Course essentials
Boot camp at a glance
-
Method
Online, in-person, team onsite
-
Duration
5 days
-
Experience
1-3 years
What you'll learn
Training overview

From the power grid to water treatment facilities, SCADA controls our nation’s mission-critical infrastructure. Infosec’s ICS/SCADA Boot Camp builds your homeland security skills by teaching you how to assess and secure SCADA systems — and you’ll gain hands-on experience on the latest threats via our SCADA Cyber Range.
You’ll learn everything from field-based attacks to automated vulnerability assessments for SCADA networks. The boot camp also prepares you to pass the CSSA certification exam and become a Certified SCADA Security Architect.
Award-winning training you can trust
What's included
Everything you need to know

- 90-day extended access to Boot Camp components, including class recordings
- 100% Satisfaction Guarantee
- Exam Pass Guarantee
- Exam voucher
- Free 90-day Infosec Skills subscription (access to 1,400+ additional courses and labs)
- Hands-on cyber ranges and labs
- Knowledge Transfer Guarantee
- Onsite proctoring of exam
- Pre-study learning path
- Unlimited practice exam attempts
Before your boot camp
Prerequisites
Prior to enrolling in the SCADA Security Training Boot Camp, you must have:
- An understanding of computer hardware and operating systems
- Basic knowledge of SCADA systems
Syllabus
Training schedule
Day 1
Introduction
SCADA/ICS overview
- Introduction to CSSA
- Industrial Control Systems (ICS)
- Types of ICS
- ICS components
- BPCS & SIS
- Control system strengths and weaknesses
- ICS PCN & protocols
- PCN evolution
SCADA/ICS overview continued
- Introduction to CSSA
- Industrial Control Systems (ICS)
- Types of ICS
- ICS components
- BPCS & SIS
- Control system strengths and weaknesses
- ICS PCN & protocols
- PCN evolution
Optional group & individual study
Day 2
SCADA security governance
- Threat to SCADA
- SCADA attacks and threats case studies
- Lab: Attacking the infrastructure
- SCADA security challenge
- Security frameworks, strategy, policies
- Standards, procedures and guidelines
- SCADA security standards bodies (NIST / ISA / CFATS / NERC CIP)
- Risk management process
- Lab: “Theoretical” assessment with CSET
- SCADA security assessment methodology
- NESCOR guide to vulnerability assessment
SCADA security governance continued
- Threat to SCADA
- SCADA attacks and threats case studies
- Lab: Attacking the infrastructure
- SCADA security challenge
- Security frameworks, strategy, policies
- Standards, procedures and guidelines
- SCADA security standards bodies (NIST / ISA / CFATS / NERC CIP)
- Risk management process
- Lab: “Theoretical” assessment with CSET
- SCADA security assessment methodology
- NESCOR guide to vulnerability assessment
Optional group & individual study
Day 3
Pentesting SCADA systems
- Security assessment strategy
- Pentesting steps
- Safety and security considerations
- Information gathering
- Architecture analysis
- Host, application and platform fingerprinting
- DNS and SNMP recon
- Lab: SNMP recon
- Host and port scanning
- Security considerations
- Scanning tools and techniques
- Lab: Scanning ICS/SCADA networks
- Network communications capture and analysis
- RF signal capture
Pentesting SCADA systems continued
- Sniffing network traffic
- Device functionality analysis
- Lab: Datasheet analysis
- Vulnerability identification
- Common SCADA vulnerabilities
- Finding vulnerabilities
- Physical access
- Vulnerability scanning
- Server OS testing
- Patch levels
- Default and insecure configurations
- Authentication and remote access
- Firmware analysis
- Attacking ICS
- Attacking standard services (HTTP, FTP)
- Attacking server OS
- Lab: Exploiting OS-level vulnerabilities (Shellshock exploit)
- Attacking ISC Protocols
- Lab: Capturing and manipulating protocol data
- Attacking wireless communications
- Lab: Recovering ZigBee network keys
- Lab: WEP/WPA2 password cracking
Optional group & individual study
Day 4
SCADA security controls
- Categorization of system controls
- Physical security & safety
- Identification, Authentication & Authorization (IA&A)
- IA&A and access control
- Remote access security
- Encryption
- Logical security
- Lab: Firewall rule design
- Monitoring, detection and protection
SCADA security controls
- Categorization of system controls
- Physical security & safety
- Identification, Authentication & Authorization (IA&A)
- IA&A and access control
- Remote access security
- Encryption
- Logical security
- Lab: Firewall rule design
- Monitoring, detection and protection
Optional group & individual study
Day 5
SCADA review
Take the CSSA exam
Guaranteed results
Our boot camp guarantees

Exam Pass Guarantee
If you don’t pass your exam on the first attempt, get a second attempt for free. Includes the ability to re-sit the course for free for up to one year (does not apply to CMMC-AB boot camps).

100% Satisfaction Guarantee
If you’re not 100% satisfied with your training at the end of the first day, you may withdraw and enroll in a different online or in-person course.

Knowledge Transfer Guarantee
If an employee leaves within three months of obtaining certification, Infosec will train a different employee at the same organization tuition-free for up to one year.
Unlock team training discounts
If you’re like many of our clients, employee certification is more than a goal — it’s a business requirement. Connect with our team to learn more about our training discounts.

You're in good company
The instructor was able to take material that prior to the class had made no sense, and explained it in real world scenarios that were able to be understood.
Erik Heiss, United States Air Force
I really appreciate that our instructor was extremely knowledgeable and was able to provide the information in a way that it could be understood. He also provided valuable test-taking strategies that I know not only helped me with this exam, but will help in all exams I take in the future.
Michelle Jemmott, Pentagon
The course was extremely helpful and provided exactly what we needed to know in order to successfully navigate the exam. Without this I am not confident I would have passed.
Robert Caldwell, Salient Federal Solutions
Enroll in a boot camp
Explore our top boot camps
More learning opportunities
-
Most popularBoot camp
CompTIA Security+ Training Boot Camp
Infosec’s CompTIA Security+ Boot Camp teaches you information security theory and reinforces that theory with hands-on exercises to help you learn by doing. You’ll learn how to configure and operate many different technical security controls — and leave prepared to pass your Security+ exam.
Learn More
-
#1 FOR BEGINNERSBoot camp
Cisco CCNA Associate & CyberOps Associate Training Boot Camp with Dual Certification
Infosec’s authorized CCNA Dual Certification Boot Camp helps you build your knowledge of networking and provides hands-on experience installing, configuring and operating network devices — all while preparing you to earn two Cisco certifications.
Learn More
-
Most requestedBoot camp
(ISC)² CISSP® Certification Training and Boot Camp
Take your career to the next level by earning one of the most in-demand cybersecurity certifications. Infosec’s CISSP training provides a proven method for mastering the broad range of knowledge required to become a Certified Information Systems Security Professional.
Learn More