User Manual

Getting started
Safety notes
2
A6V12237004_enUS_b
17 | 47
Remote Web Client
The recommended browser for use with Cerberus Cloud Apps is Chrome.
Incident Handling
Siemens has processes in place for handling security incidents. If a cybersecurity
threat is suspected or found, immediately contact Siemens Computer Emergency
Response Team for products (Product CERT) or your local Siemens customer
service.
More detail on Incident handling can be found
at:
https://www.siemens.com/cert/advisories.
2.4.2 Customer Operation Best Practices
Most cybersecurity breaches are the result of an internal employee/contractor in an
organization doing something either they were not supposed to do or they fail to do
something they are supposed to do, or both. Listed below are some of the best
practices from a customer management and risk mitigation perspective to ensure
cybersecurity risks are identified and mitigated.
Remote Web Client
Users must keep the web browsers and operating system continuously updated
on their client devises (PC, tablet, mobile) to mitigate security vulnerabilities.
Users must keep a continuously up-to-date virus and malware protection software
installed on their client devices (PC, tablet, mobile).
Replace client devices if they have reached the end of their life cycle or
maintenance cycle.
Cloud Application
Recommend no more than two Administrator accounts for one Cerberus Cloud
Apps subscription. Tasks should be limited to managing users and subscriptions.
Administrators must never share their login credentials.
When inviting users to Cerberus Cloud Apps, use the least privilege principle, that
is, individuals are invited with roles reflecting the minimum privilege required to
complete their task within the organization
Remove/update a user accounts as soon as user is no longer associated with a
company or their role.
Refer to the User Guide for Roles and Authorization.
Always logout of your session once you finish using the application.
On-premise IT/OT network and Connect X300 gateway
Ensure Connect X300 gateway installation follows the Cerberus Cloud Apps
installation guide and the fire system cybersecurity guideline.
Administrator credentials for Connect X300 gateway must not be shared.
Ensure correct configuration on the Connect X300 gateway to access web
applications.