14
392616/B
systems.Theyarestand-aloneeventhoughtheymaybeconnectedtoanetworkfor
sensorinterfacesand/ordatadistribution.
Note
NonetworksafetyapplicationsareinstalledonanyKongsbergMaritimecomputers.
Thecomputersarethusnotprotectedagainstviruses,malwareorunintentionalaccess
fromexternalusers.
SecuringtheEA440systemitselfhasnomeaningunlessthereisapolicyinplacethat
securesallcomputersinthenetwork.Thispolicymustincludephysicalaccessby
trainedandtrustedusers.Thecustomer/enduseroftheEA440systemwillalwaysbe
inchargeofdeningandimplementingasecuritypolicy,andprovidingtherelevant
networksecurityapplications.
Note
KongsbergMaritimewillnotacceptanyresponsibilityforerrorsand/ordamagescaused
byunauthorizeduseoraccesstotheEA440.
IfyouwishtoconnecttheEA440systemtotheship'slocalareanetwork,youmust
implementthesamesecuritymechanismsontheEA440computer(s)asfortherestof
thenetwork.Thisisataskforthenetworkresponsiblepersononboard.Somekey
elementsheremustbe:
•Thesameanti-virusprotectiononallcomputers,includingroutinesforupdating
thisprotection.
•Thesamesettingsfortherewallonallcomputers.
•Controlledphysicalaccesstocomputersonthenetwork.
•Trustedandtrainedoperators.
•Log-inaccessmechanisms.
•Samepolicyforattachingperipheralequipmenttothecomputers(USBdevices,
harddrivesetc).
•Installationofprogramsonanycomputerinthenetwork,vericationthateach
programisauthentic.
•Denitionofwhichprogramsareallowedtorunoneachcomputer.
•Loggingmechanismofcomputeractivity,andinspectionoftheselogs.
Howtodeneandimplementtheserulesdependsoneachenduser'snetworksystem
conguration,whichagainmustbearesultofthepoliciesandthreatlevelstheenduser
hasdenedforthecompleteinstallation.Forsomeproductsthenetworkconsistsofonly
processorunitsand/orworkstations,transceiversandafewsensors.Onothervessels,
largercomputersystemscanbeinstalledtoincludenumerousproductsanddatasystems.
Theremustbeoneresponsiblepersonforthesecurityofthesystem,largeorsmall.
EA440Installationmanual