3.5 Users
3.5.1 Accounts
The Bandura Cyber TIG is protected by usernames and passwords, and no one can modify the
internal operation of the device unless they have a registered account.
There is one predefined user account:
User ID: admin
Password: admin
Roles: all
Access restrictions: none
Please consider the following recommendations:
● Immediately change the password on the admin account. Since this has a known default
User ID and password, it is a potential security risk. Be sure the admin account has a
new password before you deploy your Bandura Cyber TIG on your network.
● Create a unique User ID for every administrator of the Bandura Cyber TIG. Each
administrator should keep their password secret and never share it with anyone else.
This gives a better audit trail, encourages individual accountability, and decreases the
risk of fraud and misunderstanding.
● When you no longer need a user account, disable it rather than deleting it. A disabled
User ID cannot be used, but you still have easy access to that account's session logs
Here are the available actions for user accounts:
Show User Sessions
Show login times and an audit trails of actions
Edit User Account
Change account password, roles, and access restrictions
Delete User Account
Permanently delete a users account. An account cannot be
deleted until it is disabled first
3.5.1.1 Creating a New User
Generally, a new user should be created for each person who will administer the Bandura Cyber
TIG. Every person with administrator access should have their own username and password.
Each user account should be assigned to one and only one person. No accounts should be
shared. Each person should immediately change their password when getting a new account.
42