Connected CNC, Hidden Risk: An OT Cybersecurity Procurement Checklist for Machine Tool Buyers
連網 CNC 的隱形風險:工具機買家必備的 OT 資安採購清單
네트워크에 연결된 CNC의 보이지 않는 위험: 공작기계 구매자를 위한 OT 사이버 보안 체크리스트
Once a CNC machine is connected to the factory network, cybersecurity stops being an office-computer problem. A modern machining cell may link the CNC controller, servo drives, industrial robots, vision systems, tool management, MES, production databases and a supplier’s remote-service platform. Those links improve visibility and shorten service response — and they also create paths between enterprise IT and the production floor that did not exist when the machine stood alone. So when buying a five-axis machining centre, a mill-turn lathe or an automated loading cell, network architecture, account control, remote maintenance, patching policy and recovery capability belong in the procurement specification alongside accuracy, spindle speed, travels and cycle time. Machine tool cybersecurity is a specification question before it is an IT one.
當 CNC 工具機接上工廠網路,資安就不再只是辦公室電腦的問題。現代加工單元可能同時串接控制器、伺服驅動器、工業機器人、視覺系統、刀具管理、MES、生產資料庫,以及供應商的遠端維修平台。這些連線提升了生產透明度與維修效率,同時也在企業網路與生產現場之間開出了原本不存在的通道。因此,採購五軸加工機、車銑複合機或自動上下料系統時,網路架構、帳號權限、遠端維護方式、修補政策與備份復原能力,應該和精度、轉速、行程、節拍一樣,被寫進正式採購規格。
CNC 공작기계가 공장 네트워크에 연결되는 순간, 사이버 보안은 더 이상 사무용 컴퓨터만의 문제가 아닙니다. 현대적인 가공 셀은 CNC 제어기, 서보 드라이브, 산업용 로봇, 비전 시스템, 공구 관리, MES, 생산 데이터베이스, 공급사의 원격 유지보수 플랫폼까지 연결될 수 있습니다. 이러한 연결은 생산 가시성과 서비스 대응 속도를 높이지만, 동시에 장비가 독립적으로 운전될 때는 없었던 경로를 기업 IT와 생산 현장 사이에 만듭니다. 따라서 5축 머시닝센터, 복합가공기, 자동 로딩 셀을 구매할 때 네트워크 구조, 계정 권한, 원격 유지보수 방식, 패치 정책, 복구 능력은 정밀도·회전수·행정·사이클 타임과 함께 구매 사양에 포함되어야 합니다.
🏭 Why CNC Security Is an OT Issue, Not Only an IT One (為什麼 CNC 資安屬於 OT)
CNC controllers, robot control cabinets, PLCs, HMIs and servo systems belong to the operational technology (OT) environment, where safe operation, process stability and availability come first. An office PC can usually be patched and rebooted soon after a vulnerability is published. Updating a CNC controller may affect NC program and parameter compatibility, PLC or PMC logic, servo tuning and compensation data, communication with robots and peripherals, safety circuits and machine certification status, and processes that have already been validated for production. OT security therefore does not mean pushing every update immediately; it means assessing safety, production and compatibility impact first, then backing up, testing, updating and re-verifying under controlled conditions. NIST SP 800-82 Rev. 3 makes the same point: OT security has to weigh performance, reliability, safety and availability, rather than transplanting conventional IT controls unchanged.
OT 的優先順序不同:CNC 控制器、機器人控制櫃、PLC、HMI 與伺服系統都屬於營運技術(Operational Technology, OT)環境,首要目標是設備安全、製程穩定與生產可用性。一般辦公室電腦在漏洞公布後多半可以很快更新並重新開機;但 CNC 控制器的更新可能影響 NC 程式與參數相容性、PLC/PMC 邏輯、伺服調校與補償資料、機器人與周邊設備的通訊、安全迴路與機台認證狀態,以及既有的生產驗證結果。所以 OT 資安不是「把所有設備立刻更新到最新版」,而是先評估安全、生產與相容性影響,再於受控條件下備份、測試、更新並重新驗證。NIST SP 800-82 Rev. 3 的立場也是如此:OT 環境必須同時衡量性能、可靠度、安全與可用性,不能直接照搬一般 IT 的資安作法。
OT는 우선순위가 다릅니다: CNC 제어기, 로봇 제어반, PLC, HMI, 서보 시스템은 운영 기술(Operational Technology, OT) 환경에 속하며, 여기서는 안전 운전·공정 안정성·가용성이 우선합니다. 사무용 PC는 취약점이 공개된 뒤 비교적 빨리 패치하고 재부팅할 수 있습니다. 그러나 CNC 제어기 업데이트는 NC 프로그램과 파라미터 호환성, PLC·PMC 로직, 서보 튜닝과 보정 데이터, 로봇 및 주변장치와의 통신, 안전 회로와 기계 인증 상태, 이미 검증된 생산 공정에 영향을 줄 수 있습니다. 따라서 OT 보안은 모든 업데이트를 즉시 적용하는 것이 아니라, 안전·생산·호환성 영향을 먼저 평가한 뒤 통제된 조건에서 백업·시험·업데이트·재검증을 수행하는 것입니다. NIST SP 800-82 Rev. 3도 OT 보안은 성능·신뢰성·안전·가용성을 함께 고려해야 하며 일반 IT 통제를 그대로 옮겨서는 안 된다고 설명합니다.
🚨 What an Incident Can Actually Affect (一次事件可能影響什麼)
The risk is not simply "the machine screen catches a virus". A compromise of a connected CNC environment can mean unauthorised changes to NC programs, tool offsets or machine parameters; controllers, HMIs or robots that cannot be logged into or started; loss of production scheduling and traceability data; exposure of drawings, programs and customer information; ransomware moving laterally from enterprise IT into the production network; misuse of a vendor remote-service account; and extended downtime with no reliable backup to restore from. Where the plant makes aerospace, defence, medical or other regulated parts, an incident may also touch confidentiality obligations, export-controlled information and supply-chain contract terms. That said, CMMC and NIST SP 800-171 do not apply automatically to every aerospace supplier — applicability depends on the contract, the information handled, and whether the organisation processes US Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Scope should be confirmed by contract and compliance staff, not assumed from the industry label.
影響範圍不只是「螢幕中毒」:連網 CNC 遭入侵,可能造成 NC 程式、刀具補正或機台參數被未授權修改;控制器、HMI 或機器人無法登入或啟動;生產排程與品質追溯資料無法取得;加工圖面、程式與客戶資料外洩;勒索軟體由企業 IT 網路橫向移動至生產網路;遠端維修帳號被冒用;以及機台長時間停機卻無可靠備份可還原。若工廠承接航太、國防、醫療或其他受管制零件,事件還可能牽涉客戶保密義務、出口管制資料與供應鏈合約要求。不過,CMMC 或 NIST SP 800-171 並不會自動適用於所有航太供應商——是否適用取決於客戶合約、處理的資料類型,以及企業是否接觸美國聯邦合約資訊(FCI)或受控非機密資訊(CUI)。適用範圍應由合約與法遵人員確認,不能僅憑產業別推定。
"화면이 감염되는" 문제가 아닙니다: 연결된 CNC 환경이 침해되면 NC 프로그램·공구 보정값·기계 파라미터의 무단 변경, 제어기·HMI·로봇의 로그인 또는 기동 불가, 생산 일정과 추적 데이터의 손실, 도면·가공 프로그램·고객 정보 유출, 기업 IT에서 생산 네트워크로의 랜섬웨어 확산, 공급사 원격 서비스 계정의 도용, 신뢰할 수 있는 백업이 없어 길어지는 정지가 발생할 수 있습니다. 항공우주·방산·의료 등 규제 부품을 가공하는 공장이라면 고객 기밀유지 의무, 수출통제 정보, 공급망 계약 조건에도 영향이 미칠 수 있습니다. 다만 CMMC나 NIST SP 800-171이 모든 항공우주 협력업체에 자동으로 적용되는 것은 아닙니다. 적용 여부는 계약 내용, 취급 정보의 유형, 미국 연방계약정보(FCI) 또는 통제되지 않은 비밀정보(CUI) 처리 여부에 따라 결정됩니다. 적용 범위는 산업 분류가 아니라 계약·컴플라이언스 담당자가 확인해야 합니다.
📋 1. A Complete Asset and Software Inventory (完整的設備與軟體清單)
Ask the supplier for a list of every component in the machine that has a network interface or processes data: CNC controller and HMI; PLC, PMC and safety controller; industrial PC, operating system and database; robot and vision controllers; industrial switches, wireless devices and IoT gateways; remote-service software; the protocols and ports actually enabled; and the major firmware and software versions. Without that inventory it is difficult to judge which components need patching, isolation or monitoring — and impossible to answer quickly when a vulnerability is published for a component you did not know was in the machine. CISA’s asset-inventory guidance for OT owners and operators treats this as the foundation on which a defensible OT architecture is built.
先問清楚機台裡有什麼:請供應商列出機台內所有具網路介面或資料處理能力的元件:CNC 控制器與 HMI;PLC/PMC 與安全控制器;工業電腦、作業系統與資料庫;機器人與視覺控制器;工業交換器、無線設備與 IoT 閘道器;遠端維修軟體;實際啟用的通訊協定與連接埠;以及主要韌體與軟體版本。沒有這份清單,就難以判斷哪些元件需要修補、隔離或監控;當某個元件被公布漏洞時,也無法快速回答「機台裡到底有沒有這個東西」。CISA 針對 OT 業主與運維單位發布的資產盤點指引,也把它視為建立可防禦 OT 架構的基礎。
장비 안에 무엇이 들어 있는지부터: 네트워크 인터페이스가 있거나 데이터를 처리하는 모든 구성요소의 목록을 공급사에 요청하십시오. CNC 제어기와 HMI, PLC·PMC와 안전 제어기, 산업용 PC·운영체제·데이터베이스, 로봇 및 비전 제어기, 산업용 스위치·무선 장치·IoT 게이트웨이, 원격 유지보수 소프트웨어, 실제로 활성화된 프로토콜과 포트, 주요 펌웨어와 소프트웨어 버전입니다. 이 목록이 없으면 어떤 구성요소를 패치·격리·감시해야 하는지 판단하기 어렵고, 특정 부품의 취약점이 공개되었을 때 해당 부품이 장비에 있는지조차 즉시 답할 수 없습니다. CISA가 OT 소유자와 운영자를 위해 제시한 자산 목록 지침도 이를 방어 가능한 OT 아키텍처의 기초로 봅니다.
🧱 2. Equipment That Can Be Segmented (可實施網路分區)
CNC network security starts with where the machine sits on the network. It should not be directly exposed to the public internet without protection, nor share an unrestricted network with office PCs, guest Wi-Fi and general-purpose devices. The specification should call for support for fixed addressing and a documented set of communication requirements; the ability to restrict source, destination and service through an industrial firewall or ACLs; the ability to disable unused network services; separation of IT, OT, automation cells and the remote-service zone; and, where MES, file or historian data has to cross the boundary, a DMZ to exchange it. NIST SP 800-82 Rev. 3 recommends characterising, segmenting and isolating IT and OT devices by trust level, criticality, administrative ownership and data flow — which is easier to implement when it was written into the order than when it is retrofitted after installation.
分區要在下單時就能落實:CNC 不應在沒有防護的情況下直接暴露於公共網際網路,也不應與辦公室電腦、訪客 Wi-Fi 及一般設備處於完全開放的同一網段。採購規格應要求:支援固定 IP 並提供明確的通訊需求清單;可透過工業防火牆或 ACL 限制來源、目的地與服務;未使用的網路服務可以停用;IT、OT、自動化單元與遠端維修區可以分區;若 MES、檔案或歷史資料必須跨區交換,可透過 DMZ 進行。NIST SP 800-82 Rev. 3 建議依信任程度、關鍵性、管理權責與資料流來分類、分割並隔離 IT/OT 設備——這些要求寫在訂單裡最容易落實,等安裝後才補做通常代價更高。
망 분리는 발주 단계에서 가능해야 합니다: CNC를 보호 조치 없이 공용 인터넷에 직접 노출하거나, 사무용 PC·방문자 Wi-Fi·범용 장비와 제한 없는 동일 네트워크에서 운용해서는 안 됩니다. 사양에는 고정 주소 지원과 통신 요구사항 목록 제공, 산업용 방화벽 또는 ACL을 통한 출발지·목적지·서비스 제한, 미사용 네트워크 서비스의 비활성화, IT·OT·자동화 셀·원격 유지보수 구간의 분리, MES·파일·히스토리안 데이터 교환이 필요한 경우의 DMZ 구성을 포함하십시오. NIST SP 800-82 Rev. 3은 신뢰 수준, 중요도, 관리 주체, 데이터 흐름에 따라 IT와 OT 장비를 분류·분할·격리할 것을 권고합니다. 이런 요구사항은 발주서에 적혀 있을 때 가장 쉽게 구현되며, 설치 후 소급 적용하면 대개 비용이 커집니다.
👤 3. Unique Accounts and Role-Based Permissions (唯一帳號與角色權限)
A shared administrator account makes it impossible to say who changed what. Equipment should support individual accounts for operators, engineers and service staff; permissions set by role; a higher authorisation level for changes to NC programs, parameters and PLC logic; removal or modification of factory default passwords; prompt revocation when someone leaves or a job ends; and an audit record of logins and significant changes. Where the controller itself cannot provide full account management — which is common on older CNC generations — the supplier should state what compensating controls are available instead: a hardened jump host, firewall allowlisting, or a physical key switch that limits who can put the machine into a state where parameters can be edited.
共用管理員帳號等於沒有責任歸屬:設備應支援每位操作員、工程師與維修人員使用個別帳號;依職務設定角色權限;變更 NC 程式、參數與 PLC 邏輯時採用較高權限;可停用或修改出廠預設密碼;人員離職或任務結束後能迅速撤銷權限;並保留登入與重要變更的稽核紀錄。若控制器本身無法提供完整帳號管理(較舊世代的 CNC 相當常見),供應商應說明可採用哪些補償控制:強化過的跳板主機、防火牆白名單,或以實體鑰匙開關限制誰能把機台切換到可修改參數的狀態。
공용 관리자 계정은 책임 추적을 없앱니다: 설비는 작업자·엔지니어·서비스 인력별 개별 계정, 직무에 따른 역할 권한, NC 프로그램·파라미터·PLC 로직 변경 시의 상위 권한, 출하 기본 비밀번호의 변경 또는 비활성화, 퇴사나 작업 종료 시의 신속한 권한 회수, 로그인과 주요 변경의 감사 기록을 지원해야 합니다. 제어기 자체가 완전한 계정 관리를 제공하지 못하는 경우(구세대 CNC에서는 흔합니다) 공급사는 대체 통제 수단을 제시해야 합니다. 보안이 강화된 점프 호스트, 방화벽 허용 목록, 또는 파라미터를 수정할 수 있는 상태로 전환할 수 있는 사람을 제한하는 물리적 키 스위치 등입니다.
🔐 4. Controlled Remote Service (受控的遠端維修)
Remote CNC maintenance genuinely shortens downtime on imported equipment, and no buyer should give it up out of caution alone. What creates risk is the permanently open, unsupervised channel. A sound arrangement uses an encrypted VPN or a managed access gateway; multi-factor authentication for remote and privileged access; per-session approval by plant staff; access that is time-limited and expires when the work is done; access scoped to the assigned machine only; logs showing who connected, when, to what and what they did; and a plant-side means — physical or logical — of cutting the connection immediately. CISA’s primary mitigations for OT make the same recommendation: take OT assets off direct public-internet exposure and, where remote access is genuinely required, put it behind controlled, encrypted, MFA-protected and logged connectivity with least privilege.
問題不在遠端維修,而在「永遠開著」:遠端診斷確實能縮短進口設備的停機時間,買家不需要因為擔心資安就一律拒絕;真正的風險是長期開啟又無人監督的通道。較合理的做法包括:使用加密 VPN 或受管制的安全閘道;對遠端與管理權限實施多因素驗證(MFA);由工廠人員逐次核准連線;權限限時、工作完成後自動失效;只能存取指定機台;保留連線者、時間、目標設備與操作內容的紀錄;並提供工廠端可立即中斷連線的實體或邏輯手段。CISA 的 OT 優先緩解措施也是同樣建議:先讓 OT 資產離開直接暴露於公共網際網路的狀態,若確實需要遠端存取,則以受控、加密、具 MFA 且留有紀錄的最小權限連線方式進行。
문제는 원격 유지보수가 아니라 "항상 열려 있음"입니다: 원격 진단은 수입 설비의 정지 시간을 실제로 줄여 주므로 보안을 이유로 무조건 배제할 필요는 없습니다. 위험을 만드는 것은 상시 개방된 무감독 통로입니다. 바람직한 구성은 암호화 VPN 또는 관리형 접속 게이트웨이, 원격 및 관리자 접속에 대한 다중 인증(MFA), 접속 건별 공장 담당자 승인, 작업 종료 시 만료되는 시간 제한 권한, 지정 장비로 한정된 접근 범위, 접속자·시간·대상 장비·작업 내용의 기록, 공장 측에서 즉시 차단할 수 있는 물리적 또는 논리적 수단입니다. CISA의 OT 우선 완화 조치도 동일합니다. OT 자산을 공용 인터넷 직접 노출에서 제외하고, 원격 접속이 꼭 필요하다면 통제·암호화·MFA·로깅을 갖춘 최소 권한 연결로 수행하라는 것입니다.
📁 5. Secure Program and File Transfer (安全的程式與檔案傳輸)
NC programs reach the machine by USB stick, shared folder, DNC, FTP or MES, and each route is a way in as well as a way to work. Establish before purchase whether USB ports can be restricted, disabled or allowlisted; whether files can be scanned before transfer; whether the machine still depends on unencrypted FTP, Telnet or similar legacy services; whether NC program changes are versioned, approved and traceable; and whether the controller can verify the source and integrity of update and firmware files. Legacy protocols that cannot be replaced are not automatically unacceptable — but they should then be protected by segmentation, strict allowlisting, a controlled gateway or one-way transfer, and that should be part of the delivered design rather than left to the buyer to work out afterwards.
傳程式的路徑,也是進來的路徑:NC 程式可能透過 USB、共享資料夾、DNC、FTP 或 MES 傳送。採購前應確認:USB 裝置能否限制、停用或建立核准清單;是否支援傳輸前掃描;機台是否仍依賴未加密的 FTP、Telnet 等舊式服務;NC 程式修改是否有版本、核准與稽核機制;控制器能否驗證更新檔與韌體的來源及完整性。無法替換的舊式協定並非絕對不能接受,但應以網路隔離、嚴格白名單、受控閘道或單向傳輸加以保護,而且這應該是交付設計的一部分,不該留給買方事後自行想辦法。
프로그램이 들어오는 경로가 곧 침입 경로입니다: NC 프로그램은 USB, 공유 폴더, DNC, FTP, MES를 통해 전송됩니다. 구매 전에 USB 포트의 제한·비활성화·허용 목록 적용 가능 여부, 전송 전 파일 검사 지원 여부, 암호화되지 않은 FTP·텔넷 등 구형 서비스에 대한 의존 여부, NC 프로그램 변경의 버전 관리·승인·추적 가능 여부, 업데이트 파일과 펌웨어의 출처 및 무결성 검증 가능 여부를 확인하십시오. 대체할 수 없는 구형 프로토콜이 반드시 불가한 것은 아니지만, 그 경우 망 분리, 엄격한 허용 목록, 통제형 게이트웨이, 단방향 전송으로 보호해야 하며, 이는 납품 설계에 포함되어야지 바이어가 사후에 알아서 해결할 문제가 아닙니다.
🛠️ 6. Vulnerability Disclosure and Update Policy (漏洞揭露與安全更新政策)
Ask the supplier to explain how security reports are received and handled; whether security advisories or CVE information are published; the support period for software, firmware and the operating system; how compatibility is tested before an update is released; what interim mitigation is offered while a patch is being prepared; how a failed update is rolled back; and what upgrade or isolation options exist once a controller reaches end of support. This last point matters more than it looks: a machine tool often stays in service well past the security support life of its controller PC and operating system, so knowing the end-of-support date at purchase is part of planning the asset, not a detail. Neither "never update" nor "update immediately without testing" is a mature OT maintenance policy.
先問清楚支援期限:採購時應請供應商說明:如何接收與處理資安漏洞通報;是否發布安全公告或 CVE 資訊;軟體、韌體與作業系統的支援期限;更新發布前的相容性測試方式;修補程式尚未完成時的暫時緩解措施;更新失敗時的回復程序;控制器停止支援後有哪些升級或隔離方案。最後一點的重要性常被低估:工具機的使用年限通常遠超過控制器工業電腦與作業系統的資安支援期,因此在採購階段就掌握終止支援日期,是資產規劃的一部分,而不是細節。「永遠不更新」與「未經測試立即更新」,都不是成熟的 OT 維護策略。
지원 기간을 먼저 확인하십시오: 공급사에 취약점 제보의 접수·처리 방식, 보안 공지나 CVE 정보 제공 여부, 소프트웨어·펌웨어·운영체제의 지원 기간, 업데이트 배포 전 호환성 시험 방법, 패치 준비 중 제공되는 임시 완화 조치, 업데이트 실패 시 롤백 절차, 제어기 지원 종료 후의 업그레이드 또는 격리 방안을 설명하도록 요청하십시오. 마지막 항목은 흔히 과소평가됩니다. 공작기계의 사용 연한은 제어기 산업용 PC와 운영체제의 보안 지원 기간을 크게 넘기는 경우가 많으므로, 구매 시점에 지원 종료일을 아는 것은 자산 계획의 일부입니다. "절대 업데이트하지 않는" 방식도, "시험 없이 즉시 업데이트하는" 방식도 성숙한 OT 유지보수 정책은 아닙니다.
💾 7. Backups Held Offline and Actually Tested (可離線保存且實際驗證的備份)
Backing up the NC programs alone is usually not enough. Recovery may also need machine parameters and compensation values, PLC or PMC programs, servo and spindle parameters, tool, work and coordinate data, HMI, industrial-PC and robot settings, vision recipes and communication configuration, and the software licences and installation media. At least one copy should be held offline, isolated from the production network, and restoration should be tested rather than assumed. Real recovery capability is not "we have backup files" — it is "we have demonstrated that production can be restored within an acceptable time". Agree at order stage which of these items the supplier will hand over, in what format, and whether a licence can be reissued if the original controller board is replaced.
只備份 NC 程式通常不夠:復原可能還需要機台參數與補償值、PLC/PMC 程式、伺服與主軸參數、刀具與工件座標資料、HMI/工業電腦/機器人設定、視覺配方與通訊設定,以及軟體授權與安裝媒體。備份至少應有一份離線保存、與生產網路隔離,並且要實際測試能否還原,而不是假設可以。真正的復原能力,不是「有備份檔」,而是「曾經驗證可以在可接受的時間內恢復生產」。建議在下單階段就談定:上述項目中供應商會交付哪些、以什麼格式交付,以及若原控制器板卡更換,授權能否重新核發。
NC 프로그램만 백업하는 것으로는 부족합니다: 복구에는 기계 파라미터와 보정값, PLC·PMC 프로그램, 서보 및 주축 파라미터, 공구·워크·좌표 데이터, HMI·산업용 PC·로봇 설정, 비전 레시피와 통신 설정, 소프트웨어 라이선스와 설치 미디어까지 필요할 수 있습니다. 최소 한 부는 생산 네트워크와 분리해 오프라인으로 보관하고, 복원 가능 여부는 가정이 아니라 실제 시험으로 확인해야 합니다. 진정한 복구 능력은 "백업 파일이 있다"가 아니라 "허용 가능한 시간 안에 생산을 복구할 수 있음을 입증했다"입니다. 위 항목 중 공급사가 무엇을 어떤 형식으로 인도하는지, 제어기 보드를 교체할 경우 라이선스를 재발급할 수 있는지도 발주 단계에서 정하십시오.
📊 8. Event and Audit Logs That Can Be Exported (可匯出的事件與操作紀錄)
At minimum the equipment should record, and allow the export of, successful and failed logins; account and privilege changes; program, parameter and configuration modifications; remote sessions; software and firmware updates; USB and removable-media activity; and critical alarms and controller restarts. Logs that exist only on the machine and can only be read on its own screen are of limited use during an investigation. If they can be forwarded securely to a central platform, unusual access, unauthorised changes and patterns that span several machines become far easier to notice — and the same records support warranty and quality investigations that have nothing to do with security.
紀錄要能匯出,才有調查價值:設備至少應能記錄並匯出:成功與失敗的登入;帳號及權限變更;程式、參數與組態修改;遠端連線;軟體或韌體更新;USB 與外部媒體使用;重要警報與控制器重新啟動。只存在機台內、且只能在機台螢幕上讀取的紀錄,在事件調查時用途有限。若能安全地轉送至集中式日誌平台,異常登入、未授權變更與跨機台的模式就容易得多被發現;同一份紀錄也能支援與資安無關的保固與品質調查。
로그는 내보낼 수 있어야 조사에 쓰입니다: 설비는 최소한 로그인 성공과 실패, 계정 및 권한 변경, 프로그램·파라미터·설정 변경, 원격 접속, 소프트웨어와 펌웨어 업데이트, USB 및 이동식 매체 사용, 주요 알람과 제어기 재시작을 기록하고 내보낼 수 있어야 합니다. 장비 안에만 남고 장비 화면에서만 볼 수 있는 로그는 사고 조사에서 활용도가 낮습니다. 중앙 로그 플랫폼으로 안전하게 전달할 수 있으면 비정상 접속, 무단 변경, 여러 장비에 걸친 패턴을 훨씬 쉽게 발견할 수 있고, 같은 기록이 보안과 무관한 보증·품질 조사에도 도움이 됩니다.
🛡️ 9. Security That Does Not Undermine Machine Safety (不破壞安全功能的資安設計)
Cybersecurity controls must not interfere with emergency stops, door interlocks, collision protection or other safety functions, and the failure of a network appliance, identity service or log server must not put the machine into an unsafe state. Ask the supplier to explain how the machine behaves during a network outage; whether a remote session can override local safety conditions; what the fail-safe state is when a security component fails; how safety and machining functions are re-verified after an update; and which controls must remain locally available regardless of network status. Safety and security are usually complementary, but where they interact, safety governs — and that interaction is a design question, not something to resolve on the shop floor.
資安不能妨礙機械安全:資安控制不應干擾緊急停止、安全門連鎖、碰撞防護或其他安全功能;當網路設備、身分驗證系統或日誌伺服器失效時,機台也不應進入危險狀態。請供應商說明:網路中斷時機台如何運作;遠端連線能否繞過現場安全條件;資安元件故障時的安全狀態(fail-safe)為何;更新後如何重新驗證安全與加工功能;哪些控制必須不依賴網路而保留在本地端。安全(Safety)與資安(Security)多數時候互補,但兩者互相牽動時應以機械安全為優先——而且這是設計階段的問題,不該留到現場處理。
보안이 기계 안전을 훼손해서는 안 됩니다: 사이버 보안 통제가 비상 정지, 도어 인터록, 충돌 방지 등 안전 기능을 방해해서는 안 되며, 네트워크 장비·인증 서비스·로그 서버의 장애가 장비를 위험한 상태로 만들어서도 안 됩니다. 네트워크 장애 시 장비의 동작, 원격 접속이 현장 안전 조건을 우회할 수 있는지 여부, 보안 구성요소 고장 시의 페일세이프 상태, 업데이트 후 안전 및 가공 기능의 재검증 방법, 네트워크 상태와 무관하게 현장에 남아 있어야 하는 제어 기능을 공급사에 확인하십시오. 안전과 보안은 대개 상호 보완적이지만, 서로 충돌할 때는 기계 안전이 우선하며 이는 현장이 아니라 설계 단계에서 정리되어야 합니다.
🗑️ 10. Decommissioning and Data Removal (退役與資料清除機制)
Before resale, lease return, controller replacement or scrapping, a CNC may still hold customer drawings, NC programs, network settings, accounts and access credentials. The purchase contract should establish where storage media are located and of what type; whether data can be securely exported and erased; how disks or controller boards replaced during service are handled; whether the supplier will provide a record of data destruction; and how cloud accounts and remote-service credentials are revoked. The service case is the one most often missed — a controller board swapped out under warranty leaves the plant with the previous owner’s data still on it unless someone specified otherwise.
最容易被忽略的是「維修換下來的那塊板子」:CNC 在轉售、租賃歸還、控制器更換或報廢前,可能仍保存客戶圖面、NC 程式、網路設定、帳號與存取憑證。採購合約應先確認:儲存媒體的位置與類型;資料能否安全匯出及清除;維修更換下來的硬碟或控制器板卡如何處理;供應商是否提供資料清除證明;雲端帳號與遠端維修憑證如何撤銷。其中維修情境最常被遺漏——保固期內換下的控制器板卡,若沒有事先約定,往往帶著前一位使用者的資料離開工廠。
가장 자주 놓치는 것은 "교체해 나간 보드"입니다: 재판매, 리스 반납, 제어기 교체, 폐기 전에도 CNC에는 고객 도면, NC 프로그램, 네트워크 설정, 계정과 접속 자격 증명이 남아 있을 수 있습니다. 구매 계약에는 저장 매체의 위치와 종류, 데이터의 안전한 내보내기와 삭제 가능 여부, 서비스 중 교체된 디스크나 제어기 보드의 처리 방법, 데이터 파기 증빙 제공 여부, 클라우드 계정과 원격 유지보수 자격 증명의 폐기 방법을 규정해야 합니다. 특히 서비스 상황이 자주 누락됩니다. 보증 기간에 교체된 제어기 보드는 사전에 정해 두지 않으면 이전 사용자의 데이터를 그대로 담은 채 공장을 떠납니다.
📜 Reading IEC 62443 Correctly (如何正確看待 IEC 62443)
IEC 62443 is a series of standards for industrial automation and control systems, not a single certificate that covers every security capability. The parts most often relevant to a machine purchase are IEC 62443-2-4 (security programme requirements for IACS service providers), IEC 62443-3-3 (system security requirements and security levels), IEC 62443-4-1 (secure product development lifecycle requirements) and IEC 62443-4-2 (technical security requirements for IACS components). So the useful question is not "are you IEC 62443 compliant?" but which part and edition applies, to which product scope, who issued the certificate, and which of those capabilities are actually included in the system being delivered. A certificate held by a component vendor deep in the supply chain does not automatically describe the machine in front of you.
它是一系列標準,不是一張萬用證書:IEC 62443 是針對工業自動化與控制系統的系列標準。採購時較常涉及的分冊包括:IEC 62443-2-4(對 IACS 服務提供者的安全方案要求)、IEC 62443-3-3(系統安全需求與安全等級)、IEC 62443-4-1(產品安全開發生命週期要求)、IEC 62443-4-2(IACS 元件的技術安全要求)。因此真正有用的問法不是「你們符合 IEC 62443 嗎」,而是:適用哪一分冊與版本、涵蓋哪些產品範圍、由哪個機構核發、以及其中哪些能力真正包含在這次交付的系統中。供應鏈上游某個元件廠商持有的證書,並不自動代表眼前這台機器的能力。
단일 인증서가 아니라 표준 시리즈입니다: IEC 62443은 산업 자동화 및 제어 시스템을 위한 표준 시리즈이며, 모든 보안 능력을 한 장으로 증명하는 인증서가 아닙니다. 장비 구매와 자주 관련되는 부분은 IEC 62443-2-4(IACS 서비스 제공자의 보안 프로그램 요구사항), IEC 62443-3-3(시스템 보안 요구사항과 보안 수준), IEC 62443-4-1(제품 보안 개발 생명주기 요구사항), IEC 62443-4-2(IACS 구성요소의 기술적 보안 요구사항)입니다. 따라서 유용한 질문은 "IEC 62443을 준수합니까?"가 아니라 어떤 파트와 판이 어떤 제품 범위에 적용되는지, 인증기관은 어디인지, 그 능력 중 실제 납품 시스템에 포함된 것은 무엇인지입니다. 공급망 상류의 부품 업체가 보유한 인증서가 눈앞의 장비를 그대로 설명해 주지는 않습니다.
✅ Questions to Put Straight into the RFQ / URS
Assets and network: 1. Provide an inventory of hardware, software, firmware, operating systems and network interfaces. 2. List every port, protocol, source, destination and data flow required for normal operation. 3. Can unused communication services and physical interfaces be disabled?
Accounts and remote access: 4. Does the equipment support unique accounts, role-based permissions, password policy and audit logs? 5. Does remote service use an encrypted channel, MFA, per-session approval and time-limited accounts? 6. Can the plant terminate a remote session immediately? 7. Which machines, files and functions can a remote engineer reach?
Updates and support: 8. How are vulnerability advisories, security updates and interim mitigations communicated? 9. What are the security-support and end-of-support dates? 10. Are CNC, PLC, servo, robot and safety functions tested for compatibility before an update is released?
Recovery and records: 11. Which parameters, programs, licences and settings can be backed up and restored? 12. Is a documented and actually tested recovery procedure supplied? 13. Which events can be logged, and can they be exported to a central logging system? 14. How are USB, DNC, shared folders and NC program transfers controlled?
End of life and evidence: 15. How is customer data securely erased on controller replacement or decommissioning? 16. Can you provide evidence of IEC 62443 development process, product capability or certification — stating the exact part, edition, scope and certification body?
資產與網路:1. 請提供完整的硬體、軟體、韌體、作業系統與網路介面清單。2. 請列出設備正常運作所需的所有連接埠、協定、來源、目的地與資料流向。3. 未使用的通訊服務與實體介面是否可以停用?
帳號與遠端存取:4. 設備是否支援唯一帳號、角色權限、密碼政策與稽核紀錄?5. 遠端維修是否使用加密通道、MFA、逐次核准與限時帳號?6. 工廠是否能立即中止遠端連線?7. 遠端工程師可以存取哪些設備、檔案與功能?
更新與支援:8. 供應商如何發布漏洞公告、安全更新與暫時緩解措施?9. 產品的安全支援期限與停止支援日期為何?10. 更新發布前是否測試 CNC、PLC、伺服、機器人與安全功能的相容性?
復原與紀錄:11. 可備份及還原哪些參數、程式、授權與設定?12. 是否提供完整書面且實際測試過的復原程序?13. 設備可產生哪些事件紀錄?能否匯出至集中式日誌系統?14. USB、DNC、共享資料夾與 NC 程式傳輸如何受到管制?
退役與佐證:15. 設備退役或控制器更換時,如何安全清除客戶資料?16. 是否能提供 IEC 62443 相關開發流程、產品能力或認證證據?請註明具體分冊、版本、適用範圍與證書核發單位。
자산과 네트워크: 1. 하드웨어·소프트웨어·펌웨어·운영체제·네트워크 인터페이스 목록을 제공해 주십시오. 2. 정상 운전에 필요한 모든 포트·프로토콜·출발지·목적지·데이터 흐름을 명시해 주십시오. 3. 미사용 통신 서비스와 물리적 인터페이스를 비활성화할 수 있습니까?
계정과 원격 접속: 4. 개별 계정, 역할 권한, 비밀번호 정책, 감사 로그를 지원합니까? 5. 원격 유지보수에 암호화 통신, MFA, 건별 승인, 시간 제한 계정을 적용합니까? 6. 공장에서 원격 접속을 즉시 차단할 수 있습니까? 7. 원격 엔지니어가 접근할 수 있는 장비·파일·기능의 범위는 무엇입니까?
업데이트와 지원: 8. 취약점 공지, 보안 업데이트, 임시 완화 조치는 어떻게 전달합니까? 9. 보안 지원 기간과 지원 종료일은 언제입니까? 10. 업데이트 배포 전에 CNC·PLC·서보·로봇·안전 기능의 호환성을 시험합니까?
복구와 기록: 11. 어떤 파라미터·프로그램·라이선스·설정을 백업하고 복구할 수 있습니까? 12. 문서화되고 실제로 시험된 복구 절차를 제공합니까? 13. 어떤 이벤트를 기록하며 중앙 로그 시스템으로 내보낼 수 있습니까? 14. USB·DNC·공유 폴더·NC 프로그램 전송을 어떻게 통제합니까?
폐기와 증빙: 15. 제어기 교체 또는 설비 폐기 시 고객 데이터를 어떻게 안전하게 삭제합니까? 16. IEC 62443 관련 개발 절차, 제품 기능, 인증 증빙을 제공할 수 있습니까? 해당 파트·판·적용 범위·인증기관을 명시해 주십시오.
🎯 Conclusion: Settle the Security Specification Before the Purchase Order (結論:資安規格要在下單前確認)
A machine tool may stay in service for more than ten years, while the security lifecycle of its controller operating system, remote-service software and network components is often considerably shorter. If accounts, logging, backups and segmentation are first discussed after the machine is installed, improvement usually costs more and may be limited by the controller architecture that was already chosen. A mature CNC procurement establishes not only whether the machine can produce acceptable parts, but also: who can connect, what each user is allowed to do, whether critical activity can be traced, how vulnerabilities will be handled safely, whether production can be restored reliably, and whether sensitive data can be removed at end of life. Connectivity is not the problem. Connectivity without boundaries, accountability and recovery is. Writing OT security requirements into the RFQ, URS and acceptance documents remains the cheapest point at which to control that risk — before the machine reaches the factory.
萬洋國際的觀察:工具機的使用壽命可能超過十年,但控制器作業系統、遠端維修軟體與網路元件的資安生命週期往往短得多。如果直到設備安裝後才討論帳號、日誌、備份與網路隔離,改善成本通常更高,也可能受限於當初選定的控制器架構。成熟的 CNC 採購,不只確認機台能不能加工出合格零件,也會確認:誰可以連線、每個使用者能做哪些操作、重要操作能否追蹤、發現漏洞後如何安全處理、系統受損後能否可靠復原,以及設備生命週期結束後資料能否安全移除。連網不是問題;缺乏邊界、權責與復原能力的連網,才是問題。把 OT 資安要求寫進 RFQ、URS 與驗收文件,仍是在機台進廠之前成本最低的風險控制方式。
Z&Z STROTEC의 관점: 공작기계는 10년 이상 사용될 수 있지만, 제어기 운영체제·원격 유지보수 소프트웨어·네트워크 구성요소의 보안 수명은 그보다 훨씬 짧은 경우가 많습니다. 설치가 끝난 뒤에야 계정·로그·백업·망 분리를 논의하면 개선 비용이 커지고, 이미 선택된 제어기 구조 때문에 구현이 제한될 수도 있습니다. 성숙한 CNC 구매는 장비가 합격 부품을 만들 수 있는지뿐 아니라 누가 접속할 수 있는지, 각 사용자가 무엇을 할 수 있는지, 중요한 작업을 추적할 수 있는지, 취약점을 어떻게 안전하게 처리할 것인지, 시스템 손상 후 신뢰성 있게 복구할 수 있는지, 수명 종료 후 민감한 데이터를 제거할 수 있는지를 함께 확정합니다. 연결 자체가 문제는 아닙니다. 경계와 책임 추적, 복구 능력이 없는 연결이 문제입니다. OT 보안 요구사항을 RFQ·URS·검수 문서에 기재하는 것은 장비가 공장에 들어오기 전에 위험을 통제하는 가장 저렴한 방법입니다.
This article provides general technical and procurement information. It does not replace a site-specific cybersecurity risk assessment, functional-safety validation, contract review or legal advice. / 本文提供一般性技術與採購資訊,不取代個別工廠的資安風險評估、功能安全驗證、合約審查或法律意見。/ 본문은 일반적인 기술·구매 정보를 제공하며, 개별 사업장의 사이버 보안 위험 평가, 기능 안전 검증, 계약 검토, 법률 자문을 대체하지 않습니다.
Need These Requirements in Your Next Machine Specification?
Z&Z STROTEC helps overseas buyers of Taiwanese machine tools put network, account, remote-service and recovery requirements into the RFQ and acceptance documents — and confirms with the manufacturer what the delivered machine actually supports.
Z&Z STROTEC