What is the password set condition/rules need to follow to set the Micom P40 password with CSL0?
Issue/description:
Password set condition/rules need to follow to set the Micom P40 password with CSL0
Product family:
Easergy MiCOM Px4x relay
Resolution:
For Easergy MiCOM Px4x relay with CSL0, SAT is not supported for the configuration, so only the alphanumeric password can be used.
• The alphanumeric password is settable via Easergy Studio and the Front panel
• Passwords may be any length between 1 and 16 characters long
• Passwords may contain any ASCII character in the range ASCII code 33 (21 Hex) to ASCII code 122 (7A Hex) inclusive
• No password compliance is required
• The alphanumeric password will used for Courier access and the front panel access Arrow key password is not available for relay with CLS0.
Important Note:
The Schneider Electric password policy is one of the key elements of the Cyber
Security Policy.
Good practice to improve the Password definition:
- Use common Cyber Security Good Practice for password complexity definition
by using strong passwords.
- Change All Passwords from their default value when taking the protection device
into use. (User must change password after first login).
- Change Passwords regularly. (User must update password after a certain period
of time).
- Use NERC Compliant password as much as possible.
- Enforce the use of strong and complexes Password as : Caps characters +
Lowercases characters + Numbers + Special characters in one password.
- Set the minimum password length to 10 characters.
- Switch off all Comm port not use on the device, if possible.
- Do not reuse old passwords.
- All P40 relays installed before January 2020 should be checked separately case by
case to confirm the Cyber Security conformity to Standard/country law.
All user must be aware of best practice concerning passwords, these include:
- Not Sharing personal passwords.
- Not displaying passwords during password entry.
- Not transmitting passwords in email or by other means.
- Not saving the passwords on PC’s or other devices.
- Not written password on any supports.
- Regularly reminding users about best practices concerning password.