| NERC CIP Standards |
|
|
|
|
T he North American Electric Reliability Corporation (NERC) has developed Cyber Security standards addressing “critical cyber assets" associated with critical components of the Bulk Electric System. Collectively, these are referred to as NERC CIP Standards 002-009. The objective of these standards is to enforce the security of the bulk electric system by taking preventative measures to protect against and minimize cyber vulnerabilities.NERC CIP Standards 002-009 require that transmission owners, operators and generators of bulk power systems identify and document cyber risks and vulnerabilities, establish controls to secure critical cyber assets from physical and cyber sabotage; report security incidents, and establish plans for recovery in the event of an emergency. These utility organizations are responsible for compliance with CIP Standards 002-009. Non-compliance can result in penalties of up to $1 million per day, per violation. Current documentation of NERC CIP Standards 002-009 is available in our CIP Compliance Library. How USDN Can Assist Your Utility Organization with NERC CIP 002-009USDN has extensive experience with control system and SCADA network security audit. We work with electric transmission clients to develop viable controls, processes and audit mechanisms to ensure compliance with NERC CIP Security Standards CIP 002-009. Our experience with the testing of SCADA systems has involved live-fire exercises in conjunction with the Department of Energy.
USDN’S PerfectWitness IDSCompliance Monitoring, Insight and Management. PerfectWitness IDS offers simple, cost-effective monitoring and control of your SCADA and operational networks. Our appliance provides your organization with insight into its compliance with NERC CIP 002-009 security requirements through comprehensive real-time views of network security events, vulnerabilities and policy violations. Audit and ComplianceNERC CIP Standards 002-009 require that utilities demonstrate compliance in the form of documented evidence of processes and security controls. Management of evidentiary documentation will be a must for both initial and subsequent compliance audits. Although paper trails may adequately demonstrate compliance for some requirements, audit records generated electronically from Critical Cyber Assets will provide a more accurate, reliable, cost effective and efficient audit trail. PerfectWitness IDS captures and preserves historic packet-level information associated with security events, satisfying audit and compliance for NERC CIP Cyber Security Standards 002-009. Secure Preservation of DataPerfectWitness IDS stores data securely. Our appliance has been designed to ensure information can only be captured and not altered. Access is configurable, enabling individualized viewing privileges. Effective Security Monitoring and Targeted RemediationPerfectWitness IDS can be easily configured to monitor, detect and prioritize security events in accordance with NERC CIP requirements and security policies. Once PerfectWitness IDS is configured for your organization, its intuitive reporting module enables authorized personnel to easily see the highest priority items, escalate and resolve. Underlying packet-level data is captured, so you can effectively target your efforts and quickly determine the appropriate course of action. Our solution is scalable. Whether your operational network is large or small, PerfectWitness IDS will provide efficiency and free up your personnel to perform strategic objectives, target remediation efforts and not fight fires. Business InsightPerfectWitness IDS is not just an IT tool. Its powerful yet elegant executive reporting function synthesizes event findings and network activity to enable all levels of management to understand what the data means. Contact UsFor information about how USDN can assist your organization with its specific NERC CIP needs, please contact us at This e-mail address is being protected from spambots. You need JavaScript enabled to view it or call (866) 930-4312 (Toll Free). |



