Skip to content

Security Procedures

Info

See also the topic " Best Practices - Security."

Safety procedures for the HSM operator or safety officer:

  1. Follow the Installation Procedure in the Configuration Manual upon receiving the equipment;
  2. Change the default PIN of the smart cards immediately after formatting;
  3. Immediately change the default password for special operator authentication master on the HSM, and then change it periodically;
  4. Create operator-type users for each individual HSM administrator. This will ensure that administrative operations are individualized and recorded in the HSM 's audit trails (logs);
  5. Verify the OEM security code immediately after Initialization to attest to the equipment's integrity.
  6. Divide the M out of N cards into separate piles;
  7. Configure the HSM for the correct operating mode (NRM, RM1, or RM2) in accordance with local security policy;
  8. Frequently verify the trust relationships between users.
  9. Inspect the module with reasonable frequency for evidence of tampering in three areas of the equipment:
    1. Adeviso seal labels, located on the sides, and the metal seal(s) on the back;
    2. ventilation openings, located at the front and rear;
    3. physical ports for a smart card reader, video, and keyboard on the front;
  10. Verify the OEM security code with reasonable frequency.
  11. Establish a policy for systematic log extraction, analysis, and retention.
  12. Establish a backup policy for the HSM key base, using a strong password to protect the backup file;

Operator behavior relevant to the safe operation of the HSM:

  1. Use a strong password for remote authentication via API;
  2. Remove the smart card from the reader after use;
  3. Keep the local console logically locked (locked shell) when not in use;
  4. Monitor the use of HSM resources (CPU and memory) at different times in the daily usage cycle (peak hours, idle hours, etc.);