After three consecutive failed login attempts the user will be locked
out for ten minutes before a new attempt to log in can be
performed. This time is settable 10 minutes to 60 minutes.
The PCM600 tool caches the login credentials after successful login
for 15 minutes. During that time no more login will be necessary.
4.2
Predefined user roles
GUID-41C5DF7D-BE92-476D-B3A9-646238A7CD6A v1.1.1
There are different roles of users that can access or operate different areas of the
IED and tool functionalities.
Ensure that the user logged on to the IED has the required access
when writing particular data to the IED from PCM600. For more
information about setting user access rights, see the PCM600
documentation.
The meaning of the legends used in the table:
•
X= Full access rights
•
R= Only reading rights
•
- = No access rights
Table 4:
Predefined user roles
Access rights
VIEWER
OPERATOR ENGINEER INSTALLER SECADM
SECAUD
RBACMNT
Config – Basic
-
-
X
X
-
-
-
Config – Advanced
-
-
X
X
-
-
-
FileTransfer – Tools
-
-
X
X
-
-
-
UserAdministration
-
-
-
-
X
-
X
Setting – Basic
R
-
X
X
-
-
-
Setting – Advanced
R
-
X
X
-
-
-
Control – Basic
-
X
X
-
-
-
-
Control – Advanced
-
X
X
-
-
-
-
IEDCmd – Basic
-
X
X
-
-
-
-
IEDCmd – Advanced
-
-
X
-
-
-
-
FileTransfer – Limited
-
X
X
X
X
X
X
DB Access normal
-
X
X
X
X
X
X
Audit log read
-
-
-
-
-
X
-
Setting – Change Setting Group
-
X
X
X
-
-
-
Security Advanced
-
-
-
-
-
X
-
Section 4
1MRK 511 454-UEN A
Managing user roles and user accounts
14
GMS600 1.3
Cyber security deployment guideline