User manual
SimradES70
•Thelikelihoodthatanyremoteconnectionwilldoanyoftheabove.
•Thedamagedoneifaremoteconnectionsucceedsdoingthis.
BecauseKongsbergMaritimehasnoinformationregardingthecompletesystem
installationonanyvessel,wecannotestimatethethreatlevelandtheneedfornetwork
security.Forthisreason,wecannotacceptresponsibilityfornetworksecurity.Systems
providedbyKongsbergMaritimeareregardedasstand-alonesystems,eventhoughthey
maybeconnectedtoanetworkforsensorinterfacesand/ordatadistribution.Forthis
reason,nosafetyapplicationsareinstalledonanycomputerstoprotecttheseagainst
viruses,malwareorunintentionalaccessbyexternalusers.
SecuringtheES70itselfhasnomeaningunlessthereisapolicyinplacethatsecures
allcomputersinthenetwork,includingphysicalaccessbytrainedandtrustedusers.
Thismustalwaysbeataskfortheendusertoimplement.TheES70systemhasbeen
veriedtorununderratherstrictsecuritysetup,soitshouldbepossibletoimplement
agoodsecurityregime.
IfyouwishtoconnecttheES70totheship'snetwork,youmustimplementthesame
securitymechanismsontheES70computer(s)asfortherestofthenetwork.Inthe
tentativestandardfromDetNorskeV eritas(DNV)-IntegratedSoftwareDependent
System(DNV-OS-D203)–thisisdescribedasataskforthenetworkresponsiblepersonin
chargeoftheoverallbehaviourofthenetworksystem.Somekeyelementsheremustbe:
•Thesameanti-virusprotectiononallcomputers,includingroutinesforupdating
thisprotection.
•Thesamesettingsfortherewallonallcomputers.
•Controlledphysicalaccesstocomputersonthenetwork.
•Trustedoperators.
•Log-inaccessmechanisms
•Samepolicyforattachingperipheralequipmenttothecomputers(USBdevices,
harddrivesetc)
•Installationofprogramsonanycomputerinthenetwork,vericationthateach
programisauthentic.
•Denitionofwhichprogramsareallowedtorunoneachcomputer.
•Loggingmechanismofcomputeractivity,andinspectionoftheselogs.
Howtodeneandimplementtheserulesdependsoneachenduser'snetworksystem
conguration,whichagainmustbearesultofthepoliciesandthreatlevelstheenduser
hasdenedforthecompleteinstallation.Forsomeproductsthenetworkconsistsofonly
processorunitsorworkstations,transceiversandafewsensors.Onothervessels,larger
computersystemscanbeinstalledtoincludenumerousproductsanddatasystems.As
theDNV-OS-D203suggests,theremustbeoneresponsiblepersonforthesecurityof
asystem,largeorsmall.
18
338106/C










