Security checklist
This checklist summarizes the required configuration steps for the secure operation of PLCnext Technology devices. This checklist does not replace a comprehensive security concept. Additional organizational and network-level measures must be considered.
Initial setup (starting up)
Device preparation
⚪ Device is checked before commissioning
⚪ Device integrity state is verified
⚪ IP addresses are derived and assigned
User setup
⚪ Initial users are created
⚪ Roles are assigned (e.g. SecurityEngineer, Engineer, Operator)
⚪ Default credentials are not used for productive operation
Secure communication (TLS and certificates)
⚪ TLS is configured
⚪ HTTPS certificate is generated in the WBM
⚪ Certificate is installed or accepted in the client (browser)
Basic device hardening
⚪ SD card settings and encryption are configured
⚪ Basic firewall settings are configured
⚪ Netload limiter is configured
Logging
⚪ Security logging is configured
Environmental requirements
Engineering and integrity
⚪ PLCnext Engineer is configured securely
⚪ Project integrity is checked
Network and system configuration
⚪ Extended firewall settings are configured
⚪ System time is configured
⚪ Central logging is configured
System service activation
⚪ Required system services are enabled (e.g. HMI, PROFINET, OPC UA, Modbus TCP, PLCnext Store, Proficloud)
⚪ Activation of additional system services is restricted to required use cases
⚪ For each system service, a risk assessment has been proceeded before activation
Certificates and secure communication (advanced)
⚪ Certificates are managed for secure communication
⚪ Certificates for enabled system services are configured
Software and system extensions
⚪ Software update configuration is defined
⚪ Signed apps are installed
⚪ For each app, a risk assessment has been proceeded before installation
Backup and recovery
⚪ Backup mechanism is configured
⚪ Backup and restore procedures are verified
Account management
User lifecycle
⚪ Users are created according to defined roles
⚪ User accounts are regularly reviewed
Password security
⚪ Password complexity rules are configured
⚪ Password validity is checked
Authentication and sessions
⚪ Authentication error handling is configured
⚪ Session behavior is configured
Central user management
⚪ Active Directory / LDAP connection is configured if required
Controller-specific settings
⚪ The settings specific to the PLCnext Control have been checked
⚪ Measures to protect against physical access have been checked and implemented
⚪ Periodic security maintenance activities are planned