User
Access and Passwords |
CIP-004-1
CIP-005-1
CIP-007-1 |
Individual
user accounts and passwords
Required
strong passwords, expiring passwords,
etc.
Digital
security packages
Strong
Two-factor authentication – IKE
Support |
Access
Control Management |
CIP-003-1
CIP-005-1 |
 Centralized
administration
 Individual
administration accounts and passwords
 Comprehensive
reports: lists of users, assets,
access points, etc. |
Electronic
Security Perimeter |
CIP-005-1
CIP-007-1 |
 Secure
Access Points
 Access
denied by default
 Technical
Control Methods (2-factor authentication,
etc.)
 Electronic
access monitoring and logging
 Appropriate
use banners |
Network
/ Routing Security |
CIP-005-1
CIP-007-1 |
 Enable/Disable
Ethernet Ports / Services
 Firewall
/ VPN
 IP
Access Control
 802.1x
Port Security / 802.1Q VLAN
 Intrusion
Detection System/Denial of Service
 AES256
or 3DES Encryption
 Selective
Layer Encryption (SLE) for VSAT
 Programmable
changing of Security Keys
 SNMP
guarantee traps |
Dial-up
Security |
CIP-005-1 |
 Secure
dial-up modem access control, monitoring
and logging
 VPN
Cellular access for failover |
Logs,
Reports and
Audit Resources |
CIP-003-1
CIP-004-1
CIP-005-1
CIP-007-1
CIP-008-1 |
 Comprehensive
reports
 Detailed
access logs with user, port and
connection information
 User,
Administrator and Asset and Access
Point lists
 NERC
CIP Auto Audit report
 Cyber
incident reports |
Employee
termination /
User rights revocation |
CIP-004 |
 Account
/ security credential expiration
 Administrator
initiated user rights revocation
 Suspended
user accounts |
Alerts
and Notifications |
CIP-005
CIP-007 |
 Configurable
system alert email messages (SNMP)
 Unauthorized
access attempt notification
 System
lockout / system error notification |
Security
Patch Management |
CIP-007 |
 Published
Security Patch scrubs
 Remote
upgrades and auto-update |
Malicious
Software Prevention |
CIP-007-1 |
 Encrypted
operating system |
System
Recovery |
CIP
-009 |
 Multi-master,
multicast support for Serial SCADA applications
 Resilient
networking w. Cellular technologies
primary/backup, with VRRP support.
 Two
code & configuration regions |
| |
|
|
BANDIT
II Data Sheet BANDIT
III Data Sheet VSR-1200
Data Sheet
|
|
|
|