CPU 410 Process Automation/CPU 410 SMART 
System Manual, 05/2017, A5E31622160-AC 
133 
  Special functions of the CPU 410 
 
Security functions of the CPU 410 
Automation system protection 
The CPU 410 has a range of functions with which you can protect your automation system. 
●  Signed firmware:  
The firmware of the CPU 410 has a signature to detect manipulations on the CPU itself. If 
firmware with errors in its signature is loaded, the CPU 410 rejects the firmware update. 
●  Protection level: 
A number of different protection levels regulate access to the CPU. See Security levels 
(Page 134) 
●  SysLogEvents: 
Security-related changes to the CPU can be sent to one or more SIEM systems as 
SysLogEvent; see Security event logging (Page 136) 
●  Field Interface Security: 
If an interface of the CPU is only used for connecting field devices, access for other 
devices at the interface can be prevented; see Field Interface Security (Page 139) 
●  Support of "Block Privacy": 
Blocks can be encrypted with a password using the STEP 7 "Block Privacy". The CPU 
410 supports this function and can therefore process protected blocks; see Access-
protected blocks (Page 139) 
There are also additional products in the SIMATIC range for increasing the security of your 
automation system. For connection to the plant bus or third-party systems, for example, the 
CP443-1 Advanced can be used to protect communications connections in particular. With a 
combination of different security measures such as firewall, NAT/NAPT router and VPN 
(Virtual Private Network) over IPsec tunnel, the CP443-1 Advanced protects individual 
devices or entire automation cells from unauthorized access. 
You can find additional information about Industrial Security in the introduction in Security 
information (Page 20).