Security Procedures
Info
See also the topic " Best Practices - Security."
Safety procedures for the HSM operator or safety officer:
- Follow the Installation Procedure in the Configuration Manual upon receiving the equipment;
- Change the default PIN of the smart cards immediately after formatting;
- Immediately change the default password for special operator authentication master on the HSM, and then change it periodically;
- Create operator-type users for each individual HSM administrator. This will ensure that administrative operations are individualized and recorded in the HSM 's audit trails (logs);
- Verify the OEM security code immediately after Initialization to attest to the equipment's integrity.
- Divide the M out of N cards into separate piles;
- Configure the HSM for the correct operating mode (NRM, RM1, or RM2) in accordance with local security policy;
- Frequently verify the trust relationships between users.
- Inspect the module with reasonable frequency for evidence of tampering in three areas of the equipment:
- Adeviso seal labels, located on the sides, and the metal seal(s) on the back;
- ventilation openings, located at the front and rear;
- physical ports for a smart card reader, video, and keyboard on the front;
- Verify the OEM security code with reasonable frequency.
- Establish a policy for systematic log extraction, analysis, and retention.
- Establish a backup policy for the HSM key base, using a strong password to protect the backup file;
Operator behavior relevant to the safe operation of the HSM:
- Use a strong password for remote authentication via API;
- Remove the smart card from the reader after use;
- Keep the local console logically locked (locked shell) when not in use;
- Monitor the use of HSM resources (CPU and memory) at different times in the daily usage cycle (peak hours, idle hours, etc.);