Cyber security starts at the communications links to devices. On Emerson PLC/PAC control products, support for non-essential ports and protocols is removed. Station Manager, USB and SD card ports are disabled by default. Access to the devices is restricted to only what is needed for the supported communications protocols: HTTP Proxy support for controlled access to the Internet, and HTTPS protocols with certificates for secure Predix connection on the WAN. We have even implemented a private cellular network with carriers for our Field Agent products. Emerson reduces the attack surface of its PLC/PAC products by limiting access to essential ports and services. Emerson also acquires cyber security certification for our control products. Whether it is the globally recognized Achilles Level 2 certification, or the specific TRIMPS certification, these designations indicate that Emerson PLC/PAC control systems meet global security standards.Achilles TestingThe Wurldtech Achilles certifications are communications tests performed on devices while monitoring specific performance indicators. Achilles testing is categorized into three main groups:
Emerson encourages customers to use enhanced communication protocols. OPC UA is widely accepted for its secure communications between systems. OPC UA is platform-independent and no longer requires security of COM/DCOM. OPC UA security allows for managed certificate exchange between client and server. This certificate is an electronic ID held by the application that defines the identity of the holder. These certificates conform to the X509 specification. The data is encrypted between end points of the OPC UA exchange to deny man-in-the middle access. Even with its enhanced features, OPC UA is IT network friendly and communicates through standard HTTP or UA TCP port. OPC UA can even connect securely over VPN and through firewalls.Reducing attack surface is only a piece of the security puzzle. Check out other blogs in this Forum for additional tips on securing your PLC/PAC control systems.