Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 31 of 37

Principle 3. Provide secure and repeatable configuration with strong access controls

Access control features are integral to prevent unauthorised access and to enable effective logging of configuration changes. The configuration interface should allow multiple accounts to be made with varying privilege levels. For example, an ‘admin’ account may have access to all configuration options, whereas a a lower privileged maintenance or management account may only be able to access basic configuration and diagnostic information. Following the principle of least privilege, this will ensure that any user that requires access to the device will only have access to the information and configuration options necessary to conduct their specific role. This will reduce the insider threat from employees acting negligently or maliciously, and potentially make compromise of the device by an external actor more challenging.

Implementing multiple user accounts allows you to conduct more effective logging. It enables configuration actions to be tied to a user account, increasing the likelihood of detecting unauthorised changes to device configuration (or at very least logging these changes, thereby complying with the principle of non-repudiation).

To enable this, assign accounts to individual users wherever possible, and avoid using shared/generic accounts. Where supported, administrators should also use multi‑factor authentication (MFA), as these interfaces are often deployed at the edge of networks and may be exposed to higher risk; see the NCSC’s guidance on implementing multi‑factor authentication for further advice.

Published

Reviewed

Version

1.0