbooks. Next: SCADA Named.
1. What ICS Overview covers (named)
Level 0 sensors/actuators, Level 1 controllers, Level 2 SCADA/HMI, Level 3 operations, Levels 4–5 enterprise IT. Each level has distinct safety and monitoring priorities. On $OT_LAB, document literacy rows on fictional LAB-OT-001 — never live plant IPs, credentials, or exploit steps.
Write ICS layer card — one fictional component per Purdue level for LAB-OT-001. Not nmap output from plant subnets. On $OT_LAB, document literacy rows on fictional LAB-OT-001 — never live plant IPs, credentials, or exploit steps.
Command guide
Try these commands — What ICS Overview covers (named)
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Purdue Model OT — https://www.cisa.gov/topics/industrial-control-systems NIST SP 800-82 — https://csrc.nist.gov/publications/detail/sp/800-82/rev-3/final
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export OT_LAB=${OT_LAB:-$HOME/cyberlium-lab/t38-ot}
curl -sS https://www.cisa.gov/topics/industrial-control-systems | head -10
cat > "$OT_LAB/notes/ics-overview-named.txt" <<'EOF'
ICS overview — NAMED LITERACY:
L0: sensors/actuators
L1: PLCs/RTUs
L2: SCADA/HMI
L3: operations/historian
L4-5: enterprise IT
Context: LAB-OT-001 fictional plant — YOUR lab templates only
Lab: populate ICS layer card in Module 2 pack — not live asset scans
EOFCommand — copy this
grep -E 'L0|L1|LAB-OT-001' "$OT_LAB/notes/ics-overview-named.txt"
Primary tools to practice this lesson: curl, grep. Reference sites: Purdue Model OT (https://www.cisa.gov/topics/industrial-control-systems); NIST SP 800-82 (https://csrc.nist.gov/publications/detail/sp/800-82/rev-3/final). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Why ICS Overview matters for defenders
Shared ICS vocabulary aligns IT security and OT engineers. Undocumented assets hide monitoring gaps. On $OT_LAB, document literacy rows on fictional LAB-OT-001 — never live plant IPs, credentials, or exploit steps.
Students draft layer cards on notes. Production models follow CMDB and OT engineering standards. On $OT_LAB, document literacy rows on fictional LAB-OT-001 — never live plant IPs, credentials, or exploit steps.
3. $OT_LAB boundary
Forbidden: nmap scans of plant OT subnets. Allowed: ICS overview card with fictional components. On $OT_LAB, document literacy rows on fictional LAB-OT-001 — never live plant IPs, credentials, or exploit steps.
Ship: ICS layer card. Next: SCADA Named.
4. What you ship: ics overview card for $OT_LAB
ICS overview literacy names sensors, controllers, historians, and supervisory layers. $OT_LAB named. NEVER real-plant attack steps. chmod 600.
5. What you record before the next lesson
Date (UTC). ICS Overview card. $OT_LAB named. File t38-m02-l01-ics-overview.txt chmod 600.
6. Wrong vs right: plant attacks vs YOUR OT lab sims
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Scan employer OT VLAN to populate ICS inventory.
Right
Write ics overview card for YOUR $OT_LAB. Next: SCADA Named.
Mission: document ICS Overview on YOUR OT lab
1) Name literacy rows on $OT_LAB. 2) Write NEVER list (no real-plant attacks, unauthorized OT scans, or exploit cookbooks). 3) chmod 600. Never scan or exploit real industrial networks.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: literacy on $OT_LAB — not attack recipes against live plants.
Knowledge Check
APPLY: ICS Overview on Cyberlium means:
Multiple choice
Knowledge Check
APPLY: True or False: Topic 38 includes ICS attack cookbooks against real plants.
True or False
Knowledge Check
APPLY: ICS Overview literacy on Cyberlium uses:
Multiple choice