background image

SMARTVFD SECURITY GUIDE

31-00140—01

4

APPENDIX 4 - SMARTVFD PC 
SECURITY INFORMATION

This section contains additional information on 
Installation security Issues for SmartVFD.

Software and operating system 
security

This section includes information to installing and 
configuring non-SmartVFD software and the operating 
system.

Virus protection

Although some modern threats can bypass even the best 
antivirus checks, antivirus software is still an essential 
element of a comprehensive security strategy.

Installing antivirus software

Install antivirus software on every computer in the 
network, including the SmartVFD commissioning 
software, SmartVFD, and computers used for web browser 
access. After installing antivirus software, check the 
Windows Event Logs and ensure no errors are reported. If 
the system starts experiencing failures, the inability to 
read or write files, the logs show deadlock errors, or the 
system shows any other unusual behavior, disable the 
antivirus software to see if the failures continue. Note that 
some antivirus software may need to be completely 
uninstalled in order to be disabled.

Ensure frequent updates to 
antivirus signature files

It is important to update antivirus signature files 
frequently by subscribing to the updates of your antivirus 
software vendor(s) and leveraging enterprise antivirus 
policies and practices when available. Since new viruses 
are released every day, the system will remain vulnerable 
to attack if the signature files are not updated at the same 
rate. Where it is not practical to perform updates daily, 
monitor reputable web sites that publish information 
about new virus attacks so that the system can be isolated 
if a specific threat appears.

Receipt of new signature files generally requires Internet 
access so that the files can be downloaded from the 
antivirus software vendor. If possible, set up servers for the 
controlled distribution of antivirus signature files.

Configuring active antivirus 
scanning

Adopting an active virus scanning strategy as on-access 
scanning provides the best real-time protection for your 
system. Configure the virus scanner to run on-demand 

scans during regular, scheduled maintenance to catch 
any malicious files or programs which may be dormant on 
the computer.

Configure both on-access and on-demand scanning to:
• Scan the boot sectors of all disks.
• Move infected files to a quarantine directory and notify 

the user that an infected file was found.

Allow the user to clean up the infection.

Regularly review virus scan reports as part of the active 
scanning strategy.

Tuning antivirus scanning for 
system performance

When formulating your virus scanning strategy you must 
take into account the potential impact on critical system 
resources. For example, if the SmartVFD commissioning 
software is experiencing problems due to low system 
resources, you may need to:
• Ensure that antivirus software only runs when system 

resources on the computer are adequate to meet 
system needs.

• Limit system resources that are used by antivirus 

software during scanning.

To find the proper balance between browser workstation 
performance and virus protection you need to make 
configuration choices such as disabling scanning on 
reading of files and changing the default process-based 
scanning to per-process scanning.

Do not automatically schedule full system scans, as this 
can result in severe degradation of performance, which 
could impact the ability of operators to respond to an 
incident.

Service packs and security updates

An important part of the overall security strategy is to 
ensure that the operating system is kept up-to date with 
the latest patches and updates. Before turning the system 
over to the customer, ensure that you have:
• Installed the latest supported web browser version.
• Updated Windows to the latest service pack supported 

by SmartVFD (this information is available on the 
SmartVFD web site or by contacting Technical 
Support).

• Configured Windows Update to automatically check for 

updates.

For the SmartVFD primary workstation, discuss with the 
customer about how to automatically or manually apply 
updates. The customer may opt to install them manually 
in order to control when the SmartVFD primary 
workstation gets rebooted. For client workstation 
computers, updates should be installed automatically.

Summary of Contents for SmartVFD

Page 1: ...scribed and used by the SmartVFD The SmartVFD has multiple communication protocol options Typically only one communication protocol is chosen to interface with the SmartVFD in any given installation SYSTEM DESIGN AND PLANNING This section contains information on activities that need to happen when the system is being planned by the contractor Physical Security of Components It is important to have...

Page 2: ...rough the use of an access code settable on the keypad parameter P8 1 and P8 2 Access to the SmartVFD directly by PC via the Drive Care Tool software and the HVFDCDMCA hardware kit requires no password Any PC application accessing the SmartVFD via the BMS or router should be protected with a robust password See APPENDIX 3 SECURITY MAINTENANCE TASKS on page 3 PCs used to access the SmartVFD Each PC...

Page 3: ...ion best practices for SmartVFD SMARTVFD Communication Bus Lon BACnet MS TP etc Security of the bus also means that the bus is electrically reliable for communications It is important the bus is installed with one wire type consistent throughout the whole gateway to controller connection as to eliminate reflections from bus wire impedance mismatches Shielded wire is not recommended for normal inst...

Page 4: ...est real time protection for your system Configure the virus scanner to run on demand scans during regular scheduled maintenance to catch any malicious files or programs which may be dormant on the computer Configure both on access and on demand scanning to Scan the boot sectors of all disks Move infected files to a quarantine directory and notify the user that an infected file was found Allow the...

Page 5: ...tronger password that is also easier for the user to remember For example My dog Fido has 50 fleas is a much stronger password and much easier to remember than X 9d8oc Ek Enforce password history set to 24 passwords remembered This prevents reuse of the same password too quickly Password must meet complexity requirements set to enabled improves encryption and makes guessing harder Suggest requirin...

Page 6: ...will reject any incoming connections by default Exceptions must be put into the firewall to allow incoming connections to succeed If not manually configured on first usage the Windows firewall will prompt the user to add a firewall exception Use the following configuration settings The firewall is on The firewall is on for all network locations Home or work Public or Domain The firewall is on for ...

Page 7: ...accessible fit locks or remove the DVD drives Disable unused USB ports to prevent USB drives or other uncontrolled devices from being connected to the system Such devices may be used to introduce a virus or other malware Also disable or physically protect the power button to prevent unauthorized use Set the BIOS to boot only from the operating system s root partition drive Set a BIOS password ensu...

Page 8: ... M S 01 18 Printed in United States By using this Honeywell literature you agree that Honeywell will have no liability for any damages arising out of your use or modification to the literature You will defend and indemnify Honeywell its affiliates and subsidiaries from and against any liability cost or damages including attorneys fees arising out of or resulting from any modification to the litera...

Reviews: