| Вид документа | Технічний документ |
|---|---|
| Виробник | SIEMENS |
| Код документа | Configuration |
| Сторінок | 124 |
| Мова документа | англійська |
| Розмір файлу | 3.4 МБ |
Текст документа
Introduction 1
Security instructions 2
What is industrial
cybersecurity? 3
SINUMERIK
Why is industrial
cybersecurity so important? 4
SINUMERIK ONE
Industrial Cybersecurity General security measures
in automation and drive 5
technology
Configuration Manual
System overview 6
Intended operational
environment 7
Protection objectives 8
Security functions of the
product 9
Recommendations for
secure operation and 10
secure disposal
Security-critical system
states 11
Procedure for managing
security updates 12
Tips for security checks 13
Valid for the SINUMERIK ONE control system
CNC software Version 6.23 References A
01/2024
A5E51912408B AB
Legal information
Warning notice system
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
DANGER
indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
indicates that minor personal injury can result if proper precautions are not taken.
NOTICE
indicates that property damage can result if proper precautions are not taken.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
Qualified Personnel
The product/system described in this documentation may be operated only by personnel qualified for the specific
task in accordance with the relevant documentation, in particular its warning notices and safety instructions.
Qualified personnel are those who, based on their training and experience, are capable of identifying risks and
avoiding potential hazards when working with these products/systems.
Proper use of Siemens products
Note the following:
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
documentation. If products and components from other manufacturers are used, these must be recommended or
approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and maintenance
are required to ensure that the products operate safely and without any problems. The permissible ambient
conditions must be complied with. The information in the relevant documentation must be observed.
Trademarks
All names identified by ® are registered trademarks of Siemens Aktiengesellschaft. The remaining trademarks in
this publication may be trademarks whose use by third parties for their own purposes could violate the rights of
the owner.
Disclaimer of Liability
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
Siemens Aktiengesellschaft A5E51912408B AB Copyright © Siemens 2024.
Digital Industries Ⓟ 12/2023 Subject to change All rights reserved
Postfach 48 48
90026 NÜRNBERG
GERMANY
Table of contents
1 Introduction ........................................................................................................................................... 7
1.1 About SINUMERIK ................................................................................................................ 7
1.2 About this documentation ................................................................................................... 8
1.2.1 Purpose of the documentation ............................................................................................. 8
1.2.1.1 Target group ........................................................................................................................ 8
1.2.1.2 Data for the technical security design and the secure system configuration ........................... 8
1.2.2 Standard scope .................................................................................................................... 9
1.3 Documentation on the internet .......................................................................................... 10
1.3.1 Documentation overview SINUMERIK ONE ......................................................................... 10
1.4 Feedback on the technical documentation ......................................................................... 11
1.5 mySupport documentation ................................................................................................ 12
1.6 Service and Support........................................................................................................... 13
1.7 Using OpenSSL .................................................................................................................. 15
1.8 General Data Protection Regulation .................................................................................... 16
2 Security instructions ............................................................................................................................ 17
2.1 Fundamental safety instructions......................................................................................... 17
2.1.1 General safety instructions................................................................................................. 17
2.1.2 Warranty and liability for application examples ................................................................... 17
2.1.3 Cybersecurity information .................................................................................................. 17
3 What is industrial cybersecurity?......................................................................................................... 19
3.1 Delimitation: Functional safety and industrial cybersecurity ................................................ 20
4 Why is industrial cybersecurity so important? .................................................................................... 21
4.1 Trends with an impact on industrial cybersecurity............................................................... 21
4.2 Possible corporate security vulnerabilities........................................................................... 22
4.3 Why is industrial cybersecurity so important?...................................................................... 23
5 General security measures in automation and drive technology ....................................................... 25
5.1 Security measures.............................................................................................................. 25
5.2 Defense in depth concept................................................................................................... 26
5.3 Siemens Industrial Holistic Security Concept ....................................................................... 28
5.4 Standards and regulations.................................................................................................. 29
5.5 Security management........................................................................................................ 30
5.6 Plant security ..................................................................................................................... 32
5.6.1 Overview ........................................................................................................................... 32
5.6.2 Physical protection of critical production areas.................................................................... 32
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 3
Table of contents
5.7 Network security................................................................................................................ 34
5.7.1 Overview ........................................................................................................................... 34
5.7.2 Network segmentation ...................................................................................................... 34
5.7.2.1 Separation between production and office networks........................................................... 34
5.7.2.2 Network segmentation with SCALANCE S ........................................................................... 35
5.8 System integrity and authenticity ....................................................................................... 38
5.8.1 Overview ........................................................................................................................... 38
5.8.2 System hardening .............................................................................................................. 38
5.8.2.1 Services and ports.............................................................................................................. 38
5.8.2.2 User accounts .................................................................................................................... 39
5.8.2.3 Operating units used in the industrial context .................................................................... 39
5.8.2.4 Store sensitive data securely............................................................................................... 39
5.8.2.5 Transporting sensitive data securely ................................................................................... 40
5.8.2.6 Secure passwords .............................................................................................................. 40
5.8.2.7 Virus scanner ..................................................................................................................... 41
5.8.2.8 Allowlists ........................................................................................................................... 42
5.8.2.9 Product security notifications.............................................................................................. 42
5.8.3 Patch management............................................................................................................ 43
5.8.3.1 Windows patch management............................................................................................. 43
5.8.3.2 Program updates in the TIA Portal ...................................................................................... 44
5.8.3.3 Product software................................................................................................................ 44
6 System overview ................................................................................................................................. 45
6.1 System overview................................................................................................................ 45
6.2 Communication interfaces ................................................................................................. 48
6.3 Data flows and data memory ............................................................................................. 50
7 Intended operational environment .................................................................................................... 51
7.1 Description of the intended operational environment ......................................................... 51
7.2 Security assumptions for the intended operational environment ......................................... 52
8 Protection objectives ........................................................................................................................... 53
8.1 Overview of protection objectives ...................................................................................... 53
9 Security functions of the product ........................................................................................................ 55
9.1 Overview ........................................................................................................................... 55
9.2 Role and access requirements for security functions ........................................................... 56
9.3 User management and access control ................................................................................ 57
9.3.1 Types of supported access management systems................................................................ 57
9.3.2 Classic access management: Group-based access levels ...................................................... 57
9.3.3 Features and benefits of user management ........................................................................ 58
9.3.4 User management ............................................................................................................. 59
9.3.4.1 Overview and definition ..................................................................................................... 59
9.3.4.2 Architecture of the user management ................................................................................ 60
9.3.4.3 Groups and role concept .................................................................................................... 63
9.3.4.4 Role of the security admin.................................................................................................. 64
9.3.4.5 Activating and configurating user management.................................................................. 65
9.3.4.6 Role and access requirements for security functions of user management........................... 66
9.3.4.7 Backing up/restoring data................................................................................................... 67
Industrial Cybersecurity
4 Configuration Manual, 01/2024, A5E51912408B AB
Table of contents
9.4 Backup and restore ............................................................................................................ 69
9.4.1 Options for backing up and restoring data .......................................................................... 69
9.4.2 Security archive ................................................................................................................. 70
9.5 System integrity................................................................................................................. 72
9.5.1 Integrity check on the NCU................................................................................................. 72
9.5.2 PLC security ....................................................................................................................... 72
9.5.2.1 Password to protect confidential PLC configuration data...................................................... 72
9.5.2.2 Access level password ........................................................................................................ 74
9.5.2.3 Password for the protection of the offline safety program.................................................... 75
9.5.2.4 Know-how protection password ......................................................................................... 76
9.5.2.5 Copy protection password .................................................................................................. 76
9.5.2.6 Write protection password.................................................................................................. 77
9.5.3 Trusted devices .................................................................................................................. 77
9.5.3.1 Overview ........................................................................................................................... 77
9.5.3.2 Pairing the NCU and IPC ..................................................................................................... 79
9.5.3.3 Unpairing the NCU and IPC................................................................................................. 80
9.6 Know-how protection ........................................................................................................ 81
9.6.1 SINUMERIK Integrate Lock MyCycles ................................................................................... 81
9.6.2 Encryption of blocks .......................................................................................................... 81
9.7 Secure communication ...................................................................................................... 82
9.7.1 OPC UA.............................................................................................................................. 82
9.7.2 Protocols for network drives ............................................................................................... 83
9.7.3 SSH encryption .................................................................................................................. 84
9.8 Logging and monitoring .................................................................................................... 85
9.8.1 Security Eventlog ............................................................................................................... 85
9.8.1.1 Overview of Security Eventlog............................................................................................ 85
9.8.1.2 Features of Security Eventlog ............................................................................................. 85
9.8.1.3 Transmission of events relevant to security ......................................................................... 86
9.8.1.4 Content of the EventLog .................................................................................................... 87
9.9 Network security and firewall ............................................................................................ 88
9.9.1 Overview ........................................................................................................................... 88
9.9.2 Firewall settings................................................................................................................. 88
9.10 Reduction of the attack surface .......................................................................................... 90
9.10.1 Least functionality of hardware ports and their drivers........................................................ 90
9.10.2 Least functionality of protocols and ports as well as their associated drivers and services..... 91
9.10.3 Finding the latest documentation in SiePortal..................................................................... 91
9.11 Plant security ..................................................................................................................... 93
9.11.1 Physical protection against manipulation of the NCU .......................................................... 93
10 Recommendations for secure operation and secure disposal............................................................. 95
10.1 Recommendations for secure operation of the product ....................................................... 96
10.2 Security by default ............................................................................................................. 97
10.3 Recommendations for secure product disposal ................................................................... 98
10.3.1 General recommendations for disposal............................................................................... 98
10.3.2 Securely disposing of data storage media ........................................................................... 99
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 5
Table of contents
11 Security-critical system states ........................................................................................................... 101
11.1 Overview ......................................................................................................................... 101
11.2 Eboot service system on an USB memory ......................................................................... 102
11.3 Operating system with access to the SD card .................................................................... 103
11.4 Access to the Linux file system with CMC with USB stick.................................................... 104
12 Procedure for managing security updates ........................................................................................ 105
12.1 Vulnerability management ............................................................................................... 105
12.2 Sourcing software updates............................................................................................... 106
12.3 Installing software updates .............................................................................................. 107
12.4 Windows update for IPC systems ...................................................................................... 108
13 Tips for security checks...................................................................................................................... 109
13.1 Checking software signatures........................................................................................... 110
13.1.1 Manually checking software signatures under Windows.................................................... 110
13.1.2 Automatically checking software signatures under Windows............................................. 111
A References ......................................................................................................................................... 113
Glossary ............................................................................................................................................. 115
Index .................................................................................................................................................. 123
Industrial Cybersecurity
6 Configuration Manual, 01/2024, A5E51912408B AB
Introduction 1
1.1 About SINUMERIK
From simple, standardized CNC machines to premium modular machine designs – the
SINUMERIK CNCs offer the right solution for all machine concepts. Whether for individual parts
or mass production, simple or complex workpieces – SINUMERIK is the highly dynamic
automation solution, integrated for all areas of production. From prototype construction and
tool design to mold making, all the way to large-scale series production.
Visit our website for more information SINUMERIK (https://www.siemens.com/sinumerik).
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 7
Introduction
1.2 About this documentation
1.2 About this documentation
1.2.1 Purpose of the documentation
1.2.1.1 Target group
Overview
This documentation is intended for the following target groups:
• Planners and project engineers
• System integrators
• IT department of machine manufacturers (OEM) or end users
The target groups mentioned can use the information provided in this manual to securely
configure and use the product.
In particular system integrators require the information to be able to derive specifications to
define technical security designs. The following issue is of central importance:
• Identify a suitable secure product configuration as component of the system engineering in
which the product will be integrated.
This documentation includes references to security requirements as laid down in IEC
62443-4-2 at the component level. The security requirements of the particular
implementation in the product are compared in Chapter Security functions of the product
(Page 55). This comparison is intended to support system integrators to harmonize product-
specific security functions with the technical security design of the system itself.
1.2.1.2 Data for the technical security design and the secure system configuration
The system integrator defines the technical security design of the system and a secure
configuration of all system components.
As part of this task, a system integrator must clearly understand the security capabilities
of the product, and the recommendations for a secure configuration of the product. A
good understanding of the relevant configuration options can be gained by reading Chapter
System overview (Page 45).
The security capabilities of the product were developed with reference to a specific intended
operational environment, and must be integrated in an overall security concept, as described
in Chapter Security assumptions for the intended operational environment (Page 52).
Generally, the system is the main component of the intended operational environment for
the product, which means that the system integrator must also ensure that the technical
overall security design of the system complies with the assumptions described in Chapter
Security assumptions for the intended operational environment (Page 52). This is absolutely
necessary for the overall system security level, and if the system should not comply with
assumptions, then this is taken into account in the TRA of the system.
Details about the security capabilities and the secure configuration for the product are
provided in Chapter Security functions of the product (Page 55). The specific operating
Industrial Cybersecurity
8 Configuration Manual, 01/2024, A5E51912408B AB
Introduction
1.2 About this documentation
instructions for the settings are not part of this manual; however, you can find these in the
Commissioning Manuals for the relevant product and the current online help.
The recommendations in the specified chapter support system integrators when it comes to
the following security tasks:
• Chapter Recommendations for secure operation and secure disposal (Page 95): Defining
the security documentation for secure operation and secure disposal, which the system
integrator hands over to customers.
• Chapter Procedure for managing security updates (Page 105): Defining the procedure for
managing security updates
• Chapter Tips for security checks (Page 109): Performing security tests
1.2.2 Standard scope
Standard scope
This documentation only describes the functionality of the standard version. This may differ
from the scope of the functionality of the system that is actually supplied. Please refer to the
ordering documentation only for the functionality of the supplied drive system.
It may be possible to execute other functions in the system which are not described in this
documentation. This does not, however, represent an obligation to supply such functions
with a new control or when servicing.
For reasons of clarity, this documentation cannot include all of the detailed information
on all product types. Further, this documentation cannot take into consideration every
conceivable type of installation, operation and service/maintenance.
The machine manufacturer must document any additions or modifications they make to the
product themselves.
Websites of third-party companies
This document may contain hyperlinks to third-party websites. Siemens is not responsible for
and shall not be liable for these websites and their content. Siemens has no control over the
information which appears on these websites and is not responsible for the content and
information provided there. The user bears the risk for their use.
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 9
Introduction
1.3 Documentation on the internet
1.3 Documentation on the internet
1.3.1 Documentation overview SINUMERIK ONE
Comprehensive documentation about the functions provided in SINUMERIK ONE Version 6.13
and higher is provided in the Documentation overview SINUMERIK ONE (https://
support.industry.siemens.com/cs/ww/en/view/109768483).
You can display documents or download them in PDF and HTML5 format.
The documentation is divided into the following categories:
• User: Operating
• User: Programming
• Manufacturer/Service: Functions
• Manufacturer/Service: Hardware
• Manufacturer/Service: Configuration/Setup
• Manufacturer/Service: Safety Integrated
• Information and training
• Manufacturer/Service: SINAMICS
Industrial Cybersecurity
10 Configuration Manual, 01/2024, A5E51912408B AB
Introduction
1.4 Feedback on the technical documentation
1.4 Feedback on the technical documentation
If you have any questions, suggestions, or corrections regarding the technical documentation
published in the Siemens Industry Online Support, use the link "Give feedback" link which
appears at the end of the entry.
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 11
Introduction
1.5 mySupport documentation
1.5 mySupport documentation
With the "mySupport documentation" web-based system you can compile your own individual
documentation based on Siemens content, and adapt it for your own machine documentation.
To start the application, click on the "My Documentation" tile on the "mySupport links and
tools" (https://support.industry.siemens.com/cs/ww/en/my) portal page:
The configured manual can be exported in RTF, PDF or XML format.
Note
Siemens content that supports the mySupport documentation application can be identified by
the presence of the "Configure" link.
Industrial Cybersecurity
12 Configuration Manual, 01/2024, A5E51912408B AB
Introduction
1.6 Service and Support
1.6 Service and Support
Product support
You can find more information about products on the internet:
Product support (https://support.industry.siemens.com/cs/ww/en/)
The following is provided at this address:
• Up-to-date product information (product announcements)
• FAQs (frequently asked questions)
• Manuals
• Downloads
• Newsletters with the latest information about your products
• Global forum for information and best practice sharing between users and specialists
• Local contact persons via our Contacts at Siemens database (→ "Contact")
• Information about field services, repairs, spare parts, and much more (→ "Field Service")
Technical support
Country-specific telephone numbers for technical support are provided on the internet at
address (https://support.industry.siemens.com/cs/ww/en/sc/4868) in the "Contact" area.
If you have any technical questions, please use the online form in the "Support Request" area.
Training
You can find information on SITRAIN at the following address (https://www.siemens.com/
sitrain).
SITRAIN offers training courses for automation and drives products, systems and solutions from
Siemens.
Siemens support on the go
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 13
Introduction
1.6 Service and Support
With the award-winning "Industry Online Support" app, you can access more than 300,000
documents for Siemens Industry products – any time and from anywhere. The app can
support you in areas including:
• Resolving problems when implementing a project
• Troubleshooting when faults develop
• Expanding a system or planning a new system
Furthermore, you have access to the Technical Forum and other articles from our experts:
• FAQs
• Application examples
• Manuals
• Certificates
• Product announcements and much more
The "Industry Online Support" app is available for Apple iOS and Android.
Industrial Cybersecurity
14 Configuration Manual, 01/2024, A5E51912408B AB
Introduction
1.7 Using OpenSSL
1.7 Using OpenSSL
This product can contain the following software:
• Software developed by the OpenSSL project for use in the OpenSSL toolkit
• Cryptographic software created by Eric Young.
• Software developed by Eric Young
You can find more information on the internet:
• OpenSSL (https://www.openssl.org)
• Cryptsoft (https://www.cryptsoft.com)
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 15
Introduction
1.8 General Data Protection Regulation
1.8 General Data Protection Regulation
Overview
Siemens observes standard data protection principles, in particular the data minimization rules
(privacy by design).
For the SINUMERIK Operate, this means:
The product processes/saves the following personal data:
• FullName (optional): Only if user management is activated
• User name + password: Only if user management is activated
• UserID: nur bei aktivierter Benutzerverwaltung
• IP address
• Security events
• Time stamp
It does not involve data from the personal or private sphere.
The above data is required for the user log-in function. The storage of data is appropriate and
limited to what is necessary, as it is essential for the identification of the authorized operator.
(Mandatory here are: user name + password; the FullName is optional.)
The above-mentioned data cannot be stored anonymously or – with the exception of
the user name – pseudonymously, as otherwise the purpose of identifying the operating
personnel cannot be achieved.
Our products do not automatically delete the data mentioned above. The data and logs can
be deleted manually by authorized personnel.
The above data is secured against loss of integrity and confidentiality by Industry State-of-the-
Art Product Security mechanisms.
Industrial Cybersecurity
16 Configuration Manual, 01/2024, A5E51912408B AB
Security instructions 2
2.1 Fundamental safety instructions
2.1.1 General safety instructions
WARNING
Danger to life if the safety instructions and residual risks are not observed
If the safety instructions and residual risks in the associated hardware documentation are not
observed, accidents involving severe injuries or death can occur.
• Observe the safety instructions given in the hardware documentation.
• Consider the residual risks for the risk evaluation.
WARNING
Malfunctions of the machine as a result of incorrect or changed parameter settings
As a result of incorrect or changed parameterization, machines can malfunction, which in turn
can lead to injuries or death.
• Protect the parameterization against unauthorized access.
• Handle possible malfunctions by taking suitable measures, e.g. emergency stop or
emergency off.
2.1.2 Warranty and liability for application examples
Application examples are not binding and do not claim to be complete regarding configuration,
equipment or any eventuality which may arise. Application examples do not represent specific
customer solutions, but are only intended to provide support for typical tasks.
As the user you yourself are responsible for ensuring that the products described are
operated correctly. Application examples do not relieve you of your responsibility for safe
handling when using, installing, operating and maintaining the equipment.
2.1.3 Cybersecurity information
Siemens provides products and solutions with industrial cybersecurity functions that support
the secure operation of plants, systems, machines and networks.
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 17
Security instructions
2.1 Fundamental safety instructions
In order to protect plants, systems, machines and networks against cyber threats, it is
necessary to implement – and continuously maintain – a holistic, state-of-the-art industrial
cybersecurity concept. Siemens’ products and solutions constitute one element of such a
concept.
Customers are responsible for preventing unauthorized access to their plants, systems,
machines and networks. Such systems, machines and components should only be connected
to an enterprise network or the internet if and to the extent such a connection is necessary
and only when appropriate security measures (e.g. firewalls and/or network segmentation)
are in place.
For additional information on industrial cybersecurity measures that may be implemented,
please visit
https://www.siemens.com/cybersecurity-industry.
Siemens’ products and solutions undergo continuous development to make them more
secure. Siemens strongly recommends that product updates are applied as soon as they are
available and that the latest product versions are used. Use of product versions that are no
longer supported, and failure to apply the latest updates may increase customer’s exposure
to cyber threats.
To stay informed about product updates, subscribe to the Siemens Industrial Cybersecurity
RSS Feed under
https://new.siemens.com/cert.
Further information is provided on the Internet:
Industrial Security Configuration Manual (https://support.industry.siemens.com/cs/ww/en/
view/108862708)
WARNING
Unsafe operating states resulting from software manipulation
Software manipulations, e.g. viruses, Trojans, or worms, can cause unsafe operating states in
your system that may lead to death, serious injury, and property damage.
• Keep the software up to date.
• Incorporate the automation and drive components into a state-of-the-art, integrated
industrial cybersecurity concept for the installation or machine.
• Make sure that you include all installed products in the integrated industrial cybersecurity
concept.
• Protect files stored on exchangeable storage media from malicious software by with suitable
protection measures, e.g. virus scanners.
• Carefully check all cybersecurity-related settings once commissioning has been completed.
Industrial Cybersecurity
18 Configuration Manual, 01/2024, A5E51912408B AB
What is industrial cybersecurity? 3
Definition of industrial cybersecurity
Generally, industrial cybersecurity is understood to be all of the measures for protecting against
the following:
• Loss of confidentiality due to unauthorized access to data
• Loss of integrity due to data manipulation
• Loss of availability (e.g. due to destruction of data or Denial-of-Service (DoS))
Objectives of industrial cybersecurity
The objectives of industrial cybersecurity encompass:
• Fault-free operation and guaranteeing of availability of industrial plants and production
processes
• Preventing hazards to people and production due to cyber security attacks
• Protection of industrial communication from espionage and manipulation
• Protection of industrial automation systems and components from unauthorized access and
loss of data
• Practicable and cost-effective concept for securing existing systems and devices that do not
have their own security functions
• Utilization of existing, open, and proven industrial cybersecurity standards
• Fulfillment of legal requirements
An optimized and adapted security concept applies for automation and drive technology. The
security measures must not hamper or endanger production.
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 19
What is industrial cybersecurity?
3.1 Delimitation: Functional safety and industrial cybersecurity
3.1 Delimitation: Functional safety and industrial cybersecurity
Safety functions
Safety functions ensure the reliable functioning of safety-related components and functions,
which must ensure that either the plant remains in a safe state or it is brought into a safe state
if a fault occurs.
The highest priority is the prevention of systematic errors and the control of random errors or
failures.
Functional safety guarantees the safety of persons and goods in the immediate vicinity of a
component.
Security functions
Security functions and measures, on the other hand, maintain the expected system behavior by
protecting against cyber attacks or unintended manipulation.
Cyber attacks and threats potentially leading to the failure of a component occur throughout
the life cycle. For this reason security functions and measures must be regularly evaluated
and adapted.
Industrial Cybersecurity
20 Configuration Manual, 01/2024, A5E51912408B AB
Why is industrial cybersecurity so important? 4
4.1 Trends with an impact on industrial cybersecurity
Global trends
There are many new trends which affect industrial cybersecurity. These effects underscore the
relevance of security functions and measures.
• Cloud computing in general
The number of network connections across the world is constantly increasing. This
increasingly enables technologies such as cloud computing and the associated applications.
In conjunction with cloud computing, there has been a massive increase in the number of
mobile devices, such as cell phones and tablet PCs.
• Wireless technology
On the other hand, the increasing use of mobile devices has only become possible thanks to
the ubiquitous availability of mobile networks. Wireless LAN is also becoming increasingly
available. The development of new WLAN and mobile radio standards continues to advance.
• Worldwide remote access to plants, machines and mobile applications
• The Internet of Things (IoT)
Millions of electronic devices are now network-capable and are communicating via the
Internet.
To keep networked components and applications running smoothly, your plant needs a
network infrastructure and applications that reliably protect against cyber attacks.
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 21
Why is industrial cybersecurity so important?
4.2 Possible corporate security vulnerabilities
4.2 Possible corporate security vulnerabilities
Possible corporate security vulnerabilities
The security chain of a company is only as strong as its weakest link. Security vulnerabilities can
occur in numerous places in an organization, such as:
• Employees / external companies
• Production plants
• Network infrastructure
• Data centers / PC workstations
• Laptops/tablets
• Printers
• Smartphones/smartwatches
• Mobile data storage media
A holistic approach is needed to identify security problems and find solutions. Binding
guidelines and regulations must address all relevant areas of a company: Devices, systems,
processes and employees.
Industrial Cybersecurity
22 Configuration Manual, 01/2024, A5E51912408B AB
Why is industrial cybersecurity so important?
4.3 Why is industrial cybersecurity so important?
4.3 Why is industrial cybersecurity so important?
The topic of data security is becoming increasingly important in the industrial environment,
especially due to the worldwide increase in legal requirements for data protection.
Possible threats:
Potential security threats include confidentiality, integrity, and availability. Examples of threats
are:
• Espionage of data
• Manipulation of data or software
• Sabotage of production plants
• System stoppage, e.g. due to virus infection or malware
• Unauthorized use of system functions
Possible effects of a security incident
• Loss of intellectual property
• Loss of production or reduced product quality
• Negative company image and economic damage
• Catastrophic environmental influences
• Danger to people and machines
Industrial Cybersecurity
Configuration Manual, 01/2024, A5E51912408B AB 23
Why is industrial cybersecurity so important?
4.3 Why is industrial cybersecurity so important?
Industrial Cybersecurity
24 Configuration Manual, 01/2024, A5E51912408B AB
General security measures in automation and
drive technology 5
5.1 Security measures
Integration of security into the products
The following measures ensure the integration of security in current Siemens products for
automation and drive technology:
• The requirements specified in IEC 62443-4-1 for the product lifecycle management (PLM)
process are implemented. The implementation was certified by TÜV.
• Code analyses are used to identify and correct possible errors.
• Siemens implements measures to secure integrity in its products and its manufacturing
processes.
• Siemens constantly checks the measures relating to hardening:
– Operating systems are configured in such a way that points of attack (e.g. via ports,
unneeded services) are minimized.
– Siemens tests its products to detect weak points at an early stage.
– Siemens checks its products for security weak points during development and performs
appropriate patch management.
– As manufacturer of automation and drive products, Siemens supports secure operation
through direct support of system integrators and operating companies by providing
patches, security components and the appropriate services.
Protection of the development infrastructure and supply chains
As manufacturer of automation and drive products, Siemens supports secure operation of the
products by securing the development infrastructure and supply chains:
• The Siemens ProductCERT (https://www.siemens.com/cert/en/cert-security-advisories.htm)
(Cyber Emergency Readiness Team) is the central department for security-related incidents
in the Siemens product and solution environment. Siemens ProductCERT supports
development departments in the form of consulting and other services. ProductCERT
provides information about current threats and vulnerabilities as well as the appropriate
countermeasures.
• Industrial cybersecurity is a dynamic and complex subject that requires continuous
monitoring and adaptation of new security measures. Information on how Siemens protects
its products and solutions against cyber attacks and how industry profits from the
competence of Siemens can be found on the Internet (https://new.siemens.com/global/en/
products/automation/topic-areas/industrial-security.html).
Industrial Cybersecurity
Configuration Manual, 01/2024, Показано початок документа. Повний текст — у PDF за посиланням вище.
Документ виробника, опублікований як довідковий матеріал на обладнання, яке ми постачаємо. Правовласник може попросити прибрати його — приберемо.
