Control Objectives: Vulnerability and Configuration Analysis
No control objectives match the current filters.
Cybersecurity Risks should be identified for the manufacturing system and mitigation activities should be planned including owner, required activities and due date.
SNow
Classification: IdentifyState: Published
Cybersecurity Risks should be identified for the manufacturing system and mitigation activities should be planned including owner, required activities and due date.
In-depth Technical Security Verification (Penetration Test)
SNow
Classification: PreventiveState: Published
A trusted and approved 3rd party cyber-security expert shall execute a penetration test to simulate an attack and identify vulnerabilities. The system or solution must successfully pass without any major or critical findings.
Patch Management for Security and Compliance
SNow
Classification: PreventiveState: Published
Ensure that a professional security patch management process is established (or supported) to maintain up-to-date, vendor-supported software and the installation of security patches and software updates to address security vulnerabilities.
Prevent Loss of Data using Backup and Restore
SNow
Classification: PreventiveState: Published
Prevent data loss in systems containing business critical, C4, or Sensitive personal data by scheduling and executing data backups and restore testing procedures to address availability and compliance requirements of the system and data. It must also be ensured that backup data is adequately secured
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: PL ID 24640623 Manufacturing Cybersecurity Vulnerability Identification in Manufacturing.
SNow
Classification: IdentifyState: Published
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: PL ID 24640623 Manufacturing Cybersecurity Vulnerability Identification in Manufacturing.
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: Vulnerability Management SOP.
SNow
Classification: DetectState: Published
The manufacturing system should be subject to Active or Passive Vulnerability Identification (scanning) process according the: Vulnerability Management SOP 24090-03.
The manufacturing system should be supported by Vendor (not obsolete) including a notification process for vulnerabilities affecting the supported system.
SNow
Classification: IdentifyState: Published
The manufacturing system should be supported by Vendor (not obsolete) including a notification process for vulnerabilities affecting the supported system.
The manufacturing system should have technicall capabilities to receive patches / updates in a secured manner according to regirements defined within the: PL ID 22235185 Roche MCRP - Network Segmentation Concept.
SNow
Classification: CorrectiveState: Published
The manufacturing system should have technicall capabilities to receive patches / updates in a secured manner according to regirements defined within the: PL ID 22235185 Roche MCRP - Network Segmentation Concept.
Vulnerability Assessment and Security Testing
SNow
Classification: PreventiveState: Published
Vulnerability Assessment is an essential part of the software development life cycle and the deployment of systems into production.
This assessment must be present from the development until the later stages like the acceptance or the actual production of the system and it is conducted via securi
Vulnerability and Configuration Scan
SNow
Classification: DetectiveState: Published
An initial and periodic (or regular) vulnerability and configuration scan will provide the necessary information to make informed decisions on corrective actions to ensure the system or solution is securely configured prior to go-live (release to production) and throughout ongoing operations.
Web Application Security Scan
SNow
Classification: DetectiveState: Published
The Web Application Security Scan (WASS) is an inspection of a web application, while similar to a vulnerability scan, it is designed to provide a rapid assessment of the security state of a Roche-managed website.