Rohde&Schwarz OSP220, OSP230, OSP320, OSP-B200S2 Instrument Security

R&S®OSP Open Switch and Control Platform Instrument Security Procedures
1179467002 Version 01
This document describes the types of memory and their use in the R&S®OSP base unit models. While every effort has been made to ensure the accuracy of the information herein, it is provided without warranty. Design iteration and revisions may result in minor differences between the information provided here and your product.
© 2021 Rohde & Schwarz GmbH & Co. KG
Mühldorfstr. 15, 81671 München, Germany
Phone: +49 89 41 29 - 0
Email: info@rohde-schwarz.com
Internet: www.rohde-schwarz.com
Subject to change – data without tolerance limits is not binding.
R&S® is a registered trademark of Rohde & Schwarz GmbH & Co. KG.
Trade names are trademarks of the owners.
1179.4670.02 | Version 01 | R&S®OSP
Throughout this document, products from Rohde & Schwarz are indicated without the ® symbol , e.g. R&S®OSP is indicated as
R&S OSP.
R&S®OSP

Contents

Contents
1 Overview................................................................................................. 3
2 Instrument models covered.................................................................. 4
3 Security terms and definitions..............................................................4
4 Statement of volatility............................................................................5
4.1 Volatile memory.............................................................................................................6
4.2 Non-volatile memory.....................................................................................................6
4.3 Media.............................................................................................................................. 6
5 Instrument sanitization procedure....................................................... 7
5.1 Volatile memory.............................................................................................................7
5.2 Non-volatile memory.....................................................................................................7
5.3 Media.............................................................................................................................. 7
6 Functionality outside secured area....................................................10
7 Recommended security settings........................................................10
7.1 USB interfaces.............................................................................................................10
7.2 LAN interface...............................................................................................................10
7.3 Graphical user interface (GUI)................................................................................... 10
Glossary: Terminology for instrument security procedures........... 10
Index......................................................................................................11

1 Overview

Securing important information is crucial in many applications.
In many cases, it is imperative that the R&S OSP instruments are used in a secured environment. Generally, highly secured environments do not allow any test equipment to leave the area unless it can be proven that no user information leaves with the test equipment, e.g. to be calibrated.
"Regarding sanitization, the principal concern is ensuring that data is not unintention­ally released" [1].
3Instrument Security Procedures 1179.4670.02 ─ 01
R&S®OSP
Instrument models covered
This document provides a statement regarding the volatility of the memory types used and specifies the steps required to sanitize an instrument.
The procedures in this document follow "NIST Special Publication 800-88: Guidelines for Media Sanitization" [1].
In addition, recommendations are provided to safeguard information on the R&S OSP.
References
See the following literature for further information.
[1] Kissel Richard L. [et al.] Guidelines for Media Sanitization = Special Publication (NIST SP) =
NIST SP - 800-88 Rev 1. - Gaithersburg : [s.n.], December 17, 2014.
[2] National Industrial Security Program Authorization Office Defense Security Service (DSS)
Assessment and Authorization Process Manual (DAAPM). - May 6, 2019.
[3] ACSC Australian Cyber Security Centre Australian Government Information Security Manual,
January 2020.

2 Instrument models covered

Table 2-1: R&S
Product name Order number
R&S OSP220 1528.3105K02
R&S OSP230 1528.3105K03
R&S OSP320 1528.3111K02
OSP models

3 Security terms and definitions

Terms defined in Guidelines for Media Sanitization
NIST Special Publication 800-88 [1]
Sanitization
"Media sanitization refers to a process that renders access to target data on the media infeasible for a given level of effort."
Clear
"Clear applies logical techniques to sanitize data in all user-addressable storage locations for protection against simple non-invasive data recovery techniques; typi­cally applied through the standard Read and Write commands to the storage device, such as by rewriting with a new value or using a menu option to reset the device to the factory state (where rewriting is not supported)."
Purge
4Instrument Security Procedures 1179.4670.02 ─ 01
Loading...
+ 9 hidden pages