PKR39809-02

Potential Risks and Compensating Controls

Cyber threats are part of the digital world of communicating products. The PowerLogic ADVC Controller offers several different features to users to manage cyber security risks.

Unsecure protocols

Modbus, DNP3, IEC 60870-5-101, IEC 60870-5-104, IEC 61850 (IEC 61850
MMS (Manufacturing Message Specification) and IEC 61850 GOOSE (Generic Object Oriented System Event)) protocols, and some IT protocols (Network Time Protocol (NTP), DHCP, PPP) are unsecure.

The device does not have the capability to transmit data encrypted using these protocols. If a malicious user gained access to your network, transmitted information could be disclosed or subject to tampering.

For transmitting data over an internal network, physically or logically segment the network and restrict access using standard controls such as fire walls and in particular IP Table allow lists.

For transmitting data over an external network, encrypt protocol transmissions over all external connections using an encrypted tunnel, TLS wrapper or a similar solution.

For PPP over Radio connection the customer is responsible for verifying that the cellular network is a private and protected network.

Enclosure

The physical integrity of the installation must be ensured by the end user. Physical access to the PowerLogic ADVC Controller and the operational area must be restricted.

The PowerLogic ADVC Controller embeds a door open digital signal to report to the system a physical access to the cabinet or the room.

Standard PowerLogic ADVC Controller Range cubicles are equipped with
3 or 2-point locking door and a vandal resistant door handle. User provided lock can be helps to secure the cabinet door.

QR Code is a registered trademark of DENSO WAVE INCORPORATED in Japan and other countries.

Was this helpful?