Siemens SIMATIC S7-1500 System Manual page 30

Drive controller
Hide thumbs Also See for SIMATIC S7-1500:
Table of Contents

Advertisement

Industrial cybersecurity
4.4 Integrated security concept and security strategies
Employee awareness
Regular training in cybersecurity and continuous testing of training success are essential so
that cybersecurity measures are internalized in processes and work instructions. This involves
general training in the use of software and IT hardware for company communication and as
work tools, e.g.:
• secure handling of USB devices
• encrypted communication
• use of VPN
• rules for passwords and use of access
• setting up two-factor authentication
• educating employees about the dangers posed by malware, phishing, social engineering,
etc.
Furthermore, if applicable, production equipment and software training should always
include the topic of cybersecurity.
Maintaining the security concept through updates
Keeping software up-to-date is essential, for example, to benefit from the following
measures:
• Implementation of new security strategies, protocols and techniques
• Closing of security vulnerabilities
• Elimination of security vulnerabilities
To this end, it is necessary to keep a constant eye on the further development of protective
measures and, if necessary, the expansion of requirements.
It is recommended to:
• Set up notifications for (security) updates
• Subscribe to information on vulnerabilities
• Monitor and implement the further development of the technology, especially in the area
of cybersecurity
In short: Always keep technology and knowledge up to date.
Consideration of the risks posed by cyber attacks in the Threat and Risk Assessment (TRA)
Make an inventory of all software, hardware, and infrastructure devices, in order to identify
risks to the location or organization. Incident response procedures must be incorporated into
all IT and manufacturing processes. The choice of risk mitigation measures should be based
on a cost-benefit analysis and classification of risks. This is followed by the introduction of
cybersecurity rules and procedures and the training of personnel.
28
SIMATIC Drive Controller
System Manual, 11/2023, A5E46600094-AD

Advertisement

Table of Contents
loading

Table of Contents