© ABB | Slide 1 NERC CIP Version 5 webinar series “Access management and malicious software controls” 10/29/2014 October 29, 2014.

Slides:



Advertisements
Similar presentations
Confidential & Proprietary to Cooper Compliance Corporation Revised September 8, 2014 AUDiT-READY TM.
Advertisements

©EverFi, Inc. All rights reserved. Please Contact: Sarah Pratt Ponder EverFi provides FREE online platforms High School:
Brent Castagnetto Manager, Cyber Security Audits & Investigations Team CIP v5 Implementation Guidance CIP v5 Roadshow Salt Lake City, UT May 14-15, 2014.
CIP Spot Check Process Gary Campbell Manager of Compliance Audits ReliabilityFirst Corporation August, 2009.
Automation & Power World 2015 Harnessing the power of change March 2-5, 2015 | Houston, Texas.
PRODUCT FOCUS 5/27/14 – 6/6/14 INTRODUCTION Our Product Focus for the next two weeks is CompTIA. CompTIA is most well known for serving as the backbone.
Internal Audit Awareness
1 Compliance Guidance for Initial Compliance Review Dates Lew Folkerth 2Q2010 Webinar June 22, 2010.
Standards Certification Education & Training Publishing Conferences & Exhibits 2014 ISA Process Safety Control Symposium.
PRODUCT FOCUS 2/3/14 – 2/14/14 INTRODUCTION Our Product Focus for the next two weeks is VMware. VMware is the current industry leader in server / data.
PROJECT MANAGEMENT PRODUCT FOCUS 2/17/14 – 2/28/14.
CIP Version 5 Update OC Meeting November 7, 2013.
World Class Security Experts © Copyright 2004 SkyView Partners LLC. All rights reserved. How IT is affected by Sarbanes-Oxley Act.
Stephen S. Yau CSE , Fall Security Strategies.
Measuring the effectiveness of government IT systems Current ANAO initiatives to enhance IT Audit integration and support in delivering Audit outcomes.
NERC CIP Version 5 webinar series “Baseline management”
This presentation, including any supporting materials, is owned by Gartner, Inc. and/or its affiliates and is for the sole use of the intended Gartner.
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
Welcome to the Learning Community 2015 Roll out webinar Hosted by the Family Institute for Education, Practice & Research The webinar will begin shortly.
K E M A, I N C. NERC Cyber Security Standards and August 14 th Blackout Implications OSI PI User Group April 20, 2004 Joe Weiss
CIP 43 ReliabilityFirst Audit Observations ReliabilityFirst CIP Webinar Thursday, September 30, 2010 Tony Purgar, Sr. Consultant - Compliance.
Lisa Wood, CISA, CBRM, CBRA Compliance Auditor, Cyber Security
June-September 2009www.ihe.net IHE 2010 Educational Webinar Series Preparations for the 2010 N.A. Connectathon & HIMSS11 Interoperability Showcase
Implementing the New Reliability Standards Status of Draft Cyber Security Standards CIP through CIP Larry Bugh ECAR Standard Drafting Team.
Internal Control in a Financial Statement Audit
Security Trifecta – Overview of Vulnerabilities in the Racing Industry Gus Fritschie December 11, 2013.
SPP.org 1. EMS Users Group – CIP Standards The Compliance Audits Are Coming… Are You Ready?
FAFSA Collective Impact Initiative Professional Learning Community January 13, 2015.
Overview of WECC and Regulatory Structure
K E M A, I N C. Ten Steps To Secure Control Systems APPA 2005 Conference Session: Securing SCADA Networks from Cyber Attacks Memphis, TN April 18, 2005.
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
AREVA T&D Security Focus Group - 09/14/091 Security Focus Group A Vendor & Customer Collaboration EMS Users Conference September 14, 2009 Rich White AREVA.
2013 NPMA Fall Conference Value Through Professional Asset Management ISO 55000: First Steps Jim Dieter. MIAM, CPPM CF November 13, 2013.
Producing Quality Webinars: or If You Build It They Will Come Rebecca Daniel-Burke, PhD Director, Professional Projects & Career Services
Advanced Compliance Transport Resource Management Dean Baker Sales Director - TruTac Ltd.
Security Assessment Tools Paula Kiernan Senior Consultant Ward Solutions.
12 Steps to Cloud Security A guide to securing your Cloud Deployment Vishnu Vettrivel Principal Engineering Lead,
Employee Privacy at Risk? APPA Business & Financial Conference Austin, TX September 25, 2007 Scott Mix, CISSP Manager of Situation Awareness and Infrastructure.
Introduction: Information security services. We adhere to the strictest and most respected standards in the industry, including: -The National Institute.
Analysis & Presentation of Integrity Management Audit Results Western Regional Gas Conference August 21, 2007 Gary R. White.
HP OpenView eCare is a fast, efficient way to access always- on, interactive technical support tools needed to manage your business and ensure uptime.
FFIEC Cyber Security Assessment Tool
Information Security In the Corporate World. About Me Graduated from Utica College with a degree in Economic Crime Investigation (ECI) in Spring 2005.
IS2210: Systems Analysis and Systems Design and Change Twitter:
Information Security Measures Confidentiality IntegrityAccessibility Information cannot be available or disclosed to unauthorized persons, entities or.
HIPAA Compliance Case Study: Establishing and Implementing a Program to Audit HIPAA Compliance Drew Hunt Network Security Analyst Valley Medical Center.
“2014 Benchmark Survey Results” 2015 Quality Management Best Practice Series Friday, March 27, 2015.
Patricia Alafaireet  Lecture 2 – Implementation and go-live strategies Data conversion Communication Planning Downtime.
Updates from HDI Corporate April HDI Membership: Now More Connected Than Ever Connect and collaborate with professionals who share your goals and.
GPUG Membership Benefits Overview & Orientation By: Bob Buresh GPUG Membership Manager November 19, 2015 Broadcast Live Third Thursday Monthly: Next One.
@NAVUG Housekeeping Organizer will mute all lines during this presentation Use the Questions Box as a means to communicate with the organizer (feel free.
Building a Sound Security and Compliance Environment for Dynamics AX Frank Vukovits Dennis Christiansen Fastpath, Inc.
Public Tech Instruction: Internet Safety March 26, 2014.
@NAVUG. Objective: Build User Group Communities through engagement. Vision: Enable partners and their customers to enrich their lives and business success.
Welcome (we’ll begin momentarily) Partner Showcase: Keep it Simple - Advanced EDI Integration for GP by Data Masons Presented by: Glenn McPeak, Data Masons.
Who doesn’t need to be WISE? Bringing into reality global information security collaboration Alessandra Scicchitano GÉANT - Project Development Officer.
Talks! Acteva: Event Management Made Easy September 17, 2009 Audio is only available by calling this number: Conference Call: ; Access Code:
Information and Orientation Session
ALIEF U TRACKING FOR ADMINISTRATORS
In This Week’s “The EDGE”
Microsoft Dynamics GP User Group (GPUG®)
Leverage What’s Out There
DETAILED Global CYBERSECURITY SURVEY Summary RESULTS
Session title Sub headline
Understanding Existing Standards:
APW, now ABB Customer World
2014 ISA Process Safety Control Symposium
Cyber System-Centric Approach To Cyber Security and CIP
DegreeWorks Training Guide
In This Week’s “The EDGE”
Presentation transcript:

© ABB | Slide 1 NERC CIP Version 5 webinar series “Access management and malicious software controls” 10/29/2014 October 29, 2014

© ABB | Slide 2 Joseph Baxter CISSP/CISA/CISM/CGEIT/MCDBA/MCSE:S NERC CIP Lead – HVDC / FACTS (919) About the presenter(s) October 29, 2014 Before coming to ABB, Joseph Baxter completed several years as a NERC CIP Auditor for the SERC region, with special emphasis on the technical side of cyber security. He has both audited and been audited in the realm of CIP, and brings over fifteen years of Information Security experience gleaned from the Financial Sector to bear on the problems facing Grid Security today.

© ABB | Slide 3 Security programs October 29, 2014 Program, Plan, Policy, Process, Procedure, Practice  Don’t let NERC do this for you  This is your Cyber Security Program, not theirs - take control!  Separation of Duties and Reporting Structure legitimize this effort Risk Analysis Document Program Implement Controls Audit Controls Remediate Findings

© ABB | Slide 4 Quality evidence  Record (get it down)  Retrieve (find it fast)  Reference (do it once)  Report (show it well)  Repeat (keep it up) October 29, 2014 Documentation is king

© ABB | Slide 5 Audience question #1 October 29, 2014 Malicious Software Prevention

© ABB | Slide 6 Malicious code prevention October 29, 2014 A choice in strategy  Traditional antivirus  Requires processing power  Can corrupt databases  Requires constant update  Often falls into the category of “Cure more painful than the disease”

© ABB | Slide 7 Hardening vs Antivirus October 29, 2014 A 2x2 matrix choice  Answers are pretty obvious  However the question isn’t binary  A hybrid approach might work Antivirus Partial Coverage Antivirus Full Coverage Hardening Partial Coverage Hardening Full Coverage

© ABB | Slide 8 Hardening controls October 29, 2014 Out of the box  AppLocker in Active Directory + Group Policy Object lockdowns  AppArmor in Linux  Not comprehensive, but does it have to be?  Policy plays a role  What is really required?

© ABB | Slide 9 Audience question #2 October 29, 2014 Technical Feasibility Exceptions

© ABB | Slide 10 Access management October 29, 2014 A few changes for good  Nothing to see here…  Widely applicable to Highs and Mediums  Interactive User Access  Where Technically Feasible

© ABB | Slide 11 Remote access October 29, 2014 Line in the sand  Lots of confusion here  Keep the hot side hot  Keep the cold side cold  Multifactor requirements

© ABB | Slide 12 Cyber vulnerability assessments October 29, 2014 Had little to do with vulnerabilities  But now things are different  The word ‘vulnerability’ actually matters again  But that doesn’t have to be all it does  Check up on your Security Hardening Controls

© ABB | Slide 13 Questions? This is the point to review and answer any questions in the panel. If you have a question, please type your question in now. October 29, 2014

© ABB | Slide 14  Change management Wednesday, October 15, 2014 at 2:00 p.m. Learn about change management and the fact that this will be the largest area of recurring effort. You will gain understanding of why Patch Management is not a solution to meet your NERC CIP updates and why Version 3 no longer applies. Register now:  Baseline management Wednesday, October 22, 2014 at 2:00 p.m. Learn what a baseline and testing are, why automation is key and what is required to meet Version 5 compliance. Register now:  Cyber asset grouping Thursday, October 23, 2014 at 12:00 p.m. (Power generation specific) Learn process approaches to CIP R1 as it pertains to BES cyber asset categorization. Register now: Additional NERC CIP educational webinars October 29, 2014 (All webinars are Eastern Time)

© ABB | Slide 15  Access management and malicious software controls Wednesday, October 29, 2014 at 2:00 p.m. Learn how to access control fits with CIP and why account management is not effortless. Register now:  Low assets and future CIP versions Wednesday, November 5, 2014 at 2:00 p.m. (Power generation specific) Learn the compliance requirements for entities with low assets and audit worksheets as well as future standard activities. Register now:  Identification and review of critical transmission assets Wednesday, November 12, 2014 at 2:00 p.m. Learn how to approach the guidelines and criteria highlighted by NERC to fulfill the risk assessment goal. Register now: Additional NERC CIP educational webinars October 29, 2014 (All webinars are Eastern Time)

© ABB | Slide 16  Theme: Preparing for the power evolution  Date: November 6, 2014 – 11 a.m. – 6 p.m. EST  Why should you attend? 25 educational webinars, dozens of scheduled chats and interviews and more than 100 white papers available for download from knowledgeable subject matter experts.  Earn Professional Development Hours (PDH) Download an official attendance certificate for every live webinar session you attend to get credit for your learning time  No travel or registration costs!  Can’t attend the day of? That’s fine. All webinars will be recorded and will be available for on-demand viewing after the live event.  Register now: Automation & Power World (APW) October 29, 2014 Power SmartStream Digital Conference

© ABB | Slide 17  Theme: Harnessing the power of change  Date: March 2-5, 2015 in Houston, Texas  Location: George R. Brown Convention Center  Why should you attend?  Listen to interesting and topical keynote presentations  Chose from over 300 industry and solution-focused educational sessions and panel discussions  Network with ABB experts and your peers  Earn Professional Development Hours (PDH)  Completely free!  Check the website for updates: Automation & Power World (APW) October 29, 2014 LIVE conference – APW 2015

© ABB | Slide 18 Survey Please take a few moments to answer the survey questions. Thank you. October 29, 2014