-

Plant Management

This topic contains the following sections:

Making (physical) on-site access controllable

In addition to the remote access, the "physical access" on site must also be controlled and restricted if necessary. To prevent damage due to unauthorized access:

Security Patch Management

Following the release process, usually patches are provided. Features and functionality patches increase or enhance the product's range of functions or improve the plant operation or reliability. Besides these well-known feature/functionality patches, security patches are important.

Security patches fix known vulnerabilities in a system/an ICS. These vulnerabilities relate to software and hardware likewise. Often, they result from improperly programmed software or device firmware, or from an improper configuration/parameterization of integrated system components. Consequently, the elimination of these vulnerabilities is the responsibility of the manufacturer or the system integrator, respectively.

Security patches are an important element when it comes to maintaining the operational capability of a plant.

Therefore, a suitable security patch management process must be established and reviewed, accompanied by a notification/announcement mechanism, that informs, for example, the plant users about vulnerability as soon it has been detected.

The patch/update management process should be defined as follows:

Note
If the support for a component or its software has been discontinued (end of life cycle), a new thread risk assessment is required for the entire system to evaluate the changed threat situation.