394149/C
37
Networksecurity
IfaEK80systemisconnectedtotheshipâslocalareanetwork,datasecurityisofvital
importance.
EquipmentmanufacturedbyKongsbergMaritimearefrequentlyconnectedtotheship's
localareanetwork(LAN).Connectinganycomputertoanetworkwillalwaysexpose
thedataonthatcomputertoallothercomputersconnectedtothesamenetwork.Several
threatsmayimmediatelyoccur:
â˘Remotecomputerscanreadthedata.
â˘Remotecomputerscanchangethedata.
â˘Remotecomputerscanchangethebehaviourofthecomputer,forexamplebyinstalling
unwantedsoftware.
Usually,twoparametersareusedtodeîżnethethreatlevel:
1Thelikelihoodthatanyremoteconnectionwilldoanyoftheabove.
2Thedamagedoneifaremoteconnectionsucceedsdoingthis.
BecauseKongsbergMaritimehasnoinformationregardingthecompletesysteminstallation
onanyvessel,wecannotestimatethethreatlevelandtheneedfornetworksecurity.For
thisreason,wecannotacceptresponsibilityfornetworksecurity.Systemsprovidedby
KongsbergMaritimeareregardedasstand-aloneofîinesystems,eventhoughtheymaybe
connectedtoanetworkforsensorinterfacesand/ordatadistribution.
Note
NonetworksafetyapplicationsareinstalledonanyKongsbergMaritimecomputers.The
computersarethusnotprotectedagainstviruses,malwareorunintentionalaccessfrom
externalusers.
SecuringtheEK80systemitselfhasnomeaningunlessthereisapolicyinplacethatsecures
allcomputersinthenetwork.Thispolicymustincludephysicalaccessbytrainedandtrusted
users.Thecustomer/enduseroftheEK80systemwillalwaysbeinchargeofdeîżningand
implementingasecuritypolicy,andprovidingtherelevantnetworksecurityapplications.
Note
KongsbergMaritimewillnotacceptanyresponsibilityforerrorsand/ordamagescausedby
unauthorizeduseoraccesstotheEK80.
SimradEK80