
Getting Started in OT/ICS Cybersecurity 2026 (Module 5): The Ultimate Guide to Asset Registers
Keywords
Summary
194 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides high practical value for anyone starting in OT/ICS cybersecurity, offering a clear, step-by-step approach to building an asset register. The argumentation is solid, grounded in the instructor’s professional experience and real-world incidents. The emphasis on the asset register as the foundation for all other security activities is well-justified. The instructor effectively argues for a balanced approach, combining active and passive discovery methods, and highlights the risks of active scanning on legacy systems. The use of a concrete example (the Ukraine attack) strengthens the argument for the importance of asset visibility. The content is well-structured and the reasoning is logical, making it a valuable resource for practitioners.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates a good level of scientific rigor, with the instructor referencing industry standards like IEC 62443 and citing real-world incidents. The sources cited are primarily the instructor’s own experience and the course materials provided in the description. The title accurately reflects the content, which is a comprehensive guide to asset registers. The video is well-organized and the information is presented in a clear, logical manner. The instructor also provides a downloadable asset register template, which adds practical value. The main limitation is the lack of external citations or references to academic or industry publications, but this is common for tutorial-style content. Overall, the video is a reliable source of information for its intended audience.
240 words
Title / Content Match
The title accurately reflects the content, which is a comprehensive guide to building and maintaining OT asset registers, a core component of OT/ICS cybersecurity.
Quality & Reliability
8/10
The content is based on the author's professional experience in OT/ICS cybersecurity, referencing established practices and standards (IEC 62443). It provides practical, actionable guidance with clear explanations of technical concepts. The author demonstrates a strong understanding of the domain, though the content is largely anecdotal and not peer-reviewed.
Chapters
- Introduction: Why asset registers are the least welcome, yet most critical, aspect of OT cybersecurity.
- Defining the Asset Register: What it is and the key properties it should contain (IP, MAC, firmware).
- Basic Template Walkthrough: A simple look at how asset rows and vulnerability tracking connect.
- The Incident Response Reality: Why teams like Dragos and Mandiant need your register immediately during a crisis.
- Leveraging AI: Using tools like Claude to generate a practical and effective asset register template.
- Custom Spreadsheet Deep Dive: Exploring the data dictionary, risk scoring, zones, and dashboards.
- Unauthorized Changes & Accuracy: Dealing with rogue devices, from personal laptops to control room Xboxes.
- Secure Storage: Where to store the register and why cloud storage carries risks.
- Method 1: Walking the Environment: The physical safety risks and time constraints of tracing cables on the plant floor.
- Method 2: Reviewing Project Files: Using network diagrams, purchase records, and switch ARP caches to find devices.
- Method 3: Active Scanning & Nmap: Why traditional IT port scanning can brick legacy PLCs, and the alternative of "active polling".
- Method 4: Passive Listening: Sniffing network traffic using Wireshark and Network Miner to safely identify assets.
- Securing the Treasure Map: Access controls, encryption, and physical security for your asset data.
- Maintenance & Change Management: Keeping the register accurate over time and responding to rogue IPs.
Cited Sources
- Course Materials (Google Drive) — Downloadable asset register template and other course resources.
- Mike Holcomb's Website — Author's website for more OT/ICS training content.
Concurring Sources
- NIST SP 800-82 — Provides guidance on OT security, including asset inventory and management.
- IEC 62443 — International standard for industrial cybersecurity, which includes asset management requirements.
Contribution & Novelties
The video provides a practical, step-by-step guide to building an OT asset register, which is a foundational but often neglected aspect of OT security. It offers a balanced comparison of active and passive discovery methods, with clear warnings about the risks of active scanning on legacy systems. The inclusion of a downloadable template and the demonstration of using AI to generate a customized register are innovative and time-saving for practitioners. The video also emphasizes the importance of maintaining the register over time and integrating it with change management processes.
Pour aller plus loin :
- IEC 62443 — The international standard for industrial cybersecurity, which provides a framework for OT security, including asset management.
- NIST SP 800-82 — Guide to Operational Technology (OT) Security, which includes guidance on asset inventory and management.
- Purdue Model — A reference model for OT network segmentation, useful for understanding asset zones and conduits.
148 words
Radar Profile
The radar profile shows high scores in information quantity and quality, indicating a content-rich and well-structured tutorial. The technical level is high, suitable for professionals, and the reliability is strong, based on the author's expertise and references to standards. The overall profile suggests a highly valuable resource for OT cybersecurity practitioners.