Professional Documents
Culture Documents
Sabp Z 054
Sabp Z 054
1 Introduction……………………............................ 2
2 Conflicts with Mandatory Standards................... 2
3 References......................................................... 2
4 Definitions........................................................... 3
5 Account & passwords Policies............................ 5
6 Services and applications settings.................... 7
7 Hardening controls............................................ 9
8 Logs and Auditing............................................. 12
1 Introduction
1.1 Purpose and Intended Users
The purpose of this best practice document is to establish a recommended
methodology to implement advanced security configurations for Industrial
Control Systems (ICS). These guidelines are intended for plant network
administrator(s) and technical support staff for the purpose of prompt risk
mitigation and overall adherence to company’s cyber security regulations,
especially those intended for immediate implementation. The intended users
include engineers and / or technicians working as Process Automation Network
(PAN) Administrators.
1.2 Scope
This best practice defines the methodology to harden the Emerson DeltaV
Smart Switches configurations settings, which might require software /
hardware to ensure “secure configuration” as per SAEP-99 “Process Automation
Networks and Systems Security” procedure.
This implementation of this best practice shall satisfy the audit requirement for
the BIT recommendations and can be assessed using “Performing Security
Compliance Assessment Manual”
1.3 Disclaimer
This Best Practice complements other procedures or best practices provided by
vendor and / or consulting agent for the implementation of security
configurations by the PAN administrator(s), and shall not be considered
“exclusive” to provide “comprehensive” compliance to SAEP-99 or any other
Saudi Aramco Engineering’s standards requirements.
The use of this Best Practice does not relieve the PAN administrator(s) from
their responsibility or duties to confirm and verify the accuracy of any
information presented herein and the thorough coordination with respective
control system steering committee chairman and vendor.
Page 2 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
4 Definitions
This section contains definitions for acronyms, abbreviations, words, and terms as they
are used in this document.
4.1 Acronyms
DCS - Distributed Control System
ESD - Emergency Shutdown Systems
IP - Internet Protocol
ISA - The International Society of Automation
PCS - Process Control Systems
PAN - Process Automation Network
PMS - Power Monitoring System
SCADA - Supervisory Control and Data Acquisition
IP - Internet Protocol
TMS - Terminal Management System
VMS - Vibration Monitoring System
4.2 Abbreviations
Authentication: A security measure designed to establish the validity of a
transmission, message, or originator, or a means of verifying an individual's
authorization to receive specific categories of information. When humans have
assets that are worth to be protected, the authentication always exists. The initial
step in protecting systems and information is authentication that identifies who.
Page 3 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Page 4 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Dependencies
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
The deltav command initiates a wizard setup of the Smart Switch. Whenever
you want to skip a configuration just hit return.
During the setup steps, you should have the following request
Instruction Change the default admin password
Type the newest password and be sure to respect the requirements stated in the
SAEP-99
The admin password can only be reset via the DeltaV Setup wizard using the serial
port or telnet connection. Changing this password only impacts user access to the
switch and is not connected or synchronized with the DeltaV or Windows
passwords.
Page 5 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Dependencies
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
The deltav command initiates a wizard setup of the Smart Switch. Whenever
you want to skip a configuration just hit return.
During the setup steps, you should have the following request
Instruction Change the default user password
Type the newest password and be sure to respect the requirements stated in the
SAEP-99
The user password can only be reset via the DeltaV Setup wizard using the serial
port or telnet connection. Changing this password only impacts user access to the
switch and is not connected or synchronized with the DeltaV or Windows
passwords.
Page 6 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Dependencies
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
Page 7 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Dependencies The Telnet Service could be used for the Monitoring purposes. See EME-LA-03
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
Page 8 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
7 Hardening controls
Dependencies
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
The deltav command initiates a wizard setup of the Smart Switch. Whenever
you want to skip a configuration just hit return.
- Geo location: 3 characters referring to City or Plant (URT, ABQ, DHR ...)
- Admin Area : 3 characters referring to whether it is an Oil or Gas plant
- Device role : 2 or 3 characters indicating the device role
o PLC, DCS..
o WRK stands for workstation
o SRV stands for server
o PRT stands for printer
o FW for Firewall , RT for Router and so on
- Incremental ID : 3 variables
Ex : ABQ-RTR-005 : means router number 5 in Abqaiq Plant. We can suppose,
there are ABQ-RT-001, ABQ-RTR-002, ABQ-RTR-003 etc ..
Page 9 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
The deltav command initiates a wizard setup of the Smart Switch. Whenever
Instruction
you want to skip a configuration just hit return.
Page 10 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
The deltav command initiates a wizard setup of the Smart Switch. Whenever
Instruction you want to skip a configuration just hit return.
Used for setup of switches to be installed in DeltaV v10.3 or 10.3.1 only. This command
disables the switch discovery access that is needed for v11 and newer systems. It should
be disabled in v10 systems as a security measure.
Page 11 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
The deltav command initiates a wizard setup of the Smart Switch. Whenever
Instruction
you want to skip a configuration just hit return.
Allows switch to send any preconfigured traps to a computer on the DeltaV network
Page 12 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Connect the to switch using the Serial port (9600 baud, 8 data bits, no parity, 1
stop bit, no flow control)
The deltav command initiates a wizard setup of the Smart Switch. Whenever
Instruction you want to skip a configuration just hit return.
Allows switch to send to a computer on the DeltaV network that is setup to collect
communications traffic information from the switch
Page 13 of 14
Document Responsibility: Plants Networks Standards Committee SABP-Z-054
Issue Date: 4 May 2015 Network Devices Hardening
Next Planned Update: 4 May 2020 Guide – Emerson DeltaV Smart Switches
Dependencies
Telnet to the switch IP. At the prompt, type the following command for
Revision Summary
4 May 2015 New Saudi Aramco Best Practice.
Page 14 of 14