|12
that users access from the internet and often attack targets, such as web servers and database
servers. Apply both types of protection.
• Refer CloudLink (R100 and R110) manuals for security features in CloudLink MODEM and refer
RV50 and RV50X and RV55 data sheets for RV50/RV50X/RV55.
• Report security issues or vulnerabilities at MI-TAC-Support@Honeywell.com for us to quickly
respond.
• The RV50x/RV55 unique Password to access ALMS (AirLink Management Service) for each
device will be provided along with the Product test Report document shipped with each device.
ROLES:
System
Operator
Role allows a user to login into the device and collect application data
Field
Technician
Role allows a user to login into the device, configure, calibrate, collect application data
and test for proper operation.
MIWI350 deployments with CloudLink R100/R110:
The user is recommended to deploy the device and Remote MDM server application under secured VPN
network.
• Restrict physical access to the device and other network devices in the network.
• Secure the connection between the Cellular carrier network and end gateway by VPN tunnel.
• Secure the LAN connecting Customer/User VPN gateway and the MDM server running the MDM
application.
• Use a firewall for the business network to process control/monitor network interface to restrict
access from the business network to process control network.
• Use a firewall within local area network connecting VPN Gateway to server hosting MDM
application.
• Close all unused TCP and UDP communication ports on server hosting MDM application.
• Set the minimum level of privilege for all accounts, and enforce a strong password policy.
• Do not allow the use of unauthorized removable media.
• Prevent the use of unauthorized laptops on the process control network.
• Use and enforce a strong password policy.
2 Security Control Measures