Operational Technology Ordering Guide
Operational Technology Ordering Guide
Fortinet secures operational technology (OT) with best-of-breed enterprise threat protection and offers a
broad, integrated, and automated cybersecurity platform to securely drive IT/OT convergence – across the
network perimeter, datacenter, and the cloud.
PRODUCT OFFERINGS
Fortinet offers a broad range of cybersecurity solutions that provide visibility, control, and actionable
intelligence for ICS/OT and converged IT/OT environments while supporting compliance with several
industry regulations, standards, and best practices.
Additionally, the Fortinet Security Fabric platform approach for IT/OT minimizes complexity, streamlines
security operations, and reduces the operating expense (OpEx) for asset owners and operators
compared to point security solutions in siloed IT and OT environments.
1
ORDERING GUIDE | Operational Technology (OT)
2
ORDERING GUIDE | Operational Technology (OT)
USE CASES
Fortinet has a comprehensive portfolio of cybersecurity solutions for both IT and OT environments that includes purpose-
built products and features for securing industrial automation and control systems, cyber-physical systems, and critical
infrastructures. This ordering guide is a quick reference to the most deployed Fortinet Security Fabric solutions aligned with the
cybersecurity use cases across IT and OT environments.
The following table lists the Fortinet Security Fabric solution offerings mapped to the cybersecurity use cases and applicable
Purdue levels. The table is based on the industry-recommended best practices and cybersecurity requirements for IT and OT
environments and can be used as a quick reference to navigate the ordering guide.
3
ORDERING GUIDE | Operational Technology (OT)
4
ORDERING GUIDE | Operational Technology (OT)
5
ORDERING GUIDE | Operational Technology (OT)
FortiSwitch is a secure access switch family that delivers outstanding performance, scalability, and manageability. FortiSwitch
allows OT customers to extend networking and security across their network infrastructure. FortiSwitch seamlessly integrates
with the Security Fabric via FortiLink. FortiCloud or FortiGate can manage FortiSwitch. The unified management of FortiSwitch
via FortiGate offers complete visibility and control of users and devices in the network.
FortiAP is a series of Wi-Fi access points that FortiCloud or FortiGate can manage. FortiAPs offer high throughput, optimal
coverage, and enterprise class 802.11ax services. FortiAPs can seamlessly integrate with the Security Fabric and enable security
and access control policy enforcement for end users as devices try to access the network.
FORTIAP BASE PRODUCT SUPPORT
FAP-221E FAP-221E-X * FC-10-PE221-247-02-DD
FAP-234F FAP-234F-X * FC-10-P234F-247-02-DD
FAP-431F FAP-431F-X * FC-10-F431F-247-02-DD
FAP-433F FAP-433F-X * FC-10-F433F-247-02-DD
FAP-432FR FAP-432FR-X * FC-10-F432FR-247-02-DD
* Replace X with the country code.
6
ORDERING GUIDE | Operational Technology (OT)
FortiAnalyzer offers a centralized log management, analytics, and reporting platform, providing customers with single-pane
orchestration, automation, and response for simplified security operations, proactive identification, risk remediation, and
complete visibility of the entire attack surface. FortiAnalyzer can collect different types of logs and events from Fortinet products
via Security Fabric integration.
FORTIANALYZER BASE PRODUCT HW/VM BUNDLE OT SECURITY SERVICE SUPPORT
FAZ-300G FAZ-300G FAZ-300G-BDL-466-DD FC-10-L03HG-159-02-DD FC-10-L03HG-466-02-DD
FAZ-1000F FAZ-1000F FAZ-1000F-BDL-466-DD FC-10-L01KF-159-02-DD FC-10-L01KF-466-02-DD
FAZ-3000G FAZ-3000G FAZ-3000G-BDL-466-DD FC-10-L03KG-159-02-DD FC-10-L03KG-466-02-DD
FAZ-VM - FC1-10-AZVMS-465-01-DD FC1-10-LV0VM-159-02-DD -
FortiManager provides automation-driven centralized management. FortiManager allows end users to centrally manage
FortiGate, FortiSwitch, and FortiAP devices in their network with a single-console centralized management platform.
FortiSIEM provides unified event correlation and risk management for multivendor implementations. It enables analytics from
diverse information sources including logs, performance metrics, SNMP traps, security alerts, and configuration changes. It
feeds all the information into an event-based analytics engine and supports real-time searches, rules, dashboards, and ad hoc
queries.
FortiSOAR offers a holistic security orchestration, automation, and response workbench designed for SOC teams to efficiently
respond to the ever-increasing influx of alerts, repetitive manual processes, and resource shortages. Its patented and
customizable security operations platform provides automated playbooks and incident triaging, and real-time remediation for
enterprises to identify, defend, and counter attacks. FortiSOAR optimizes SOC team productivity by seamlessly integrating
with over 300+ security platforms and 3000+ actions. This results in faster responses, streamlined containment, and reduces
mitigation times from hours to seconds.
7
ORDERING GUIDE | Operational Technology (OT)
FortiDeceptor offers honeypot and deception technology to deceive, expose, and eliminate external and internal threats early
in the attack kill chain and it proactively blocks these threats before any significant damage occurs. It automates blocking of the
attackers targeting IT and OT systems and devices by laying out a layer of decoys and lures that helps with redirecting attackers
focus while revealing their presence on the network.
ADD 1 VLAN
FORTIDECEPTOR BASE PRODUCT SUPPORT CENTRAL MANAGEMENT WINDOWS DECOYS
SUBSCRIPTION *
FDR-100G FDR-100G FC-10-DR1HG-247-02-DD FC1-10-DR1HG-495-02-DD FC1-10-FDCCM-497-02-DD LIC-FDC-WIN
FDC-1000G FDC-1000G FC-10-DC1KG-247-02-DD FC1-10-DC1KG-495-02-DD FC1-10-FDCCM-497-02-DD LIC-FDC-WIN
FDC-VMS Subscription Included with subscription FC1-10-DCVMS-496-02-DD FC1-10-FDCCM-497-02-DD LIC-FDC-WIN
* Minimum order of two VLANs.
FortiEDR delivers real-time automated endpoint protection with orchestrated incident response across IT and OT endpoints. All
in a single integrated platform, with flexible deployment options, and a predictable operating cost, FortiEDR provides real-time
proactive risk mitigation, endpoint security, preinfection protection via a kernel-level Next Generation AntiVirus (NGAV) engine,
postinfection protection, and forensics.
8
ORDERING GUIDE | Operational Technology (OT)
FortiAuthenticator offers single sign-on and user authorization into the Fortinet secured enterprise network identifying users,
querying access permissions from 3rd party systems, and communicating the access requests to FortiGate to implement
identity-based security policies. FortiAuthenticator supports wide array of methods and tools for authentication and
authorization, such as Active Directory, RADIUS, LDAP, SAML SP/IdP, PKI, and multi-factor authentication.
FortiToken enables two-factor authentication with One-Time Password (OTP) Application with Push Notifications or a Hardware
Time-Based OTP Token. FortiToken Mobile (FTM) and hardware OTP Tokens are fully integrated with FortiClient, secured by
FortiGuard, and leverage direct management and use within the FortiGate and FortiAuthenticator security solutions. FortiGate,
FortiToken, and FortiAuthenticator integrated solution is easy to implement, use, and manage for multi-factor authentication use
case.
FortiPAM enables privileged access and session management, controlling privileged user access, and monitoring activity
on privileged accounts. FortiPAM provides tightly controlled privileged access to the most sensitive resources within an
organization. It enables end-to-end management of privileged accounts, control of privileged user access, and visibility of
account usage including monitoring and audit capabilities.
FORTIPAM SUBSCRIPTION
FortiPAM-VM - 5 to 9 users FC1-10-PAVUL-591-02-DD
FortiPAM-VM - 50 to 99 users FC4-10-PAVUL-591-02-DD
FortiRecon scans the organization’s attack surface and identifies risks to assets. FortiGuard Threat intelligence delivers early
warning of risks to the organization through targeted, curated intelligence. It provides visibility into the diverse threats to the
organization and brand reputation, allowing customers to respond more quickly to incidents, better understand attackers, and
safeguard assets while expanding view and early warning of adversarial activity from Dark Web and other sources.
9
ORDERING GUIDE | Operational Technology (OT)
FORTISASE SUBSCRIPTION
FortiSASE User Subscription - 50 to 499 Users FC2-10-EMS05-547-02-DD
FortiSASE User Subscription - 500 to 1999 Users FC3-10-EMS05-547-02-DD
FortiWeb offers security protection for business-critical web applications and APIs from attacks that target known and unknown
vulnerabilities. Using an advanced multilayered approach backed by a sophisticated machine learning engine, FortiWeb protects
against the OWASP Top 10 and more. The FortiWeb product line offers solutions and deployment options across SaaS, VMs, and
hardware appliances.
FortiNDR offers next-generation AI-driven breach protection technology to defend against various cyberthreats, including
advanced persistent threats through a trained Virtual Security AnalystTM. The virtual analyst helps with identifying, classifying,
and responding to threats including those well-camouflaged. Employing – patent-pending – Deep Neural Networks based
on Advanced AI and Artificial Neural Network, it provides sub-second security investigation by harnessing deep learning
technologies that assist in an automated response to remediate different types of attacks.
10
ORDERING GUIDE | Operational Technology (OT)
11
ORDERING GUIDE | Operational Technology (OT)
Where can I find the information about latest Application Control and IPS signatures available in the FortiGuard OT Security Service? Where can I find the
information about Attack Surface Security Service coverage?
The up-to-date information and latest release of Application Control and IPS signatures for FortiGuard OT Security Service can be found on the FortiGuard
website. The information about Attack Surface Security Service is available on the FortiGuard website.
If the license on FortiGate hardware or VM appliance has expired, can the IPS signature database get signature updates?
No. Once the license on FortiGate hardware or VM appliance has expired, the appliance will not get any future updates for the IPS signatures from the date
of license expiry until the license is renewed. However, the IPS signatures existing in the appliance’s database will still function while the license has expired
although the database will not be up to date.
Does FortiGate rugged hardware appliances come with a power supply unit?
No. The FortiGate rugged hardware appliances are equipped with power input connectors only and the customers would be required to purchase a suitable
external power supply unit from 3rd party suppliers to power the appliances.
What license or subscription is required for running the OT decoys and lures in FortiDeceptor?
The “Deceptor Bundle Contract” subscription for FortiDeceptor includes the OT decoys and lures.
Why are some products listed as “Optional” in the use case to solution mapping in the Ordering Guide?
The “Optional” products can be integrated with the “Recommended” products and offer added value for the use case implementation. In addition, the
customers can benefit additional features and functionalities offered in the "Optional" products such as, centralized management, monitoring, logging, etc.
and extend the solution capabilities beyond "Recommended" products in their projects.
Why does the Ordering Guide only list limited SKUs for each Fortinet product line?
The SKUs that are listed in the Ordering Guide are representing the most deployed products for the use case implementations from our current customer
base. However, additional information on the other SKUs can be obtained from the Fortinet website.
Where can I find more information about product installation and configuration?
The product installation manuals, user guides, and quick start guides are available on the Fortinet website.
Ordering Information
FCSS – OT Security Training and Certification
Learn how to secure your OT infrastructure using Fortinet solutions; and SKU DESCRIPTION
design, deploy, administrate, and monitor FortiGate, FortiNAC, FortiAnalyzer,
FT-OTS Instructor-led training - 3 full days or 4 half days
and FortiSIEM devices to secure OT infrastructures. These skills provide you
with a solid understanding of how to design, implement, and operate an OT FT-OTS-LAB Self-paced on-demand labs
security solution based on Fortinet products. NSE-EX-FTE4 Certification exam
Course description
For information about prerequisites, agenda topics, and learning objectives, see the course description at https://training.fortinet.com/local/staticpage/view.
php?page=library_ot-security
Copyright © 2024 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product
or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other
conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser
that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any
such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise
revise this publication without notice, and the most current version of the publication shall be applicable.
OT-OG-R18-20240521