Understanding ClearSCADA Security
Security is applied by the ClearSCADA servers to every client that accesses the system (ViewX, WebX, Third Party OPC applications etc.). For example, a user that accesses the system via a Third Party OPC client is subject to the same restrictions as when accessing the system via ViewX.
The ClearSCADA security features are designed to:
- Help protect your system against unauthorized users, both via ViewX and Third Party applications
- Restrict system users to those features that are relevant to their duties so that users only make use of the features for which they have been suitably trained
- Reduce the possibility of untrained staff making inappropriate changes to the configuration of your system.
- Allocate security permissions quickly and with minimal effort.
ClearSCADA has three levels of security:
- Overall system security—The overall security of ClearSCADA is managed within the Server Configuration Tool. This tool allows you to define the default level of security for the whole system including:
- Default account settings
- Use of Windows Authentication
- Use of secure connections
- A client access control list, which defines the number and type of clients that can connect to the server.
- User accounts—Each system user requires a user account to access the system. User accounts define the features that a user can access using ViewX and other client applications
- Access Control List (ACL)—Each item in the database can have its own security settings that define which User accounts and User Groups can access the item, and which features are available. This is called the Access Control List (ACL) for the item. A set of permissions can be allocated to each account to define which features can be accessed by users.
Third Party applications that access ClearSCADA will use a configured user account or the built-in Guest user, depending on whether client security is supported by the Third Party application (see Security for Third Party Applications).
Further Information
see Security Settings at the Server