Recording of Cyber-Security Events
The 7SR5 devices and Reydisp Manager provide a security audit trail which chronologically acquires and cate-
gorizes security-relevant events according to the origin and severity.
The 7SR5 devices automatically send the security-relevant events to an external syslog-server.
The transmission of the security events to the configured syslog server(s) takes place spontaneously and
without a conformation via UDP (User Datagram Protocol) when the security event occurs. A later readout of
the recorded security-events from the device-local security event buffer is possible. The security events are in
English.
i
i
NOTE
On the syslog server(s), Siemens recommends protecting the received security-events from unauthorized
read or write access with the role Auditor.
Structure of Security Events
A syslog event is built up with following elements:
Table 9-1
Security Events
Element
Description
Severity (level)
Severity levels of the event:
•
Warning
•
Alarm
Date
Date when the event is received or logged from the syslog server
Time
Time when the event is received or logged from the syslog server
•
T
Time
•
hh:mm:ss.ttt
Time when the event is created
•
+hh:mm
Time deviation from GMT
IP address or port
name
IP address or port name of the product or subcomponent that generates the log entry
Module name
The name of the product module that generates the log entry
BOM
Byte order mark for UTF8 encoding
Product name
The name of the product that generates the log entry
Indication text
The message part of a syslog event
Depending on the event, the indication text can contain variable additional informa-
tion (%A1%, %A2%, %A3%, and %A4%).
i
i
NOTE
Multiple password entry attempts in quick succession may be disregarded by the device as not genuine
entry attempts.
Configuration Overview
To record cybersecurity events during the operation of 7SR5 devices, recordings are automatically created and
data is collected. All security-related events and alarms recorded in the device-internal security log can also be
transmitted simultaneously to a central syslog server. This action allows safety-relevant events to be recorded
from various transformer stations with the requirements of standards and guidelines, such as IEEE 1686,
9.9
Security Settings
9.9 Recording of Cyber-Security Events
142
Reyrolle 7SR5, Operating, Manual
C53000-B7040-C013-1, Edition 05.2021
Содержание Reyrolle 7SR5
Страница 6: ...6 Reyrolle 7SR5 Operating Manual C53000 B7040 C013 1 Edition 05 2021 ...
Страница 10: ...10 Reyrolle 7SR5 Operating Manual C53000 B7040 C013 1 Edition 05 2021 ...
Страница 40: ...40 Reyrolle 7SR5 Operating Manual C53000 B7040 C013 1 Edition 05 2021 ...
Страница 76: ...76 Reyrolle 7SR5 Operating Manual C53000 B7040 C013 1 Edition 05 2021 ...
Страница 114: ...114 Reyrolle 7SR5 Operating Manual C53000 B7040 C013 1 Edition 05 2021 ...