Windows Defender will scan removable media for malware and other malicious code. It is
important to keep it up-to-date. See also Section "Windows security center (Page 11)".
Also identify what sensitive information is handled in the target system context, and how
unauthorized disclosure, modification, removal or destruction of such information can be
ensured in relation to the handling of removable media.
In case user/asset owner provides a security policy for removable media handling, this has to
be followed. If there is no policy or it is incomplete, please follow this guidance:
• It is user/asset owner's responsibility to provide removable media that is part of the
customer’s IT/OT ecosystem.
• Use of personal devices is prohibited.
• Removable media must be scanned regularly for malware, malicious code (e.g., Provaia scan-
station on SIEMENS sites, customer scan services, Windows Defender …).
• Removable media must be labeled with the employee's ID, organization and purpose (e.g.,
test data, commissioning …).
• Where confidentiality or integrity of data is important, cryptographic techniques for securing
data on removable media must be used.
• Removable media without labeling is not allowed to be used for any purpose and should be
destroyed.
• Removable media with labeling must be returned to the owner. The owner must then check
the medium.
• When disposed, removable media must be destroyed in a secure manner, so that the
contents made unrecoverable.
• Removable media must be locked away when not used.
Time synchronization
It is important to ensure synchronized clocks in the system and related environment, e.g. for
correct time stamps in security logs and events.
The system is shipped with preconfigured NTP-settings.
If another NTP-configuration is necessary, this can be adapted during commissioning by
trained personnel.
Incident management process
In cases where the asset owner or personnel involved in operation, maintenance, and service,
detect potential security incidents please contact Siemens customer service.
An incident handling process will be initiated.
Please nominate a cybersecurity responsible within your organization as contact point for
incident handling process.
Safety notes
2.5 Security recommendations
Operator panel for SINAMICS Perfect Harmony GH150 air-cooled MV Converters
Function Manual, 12/2022, A5E51241343A
9
Summary of Contents for SINAMICS PERFECT HARMONY GH150
Page 2: ......
Page 135: ......
Page 136: ... HUPDQ XUWKHU QIRUPDWLRQ ZZZ VLHPHQV FRP 6LHPHQV DUJH ULYHV SSOLFDWLRQV 9RJHOZHLKHUVWU 1 51 5 ...