AdobeStock_497954909_lichtpunkt_bearb_ANMC_web

Security Measures with atvise®

Secure systems are not created by a single feature, but by many small decisions made during commissioning and operation. These points are covered in our Security Whitepaper, but they are spread across numerous pages. That’s why we’re bringing them to you one by one: one topic per week, each with a specific security measure.

Overview

Passwords and Password PolicySecure Login to the VisualizationCyber Resilience Act: What Applies Sept. 11Use of Certificates
Encrypted Field CommunicationReduce the Attack SurfaceData Security and Secure BackupsSecurity Checklist
1 / 2

Part 1: Overview Passwords and Password Policy

The first security check: Strong passwords are not created by agreement but by controls.

The root user enables engineering work before project-specific user management is in place and for this purpose has full access to the project. As long as this user is not protected all further authorization rules have only limited effect.

You must set a passwordYou must set a password for root before the project goes live.
You must disable Visual Loginroot is an engineering account. Starting with version 3.7 web access for the predefined administrator can be specifically disabled.
Enable password policyIt specifies the minimum length, character composition, validity period, as well as account lockout and deceleration after failed login attempts.


With atvise® 3.16 password assignment for root becomes part of the atvise® installation itself. Until then it is the first item on the checklist. For existing systems you must check whether this step was performed at the time. It can be done at any time.

Fotolia_95397921_XXL_lichtpunkt_bearb

Part 2: Secure Login to the Visualization

Transport method, login method, and two-factor authentication: three key elements that can be used to protect login to the visualization.

Access control functions only once it is clear who is logging in – and how the person is doing it.

Use HTTPSYou must disable the HTTP web server and use only HTTPS. This ensures that all data traffic is encrypted and can no longer be read by an attacker.
Specify the login methodYou must select the web server's "form" or "script" authentication methods for security-relevant applications. The "script" method also permits blocking logins from specific IP address ranges or using external authentication systems.
Add a second factorSince version 3.10 atvise® has supported two-factor authentication. Starting with version 3.14 the validity period of one-time passwords is configurable .


The web server's identity is backed up by the HTTPS certificate. What to look out for in this regard is covered in Part 4 (Certificates).

iStock-1201645264_atvise_lichtpunkt_bearb

8 Weeks, 8 Measures, 1 Checklist

All Security Measures...

icon_37_keine_mehrfachen_datenpunktlisten_rgb
...at a Glance.

For eight weeks, we’ll show you which small measures can make a big difference to the security of your system. At the end of the campaign, you’ll get:

  • All 8 security measures in one compact checklist

This gives you all the measures at a glance, so you can review your system step by step.

Once the campaign has ended, the checklist will be available here as a free download.