background image

Safeguard

Security Context & Rationale

References

Each account should be tied to an

individual. Organizations should

control individual accounts

through policy.

Mobile application requires

registration and authentication

and security events are logged.

This safeguard ensures all

activities are traceable and non-

repudiable.

ATT&CK for ICS: M0801
NIST SP 800-53 Rev5: AC-3(7)
ISA/IEC 62443-3-3: SR 1.1

Ensure Magnet Key is removed

after putting the optimyze sensor

in Configuration Mode so that the

device does not re-enter

Configuration Mode unexpectedly

and enable alternative access to

your data.

Protections, such as the magnet

key, are put in place to make

pairing deliberate and to require

physical proximity to the device.

This safeguard provides

additional checks and ensures no

fingerprinting of BLE devices

takes place.

NIST SP 800-53 Rev5: AC-18
ISA/IEC 62443-4-2: CR 4.1, NDR

1.6

Ensure Bluetooth signal cannot

be received outside the

organization-controlled

boundaries by employing

emission security and

purposefully positioning the

device.

Multiple BLE pairing mechanisms

are available to ensure availability

of data. This safeguard reduces

the likelihood of capturing or

intercepting signals.

ATT&CK for ICS: M0806
NIST SP 800-53 Rev5: AC-18,

SC-40
ISA/IEC 62443-3-3: SR 5.2

Implement specific inventory,

logging and monitoring of

hardware and report security-

related incidents associated with

optimyze devices to Xylem.

These might include unexpected

operations, confirmed tampering,

or theft of the device.

Devices are hardened and Xylem

provides PSIRT to help

customers investigate potential

security incidents. This safeguard

supports the ability to track assets

and recognize potential security

events.

ATT&CK for ICS: M0947
NIST SP 800-53 Rev5: SM-8
ISA/IEC 62443-3-3: SR 1.11, SR

2.8, SR 3.4

Maintain updated firmware and

software on all devices and apps.

Device firmware integrity is

maintained by cryptographically

signing at the source and then

verifying the authenticity and

integrity at runtime. It builds on

modern tools provided by our

partners. Sometime vulnerabilities

are discovered, and we work with

our partners to deploy updates to

security and resilience. This

safeguard mitigates exploitation

risks and ensures security

patching.

ATT&CK for ICS ID: M0951
NIST SP 800-53 Rev5: MA-3(6)
ISA/IEC 62443-3-3: SR 3.1.3, SR

7.1

Ensure cybersecurity policies,

awareness, and training to the

operators, administrators and

other personnel.

While the system has been

hardened in many ways, this

safeguard prevents Social

Engineering attacks and

promotes awareness related to

cybersecurity.

NIST SP 800-53 Rev5: AT-2
ISA/IEC 62443-2-4: SP.01

Before device disposal clear all

paired connections and disable

accounts.

No data is persistent on the

Gateway device, but BLE bonding

is enabled for continuous

gathering of sensor data. This

safeguard ensures that no one

can connect to your sensors

using already-paired devices.

ATT&CK for ICS ID: M0942
NIST SP 800-53 Rev5: SR-12
ISA/IEC 62443-3-3: SR 4.2

For additional information see references:

10  Cybersecurity

optimyze

 Gateway Instruction, Operation, and Maintenance Manual

15

Summary of Contents for optimyze

Page 1: ...Instruction Operation and Maintenance Manual P2007090 Rev 1 optimyze Gateway...

Page 2: ......

Page 3: ...ns 7 4 2 LEDs 7 5 Installation 8 5 1 Precautions 8 5 2 Mounting options 8 6 Operation 9 6 1 Configure and install the optimyze sensors 9 6 2 Set up optimyze Gateway 9 6 3 Unpairing 9 7 Troubleshooting...

Page 4: ...11 Certifications 17 11 1 For U S 17 11 2 For Canada ISED 18 11 3 UK UKCA 18 11 4 EU Regulatory 18 Table of Contents 2 optimyze Gateway Instruction Operation and Maintenance Manual...

Page 5: ...fety terminology and symbols About safety messages It is extremely important that you read understand and follow the safety messages and regulations carefully before handling the product They are publ...

Page 6: ...t and safety devices Use personal protective equipment as needed Examples of personal protective equipment include but are not limited to hard hats safety goggles protective gloves and shoes and breat...

Page 7: ...e packing materials from the product Dispose of all packing materials in accordance with local regulations 2 To determine whether any parts have been damaged or are missing examine the product 3 If th...

Page 8: ...Compact Form Factor 110 3 mm 4 4 in x 99 2 mm 3 9 in x 35 4 mm 1 4 in Visual status indication LED Clear indication of optimyze Gateway status See Button locations on page 7 for different status info...

Page 9: ...elow LED color LED Description Blue 5 second single blink Normal mode 1 second blink Pairing mode On Connected over Bluetooth to optimyze sensor Triple blink Successful new Bluetooth pairing with an o...

Page 10: ...ng the unit on a vertical surface The screw head diameter can be no larger than 7 mm with a maximum thread diameter of 3 75 mm and a head height of 3 2 mm When the screw is installed in the mounting s...

Page 11: ...ED blinks pink b Once the sensor is in configuration mode press Bluetooth button on the optimyze Gateway Blue LED starts blinking with a one second interval indicating pairing mode is active Pairing m...

Page 12: ...y because of lacking network coverage optimyze sensor is in configuration mode and Gateway is in pairing mode but they are not pairing optimyze sensor may not be in pairing range 6 sensors may already...

Page 13: ...95 non condensing Power supply Feature Value Operating location Indoor use Operating environment Non hazardous non corrosive Operating temperature 0 C to 40 C 32 F to 104 F Storage temperature 20 C to...

Page 14: ...ature Value Weight for Gateway boxed kit without power supply 0 518 lbs 0 24 kg Weight for Power Supply 0 300 lbs 0 14 kg 8 7 Part numbers Part Part number optimyze Gateway w USB cable P2007065 Power...

Page 15: ...Warranty are warranted only for the balance of the warranty period on the parts that were repaired or replaced Seller shall have no warranty obligations to Buyer with respect to any product or parts...

Page 16: ...ecurity is governed through a three lines of defense model that includes product developers product security engineers and audit staff 10 2 Security Recommendations for End User optimyze Gateway has b...

Page 17: ...erations confirmed tampering or theft of the device Devices are hardened and Xylem provides PSIRT to help customers investigate potential security incidents This safeguard supports the ability to trac...

Page 18: ...hp Mitigations 2 NIST SP 800 53 Rev 5 available online https nvlpubs nist gov nistpubs SpecialPublications NIST SP 800 53r5 pdf 3 ISA IEC 62443 standards available for purchase from ISA IEC or ANSI 10...

Page 19: ...harmful interference in a residential installation This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instructions may cause har...

Page 20: ...ding Digital Apparatus Based on this evaluation this product continues to observe compliance to the requirements set forth by The Innovation Science and Economic Development Canada ISED and complies w...

Page 21: ...Page left intentionally blank...

Page 22: ...Page left intentionally blank...

Page 23: ...Page left intentionally blank...

Page 24: ...customers who know us for our powerful combination of leading product brands and applications expertise with a strong focus on developing comprehensive sustainable solutions For more information on h...

Reviews: