Grid Automation Products. SAM600 Process Bus I/O System Cyber Security Deployment Guideline



Similar documents
Lifecycle Service Tool. Operator's manual

AC 800M. EtherNet/IP DeviceNet Linking Device LD 800DN. Power and productivity for a better world TM SP1134

Field Information Manager Product guide. Field Information Manager version 1.1

Remote Access Platform. Architecture and Security Overview

Communication Unit 560CMU05 Data sheet

CAP 501. User s Guide

Snapshot Reports for 800xA User Guide

Relion Protection and Control. 670 series IEC 2.0 Cyber Security Deployment Guideline

Protection and Control IED Manager PCM600 Getting Started Guide

Relion Protection and Control. 670 series 2.1 IEC Cyber security deployment guideline

Waveguide Access Point WGA631. Product Guide

Relion 611 series. Feeder Protection and Control REF611 Modbus Point List Manual

IEC 61850: Communication Networks and Systems in Substations

WA Manager Alarming System Management Software Windows 98, NT, XP, 2000 User Guide

Motor control and protection unit MCUSetup user guide

Hypercom Key Loading and Management (HKLM) RS232 PPP Key Injection PC Setup Guide

System 800xA Operations Operator Workplace Support for Mobile Devices

Creating the program. TIA Portal. SIMATIC Creating the program. Loading the block library. Deleting program block Main [OB1] Copying program blocks

SIMATIC NET. CP AS-Interface Master B C. Preface Contents. Technical Description and Installation Instructions Interface to the User Program

McAfee Encrypted USB Hard Disk Non-Bio Quick Start Guide

M3 Single-Slot Cradle. User Guide. Cradle Model: A-1CR-U R00, A-1CR-U00D-040-R00, A-1CR-US R00, A-1CR-U0ED-110-R00

Oracle Cloud. Creating a Business Intelligence Cloud Extract E

System 800xA PC, Network, and Software Monitoring Operation

Ethernet Radio Configuration Guide

M3 ORANGE Snap-On. User Guide. Product Model: A-SNO-ATYP-060-R00. Compatible Device: M3 ORANGE. Version 2.2 Released in March 2013

NEC Express5800 Series NEC ESMPRO AlertManager User's Guide

System 800xA Information Management Enterprise Historian Migration

MicroTech II McQuay Maverick II Rooftop Unit Controller BACnet Communication Module (MS/TP)

Variable speed drives for synchronous and asynchronous motors

System 800xA Tools. System Version 5.1. Power and productivity for a better world TM

Agilent U1610/20A Handheld Digital Oscilloscope Quick Start Guide

Universal Serial Bus (USB) to DH-485 Interface Converter

COM600 series, Version 4.1 Cyber Security Deployment Guideline

Configuring PROFINET

BNI EIP Z009 IP67 Module, Unmanaged Switch

Samsung Portable SSD T1

Two kinds of size notation are employed in this manual. With this machine refer to the metric version.

VOIP-2CH. Telephone Clocking Adapter. Installation Guide

Addendum to the Operating Instructions

System 800xA PC, Network, and Software Monitoring Configuration

Substation Automation Products Relion 670/650 series IEC and ANSI Hardware

Symantec Database Security and Audit 3100 Series Appliance. Getting Started Guide

WinCC Runtime Professional Readme SIMATIC HMI. WinCC V11 SP1. Readme WinCC Runtime Professional. Special considerations for Windows 7.

System System 800xA PC, Network, and Software Monitoring Configuration

BK MIKRO9. Tool monitoring system. Getting Started with Profibus Release 1.00 /

1SFC170011M0201 EN, Rev C. Arc Guard System, TVOC-2 Installation and maintenance guide

Document ID. Cyber security for substation automation products and systems

M7250P. PoE Powered. Gigabit Ethernet Media Converter 1000BASE-TX TO 1000BASE-SX/LX. Installation Guide

ABB Drives. User s Manual. Pulse Encoder Interface Module RTAC-01

C13 User Manual Document ID: 2CMC486004M0201 Revision: A

About This Guide SolarEdge Configuration Tool Software Guide. About This Guide

Wireless Router Setup Manual

NortechCommander Software Operating Manual MAN R6

Relion 611 series. Feeder Protection and Control REF611 Application Manual

The Shift to Wireless Data Communication

Netbiter Remote Access

Networking Guide Redwood Manager 3.0 August 2013

M3 ORANGE single-slot Cradle. User Guide. Product Number: A-1CR-US0D-030-R00, A-1CR-U0ED-030-R00. Compatible Device(s): M3 ORANGE

SoftRAID 5 QUICK START GUIDE. for OWC ThunderBay

Network Guide. Windows Configuration Using a Printer Server Monitoring and Configuring the Printer Appendix

Installation Guide Wireless 4-Port USB Sharing Station. GUWIP204 Part No. M1172-a

Quick Start Guide. Rev. 1.0

OfficeServ Link. User Guide. Version 2.1 June 2005

BIT COMMANDER. Serial RS232 / RS485 to Ethernet Converter

StruxureWare Power Monitoring 7.0.1

Brake module AX5021. Documentation. Please read this document carefully before installing and commissioning the brake module!

ES-3305P V2 / ES-3308P V2. Quick Installation Guide / v1.0

Network Interface Panel User s Guide NPD EN

Manual. Simrad StructureScan LSS-1 Sonar Module. English

User Manual. AS-Interface Programmer

Sunny Boy Accessories SMA POWER BALANCER

USER GUIDE. Touchpoint Pro Webserver

Virtual CD v10. Network Management Server Manual. H+H Software GmbH

Taurus Super-S3 LCM. Dual-Bay RAID Storage Enclosure for two 3.5-inch Serial ATA Hard Drives. User Manual March 31, 2014 v1.2

Studio 5.0 User s Guide

Industrial L2+ Managed Gigabit/ 10 Gigabit Ethernet Switch. IGS-5225 Series. Quick Installation Guide

784 INTELLIGENT TRANSPORTATION SYSTEMS NETWORK DEVICES. (REV ) (FA ) (7-12)

User Manual Revision English

Sage 100 ERP. Installation and System Administrator s Guide

TX OPEN RS232/485 module

Operating instructions. AS-i Profibus gateway AC1411 / AC /00 04/2014

The software is sold on an AS IS basis. ALVARION, its affiliates or its licensors MAKE NO

Documentation for. KL2602 and KL2622. Two-channel Relay Output Terminals for 230 V AC / 30 V DC. Version: 1.4 Date:

CPU PN/DP: Configuring an ET. 200S as PROFINET IO device SIMATIC. PROFINET CPU PN/DP: Configuring an ET 200S as PROFINET IO device

Kvaser Mini PCI Express User s Guide

EMC RepliStor for Microsoft Windows ERROR MESSAGE AND CODE GUIDE P/N REV A02

StructureScan HD Module. Installation Guide ENGLISH

System 800xA Multisystem Integration

Dollar Universe SNMP Monitoring User Guide

Substation Automation based on IEC 61850

SIMATIC S Getting Started for First Time Users. Order No.: 6ZB5310-0NC02-0BA0 04/2007 A5E

VFS24/32HDIP. Public Display IP Monitor User Manual

Low Voltage Switchgear MNS is with MSpeed

GETTING TO KNOW YOUR NEW TELSTRA MOBILE WI-FI 4G

Ethernet Interface Manual Thermal / Label Printer. Rev Metapace T-1. Metapace T-2 Metapace L-1 Metapace L-2

Installation Instructions For Controllers with MS/TP Automatic MAC Addressing. Patent Pending

USB Plus+ RFID Reader Setup Guide

UPS Network Interface. Quick InstallationGuide

Communication Interface for SMA Inverters SMA BLUETOOTH PIGGY-BACK

R-NET MOUSE MODULE TECHNICAL MANUAL SK

Transcription:

Grid Automation Products SAM600 Process Bus I/O System Cyber Security Deployment Guideline

Document ID: 1MRK 511 430-UEN Issued: April 2016 Revision: - Product version: 1.1 Copyright 2016 ABB. All rights reserved

Copyright This document and parts thereof must not be reproduced or copied without written permission from ABB, and the contents thereof must not be imparted to a third party, nor used for any unauthorized purpose. The software and hardware described in this document is furnished under a license and may be used or disclosed only in accordance with the terms of such license. Trademarks ABB is a registered trademark of the ABB Group. All other brand or product names mentioned in this document may be trademarks or registered trademarks of their respective holders. Open Source License Acknowledgements This product incorporates open source software components covered by the terms of third party copyright notices and license agreements. For more information, refer to 1MRK 511 428-BEN SAM600 Product Guide. Warranty Please inquire about the terms of warranty from your nearest ABB representative.

Disclaimer The data, examples and diagrams in this manual are included solely for the concept or product description and are not to be deemed as a statement of guaranteed properties. All persons responsible for applying the equipment addressed in this manual must satisfy themselves that each intended application is suitable and acceptable, including that any applicable safety or other operational requirements are complied with. In particular, any risks in applications where a system failure and /or product failure would create a risk for harm to property or persons (including but not limited to personal injuries or death) shall be the sole responsibility of the person or entity applying the equipment, and those so responsible are hereby requested to ensure that all measures are taken to exclude or mitigate such risks. This product is designed to be connected to and to communicate information and data via a network interface. It is Customer s sole responsibility to provide and continuously ensure a secure connection between the product and Customer s network or any other network (as the case may be). Customer s shall establish and maintain any appropriate measures (such as but not limited to the installation of firewalls, application of authentication measures, encryption of data, installation of anti-virus programs, etc) to protect the product, the network, its system and the interface against any kind of security breaches, unauthorized access, interference, intrusion, leakage and/or theft of data or information. ABB and its affiliates are not liable for damages and/or losses related to such security breaches, any unauthorized access, interference, intrusion, leakage and/or theft of data or information. This document has been carefully checked by ABB but deviations cannot be completely ruled out. In case any errors are detected, the reader is kindly requested to notify the manufacturer. Other than under explicit contractual commitments, in no event shall ABB be responsible or liable for any loss or damage resulting from the use of this manual or the application of the equipment.

Conformity This product complies with the directive of the Council of the European Communities on the approximation of the laws of the Member States relating to electromagnetic compatibility (EMC directive 2014/30/EU) and concerning electrical equipment for use within specified voltage limits (Low-voltage directive 2014/35/EU). This conformity is the result of tests conducted by ABB in accordance with the product standard EN 60255-26 for the EMC directive, and with the product standard EN 60255-27 for the low voltage directive. The product is designed in accordance with the international standards of the IEC 60255 series.

Safety Information Observe the following safety instructions when using the product. Before first usage, read the product documentation in order to ensure safe and reliable operation of SAM600 products. Dangerous voltages can occur on the connectors, even though auxiliary voltages are disconnected. Each SAM600 product must be safely connected to ground using the ground strap. Only a competent electrician is allowed to carry out the electrical installation. Always follow national and local electrical safety regulations. Non-observance of the safety information can result in death, personal injury or substantial property damage. Whenever changes in parameter settings are applied to SAM600 modules, take measures to avoid inadvertent tripping or malfunction of connected protection and control devices.

Table of contents Table of contents Section 1 Introduction... 3 1.1 This manual... 3 1.2 Intended audience... 3 1.3 Related documents... 3 1.4 Symbols and conventions... 4 1.4.1 Symbols... 4 1.4.2 Document conventions... 4 Section 2 Secure access... 5 2.1 Secure system setup... 5 2.2 Ethernet ports... 5 Section 3 User account management... 7 Section 4 Security event logging... 9 Appendix A Glossary... 11 SAM600 Process Bus I/O System 1 Cyber Security Deployment Guideline

2

1MRK 511 430-UEN - Section 1 Introduction Section 1 Introduction 1.1 This manual The cyber security deployment guideline describes the process for handling cyber security when communicating with SAM600 modules. The guideline can be used as a technical reference during the engineering phase, installation and commissioning phase, and during normal service of the product. 1.2 Intended audience This guideline is intended for system engineering, commissioning, operation and maintenance personnel handling cyber security during the engineering, installation and commissioning phases, and during normal service. The personnel is expected to have general knowledge about topics related to cyber security. 1.3 Related documents SAM600 Product documentation SAM600 Product Guide SAM600 Engineering Manual SAM600 Operation Manual SAM600 Cyber Security Deployment Guideline SAM600 Accessory List SAM600-TS Wiring Diagram SAM600-VT Wiring Diagram SAM600-CT Wiring Diagram Document number 1MRK 511 428-BEN 1MRK 511 431-UEN 1MRK 511 429-UEN 1MRK 511 430-UEN 1MRK 511 432-BEN 1KHL511910 1KHL511911 1KHL511912 SAM600 Process Bus I/O System 3 Cyber Security Deployment Guideline

Section 1 1MRK 511 430-UEN - Introduction 1.4 Symbols and conventions 1.4.1 Symbols The electrical warning icon indicates the presence of a hazard which could result in electrical shock. The warning icon indicates the presence of a hazard which could result in personal injury. The caution icon indicates important information or warning related to the concept discussed in the text. It might indicate the presence of a hazard which could result in corruption of software or damage to equipment or property. The information icon alerts the reader of important facts and conditions. The tip icon indicates advice on, for example, how to design your project or how to use a certain function. Although warning hazards are related to personal injury, it is necessary to understand that under certain operational conditions the operation of damaged equipment may result in degraded process performance leading to personal injury or death. Therefore, it is recommended to comply fully with all warning and caution notices. 1.4.2 Document conventions A particular convention may not be used in this manual. Abbreviations and acronyms in this manual are spelled out in the glossary. The glossary also contains definitions of important terms. HMI menu paths are presented in bold. For example, select Main menu/settings. Parameter names are shown in italics. For example, the function can be enabled and disabled with the Operation setting. 4 SAM600 Process Bus I/O System Cyber Security Deployment Guideline

IEC 61850-9-3 1MRK 511 430-UEN - Section 2 Secure access Section 2 Secure access 2.1 Secure system setup Access to a SAM600 system is only possible through PCM600 and a physical connection to any SAM600 module in a SAM600 system through USB as illustrated in Figure 1. Once a SAM600 system is configured, each Ethernet port of the system supports only the functionality that is configured. The following communication services are configurable per port: Closed port (both Tx and Rx) IEC 61850-9-2 uplink (Tx enabled, Rx disabled) IEC 61850-9-2 downlink (Tx disabled, Rx enabled) IEC 61850-9-2 uplink and downlink (both Tx and Rx enabled) IEC 61850-9-3 (IEEE 1588 V2, both Tx and Rx enabled) IEC 61850 Station Bus IED Ctrl IED Prot IEC 61850-9-2 uplink ports SAM600 -TS SAM600 -CT SAM600 -VT USB IEC 61850-9-2 downlink ports PCM600 Sensor Figure 1: SAM600 secure system overview 2.2 Ethernet ports SAM600 modules only use Ethernet based protocols. Those protocols are IEC 61850-9-2 and IEC 61850-9-3 (IEEE 1588 V2). No TCP/IP or UDP ports are used and opened by a configured SAM600 system. SAM600 Process Bus I/O System 5 Cyber Security Deployment Guideline

6

1MRK 511 430-UEN - Section 3 User account management Section 3 User account management A SAM600 system does not provide any local or central user account management services. SAM600 Process Bus I/O System 7 Cyber Security Deployment Guideline

8

1MRK 511 430-UEN - Section 4 Security event logging Section 4 Security event logging A SAM600 system provides general event logging functionality that includes security relevant events as documented in Table 1. A SAM600 system does not provide any user activity logging as it does not support user management and authorization. Table 1: Security event types Severity Event name Description Required action Error Error Information Event buffer overflow Serial communication failure Configuration mode Created when the internal event queue overflows and log events are lost Created when a SAM600 module fails to receive a command from PCM600 on its USB port, or when a SAM600 module fails to send a command to PCM600 from its USB port Created when a SAM600 module is set to wait in configuration state Information Event log reset Created when the event log on a SAM600 module is deleted Information Information Information Information Information Information New application configuration applied New configuration applied New configuration received New system time set Port settings modified Reset to factory defaults Created when SAM600 parameter settings are modified as part of a configuration download Created when a SAM600 module has successfully applied a configuration Created when a SAM600 module has received a configuration Created when a new system time is set on the SAM600-TS module Created when a SAM600 system bus port settings are modified Created when the configuration of a SAM600 module is erased Information Simulation mode Created when the simulation mode is switched ON or OFF None Check the SAM600 module s USB connection. If the error persists, contact ABB support line. None None None None None None None None None For more information about event logging functionality, event types, and event names, refer to 1MRK 511 429-UEN SAM600 Operation Manual. SAM600 Process Bus I/O System 9 Cyber Security Deployment Guideline

10

1MRK 511 430-UEN - Appendix A Glossary Appendix A Glossary Abbreviation 1PPS AC AIS BMC DC FOCS FTDI GIS ICT IEC 61850 IED IID LE LED MAC MSVCB PCM600 PTP RCB SAM600 SAMU SCD SCL SCT SFP SMVID Description One Pulse Per Second Alternating Current Air Isolated Switchgear Best Master Clock Direct Current Fiber Optic Current Sensor Future Technology Devices International Ltd. (http://www.ftdichip.com/) Gas Isolated Switchgear IED Configuration Tool Substation Automation Communication Standard Intelligent Electronic Device Instantiated IED Description IEC 61850-9-2LE Light Edition Light Emitting Diode Media Access Control Multicast Sample Value Control Block Protection and Control IED Manager IEEE 1588 Precision Time Protocol Report Control Block SAM600 Standalone Merging Unit Standalone Merging Unit Substation Communication Description System Configuration Description Language System Configuration Tool Small Form-Factor Pluggable Sample Value Identifier SAM600 Process Bus I/O System 11 Cyber Security Deployment Guideline

Appendix A 1MRK 511 430-UEN - Glossary Abbreviation SST SV USB UTC Description System Specification Tool Sample Value Universal Serial Bus Coordinated Universal Time 12 SAM600 Process Bus I/O System Cyber Security Deployment Guideline

13

1MRK 511 430-UEN - Copyright 2016 ABB. All rights reserved. Contact us ABB AB Grid Automation Products SE-721 59 Västerås, Sweden Phone: +46 (0) 21 32 50 00 Fax: +46 (0) 21 14 69 18 www.abb.com/protection-control