Vulnerabilities / Threats
10/23/2012
02:11 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Siemens Awarded Certification For Cyber Security Threat Protection

Siemens meets industry benchmarks for device manufacturers' security processes and practices

VANCOUVER, British Columbia and NUREMBERG, Germany < Oct. 23, 2012 ­Wurldtech Security Technologies, leaders in protecting mission-critical connected devices from cyber security threats and Siemens, today announced that Siemens Infrastructure & Cities, Smart Grid Division, has obtained the Achilles® Practices Certification, by passing strict industry benchmarks for device manufacturers¹ security processes and practices.

Based upon the standards set by the International Instrument Users Association (WIB), Achilles Practices Certification sets the bar for cyber security best practices in processes, practices, development, testing, commissioning, maintenance and support throughout the product lifecycle.

By meeting these stringent security requirements, device manufacturers are able to provide their customers with the assurance that corporate processes lead to the development and implementation of secure products and systems.

³We congratulate Siemens on achieving Achilles Practices Certification,² said Wurldtech CTO and founder, Nate Kube. ³By passing this strict certification process, Siemens is able to assure its customers that its processes meet and exceed best practice benchmarks for a system and solution provider in the smart grid business.²

Through the Achilles Practices Certification, Siemens further optimized its capabilities to deliver secure systems to its customers. Additionally, through Achilles Certification, Siemens can support a key component of their customers¹ corporate risk management programs.

³The Achilles Certification allows us to communicate to our customers that the Siemens Smart Grid Division, as a global market leader in energy automation, is committed to providing secure products and best practices throughout the entire product lifecycle,² said Robert Rosenberger, Head of Lifecycle Management, Siemens Smart Grid Division, Business Unit Energy Automation. ³Siemens is dedicated to ensuring that our systems and networks meet current and emerging international cyber security standards and government regulations. We look forward to assuring our customers that we have taken the necessary steps to proactively and independently certify our policies and practices.²

About Wurldtech Security Technologies

Founded in 2006, Wurldtech is a software company providing protection for mission critical connected devices against the persistent and dynamic threat of cyber attack. Wurldtech follows our customers¹ security lifecycle by providing innovative assessment products to discover and analyse threat and vulnerability profiles; mitigation of known vulnerabilities in installed networks with Achilles Threat Intelligence Signatures and device and development practice certification through Achilles Certification.

Wurldtech¹s internationally recognized cyber security experts help industrial stakeholders identify and mitigate cyber security vulnerabilities to reduce the risk and cost of attacks. Global customers worldwide spanning Oil & Gas, Electric Power, Medical, Nuclear, Chemical and Water Treatment markets currently use Wurldtech solutions. Visit wurldtech.com for more information.

About Siemens Smart Grid

The Siemens Smart Grid Division (Nuremberg, Germany) supplies power providers and network operators, industrial enterprises, infrastructure elements and cities with products and solutions for intelligent and flexible network infrastructures. To meet growing energy needs, the networks of today and tomorrow must integrate more and more renewable energy sources and ensure bi-directional energy and communication flows. Smart Grids help make it possible to generate and use power efficiently and on demand. For more information, visit http://www.siemens.com/smartgrid

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4692
Published: 2015-07-27
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.

CVE-2015-1840
Published: 2015-07-26
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space cha...

CVE-2015-1872
Published: 2015-07-26
The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via craft...

CVE-2015-2847
Published: 2015-07-26
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.

CVE-2015-2848
Published: 2015-07-26
Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to hijack the authentication of arbitrary users for requests associated with home-automation commands, as demonstrated by a door-unlock command.

Dark Reading Radio
Archived Dark Reading Radio
What’s the future of the venerable firewall? We’ve invited two security industry leaders to make their case: Join us and bring your questions and opinions!