Vulnerabilities / Threats
10/23/2012
02:11 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

Siemens Awarded Certification For Cyber Security Threat Protection

Siemens meets industry benchmarks for device manufacturers' security processes and practices

VANCOUVER, British Columbia and NUREMBERG, Germany < Oct. 23, 2012 ­Wurldtech Security Technologies, leaders in protecting mission-critical connected devices from cyber security threats and Siemens, today announced that Siemens Infrastructure & Cities, Smart Grid Division, has obtained the Achilles® Practices Certification, by passing strict industry benchmarks for device manufacturers¹ security processes and practices.

Based upon the standards set by the International Instrument Users Association (WIB), Achilles Practices Certification sets the bar for cyber security best practices in processes, practices, development, testing, commissioning, maintenance and support throughout the product lifecycle.

By meeting these stringent security requirements, device manufacturers are able to provide their customers with the assurance that corporate processes lead to the development and implementation of secure products and systems.

³We congratulate Siemens on achieving Achilles Practices Certification,² said Wurldtech CTO and founder, Nate Kube. ³By passing this strict certification process, Siemens is able to assure its customers that its processes meet and exceed best practice benchmarks for a system and solution provider in the smart grid business.²

Through the Achilles Practices Certification, Siemens further optimized its capabilities to deliver secure systems to its customers. Additionally, through Achilles Certification, Siemens can support a key component of their customers¹ corporate risk management programs.

³The Achilles Certification allows us to communicate to our customers that the Siemens Smart Grid Division, as a global market leader in energy automation, is committed to providing secure products and best practices throughout the entire product lifecycle,² said Robert Rosenberger, Head of Lifecycle Management, Siemens Smart Grid Division, Business Unit Energy Automation. ³Siemens is dedicated to ensuring that our systems and networks meet current and emerging international cyber security standards and government regulations. We look forward to assuring our customers that we have taken the necessary steps to proactively and independently certify our policies and practices.²

About Wurldtech Security Technologies

Founded in 2006, Wurldtech is a software company providing protection for mission critical connected devices against the persistent and dynamic threat of cyber attack. Wurldtech follows our customers¹ security lifecycle by providing innovative assessment products to discover and analyse threat and vulnerability profiles; mitigation of known vulnerabilities in installed networks with Achilles Threat Intelligence Signatures and device and development practice certification through Achilles Certification.

Wurldtech¹s internationally recognized cyber security experts help industrial stakeholders identify and mitigate cyber security vulnerabilities to reduce the risk and cost of attacks. Global customers worldwide spanning Oil & Gas, Electric Power, Medical, Nuclear, Chemical and Water Treatment markets currently use Wurldtech solutions. Visit wurldtech.com for more information.

About Siemens Smart Grid

The Siemens Smart Grid Division (Nuremberg, Germany) supplies power providers and network operators, industrial enterprises, infrastructure elements and cities with products and solutions for intelligent and flexible network infrastructures. To meet growing energy needs, the networks of today and tomorrow must integrate more and more renewable energy sources and ensure bi-directional energy and communication flows. Smart Grids help make it possible to generate and use power efficiently and on demand. For more information, visit http://www.siemens.com/smartgrid

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.