Skip to main content
Course

GIAC Global Industrial Cyber Security Professional (GICSP) Exam Prep

Secure ICS and OT environments where safety and availability come first.

Advanced

Level

6

Modules

24

Lessons

6

Graded quizzes

10 hours

Estimated time

What you will be able to do

  • Explain ICS and OT components, processes and safety priorities
  • Describe industrial protocols and where they are exposed
  • Apply the Purdue model, zones and conduits to segment an OT network
  • Assess ICS risk and manage vulnerabilities without breaking availability
  • Monitor OT networks and respond to incidents safely
  • Govern the IT and OT boundary with appropriate standards
  • Pass a timed practice exam covering the GICSP objective areas

What is inside

6 modules, 24 lessons. Each module ends in a graded quiz.

  1. 01

    ICS Foundations: Processes, People, and the IT/OT Divide

    Covers the GICSP ICS Overview and Concepts domain: what industrial control systems physically do, who runs them, and how operational technology priorities differ from enterprise IT. You will learn control loop mechanics, the Purdue reference model, plant roles and management of change, the safety first priority order, and how physical security and safety instrumented systems function as cyber controls. Every concept is anchored to consequence, because in an industrial environment the impact of an attack is measured in physics rather than in records lost.

    4 lessons · 15 quiz questions

  2. 02

    ICS Components and Secure Architecture

    Covers the GICSP ICS Components and Architecture domain, from the Purdue Enterprise Reference Architecture and the devices that live at each level through asset inventory, zoning, and segmentation. You will learn to place any industrial asset at the correct level, build and maintain an OT inventory that survives contact with a real plant, and partition a system into zones and conduits using the IEC 62443 method. The module closes by walking a complete secure reference architecture and giving you a repeatable way to review one and report what is wrong with it.

    4 lessons · 15 quiz questions

  3. 03

    PERA Technology Deep Dive and How It Gets Compromised

    Covers the two GICSP technology domains together: what actually sits at PERA Levels 0 and 1, what sits at Levels 2 and 3, and how adversaries turn each layer into a physical or operational consequence. You learn sensors, final control elements, controllers, safety instrumented systems, control protocols, human machine interfaces, historians, engineering workstations, and the industrial DMZ, and then study the compromise patterns for each layer in defensive terms: what they look like in telemetry, how to detect them, and which architectural and engineered controls contain them. Every lesson ends with exam style checks, and the module closes with a fifteen question domain quiz.

    4 lessons · 15 quiz questions

  4. 04

    ICS Protocols, Cryptography, and Wireless Attack Surface

    Covers the GICSP domain on protocols, communications, compromises, and wireless technologies. You will learn how serial and Ethernet communication is structured in a plant, how Modbus, DNP3, OPC, and the wider protocol family fail when they meet an untrusted network, and where cryptography genuinely helps in an environment ruled by latency, device lifespan, and safety. The final lesson covers the wireless technologies found on industrial sites, how each one is targeted, and the countermeasures and program controls that hold up in production.

    4 lessons · 15 quiz questions

  5. 05

    Hardening and Protecting ICS Endpoints

    Covers the GICSP Hardening and Protecting Endpoints domain across the Windows, Unix, Linux, and embedded hosts that make up a real control system. You will learn how to reduce attack surface, control accounts and credentials, tailor and enforce a hardened baseline, and make patch and change decisions that respect vendor validation, outage windows, and process safety. The module closes with the protective layer that industrial endpoints depend on most, namely application allowlisting, tuned antivirus and endpoint detection, useful logging and detection, and control of removable media and transient assets.

    4 lessons · 15 quiz questions

  6. 06

    Building the ICS Security Program: Policy, Threats, Risk, and Response

    Covers the GICSP program, intelligence, risk, and response domain end to end. You will learn how to charter an ICS security program that operations will actually support, write policy a technician can follow during a night shift, gather and apply threat intelligence about industrial adversaries, model threats and measure risk from consequence backwards, and build disaster recovery and incident response capability that restores a plant without causing the outage you were trying to prevent.

    4 lessons · 15 quiz questions