| name | performing-ot-network-security-assessment |
| description | Use when this skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infra... |
| domain | cybersecurity |
| tags | ["ot-security","ics","scada","industrial-control","iec62443","network-assessment"] |
| subdomain | ot-ics-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-05","GV.OC-02"] |
Performing Ot Network Security Assessment
Overview
Cybersecurity skill for performing ot network security assessment. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing ot network security assessment"
-
"This skill covers conducting comprehensive security assessments of Operational T"
-
When conducting an initial security baseline of an OT/ICS environment for a new client
-
When evaluating the security posture of a facility after an IT/OT convergence initiative
-
When preparing for IEC 62443 or NERC CIP compliance audits
-
When assessing risk following a merger or acquisition involving industrial facilities
-
When investigating whether an OT network has been compromised or has unmonitored pathways to corporate IT
Do not use for IT-only network assessments without OT components, for application-layer vulnerability scanning of IT web applications (see performing-web-app-penetration-test), or for active exploitation of live OT systems without explicit authorization and safety controls in place.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization from the asset owner and operations management for all assessment activities
- Understanding of the Purdue Reference Model and IEC 62443 zone/conduit architecture
- Passive network monitoring tools (Nozomi Guardian, Dragos Platform, or Wireshark with industrial protocol dissectors)
- Access to network diagrams, firewall rule sets, and asset inventories (or the ability to perform passive discovery)
- Safety briefing on the physical processes controlled by the OT systems under assessment
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}