Protego field desk
Infrastructure Security Architecture / 25-30% of exam

L11.Endpoint, IoT & OT Security Requirements

Course outlineLesson 11 of 18

Specify measurable security requirements for servers, clients, mobile, IoT, embedded, OT, and ICS assets while respecting operational and safety constraints.

Segment endpoint classes

Servers, user devices, mobile devices, IoT, and operational technology have different owners, lifecycles, and failure consequences. Define asset classes and a minimum baseline for each rather than forcing one control set onto every device.

Write requirements that can be verified

Baseline requirements can include supported operating systems, secure boot, encryption, endpoint detection, host firewalls, application control, vulnerability and patch processes, configuration management, local privilege restrictions, logging, and isolation procedures.

Control local administration

Windows Local Administrator Password Solution manages unique, rotated local administrator passwords and can store them in Active Directory or Microsoft Entra ID according to the chosen design. Limit who can retrieve passwords and monitor retrieval and reset activity.

Respect OT and ICS constraints

Safety, availability, vendor support, and long replacement cycles can limit agents and patching. Use passive discovery, network segmentation, controlled remote access, allowlisting, secure engineering workstations, and tested maintenance windows. Microsoft Defender for IoT can provide monitoring for supported environments.

Plan for containment

Every endpoint class needs a safe isolation and recovery path. For OT, an automatic containment action that interrupts a physical process may create more harm than the cyber event, so define human decision authority in advance.

Exam Focus Points
  • Create distinct baselines for server, client, mobile, IoT, and OT asset classes
  • Requirements must produce measurable configuration or operational evidence
  • Windows LAPS provides unique, rotated local administrator passwords
  • OT containment must account for safety, availability, and process impact
Knowledge Check

1. Why might automatic network isolation be inappropriate for an OT controller?