Cybersecurity

Cybersecurity Guidelines

Use this product inside a secure industrial automation and control system. Total protection of components (equipment/devices), systems, organizations, and networks from cyber attack threats requires multi-layered cyber risk mitigation measures, early detection of incidents, and appropriate response and recovery plans when incidents occur. For more information about cybersecurity, refer to the Pro-face HMI/IPC Cybersecurity Guide.

https://www.proface.com/en/download/manual/cybersecurity_guide

POTENTIAL COMPROMISE OF SYSTEM AVAILABILITY, INTEGRITY, AND CONFIDENTIALITY

  • Change default passwords at first use to help prevent unauthorized access to device settings, controls and information.

  • Disable unused ports/services and default accounts, where possible, to minimize pathways for malicious attacks.

  • Place networked devices behind multiple layers of cyber defenses (such as firewalls, network segmentation, and network intrusion detection and protection).

  • Apply the latest updates and hotfixes to your Operating System and software.

  • Use cybersecurity best practices (for example: least privilege, separation of duties) to help prevent unauthorized exposure, loss, modification of data and logs, interruption of services, or unintended operation.

Failure to follow these instructions can result in death, serious injury, or equipment damage.

Security Features Provided

This product provides the following security features. These features provide security capabilities which contribute towards protecting the product from potential security threats.

Notes on safe operation

  1. Build a secure network to prevent unauthorized access

  2. Build a communication environment using encrypted communication.

  3. Make sure your network is secure before establishing communication and transferring data over Ethernet.

  4. Select a transfer option that is not based on Ethernet communication. (For example: USB cable or external storage)
    Transferring Project Files via USB Transfer Cable
    Transfer using external storage

  5. Open the data communication port only when using a communication service.

  6. Protect your computer with a firewall and use the computer on a trusted network.

  1. Prevent unauthorized operations from third parties

  2. Use Windows security features such as password settings, automatic logout, and so on.

  3. If you use a Windows administrator account, define secure passwords and security settings.

  4. Use the display unit’s security feature.

  5. IPC Series, PC/AT

  1. Protect against information tampering

  2. To protect your computer and enhance security settings, use the following guidelines which are based on cybersecurity best practices (including antivirus software, operating system updates, strong password policies, and application allowlist software).
    https://www.pro-face.com/trans/en/manual/1087.html

  3. Manage your own data carefully.

  4. Apply a password to your project for protection.
    Project Information - Password

  5. When using USB cable or Ethernet transfer options, from [Send/Receive Project File] enable [Password].
    Secure Transfer with Passwords

  6. Use GP-Pro EX on trusted computers only.

  7. In a local network (LAN) environment, prepare a secure communication environment to prevent third party intervention.
    (For example: Strict control of the installation place of the LAN hub between GP-Pro EX and the display)

  8. As password setting data includes security information, store in a secure environment.
    Creating Password Settings

  9. After GP-Pro EX is installed, any files (such as project files, package files and exported files) that are created or output are not deleted when GP-Pro EX is uninstalled. We recommend reviewing contents carefully and either managing or deleting the files.

  10. Uninstalling WinGP does not delete any files (such as project files and exported files) used by WinGP or generated by WinGP. We recommend reviewing contents carefully and either managing or deleting the files.