considered with regard to security so that Siemens already applies the same security standards
when purchasing as for the manufacture of its own products.
0RQLWRULQJRIWKH
UHVLGXDOULVNLQRUGHUWR
LPSURYHWKHVHFXULW\
FRQFHSWZKHQUHTXLUHG
HJZKHQQHZWKUHDWV
DSSHDU
6HOHFWLRQDQG
LPSOHPHQWDWLRQRI
VXLWDEOHPHDVXUHVLQ
RUGHUWRIXOILOOWKH
VWLSXODWHGUHTXLUH
PHQWVHJFHOO
SURWHFWLRQFRQFHSW
6HFXULW\UHTXLUHPHQWV
PXVWEHIXOILOOHGE\WKH
,7LQIUDVWUXFWXUHDQG
,7SURFHVVHVEDVHG
RQLQWHUQDWLRQDO
VWDQGDUGV,(&
DQG,62
6LJQLILFDQFHRI
NQRZKRZSURWHFWLRQ
DQGSURGXFWLQWHJULW\
IRUWKHFRPSDQ\
3URGXFWVDQG
EXVLQHVVDUHDVWDNHQ
LQWRDFFRXQWLQWKH
+ROLVWLF6HFXULW\
&RQFHSW
0RQLWRULQJRI
5HVLGXDO5LVN
3URWHFWLRQ
&RQFHSW
7DUJHW
3URWHFWLRQ
/HYHO
%XVLQHVV
,PSDFW
$VVHVVPHQW
6FRSH
Figure 3-1 SI HSC security management process
Standards and regulations
Siemens complies with the valid standards and regulations in the industrial security area
throughout the entire development process:
● ISO 2700X: Management of information security risks
● IEC 62443: IT security for industrial higher-level control systems – network and system
protection
3.4 Security management
The security management process as a basis
Protect your system and your company. Security management according to IEC 62443 and
ISO 27001 forms the basis for the successful implementation of Industrial Security.
The security management process is shown in the following:
Industrial Security
3.4 Security management
Industrial Security
16 Configuration Manual, 08/2017, A5E36912609A