{"id":37831,"date":"2019-10-31T22:20:00","date_gmt":"2019-10-31T19:20:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-kazaki-gicsp-sertifikat-poluchali\/"},"modified":"2019-10-31T22:20:00","modified_gmt":"2019-10-31T19:20:00","slug":"kak-kazaki-gicsp-sertifikat-poluchali","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/kak-kazaki-gicsp-sertifikat-poluchali","title":{"rendered":"How the Cossacks obtained the GICSP certificate.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Hello everyone! On our beloved portal, there have been many different articles related to certification in the field of information security, so I don't intend to claim originality or uniqueness of content, but I would still like to share my experience obtaining GIAC (Global Information Assurance Company) certification in industrial cybersecurity. Since the emergence of such frightening terms as <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/358930\/\">Stuxnet<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/159669\/\">Duqu<\/a><\/noindex>, Shamoon, Triton, the market for specialists who seem to be IT professionals but can also reboot PLCs by rewriting configurations on ladders without stopping production has gradually formed. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>Thus, the concept of IT&amp;OT (Information Technology &amp; Operation Technology) has entered the world. <\/p>\n<p><\/p>\n<p>Immediately afterward, (it's clear that unqualified personnel must not be admitted to work) the necessity arose to certify specialists in the field associated with ensuring the security of automated control systems for technological processes, industrial systems \u2014 of which, it turns out, there are many in our lives, from automatic water supply valves in apartments to aircraft control systems (let's recall the wonderful article about the investigation of problems <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/448174\/\">Boeing<\/a><\/noindex>). And even, as it suddenly turned out \u2014 complex medical equipment. <\/p>\n<p><\/p>\n<p>A little preamble on how I came to the necessity of obtaining certification (can be skipped): After successfully completing my studies in the late 2000s at the Faculty of Information Security, I proudly stepped into the ranks of KIP workers, working as a technician in low-current security alarm systems. It was said to me at that time that this was information security :) Thus began my career as an automated control systems specialist with a bachelor's degree in information security. After six years, having risen to the head of the SCADA systems department, I left to work as a consultant for the security of industrial control systems at a foreign software and equipment vendor company. It was precisely here that the necessity of being a certified information security specialist arose. <\/p>\n<p><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.giac.org\">GIAC<\/a><\/noindex> is developed by <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sans.org\">SANS<\/a><\/noindex> an organization that conducts training and certifies specialists in information security. The reputation of the GIAC certificate is very high among professionals and clients in the EMEA, US, and Asia Pacific markets. Here, in the post-Soviet space and in the CIS countries, such a certificate may only be requested by foreign companies doing business in our countries, as well as international and consulting agencies. Personally, I have never encountered a request for such certification from domestic companies. Mostly, everyone requests CISSP. This is my subjective opinion, and it would be interesting to hear from anyone who shares their experience in the comments.<\/p>\n<p><\/p>\n<p>SANS offers a variety of different directions (in my opinion, lately, they have expanded their offerings too much), but there are also some very interesting practical courses. I was particularly impressed by <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sans.org\/netwars\/\">NetWars<\/a><\/noindex>. But this story will focus on the course <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sans.org\/course\/ics-scada-cyber-security-essentials\">ICS410: ICS\/SCADA Security Essentials <\/a><\/noindex> and the certification called: <noindex><a rel=\"nofollow\" href=\"https:\/\/www.giac.org\/certification\/global-industrial-cyber-security-professional-gicsp\">Global Industrial Cyber Security Professional (GICSP)<\/a><\/noindex>.<\/p>\n<p><\/p>\n<p>Of all the types of Industrial Cyber Security certifications offered by SANS, this one is the most versatile. The second certification is more focused on Power Grid systems, which receive special attention in the West, and belong to a distinct class of systems. The third certification (at the time of my certification journey) was related to Incident Response.<br \/>\nThe course is not cheap, but it provides a sufficiently broad knowledge base for both IT and OT. It will be especially useful for those colleagues who have decided to switch fields, for example, from IT security in the banking sector to Industrial Cyber Security. Since I already had a background in automated control systems, instrument calibration, and Operation Technology, there was nothing fundamentally new or critically important in this course for me.<\/p>\n<p><\/p>\n<p>The course consists of 50% theory and 50% practice. The most interesting practical part was the contest \u2013 NetWars. Over the course of two days, after the main course sessions, all students from all classes were divided into teams and worked on tasks related to gaining access, extracting necessary information, accessing networks, a bunch of hash-cracking tasks, working with Wireshark, and various other activities. <\/p>\n<p><\/p>\n<p>The course material includes a brief summary in the form of books, which you then keep for permanent use. By the way, you can take them to the exam, as it's an Open Book format, but they won't be very helpful since the exam is 3 hours long, consists of 115 questions, and is conducted in English. You can take a 15-minute break during the 3 hours. However, keep in mind that if you take a 15-minute break and return to the tests after 5 minutes, you simply lose the remaining ten minutes, as you cannot stop the time during the testing program. You can skip up to 15 questions, which will then appear at the very end. <\/p>\n<p><\/p>\n<p>Personally, I do not recommend leaving too many questions for later because 3 hours is really not enough time, and when unresolved questions pop up at the end, there is a high probability you won't finish. I left only three questions for later that were truly difficult for me, as they related to the NIST 800.82 standard and NERC. Psychologically, such 'later' questions can be stressful at the end\u2014when your brain is tired, you want to go to the restroom, and the timer on the screen seems to be speeding up exponentially. <\/p>\n<p><\/p>\n<p>In general, to pass the test, you need to score 71% correct answers. Before you take the exam, you will have the opportunity to practice with real tests, as the cost includes 2 practice tests with 115 questions and conditions similar to those of the actual exam.<\/p>\n<p><\/p>\n<p>I recommend taking the exam a month after completing the training, using that month for systematic self-study on the topics where you feel uncertain. It would be good if you take the printed materials received during the course, which look like concise summaries of each topic, and specifically look for information on the topics contained in those books. Divide the month into two parts, taking practice tests and getting a rough idea of where your strengths lie and where you need improvement. <\/p>\n<p><\/p>\n<p>I would like to highlight the following main areas that make up the actual exam (not the training course, as it covers a much broader range of topics):<\/p>\n<p><\/p>\n<ol>\n<li>Physical security: as with other certification exams, this topic receives considerable attention in the GICSP. Questions regarding the types of physical locks on doors are common, as well as scenarios involving the forgery of electronic passes, where it is necessary to provide a clear identification of the problem. There are also questions directly related to the security of technology (process) depending on the subject area\u2014oil and gas processes, nuclear power plants, or electric grids. For example, there may be a question like: Determine what type of physical security control is represented by an alarm from a steam temperature sensor on the HMI? Or a question such as: What situation (event) would warrant an analysis of footage from the surveillance cameras of the perimeter security system?\n<p>In percentage terms, I would note that the number of questions in this section did not exceed 5% on my exam and in practice tests.<\/li>\n<li>Another and one of the most prevalent categories of questions pertains to automated control systems, PLC, SCADA: here, it is necessary to approach the study of materials systematically from how technological process control systems are arranged, starting from sensors to the servers where the application software itself operates. A sufficient number of questions will concern the various types of industrial data transmission protocols (ModBus, RTU, Profibus, HART, etc.). There will be questions about the differences between RTU and PLC, how to protect data in PLCs from modification by malicious actors, in which memory areas PLCs store data, and where the logic itself (the program written by the control system programmer) is held. For instance, there might be a question like: Provide an answer on how to detect an attack between PLC and HMI that operate over the ModBus protocol?\n<p>Questions regarding the differences between SCADA and DCS systems will arise. A large number of questions will focus on the rules for network segmentation of automated control systems at levels L1 and L2 from level L3 (which I will describe in more detail in the section on networks). Situational questions on this topic will also be quite diverse\u2014describing a situation in the control room and requiring the selection of actions that should be undertaken by the process operator or dispatcher.<\/p>\n<p>Overall, this section is the most specific and narrow in focus. It will require a good understanding from you:<br \/>\n \u2014 Automated Control Systems (ACS), the field part (sensors, types of device connections, physical characteristics of sensors, PLCs, RTUs);<br \/>\n \u2014 systems for emergency protection (ESD \u2013 emergency shutdown system) of processes and facilities (by the way, there is a great series of articles on this topic on Habr by <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/308634\/\">Vladimir_Sklyar<\/a><\/noindex>)<br \/>\n \u2014 a basic understanding of the physical processes occurring, for example, in oil refining, power generation, pipelines, etc.;<br \/>\n \u2014 understanding the architecture of DCS and SCADA systems;<br \/>\nI would note that questions of this type can make up to 25% throughout all 115 exam questions. <\/li>\n<li>Network technologies and network security: I think the number of questions on this topic will be the highest in the exam. There will probably be absolutely everything \u2013 OSI model, at which levels a particular protocol operates, many questions on network segmentation, situational questions on network attacks, examples of connection logs with a suggestion to determine the type of attack, examples of switch configurations with a suggestion to identify a vulnerable configuration, questions about vulnerabilities of network protocols, questions about the specifics of industrial communication protocol connections. Particularly, there are many questions about ModBus. The structure of network packets for ModBus, depending on its type and the versions supported by the device. Great attention is paid to attacks on wireless networks \u2013 ZigBee, Wireless HART, general questions about network security for the whole 802.1x family. There will be questions about the rules for placing certain servers in the ACS network (here it is necessary to read the IEC-62443 standard and understand the principles of reference models for ACS networks). Questions related to the Purdue model will also be encountered.<\/li>\n<li>This category of questions relates exclusively to the functional features of power transmission systems and their information security systems. In the USA, this category of automated control systems is referred to as the Power Grid and has a distinct role. Separate standards (NIST 800.82) are even developed to regulate the approach to creating information security systems for this sector. In our countries, this sector is mostly limited to energy consumption monitoring systems (please correct me if anyone has encountered a more serious approach to controlling power distribution and delivery systems). In the exam, you will encounter quite specific questions related to the Power Grid. Most of these were use-cases for specific situations occurring at a Power Plant, but there may also be questions regarding devices that are specifically used in the Power Grid. There will be questions addressing knowledge of NIST sections applicable to this category of systems.<\/li>\n<li>Questions related to knowledge of standards: NIST 800-82, NERC, IEC62443. I think this requires no special comments - one needs to be familiar with the sections of the standards, what each is responsible for, and what recommendations they contain. Specific questions arise, for example, asking about the frequency of system functionality checks, the frequency of procedure updates, etc. In terms of percentage, such questions may account for up to 15% of the total number of questions. But it can vary. For instance, in two practice tests, I encountered only a couple of such questions. However, in the actual exam, there were indeed many.<\/li>\n<li>The last category of questions includes various use-cases and situational questions. <\/li>\n<\/ol>\n<p><\/p>\n<p>Overall, the training, except for perhaps the CTF NetWars, was not very informative for me in terms of acquiring potentially new knowledge. Rather, I gained deeper insights into certain topics, especially in the field of organizing and securing radio networks used for transmitting technological information, as well as a more structured material on foreign standards related to this topic. Therefore, for engineers and specialists with sufficient knowledge and experience in Automated Control Systems\/Measurement and Control Equipment (ACS\/MCE) or Industrial Networks, it might be worth considering saving on the training (which does make sense), preparing on your own, and going straight to take the certification exam, which costs 700 USD, by the way. In case of failure, you will have to pay again. There are plenty of certification centers that will accept you for the exam; just make sure to apply in advance. In general, I recommend immediately setting an exam date, as otherwise, you will keep postponing it, substituting the preparation process with other life priorities, both important and not so much. Having a specific deadline will keep you self-motivated.<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/466361\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442! \u041d\u0430 \u0432\u0441\u0435\u043c\u0438 \u043b\u044e\u0431\u0438\u043c\u043e\u043c \u043f\u043e\u0440\u0442\u0430\u043b\u0435 \u0431\u044b\u043b\u043e \u043c\u043d\u043e\u0433\u043e \u0440\u0430\u0437\u043d\u044b\u0445 \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u043e \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u0418\u0411, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043f\u0440\u0435\u0442\u0435\u043d\u0434\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0438 \u043d\u0435\u043f\u043e\u0432\u0442\u043e\u0440\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u043d\u0435 \u0441\u043e\u0431\u0438\u0440\u0430\u044e\u0441\u044c, \u043d\u043e \u0432\u0441\u0435 \u0436\u0435 \u043e\u0447\u0435\u043d\u044c \u0445\u043e\u0442\u0435\u043b \u0431\u044b \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441\u0432\u043e\u0438\u043c \u043e\u043f\u044b\u0442\u043e\u043c \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f GIAC (Global Information Assurance Company) \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u0440\u043e\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u043e\u0439 \u043a\u0438\u0431\u0435\u0440\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0421\u043e \u0432\u0440\u0435\u043c\u0435\u043d \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0442\u0430\u043a\u0438\u0445 \u0441\u0442\u0440\u0430\u0448\u043d\u044b\u0445 \u0441\u043b\u043e\u0432 \u043a\u0430\u043a Stuxnet, Duqu, Shamoon, Triton, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37831","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442!\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/kak-kazaki-gicsp-sertifikat-poluchali\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u043a\u0430\u0437\u0430\u043a\u0438 GICSP \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043f\u043e\u043b\u0443\u0447\u0430\u043b\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442!\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/kak-kazaki-gicsp-sertifikat-poluchali\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:20:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:20:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47How Cossacks received the GICSP certificate | ProHoster","description":"Hello everyone!","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/kak-kazaki-gicsp-sertifikat-poluchali","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u043a\u0430\u0437\u0430\u043a\u0438 GICSP \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043f\u043e\u043b\u0443\u0447\u0430\u043b\u0438 | ProHoster","og:description":"\u0412\u0441\u0435\u043c \u043f\u0440\u0438\u0432\u0435\u0442!","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/kak-kazaki-gicsp-sertifikat-poluchali","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:20:00+00:00","article:modified_time":"2019-10-31T19:20:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37831","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 19:26:35","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:20:22","updated":"2026-01-23 19:26:35","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=37831"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/37831\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=37831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=37831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=37831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}