Vulnerabilities / Threats
10/23/2012
02:11 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Siemens Awarded Certification For Cyber Security Threat Protection

Siemens meets industry benchmarks for device manufacturers' security processes and practices

VANCOUVER, British Columbia and NUREMBERG, Germany < Oct. 23, 2012 ­Wurldtech Security Technologies, leaders in protecting mission-critical connected devices from cyber security threats and Siemens, today announced that Siemens Infrastructure & Cities, Smart Grid Division, has obtained the Achilles® Practices Certification, by passing strict industry benchmarks for device manufacturers¹ security processes and practices.

Based upon the standards set by the International Instrument Users Association (WIB), Achilles Practices Certification sets the bar for cyber security best practices in processes, practices, development, testing, commissioning, maintenance and support throughout the product lifecycle.

By meeting these stringent security requirements, device manufacturers are able to provide their customers with the assurance that corporate processes lead to the development and implementation of secure products and systems.

³We congratulate Siemens on achieving Achilles Practices Certification,² said Wurldtech CTO and founder, Nate Kube. ³By passing this strict certification process, Siemens is able to assure its customers that its processes meet and exceed best practice benchmarks for a system and solution provider in the smart grid business.²

Through the Achilles Practices Certification, Siemens further optimized its capabilities to deliver secure systems to its customers. Additionally, through Achilles Certification, Siemens can support a key component of their customers¹ corporate risk management programs.

³The Achilles Certification allows us to communicate to our customers that the Siemens Smart Grid Division, as a global market leader in energy automation, is committed to providing secure products and best practices throughout the entire product lifecycle,² said Robert Rosenberger, Head of Lifecycle Management, Siemens Smart Grid Division, Business Unit Energy Automation. ³Siemens is dedicated to ensuring that our systems and networks meet current and emerging international cyber security standards and government regulations. We look forward to assuring our customers that we have taken the necessary steps to proactively and independently certify our policies and practices.²

About Wurldtech Security Technologies

Founded in 2006, Wurldtech is a software company providing protection for mission critical connected devices against the persistent and dynamic threat of cyber attack. Wurldtech follows our customers¹ security lifecycle by providing innovative assessment products to discover and analyse threat and vulnerability profiles; mitigation of known vulnerabilities in installed networks with Achilles Threat Intelligence Signatures and device and development practice certification through Achilles Certification.

Wurldtech¹s internationally recognized cyber security experts help industrial stakeholders identify and mitigate cyber security vulnerabilities to reduce the risk and cost of attacks. Global customers worldwide spanning Oil & Gas, Electric Power, Medical, Nuclear, Chemical and Water Treatment markets currently use Wurldtech solutions. Visit wurldtech.com for more information.

About Siemens Smart Grid

The Siemens Smart Grid Division (Nuremberg, Germany) supplies power providers and network operators, industrial enterprises, infrastructure elements and cities with products and solutions for intelligent and flexible network infrastructures. To meet growing energy needs, the networks of today and tomorrow must integrate more and more renewable energy sources and ensure bi-directional energy and communication flows. Smart Grids help make it possible to generate and use power efficiently and on demand. For more information, visit http://www.siemens.com/smartgrid

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

CVE-2014-2392
Published: 2014-04-24
The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer log...

Best of the Web