Method and computer program for handling information security vulnerabilities within an industrial automation system

WO2026201381A1PCT designated stage Publication Date: 2026-10-01SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/053749
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-27
Filing Date
2026-02-12
Publication Date
2026-10-01

Smart Images

  • Figure EP2026053749_01102026_PF_FP_ABST
    Figure EP2026053749_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for handling information security vulnerabilities within an industrial automation system, in which devices (10) and / or resources of the automation system which need to be protected against unauthorized access are identified. Known information security vulnerabilities (11-15) are detected for the identified devices (10) and / or resources. A device-specific and / or resource-specific task list (110) containing all the measures (111-114) provided for the device and / or the resource is created for each device (10) and / or resource, said measures being required or suitable for handling the detected information security vulnerabilities (11-15). On the basis of the particular device-specific and / or resource-specific task list (110), the measures (111-114) are checked in order to determine whether they are provided for remedy for a plurality of information security vulnerabilities (11-15). Measures (111-113) which are provided for a plurality of information security vulnerabilities (11-14) are linked to one another in the particular device-specific and / or resource-specific task list (110). In the case of interlinked measures (111-113), only a single implementation is carried out for all information security vulnerabilities (11-14) for which the particular measure is provided for remedy.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] 202504401 Foreign version

[0002] 1

[0003] Description

[0004] Method and computer program for addressing information security vulnerabilities within an industrial automation system

[0005] The present invention relates to a method for treating information security vulnerabilities within an industrial automation system and a computer program for carrying out the method.

[0006] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.

[0007] Industrial automation systems typically comprise a multitude of automation devices interconnected via an industrial communication network and serve to control or regulate plants, machines, or equipment within the context of manufacturing or process automation. Due to time-critical conditions in industrial automation systems, real-time communication protocols such as PROFINET, PROFIBUS, Real-Time Ethernet, or Time-Sensitive Networking (TSN) are predominantly used for communication between automation devices. In particular, control services or applications can be automatically and load-dependently distributed across currently available servers or virtual machines within an industrial automation system.

[0008] Automation devices and end devices that exchange time-critical data with communication partners to control machines or equipment must be protected against manipulation and eavesdropping. In addition to software and firmware updates, encryption of communication to and from these devices is a crucial protective measure. This is typically achieved using encryption protocols such as TLS (Transport Layer Security) or SSL (Secure Socket Layer), which provide each device with a key pair and a certificate based on the public key of that key pair. Appropriate configuration is essential to ensure that no information security vulnerabilities arise or can be exploited.

[0009] To prevent the exploitation of existing vulnerabilities in program code, compiler-based exploit protection concepts can be used, for example, as described in the foreign version of 202504401.

[0010] 2

[0011] The program code receives additional protection or... during a compilation process.

[0012] Insert verification routines. Such protection concepts can be implemented purely in software or with hardware support. In particular, these protection concepts can detect threats such as code injection, buffer overflows, return-oriented programming (ROP), and jump-oriented programming (JOP) at runtime. Upon detection of a potential attack, for example, an error message is displayed in a command line or program execution is immediately stopped. This makes it more difficult to exploit existing vulnerabilities.

[0013] From EP 3650968 A1, a method for operating a production or machine tool is known in which an app comprising at least one virtual container, together with an app configuration, is downloaded from remote storage to the storage of the production or machine tool. Immediate startup of the downloaded app on the production or machine tool is prevented. First, the app configuration of the downloaded app is automatically modified. For this purpose, identifiers included in the app configuration are evaluated and compared with identifiers included in a positive list and a negative list, respectively. An identifier not included in either the positive or negative list is replaced by an automatically selected or automatically generated target expression. After the app configuration has been modified, the downloaded app is automatically started.

[0014] WO 2020 / 182627 A1 describes a method for monitoring the integrity of an industrial cyber-physical system. This method involves providing or accessing measurement data acquired by various sensors of the cyber-physical system, or control data intended for various actuators of the cyber-physical system. Furthermore, at least one measurement data correlation parameter is determined between the measurement data acquired by the different sensors, or at least one control data correlation parameter is determined between the control data intended for the various actuators. This measurement data correlation parameter is compared to a measurement data correlation reference, and the control data correlation parameter is compared to a control data correlation reference. Based on this comparison, the integrity of the cyber-physical system being monitored is assessed.

[0015] From WO 2024 / 241287 A2, a method for analyzing the cybersecurity situation for an OT (Operation Technology) infrastructure is known, in which devices of one or more systems of the 202504401 foreign version

[0016] 3

[0017] OT infrastructure is categorized into multiple levels based on each device's exposure to a communication network. These levels indicate the devices' vulnerability to cyber threats, with vulnerability increasing with each level. For the categorized devices, known vulnerabilities and exposures (CVEs) of components are identified at each level, using the respective device's bill of materials (BoM). A severity score is assigned to the identified CVEs based on one or more vulnerability-associated databases. A total severity score is then calculated based on the number of CVEs at each level and their associated severity scores.From this, a plant cybersecurity posture score (PCPS) is determined for one or more plants, based on the sum of the severity levels, the number of devices in each level, and a compensation value.

[0018] EP 4047870 A1 concerns a method for mitigating cybersecurity risks in enterprise networks, which uses process-oriented analytical attack graphs (AAGs) and a mitigation simulator to prioritize remediation measures. Within an agile security platform, asset vulnerabilities of enterprise-wide assets are identified, and attack paths to targets are analyzed. The process-oriented AAGs are represented by graph data to depict potential lateral movement of attackers within a computer network. Risk profile data describes an organization's risk profile with respect to two or more risk aspects. The risk profile includes a set of risk acceptance values, each representing an organization's tolerance for the respective risk aspect. A risk assessment is then generated based on a process-oriented AAG and a risk profile.The risk assessment includes risk values ​​for the contexts of the process, the crown jewel (critical assets), and attack targets. Based on the process-oriented AAG, the risk profile, and the risk assessment, a list of remedial measures for risk reduction is generated.

[0019] US Patent 2012 / 180133 A1 discloses a method for conducting a cybersecurity risk assessment for a large number of process control systems and networks encompassing a variety of primary network resources in an industrial process plant. Using a module for scanning industrial and process-controlled systems, network and system topologies are identified, and analyses are performed regarding system and network security, vulnerabilities, viruses, and other threats. (202504401 Foreign Version)

[0020] 4

[0021] The system analyzes connection and node congestion. This allows for the detection of vulnerabilities to known threats and the identification of potential weaknesses. A threat probability and impact module determines the likelihood that each of a multitude of known threats will exploit identified vulnerabilities. Furthermore, the consequences of exploiting these vulnerabilities for individual affected systems and overall plant operations are assessed. Based on this analysis, a risk assessment is performed for all identified vulnerabilities, and recommended corrective actions are defined.

[0022] Particularly in automation devices or end devices used in industrial automation systems, information security vulnerabilities are discovered in their firmware throughout their long lifecycle. Manufacturers or third parties publish information and recommendations on how to address these vulnerabilities. To eliminate such vulnerabilities, for example, the firmware can be updated, or other measures can be taken to circumvent or mitigate the problem associated with the vulnerability.

[0023] In view of the increasing networking between automation devices or

[0024] For end devices, ignoring vulnerabilities in the long term is not a viable approach, especially for plant operators. Therefore, it is essential for plant operators to identify devices and resources with known vulnerabilities and to implement measures to eliminate, mitigate, or circumvent them. In industrial automation systems, for example, many measures can often only be implemented during a plant shutdown. Furthermore, it must be ensured that implementing these measures does not compromise interoperability or compatibility between devices within a plant.

[0025] This presents plant operators with particular challenges in planning and implementing measures to address information security vulnerabilities across a large number of diverse devices and resources within a plant. In addition to considering time constraints, it is crucial to avoid treating vulnerabilities in isolation – especially since a single measure can address multiple vulnerabilities simultaneously – and to implement the measures efficiently and consistently. 202504401 Foreign version

[0026] 5

[0027] The present invention therefore aims to provide an automated, user-friendly method for the efficient and consistent treatment of information security vulnerabilities within an industrial automation system and to create a suitable technical implementation for its execution.

[0028] This problem is solved according to the invention by a method having the features specified in claim 1 and by a computer program having the features specified in claim 14. Advantageous embodiments of the present invention are specified in the dependent claims.

[0029] According to the inventive method for addressing information security vulnerabilities within an industrial automation system, executed by a plant monitoring system, devices or resources of the automation system that require protection against unauthorized access are identified. Known information security vulnerabilities are recorded for the identified devices or resources. Information security is, in particular, a state of technical or non-technical systems for information processing and storage that aims to ensure confidentiality, availability, and integrity as protection goals. For example, information security serves to protect against hazards or threats, prevent damage, and minimize risks.

[0030] Information security vulnerabilities can advantageously be identified using information provided by device manufacturers or trusted entities. Measures to address these vulnerabilities can then be determined based on recommendations provided by these manufacturers or trusted entities. These measures preferably include software updates, particularly firmware updates, or configuration changes. The information and recommendations provided by device manufacturers or trusted entities may, for example, specify which firmware versions resolve the respective vulnerability.

[0031] According to the invention, a device- or resource-specific task list is created for each device or resource, containing all measures intended for the device or resource that are necessary or suitable for addressing the identified information security vulnerabilities. The measures are determined based on the respective device- or resource-specific requirements.

[0032] 6

[0033] The system checks the resource-specific task list to see if it is intended to address multiple information security vulnerabilities. Measures intended for multiple vulnerabilities are linked together in the respective device- or resource-specific task list. For linked measures, implementation only occurs once for all vulnerabilities for which the respective measure is intended. The task lists containing the measures can then be processed, for example, device- or resource-wise.

[0034] The device- and resource-specific task lists, containing all measures planned for each device or resource, create a central point of contact, preventing unnecessary or even detrimental repetition of measures. Potential conflicts between measures can also be resolved efficiently and consistently. A reduction in potential sources of error results, in particular, from the automatic and time-saving linking of measures relevant to multiple information security vulnerabilities.

[0035] According to a particularly user-friendly embodiment of the present invention, possible measures for each information security vulnerability are displayed for user selection on a graphical user interface of a plant monitoring system when creating device- or resource-specific task lists. One of the possible measures is then entered into the currently edited device- or resource-specific task list according to the user's selection.

[0036] In particular, an automatic link is established with all matching measures in the device- or resource-specific task list that are intended to address other information security vulnerabilities. This further reduces potential sources of error.

[0037] Furthermore, information security vulnerabilities are preferably displayed on the graphical user interface of the plant monitoring system to enable user prioritization of measures when creating device- or resource-specific task lists, along with a risk assessment, particularly in the form of a risk level. The measures are then processed according to the user prioritization by a configuration system of the industrial automation system. This ensures that information security vulnerabilities that are most significant for an industrial automation system are quickly eliminated or minimized. 202504401 Foreign version

[0038] 7

[0039] Preferably, the available measures for each information security vulnerability, along with an assessment of the risk reduction offered by each measure, will be displayed to the user in the graphical user interface of the plant monitoring system. This allows for the easy identification of effective measures.

[0040] According to a further embodiment of the present invention, the measures are checked against the device- or resource-specific task lists to determine whether they are intended for multiple devices or resources. For multiple devices or resources,

[0041] Resource-related actions are linked together in the device- and / or resource-specific task lists. For linked actions, implementation only occurs once for all devices and / or resources affected by the respective action. This allows for consistent action to be defined across device and resource boundaries. This is a significant advantage, particularly from an interoperability and compatibility perspective. For example, essential firmware updates no longer need to be postponed for fear that devices with updated firmware will no longer function in conjunction with other devices.

[0042] Advantageously, a user-selected action entered into a currently edited device- or resource-specific task list is automatically linked to all other task lists for devices or resources that also require the respective action. This ensures maximum smooth interaction between different devices and resources.

[0043] According to a preferred embodiment of the present invention, the graphical user interface of the plant monitoring system displays a list of available firmware versions for a selected device or resource, indicating the information security vulnerabilities of the selected device or resource that are addressed by each firmware version. Advantageously, the device- or resource-specific task list is automatically adapted to the respective firmware version. Furthermore, the list of available firmware versions, including the information security vulnerabilities addressed by each firmware version, can be sorted according to the risk level of the addressed vulnerabilities.Overall, this allows for significant time savings and a high degree of transparency when selecting firmware updates to be installed. For example, it is quickly apparent which information security vulnerabilities, and of what severity, exist according to the foreign version of 202504401.

[0044] 8

[0045] Firmware updates will remain and must be addressed through other measures. Based on this, the security level within an industrial automation system can be specifically increased.

[0046] The computer program according to the invention is suitable for carrying out a method as described above and comprises at least one code section that can be loaded into the working memory of a data processing device and executed by a processor of the data processing device. When the code section is executed, devices or resources of the automation system are identified that must be protected against unauthorized access when the computer program is running in the data processing device. Furthermore, when the code section is executed, known information security vulnerabilities are detected for the identified devices and / or resources. Additionally, a device- or resource-specific task list is generated for each device or resource, containing all measures intended for the device or resource that are necessary or suitable for addressing the detected information security vulnerabilities.

[0047] Furthermore, when the code section of the computer program according to the invention is executed, the measures are checked against the respective device- or resource-specific task list to determine whether they are intended to address multiple information security vulnerabilities. Measures intended to address multiple information security vulnerabilities are linked together in the respective device- or resource-specific task list. For linked measures, the computer program according to the invention only performs a single implementation for all information security vulnerabilities for which the respective measure is intended to address the vulnerabilities.

[0048] The present invention is explained in more detail below using an exemplary embodiment with reference to the drawing. It shows

[0049] Figure 1 shows a schematic representation of how information security vulnerabilities of a device or resource are handled within an industrial automation system.

[0050] Figure 2 shows a schematic representation of a selection of firmware versions for addressing information security vulnerabilities. 202504401 Foreign version

[0051] 9

[0052] The starting point for the treatment of information security vulnerabilities of a device or resource within an industrial automation system, as illustrated in Figure 1, is first the identification of devices or resources that must be protected, at least against unauthorized access. Known information security vulnerabilities are then recorded for these identified devices or resources. These vulnerabilities can be identified, for example, using information provided by device manufacturers or trusted entities.

[0053] In the present embodiment, a device 10 is considered for which five information security vulnerabilities 11-15 have been identified. The following explanations apply analogously to resources with information security vulnerabilities. In principle, a device- or resource-specific task list 110 is created for each device or resource, containing all measures 111-114 intended for the device 10 or resource that are necessary or suitable for addressing the identified information security vulnerabilities 11-15. This device- or resource-specific task list 110 is preferably displayed on a graphical user interface of a plant monitoring system for verification and confirmation by operating personnel. Generally, the measures 111-114 are checked against the respective device- or resource-specific task list 110 to determine whether they are intended to address multiple information security vulnerabilities 11-14.The measures 111-114 for addressing information security vulnerabilities 11-14 are preferably determined based on recommendations provided by device manufacturers or trusted authorities. However, in principle, a user-specific definition of measures is also possible, independent of such recommendations.

[0054] For automated comparison, the graphical user interface of the plant monitoring system displays possible measures 111-113 for user selection in a display area 101-105, individually provided for each information security vulnerability 11-14. As explained in detail below, measures 111-114 that are intended for multiple information security vulnerabilities 11-15 are linked together in the device- or resource-specific task list 110. For linked measures 111-114, implementation occurs only once for all information security vulnerabilities 11-15 for which the respective measure 111-114 is intended to remedy them. 202504401 Foreign version

[0055] 10

[0056] As shown in Figure 1, for a first information security vulnerability 11, in particular a first measure 111, a second measure 112, and a third measure 113 are suggested as options in display area 101, while for a second information security vulnerability 12, for example, the second measure 112 is suggested in display area 102. Furthermore, for a third information security vulnerability 13, in display area 103, in particular the first measure 111 is suggested, while for a fourth information security vulnerability 14, in display area 104, for example, the second measure 112 and the third measure 113 are suggested as possible remediation options. At least one of the possible measures 111-113 is entered into the device- or resource-specific task list 110 according to user selection 1-3.

[0057] In the embodiment shown in Figure 1, the first measure 111 from the display area 101 for the first information security vulnerability 11 is entered into the device- or resource-specific task list 110 by a first user selection 1. The first measure 111 for the first information security vulnerability 11 is automatically linked to the corresponding first measure 111 suggested in the display area 103 for the third information security vulnerability 13. Selected or automatically linked measures 111-113 are displayed in the graphical user interface of the plant monitoring system, each in a separate control area 121-125 for each information security vulnerability 11-15.In this context, linked measures are advantageously highlighted by dashed lines between entries for measures in the respective control area 121-125 and entries for measures in the device- or resource-specific task list 110.

[0058] In the present embodiment, the second measure 112 from display area 101 for the first information security vulnerability 11 is entered into the device- or resource-specific task list 110 by a second user selection 2. The second measure 112 for the first information security vulnerability 11 is automatically linked to the corresponding second measures 112 suggested in display area 102 for the second information security vulnerability 12 and in display area 104 for the fourth information security vulnerability 14. Accordingly, the entries for the second measure 112 in control areas 121 and 124, on the one hand, and in the device- or resource-specific task list 110, on the other hand, are highlighted as linked by means of dashed lines. 202504401 Foreign version

[0059] 11

[0060] Furthermore, in the present embodiment, the third measure 113 from display area 104 for the fourth information security vulnerability 14 is entered into the device- or resource-specific task list 110 by a third user selection 3. The third measure 113 for the fourth information security vulnerability 14 is automatically linked to the corresponding third measure 113 suggested in display area 101 for the first information security vulnerability 11. Accordingly, the entries for the third measure 113 in control areas 121 and 124, on the one hand, and in the device- or resource-specific task list 110, on the other hand, are highlighted as linked by means of dashed lines.

[0061] As shown in Figure 1, in addition to the previously described selection from suggested measures, a measure can also be defined manually or by a user. For example, such a user-defined measure 114 is entered into the device- or resource-specific task list 110 via user input 4 for a fifth information security vulnerability 15. Since this user-defined measure 114 is also to be applied to the second information security vulnerability 12 according to the present embodiment, the user-defined measures 114 for the second 12 and the fifth information security vulnerability 15 are linked accordingly via the device- or resource-specific task list 110, analogous to the procedure described above.In the graphical user interface of the plant monitoring system, this link is symbolized by lines between the control areas 122, 125 on the one hand and the device- or resource-specific task list 110 on the other.

[0062] Additionally, the information security vulnerabilities 11-15 can be displayed on the graphical user interface of the plant monitoring system for user prioritization of measures 111-114 when creating the device- or resource-specific task list 110, along with a risk assessment, particularly in the form of a risk level. This allows measures 111-114 to be processed according to the user prioritization by a configuration system of the industrial automation system. Furthermore, the available measures 111-114 for each information security vulnerability 11-15 can be selected by the user, along with an assessment of the risk reduction achieved by each measure 111-114, on the graphical user interface of the plant monitoring system.

[0063] 12

[0064] They will be displayed. In this way, measures 111-114 can be prioritized to maximize their impact.

[0065] Task lists with actions are advantageously processed device- or resource-wise. As shown in Figure 1, a package of actions 120 is defined for device 10, comprising the device- or resource-specific task list 110 with the selected actions 111-114 confirmed by operating personnel. In principle, the actions can be checked against device- or resource-specific task lists to determine whether they are intended for multiple devices or resources. Actions intended for multiple devices or resources can then be linked together in the device- or resource-specific task lists. In this case, linked actions are implemented only once or uniformly for all devices or resources affected by the respective action. Preferably, an action that is selected by the user and placed in a currently processed device- or resource-specific task list is...When a resource-specific task list is entered, it is automatically linked to all other task lists for devices or...

[0066] Resources are linked that also require the respective action. In this way, actions can be implemented across multiple devices or resources without contradictions.

[0067] The measures 111-114 for addressing the information security vulnerabilities 11-15 may include software updates, especially firmware updates, or...

[0068] Configuration changes are included. Preferably, the information or recommendations provided by device manufacturers or trusted entities also include details of which firmware versions address the respective information security vulnerabilities 11-15. For example, the graphical user interface of the plant monitoring system can display a list of available firmware versions for a selected device or resource, indicating which information security vulnerabilities are addressed by each firmware version. Furthermore, the device- or resource-specific task list is advantageously automatically updated to reflect the respective firmware version.Furthermore, the list of available firmware versions can be sorted by risk level according to the information security vulnerabilities fixed by each firmware version (202504401 foreign version).

[0069] 13

[0070] Information security vulnerabilities are displayed in a sorted format. This allows for even better prioritization of the implementation of measures.

[0071] Support in selecting suitable firmware versions for addressing information security vulnerabilities can be provided, in particular, by means of a monitoring application supplied by the plant monitoring system. As shown in Figure 2, the monitoring application 200 accesses information about the information security vulnerabilities 11-15 identified for the device 10 as described above. The monitoring application 200 provides, in particular, functions 201 aimed at the isolated analysis of individual information security vulnerabilities. This includes a function module 211 for checking whether a firmware update to address the respective information security vulnerability is available.

[0072] Furthermore, a function module 212 is provided to determine which specific firmware version is required as an update. Finally, a function module 213 is provided to analyze whether, in addition to a firmware update, further steps are necessary to resolve the respective information security vulnerability.

[0073] Beyond the isolated analysis of individual information security vulnerabilities, the monitoring application 200 provides functions 202 aimed at analyzing information security vulnerabilities in conjunction with other security-relevant factors. This includes a function module 221 for generating a list of firmware versions available as updates. Additionally, a function module 222 is provided for identifying those information security vulnerabilities that cannot be resolved by a firmware update. Complementing this is an additional function module 223, which generates a list of information security vulnerabilities for which no further remediation steps are required. Furthermore, a function module 224 is provided for determining a version hierarchy for the available firmware versions.

[0074] Furthermore, the monitoring application provides 200 functions 203 for generating action options 231-233 based on the analyses described above. A first, recommended action option 231 could, for example, include a firmware update to a selected or latest firmware version x, which would resolve a maximum number n of information security vulnerabilities with a given risk level. Alternatively, a second action option 232, with limitations, could, for example, include a firmware update to a previous version x-1 of the selected or latest firmware version, which would resolve a reduced number of 202504401 foreign version

[0075] 14

[0076] The number of information security vulnerabilities with a given risk level can be remedied. In contrast, a third action option 233, with even more extensive limitations, could, for example, include a firmware update to a version two years prior. At least one of these action options 231-233 can be selected and implemented via user selection 21, 22. Preferably, the monitoring application 200 displays in detail for each action option which information security vulnerabilities are specifically remedied, which information security vulnerabilities cannot be remedied by a firmware update, and for which information security vulnerabilities further steps are required.

[0077] The above measures include not only firmware updates or configuration changes, but can also include, for example, physical or spatial data backup or other precautions regarding data backup, encryption and access controls, as well as the use of fault-tolerant systems.

Claims

202504401 Foreign version 15 Patent claims 1. Method for addressing information security vulnerabilities within an industrial automation system, executed by a plant monitoring system, in which - Devices (10) and / or resources of the automation system are identified that need to be protected against unauthorized access, - known information security vulnerabilities (11-15) for the identified devices (10) and / or resources are recorded, - for each device (10) and / or resource, a device- and / or resource-specific task list (110) is created with all measures (111-114) intended for the device and / or resource that are necessary or appropriate to address the identified information security vulnerabilities (11-15), - the measures (111-114) are checked against the respective device- and / or resource-specific task list (110) to see whether they are intended to address multiple information security vulnerabilities (11-15), - Measures (111-113) that are provided for in the case of multiple information security vulnerabilities (11-14) are linked together in the respective device- and / or resource-specific task list (110), - in the case of interconnected measures (111-113), only a single implementation is carried out for all information security vulnerabilities (11-14) for which the respective measure is intended to remedy them.

2. Method according to claim 1, In a system where, for the creation of device- and / or resource-specific task lists, possible measures for each information security vulnerability are displayed for user selection on a graphical user interface of a plant monitoring system, and where one of the possible measures is entered into a currently edited device- and / or resource-specific task list according to user selection and is automatically linked with all matching measures in the device- and / or resource-specific task list that are intended for remedying other information security vulnerabilities.

3. Method according to claim 2, where the information security vulnerabilities are used to determine a user prioritization of measures when creating the device and / or 202504401 foreign version 16 Resource-specific task lists with a risk assessment, particularly in the form of a risk level, are displayed on the graphical user interface of the plant monitoring system, and the measures are processed according to user prioritization by a configuration system of the industrial automation system.

4. Method according to one of claims 2 or 3, where the possible measures for each information security vulnerability are displayed to the user for selection, along with an assessment of the risk reduction achieved by each measure, on the graphical user interface of the plant monitoring system.

5. Method according to any one of claims 1 to 4, where the measures are checked against the device- and / or resource-specific task lists to see if they are intended for multiple devices and / or resources, where measures intended for multiple devices and / or resources are linked together in the device- and / or resource-specific task lists, and where, in the case of linked measures, only a one-time implementation takes place for all devices and / or resources affected by the respective measure.

6. Method according to claim 5, where a corresponding user selection entered into a currently edited device- and / or resource-specific task list is automatically linked to all other task lists for devices and / or resources that also require the respective action.

7. Method according to any one of claims 1 to 6, where the task lists are processed with the measures on a device- and / or resource-by-device basis.

8. Method according to any one of claims 1 to 7, where information security vulnerabilities are identified using information provided by device manufacturers and / or trusted entities, and where measures to address the information security vulnerabilities are determined using recommendations provided by device manufacturers and / or trusted entities. 202504401 Foreign version 17 9. Method according to claim 8, where the measures include software updates, especially firmware updates, and / or configuration changes.

10. Method according to one of claims 8 or 9, where the information and / or recommendations provided by device manufacturers and / or trusted entities include details of which firmware versions will fix the respective information security vulnerability.

11. Method according to claim 10, where, on the graphical user interface of the plant monitoring system, a list of available firmware versions is displayed for a selected device and / or resource, indicating the information security vulnerabilities of the selected device and / or resource that are addressed by each firmware version, allowing the user to make a selection.

12. Method according to claim 11, where the device- and / or resource-specific task list is automatically adapted to the respective firmware version.

13. Method according to one of claims 11 or 12, where the list of available firmware versions is displayed, sorted by risk level of the information security vulnerabilities addressed by each firmware version.

14. Computer program comprising at least one code section that can be loaded into the main memory of a data processing device and executed by a processor of the data processing device, the execution of which - Identify devices and / or resources of the automation system that need to be protected against unauthorized access, - known information security vulnerabilities for the identified devices and / or resources are recorded, - a device- and / or resource-specific task list is created for each device and / or resource, containing all measures intended for the device or resource that are necessary or suitable for addressing the identified information security vulnerabilities, 202504401 Foreign version 18 - the measures are checked against the respective device- and / or resource-specific task list to see if they are intended to address multiple information security vulnerabilities, - Measures that are planned for multiple information security vulnerabilities are linked together in the respective device- and / or resource-specific task list, - in the case of interconnected measures, only a one-time implementation is carried out for all information security vulnerabilities for which the respective measure is intended to remedy, when the computer program is running in the data processing facility.

15. Computer program according to claim 14, wherein the computer program is designed to carry out a method according to one of claims 1 to 13.