Cybersecurity Considerations
CAUTION |
|---|
|
UNINTENDED EQUIPMENT BEHAVIOR Ensure all system hardware, software, network design, configuration and cybersecurity robustness are correctly configured, commissioned and approved for operation. Failure to follow these instructions can result in injury or equipment damage |
The risk of any potential loss of data or recorder status must be minimized when communicating across a network or EPM is being controlled via a third party client, for example, another recorder, PLC or HMI.
EPM Solution components are securely designed in accordance with our Secure Development Lifecycle (SDL) process. This process is governed by a structured secure design approach primarily aligned with the International Electrotechnical Commission (IEC) 62443-4-1 standard, while also referencing relevant industrial control regulations, customer expectations and cybersecurity best practices.
EPM Data Management
For EPM Data Management the following should be considered:
-
Secure passwords, see Configuring Users from the EPM Data User Interface for details.
-
Access restricted by Role, see EPM Data User Interface Roles for details.
Sensitive Data Handling - Exported Files
Where data containing sensitive information, including but not limited to names, usernames, and email addresses, is exported from EPM Data Management, the following applies:
-
Exported .uhh files and archive files are not encrypted by the device.
-
The device ensures secure transmission when configured to use secure protocols, for example, Secure File Transfer Protocol (SFTP).
-
Once exported, the protection of the data becomes the responsibility of the user or organization.
You must ensure that exported files are protected using appropriate security controls, including but not limited to:
-
Encryption using approved cryptographic mechanisms.
-
Access control restrictions on storage systems.
-
Encrypted USB media when using removable storage, see Best Practice for Using a USB Flash Drive for details.
-
Secure handling in accordance with organizational cybersecurity policies.
Failure to protect exported files may result in unauthorized disclosure of sensitive information.
Physical Tamper Resistance and Detection
To meet the stringent Cybersecurity requirements relating to physical access, it is strongly recommended that EPM Solution devices are installed with physical access restrictions. For example, to restrict access to authorized personnel only, devices should be installed within secure areas/rooms or lockable enclosures. An alarm could be considered to detect any unauthorized physical access to those spaces.
Cybersecurity Best Practice
Malware Scanning of External Files
As part of security best practice, you should ensure that all external files are scanned for security threats, for example, viruses or malware, before uploading them to any device.
External files may include, but are not limited to:
-
Configuration files.
-
Upgrade files.
All external files are considered untrusted until they are scanned using appropriate and up-to-date malware detection tools. Scanning should be performed externally to reduce the risk of introducing malicious content into the system.
This guidance applies to any file upload functionality and should be considered as part of operational commissioning and maintenance security practices.
Last update - May 2026
CAUTION