show the entry list
Industrial Ethernet network components (security) -- Product information -- System description
Configuration Limits of Security Configuration Tool (SCT)
Where can you find information on the topic of "Industrial Security"?
Cellular Radio Components (GSM) -- Product information -- System description
How do you code an SMS text in the GSM 3.38 cellular radio standard?
Which security modules support dynamic DNS and can use it to communicate with each other?
Why does the VPN LED of the SCALANCE M875 and MD741-1 continue to light although the secure IPsec tunnel connection is disconnected?
What measures should you take when the radio transmission is very sluggish or unstable due to a bad radio link?
Where can you find information on the topic of "Industrial Security"?
SINAUT - TIMs -- Product information -- System description
Which mechanisms does the CP1242-7 use in the "TeleControl" mode for sending and receiving data?
Which security mechanisms does the TeleControl Basic system offer?
What measures should you take when the radio transmission is very sluggish or unstable due to a bad radio link?
Where can you find information on the topic of "Industrial Security"?
What are the requirements for using the S7 routing function and which modules can you implement?
Industrial Security -- Product information -- System description
What should you watch out for when you enable the "SNMP" function in the configuration of the security module?
Which security modules support dynamic DNS and can use it to communicate with each other?
Why does the VPN LED of the SCALANCE M875 and MD741-1 continue to light although the secure IPsec tunnel connection is disconnected?
What should you watch out for when enabling and using the security functions of CP343-1 Advanced and CP443-1 Advanced?
How can you display the security status of the CP1628 over the Online View in the Security Configuration Tool (SCT)?
What remedies are there for weak points in WinCC flexible 2008 and WinCC V11?
Where can you find information on the topic of "Industrial Security"?
Where can you find information on the topic of "Industrial Security"?
Part number:

Description
This entry provides an overview of:

Industrial Security
The growing networking of industrial plants increases productivity. At the same time, however, IT security risks increase likewise, which must be tackled with appropriate protective mechanisms for Industrial Security. It is essential here to have an overall perception that includes both technical measures and staff training as well as the definition of guidelines and processes. This is necessary to achieve optimum security and ensure secure operation of the plant.
More information about technical solutions and our service offering for industrial security is available in the internet at:
http://www.industry.siemens.com/industrial-security

Applications & Tools
The Applications & Tools below provide information on the topic of "Industrial Security".
 
Applications & Tools Description Entry ID
Security with SIMATIC NET This application provides an overview of possible security configurations in the Local Area Network (LAN) and WAN (Wide Area Network) with SCALANCE S61x modules and the SOFTNET security client. 27043887
Industrial Security with SCALANCE S modules via IPSec VPN tunnel (Configuration 4) These applications show safe teleservicing with SCALANCE S via a Virtual Private Network (VPN). 22056713
Secure remote access to SIMATIC stations via Internet and EGPRS router MD741-1 and SCALANCE S612 (Configuration 9)  24960449
Protection of an automation cell by the Security Module SCALANCE S602 via firewall (bridge/routing) (Configuration 5) This application shows the configuration of a secure automation cell with SCALANCE S firewall. 22376747
SINAUT ST7 Telecontrol sample configurations in Ethernet, secure Internet and (E)GPRS environment (Configuration 8) This application shows the configuration of secure internet connections for Telecontrol stations with SINAUT ST7 23810112
User login on the operator panel via HMI-RFI This application shows how to carry out a secure user login on an operator panel with an HMI-RFI (card reader). 35214239
Diagnostics and teleservicing of SIMATIC Industry PCs This application shows you how to use the teleservicing option with SIMATIC Industry PCs and the integrated Intel AMT technology. 52310936
Table 01

Microsoft Security Updates
The entries below provide information about using Microsoft Security Updates together with WinCC, PCS 7, SIMOTION and SINUMERIK.
 
Product Entry title Entry ID
WinCC Which Microsoft Security Patches are released for use with SIMATIC WinCC? 18752994
PCS 7 Which Microsoft Security Patches have been tested for compatibility with SIMATIC PCS 7? 18490004
SIMOTION SIMOTION P350: Compatibility of Microsoft security patches 22159441
SINUMERIK   SINUMERIK 810D/840Di/840D: Compatibility of Microsoft security patches with SINUMERIK PCU 50/70 19739695
Table 02

Virus Protection
The manuals and entries below provide information about virus protection for PCS 7 and SINUMERIK.
 
Product Entry or manual title Entry ID
STEP 7
STEP 7 V5.3, V5.4 and V5.5. Which virus scanner versions can you use for STEP 7 V5.3, V5.4 and V5.5? 37208360
PCS 7
Trend Micro Office Scan SIMATIC Process Control System PCS 7 Configuration Trend Micro Office Scan V7.3 incl. Patch 2 38006151
Configuration Trend Micro OfficeScan V8.0 38006929
Symantec AntiVirus SIMATIC Process Control System PCS 7 Configuration Symantec AntiVirus V10.2 38006339
Symantec Endpoint Protection SIMATIC Process Control System PCS 7 Configuration Symantec Endpoint Protection 11.0 38004530
McAfee VirusScan SIMATIC Process Control System PCS 7 Configuration McAfee VirusScan (V8.5; V8.5i; V8.7) 38006821
SINUMERIK  
SINUMERIK   Notes on virus protection for SINUMERIK 840D sl / 840Di sl 19577116
Table 03

Whitelisting Protection Mechanisms
The entries below provide information about using whitelisting protection mechanisms with SIMATIC products.
 
Product Entry title Entry ID
STEP 7 V5.5 Using whitelisting protection mechanisms with SIMATIC products 49382928
PCS7 V7.1 + SP2
WinCC V7.0 + SP1
WinCC V7.0 + SP2
WinCC flexible 2008 + SP2
Table 04

Firewall
The entries below provide information about configuring a firewall.
 
Product Entry title Entry ID
SCALANCE S Which firewall rules should you configure for SCALANCE S in order to have access to the internet with the PG/PC via the SCALANCE and router? 26517928
Which firewall rules do you have to define for SCALANCE S in the Security Configuration Tool to allow data traffic between internal and external networks for a specific IP address area? 34675703
EGPRS Router Which firewall rules should you configure for the EGPRS router MD741-1 in order to have access to the internet with the PG/PC from the LAN of the MD741-1? 31525978
Security Configuration Tool What are the restrictions when configuring the bandwidth limit of a firewall rule with the Security Configuration Tool V2.1? 27080202
Table 05

Virtual Private Network (VPN)
The entries below provide information about configuring a Virtual Private Network (VPN) with SCALANCE S and SOFTNET Security Client.
 
Product Entry title Entry ID
SOFTNET Security Client How do you configure a VPN tunnel between a PC station and SCALANCE S61x via the internet with the 2008 edition of SOFTNET Security Client? 32447942
How do you configure a VPN tunnel between a PC station and SCALANCE S61x V2.1 via the internet with the SOFTNET Security Client Edition 2005 HF1? 24953806
SCALANCE S How is a VPN tunnel between two SCALANCE S S 61x modules configured in Routing mode via the internet? 24968210
How do you configure a VPN tunnel between a PC station with Windows XP SP2 and SCALANCE S61x V2.1 via the internet with the Microsoft Management Console? 26098354
What can you do if there is no VPN tunnel set up in the SCALANCE S 61x, the SOFTNET Security Client or the MD740-1? 26361542
What configuration steps are necessary to forward the coded data packages incoming on the SCALANCE S61x from the VPN tunnel to specific internal nodes only? 24533873
Table 06  

Access Control
The entries below provide information about access control in process control systems like PCS 7.
 
Product Entry title Entry ID / Link
WinCC / PCS 7 Process Control System Which safety precautions help against unauthorized access in the SIMATIC PCS 7 / WinCC environment? 44443744
WinCC / PCS 7 SCADA System
PCS 7 Process Control System Security concept 60119725
Table 07

Remote Access via Internet, Gateways
The entries below provide information about Remote Access via the internet and you you can use an Industrial Ethernet CP or SCALANCE S as a gateway.
 
Product Entry title Entry ID
Remote Access with WinCC flexible What are the options for remote maintenance of a WinCC flexible Runtime system (Panel/PC) via the internet (WAN)? 19865167
Industrial Ethernet CP or SCALANCE S as Gateway How do you use an Industrial Ethernet CP or SCALANCE S as a gateway? 45632056
Table 08

Stuxnet
The entries below provide information about the latest developments and the measures recommended by Siemens for handling Stuxnet.
 
Product Entry title Entry ID
WinCC / PCS 7 SIMATIC WinCC / SIMATIC PCS 7: Information about malware / viruses / Trojan horses 43876783
SIMOTION SIMOTION: Latest information about malware / viruses / Trojan horses 44050544
SINUMERIK   SINUMERIK PCU: Latest information about malware / viruses / Trojan horses 44050056
Table 09

Protection against Manipulation
Information about how to recognize and prevent program code manipulation in STEP 7 V5.5 is available in Entry ID: 51577287.

 Entry ID:50203404   Date:2012-09-04 
I regard this article....as helpfulas not helpful                                 
mySupport
My Documentation Manager 
Newsletter 
CAx-Download-Manager 
Support Request
To this entry
Print
Create PDF 
Send to a friend
QuickLinks
Compatibility tool 
Help
Online Help
Guided Tour