Beta Release: Bandolier Security Audit Files for ABB, Siemens, SNC, and Telvent
Digital Bond is pleased to announce the Beta Release of the Bandolier Security Audit Files, a Digital Bond project funded by the Department of Energy. We are excited to announce the latest release includes Nessus audit files for the ABB Ranger, Siemens Spectrum Power TG, SNC GENe, and Telvent OASyS DNA applications. Asset owners and integrators will be able to audit the security settings of their control system application components at deployment and periodically, and we believe this represents a huge step toward better security for control system servers and workstations. Even better news is there are more of these files coming.
If you already use the Nessus compliance checks or Tenable Security Center and are a Digital Bond site subscriber, simply download the appropriate package. If you’re new to the Nessus compliance checks, check out the SCADApedia article “Bandolier User Guide for Nessus“.
Reports from the application checks now include severity ratings and a link to additional documentation. We discussed this a couple of weeks ago. You can also see more details on the Bandolier page, including a table of all the application checks with links to the documentation. If you’re not a site subscriber yet, here’s an example of what you can expect.
Some of the vendors have been extremely helpful in identifying the optimal security settings, testing the Bandolier security audit files, and improving the results. These vendors are using the Bandolier results for deployments and are distributing the Bandolier audit files through their support channels.
We appreciate any feedback you have and will continue working to make the audit files as useful as possible. Stay tuned for more Bandolier updates!
—
Below are download links and a list of audit files included in each package:
Download the ABB Ranger package 
- Ranger NM2003 DAS-App.audit
- Ranger NM2003 DAS-OS-TRU64.audit
- Ranger NM2003 RDAS-App.audit
- Ranger NM2003 RDAS-OS-TRU64.audit
- Ranger NM2003 WEB-App.audit
- Ranger NM2003 WEB-OS-TRU64.audit
- Ranger NM2003 Workstation-App.audit
- Ranger NM2003 Workstation-OS-XP.audit
Download the Siemens Spectrum Power TG package 
- Spectrum Power TG 8.2-SCADA Host Server-App-Linux.audit
- Spectrum Power TG 8.2-SCADA Host Server-OS-Linux.audit
- Spectrum Power TG 8.2-SCADA Workstation-App.audit
- Spectrum Power TG 8.2-SCADA Workstation-OS-XP.audit
- Spectrum Power TG 8.2-Web Host-App.audit
- Spectrum Power TG 8.2-Web Host-OS-2003.audit
Download the SNC-Lavalin ECS GENe package 
- GENe-App.audit
- GENe-OS-Linux.audit
Download the Telvent OASyS DNA package 
- OASyS DNA 7.5-Engineering Station-App.audit
- OASyS DNA 7.5-Engineering Station-OS-2003.audit
- OASyS DNA 7.5-Historical Server-App.audit
- OASyS DNA 7.5-Historical Server-OS-2003.audit
- OASyS DNA 7.5-RealTime Server-App.audit
- OASyS DNA 7.5-RealTime Server-OS-2003.audit
- OASyS DNA 7.5-XOS Workstation-App.audit
- OASyS DNA 7.5-XOS Workstation-OS-XP.audit
Author: Jason Holcomb
Posted: October 13th, 2008 under Bandolier.
Comments: none
Write a comment