background image

2  Basic Demands 

High Security Systems, Technical Manual

10 (20)

TAC AB, Nov 2006

04-00007-01-en

The Vista server should be configured to accept Windows user authori-
zation only. This means that Vista users defined in the TAC Vista data-
base cannot gain access to the system.

The disk volume of the Vista system and database should be formatted 
as NTFS partitions, which enables files and directories to be protected 
from changes in access. The TAC Vista database directories (object 
database and event log database) should be protected from changes in 
access by normal users, but of course be fully accessible by the account 
running the TAC Vista server. An automatic function of the TAC Vista 
server provides this protection.

The TAC Vista servers should be configured to perform scheduled 
backup automatically. The backup files should be directed to a shared 
directory on the server. The server should be scheduled to create these 
backup files on a write-only medium such as a CD-ROM. A stand-alone 
TAC Vista and Server can be installed on the server to view the backups 
made.

TAC Vista database objects that are critical to the requirements of data 
security during data logging, should be protected from being changed 
by the users of TAC Vista. Only one user account should be registered 
as the Owner of the TAC Vista database. No user should be given the 
right to change access to TAC Vista objects. Only the owner has the 
right to make changes. Protected objects should include:

Sensor objects in data log definitions

Data log definition objects

Event log definition object

Alarm objects reporting conditions on hardware involved in log-
ging data

Database Backup definition objects

Time event objects controlling automatic backup

Xenta outstation objects

The owner account should be protected from intrusion by using pass-
word expiration and maximum logon attempts in Windows. The server 
should be set up to log invalid logon attempts.

The Vista has to be set up to create backups automatically at regular 
intervals. The log database definitions in Vista have to define cyclic 
logs. It is the creation of backups that secures the data. The hard disk 
storing the TAC Vista database should have sufficient capacity to cover 
a full cycle of all data logs and the event logs.

At least two Vista servers have to be running permanently on the net-
work. They have to be configured so that if one fails, the other sends an 
alarm to a permanently manned site.

The TAC Xenta should be programmed to store eight days of data on a 
rolling re-writeable cycle. The TAC Xenta is capable of storing eight 

Summary of Contents for Vista

Page 1: ...High Security Systems Technical Manual...

Page 2: ......

Page 3: ...High Security Systems Technical Manual...

Page 4: ...ment Only licensed users of the product and the document are permitted to use the document or any information therein Distribution disclosure copying storing or use of the product the information or t...

Page 5: ...1 Typographic Conventions 8 2 Basic Demands 9 2 1 System Topology and Configuration 9 2 1 1 TAC Xenta Protection 11 2 1 2 Functional Description 11 3 User s Guide for System Configuration 13 3 1 Setti...

Page 6: ...Contents High Security Systems Technical Manual 6 20 TAC AB Nov 2006 04 00007 01 en...

Page 7: ...n on how to install software we refer you to the instruc tions delivered with the software For information on third party products we refer you to the instructions delivered with the third party produ...

Page 8: ...cal harm to you or to the hardware Caution Alerts you to possible data loss breaches of security or other more serious problems Important Alerts you to supplementary information that is essential to t...

Page 9: ...manipulated or altered acciden tally or intentionally by any user of the system This also covers the transport of values from the sensors to the secure database System reliability System reliability e...

Page 10: ...ted from being changed by the users of TAC Vista Only one user account should be registered as the Owner of the TAC Vista database No user should be given the right to change access to TAC Vista objec...

Page 11: ...ns UPS backup on TAC Xenta units ensures uninterrupted local data logging Database backups secure the collected data at the TAC Vista level The database backups should be copied onto another media aut...

Page 12: ...TAC Vista object databasee as well as the directories and files on the hard disk drive The system also protects the system from time change by a normal user However it should be noted that Vista stor...

Page 13: ...gers group are supposed to have Change authority for some parts of the TAC Vista database They can change all programming and behavior of objects create and delete objects and so on They can also bloc...

Page 14: ...the TAC Vista Setup program and select the Authority sheet 5 In the Vista security level area select High Level Use NT Accounts 6 In the Protected by account area select This Account and enter PlantT...

Page 15: ...roup PlantTAC VistaAdministrators has automatically been created in the ACL editor and the users in this group can be expanded Note also that the users of this group have been added to the Vista group...

Page 16: ...3 User s Guide for System Configuration High Security Systems Technical Manual 16 20 TAC AB Nov 2006 04 00007 01 en...

Page 17: ...having checked Replace permissions on Sub units and Replace Per missions on Existing objects Now all the database objects are pro tected from change by any user although owners can still change the A...

Page 18: ...4 Setting up Access Control Protection of Objects in the TAC Vista Database High Security Systems Technical Man 18 20 TAC AB Nov 2006 04 00007 01 en...

Page 19: ......

Page 20: ...their respective owners Information con tained within this document is subject to changewithout no tice All rights reserved 04 00007 01 en Europe Headquarters Malm Sweden 46 40 38 68 50 Americas Dall...

Reviews: