Category
Description
•
Do not connect an unauthorized USB device, CD/DVD or SD
card for any operation (for example, firmware upgrade,
configuration change and boot application change).
•
Before connecting any portable device through USB, CD/
DVD or SD card slot, scan the device for malwares and
viruses.
Authorization and
access control
It is extremely important to securely configure the logical access
mechanisms provided in the UPS to safeguard the device from
unauthorized access. Our company recommends that the
available access control mechanisms be used properly to
ensure that access to the system is restricted to legitimate
users only. And, such users are restricted to only the privilege
levels necessary to complete their job roles/functions.
•
Ensure that default credentials are changed upon first login.
The UPS should not be commissioned for production with
default credentials. It is a serious cybersecurity flaw as the
default credentials are published in the manuals.
•
No password sharing - Make sure that each user gets their
own password for that desired functionality instead of
sharing the passwords. Security monitoring features of the
UPS are created with the view of each user having their own
unique password. Security controls will be weakened as
soon as the users start sharing the password.
•
Restrict administrative privileges - Threat actors are
increasingly focused on gaining control of legitimate
credentials, especially those associated with highly
privileged accounts. Limit privileges to only those needed for
a user’s duties.
•
Perform periodic account maintenance (remove unused
accounts).
•
Change passwords and other system access credentials
whenever there is a personnel change.
Access to service screen and configuration screen is access-
controlled. Access to UPS features is restricted based on roles:
•
Configuration screen can be accessed by the User role.
•
Service screen can be accessed only by the Service
engineer role.
The following are the access levels in the UPS:
•
Level 1: Control password for User
•
Level 2: Configure password for User
•
Level 3: Service password for an authorized Eaton
Customer Service Engineer or qualified service personnel
authorized by Eaton
Users are recommended to change default passwords on first
use of the system. The default session timeout is 10 minutes.
The UPS does not enforce any account policies. Customers
need to enforce their account policies.
© Eaton Corporation plc 2020. All rights reserved.
Revision: 006
Document ID: P-164000493
121
(126)
Eaton 91PS/93PS UPS 8–40 kW
User’s and Installation Guide