Technical Trade SchoolBOOT advanced-bootcamp
BOOT-OT
Ten concept and evidence figures

BOOT-OT Visual Aid Library

Figure-use rule

Each figure is an orientation and reasoning aid, not a project drawing. Learners must pair it with the current sequence, point list, wiring/piping documents, manufacturer instructions, and as-found evidence.

Figure 1 — OT mission, consequences, governance, scope and lab ethics critical

Normal-rule anchor

OT security serves safe reliable operation; technical curiosity, tool capability, or an alert does not create authority.

Case overlay

A suspected controller compromise is reported during extreme weather, but ownership and shutdown consequences are unclear.

Calculation/evidence callout: Calculate qualitative/quantitative risk from supplied criteria, scope coverage, decision windows, and consequence-weighted priorities.

Figure 2 — Asset, software, data and dependency inventory critical

Normal-rule anchor

An IP scan alone cannot establish a safe OT inventory; passive evidence, project records, platform data, owner confirmation, and functional dependencies must reconcile.

Case overlay

A supervisor replacement fails because certificate, license, DNS, history, and third-party integration dependencies were absent from inventory.

Calculation/evidence callout: Calculate inventory coverage/confidence, unsupported assets, ownership gaps, dependency coverage, and backup readiness.

Figure 3 — Current/future architecture, zones, conduits and blast radius critical

Normal-rule anchor

Segmentation is a risk and consequence design, not merely more VLANs; required operations and recovery paths must remain explicit.

Case overlay

A flat BAS network includes workstations, JACEs, controllers, vendor access, and historian traffic with no documented trust boundary.

Calculation/evidence callout: Calculate subnet plans, asset/flow counts by zone, single-point and blast-radius measures, migration stages, and rollback points.

Figure 4 — Identity, RBAC, service accounts, certificates and secure remote access critical

Normal-rule anchor

Remote connectivity is not standing permission; shared accounts and indefinite broad access defeat attribution and containment.

Case overlay

A vendor needs two-hour read-only access to one training JACE, but the current method uses a shared admin account and open VPN.

Calculation/evidence callout: Calculate entitlement coverage, privileged/shared accounts, session duration/expiry, revocation time, certificate renewal window, and audit completeness.

Figure 5 — Supported hardening and operational validation critical

Normal-rule anchor

A checklist is not acceptance; hardening must be supported, authorized, operationally tested, documented, and recoverable.

Case overlay

A disabled legacy service closes exposure but breaks graphics and alarm delivery after restart.

Calculation/evidence callout: Calculate baseline/compliant/exception coverage, required-function pass rate, residual exposure, change/rollback time, and monitoring window.

Figure 6 — Required-flow rules, routing, NAT, broadcasts and application proof critical

Normal-rule anchor

Port reachability is not application success, and a broad allow is not an acceptable substitute for understanding BACnet and vendor flows.

Case overlay

Ping passes across a firewall but routed BACnet discovery and certificate validation fail; a temporary any-any rule remains.

Calculation/evidence callout: Calculate subnet/routing decisions, rule coverage/redundancy/shadowing from supplied data, allow/deny tests, latency, and temporary-rule closure.

Figure 7 — Monitoring, baselines, time, logs and useful alerts

Normal-rule anchor

More logs and alerts do not guarantee detection; time quality, context, ownership, retention, tuning, and response path determine usefulness.

Case overlay

Repeated authentication failures coincide with a maintenance window, but one controller time source is 18 minutes wrong.

Calculation/evidence callout: Calculate clock skew, baseline ranges, event/alert rates, false-positive ratio, retention/storage, and detection/escalation time.

Figure 8 — Incident command, evidence, containment and operational recovery critical

Normal-rule anchor

Fast containment is valuable only when authority, physical consequences, dependencies, evidence, reversibility, and recovery are considered.

Case overlay

A compromised workstation communicates with a JACE serving critical space; disconnecting the JACE would remove operator visibility and schedules.

Calculation/evidence callout: Calculate severity from supplied rubric, affected assets/dependencies, containment blast radius, decision/recovery timeline, and evidence coverage.

Figure 9 — Backup scope, protected copies, checksums, RPO/RTO and restore proof critical

Normal-rule anchor

A backup file is not recovery evidence; integrity, completeness, access, dependencies, supported restore procedure, and functional tests must pass.

Case overlay

The station backup starts, but certificates, switch configuration, controller database, and alarm recipients are missing.

Calculation/evidence callout: Calculate backup age versus RPO, restore time versus RTO, dependency and function coverage, checksum results, and residual gaps.

Figure 10 — Staged migration, exception governance and continuous improvement; Architecture/change capstone, restore exercise and defense critical

Normal-rule anchor

A target architecture without sequencing, ownership, acceptance, rollback, and exception expiry is not an executable security plan. Security acceptance is operational: required flows, physical sequences, operator tasks, incident decisions, and recoverability must all be proven.

Case overlay

The owner approves segmentation but cannot replace three unsupported controllers this year. Changed-capstone condition: The proposed architecture passes network tests but fails a plant restart sequence and remote-session revocation during an incident.

Calculation/evidence callout: Calculate risk-reduction priority, stage coverage, budget/schedule assumptions, exception age/expiry, pilot success, and rollback points. Calculate requirement/test coverage, allow/deny/function pass rates, RPO/RTO, incident/recovery timing, issue closure, residual risk, and ownership completeness.