Station Compliance›Equipment
Scope guide
The rule names EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into programming. That third clause is doing most of the work, and it is the one most stations have read too narrowly.
The test to apply to any device: is it remotely manageable, and can it affect what goes out over the air?
If both are true, it is in scope — whatever kind of box it is, whoever sold it to you, and whether or not it has anything to do with EAS.
Running a television plant? The rule applies identically and on the same date, but the equipment list is longer — master control, playout, the encoder, and the character generator that puts the EAS crawl on screen, which § 11.51(d) requires you to have and which is squarely inside the scope language. The television scope guide covers it device by device.
Devices with documented, verifiable security behavior worth knowing before you start:
| Device | Why it is on this list |
|---|---|
| Barix Instreamer / Exstreamer |
No password protection at all in the default configuration — and a documented incident in which a station's STL was reconfigured by an outsider to pull a different stream. Very common in small-market STL. |
| Comrex ACCESS / BRIC-Link |
Factory default password comrex, publicly targeted. Two separate passwords, only one of which is the management credential. Port 80 forwarding is the usual real problem. |
The kit's device reference also covers DASDEC, Sage ENDEC 3644 (and why Rev 96 matters for more than this rule), Tieline (whose recent firmware ships unique 15-character passwords already), Burk ARC Plus, and Inovonics — plus transmitter sites, audio-over-IP networks, and an eight-step method for anything not listed.
Some product lines are firmly in scope but carry no per-model entry here, and the reason is a deliberate one.
Automation and playout — StationPlaylist, Zetta, NexGen, Simian, Rivendell, WideOrbit, ProppFrexx and similar are in scope when remotely manageable. Per-product security specifics are not published because these are general-purpose Windows or Linux applications whose exposure depends far more on the host machine and network than on the application itself. Pay attention to remote desktop access to the automation PC, the host OS patch status, any web or API interface, and shared operator logins.
The automation PC is often the single most exposed device in a small-market station — and the least likely to appear on an EAS-focused checklist.
Audio processors — Omnia, Orban Optimod, Wheatstone and similar networked processors are in scope where remotely manageable. Per-model password behavior for these lines has not been verified, and it will not be guessed at here. A guessed number would cause a station to record compliance it does not have.
No inventory checklist has a slot for these, and you cannot find them by walking the rack:
The test: does this account let someone change what goes out over the air? If yes, it is a program chain credential and the same standard applies.
Offboarding is where this fails. The specific failure is a contractor who parts ways with the station while their vendor portal login keeps working — because that account lives at the vendor, not on any device you control.
Changing the web password does not change the other one. Most gear exposes several management paths — web, Telnet or SSH, SNMP, a vendor desktop application, a serial console sometimes bridged onto the network, a front panel PIN — and they frequently keep separate credential stores.
Setting a strong web password on a unit whose Telnet still accepts the factory login leaves the device exactly as open as it was, while producing a compliance record saying you fixed it. This is the most consequential failure mode in the whole exercise, because the paperwork looks correct.
SNMP deserves particular attention. Versions 1 and 2c have no encryption and use community strings as their only credential; public for read and private for write are near-universal defaults. A write-capable SNMP interface on a transmitter remote control is a control path into your program chain protected by a word guessed on the first try. Use SNMPv3 where supported; otherwise change the community strings and restrict SNMP to your management network.
This ranking reflects real exposure, not equipment cost:
comrex being a documented, publicly targeted exampleMemory catches what you can remember. These catch what you cannot:
Everything above is scope and method. The Program Chain Compliance Kit is the part that gets it done: a 90-minute start-here path, the verified device reference in full, three network segmentation patterns for a one-rack station, and the worksheets already written — program chain inventory, port-forwarding audit, compliance memo, exception justification forms, patch log, credential and offboarding policy.