Industrial Data Communications 4th Edition

Chapter 9 - Security

Because bad things happen to good computer systems, we've included a chapter on the
subject of security and industrial networking. As the hardware and software used in the
industrial arena have become far less proprietary and much more like commercial software,
security problems have begun to multiply. It is not so much that commercial systems are
more vulnerable but that they are much more widely known (which is the reason for their
adoption in the first place). Because of the ever present threat of viruses, hackers, backdoors,
Trojans, and other malware including spam and those wonderful phishing trips, not
to mention testing all of the software patches for operability among various applications,
you might think that security was the full-time job of the industrial network technician-
and you just might be right.

Defining the Types of Security

Figure 9-1. Types of Security

Physical security consists of physically ensuring the security of information by using actual
guards and gates, vaults, or any form of physical obstruction between the system and a
potential intruder. If an intruder has physical access to your system, particularly the servers,
the intruder has your information.

Personnel security means ensuring that personnel are not security risks by conducting background
checks on employees, having enforceable and enforced written policies for network
use and staff conduct, and monitoring personnel for suspicious behavior (like accessing the
system when not on duty, etc.).

Cyber security has many aspects, including group policies (a term for policies on a domain
controller, etc.), network use policies, firewalls, password policies, and so on. Anything
having to do with the computer system itself (access to files, programs, and applications)
must be planned ahead and consistent.

This division of security into three areas originated in the security industry. Typically, the
general public thinks of security as the first type, physical security. Yet all three aspects of
security work together-none is independent. If you only protect one type (cyber-physical-
personnel), the potential invader may try another mode to determine if it is unprotected.

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Security Software
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.