Professional Documents
Culture Documents
Copy of (양식) 사이버침해사고 생산위험도 평가 지표 조사v4 - (협력사명) - KORENG - R2 0800324 1
Copy of (양식) 사이버침해사고 생산위험도 평가 지표 조사v4 - (협력사명) - KORENG - R2 0800324 1
협력사명 작성자 성함
협력사 주소 직위
매출액('22년) 메일 아이디
매출액 기준 통화 휴대폰 번호
▣ 협력사 보안 인프라 보유 현황
종 류 유/무 설 명 현황 상세 설명 평가
PC 백신 PC용 바이러스 백신
서버 백신 서버용 바이러스 백신
이름 이름
서열 품목
서열품목 비중 1 납품하는 부품 중 서열품목의 비중
정보
생산
5-2 자동화시스템에 문제 발생 시 수작업으로 고객사 차종 생산계획을 확보하는데 소요되는 시간
영향도
☞ 자동화 정의 :
자동화 [예시] - 중간 물류 창고/서열장 등 에서 서열시스템 또는 자동화 창고와 같은 전산시스템을 통해
13-1
수준 최종 완성차 조립 라인에 부품 납품
물류/납품
- 전산시스템을 통해 납품차량의 위치 추적 및 고객사 도착 유무 확인
- 전산시스템을 통해 납품차량 배차 관리
Address B-67,68, Sipcot Industrial Park, Irungattukottai, Sriperumbudur Taluk, Kanchipuram, Tamil Nadu - 602105 Designation Asst. Manager
Type Possession Descriptions ( Customer Requirements) Actuals in your Company ( Explains the availability of Customer Requirements in detail) Self Assessment
Firewall YES Network Firewall (including UTM), i.e) fortigate, juniper, CISO ASA, etc. Fortigate 80 F firewall v6.4.15 build2030 (GA) Serial Number - FGT80FTK22022988 - License End on (07/01/2026) Good System in Place ( > 80%)
Worry Free Business Security - Trendmicro Version 10.0 Service Pack 1 Build - 2495 - Server GUID: 7e9487e4-
f0f3-4198-98ed-6dd27cac50b2/Server GUID: 7e9487e4-f0f3-4198-98ed-6dd27cac50b2/ Hot Fix History: Patch
PC Vaccine YES Anti-virus solutions for PCs Good System in Place ( > 80%)
2459, Patch 2472, Patch 2495
License end on - 7/23/2026
Worry Free Business Security - Trendmicro Version 10.0 Service Pack 1 Build - 2495 - Server GUID: 7e9487e4-
f0f3-4198-98ed-6dd27cac50b2/Server GUID: 7e9487e4-f0f3-4198-98ed-6dd27cac50b2/ Hot Fix History: Patch
Server vaccine YES Anti-virus solutions for Servers Good System in Place ( > 80%)
2459, Patch 2472, Patch 2495
License end on
Solutions that restrict access to storage and communication media available on PCs such as USB access restricted by using Antivirus secuirty end point software (Device control) Good System in Place ( > 80%)
Medium control system YES
USB, MTP, Bluetooth, etc.
(i) Blocked web site by Firewall and Antivirus by URL Filtering and Approve blocked URLS
Block harmful sites YES Solutions that block access to harmful websites. Good System in Place ( > 80%)
(Adult,Business,Communication search,General,Internet Security,Lifestyle,Network Bandwidth
NAC By Firewall protection We inspects incoming and outgoing traffic using a set of security rules to identify and block
YES Solutions that restrict access to the internal network of unauthorized equipment. Partially Available (>50%)
(Network Access Cotrol) threats - Firewall model Fortigate 80 F firewall v6.4.15 build2030 (GA) Serial Number - FGT80FTK22022988
DLP
NO Solutions that prevent data leakage or destruction We are not using DLP Not Available
(Data Loss Prevention)
SAC/DAC
NO
Solutions that control and manage access to Server/Data through authentication, We are not using SAC/DAC control Not Available
(Server/Data Access Control) authorization, and auditing mechanisms.
(i) With out admin permission user not able to install any software (ii) .Exe download
Software Whitelisting YES Solutions that prevent the installation or execution of unauthorized software. blocked thorugh firewall policy Partially Available (>50%)
DRM
NO
Solutions that protect copyright of digital content through encryption and access right We are not using any mentioned points Not Available
(Digital Rights Management) management. i.e) MS AIP
Solutions that consolidates and organizes documents from various sources into a single We are not using document cetralization Not Available
Document Centralization NO
centralized location for easy access and management.
IPS
YES
Solutions that monitor network traffic, detect malicious activities or unauthorized access IPS enable default pattern in Firewall Good System in Place ( > 80%)
(Intrusion Prevention System) attemps, and prevent them from compromising the system or network.
Spam Filter YES Solutions that Block spam and malicious mail flowing into the mail server in real-time. Wblock service we are used to control spam and malicious mail flow Partially Available (>50%)
DB Encryption NO Solutions that protect sensitive information stored in databases by encrypting it. Data base encryption software we are not using Not Available
VPN
NO
Solutions that allow users to securely access the company's internal systems from outside We are not using VPN Not Available
(Virtual Private Network) the company.
IAM
NO
Solutions that manage and control access to their resources by defining and enforcing We are not using IAM Not Available
(Identity and Access Management) policies for user authentication, authorization, and permissions.
We are using for End point security solutions which continously monitor all desktop systems from
Solutions that protect network endpoints such as PC, servers, mobile devices, from security Virus/Malware,Spyware,Web reputation Network virus.Antivirus - Worry Free Business Security - Trendmicro
ESS
YES threats by real-time monitoring and collection of security data and automated threat Version 10.0 Service Pack 1 Build - 2495/Server GUID: 7e9487e4-f0f3-4198-98ed-6dd27cac50b2/Server GUID: Partially Available (>50%)
(Endpoint Security Solutions)
response mechanisms. i.e) EDR, XDR, NDR etc. 7e9487e4-f0f3-4198-98ed-6dd27cac50b2/ Hot Fix History: Patch 2459, Patch 2472, Patch 2495
License end on - 7/23/2026
Solutions that detect, analyze, and respond to security incidents and threats in real-time. i.e) We are not using secuirty operation response Not Available
Security Operation and Response NO
SIEM, SOAR etc.
★ Please fill it out with all working-level personnel in the relevant area (Sales/Production/Logistics/Procurement/IT/Security).
Classification Investigation items No Description and Writing Guide Answer column References
General items Stock securing level of general A duration during which delivery to HMC/KIA is possible only with inventory when production line is discontinued. 1Day~less than
Information items 4 ☞ Please answer based on the items with the minimum inventory among general items other than sequenced items. 2Days
Automation level ★ Please refer to the right image to identify the work stage corresponding to each question Briefly Explain
★ When answering the "Production Impact", please answer based on the items with the lowest level of inventory.
The proportion of automation in the process of acquiring a model production plan from a customer
☞ Select the ratio of the number of items automated to acquire the vehicle production plan among
the total number of items delivered to the customer company
[EXAMPLE] - In the case of automation for passenger cars and manual production plans for commercial
vehicles, Select the proportion of the number of passenger items out of the total number
Automation of items. None(100% (i) Sequence data Download from HMI portal https://hvn.hmil.net/irj/portal ( Enquire production status R/P H)
5-1 Level ☞ Definition of automation : Acquire vehicle production plan or part sequence information provided by manual) (ii) Convert the sequence data to excel format to create NVH Format
Acquiring production plan for the customer through the computer system (iii) Printout the sequence sheet and hand over to production for part loading
customer model [EXAMPLE] - Acquire customer's vehicle model production plan through a direct sequence system
provided by the customer company
- Acquire customer model production plan through self-developed program.
☞ Only downloading production plans and sequence information from websites provided by customers,
such as partner sites (VAATZ), is not considered automation.
Production The time required to secure the production plan of the customer's vehicle model manually when a problem N/A(No
5-2 Impact occurs in the automation system Automation) No Impact on production plan as it done in excel through mail
The proportion of automation in the process of establishing a part production plan (daily work plan) from
the model production plan provided by the customer. (i) Received plan from PPC team through mail and hardcopy to start production
☞ Select the ratio of the number of items automated for production planning out of the total number (ii) After part production the final inspection done then from PBS (Production Bar Code) system (Production barcode system) we take alc print
of items and past on part and move to FG location
6-1 Automation ☞ Definition of automation : Calculate and manage work plans through the computer system Less than 20% (iii) EOL inspection stage sub parts available confirmation by File safe JIG.
Level [EXAMPLE] - Manage customer's vehicle production plan through a computer system such as ERP ( Automated System avilable in Covering shelf line only )
Establishing Production plan - The daily or hourly part production plan is automatically calculated according to the rules (iv) After part move to FG area we received plan form HMI through SAP by Logistics then PDI inspection by Manual.
programmed in the computer system (v) After PDI inspection done the part moved to despacth area.
☞ If a part production plan is established using office SW such as Excel, it is not considered as
automation.
Production The time required to manually establish a part production plan (daily work plan) when a problem occurs in
6-2 Impact the automation system Less than 1Hour 1 hour required to stable the process
The proportion of automation in the process of establishing the shipping/delivery plan of the product
☞ Select the ratio of the number of items automated for logistics planning among the total number of
items (i) We download sub daily and timely plan form HMI SAP Portal https://hvn.hmil.net/irj/portal
☞ Definition of automation : Establish and manage part transportation/delivery work plan (ii) Convert the plan data to excel format to create NVH Format
through the computer system
7-1 Automation [EXAMPLE] - Manage part transportation/delivery plans through a computer system such as ERP None(100% (iii)Based on pending quantity we gave plan to production for delivery
Level - The computer system automatically calculates part shipment/delivery plan according to manual) (iv)Monthly PO download from HMI portal and upload in SMS mapol software for Invoice process
Establishing logistics plan programmed rules (v) As per given plan to raise the invoice to HMI through SMS mapol software after vechile updatation,E-invoice creation,Push to HMI port
- Share the parts transportation/delivery plan to the supplier in charge of logistics through and ASN creation automatically in HMI portal. (vi)
the computer system Interface with HMI autogate entry confirmation
☞ If part transportation/delivery plan is established using office SW such as Excel, it is not considered
as automation.
Production The time required to manually establish a shipping/delivery plan when a problem occurs in the automation
7-2 Impact system Less than 1Hour 1 hour required to stable the process
_x000D_# 본 문서는 현대자동차·기아의 정보자산으로 귀사와의 비밀유지계약 및 제반법률에 따라 법적 보호를 받습니다._x000D_ 본 문서는 현대자동차·기아의 정보자산으로 귀사와의 비밀유지계약 및 제반법률에 따라 법적 보호를 받습니다.
#
▣ Investigation for the production impact of cybersecurity incident ★ Please be fully familiar with the writing guide and fill it out without any blanks.
★ Please fill it out with all working-level personnel in the relevant area (Sales/Production/Logistics/Procurement/IT/Security).
Classification Investigation items No Description and Writing Guide Answer column References
General items Stock securing level of general A duration during which delivery to HMC/KIA is possible only with inventory when production line is discontinued. 1Day~less than
Information items 4 ☞ Please answer based on the items with the minimum inventory among general items other than sequenced items. 2Days
The proportion of automation in the process of establishing a material procurement plan for parts
production
☞ Select the ratio of the number of items automated for material delivery planning among the total (i) We are receiving HMI FG Part plan from our PPC Team(Excel),After receiving PPC FG parts Plan we convert into Raw Material plan in excel
number of items through (BOM-Bill of Material - Tims LIMS ERP)
Automation ☞ Definition of automation: Establish and manage material delivery plans through the computer system (ii) Based on Raw material plan we will send Daily,Weekly & Monthly schedules to supplier
8-1 Level [Example] - Manage material delivery plan through computer system such as ERP Less than 20% (iii) Based on Raw material plan we will prepare Purchase Orders through(TIMS-LIMS ERP) &
Establishing material - Material delivery plan is automatically calculated according to the rules programmed
procurement plan communicate to supplier through mail
in the computer system (iv) Day by Day delivery schedule updated in (TIMS-LIMS ERP) for all suppliers
- Sharing material delivery plan to material suppliers through the computer system
☞ If a material procurement plan is established using office SW such as Excel, it is not considered
as automation.
Production The time required to establish a material procurement plan manually when a problem occurs in the
8-2 Impact map automation system Less than 1Hour NO Imapact automation process , we will manually commucated with excel data.
The proportion of automation in the process in which the part production plan (daily work plan) is delivered
to the workers operating the production facility
☞ Select the ratio of the number of items whose production plan informing process is automated out of the
total number of items
☞ Definition of automation: The worker of the production line checks the amount of work through the
computer system (i)Customer Receive from HMI portal ( Display Sub Daily Requirement screen) - SAP system
[EXAMPLE] - The production plan is managed in the production information system such as ERP, MES, (ii)HMI Plan Download in Excel format
9-1 Automation etc., and the workers check the amount of work through the PC or status display 20%~less than 50% (iii)To compare HMIplan wise stock status of NVH india, Based on stock coverage, Plan for MIP plan Through Excel format
Level equipment placed at the production line. (iv)Plan has Upload in ERP Programme Software
Informing production plan (v)Work order ( Operation plan Priorities) data through ERP system
- The workers check the production plan through the in-house communication system
such as a groupware bulletin board and a in-house mail system using PCs or mobile (vi)ERP data interface with PBS system
devices placed at the production line.
☞ If the workers check the production plan through printouts or commercial communication medias
such as external mail, SNS, etc., it is not regarded as automation.
Production The time required to manually deliver the part production plan to the production line workers when a
9-2 Impact problem occurs in the automation system Less than 1Hour If system problem appear immeditely plan at Excel
10-2 Production The time required to manually switch to restart the production facility when a problem occurs in the Less than 1Hour 1 hour required to stable the process
Impact automation system
Production The time required to manually switch to restart the production facility when a problem occurs in the
11-2 Impact automation system
_x000D_# 본 문서는 현대자동차·기아의 정보자산으로 귀사와의 비밀유지계약 및 제반법률에 따라 법적 보호를 받습니다._x000D_ 본 문서는 현대자동차·기아의 정보자산으로 귀사와의 비밀유지계약 및 제반법률에 따라 법적 보호를 받습니다.
#
▣ Investigation for the production impact of cybersecurity incident ★ Please be fully familiar with the writing guide and fill it out without any blanks.
★ Please fill it out with all working-level personnel in the relevant area (Sales/Production/Logistics/Procurement/IT/Security).
Classification Investigation items No Description and Writing Guide Answer column References
General items Stock securing level of general A duration during which delivery to HMC/KIA is possible only with inventory when production line is discontinued. 1Day~less than
Information items 4 ☞ Please answer based on the items with the minimum inventory among general items other than sequenced items. 2Days
12-2 Production The time required to manually switch to re-ship parts when a problem occurs in the automation system Less than 1Hour 1 hour required to stable the process
Impact map
The proportion of automation in the process of delivery from shipment of parts to supply to the assembly line
of the customer's finished car production factory
☞ Select the ratio of the number of items automated in the logistics/delivery process among the total number
of items
☞ Definition of automation:
[EXAMPLE] - In the process of transporting parts, parts are supplied to the final finished vehicle
Automation assembly line through a computer system such as a sequence system or an automated (i)Refer 12.1
13-1 Level warehouse at the middle point such as an intermediate logistics warehouse or sequence 20%~less than 50% (ii) Delviery truck status to check in HMI portal LP truck in /out truck monitoring and Display receipt status (H) (iii)
Logistics/Delivery center. Wheels I software used to track live vehicles status
- Track the location of delivery vehicles and check the arrival of the parts to customer
through the computer system
- Manage distribution or dispatch of delivery vehicles through the computer system
☞ If the process of transporting/delivering parts is carried out without the intervention of the computer system
or automation facilities, it is not considered as automation
Production The time required to manually switch to transport/deliver parts when a problem occurs in the automation
13-2 Impact system Less than 1Hour 1 hour required to stable the process
_x000D_# 본 문서는 현대자동차·기아의 정보자산으로 귀사와의 비밀유지계약 및 제반법률에 따라 법적 보호를 받습니다._x000D_ 본 문서는 현대자동차·기아의 정보자산으로 귀사와의 비밀유지계약 및 제반법률에 따라 법적 보호를 받습니다.
#
Checked by IT Head of Approved By
Director
Manager Department MD/EFO
Name Name