3.6
Setting up encrypted communication
3.6.1
Introduction
The following chapters provide important information that has to be observed when installing
the server.
Prerequisite
The server has already been installed.
3.6.2
TLS and Assets
Introduction
This chapter provides guidance to you as end user on what to do in order to make your systems
more secure against possible cyber attacks. In addition to applying state-of-the-art
technologies instead of the outdated solutions and to meet the local regulatory requirements.
This section covers two main topics: system hardening and encrypted channels. Although the
encryption of channels is part of the system hardening, it is emphasized because of its
importance.
System hardening
In order to protect your assets or production unit, you must have the appropriate knowledge,
and the installed system must be hardened. System hardening should be done based on the
appropriate Microsoft and other hardening guidelines. For example, experts can find guidance
in CIS (Center for Internet Security) manuals or, if accessible, in company-wide available
documents, or they can choose the source which fits best for them.
Installation and maintenance engineers need to continuously improve their IT security
knowledge because the information security threats are increasing day-by-day. The system
security risk is increasingly growing, and as Siemens customer you need to prepare yourself
accordingly.
You can reuse already hardened system configurations. These configurations, however,
should also be regularly reviewed, and new rules must be applied.
Example
Carefully ensure that firewalls are "activated", and only open ports that are actually used and
are absolutely necessary for operation. No other ports may be left open, because they could
also provide a further attack surface.
When a remote desktop connection is deployed, the highest possible security configuration
must be ensure to avoid a possible MITM (Man in the Middle) attack.
Installing/configuring Windows services
3.6 Setting up encrypted communication
Manage MyResources, Optimize MyProgramming /NX-Cam Editor
Installation Manual, 12/2019, A5E44672080B AE
69