Category DescriptionAuthorization and accesscontrol It is extremely important to securely configure the logicalaccess mechanisms provided in the UPS to safeguard thedevice from unauthorized access. Our company recom-mends that the available access control mechanisms beused properly to ensure that access to the system is re-stricted to legitimate users only. And, such users are re-stricted to only the privilege levels necessary to completetheir job roles/functions.• Ensure that default credentials are changed upon firstlogin. The UPS should not be commissioned for pro-duction with default credentials. It is a serious cyber-security flaw as the default credentials are publishedin the manuals.• No password sharing - Make sure that each user getstheir own password for that desired functionality in-stead of sharing the passwords. Security monitoringfeatures of the UPS are created with the view of eachuser having their own unique password. Security con-trols will be weakened as soon as the users start shar-ing the password.• Restrict administrative privileges - Threat actors areincreasingly focused on gaining control of legitimatecredentials, especially those associated with highlyprivileged accounts. Limit privileges to only those nee-ded for a user’s duties.• Perform periodic account maintenance (remove un-used accounts).• Change passwords and other system access creden-tials whenever there is a personnel change.Access to service screen and configuration screen is ac-cess-controlled. Access to UPS features is restrictedbased on roles:1. Configuration screen can be accessed by the Userrole.2. Service screen can be accessed only by the Serviceengineer role.The following are the access levels in the UPS:• Level 1: Control password for User• Level 2: Configure password for User• Level 3: Service password for an authorized EatonCustomer Service Engineer or qualified service per-sonnel authorized by EatonUsers are recommended to change default passwords onfirst use of the system. The default session timeout is 10minutes.The UPS does not enforce any account policies. Custom-ers need to enforce their account policies.Eaton 91PS/93PS UPS 8-10 kW User's and installation guide© Eaton Corporation plc 2018. All rights reserved. Revision: 003 Document ID: P-164000672 99 (102)