Cyber security
Product manual 2TMD042000D0042
│
39
10.3
Deployment guideline
All devices need to work in security mode by default. All devices on one system shall be signed
by a public CA at commissioning stage; normally the management software acts as the CA.
It’s suggested that compatible mode is only used when the device needs to communicate with
previous generation products. In this mode, data transmission between devices are not
encrypted, it may lead to data leaks and has the risk of being attacked.
When the user decides to remove the device from the system, the user shall reset the device to
the factory settings to remove all the configuration data and sensitive data on the device. This
will prevent sensitive data leak.
It is recommended to apply "MAC filter" and "Rate limiter" in the switch to prevent DOS attacks.
10.4
Upgrading
The device supports firmware updates via management software.
10.5
Backup/Restore
None.
10.6
Malware prevention solution
The H81402FR-. device is not susceptible to malware, because custom code cannot be
executed on the system. The only way to update the software is via firmware upgrades. Only
firmware signed by ABB can be accepted.
10.7
Password rule
The user must change the engineering password when accessing the engineering settings for
the first time. This engineering password must not include continuously increasing or
decreasing numbers (e.g. 12345678, 98765432), and three consecutive identical numbers are
similarly not permitted (e.g. 123444, 666888).