User Manual
System Security
Protected System Configuration
2
12 | 27
A6V11917731_en_b_41
The integration between Novigo/Cerberus PACE digital audio network and Desigo
CC is achieved through the Net Design Software distributed by Novigo itself.
This integration is achieved through DNA – Driver iNdependent Architecture layer,
which enables a fast and efficient commissioning.
Figure 2: Driver iNdependent Architecture Layer
2.1 Protected System Configuration
The Novigo/Cerberus PACE voice evacuation system is a critical business
application aimed at protecting people. Therefore, this system must be protected
against attacks and unauthorized access.
The Novigo/Cerberus PACE voice evacuation system must be in a separate
network zone, here referred to as PACE zone or protection zone.
The components in the PACE zone must not be connected to unsecured networks
in the intranet or in the Internet. Allowed connections are those described in the
intended operational environment [➙ 17].
Communication between the PACE zone and other zones must be through a
firewall and must be limited to the minimum necessary.
2.1.1 Zone Boundary Protection
The Novigo/Cerberus PACE voice evacuation system is a safety-related system
that must be protected from attacks and unauthorized access from untrusted
networks, for example, the Internet.
The plant operator is responsible for network planning and design, including the
zone boundary protection.
The Novigo/Cerberus PACE voice evacuation system is a physically separated
network that forms a PACE zone.
The zone boundary protection has the function Inbound Protection/Outbound
Protection for the PACE zone. A separate VLAN does not meet the requirements
for zone boundaries protection (ZBP).
For any connection to external networks or other systems the corresponding
protection must be provided at the border of the PACE zone.
Local connections to the system do not require additional protective measures if
the system accessing the PACE zone is single-homed and thus has no interfaces
to other systems.
For systems accessing the multi-homed PACE zone (see Tunneled Network
Deployment [➙ 21]), protective measures are required.