Plant Security - Siemens SINAMICS Configuration Manual

Industrial security, medium-voltage converter
Hide thumbs Also See for SINAMICS:
Table of Contents

Advertisement

General security measures

4.1 Plant security

● Plant security
Plant security represents the outermost protective ring. Plant security includes
comprehensive physical security measures, e.g. entry checks, which should be closely
coordinated with protective measures for IT security.
● Network security
The measures, grouped under the keyword "Network security", form the core of the
protective measures. This refers to the segmentation of the plant network with limited and
secure communication between subnetworks ("secure islands") and the interface check
with the use of firewalls.
● System integrity
"System integrity" represents the combination two major measures. PC-based systems and
the control level must be protected against attacks. Steps include the following measures:
– User authentication for machine or plant operators with individual authorization levels
– Integrated access protection mechanisms in the automation components to prevent
– The use of antivirus and whitelisting software to protect PC systems against malware
– Maintenance and update processes to keep the automation systems up-to-date
4.1
Plant security
Unauthorized persons may be able to enter the production site/building and damage or alter
production equipment as a result of gaps in a company's physical security. Confidential
information can also be lost. This can be prevented if both the company's site and the
production areas are protected accordingly.
4.1.1
Physical protection of critical production areas
Company security
The company's physical security can be ensured via the following measures:
● Closed off and monitored company premises
● Entry control, keys / card readers and/or security personnel
● Escorting of external personnel by company employees
● Security processes in the company are taught and followed by all employees
20
unauthorized changes via the engineering system or during maintenance
(e.g. patch management, firmware updates, etc.)
Configuration Manual, 08/2017, A5E36912609A
Industrial Security

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents