operational-technology

Automate OT/ICS risk assessment, asset discovery, and security governance.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill operational-technology
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: operational-technology
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/operational-technology
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill operational-technology

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

OT/ICS security is complex and requires a structured program to discover assets, assess risks, design secure networks, and ensure regulatory compliance across industrial environments.

Core Features & Use Cases

  • Asset discovery and inventory across Purdue zones using passive monitoring and controlled active techniques
  • Risk and vulnerability assessment aligned to ISA/IEC 62443 and NERC CIP
  • Network security design, IT/OT convergence controls, DMZ and data-diodes considerations
  • Incident detection and response workflows with safety-first priorities
  • Compliance mapping and governance including Purdue zoning, SL-T targets, and ESP/CIP requirements

Quick Start

Outline an initial OT asset register, risk assessment scope, and a baseline network segmentation plan for a manufacturing or energy OT environment.

Frequently Asked Questions about operational-technology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an OT security risk assessment aligned to ISA/IEC 62443?

OT security risk assessment involves automating asset discovery, vulnerability evaluation, and compliance mapping to ISA/IEC 62443 across Purdue zones. This process identifies industrial control system risks and generates governance frameworks for energy, utility, and manufacturing environments.

What is Purdue model network segmentation and how does it secure ICS environments?

Purdue model network segmentation separates IT and OT traffic into defined zones using conduits to secure ICS environments. It enforces IT/OT convergence controls, DMZ boundaries, and data-diode considerations to prevent lateral movement and isolate critical infrastructure assets.

Can I map MITRE-ICS techniques and NERC CIP requirements to my asset inventory?

Yes, you can map MITRE-ICS techniques and NERC CIP requirements to your asset inventory. The process correlates discovered OT assets with vulnerability assessments and compliance frameworks, producing structured governance outputs that satisfy ESP/CIP regulatory mandates.

How do I design an incident response readiness plan for OT networks?

Design an incident response readiness plan for OT networks by establishing safety-first detection workflows and controlled active monitoring techniques. This approach prioritizes operational continuity while mapping threats to industrial control system vulnerabilities and ISA/IEC 62443 compliance targets.

Does passive monitoring work for asset discovery across all industrial control system zones?

Passive monitoring works for asset discovery across industrial control system zones, but combining it with controlled active techniques ensures comprehensive inventory. This dual approach captures deep Purdue level device data without disrupting critical manufacturing or energy operations.

What are the limitations of using automated tools for NERC CIP compliance mapping?

Automated NERC CIP compliance mapping limitations include relying on accurate asset visibility and requiring manual validation of ESP/CIP control deviations. While automation accelerates gap analysis across OT networks, human verification remains necessary for complex industrial control system segmentation boundaries.