Glossary · Automation fundamentals, platforms and components
SIEM for OT
Also known as: OT SIEM, Security information and event management for OT
German: SIEM für OT
In industrial cybersecurity, SIEM for OT is the use of security information and event management systems to collect, correlate and analyze security-relevant events from operational technology, such as controllers, HMIs, firewalls, switches and OT intrusion detection sensors, together with IT events.
- Automation components
- OT security
In one sentence
SIEM for OT collects and correlates security events from controllers, HMIs, firewalls and OT sensors to detect attacks and misuse in plants.
Example
The SIEM raises an alert when a PLC program download occurs outside the maintenance window from an engineering station that is not registered.
How it applies
- Engineering: OT devices often lack standard logging, so passive network monitoring sensors and logs from firewalls, jump hosts and engineering stations are key sources. Logging must not disturb real-time traffic.
- Operation: Use cases for OT include unexpected program changes, new devices, unusual protocol commands and Remote access outside agreed times. Alerts need responders who understand the process.
- Documentation: Security documentation should describe which events are logged, retention times and the response process. Accurate Time synchronization across devices is a prerequisite for correlating events. Device manuals should state which security events a product can log and how to forward them.
A SIEM detects and supports response; it does not by itself make a plant secure or compliant with IEC 62443.