ASHRAE Journal - September 2014 - 61

TECHNICAL FEATURE

a presentation by the Industrial Control Systems Cyber
Emergency Response Team (ICS-CERT), a government
agency dedicated to protecting critical infrastructure, it
was noted that having systems publicly exposed was one
of the leading causes of exploited systems.
How do we prevent this from happening? We close
the front door! To prevent unauthorized system access,
the design engineer needs to ensure four phrases are in
their specification.

Spec it Out
1. The control system will reside on a private class IP
network and will only be accessible via the private network or a Virtual Private Network (VPN) connection.
2. The control system installer will delete default
accounts and change the default passwords.
3. The control system installer will work with the client IT department to ensure that their system utilizes
Simple Network Management Protocol V.3 (SNMP) integration or equivalent for user account monitoring.
4. The control system will not use single sign on (SSO)
for user account management.
Now wait a minute, you may be saying, what if the client wants the system publicly exposed? What if the control system they want doesn't support SNMP? All good
questions.
Active Directory (AD) is how most IT groups manage
user accounts. The difference between account monitoring and account management is slight but important.
If you monitor an account, you can see who logs on and
when, which is called event logging. However when you
manage an account, specifically if you use SSO, the user
can log onto their computer and the BAS system with the
same account. Therefore, if someone penetrates your
BAS they can sometimes access your whole network.
If a client wants a publicly exposed system or they want
a system that doesn't support SNMP V.3 then you must
get in writing that the client understands and accepts
the risk and releases you from any and all liability if
someone penetrates the system causing property damage and/or loss of life.

Most, if not all, of these issues can be solved via proper
patching.
There is one phrase that I hate to see in proposals and
specifications. "Patching and software updates for the
XYZ system will be the responsibility of the controls
vendor."
Really? When is the last time any controls vendor
patched a blade server? Half of the BAS's on the market run at least two patches behind the latest Java,
Windows Service Pack, or .NET framework because
that is what the programmers used to design the
system.
So what is a patch? A patch is where a software provider delivers "fixes" to its software. When software is
created, it is often rushed to meet a completion date,
which often leaves errors. A good analogy is value engineering-you design a great specification for an art gallery, and the customer removes the dehumidification
sequence to save money. Only when the art becomes
damaged does the customer decide to add back in the
dehumidification.

Spec it Out
1. The controls provider will be required to patch the
control system and associated servers to the latest version, revision, or update every quarter. If any security
vulnerabilities are discovered by the vendor, the controls provider will be responsible for notifying the client
within five business days.
2. The controls provider will provide quarterly documentation in the form of a physical and soft logbook
ensuring that the updates and patches have been
performed.
This may seem a little extreme, but let's consider the
loss in profit and reputation for both you and your customer. If a user or non-user exploits a Java 5.0 installation and then logs into your client's hospital and
proceeds to shut down all the chillers what is the cost
of that? What if they pivot and grab patient data off the
electronic medical records (EMR)? Remember, simple
steps can avoid large damages.

Patch Up Your Holes

Don't Let "Oops" Become "You're Fired!"

The good news is the system is behind the firewall; the bad news is the
wall is on fire.

Did you need that database for the compliance survey?

What do Java exploits, unsecured operating systems,
and improperly designed platforms have in common?

Have you ever experienced that sinking feeling in
your gut as you watch the database you just spent
months developing melting away into deletion land? I
SEPTEM BER 2014

ashrae.org

ASHRAE JOURNAL

61



ASHRAE Journal - September 2014

Table of Contents for the Digital Edition of ASHRAE Journal - September 2014

Contents
ASHRAE Journal - September 2014 - Cover1
ASHRAE Journal - September 2014 - Cover2
ASHRAE Journal - September 2014 - 1
ASHRAE Journal - September 2014 - 2
ASHRAE Journal - September 2014 - Contents
ASHRAE Journal - September 2014 - 4
ASHRAE Journal - September 2014 - 5
ASHRAE Journal - September 2014 - 6
ASHRAE Journal - September 2014 - 7
ASHRAE Journal - September 2014 - 8
ASHRAE Journal - September 2014 - 9
ASHRAE Journal - September 2014 - 10
ASHRAE Journal - September 2014 - 11
ASHRAE Journal - September 2014 - 12
ASHRAE Journal - September 2014 - 13
ASHRAE Journal - September 2014 - 14
ASHRAE Journal - September 2014 - 15
ASHRAE Journal - September 2014 - 16
ASHRAE Journal - September 2014 - 17
ASHRAE Journal - September 2014 - 18
ASHRAE Journal - September 2014 - 19
ASHRAE Journal - September 2014 - 20
ASHRAE Journal - September 2014 - 21
ASHRAE Journal - September 2014 - 22
ASHRAE Journal - September 2014 - 23
ASHRAE Journal - September 2014 - 24
ASHRAE Journal - September 2014 - 25
ASHRAE Journal - September 2014 - 26
ASHRAE Journal - September 2014 - 27
ASHRAE Journal - September 2014 - 28
ASHRAE Journal - September 2014 - 29
ASHRAE Journal - September 2014 - 30
ASHRAE Journal - September 2014 - 31
ASHRAE Journal - September 2014 - 32
ASHRAE Journal - September 2014 - 33
ASHRAE Journal - September 2014 - 34
ASHRAE Journal - September 2014 - 35
ASHRAE Journal - September 2014 - 36
ASHRAE Journal - September 2014 - 37
ASHRAE Journal - September 2014 - 38
ASHRAE Journal - September 2014 - 39
ASHRAE Journal - September 2014 - 40
ASHRAE Journal - September 2014 - 41
ASHRAE Journal - September 2014 - 42
ASHRAE Journal - September 2014 - 43
ASHRAE Journal - September 2014 - 44
ASHRAE Journal - September 2014 - 45
ASHRAE Journal - September 2014 - 46
ASHRAE Journal - September 2014 - 47
ASHRAE Journal - September 2014 - 48
ASHRAE Journal - September 2014 - 49
ASHRAE Journal - September 2014 - 50
ASHRAE Journal - September 2014 - 51
ASHRAE Journal - September 2014 - 52
ASHRAE Journal - September 2014 - 53
ASHRAE Journal - September 2014 - 54
ASHRAE Journal - September 2014 - 55
ASHRAE Journal - September 2014 - 56
ASHRAE Journal - September 2014 - 57
ASHRAE Journal - September 2014 - 58
ASHRAE Journal - September 2014 - 59
ASHRAE Journal - September 2014 - 60
ASHRAE Journal - September 2014 - 61
ASHRAE Journal - September 2014 - 62
ASHRAE Journal - September 2014 - 63
ASHRAE Journal - September 2014 - 64
ASHRAE Journal - September 2014 - 65
ASHRAE Journal - September 2014 - 66
ASHRAE Journal - September 2014 - 67
ASHRAE Journal - September 2014 - 68
ASHRAE Journal - September 2014 - 69
ASHRAE Journal - September 2014 - 70
ASHRAE Journal - September 2014 - 71
ASHRAE Journal - September 2014 - 72
ASHRAE Journal - September 2014 - SCover1
ASHRAE Journal - September 2014 - SCover2
ASHRAE Journal - September 2014 - S1
ASHRAE Journal - September 2014 - S2
ASHRAE Journal - September 2014 - S3
ASHRAE Journal - September 2014 - S4
ASHRAE Journal - September 2014 - S5
ASHRAE Journal - September 2014 - S6
ASHRAE Journal - September 2014 - S7
ASHRAE Journal - September 2014 - S8
ASHRAE Journal - September 2014 - S9
ASHRAE Journal - September 2014 - S10
ASHRAE Journal - September 2014 - S11
ASHRAE Journal - September 2014 - S12
ASHRAE Journal - September 2014 - S13
ASHRAE Journal - September 2014 - S14
ASHRAE Journal - September 2014 - S15
ASHRAE Journal - September 2014 - S16
ASHRAE Journal - September 2014 - S17
ASHRAE Journal - September 2014 - S18
ASHRAE Journal - September 2014 - S19
ASHRAE Journal - September 2014 - S20
ASHRAE Journal - September 2014 - S21
ASHRAE Journal - September 2014 - S22
ASHRAE Journal - September 2014 - 73
ASHRAE Journal - September 2014 - 74
ASHRAE Journal - September 2014 - 75
ASHRAE Journal - September 2014 - 76
ASHRAE Journal - September 2014 - 77
ASHRAE Journal - September 2014 - 78
ASHRAE Journal - September 2014 - 79
ASHRAE Journal - September 2014 - 80
ASHRAE Journal - September 2014 - 81
ASHRAE Journal - September 2014 - 82
ASHRAE Journal - September 2014 - 83
ASHRAE Journal - September 2014 - 84
ASHRAE Journal - September 2014 - 85
ASHRAE Journal - September 2014 - 86
ASHRAE Journal - September 2014 - 87
ASHRAE Journal - September 2014 - 88
ASHRAE Journal - September 2014 - 89
ASHRAE Journal - September 2014 - 90
ASHRAE Journal - September 2014 - 91
ASHRAE Journal - September 2014 - 92
ASHRAE Journal - September 2014 - 93
ASHRAE Journal - September 2014 - 94
ASHRAE Journal - September 2014 - 95
ASHRAE Journal - September 2014 - 96
ASHRAE Journal - September 2014 - 97
ASHRAE Journal - September 2014 - 98
ASHRAE Journal - September 2014 - 99
ASHRAE Journal - September 2014 - 100
ASHRAE Journal - September 2014 - 101
ASHRAE Journal - September 2014 - 102
ASHRAE Journal - September 2014 - 103
ASHRAE Journal - September 2014 - 104
ASHRAE Journal - September 2014 - Cover3
ASHRAE Journal - September 2014 - Cover4
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_FFRDES
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_WMMDFY
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_HTDEWQ
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_FYONLJ
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2024november_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2024november
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_BDMHLG
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_WJDGRY
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_ATMAHK
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_VHQRAW
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_XGMDXI
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_YELQLJ
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_QJLWMC
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_MCDEBX
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_WNYSQY
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_XATVOD
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_FJSHSS
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_CCBZDS
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_XDEFVG
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2023november_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2023november
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_VHGNBL
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_WPKBNJ
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_UUVCDE
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_RTGDEW
https://www.nxtbook.com/nxtbooks/ashrae/ashraemexico_2023
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_LKRFXS
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_AZSOFG
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_ERCDBH
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_QWDFRV
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_JHGVDF
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_OPUYHG
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_SREIBM
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_LRTGLK
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_OKRFGH
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2022november_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2022november
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_TZSERA
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_LVRUIX
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_RPTVYZ
https://www.nxtbook.com/nxtbooks/ashrae/mini_pub_catalog
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_XIYTGD
https://www.nxtbook.com/nxtbooks/ashrae/ashraemexico_2022
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_RFGDOB
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_PABXNU
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_REMKLS
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_PICVBT
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_AOYTVW
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_JQOPLS
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_IOYTBC
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_SGAJJF
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_IGHYER
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_PDRKLS
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2021november
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2021november_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_XCODFR
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_QSLFGO
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_ILKVNM
https://www.nxtbook.com/nxtbooks/ashrae/ashraemexico_2021
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_OPDJKD
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_VJKSRY
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_SDHUTC
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_JPPKRR
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_SDLTTH
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_CKLLES
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_SLDOX
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_HJETUK
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_OLUHGE
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2020october
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2020october_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_ZERDGH
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_QVMNEO
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_RTPOKE
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_BBATRE
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_STUBMW
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_TPEMPE
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_JNMKDS
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_FBTTPA
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_WQMMNE
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_TVBRYN
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_showguide2020
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_KTUZMA
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_ABEDGD
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201910
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201909
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2019septmeber_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2019september
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201908
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201907
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201906
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201905
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201904
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_2019april
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201903
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_2019march
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201902
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201901
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_showguide2019
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_2018december
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_2018november
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2018fall_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2018fall
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_2018october
https://www.nxtbook.com/nxtbooks/ashrae/ashraemexico_2018
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201810
https://www.nxtbook.com/nxtbooks/ashrae/ashraeinsights_201806
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201805
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201804
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201803
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201712
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201711
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201710
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2017fall_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2017fall
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201709
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201705
https://www.nxtbook.com/nxtbooks/ashrae/ashrae_meetinginsert_201610
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2016fall_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2016fall
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_acrexindia
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2015summer_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_amca_2015summer
https://www.nxtbook.com/nxtbooks/amca/2014summer2
https://www.nxtbook.com/nxtbooks/amca/2014summer
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_acma_2014summer
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201311
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201309
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_acmasupp_2013fall
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201305
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201303
https://www.nxtbook.com/nxtbooks/ashrae/pubcatalog_2013winter
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201211
https://www.nxtbook.com/nxtbooks/ashrae/achr_expo_mexico2012
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201209
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201208_v3
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201208_v2
https://www.nxtbook.com/nxtbooks/ashrae/pubcatalog_2012summer
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201205
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201203
https://www.nxtbook.com/nxtbooks/ashrae/pubcatalog_2012winter
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201111_v2
https://www.nxtbook.com/nxtbooks/ashrae/ashraejournal_201109_v2
https://www.nxtbook.com/nxtbooks/ashrae/pubcatalog_2011summer
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201105
https://www.nxtbook.com/nxtbooks/ashrae/meetingplanner_201103
https://www.nxtbookmedia.com