ST950S Plus+ Installation and Commissioning Manual
6.9.10. Connection to Systems Other than Stratos
6.9.10.1. Security
When set to the Stratos profile and connected to Stratos only, the unit provides suitable security to
allow it to be connected to the Internet. If either of these conditions is not met (i.e. the Stratos profile
isn’t selected and / or the unit is connected to systems other than Stratos e.g. UTC systems) then a
suitable analysis should be performed to ensure that there are no security vulnerabilities in the network
configuration and / or equipment used. The details of this will depend on the networks and connections
involved and is outside the scope of this document but the following are examples of what should be
considered:
•
General:
•
Has the system (including all equipment and interconnections) been reviewed for vulnerability /
susceptibility weakness appropriate to the environment in which it is used?
•
Has a plan been drawn up to ensure that the findings of this analysis are implemented and
maintained?
•
Configuration:
•
Is configuration of equipment suitably protected?
•
Are only the services & features which are necessary enabled?
•
Is encryption used where privacy is required?
•
Is authentication used where trust is required?
•
Are firewalls in place to ensure traffic only flows as expected?
•
Maintenance:
•
Is there a plan and means to apply security fixes to firmware used in all elements of the system?
•
Are secrets (e.g. passwords, encryption / authentication keys) held securely?
•
Is there a plan and means to update secrets as required (e.g. password update & strength)?
•
Disposal:
•
Is equipment which is replaced or no longer required disposed of in a way which does not
compromise the system (e.g. through leakage of secrets, configuration, etc.)?
Note that this consideration applies to all types of networks including those considered “private”. Often
“private” networks will have external connections to some services and may also have some internal
threats. These need to be identified and considered in order to ensure that the system is secure.
6.9.10.2. Connection
When connecting to systems other than Stratos it is important to set the network configuration before
connecting the controller to a network using the Ethernet port on the CPU card. This is because the
CPU card may be a spare which has been configured for and used on another controller site. It could
therefore contain network configuration which would interfere with the site currently being installed.
The network is configured as follows;
Page 126