Auto-lockdown network security
26 November 2008
’Security made easy’ is how Emerson Process Management refers to its addition to DeltaV security functionality. Built into the family of DeltaV smart switches, Emerson has added auto-lockdown security capabilities that allow a DeltaV user to automatically lock and unlock the port access of all the switches in the network. This lockdown will disable all unused network connections on the switch.
One of the biggest security vulnerabilities in a control system is that network devices, such as Ethernet-based network switches, are located in unsecure locations out in the process –easily accessible to everyone. Locking down switch ports will prevent accidental connection and virtually prevent the deliberate connection of an unauthorised device to the switch.
“The recommended security practice disables unused connections on network devices,” said Bob Huba, product manager for DeltaV security, “This is usually done using third party IT software which creates risk of simply not doing it at all or accidentally disabling a used port. Our DeltaV one-click lockdown function makes managing network security much easier. Even a maintenance person can use the utility as part of their troubleshooting work practices.”
The one-click lockdown application automatically scans the DeltaV network to find the DeltaV switches and then allows the user the choice to automatically unlock or lock the switches. Unlocking also enables an auto-relock of the switches in 60 minutes if the user does not perform a manual relock before then.
“Our customers tell us that they do not have time to handle these security details,” said Duncan Schleiss, vice president of product marketing, Emerson Process Management. “The patent pending, auto-lockdown capability of the DeltaV smart switch delivers the security-out-of-the-box experience they are seeking.”
“These smart switches are zero configuration, plug-and-play devices in a DeltaV network. They make our system even easier to use and more reliable,” continued Schleiss. “We have learned from experience that people make mistakes and a mistake in a switch configuration can shut down a plant.”
DeltaV switches are available in DIN rail and rack mount versions and in fixed port and modular configurations. They provide Megabit and Gigabit speeds over wired and fibre communications.
Performing a system risk assessment and then implementing the appropriate security practices will allow the user to provide adequate and cost-effective security for the DeltaV system. If further help is required with site-specific DeltaV security, implementation personnel in Emerson’s SureService group can be contacted to provide this service.
DeltaV systems are a core component of Emerson’s open standards-based PlantWeb digital plant architecture which substantially reduces project costs, with customers typically saving over 30% on installed costs.
Contact Details and Archive...