4.7 SECURITY EVENTS MANAGEMENT
To implement NERC-compliant cyber-security, a range of Event records need to be generated. These log security
issues such as the entry of a non-NER
C-compliant password, or the selection of a non-NERC-compliant default
display.
Security event values
Event Value Display
PASSWORD LEVEL UNLOCKED
USER LOGGED IN
ON {int} LEVEL {n}
PASSWORD LEVEL RESET
USER LOGGED OUT
ON {int} LEVEL {n}
P
ASSWORD SET BLANK
P/WORD SET BLANK
BY {int} LE
VEL {p}
PASSWORD SET NON-COMPLIANT
P/WORD NOT-NERC
BY {int} LE
VEL {p}
PASSWORD MODIFIED
PASSWORD CHANGED
BY {int} LE
VEL {p}
PASSWORD ENTRY BLOCKED
PASSWORD BLOCKED
ON {int}
PASSWORD ENTRY UNBLOCKED
P/WORD UNBLOCKED
ON {int}
INVALID PASSWORD ENTERED
INV P/W ENTERED
ON <int}
PASSWORD EXPIRED
P/WORD EXPIRED
ON {int}
PASSWORD ENTERED WHILE BLOCKED
P/W ENT WHEN BLK
ON {int}
RECOVERY PASSWORD ENTERED
RCVY P/W ENTERED
ON {int}
IED SECURITY CODE READ
IED SEC CODE RD
ON {int}
IED SECURITY CODE TIMER EXPIRED
IED SEC CODE EXP
-
PORT DISABLED
PORT DISABLED
B
Y {int} P
ORT {prt}
PORT ENABLED
PORT ENABLED
BY {int} P
ORT {prt}
DEF. DISPLAY NOT NERC COMPLIANT DEF DSP NOT-NERC
PSL SETTINGS DOWNLOADED
PSL STNG D/LOAD
B
Y {int} GR
OUP {grp}
DNP SETTINGS DOWNLOADED
DNP STNG D/LOAD
BY {int}
TR
ACE DATA DOWNLOADED
TRACE DAT D/LOAD
BY {int}
IEC61850 C
ONFIG DOWNLOADED
IED CONFG D/LOAD
BY {int}
USER CURVES DOWNL
OADED
USER CRV D/LOAD
BY {int} GR
OUP {crv}
Chapter 19 - Cyber-Security P14x
470 P14xEd1-TM-EN-1