WebCast 5 May 2003 Proposed NERC Cyber Security Standard Presentation to IT Standing Committee Stuart Brindley, IMO May 26, 2003.

Slides:



Advertisements
Similar presentations
NERC Policies Introduction
Advertisements

Federal Energy Regulatory Commission July Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
NERC Critical Infrastructure Protection Advisory Group (CIP AG) Electric Industry Initiatives Reducing Vulnerability To Terrorism.
Homeland Security at the FCC July 10, FCCs Homeland Security Focus Interagency Partnerships Industry Partnerships Infrastructure Protection Communications.
Recent NERC Standards Activities RSC – Jan. 5, 2011 NSRS Update Date Meeting Title (optional)
Gcpud1 CRITICAL INFRASTRUCTURE PROTECTION NERC 1200 CIP CRITICAL INFRASTRUCTURE PROTECTION NERC 1200 CIP
Standards Development: Update to IMO Regulatory Standing Committee May 14, 2003.
WebCast 5 May 2003 NERC Cyber Security Standard Overview of Proposed Cyber Security Standard.
Cyber Security 2005 ERCOT COMPLIANCE ROLLOUT Lane Robinson Reliability Analyst.
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
NERC and Regional Efforts to Ensure Reliability Dave Nevius, NERC Sr. VP David Cook, NERC VP & General Counsel Louise McCarren, WECC CEO Don Benjamin,
Critical Infrastructure Interdependencies H. Scott Matthews March 30, 2004.
Jeffery J. Gust IOWA INDUSTRIAL ENERGY GROUP FALL CONFERENCE Tuesday, October 14, 2014 MidAmerican Energy Company.
NIST framework vs TENACE Protect Function (Sestriere, Gennaio 2015)
Physical Security CIP NERC Standing Committees December 9-10, 2014.
+ PROJECT BACKGROUND: KENYA THE NEED FOR CONSUMER PARTICIPATION IN THE REFORMS PROCESS OF THE ELECTRICTY SUB-SECTOR Susanne Rabisch, CUTS Nairobi.
K E M A, I N C. Current Status of Cyber Security Issues 2004 Keynote Address Joe Weiss January 20, 2004.
A project under the 7th Framework Programme CPS Workshop Stockholm 12/04/2010 Gunnar Björkman Project Coordinator A Security Project for the Protection.
June 6, 2007 TAC Meeting NERC Registration Issues Andrew Gallo, Assistant General Counsel, Litigation and Business Operations ERCOT Legal Dept.
Ontario Overview Dave Short Senior Regulatory Analyst, Regulatory Affairs IESO’s ERO Workshop – June 28, 2006.
GOP and QSE Relationship Jeff Whitmer Manager, Compliance Assessments Talk with Texas RE June 25, 2012.
K E M A, I N C. NERC Cyber Security Standards and August 14 th Blackout Implications OSI PI User Group April 20, 2004 Joe Weiss
Lisa Wood, CISA, CBRM, CBRA Compliance Auditor, Cyber Security
Applying the Distribution System in Grid Restoration/NERC CIP-014 Risk Assessment Srijib Mukherjee, Ph.D., P.E. UC Synergetic.
Federal Energy Regulatory Commission June Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation - ERO Perspective David R. Nevius and Michael J. Assante 2009 NRC Regulatory.
Implementing the New Reliability Standards Status of Draft Cyber Security Standards CIP through CIP Larry Bugh ECAR Standard Drafting Team.
CIPC Executive Committee Update CIPC Meeting Denver CO September 29, 2005 Stuart Brindley CIPC Chair Public Release.
Actions Affecting ERCOT Resulting From The Northeast Blackout ERCOT Board Of Directors Meeting April 20, 2004 Sam Jones, COO.
NATO Advanced Research Workshop “Best Practices and Innovative Approaches to Develop Cyber Security and Resiliency Policy Framework” Scenario for Discussion.
Supervision of Information Security and Technology Risk Barbara Yelcich, Federal Reserve Bank of New York Presentation to the World Bank September 10,
Overview of WECC and Regulatory Structure
K E M A, I N C. Ten Steps To Secure Control Systems APPA 2005 Conference Session: Securing SCADA Networks from Cyber Attacks Memphis, TN April 18, 2005.
Status Report for Critical Infrastructure Protection Advisory Group
1 Smart Grid Cyber Security Annabelle Lee Senior Cyber Security Strategist Computer Security Division National Institute of Standards and Technology June.
FCC Field Hearing on Energy and the Environment Monday November 30, 2009 MIT Stratton Student Center, Twenty Chimneys Peter Brandien, Vice President System.
Role for Electric Sector in Critical Infrastructure Protection R&D Presented to NERC CIPC Washington D.C. June 9, 2005 Bill Muston Public Release.
Project (COM-001-3) Interpersonal Communications Capabilities Michael Cruz-Montes, CenterPoint Energy Senior Consultant, Policy & Compliance, SDT.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
NERC Reliability Standards - Development Process: Involvement & Needs Presentation to MOSC January 14, 2004 Khaqan Khan Independent Electricity Market.
Generation assets important to the reliable operation of the Bulk Electric System What does this mean?
The Electric Reliability Organization: Getting from here to there. Gerry Cauley Director, Standards ERO Project Manager ERO Slippery Slope NERC Today Uphill.
International Telecommunication Union Geneva, 9(pm)-10 February 2009 BEST PRACTICES FOR ORGANIZING NATIONAL CYBERSECURITY EFFORTS James Ennis US Department.
September 25, 2008 Public ERCOT Critical Infrastructure Protection Advisory Group (CIP AG) TASOR TF Update Jim Brenton, CISSP CISM Director of Security.
Project – Alignment of Terms WECC Joint Meeting July 15, 2015.
Standing Up The New Electric Reliability Organization Ellen P. Vancko North American Electric Reliability Council.
NERC and ESISAC Electricity Sector Information Sharing and Analysis Center Update March 2006 CIPC Confidentiality: Public Release.
November 2, 2006 LESSONS FROM CIPAG 1 Lessons from Critical Infrastructure Group Bill Bojorquez November 2, 2006.
What is “national security”?  No longer defined only by threat of arms  It really is the economy  Infrastructure not controlled by the government.
1 Thoughts on ERCOT-Wide Critical Infrastructure Protection Committee Bill Muston October 31, 2006.
Grid Operations Report To ERCOT Board Of Directors December 16, 2003 Sam Jones, COO.
Information Security Measures Confidentiality IntegrityAccessibility Information cannot be available or disclosed to unauthorized persons, entities or.
ERCOT IT Update Ken Shoquist VP, CIO Information Technology Board Meeting February 2004.
Sicherheitsaspekte beim Betrieb von IT-Systemen Christian Leichtfried, BDE Smart Energy IBM Austria December 2011.
Reliability and the Market Place Perfect Together The Transition from NERC to NAERO Baltics Working Group June 6, 2001 Princeton, NJ The Transition from.
INFORMATION ASSURANCE POLICY. Information Assurance Information operations that protect and defend information and information systems by ensuring their.
March 23, 2015 Missouri Public Service Commission | Jefferson City, MO.
Colonel Chaipun Nilvises Deputy Director, Office of ASEAN Affairs Office of Policy and Planning Ministry of Defence of Thailand.
Aaron Clark-Ginsberg and Rebecca Slayton
Agenda Control systems defined
ERCOT Technical Advisory Committee June 2, 2005
NERC Cyber Security Standards Pre-Ballot Review
Understanding Existing Standards:
Role for Electric Sector in Critical Infrastructure Protection R&D
NERC Critical Infrastructure Protection Advisory Group (CIP AG)
NERC Cyber Security Standard
The Electric Reliability Organization: Getting from here to there.
Larry Bugh ECAR Standard Drafting Team Chair June 1, 2005
CIPC Executive Committee Update
Cyber Security in a Risk Management Framework
Presentation transcript:

WebCast 5 May 2003 Proposed NERC Cyber Security Standard Presentation to IT Standing Committee Stuart Brindley, IMO May 26, 2003

AGENDA Why A Cyber Security Standard Is Needed Why Initiate An Urgent Action Standard Scope Of The Proposed Cyber Security Standard What Is Not In The Scope Compliance The Future For The Cyber Security Standard Q&A

Why A Cyber Security Standard Is Needed Due Diligence Responsibility to Stakeholders Responsibility to Interdependent Critical Infrastructures Industry Defined Practices If the Electricity Sector is not able to self- regulate, the federal government will regulate for us.

Why Initiate An Urgent Action Standard There has been a rapid increase in the number of reported cyber security incidents January 2003 SQL Slammer Worm Impacted Electricity Sector organizations March 2003 Federal Advisory regarding foreign attack scenarios Weakest Link Principle - The bulk electric system is highly inter- connected, a vulnerability for one can be a vulnerability for all

Why Initiate An Urgent Action Standard “A spectrum of malicious actors can and do conduct attacks against our critical information infrastructures. Of primary concern is the threat of organized cyber attacks capable of causing debilitating disruption to our Nation’s critical infrastructures, economy, or national security.” The National Strategy to Secure Cyberspace, The President’s Critical Infrastructure Protection Board, February 2003

Scope Of The Proposed Standard Applies to Reliability Authority, Balancing Authority, Interchange Authority, Transmission Service Provider, Transmission Operator, Generator, or Load-Serving Entity functions that manage Critical Cyber Assets. Critical Cyber Assets are those computers, including software and data, and communication networks that support, operate, or otherwise interact with the bulk electric system operations.

Scope Of The Proposed Standard Requires: Establishing a Cyber Security Program Policy and Procedures Identify Accountable Management Identifying/Documenting Critical Cyber Assets Defining/Implementing Electronic – Security Perimeters Access Controls Monitoring Controls

Scope Of The Proposed Standard Requires: (Cont.) Defining/Implementing Physical – Security Perimeters Access Controls Monitoring Controls Defining/Implementing Personnel Authorization Controls Security Awareness Training Information Protection Controls

Scope Of The Proposed Standard Requires: (Cont.) Cyber System Management Controls Cyber System Test Procedures Incident Response and Reporting for Cyber and Physical Security Recovery Planning

What Is Not In The Scope The definition of Critical Cyber Assets currently does not include process control systems, distributed control systems, or electronic relays installed in generating stations, switching stations and substations. Does not include cyber assets that otherwise support, operate, or interact with market operations.

Compliance Compliance is managed by the Regions There will be a self-certification process No financial penalties – letters only Acknowledgement of partial compliance acceptable for January 2004 Full compliance by January 2005

The Future Current review period ends May 11, 23:59 EDT Voting runs from May 12, 00:01 EDT to May 21, 23:59 EDT Requires 2/3 majority to pass If passed, it will be submitted to Board of Trustees at their June 10 meeting The Urgent Action standard expires after one year – a one year extension is possible

The Future Formal process to develop the permanent standard was initiated by CIPAG on May 2, Development will take at least a year The permanent standard will have two separate review and comment cycles – One to refine/finalize SAR requirements One to refine/finalize drafted standard

What does this Mean in the Ontario Market ? Components required to support the real-time transfer of RTU system management information between generators and transmitters, and grid operations Critical SCADA systems used to control certain generating and transmission stations Generation dispatch communications Infrastructure components that support functionality in 1, 2, and 3, above (Internet connections, frame relay networks, etc.)

What does this Mean in the Ontario Market ?