Purpose

This guidance provides supplemental instructions for protecting your SCIEX acquisition and processing computers. This guidance is intended to supplement rather than replace your current IT policies, requirements, and practices. We suggest that you consult with your IT department before implementing any of the recommended changes.

Introduction

Although SCIEX computers are released with a general use operating system, we recommend that you treat the computer as a specialized system that is an extension of the instrument itself. To safeguard the computer, use the computer only to perform the steps required for your workflows, not for additional purposes. We recommend that you follow the security best practices outlined in this document for both acquisition and processing computers.

Do not use obsolete operating systems

Obsolete operating systems have vulnerabilities and security gaps that can be exploited by attackers. To protect the computer, make sure that it is running a supported version of Windows 10 LTSC or Windows 11. These operating systems have enhanced security features.

Disable USB ports

USB devices can be programmed to spread viruses to any computer they touch. They can infect computers at the boot stage, before antivirus tools can intervene. To protect the computer, disable the USB ports on the front panel of the computer. Make sure that the USB ports on the back panel remain enabled for SCIEX Service Support use.

Do not browse the Internet from the computer

Browsing the Internet from your computer greatly increases the risk of a malware infection. Certain malware can automatically infect your computer by visiting a compromised website without any operator intervention. Downloading and installing applications from the Internet greatly increases the surface area of attack and is strongly discouraged.

Do not use email on the computer

Email is the number one vector of attack for delivering malware. Most malware is delivered via email attachments or malicious links within emails. Using email on the computer greatly increases the risk of a potential malware infection. We strongly recommend that no email activity be performed on the computer.

Do not install any unnecessary third-party software

Installing additional software on your computer increases the attack surface for potential infections. Malware authors often exploit vulnerabilities in third-party applications (like Adobe Flash) to exploit the underlying operating system. We recommend that, whenever possible, you do not perform additional work on the acquisition computer. Instead, use a computer that is intended and protected for such use. If third-party applications must be installed, then we recommend that they be kept up-to-date with the latest security patches.

Connecting to External Third-Party Software and Services

Some customers choose to connect their SCIEX environment to external third-party software or services - including, without limitation, third-party artificial intelligence platforms, large language model APIs, and other cloud-based tools (collectively, "External Software"). SCIEX does not provide, operate, endorse, or control any External Software.

Where a customer chooses to establish such a connection, the customer is solely and exclusively responsible for:

  • Selecting and contracting with the relevant third-party provider. The customer must comply with that provider's terms of service, acceptable use policies, data processing terms, and any applicable usage restrictions. SCIEX is not a party to any agreement between the customer and a third-party provider.
  • Configuring and securing the connection. This includes obtaining and safeguarding any API keys, credentials, or access tokens required to establish the connection.
  • All data transmitted to or processed by the External Software. SCIEX has no visibility into, and accepts no responsibility for, any data — including personal data, proprietary data, or instrument data — that the customer transmits to or causes to be processed by External Software. The customer is the data controller (or, where acting on behalf of others, the data processor) for any such processing and must ensure compliance with all applicable data protection and privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and any other applicable national or regional data protection legislation.
  • International data transfers. Many External Software providers are established outside the European Economic Area (EEA). Transmitting data to such providers may constitute a transfer of personal data to a third country. The customer is solely responsible for ensuring any such transfer complies with applicable transfer mechanisms (such as Standard Contractual Clauses or adequacy decisions) and for concluding any required data processing agreements directly with the relevant provider.
  • The output, accuracy, and reliability of any results generated by External Software. SCIEX makes no representation or warranty as to the accuracy, completeness, or fitness for purpose of any output generated by External Software. The customer must independently verify any output before relying on it.
  • Any security incidents, data breaches, or regulatory consequences arising from the customer's use of or connection to External Software.

SCIEX expressly disclaims all liability for any loss, damage, regulatory fine, or other consequence arising from a customer's use of or connection to any External Software, including any failure, error, or security incident attributable to that External Software or to data processed through it.

We strongly recommend that customers consult with their IT, legal, and data protection teams before connecting any External Software to their SCIEX environment.

Establish strong password policies

Make sure that your password is at least 14 characters long and a mixture of uppercase, lowercase, alphanumeric, and special characters. Enable a screen saver password and inactivity timeout. We recommend that the timeout be 10 minutes. Lock the computer when stepping away from it. Do not share your password with others.

Enable Windows Update

Making sure that critical security patches are installed is essential to maintaining the security of the computer. Our recommended setting is to notify you about the availability of updates and to allow you to select which patches to install and when. This option provides the flexibility to ensure that the installation does not negatively affect acquisition from the instrument. Organizations must balance their security needs and risk tolerance with their need to apply usability patches immediately on release. However, we also recommend that you do not run any Windows updates during SCIEX software acquisition and data processing.

Install antivirus software

While it is a widely acknowledged good practice to employ antivirus and backup software, these applications can interfere with the real-time nature of the SCIEX acquisition software. Some antivirus and backup applications are configured by default to automatically scan and archive a file immediately after creation. Because SCIEX acquisition software can perform multiple writes to a single data file during an acquisition sequence, these real-time features must be disabled to prevent the antivirus or backup software from locking the data file while it is still needed by the SCIEX software application. Many widely-used applications can be configured to either disable real-time protection or ignore certain file-types and paths. Failure to do so might result in either failed acquisitions or acquisitions that take longer to complete than expected.

Follow these guidelines when configuring antivirus software on the acquisition computer:

  • Disable real-time scanning and archiving of files.
  • Ignore the following file types: atmsc, rdb, atds, scan, journal, wiff, qsession, wiff2
  • Ignore the following folders and paths:
    • For Analyst software installations:
      • 32-bit: C:\Program Files\Analyst
      • 64-bit: C:\Program Files (x86)\Analyst
      • D:\Analyst Data
    • For SCIEX OS installations:
      • C:\Program Data\SCIEX
      • C:\Program Files\SCIEX
      • D:\SCIEX OS Data
  • Exclude the following folders if they exist on the PC:
    • C:\Program Files\MongoDB
    • C:\Program Files\PostgreSQL
  • Also ignore any folders containing drivers for connected devices, such as Eksigent LC systems.

Note: The default installation location for the Analyst Data folders is D:\. These folders might be installed on a different drive.

For users running IDA and Scheduled MRM workflow on TripleTOF, QTRAP, and X500 QTOF systems, antivirus software might interfere with data acquisition and cause delays with acquisition of data points. We recommend that either you disable real-time antivirus protection, antivirus scheduled scans, and other data-intensive background tasks for these acquisition scenarios or perform validation for your specific antivirus and use case scenarios. After acquisition is complete, re-enable the real-time antivirus.

For instructions on how best to configure your particular antivirus or backup software, contact your antivirus or backup software provider.

Enable Windows Firewall (currently enabled by default)

As an additional layer of security, we recommend that the Windows Firewall remain enabled. The Windows Firewall has been turned on by default and is set to allow only a minimal number of necessary Windows services.

Keep other applications up to date

The SCIEX computer comes with Adobe Reader to allow operators to view our guides and documentation. We recommend that updates be installed as required, to reduce possible attack vectors. We recommend that the user guides and documentation be viewed on a computer other than the acquisition computer.

Leave network discovery turned off

Network discovery allows the computer to discover other computers on the network, but it also allows other computers to discover the computer. If the computer is discoverable, then it can be scanned for vulnerabilities. Keeping this setting disabled has little impact on your ability to access any resources.

Turn off AutoPlay (currently enabled for CD/DVDs and not removable drives)

Malware can take advantage of the AutoPlay (auto run) functionality as a mechanism to infect a computer. Because of the large-scale global outbreak of the Conflicker virus in 2008, Microsoft changed the behavior of AutoPlay for removable devices only. We recommend disabling AutoPlay for all media types, including removable and CD/DVD devices.

Internet accessible cloud-based services and servers

Cloud services provided by SCIEX that are customer-managed are configured to disable public access by default. Access is restricted to source IP addresses originating from the customer's intranet, ensuring that only authorized internal traffic can reach these services.

As a general rule, when deploying applications on public cloud platforms or internet-accessible servers, it is essential to implement firewall protections and IP address restrictions to safeguard against unauthorized access.

Backups

Customer responsibility for data. The customer is solely responsible for the protection, backup, and recovery of all data generated, stored, or processed on their SCIEX computer or within their SCIEX environment. SCIEX does not back up customer data and accepts no responsibility or liability for any loss, corruption, or unavailability of customer data, howsoever caused, including as a result of hardware failure, software failure, malicious attack, accidental deletion, or any other cause.

Backup frequency. The frequency of backup should be commensurate with the customer's organizational requirements and the criticality of the data generated. Ensuring that backups are functional and recoverable is a vital component of overall data management. Customers should test their backups regularly to verify that data can be successfully restored.

Backup configuration during acquisition. Do not back up the computer during data acquisition, or ensure that the acquisition file types listed in the antivirus section above are excluded from real-time backup activity. Backup software that scans or archives files immediately upon creation can interfere with ongoing acquisitions and result in failed or incomplete data captures.

Pre-update backups. We strongly recommend that a full backup of the computer be taken prior to the installation of any security updates. This will facilitate a rollback in the rare case that a security patch or service pack, including re-imaging, affects application functionality.

No SCIEX liability for data loss. To the fullest extent permitted by applicable law, SCIEX shall not be liable to the customer or any third party for any loss or corruption of data arising from the customer's failure to maintain adequate backups, or from any other cause related to data management on the customer's systems.

Configure browser security settings (if browsing the Internet is absolutely required)

While we strongly recommend that Internet browsing not be conducted on the computer, if you choose to do so then you should enable security settings that will help to protect your computer. These include:

  • Enable Microsoft Edge Enhanced Security mode
    Microsoft Edge Enhanced Security mode helps protect your computer by disabling just-in-time (JIT) JavaScript compilation and enabling additional operating system protections when visiting unfamiliar websites. This limits the ability of malicious code to exploit browser vulnerabilities and access your system.
  • Enable SmartScreen in Microsoft Edge
    SmartScreen in Microsoft Edge helps identify reported phishing and malware websites and assists you in making informed decisions about downloads. We recommend setting the security level for unknown websites to the highest available setting. Note that stricter settings may limit certain browsing functionality, such as running scripts or downloading files. Where possible, configure your browser to block third-party cookies and to warn before accessing sites with invalid certificates.

Security Event Log Auditing

Security event log auditing is a powerful tool that logs and tracks system activity. The logs can be used to make sure that regulatory compliance requirements are met, to monitor critical user activity, to detect anomalous behavior, and more. Because auditing plays a key role in providing evidence for regulatory compliance, consult with the appropriate personnel prior to making any of the recommended changes. To provide a secure baseline, we recommend the following customized auditing settings:

Audit Policy Setting

Log on Success

Log on Failure

Audit Credential Validation

Yes

Yes

Audit Computer Account Management

Yes

No

Audit Other Account Management Events

Yes

No

Audit Security Group Management

Yes

No

Audit Process Creation

Yes

No

Audit Logoff

Yes

No

Audit Logon

Yes

No

Audit Policy Change

Yes

Yes

Audit Security State Change

Yes

Yes

Audit Security System Extension

Yes

Yes

If you have any questions regarding the security of your system, please contact SCIEX Support at https://sciex.com/support

If you would like to arrange for SCIEX Service to perform on-site securing of your system, please email professionalservices@sciex.com