Password protection is the number one layer of defense recommended by the Industrial Control Systems Joint Working Group (ICSJWG). Enforcing stringent password policies is critical to maintaining the security of any system or network. While policies can be set and controlled on individual devices, centralized management is more effective and consistent.
Managing password policies and user accounts from an access management console provides central authentication and allows network administrators to grant or deny access to each critical control device from a single location. This is called user- or role-based access control. As security policies evolve, these changes can be made from the central console, allowing all devices to be updated simultaneously. It also enables the removal or addition of user accounts.
Since new users can be added quickly, it is even feasible to grant temporary access to guests, such as contractors and auditors. When they leave, any granted access may be revoked and the users designated inactive or deleted from the system altogether. Complete logging of all access events will be available for reporting and compliance in addition to root cause analysis in the event of an intrusion or suspect behavior.
Some important password and access policy considerations:
FoxGuard Solutions has many solutions that can help address these questions and meet the many compliance requirements governing your industry related to access management, password strength, and change policies.