| name | securing-historian-server-in-ot-environment |
| description | Use when this skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments. It addresses network placement across Purdue levels, access control for historian interfaces, data replication through DMZ using data diodes or PI-to-PI connectors, SQL injection prevention in historian queries, and integrity protection of process data used for safety analysis, regulatory reporting, and process optimization. |
| domain | cybersecurity |
| tags | ["ot-security","ics","scada","industrial-control","iec62443","historian","osisoft-pi","data-integrity"] |
| subdomain | ot-ics-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-05","GV.OC-02"] |
Securing Historian Server In Ot Environment
Overview
Cybersecurity skill for securing historian server in ot environment. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"securing historian server in ot environment"
-
"This skill covers hardening and securing process historian servers (OSIsoft PI, "
-
When deploying a new historian server in an OT environment and configuring it securely from the start
-
When hardening an existing historian after a security assessment identified it as a high-risk target
-
When designing historian data replication architecture through a DMZ for IT access to process data
-
When implementing access controls to prevent unauthorized modification of historical process data
-
When investigating suspected historian compromise or data integrity issues
Do not use for IT-only database security without OT data (see general database hardening), for real-time SCADA data transmission security (see detecting-attacks-on-scada-systems), or for historian selection and sizing decisions.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Historian platform (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) installed and operational
- Network segmentation with historian placed in Level 3 (Site Operations) per Purdue Model
- Understanding of data flows: field devices -> PLCs -> OPC servers -> historian
- Access to historian administration credentials
- DMZ infrastructure for IT-facing data replication
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}