Emerson’s Security Approach to NI Product Development

Overview

Emerson is committed to rigorous security practices in the development of NI products, ensuring both compliance and trust for customers and industry stakeholders. The company integrates security principles throughout its software engineering processes, prioritizing risk management and regulatory adherence.

 

The purpose of this document is to provide information about the Emerson Test & Measurement (Emerson T&M) approach to information and security throughout the product development lifecycle.

Contents

Emerson Information Security

As a business division of Emerson, Emerson T&M benefits from the global policies of Emerson. Emerson manages a global IT team and provides IT services for Emerson T&M employees. NI Product development is done by Emerson T&M and is separate from other Emerson divisions.

Information at Emerson T&M is protected by the policies and technologies deployed by the Emerson IT team. These policies comply with the European Union (EU) Data Protection Directive through Emerson’s Global Data Protection Program. This requires all Emerson businesses, wherever located, to adhere to the European General Data Protection Regulation (GDPR). The Emerson Global Data Protection Program has also expanded to support additional legislation such as the California Consumer Privacy Act (CCPA), the Brazilian General Data Protection Law, and the India Data Privacy Bill.

Emerson maintains a comprehensive information security program, which includes policies, standards, procedures and guidelines. The information security program is informed by several industry-standard guidelines and best practices including ISO27001, NIST CSF, and DFARS.

Emerson’s IT leadership meets on a regular basis to consider strategic and tactical direction for the information security program, and its policies, standards, procedures and guidelines. Emerson’s Chief Information Security Officer (CISO) oversees Emerson’s Cybersecurity program.

Emerson’s risk management program monitors for possible threats and vulnerabilities to information technology assets. Risk assessments are performed regularly and when there are significant changes to infrastructure, technology, or other factors.

To help customers and suppliers understand Emerson’s security posture, Emerson certifies the information security program through ISO 27001. This certification specifies the requirements for establishing, implementing, maintaining, and continually improving Emerson’s information security program. Emerson’s Global Data Center and Regional Data Centers are ISO 27001 certified. For more information regarding Emerson's ISO 27001 certified locations, please contact us.

An independent external entity assesses the maturity of Emerson’s cybersecurity program regularly and measures program maturity against industry peers and industry standards such as NIST Cybersecurity Framework and other common frameworks. The security team discusses recommendations with executive leadership and the board of directors.

Emerson performs penetration tests of internal and external network infrastructure as well as connected products on ad hoc basis using dedicated internal staff specially trained and experienced in industry standard penetration test scopes and methods. In addition to the continuous efforts of Emerson’s vulnerability management team conducting penetration testing, Emerson engages in regular external penetration exercises using an industry-leading third-party. Results are reviewed by the Information Security organization and action is taken based on risks identified.

All Emerson employees are required to complete an information security training that covers end-user security risks. Emerson’s security awareness training includes subjects such as Emerson’s security policy, data classification and handling, workspace and desktop security, network security (VPN), password security, phishing, malware, file sharing, clean desk, and insider threat. In addition to awareness training, Emerson also actively tests (e.g. mock-phishing) employees to maintain end user diligence.

Emerson has a data classification policy in place. Data is classified into four categories: Public, Internal Use Only, Confidential, and Restricted. These classifications are based on the value and risk factors of the information. Security handling and control standards have been defined for information in each of the categories. These security precautions are defined for electronic files and information (at rest and in motion) and hard copies for each stage of the data management lifecycle.

Emerson’s Legal & Compliance teams monitor and review relevant regulatory developments within their world regions or jurisdictions. Internal reviews include an assessment of the impact of regulatory developments and necessary compliance actions. Further reporting is done on these developments on a risk-based approach using existing risk management processes and structures. Emerson is committed to complying with data privacy regulations (e.g. the General Data Privacy Regulation and others) and is protecting customers, employees, and Emerson information.

Access to accounts with elevated privileges is restricted to authorized employees who require such access to perform their job functions. Server administrators have an administrative (admin) account that is separate from their normal user accounts. Admin accounts are centrally managed via Emerson Corporate IT’s Privilege Access Management (PAM) solution. Access to the PAM requires multi-factor authentication. The privileged account credentials managed in PAM are routinely randomized. Admin accounts are reviewed quarterly.

A dedicated vulnerability management team tests Emerson’s internal network regularly and external facing system hosted within Emerson data centers regularly and as-needed. Vendor and industry-accepted alert lists are monitored for new patches. Patches are reviewed at regularly scheduled meetings and are rated for deployment based on assessed severity levels. Emergency patch management meetings are called when needed. Security vulnerabilities and emerging threats are tracked by information security personnel, assessed by technical experts, and deployed according to risk priority.

Emerson has dedicated business resiliency and disaster recovery teams that coordinate Emerson’s capability to recover systems using internal or external resources. Solutions are designed to meet requirements defined by impact analyses of system or facility outages. Where appropriate, human or computer workload is distributed among multiple locations to reduce or eliminate downtime due to local outages. Tests are conducted regularly that may include table top exercises, employee/all colleague call list tests, business disruption and relocation tests, and application recovery tests. 

GCC-High Tenant for Sensitive Information

For handling sensitive information, Emerson maintains a US-based GCC-High tenant compliant with CMMC and DFARS 252.204-7012/7019/7020/7021. This environment is designed to meet stringent federal and industry requirements, ensuring secure storage and management of classified or regulated data. Customers with specific needs can engage with Emerson’s security team to coordinate data transfers through this secure environment.

Outside of the US, Emerson maintains similar tenants for communication with sensitive customers with in-country solutions. Contact your local Emerson T&M team for more information about location availability of these information services. 

Emerson Product Development Security

Emerson T&M employees follow a rigorous development process to ensure that NI products meet Emerson’s high quality and security standards. These processes are constantly improved based on customer feedback and evolving regulations. These processes align with the guidance from the US Government in NIST 800-218, Secure Software Development Framework (SSDF). The elements of Emerson T&M’s secure development lifecycle are described below.

Secure by Design

Emerson ensures that security is built into products and systems from the start by following a Secure by Design program. This program ensures security is built into products from the start in a structured way. Product designs start with threat modeling, data flow planning, architecture reviews, and default behavior planning.

Secure Development

Throughout the development process, Emerson engineers follow the secure development practices described below. Emerson’s ISO 9001 process ensures that engineers follow these practices consistently.

Secure Coding Standards—Emerson’s software engineering process (SEP) includes secure coding standards to ensure secure code development. These standards include analysis of third-party and open source components for both security and licensing.

Developer Training—Emerson software engineers are trained in latest security and coding standards. Training opportunities are provided to developers on an ongoing basis.

Independent Code Reviews—Software development includes independent and peer code reviews to ensure that security standards are maintained, and to share best development practices.

Security Governance—The Emerson development process includes security gates, metrics, and issue tracking. The structured program is led by a Product Security Officer and team.

Testing Practices—Security testing is an integral part of Emerson T&M’s development process. Static Application Security Testing (SAST) tools are used to analyze source code for vulnerabilities early in the lifecycle. Additionally, regular vulnerability assessments and penetration tests are conducted to identify and remediate risks before software release. These practices ensure that products meet stringent security standards and provide reliable protection against emerging threats.

SBOMs—Emerson T&M maintains Software Bill of Materials (SBOMs) for all actively developed software. SBOMs provide detailed inventories of software components, enabling transparency and facilitating vulnerability management. This proactive approach supports compliance with regulatory requirements and helps customers assess and address supply chain risks effectively.  SBOMs are scanned for known vulnerabilities using Software Composition Analysis (SCA) tools.

Vulnerability response and coordinated disclosure—Emerson has a reporting process at ni.com/security. Emerson reviews each report for exploitability and impact and responds appropriately with coordinated disclosures and patches. Emerson is a CVE Numbering Authority (CNA) to allow for faster response and more direct coordinated disclosures.

Software Lifecycle Support—Emerson T&M supports software versions throughout their lifecycle by applying versioning strategies and lifecycle management policies. Customers receive updates, patches, and guidance for supported versions, ensuring continued security and operational stability. End-of-life procedures are clearly communicated to help customers plan for transitions and maintain secure environments. Supported versions of software are listed at https://www.ni.com/en/support/software-product-life-cycle-policies.html.

For a complete list of recent product patches, or to subscribe to security bulletins, visit ni.com/security.

ISO 9001 Compliance

Compliance to security and quality processes is reinforced through ISO 9001 certification. Emerson’s adherence to this quality management standard ensures systematic process controls, continuous improvement, and traceability across all development and support activities. This certification demonstrates Emerson’s commitment to delivering reliable and secure products. Emerson’s ISO 9001 certification and other certifications are available at https://www.ni.com/en/about-ni/corporate-quality/certifications.html.

Anti-Counterfeit Program

Emerson T&M’s global procurement program mitigates the risk that counterfeit, fraudulent and suspect items (CFSI) can enter the supply chain. This program complies with SAE AS5553.

Emerson T&M acquires parts only directly from OEMs or their authorized and franchised distributors (the approved supplier list). Emerson T&M requires our suppliers to use only “new and authentic materials” and to sources these directly from the OEM or the approved supplier list.

Suppliers must pass Emerson T&M’s Supplier Assessment Process which includes annual site audits. They must have processes to quality their suppliers and manage a supplier rating system. They must inspect incoming material and provide a detailed inspection report with every shipment. These reports are archived by Emerson T&M.

Procurement and manufacturing employees are trained in the definition and identification of CFSI. When CFSI is identified, it is isolated, processed, and disposed of. Occurrences are reported through ERAI and GIDEP. 

Customer Documentation and Industry Certifications

Emerson T&M provides comprehensive documentation to enable customers to meet industry-specific certification requirements. Resources are accessible at ni.com/security, offering guidance, compliance statements, and support materials. These materials include:

  • Letters of Volatility for hardware, with sanitization procedures
  • Information about Software Bill of Materials
  • Secure configuration guides
  • Secure development guides
  • Anti-counterfeit statements
  • Security compliance documents

These documents empower customers to confidently achieve and maintain regulatory compliance in their own operations.

Conclusion

Emerson’s security approach in NI product development is holistic, structured, and certified to international standards. By embedding security into every stage of the software lifecycle, maintaining transparent documentation, and supporting industry certifications, Emerson delivers products that meet the evolving needs of security professionals and NI customers. This comprehensive strategy ensures that NI products are resilient, trustworthy, and aligned with best practices in software security.

Was this information helpful?

Yes

No