11.7.4 1. WinCC v7.0 - Virusscanner Administration
11.7.4 1. WinCC v7.0 - Virusscanner Administration
11.7.4 1. WinCC v7.0 - Virusscanner Administration
2
SIMATIC Prozessleitsystem PCS 7 Konfiguration Trend Micro Office Scan V7.3 incl. Patch 2
______________
Managing virus scanners
______________
Practical information 3
SIMATIC
Whitepaper
08/2009
A5E02657556-01
Legal information
Warning notice system
This manual contains notices you have to observe in order to ensure your personal safety, as well as to prevent
damage to property. The notices referring to your personal safety are highlighted in the manual by a safety alert
symbol, notices referring only to property damage have no safety alert symbol. These notices shown below are
graded according to the degree of danger.
DANGER
indicates that death or severe personal injury will result if proper precautions are not taken.
WARNING
indicates that death or severe personal injury may result if proper precautions are not taken.
CAUTION
with a safety alert symbol, indicates that minor personal injury can result if proper precautions are not taken.
CAUTION
without a safety alert symbol, indicates that property damage can result if proper precautions are not taken.
NOTICE
indicates that an unintended result or situation can occur if the corresponding information is not taken into
account.
If more than one degree of danger is present, the warning notice representing the highest degree of danger will
be used. A notice warning of injury to persons with a safety alert symbol may also include a warning relating to
property damage.
Qualified Personnel
The device/system may only be set up and used in conjunction with this documentation. Commissioning and
operation of a device/system may only be performed by qualified personnel. Within the context of the safety notes
in this documentation qualified persons are defined as persons who are authorized to commission, ground and
label devices, systems and circuits in accordance with established safety practices and standards.
Proper use of Siemens products
Note the following:
WARNING
Siemens products may only be used for the applications described in the catalog and in the relevant technical
documentation. If products and components from other manufacturers are used, these must be recommended
or approved by Siemens. Proper transport, storage, installation, assembly, commissioning, operation and
maintenance are required to ensure that the products operate safely and without any problems. The permissible
ambient conditions must be adhered to. The information in the relevant documentation must be observed.
Trademarks
All names identified by ® are registered trademarks of the Siemens AG. The remaining trademarks in this
publication may be trademarks whose use by third parties for their own purposes could violate the rights of the
owner.
Disclaimer of Liability
We have reviewed the contents of this publication to ensure consistency with the hardware and software
described. Since variance cannot be precluded entirely, we cannot guarantee full consistency. However, the
information in this publication is reviewed regularly and any necessary corrections are included in subsequent
editions.
1 Preface ...................................................................................................................................................... 5
1.1 Structure and organization of the document..................................................................................5
1.2 Special notes..................................................................................................................................5
2 Managing virus scanners ........................................................................................................................... 7
2.1 Definitions ......................................................................................................................................7
2.2 Using virus scanners......................................................................................................................8
2.3 Basic virus scanner architecture ....................................................................................................9
2.4 Strategy for distributing virus signatures......................................................................................10
2.5 Configuration of virus scanners ...................................................................................................11
2.6 Approved virus scanners for PCS 7 and WinCC .........................................................................12
3 Practical information ................................................................................................................................ 13
● The basic document is a central overview and guide for the Security Concept PCS 7
& WinCC.
It provides a systematic description of the basic principles and strategies of the security
concept. Users should have appropriate knowledge of the basic document to understand all
additional detail documents.
● The detail documents (such as this document) explain the specific principles,
solutions and their recommended configuration in detail form, focusing on particular detail
topics. The detail documents are supplemented, updated and provided separately to
ensure they are always up-to-date.
Knowledge requirements
This documentation is intended for personnel working in the fields of engineering,
commissioning and servicing of SIMATIC automation systems. It is presumed that readers
have appropriate management knowledge of office IT.
Validity
The Security Concept PCS 7 & WinCC incrementally overrides all previous documents and
recommendations "Security concept for PCS 7" and "Security concept for WinCC" and is
valid as of WinCC V6.2 and PCS 7 V7.0.
2.1 Definitions
Virus scanner:
A virus scanner is a software that detects, blocks or eliminates known harmful program
routines (computer viruses, worms and similar malware).
Fig. 2-1
Depending on the manufacturer, you can implement several virus scan servers to operate in
parallel or within a hierarchy structure.
Fig. 2-2
Symantec McAfee
Trend Trend Symantec
AntiVirus VirusScan
Micro Micro Endpoint
Requirement 10.0 V8.0i
Office Office Protection
AntiVirus VirusScan
Scan 7.3 Scan 8.0 11.0
10.2 V8.5i
The virus scanner can be installed
Yes Yes Yes Yes Yes
without firewall.
The virus scan clients can be
Yes Yes Yes Yes Yes
organized and configured in groups.
Automatic distribution of virus
Yes Yes Yes Yes Yes
signatures can be disabled.
The virus signatures can be
distributed manually and to selected Yes Yes Conditional1 Yes Yes
groups.
Manual and group-by-group file scans
Yes Yes Yes Yes Yes
are supported.
Detection of a virus triggers a
Yes No 2 Yes Yes No 2
message output but no file action.
The virus scan clients can be
configured so that they do not display Yes Yes Yes Yes Yes
any messages.
1
) Manual distribution of virus definition files is only possible if automatic distribution is
enabled as well.
2
) The guidelines do not contain an option for setting the action so that logging is enabled
although no action occurs.
Additional information
Software setup routines usually represent a serious modification of the local system and
should always be run from a virus-free storage location on a file server with integrated virus
scanner or from a DVD; a virus scanner should neither obstruct, nor corrupt such
installations. To achieve this goal, you should select so-called file transfer / installation
servers or virus scan configuration settings that do not interfere with setup procedures,
without having to disable the virus scanner.