CPU 410 Process Automation/CPU 410 SMART
System Manual, 05/2017, A5E31622160-AC
133
Special functions of the CPU 410
9
9.1
Security functions of the CPU 410
Automation system protection
The CPU 410 has a range of functions with which you can protect your automation system.
●
Signed firmware:
The firmware of the CPU 410 has a signature to detect manipulations on the CPU itself. If
firmware with errors in its signature is loaded, the CPU 410 rejects the firmware update.
●
Protection level:
A number of different protection levels regulate access to the CPU. See Security levels
(Page 134)
●
SysLogEvents:
Security-related changes to the CPU can be sent to one or more SIEM systems as
SysLogEvent; see Security event logging (Page 136)
●
Field Interface Security:
If an interface of the CPU is only used for connecting field devices, access for other
devices at the interface can be prevented; see Field Interface Security (Page 139)
●
Support of "Block Privacy":
Blocks can be encrypted with a password using the STEP 7 "Block Privacy". The CPU
410 supports this function and can therefore process protected blocks; see Access-
protected blocks (Page 139)
There are also additional products in the SIMATIC range for increasing the security of your
automation system. For connection to the plant bus or third-party systems, for example, the
CP443-1 Advanced can be used to protect communications connections in particular. With a
combination of different security measures such as firewall, NAT/NAPT router and VPN
(Virtual Private Network) over IPsec tunnel, the CP443-1 Advanced protects individual
devices or entire automation cells from unauthorized access.
Reference
You can find additional information about Industrial Security in the introduction in Security
information (Page 20).