2-4
C70 Capacitor Bank Protection and Control System
GE Multilin
2.1 INTRODUCTION
2 PRODUCT DESCRIPTION
2
When entering a settings or command password via EnerVista or any serial interface, the user must enter the correspond-
ing connection password. If the connection is to the back of the C70, the remote password must be used. If the connection
is to the RS232 port of the faceplate, the local password applies.
Password access events are logged in the Event Recorder.
c) CYBERSENTRY SECURITY
CyberSentry Embedded Security is a software option that provides advanced security services. When this option is pur-
chased, the basic password security is disabled automatically.
CyberSentry provides security through the following features:
•
An Authentication, Authorization, Accounting (AAA) Remote Authentication Dial-In User Service (RADIUS) client that
is centrally managed, enables user attribution, provides accounting of all user activities, and uses secure standards-
based strong cryptography for authentication and credential protection.
•
A Role-Based Access Control (RBAC) system that provides a permission model that allows access to UR device oper-
ations and configurations based on specific roles and individual user accounts configured on the AAA server (that is,
Administrator, Supervisor, Engineer, Operator, Observer).
•
Security event reporting through the Syslog protocol for supporting Security Information Event Management (SIEM)
systems for centralized cybersecurity monitoring.
•
Strong encryption of all access and configuration network messages between the EnerVista software and UR devices
using the Secure Shell (SSH) protocol, the Advanced Encryption Standard (AES), and 128-bit keys in Galois Counter
Mode (GCM) as specified in the U.S. National Security Agency Suite B extension for SSH and approved by the
National Institute of Standards and Technology (NIST) FIPS-140-2 standards for cryptographic systems.
CYBERSENTRY USER ROLES
CyberSentry user roles (Administrator, Engineer, Operator, Supervisor, Observer) limit the levels of access to various UR
device functions. This means that the EnerVista software allows for access to functionality based on the user’s logged in
role.
Example:
Administrative functions can be segmented away from common operator functions, or engineering type access,
all of which are defined by separate roles, as shown in the following figure, so that access of UR devices by multiple per-
sonnel within a substation is allowed.
Figure 2–2: CYBERSENTRY USER ROLES
The table lists the roles that are supported and their corresponding capabilities.
Table 2–3: PERMISSIONS BY USER ROLE FOR CYBERSENTRY
Roles
Administrator
Engineer
Operator
Supervisor
Observer
Complete access
Complete access
except for
CyberSentry
Security
Command
menu
Authorizes
writing
Default role
Device Definition
R
R
R
R
R
Settings
|------------
Product Setup
842838A2.CDR
Administrator
Engineer
Supervisor
Operator
Observer
Содержание C70
Страница 10: ...x C70 Capacitor Bank Protection and Control System GE Multilin TABLE OF CONTENTS ...
Страница 30: ...1 20 C70 Capacitor Bank Protection and Control System GE Multilin 1 5 USING THE RELAY 1 GETTING STARTED 1 ...
Страница 394: ...5 270 C70 Capacitor Bank Protection and Control System GE Multilin 5 10 TESTING 5 SETTINGS 5 ...
Страница 452: ...8 18 C70 Capacitor Bank Protection and Control System GE Multilin 8 1 OVERVIEW 8 THEORY OF OPERATION 8 ...
Страница 474: ...9 22 C70 Capacitor Bank Protection and Control System GE Multilin 9 4 SETTING EXAMPLE 9 APPLICATION OF SETTINGS 9 ...
Страница 486: ...10 12 C70 Capacitor Bank Protection and Control System GE Multilin 10 6 DISPOSAL 10 MAINTENANCE 10 ...
Страница 630: ...B 110 C70 Capacitor Bank Protection and Control System GE Multilin B 4 MEMORY MAPPING APPENDIX B B ...
Страница 676: ...E 10 C70 Capacitor Bank Protection and Control System GE Multilin E 1 OVERVIEW APPENDIX E E ...
Страница 688: ...F 12 C70 Capacitor Bank Protection and Control System GE Multilin F 2 DNP POINT LISTS APPENDIX F F ...
Страница 698: ...H 8 C70 Capacitor Bank Protection and Control System GE Multilin H 3 WARRANTY APPENDIX H H ...