Table 5:
Access rights explanation
Access rights
Explanation
Config – Basic
Configuration – Basic is intended for engineers that only adapt an existing configuration e.g. the
I/O-Configuration using SMT
Config – Advanced
Configuration – Advanced is intended for engineers that do the whole application engineering
and using e.g. ACT
FileTransfer – Tools
FileTransfer – Tools is used for some configuration files for the configuration and shall have the
same value as Config – Advanced
UserAdministration
UserAdministration is used to handle user management e.g. adding new user
Setting – Basic
Setting – Basic is used for basic settings e.g. control settings and limit supervision
Setting – Advanced
Setting – Advanced is used for the relay engineer to set settings e.g. for the protection functions
Control – Basic
Control – Basic is used for a normal operator without possibility to bypass safety functions e.g.
interlock or synchro-check bypass
Control – Advanced
Control – Advanced is used for an operator that is trusted to do process commands that can be
dangerous
IEDCmd – Basic
IEDCmd – Basic is used for commands to the IED that are not critical e.g. Clear LEDs, manual
triggering of disturbances
IEDCmd – Advanced
IEDCmd – Advanced is used for commands to the IED that can hide information e.g. Clear
disturbance record
FileTransfer – Limited
FileTransfer - Limited is used for access to disturbance files e.g. through FTP
DB Access normal
Database access for normal user. This is needed for all users that access data from PCM
Audit log read
Audit log read allows reading the audit log from the IED
Setting – Change Setting Group
Setting – Change Setting Group is separated to be able to include the possibility to change the
setting group without changing any other setting
Security Advanced
Security Advanced is the privilege required to do some of the more advanced security-related
settings
IED users can be created, deleted and edited only with the IED Users tool within
PCM600. Logging on or off can only be done on the local HMI on the IED, there
are no users, roles or rights that can be defined on local HMI.
At delivery, the IED has a default user defined with full access rights. PCM600
uses this default user to access the IED. This user is automatically removed in IED
when users are defined via the IED Users tool in PCM600.
Default User ID: Administrator
Password: Administrator
Only characters A - Z, a - z and 0 - 9 shall be used in user names.
User names are not case sensitive. For passwords see the Password
policies in PCM600.
First user created must be appointed the role SECADM to be able
to write users, created in PCM600, to the IED.
1MRK 511 454-UEN A
Section 4
Managing user roles and user accounts
GMS600 1.3
15
Cyber security deployment guideline