Emerson Automated Patch Management Service
Emerson Automated Patch Management Service
November 2020
Introduction Benefits
Every month there are new Microsoft® Windows® OS security Establish successful and proactive patch management
updates, McAfee® Endpoint Security for DeltaV Systems strategy: Automated Patch Management Service automates
antivirus updates, Symantec™ Endpoint Protection antivirus routine aspects of software update deployment for timely
updates and DeltaV DCS hotfixes that need to be acted upon. dependable implementation, while freeing staff to devote
Emerson’s Automated Patch Management Service provides more time to your own business. For large systems, the savings
an effective solution that address the five deployment steps can add up to hundreds of hours per year. Automated Patch
— identification of required Emerson-approved updates, Management Service identifies the appropriate Microsoft
acquisition of update executables, distribution to appropriate Windows security patches, tests them on DeltaV DCS and
DeltaV DCS nodes, and installation. advises the customer on which DeltaV DCS hardware needs
updating with which particular software patches on an
It is very common for the most critical security, antivirus and individual system-by-system basis.
application hotfix updates to go uninstalled for extended
periods of time, or not be installed at all. Often the reasons are Ensure the availability and business continuity of your
due to limited skilled resources and day-to-day judgment calls DeltaV system: Emerson provides approved Microsoft
about what is more important; to either address an immediate Windows security updates as well as antivirus signature file
need with a measurable business benefit or deploy the current updates on a regular basis. Experience has shown many of
batch of system software updates with their unknown and often the disruptive events reported to the Emerson Global Service
un-quantified effect on system vulnerability. Center could have been avoided, had the relevant security
update or hotfix been applied in a timely fashion.
Automated Patch Management Service November 2020
Reduce manual system administrative activity and delays By delegating patching to Emerson’s Automated Patch
associated with software updates: Maintaining security Management Service, site resources can focus on delivering
patch management and hotfixes are essential to your system’s quality product and bottom-line results; spending less time
security and availability. evaluating and deploying patches, and more time focusing on
process management and operations.
This automated service ensures that critical updates are
deployed consistently.
Applications Whitelisting
Automated Patch Management Service is an integral part of
Emerson’s Cybersecurity Management Solutions portfolio. Network Security Monitor
A comprehensive cybersecurity solution consists of many
Security Information & Event Management (SIEM)
different components; each one specific to reducing risks
associated with various process control system entities. System Health Monitoring
Emerson’s Cybersecurity Management is an integrated Smart firewalls, Smart Switches and Controller Firewalls
approach to finding the best cyber solutions to fit your
current process control system and existing plant security On-site spare parts management
policies and procedures. Security consultation services
Cybersecurity Management solutions cover: Incident Response Services
Automated/Manual Patch Management Services Development Services for IR Plan and Site Policies &
(WSUS & antivirus patching) Procedures Review
Disaster recovery Reduction of risks associated with the use of these solution
Backup and recovery components reduces the time spent on controllable issues
and allows focus on other important day-to-day issues.
www.emerson.com/cybersecurity 2
Automated Patch Management Service November 2020
For McAfee Endpoint Security for DeltaV Systems: z An Internet accessible server class computer licensed for
Microsoft Server (Upstream Server) to host applications
z McAfee ePolicy Orchestrator® Console (McAfee ePO™) —
that require Internet access.
A software application that solicits antivirus updates from
z Customer-managed network infrastructure that
either Emerson or via the Internet, typically located on a
allows the Downstream Server to securely access
server located on the L2.5 or L3 network.
the Upstream Server.
z McAfee/Agent Handler - An application platform that
deploys the antivirus updates obtained by the ePO console
to the agents located on the DeltaV ACN nodes.
www.emerson.com/cybersecurity 3
Automated Patch Management Service November 2020
Software
Emerson
Smart Firewall
Level 2.5
Reference Architecture for Emerson Automated Patch Management Service utilizing McAfee Endpoint Security for
DeltaV Systems software.
Internet
Historian Data
Level 3 - Patch Management Upstream Server
Server Server
• Symantec Antivirus Live Update Administrator (LUA)
• Microsoft WSUS (Parent)
• Guardian GSUDS Client
Level 2.5
Level 2 - ACN
Reference Architecture for Emerson Automated Patch Management Service utilizing Symantec Endpoint Protectrion
for DeltaV Systems software.
www.emerson.com/cybersecurity 4
Automated Patch Management Service November 2020
Sample WSUS Control Panel for deployment and audit of security updates.
Sample WSUS Control Panel for deployment and audit of security updates.
www.emerson.com/cybersecurity 5
Automated Patch Management Service November 2020
www.emerson.com/cybersecurity 6
Automated Patch Management Service November 2020
This product and/or service is expected to provide an additional layer of protection to your DeltaV system to help avoid certain types of undesired actions. This product and/or
service represents only one portion of an overall DeltaV system security solution. Emerson does not warrant that the product and/or service or the use of the product and/or service
protects the DeltaV system from cyber-attacks, intrusion attempts, unauthorized access, or other malicious activity (“Cyber Attacks”). Emerson shall not be liable for damages,
non-performance, or delay caused by Cyber Attack. Users are solely and completely responsible for their control system security, practices and processes, and for the proper
configuration and use of the security products.
To learn more, contact your local Emerson sales office or representative, or visit www.emerson.com/cybersecurity.
www.emerson.com/cybersecurity 7
Automated Patch Management Service November 2020