2101510MNA H | NGC82 00 AN D P GC 1000 US ER MA NUA L |
85
Table 9-1: Security guidelines
Recommendation
Description
Secure physical access
to the device
Control access to the device, its internal components, and connected
peripherals.
Secure access with
security switch
Turn the onboard security switch on to enforce authentication through bi-level
security codes or RBAC. See section
9.1.
Configure bi-level
security codes
Change default security codes to private codes (the default security code for
both level 1 and level 2 is 0000). See section
Enable Role-Based
Access Control (RBAC)
Configure RBAC if tighter control is required: define user accounts, and
specific privileges. See section
9.2 Configure Role Base Access Control
. When you enable role-based access, you can also enable
authentication for each of the communication ports.
Change the default RBAC passwords and security codes.
Secure network
connection
The device only connects to a firewall-protected private network. Do not
connect directly to the Internet.
Manage credentials
Store all private credentials, keys, and security codes in safe locations. Share
private credentials, keys, and security codes only with properly trained and
authorized personnel.
Change or update private credentials, keys, and security codes as needed.
9.1
Configure bi-level security
This procedure enables security with the hardware security switch and the configuration of bi-level
security access for PCCU32. When analyzer security is configured in this way, security codes are
required for connection to the device with PCCU32.
describes the two levels of security for
this method. Each level requires the configuration of a security code.
Table 9-2: Bi-level security
Security level
Access
Description
Level 1
Read only
View access: Ability to view data or monitor device operation
Level 2
Read and write
Full access: Ability to configure, upgrade, add applications, etc.
Local communication using USB is required for this procedure. The security switch must be set to the
UNSECURE position (flip switch
up
,
) before configuration. Do not forget to flip the switch
down
after configuring the security code.
Figure 9-1: Disable security on terminal board (switch UP)
IMPORTANT NOTE:
After this procedure is completed, connection to the analyzer will be
restricted to users with the correct security codes. Take note of the configured codes.
This procedure requires access to the internal analyzer’s termination board to be able to change the
position of the security switch. Be sure to take the safety precautions required for your site to
remove the cover and access the board.
WARNING – Bodily injury
. Do not open or remove covers unless the area, including the
internal volume of the enclosure, is known to be non-hazardous.