SlideShare ist ein Scribd-Unternehmen logo
1 von 10
Downloaden Sie, um offline zu lesen
Decrease your HMI/SCADA risk
Are you running your plant operations with serious risk? Most
industrial applications lack recommended updates and security
patches, which make them a target for hackers. Outdated
architectures, backups and spares can also create problems.
With the number of attacks on industrial applications rising and
the critical need for plant system availability, take simple steps
now to minimize risk. You can decrease unplanned downtime
while helping to protect your organization. Here’s how …
Check the expiration date
Software doesn’t usually come with an expiration date. But, the
expiration date on your operating system might have already
passed. If you’re using Windows XP®
, that “expiration date”
was April 8, 2014 – the date that Microsoft stopped supporting
XP. Don’t use software that is no longer supported by the
manufacturer; you could be running with serious risk every day.
In addition to your OS, make sure your other software packages
are still supported. Were any of the vendors acquired? Do the
new companies still support those software packages?
Key steps to minimize unplanned downtime and protect your organization.
Our business ­environment today is constantly ­changing –
make sure your ­software is keeping up.
GE
Intelligent Platforms
Schedule HMI/SCADA risk
assessments and reviews
Minimizing risk isn’t a one-time or once-a-
year activity. With serious threats on the rise,
you need to incorporate risk assessments
and reviews into your schedule.
The frequency of your risk assessments
depends on your particular business,
industry and plant applications. Start with a
conservative, ­high-frequency schedule – and
you can always increase the time between
assessments, as needed.
Assign a champion to minimize risk in your
plant operations to drive leadership and
consistency to the program.
1.	 Are you using obsolete software
	 (Windows XP or other)?
2.	 Are you running your application with 	
	­non-default / non-Administrator accounts
	 with low privileges? Have you removed
	 ADMIN and GUEST default accounts, using
	 a separate administrator account?
3.	 Where are the points of entry/failure?
4.	 Are you properly isolating (DMZ) servers
	 from untrusted network access?
5.	 Is your system missing any security
	 patches? Are you using the most
	 up-to-date version of your software?
6.	 Are you managing Bring Your Own
	 Device (BYOD) securely?
7.	 Do you have spare parts, and when
	 were they last tested?
8.	 Have you put additional controls in place
	 to protect the HMI/SCADA security files
	 from unauthorized change?”
9.	 Have you changed the default password 	
	 for Trusted Network Computing?
10.	Do you have an up-to-date backup
	 plan in place?
10 sample questions for each review
Upgrade, the right way
Don’t wait for unplanned downtime
or a disaster. Take action now.
If you do have outdated software in your plant
operations, make a plan now to upgrade the
right way. Rethink your HMI/SCADA strategy –
securely. Some HMI/SCADA users haven’t updated
their systems in 10 years or more. Don’t just
upgrade. Review your system with experts and
use an upgrade as an opportunity to assess and
modernize.
Consider technologies that will make the life of
your Plant & IT personnel easier. For example:
6	 Can existing XP machines be converted
	 into thin clients or virtualized?
6	 Can critical applications be migrated 	
to a server-based machine?
6	 Time to rethink your app strategy. How 	
many applications are you running that
	 could be consolidated?
6	 What applications can you leverage to 			
turn your installation into a web-enabled
one? Have you looked into GE Webspace and
GE Cimplicity?
6	 What applications are available now that can 	
extend the functionality of your HMI/SCADA? 	
Consider new levels of efficiency by adding 	
simple analytics, task management, alarm
	 response management, and more.
6	 How are you storing and analyzing your data to 	
improve operations? It might be time to look 	
into a plant-wide Historian.
4 steps to include in your upgrade plan
6	 Check and limit users’ rights
6	 Update / install the latest anti-virus software
6	 Create a controlled zone around your machines 	
– place them behind a firewall
6	 Make sure you have installed all of the latest 	
service packs
General IT Industrial Control System
Confidentiality
Integrity
Availabilty
Availabilty
Integrity
Confidentiality
Highest Priority
Lowest Priority
Put rigor around security
General IT goals and industrial control systems
goals have historically differed. Make sure you
review your goals and adjust as necessary, with
consideration for the increase in industrial
security threats and ­requirements for
data protection and privacy.
The priority for plant systems has historically been availability.
Plant operations simply must keep running in order to achieve
organizational success. However, plant operations teams need
to include cyber security as a high priority and implement best
practices to minimize vulnerabilities.
Security is the process of maintaining the confidentiality,
integrity, and availability of a system:
6	 Confidentiality: Ensure only the people you want
	 to see information can see it.
6	 Integrity: Ensure the data is what it is supposed to be.
6	 Availability: Ensure the system or data is available for use.
Source: Cyber Security Assessments of Industrial Control Systems, CNPI / US Homeland Security, Nov 2010.
Router
Firewall
DMZ Public
Web Server
SCADA ServerSCADA Server
Attack Targets
VPN
Web Server
Assess your current HMI/SCADA system, preferably with an outside
expert, and develop a plan to reduce risk. You can identify common
vulnerabilities and take action before a disaster.
Leverage standards and best practices
Your software vendors have the best
information regarding your particular
applications. Reach out to them for
their advice and best practices. Read
your software manuals and follow the
instructions, especially concerning
networks/connectivity and user accounts/
privileges. For example, if a manual
recommends that you disable or remove
a certain account after installing an I/O
driver, then don’t forget to do it.
Also, tap into the many industry
associations. Learn about new standards
and implement the parts that fit your
situation. Not every standard – or even
all sections of a standard – will work for
you, but you can use the standards as a
framework and add to them.
Check into ISA, MESA and other plant
systems organizations for more
information and learning opportunities
during the year. Government agencies,
such as the U.S. Department of Homeland
Security, National Institute of Standards
and Technology (NIST), and U.S.
Department of Energy, have valuable
information – which applies to almost
every SCADA user.
Additionally, some industries such as water
and power have entities such as the North
American Electric Reliability Corp. (NERC),
which provide information on HMI/SCADA
risk reduction and security.
A wealth of current information exists about how to reduce risk in HMI/SCADA systems.
Patch
management
System
hardening
Host-based
protection
HMI/SCADA
configuration
6 Define a risk-based patching policy & procedure
6 Apply the latest Microsoft security patches
6 Ensure coverage for all layers and assets (OS, DB, etc.)
6 Disable unnecessary ports, services, accounts & shares
6 Define secure configuration standards for all asset types
6 Consider restricting the use of untrusted USB media
6 Install anti-virus software on control systems PCs
6 Keep anti-virus definitions up-to-date
6 Consider HIPS/HIDS or application white-listing solutions
6 Deploy in a DMZ architecture configuration
6 Install application using a least-privileged user account
6 Disable or remove default accounts
6 Configure applications to require user authentication
6 Configure applications to use SSL or encrypted communication
6 Limit access to functions at all levels:
- By role: only give to the users access to what they really need
- By server
- By runtime/development
- By asset/device
6 Implement e-signature for complete regulatory and procedural compliance
HMI/SCADA Security - Best practices example
External/Remote Data Sources
GE Agent can be used to create trusted encrypted remote
connections over the internet using standard ports.
Firewall
DMZ
Agent
Manager
Remote
Site 1
Remote
Site 2
Remote
Site 1000x
Internal Data Sources
GE Agent can be used to create trusted connections between
networks internally to build a layered defense solution.
DMZ
Agent
Manager
Firewall
Controls
Network
Smart with
secure-by-design
innovation
The good news is that HMI/SCADA software designs can inherently
minimize some vulnerability to risk. Fundamental engineering principles
mandate safe and reliable systems. Additionally, new secure-by-design
innovation takes traditional practices to a higher level.
As an example, GE’s Agent provides an encrypted and authenticated
channel to forward monitoring and diagnostic data from remote
agents to a central repository over an intranet or the internet,
replacing the need for dedicated VPN connections.
This secure-by-design technology also delivers functionality to send
files and/or create RDP sessions from the GE Agent Enterprise Server to
GE Agents over the established connection.
Minimizing risk is, and always will be, a top priority
for GE Intelligent Platforms – and should be a top
priority for every HMI/SCADA user. Take advantage
of standards, best practices and information
sharing. GE works with customers, industry
working groups and standards bodies, government
agencies, and the security research community
to continually improve industrial automation and
control systems and global infrastructures.
Plan a risk assessment program for your
organization – and stick with it. Simple steps, such
as upgrading unsupported software and limiting
user rights, can make a big difference. There are
many ways to reduce risk, but it is important to
take the steps now – before unplanned downtime
or a disaster occur.
Summary
Need help with minimizing HMI/SCADA risk?
Contact GE for complimentary risk
assessment tools and information.
www.ge.com/digital
GE
www.ge.com/digital
www.ge.com/digital
Microsoft
http://www.microsoft.com/en-us/windows/
enterprise/endofsupport.aspx
http://windows.microsoft.com/eos
Associations / Government Agencies
ISA
MESA
U.S. Department of Homeland Security
National Institute of Standards & Technology
U.S. Department of Energy
North American Electric Reliability Corp
EU CSS
European Union Network and Information
Security Agency
Useful links
Contact information
Americas: 1-855-YOUR1GE (1-855-968-7143)
gedigital@ge.com
www.ge.com/digital
©2015 General Electric. All rights reserved. *Trademark of
General Electric. All other brands or names are property of
their respective holders. Specifications are subject to
change without notice.
About GE
GE (NYSE: GE) is the world’s Digital Industrial Company, transforming industry with
software-defined machines and solutions that are connected, responsive and
predictive. GE is organized around a global exchange of knowledge, the "GE Store,"
through which each business shares and accesses the same technology, markets,
structure and intellect. Each invention further fuels innovation and application across
our industrial sectors. With people, services, technology and scale, GE delivers better
outcomes for customers by speaking the language of industry. www.ge.com

Weitere ähnliche Inhalte

Was ist angesagt?

Fluke Connect Condition Based Maintenance
Fluke Connect Condition Based MaintenanceFluke Connect Condition Based Maintenance
Fluke Connect Condition Based Maintenance
Frederic Baudart, CMRP
 
Tripwire enterprise 87_datasheet
Tripwire enterprise 87_datasheetTripwire enterprise 87_datasheet
Tripwire enterprise 87_datasheet
Devaraj Sl
 

Was ist angesagt? (20)

RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet ArchitecturesRA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
RA TechED 2019 - NT03 - Building Converged Plantwide Ethernet Architectures
 
Critical Infrastructure Security by Subodh Belgi
Critical Infrastructure Security by Subodh BelgiCritical Infrastructure Security by Subodh Belgi
Critical Infrastructure Security by Subodh Belgi
 
Cruatech Services Intro
Cruatech Services IntroCruatech Services Intro
Cruatech Services Intro
 
Industria 4.0. Lucca, 5 luglio 2017 - The Connected Enterprise
Industria 4.0. Lucca, 5 luglio 2017 - The Connected EnterpriseIndustria 4.0. Lucca, 5 luglio 2017 - The Connected Enterprise
Industria 4.0. Lucca, 5 luglio 2017 - The Connected Enterprise
 
Nozomi Networks SCADAguardian - Data-Sheet
Nozomi Networks SCADAguardian - Data-SheetNozomi Networks SCADAguardian - Data-Sheet
Nozomi Networks SCADAguardian - Data-Sheet
 
Fluke Connect Condition Based Maintenance
Fluke Connect Condition Based MaintenanceFluke Connect Condition Based Maintenance
Fluke Connect Condition Based Maintenance
 
Industry Reliability and Security Standards Working Together
Industry Reliability and Security Standards Working TogetherIndustry Reliability and Security Standards Working Together
Industry Reliability and Security Standards Working Together
 
CompTIA PenTest+: Everything you need to know about the exam
CompTIA PenTest+: Everything you need to know about the examCompTIA PenTest+: Everything you need to know about the exam
CompTIA PenTest+: Everything you need to know about the exam
 
Bringing manufacturing in house with secure IIoT communications | Siemens & P...
Bringing manufacturing in house with secure IIoT communications | Siemens & P...Bringing manufacturing in house with secure IIoT communications | Siemens & P...
Bringing manufacturing in house with secure IIoT communications | Siemens & P...
 
Tripwire enterprise 87_datasheet
Tripwire enterprise 87_datasheetTripwire enterprise 87_datasheet
Tripwire enterprise 87_datasheet
 
Top 10 SIEM Best Practices, SANS Ask the Expert
Top 10 SIEM Best Practices, SANS Ask the ExpertTop 10 SIEM Best Practices, SANS Ask the Expert
Top 10 SIEM Best Practices, SANS Ask the Expert
 
Safety reliability and security lessons from defense for IoT
Safety reliability and security lessons from defense for IoTSafety reliability and security lessons from defense for IoT
Safety reliability and security lessons from defense for IoT
 
BMC - Response to the SolarWinds Breach/Malware
BMC - Response to the SolarWinds Breach/MalwareBMC - Response to the SolarWinds Breach/Malware
BMC - Response to the SolarWinds Breach/Malware
 
eGestalt Announces Next Generation Security Posture Management with Aegify
eGestalt Announces Next Generation Security Posture Management with AegifyeGestalt Announces Next Generation Security Posture Management with Aegify
eGestalt Announces Next Generation Security Posture Management with Aegify
 
OneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to Many
 
Many products-no-security (1)
Many products-no-security (1)Many products-no-security (1)
Many products-no-security (1)
 
The Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDThe Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMD
 
SOC Foundation
SOC FoundationSOC Foundation
SOC Foundation
 
eGestalt Announces Next Generation Security Posture Management with Aegify
eGestalt Announces Next Generation Security Posture Management with AegifyeGestalt Announces Next Generation Security Posture Management with Aegify
eGestalt Announces Next Generation Security Posture Management with Aegify
 
Splunk for Monitoring and Diagnostics in the Industrial Environment
Splunk for Monitoring and Diagnostics in the Industrial Environment Splunk for Monitoring and Diagnostics in the Industrial Environment
Splunk for Monitoring and Diagnostics in the Industrial Environment
 

Andere mochten auch

GE 이노베이션 포럼 2017 LIVE 발표자료 - 임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수
GE 이노베이션 포럼 2017 LIVE 발표자료 -  임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수GE 이노베이션 포럼 2017 LIVE 발표자료 -  임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수
GE 이노베이션 포럼 2017 LIVE 발표자료 - 임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수
GE코리아
 
GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장
GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장
GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장
GE코리아
 

Andere mochten auch (7)

GE 이노베이션 포럼 2017 LIVE 발표자료 - 임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수
GE 이노베이션 포럼 2017 LIVE 발표자료 -  임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수GE 이노베이션 포럼 2017 LIVE 발표자료 -  임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수
GE 이노베이션 포럼 2017 LIVE 발표자료 - 임채성 한국 인더스트리4.0협회장 및 건국대 경영대학 기술경영학과 교수
 
GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장
GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장
GE 이노베이션 포럼 2017 LIVE 발표자료 - 빌 루 GE 최고디지털책임자 겸 GE Digital 사장
 
GE의 디지털 산업 변화 - GE's Digital Industrial Transformation Playbook
GE의 디지털 산업 변화 - GE's Digital Industrial Transformation PlaybookGE의 디지털 산업 변화 - GE's Digital Industrial Transformation Playbook
GE의 디지털 산업 변화 - GE's Digital Industrial Transformation Playbook
 
GE RailConnect™ 360
GE RailConnect™ 360GE RailConnect™ 360
GE RailConnect™ 360
 
GE LV5 1500V 태양광 인버터(LV5 1500V Solar Inverter)
GE LV5 1500V 태양광 인버터(LV5 1500V Solar Inverter)GE LV5 1500V 태양광 인버터(LV5 1500V Solar Inverter)
GE LV5 1500V 태양광 인버터(LV5 1500V Solar Inverter)
 
산업용 클라우드 플랫폼 - 프레딕스, Industrial cloud platform – Predix, 2016스마트공장 국제 컨퍼런스
산업용 클라우드 플랫폼 - 프레딕스, Industrial cloud platform – Predix, 2016스마트공장 국제 컨퍼런스산업용 클라우드 플랫폼 - 프레딕스, Industrial cloud platform – Predix, 2016스마트공장 국제 컨퍼런스
산업용 클라우드 플랫폼 - 프레딕스, Industrial cloud platform – Predix, 2016스마트공장 국제 컨퍼런스
 
GE의 스마트 공장, 생각하는 공장(Brilliant Factory) - 2016 스마트공장 국제 컨퍼런스
GE의 스마트 공장, 생각하는 공장(Brilliant Factory) - 2016 스마트공장 국제 컨퍼런스GE의 스마트 공장, 생각하는 공장(Brilliant Factory) - 2016 스마트공장 국제 컨퍼런스
GE의 스마트 공장, 생각하는 공장(Brilliant Factory) - 2016 스마트공장 국제 컨퍼런스
 

Ähnlich wie HMI/SCADA 리스크 감소

Dr. Eric Cole - 30 Things Every Manager Should Know
Dr. Eric Cole - 30 Things Every Manager Should KnowDr. Eric Cole - 30 Things Every Manager Should Know
Dr. Eric Cole - 30 Things Every Manager Should Know
Nuuko, Inc.
 

Ähnlich wie HMI/SCADA 리스크 감소 (20)

Ten questions to ask before choosing SCADA software
Ten questions to ask before choosing SCADA softwareTen questions to ask before choosing SCADA software
Ten questions to ask before choosing SCADA software
 
TECHNICAL BRIEF Protecting & Migrating Legacy Windows OSes
TECHNICAL BRIEF Protecting & Migrating Legacy Windows OSesTECHNICAL BRIEF Protecting & Migrating Legacy Windows OSes
TECHNICAL BRIEF Protecting & Migrating Legacy Windows OSes
 
Information Security Risks - What You Can Do To Help Your Clients Avoid Costl...
Information Security Risks - What You Can Do To Help Your Clients Avoid Costl...Information Security Risks - What You Can Do To Help Your Clients Avoid Costl...
Information Security Risks - What You Can Do To Help Your Clients Avoid Costl...
 
McAfee SIEM solution
McAfee SIEM solution McAfee SIEM solution
McAfee SIEM solution
 
G01.2012 magic quadrant for endpoint protection
G01.2012 magic quadrant for endpoint protectionG01.2012 magic quadrant for endpoint protection
G01.2012 magic quadrant for endpoint protection
 
AV-Comparatives’ 2017 business software review
AV-Comparatives’ 2017 business software reviewAV-Comparatives’ 2017 business software review
AV-Comparatives’ 2017 business software review
 
Introduction to Symantec Endpoint Management75.pptx
Introduction to Symantec Endpoint Management75.pptxIntroduction to Symantec Endpoint Management75.pptx
Introduction to Symantec Endpoint Management75.pptx
 
How PCI And PA DSS will change enterprise applications
How PCI And PA DSS will change enterprise applicationsHow PCI And PA DSS will change enterprise applications
How PCI And PA DSS will change enterprise applications
 
ISS CAPSTONE TEAM
ISS CAPSTONE TEAMISS CAPSTONE TEAM
ISS CAPSTONE TEAM
 
Maintaining Continuous Compliance with HCL BigFix
Maintaining Continuous Compliance with HCL BigFixMaintaining Continuous Compliance with HCL BigFix
Maintaining Continuous Compliance with HCL BigFix
 
CoreTrace Whitepaper: Whitelisting And Control Systems
CoreTrace Whitepaper: Whitelisting And Control SystemsCoreTrace Whitepaper: Whitelisting And Control Systems
CoreTrace Whitepaper: Whitelisting And Control Systems
 
DACHNUG50 BigFix WorkspaceAndAutomation.pdf
DACHNUG50 BigFix WorkspaceAndAutomation.pdfDACHNUG50 BigFix WorkspaceAndAutomation.pdf
DACHNUG50 BigFix WorkspaceAndAutomation.pdf
 
Securing Beyond the Cloud Generation
Securing Beyond the Cloud GenerationSecuring Beyond the Cloud Generation
Securing Beyond the Cloud Generation
 
Building Elastic into security operations
Building Elastic into security operationsBuilding Elastic into security operations
Building Elastic into security operations
 
CoreTrace Whitepaper: Application Whitelisting And Energy Systems
CoreTrace Whitepaper: Application Whitelisting And Energy SystemsCoreTrace Whitepaper: Application Whitelisting And Energy Systems
CoreTrace Whitepaper: Application Whitelisting And Energy Systems
 
Dr. Eric Cole - 30 Things Every Manager Should Know
Dr. Eric Cole - 30 Things Every Manager Should KnowDr. Eric Cole - 30 Things Every Manager Should Know
Dr. Eric Cole - 30 Things Every Manager Should Know
 
JASM Flyer
JASM FlyerJASM Flyer
JASM Flyer
 
Complete Endpoint protection
Complete Endpoint protectionComplete Endpoint protection
Complete Endpoint protection
 
Rhea corporate presentation v2
Rhea corporate presentation v2Rhea corporate presentation v2
Rhea corporate presentation v2
 
Symantec Migration infographic
Symantec Migration infographic Symantec Migration infographic
Symantec Migration infographic
 

Mehr von GE코리아

GE Additive Korea 금속 3D 프린팅 사업 안내
GE Additive Korea 금속 3D 프린팅 사업 안내GE Additive Korea 금속 3D 프린팅 사업 안내
GE Additive Korea 금속 3D 프린팅 사업 안내
GE코리아
 
[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기
[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기
[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기
GE코리아
 
[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표
[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표
[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표
GE코리아
 

Mehr von GE코리아 (18)

GE 2021 지속가능성 보고서 - 래리 컬프 GE 회장 서한
GE 2021 지속가능성 보고서 - 래리 컬프 GE 회장 서한GE 2021 지속가능성 보고서 - 래리 컬프 GE 회장 서한
GE 2021 지속가능성 보고서 - 래리 컬프 GE 회장 서한
 
Proficy Historian & Operations Hub - 통합 엔터프라이즈 데이터 관리
Proficy Historian & Operations Hub - 통합 엔터프라이즈 데이터 관리 Proficy Historian & Operations Hub - 통합 엔터프라이즈 데이터 관리
Proficy Historian & Operations Hub - 통합 엔터프라이즈 데이터 관리
 
Proficy CSense 글로벌 고객 경험 및 사례 연구
Proficy CSense 글로벌 고객 경험 및 사례 연구Proficy CSense 글로벌 고객 경험 및 사례 연구
Proficy CSense 글로벌 고객 경험 및 사례 연구
 
GE디지털 제품 브로슈어 (2022년)
GE디지털 제품 브로슈어 (2022년)GE디지털 제품 브로슈어 (2022년)
GE디지털 제품 브로슈어 (2022년)
 
에너지의 미래 - GE가스파워 백서
에너지의 미래 - GE가스파워 백서에너지의 미래 - GE가스파워 백서
에너지의 미래 - GE가스파워 백서
 
GE Additive Korea 금속 3D 프린팅 사업 안내
GE Additive Korea 금속 3D 프린팅 사업 안내GE Additive Korea 금속 3D 프린팅 사업 안내
GE Additive Korea 금속 3D 프린팅 사업 안내
 
How to Uncover Successful Additive Applications that Lead to Profitable Growth
How to Uncover Successful Additive Applications that Lead to Profitable GrowthHow to Uncover Successful Additive Applications that Lead to Profitable Growth
How to Uncover Successful Additive Applications that Lead to Profitable Growth
 
LOGIQ E10 초음파
LOGIQ E10 초음파LOGIQ E10 초음파
LOGIQ E10 초음파
 
GE Additive, 21st century Paradigm Shifter - Use cases in GE
GE Additive, 21st century Paradigm Shifter - Use cases in GEGE Additive, 21st century Paradigm Shifter - Use cases in GE
GE Additive, 21st century Paradigm Shifter - Use cases in GE
 
GE 에너지모니터링시스템(EMS), 2018평창동계올림픽대회의 원활한 전력운영 지원
GE 에너지모니터링시스템(EMS), 2018평창동계올림픽대회의 원활한 전력운영 지원GE 에너지모니터링시스템(EMS), 2018평창동계올림픽대회의 원활한 전력운영 지원
GE 에너지모니터링시스템(EMS), 2018평창동계올림픽대회의 원활한 전력운영 지원
 
GE는 어떻게 차기 CEO를 선출하는가
GE는 어떻게 차기 CEO를 선출하는가GE는 어떻게 차기 CEO를 선출하는가
GE는 어떻게 차기 CEO를 선출하는가
 
GE 글로벌 파워플랜트 분석 보고서
GE 글로벌 파워플랜트 분석 보고서GE 글로벌 파워플랜트 분석 보고서
GE 글로벌 파워플랜트 분석 보고서
 
GE디지털 월드테크(GE Digital Wurldtech)
GE디지털 월드테크(GE Digital Wurldtech)GE디지털 월드테크(GE Digital Wurldtech)
GE디지털 월드테크(GE Digital Wurldtech)
 
GE iFIX
GE iFIXGE iFIX
GE iFIX
 
[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기
[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기
[GE이노베이션 포럼 2016] 파괴적 혁신을 위한 GE의 기술 이야기
 
[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표
[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표
[GE이노베이션 포럼 2016] 2016 GE글로벌혁신지표
 
리더십 사관학교 GE크로톤빌 원장이 전하는 새로운 리더십
리더십 사관학교 GE크로톤빌 원장이 전하는 새로운 리더십리더십 사관학교 GE크로톤빌 원장이 전하는 새로운 리더십
리더십 사관학교 GE크로톤빌 원장이 전하는 새로운 리더십
 
GE Marine's Digital Revolution
GE Marine's Digital RevolutionGE Marine's Digital Revolution
GE Marine's Digital Revolution
 

Kürzlich hochgeladen

Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Anamikakaur10
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
lizamodels9
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
lizamodels9
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
lizamodels9
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 

Kürzlich hochgeladen (20)

How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 

HMI/SCADA 리스크 감소

  • 1. Decrease your HMI/SCADA risk Are you running your plant operations with serious risk? Most industrial applications lack recommended updates and security patches, which make them a target for hackers. Outdated architectures, backups and spares can also create problems. With the number of attacks on industrial applications rising and the critical need for plant system availability, take simple steps now to minimize risk. You can decrease unplanned downtime while helping to protect your organization. Here’s how … Check the expiration date Software doesn’t usually come with an expiration date. But, the expiration date on your operating system might have already passed. If you’re using Windows XP® , that “expiration date” was April 8, 2014 – the date that Microsoft stopped supporting XP. Don’t use software that is no longer supported by the manufacturer; you could be running with serious risk every day. In addition to your OS, make sure your other software packages are still supported. Were any of the vendors acquired? Do the new companies still support those software packages? Key steps to minimize unplanned downtime and protect your organization. Our business ­environment today is constantly ­changing – make sure your ­software is keeping up.
  • 2. GE Intelligent Platforms Schedule HMI/SCADA risk assessments and reviews Minimizing risk isn’t a one-time or once-a- year activity. With serious threats on the rise, you need to incorporate risk assessments and reviews into your schedule. The frequency of your risk assessments depends on your particular business, industry and plant applications. Start with a conservative, ­high-frequency schedule – and you can always increase the time between assessments, as needed. Assign a champion to minimize risk in your plant operations to drive leadership and consistency to the program. 1. Are you using obsolete software (Windows XP or other)? 2. Are you running your application with ­non-default / non-Administrator accounts with low privileges? Have you removed ADMIN and GUEST default accounts, using a separate administrator account? 3. Where are the points of entry/failure? 4. Are you properly isolating (DMZ) servers from untrusted network access? 5. Is your system missing any security patches? Are you using the most up-to-date version of your software? 6. Are you managing Bring Your Own Device (BYOD) securely? 7. Do you have spare parts, and when were they last tested? 8. Have you put additional controls in place to protect the HMI/SCADA security files from unauthorized change?” 9. Have you changed the default password for Trusted Network Computing? 10. Do you have an up-to-date backup plan in place? 10 sample questions for each review
  • 3. Upgrade, the right way Don’t wait for unplanned downtime or a disaster. Take action now. If you do have outdated software in your plant operations, make a plan now to upgrade the right way. Rethink your HMI/SCADA strategy – securely. Some HMI/SCADA users haven’t updated their systems in 10 years or more. Don’t just upgrade. Review your system with experts and use an upgrade as an opportunity to assess and modernize. Consider technologies that will make the life of your Plant & IT personnel easier. For example: 6 Can existing XP machines be converted into thin clients or virtualized? 6 Can critical applications be migrated to a server-based machine? 6 Time to rethink your app strategy. How many applications are you running that could be consolidated? 6 What applications can you leverage to turn your installation into a web-enabled one? Have you looked into GE Webspace and GE Cimplicity? 6 What applications are available now that can extend the functionality of your HMI/SCADA? Consider new levels of efficiency by adding simple analytics, task management, alarm response management, and more. 6 How are you storing and analyzing your data to improve operations? It might be time to look into a plant-wide Historian. 4 steps to include in your upgrade plan 6 Check and limit users’ rights 6 Update / install the latest anti-virus software 6 Create a controlled zone around your machines – place them behind a firewall 6 Make sure you have installed all of the latest service packs
  • 4. General IT Industrial Control System Confidentiality Integrity Availabilty Availabilty Integrity Confidentiality Highest Priority Lowest Priority Put rigor around security General IT goals and industrial control systems goals have historically differed. Make sure you review your goals and adjust as necessary, with consideration for the increase in industrial security threats and ­requirements for data protection and privacy. The priority for plant systems has historically been availability. Plant operations simply must keep running in order to achieve organizational success. However, plant operations teams need to include cyber security as a high priority and implement best practices to minimize vulnerabilities. Security is the process of maintaining the confidentiality, integrity, and availability of a system: 6 Confidentiality: Ensure only the people you want to see information can see it. 6 Integrity: Ensure the data is what it is supposed to be. 6 Availability: Ensure the system or data is available for use. Source: Cyber Security Assessments of Industrial Control Systems, CNPI / US Homeland Security, Nov 2010.
  • 5. Router Firewall DMZ Public Web Server SCADA ServerSCADA Server Attack Targets VPN Web Server Assess your current HMI/SCADA system, preferably with an outside expert, and develop a plan to reduce risk. You can identify common vulnerabilities and take action before a disaster.
  • 6. Leverage standards and best practices Your software vendors have the best information regarding your particular applications. Reach out to them for their advice and best practices. Read your software manuals and follow the instructions, especially concerning networks/connectivity and user accounts/ privileges. For example, if a manual recommends that you disable or remove a certain account after installing an I/O driver, then don’t forget to do it. Also, tap into the many industry associations. Learn about new standards and implement the parts that fit your situation. Not every standard – or even all sections of a standard – will work for you, but you can use the standards as a framework and add to them. Check into ISA, MESA and other plant systems organizations for more information and learning opportunities during the year. Government agencies, such as the U.S. Department of Homeland Security, National Institute of Standards and Technology (NIST), and U.S. Department of Energy, have valuable information – which applies to almost every SCADA user. Additionally, some industries such as water and power have entities such as the North American Electric Reliability Corp. (NERC), which provide information on HMI/SCADA risk reduction and security. A wealth of current information exists about how to reduce risk in HMI/SCADA systems.
  • 7. Patch management System hardening Host-based protection HMI/SCADA configuration 6 Define a risk-based patching policy & procedure 6 Apply the latest Microsoft security patches 6 Ensure coverage for all layers and assets (OS, DB, etc.) 6 Disable unnecessary ports, services, accounts & shares 6 Define secure configuration standards for all asset types 6 Consider restricting the use of untrusted USB media 6 Install anti-virus software on control systems PCs 6 Keep anti-virus definitions up-to-date 6 Consider HIPS/HIDS or application white-listing solutions 6 Deploy in a DMZ architecture configuration 6 Install application using a least-privileged user account 6 Disable or remove default accounts 6 Configure applications to require user authentication 6 Configure applications to use SSL or encrypted communication 6 Limit access to functions at all levels: - By role: only give to the users access to what they really need - By server - By runtime/development - By asset/device 6 Implement e-signature for complete regulatory and procedural compliance HMI/SCADA Security - Best practices example
  • 8. External/Remote Data Sources GE Agent can be used to create trusted encrypted remote connections over the internet using standard ports. Firewall DMZ Agent Manager Remote Site 1 Remote Site 2 Remote Site 1000x Internal Data Sources GE Agent can be used to create trusted connections between networks internally to build a layered defense solution. DMZ Agent Manager Firewall Controls Network Smart with secure-by-design innovation The good news is that HMI/SCADA software designs can inherently minimize some vulnerability to risk. Fundamental engineering principles mandate safe and reliable systems. Additionally, new secure-by-design innovation takes traditional practices to a higher level. As an example, GE’s Agent provides an encrypted and authenticated channel to forward monitoring and diagnostic data from remote agents to a central repository over an intranet or the internet, replacing the need for dedicated VPN connections. This secure-by-design technology also delivers functionality to send files and/or create RDP sessions from the GE Agent Enterprise Server to GE Agents over the established connection.
  • 9. Minimizing risk is, and always will be, a top priority for GE Intelligent Platforms – and should be a top priority for every HMI/SCADA user. Take advantage of standards, best practices and information sharing. GE works with customers, industry working groups and standards bodies, government agencies, and the security research community to continually improve industrial automation and control systems and global infrastructures. Plan a risk assessment program for your organization – and stick with it. Simple steps, such as upgrading unsupported software and limiting user rights, can make a big difference. There are many ways to reduce risk, but it is important to take the steps now – before unplanned downtime or a disaster occur. Summary
  • 10. Need help with minimizing HMI/SCADA risk? Contact GE for complimentary risk assessment tools and information. www.ge.com/digital GE www.ge.com/digital www.ge.com/digital Microsoft http://www.microsoft.com/en-us/windows/ enterprise/endofsupport.aspx http://windows.microsoft.com/eos Associations / Government Agencies ISA MESA U.S. Department of Homeland Security National Institute of Standards & Technology U.S. Department of Energy North American Electric Reliability Corp EU CSS European Union Network and Information Security Agency Useful links Contact information Americas: 1-855-YOUR1GE (1-855-968-7143) gedigital@ge.com www.ge.com/digital ©2015 General Electric. All rights reserved. *Trademark of General Electric. All other brands or names are property of their respective holders. Specifications are subject to change without notice. About GE GE (NYSE: GE) is the world’s Digital Industrial Company, transforming industry with software-defined machines and solutions that are connected, responsive and predictive. GE is organized around a global exchange of knowledge, the "GE Store," through which each business shares and accesses the same technology, markets, structure and intellect. Each invention further fuels innovation and application across our industrial sectors. With people, services, technology and scale, GE delivers better outcomes for customers by speaking the language of industry. www.ge.com