Security request for NERC CIP compliance
J
Joshua Ditchoff
Hi. Wanted to submit a request to have the ability to disable or control access to the system.secrets.decrypt and the system.secrets.readSecretValue functions. I could definitely see a case where a NERC CIP auditor would flag these functions as violations of CIP-004-7 R6.1 and/or CIP-011-3 R1. As a company that using Ignition for power generation - this obviously is concerning to us. Our developers do not have a business need to know the database credentials to our BES Cyber System, so having the ability to do so would be a CIP-004-7 R6.1 violation. Encrypting the database credentials looks like an information-protection control, but if our developers can just uncover the password I can see an auditor also citing for a CIP-011-3 R1 violation.
Log In