BAS IT CONVERGE LEARNING TRACK
BAS IT CONVERGE 1: IT FOUNDATIONS
Module 1: Computing Fundamentals for BAS
– Computer in a BAS context
– CPUs, memory, storage — what matters for BAS
– Embedded controllers vs servers vs VMs
– OT vs IT environments
Module 2: Operating Systems & Virtualisation
– Windows, Linux, embedded OS in BAS
– Services, processes, users, permissions
– Virtual machines vs bare metal
– Virtualisation for Niagara & BAS servers
Module 3: Files, Databases & Data Basics
– Files vs databases
– Introduction to SQL concepts
– Logs, histories, trends, backups
– BAS data lifecycle
Module 4: Protocols & System Interfaces
– What is a protocol?
– IP vs serial protocols
– Northbound vs southbound interfaces
– APIs as BAS interfaces
BAS IT CONVERGE 2: NETWORKING & CONNECTIVITY
Module 1: How Networks Actually Move Data
– What a network really is (devices, links, rules)
– How BAS devices communicate on a network
– MAC addresses and device identity
– IP addresses as logical identity
– How data moves step by step (controller → supervisor)
– Common BAS network failure patterns
Module 2: IP Addressing, Subnets & Gateways
– IP address structure
– What “same network” actually means
– Why subnets exist
– Subnet masks explained practically
– Default gateways and when they are used
– MAC vs IP vs hostname (DNS in BAS context)
– Common BAS IP configuration mistakes
Module 3: Switching, VLANs & Network Segmentation
– What switches actually do
– Switching vs routing
– Broadcast traffic in BAS networks
– BACnet/IP and broadcast sensitivity
– VLANs explained for BAS environments
– Flat vs segmented networks
– When segmentation helps or hurts BAS
Module 4: Routing, Firewalls & Remote Access
– Routing basics (same network vs different network)
– How routers affect BAS communication
– Firewalls and ports
– Why BAS traffic is often blocked
– NAT explained simply
– VPNs and remote BAS access
– Common BAS firewall and security challenges
Module 5: Modern Connectivity & Protocol Patterns
– BAS protocols over IP
– Polling vs publish/subscribe models
– MQTT, HTTP and modern BAS integrations
– Edge devices and protocol gateways
– Typical gateway failure patterns
– Designing BAS networks for scale and growth
BAS IT CONVERGE 3: CLOUD INTEGRATION
Module 1: Cloud Concepts for BAS
– What cloud really means
– IaaS, PaaS, SaaS for BAS
– On‑prem vs hybrid
– Latency and availability
Module 2: Edge-to-Cloud Architectures
– Edge controllers and gateways
– Data pipelines
– Store‑and‑forward
– Offline operation
Module 3: Cloud Services Used in BAS
– Databases, storage, compute
– APIs and integrations
– Identity and access basics
– Cost awareness
Module 4: Security & Governance in the Cloud
– Shared responsibility
– Encryption basics
– Identity and secrets
– Cloud risks for BAS
BAS IT CONVERGE 4: DATA, ANALYTICS & AI
Module 1: BAS Data Fundamentals
– BAS data types
– Point vs event data
– Data quality issues
– Normalization challenges
Module 2: Analytics Concepts
– KPIs vs insights
– Rules‑based analytics
– Fault detection basics
– Analytics pitfalls
Module 3: Visualisation & Reporting
– Dashboards vs reports
– Contextual visualisation
– Avoiding misleading charts
– Performance storytelling
Module 4: AI & Machine Learning
– What AI is (and isn’t)
– ML use cases in BAS
– Data requirements
– Responsible AI
BAS IT CONVERGE 5: INFORMATION MODELLING
Module 1: Why Information Modelling Matters
– Unstructured BAS data problems
– Names vs meaning
– Interoperability challenges
– Analytics dependency
Module 2: Semantic Modelling Concepts
– Tags and relationships
– Entities vs points
– Graph thinking
– Modelling vs naming
Module 3: Industry Models
– Brick and Haystack overview
– Strengths and limitations
– BAS use cases
– Adoption realities
Module 4: Applying Models in Practice
– Modelling for analytics
– Modelling for integration
– Incremental adoption
– Avoiding over‑engineering
BAS IT CONVERGE 6: CYBERSECURITY & RESILIENCE
Module 1: Cybersecurity Fundamentals
– Why BAS is targeted
– IT vs OT security
– Threat actors
– Common vulnerabilities
Module 2: Secure Architecture Design
– Network segmentation
– Least privilege
– Secure remote access
– System hardening
Module 3: Identity, Authentication & Encryption
– Users vs services vs devices
– Authentication methods
– Certificates and encryption
– Credential management
Module 4: Resilience & Incident Response
– Designing for failure
– Backups and recovery
– Monitoring and alerting
– Incident response basics