
31-00400M-01 | Rev10-20
15
DEPLOYMENTS AND MAINTENANCE CONSIDERATIONS
Deployments and Maintenance Considerations
• Always keep local server up to date on the latest security patches via regular
system update. This applies not only to workstations or servers running on
Windows, Linux, Mac or any devices that runs as part of information
infrastructure or operations workstation.
• Always keep the thermostat firmware with the latest released firmware to have
maximum protection by built-in security features.
• Do not use default passwords for any devices (if exists). This includes, but not
limited, to all server workstations, storage servers, firewall devices, routers, and
mobile devices.
• Do not use weak passwords for server administrators or operators. Different user
role (for example administrator, user, guest, etc.) shall have different password,
and user should not share common passwords.
• It is recommended to change password in every 3 months.
• In case of wireless communication, malicious wireless devices can easily scan the
wireless channel and inject malicious packets or mass data flow to perform Deny-
of-Service attacks. Honeywell has taken steps to prevent TC500A Commercial
Thermostat device from being injected, but the mass data flow will result in loss of
wireless communication bandwidth within the whole system. Regular check of the
communication failure rate or response rate of the thermostat is helpful to
discover and isolate devices being attacked and stop the physical attacks in daily
operation
Network Communication Notice
• To keep maximum integration compatibility with third — party devices and Fast-
pack communications are un-encrypted as open protocol. Improper security
protection may lead to data leakage, spoofing and/or tampered by malicious
devices and denial-of-service attacks.
• To keep maximum integration compatibility with legacy devices, in-room wired
devices are less secure from data confidentiality and authentication thus not-
recommended for new design. It is always highly recommended to use deep mesh
wireless network communication to gain maximum protection and latest updates.
• In case of Deny-of-Service attacks, all communication channels will inevitably
have loss of bandwidth due to malicious data flow.
• The RS 485, S5 bus may contain legacy technology, which is less secure under
modern cyber-security attacks. Honeywell strongly recommends to use a secured
deep mesh wireless network communication. In case of legacy technology, user
needs to be aware of the risk of being tampered or attacked. To reduce the attack
surface, user is advised to physically secure the wired communication signals or
provide necessary shield on wires, or place necessary access control on accessing
such communication wires.
Содержание TC500A
Страница 2: ......
Страница 8: ...8 31 00400M 01 Rev10 20 COMMERCIAL TOUCHSCREEN THERMOSTAT ...
Страница 16: ...16 31 00400M 01 Rev10 20 1 ABOUT TC500A THERMOSTAT ...