Automating NERC CIP Compliance Florida

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.

Local Companies

Sunera LLC
813-541-9361
777 S. Harbour Island Blvd.
Tampa, FL
Avacuna LLC
954-719-5126
6308 La Costa Drive Ste D
Boca Raton, FL
Lagrasso Management
(561) 364-2791
3501 W Boynton Beach Blvd
Boynton Beach, FL
Shulman Marvin Inc
(786) 276-9300
90 Alton Rd
Miami Beach, FL
Katral Consulting Group
(954) 349-1281
1051 Fairfax Ln
Weston, FL
Axum Management Capabilities
(954) 742-9166
2571 NW 87th Ln
Sunrise, FL
Polaris Group
(813) 886-6500
5431 Nellie Davis Ln
Tampa, FL
Sporty's Bar-Codes Prtnr
(863) 859-3300
7301 US Highway 98 N
Lakeland, FL
Isg Resources Inc
(352) 365-6166
5634 E Harbor Dr
Fruitland Park, FL
Debt Management Foundation Services
(727) 536-2456
13553 66th St
Largo, FL



By Tom Schmidt

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible. By minimizing error-prone manual processes, he explained, companies can eliminate the fragmentation and duplication of efforts to avoid deploying redundant or unnecessary solutions.

A recent study by the IT Policy Compliance Group vividly underscores the risks related to manual processes. According to the study:

"In one form or another, human error is the overwhelming cause of sensitive data loss, responsible for 75% of all occurrences. User error is directly responsible for one in every two cases, while violations of policy -- intended, accidental and inadvertent -- are responsible for one in every four cases." ("Taking Action to Protect Sensitive Data," February 2007)

This article looks at some of the challenges the electric power industry currently faces in improving cyber security, followed by an overview of the steps companies can take to automate NERC CIP compliance.

Cyber security challenges
Improving cyber security in the electric power industry is challenging for several reasons. Chief among them:

  • Increased interconnectivity SCADA/EMS and DCS systems were initially designed with efficiency and reliability -- rather than security -- in mind. These systems are increasingly being integrated with business information systems, thus introducing new vulnerabilities.
  • Remote access requirements At the same time, company engineers, contractors, and others require remote access to plant/power system control systems via modem or other means to maintain 24/7 operations. Unfortunately, this access introduces additional vulnerability points and could lead to the unleashing of viruses or malicious code within the control systems.
  • Nonstop operations The nonstop operational requirement of utility control systems complicates security implementation and testing because systems can never be taken offline.
  • Standardization The drive to improve operational efficiency and drive costs down is also leading to increasing standardization of control system technologies and use of off-the-shelf IT technologies. SCADA/EMS and DCS are increasingly implemented on Microsoft Windows and Linux operating system-based platforms. In parallel with this trend, technical information about these standards is increasingly available in trade journals and online, enabling would-be attackers to identify vulnerabilities that can be used to attack SCADA/EMS and DCS systems.
  • Shortage of resources Another significant challenge is the shortage of security resources in key areas of the electric power industry -- for example, in energy control centers. Most control centers are not staffed 24/7 with IT and security experts, and such staffing wouldn't be economically feasible. This complicates interpretation of security logs and other activities related to maintaining security around the clock.

Gearing up for NERC CIP compliance
Formidable as these challenges to enhancing security are, it is also the case that the need for security has never been more acute, especially now that it has been formalized as a regulatory requirement. In general, most electric power utilities are in the planning stages of compliance with NERC CIP. Compliance, needless to say, is a complex issue, touching on many areas of operation. For the sake of discussion, let's focus on automating the highly repetitive and manually intensive IT control-related portion of compliance. 

One reason automation has become critical is that auditors will demand proof of due care that IT security policies are sufficient, in place, and effective. Consider, too, this finding from that IT Policy Compliance Group study:

"A challenge uniquely found among the organizations with the fewest data losses is classifying data. Moreover, the prioritized responses being taken by the leaders are unlike all other organizations, and include ... automating IT controls and procedures for protecting sensitive data."

Conclusion
IT compliance is an ongoing process, not a one-time event, and it requires automation to reduce cost and inefficiencies. Moreover, much of the cost of compliance involves IT security tasks that require weekly or even daily activities. Many electric power companies are working on new and better methods for implementing these activities in order to reduce the costs of NERC CIP compliance and improve overall IT security.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

Sunera LLC

Sunera is a business and technology risk advisory consulting firm.

813-541-9361
777 S. Harbour Island Blvd.
Tampa, FL
www.sunera.com

Sunera is a leading provider of business and technology risk management and consulting services throughout the United States and Canada. Our partners and professionals are dedicated to helping organizations achieve and sustain cost-effective corporate governance.


Regional Articles
- Automating NERC CIP Compliance Altamonte Springs FL
- Automating NERC CIP Compliance Apopka FL
- Automating NERC CIP Compliance Arcadia FL
- Automating NERC CIP Compliance Atlantic Beach FL
- Automating NERC CIP Compliance Auburndale FL
- Automating NERC CIP Compliance Avon Park FL
- Automating NERC CIP Compliance Bartow FL
- Automating NERC CIP Compliance Belle Glade FL
- Automating NERC CIP Compliance Boca Raton FL
- Automating NERC CIP Compliance Bonita Springs FL
- Automating NERC CIP Compliance Boynton Beach FL
- Automating NERC CIP Compliance Bradenton FL
- Automating NERC CIP Compliance Brandon FL
- Automating NERC CIP Compliance Brooksville FL
- Automating NERC CIP Compliance Cantonment FL
- Automating NERC CIP Compliance Cape Coral FL
- Automating NERC CIP Compliance Casselberry FL
- Automating NERC CIP Compliance Chipley FL
- Automating NERC CIP Compliance Clearwater FL
- Automating NERC CIP Compliance Clermont FL
- Automating NERC CIP Compliance Clewiston FL
- Automating NERC CIP Compliance Cocoa Beach FL
- Automating NERC CIP Compliance Cocoa FL
- Automating NERC CIP Compliance Crawfordville FL
- Automating NERC CIP Compliance Crestview FL
- Automating NERC CIP Compliance Crystal River FL
- Automating NERC CIP Compliance Dade City FL
- Automating NERC CIP Compliance Dania FL
- Automating NERC CIP Compliance Daytona Beach FL
- Automating NERC CIP Compliance Debary FL
- Automating NERC CIP Compliance Deerfield Beach FL
- Automating NERC CIP Compliance Defuniak Springs FL
- Automating NERC CIP Compliance Deland FL
- Automating NERC CIP Compliance Delray Beach FL
- Automating NERC CIP Compliance Deltona FL
- Automating NERC CIP Compliance Destin FL
- Automating NERC CIP Compliance Dunedin FL
- Automating NERC CIP Compliance Dunnellon FL
- Automating NERC CIP Compliance Englewood FL
- Automating NERC CIP Compliance Eustis FL
- Automating NERC CIP Compliance Fernandina Beach FL
- Automating NERC CIP Compliance Fort Lauderdale FL
- Automating NERC CIP Compliance Fort Myers FL
- Automating NERC CIP Compliance Fort Pierce FL
- Automating NERC CIP Compliance Fort Walton Beach FL
- Automating NERC CIP Compliance Gainesville FL
- Automating NERC CIP Compliance Green Cove Springs FL
- Automating NERC CIP Compliance Gulf Breeze FL
- Automating NERC CIP Compliance Haines City FL
- Automating NERC CIP Compliance Hallandale FL
- Automating NERC CIP Compliance Hialeah FL
- Automating NERC CIP Compliance Hobe Sound FL
- Automating NERC CIP Compliance Holiday FL
- Automating NERC CIP Compliance Hollywood FL
- Automating NERC CIP Compliance Homestead FL
- Automating NERC CIP Compliance Homosassa FL
- Automating NERC CIP Compliance Hudson FL
- Automating NERC CIP Compliance Immokalee FL
- Automating NERC CIP Compliance Inverness FL
- Automating NERC CIP Compliance Jacksonville Beach FL
- Automating NERC CIP Compliance Jacksonville FL
- Automating NERC CIP Compliance Jensen Beach FL
- Automating NERC CIP Compliance Jupiter FL
- Automating NERC CIP Compliance Key West FL
- Automating NERC CIP Compliance Kissimmee FL
- Automating NERC CIP Compliance Labelle FL
- Automating NERC CIP Compliance Lady Lake FL
- Automating NERC CIP Compliance Lake City FL
- Automating NERC CIP Compliance Lake Mary FL
- Automating NERC CIP Compliance Lake Placid FL
- Automating NERC CIP Compliance Lake Wales FL
- Automating NERC CIP Compliance Lake Worth FL
- Automating NERC CIP Compliance Lakeland FL
- Automating NERC CIP Compliance Land O Lakes FL
- Automating NERC CIP Compliance Largo FL
- Automating NERC CIP Compliance Leesburg FL
- Automating NERC CIP Compliance Lehigh Acres FL
- Automating NERC CIP Compliance Live Oak FL
- Automating NERC CIP Compliance Longwood FL
- Automating NERC CIP Compliance Loxahatchee FL
- Automating NERC CIP Compliance Lutz FL
- Automating NERC CIP Compliance Lynn Haven FL
- Automating NERC CIP Compliance Marco Island FL
- Automating NERC CIP Compliance Marianna FL
- Automating NERC CIP Compliance Melbourne FL
- Automating NERC CIP Compliance Merritt Island FL
- Automating NERC CIP Compliance Miami Beach FL
- Automating NERC CIP Compliance Miami FL
- Automating NERC CIP Compliance Miami Lakes FL
- Automating NERC CIP Compliance Middleburg FL
- Automating NERC CIP Compliance Milton FL
- Automating NERC CIP Compliance Miramar FL
- Automating NERC CIP Compliance Mount Dora FL
- Automating NERC CIP Compliance Mulberry FL
- Automating NERC CIP Compliance Naples FL
- Automating NERC CIP Compliance Navarre FL
- Automating NERC CIP Compliance New Port Richey FL
- Automating NERC CIP Compliance New Smyrna Beach FL
- Automating NERC CIP Compliance Niceville FL
- Automating NERC CIP Compliance Nokomis FL
- Automating NERC CIP Compliance North Fort Myers FL
- Automating NERC CIP Compliance North Miami Beach FL
- Automating NERC CIP Compliance North Palm Beach FL
- Automating NERC CIP Compliance North Port FL
- Automating NERC CIP Compliance Ocala FL
- Automating NERC CIP Compliance Ocoee FL
- Automating NERC CIP Compliance Okeechobee FL
- Automating NERC CIP Compliance Oldsmar FL
- Automating NERC CIP Compliance Opa Locka FL
- Automating NERC CIP Compliance Orange City FL
- Automating NERC CIP Compliance Orange Park FL
- Automating NERC CIP Compliance Orlando FL
- Automating NERC CIP Compliance Ormond Beach FL
- Automating NERC CIP Compliance Oviedo FL
- Automating NERC CIP Compliance Palatka FL
- Automating NERC CIP Compliance Palm Bay FL
- Automating NERC CIP Compliance Palm Beach FL
- Automating NERC CIP Compliance Palm Beach Gardens FL
- Automating NERC CIP Compliance Palm City FL
- Automating NERC CIP Compliance Palm Coast FL
- Automating NERC CIP Compliance Palm Harbor FL
- Automating NERC CIP Compliance Palmetto FL
- Automating NERC CIP Compliance Panama City Beach FL
- Automating NERC CIP Compliance Panama City FL
- Automating NERC CIP Compliance Pembroke Pines FL
- Automating NERC CIP Compliance Pensacola FL
- Automating NERC CIP Compliance Pinellas Park FL
- Automating NERC CIP Compliance Plant City FL
- Automating NERC CIP Compliance Pompano Beach FL
- Automating NERC CIP Compliance Ponte Vedra Beach FL
- Automating NERC CIP Compliance Port Charlotte FL
- Automating NERC CIP Compliance Port Orange FL
- Automating NERC CIP Compliance Port Richey FL
- Automating NERC CIP Compliance Port Saint Lucie FL
- Automating NERC CIP Compliance Punta Gorda FL
- Automating NERC CIP Compliance Riverview FL
- Automating NERC CIP Compliance Rockledge FL
- Automating NERC CIP Compliance Safety Harbor FL
- Automating NERC CIP Compliance Saint Augustine FL
- Automating NERC CIP Compliance Saint Cloud FL
- Automating NERC CIP Compliance Saint Petersburg FL
- Automating NERC CIP Compliance Sanford FL
- Automating NERC CIP Compliance Sarasota FL
- Automating NERC CIP Compliance Satellite Beach FL
- Automating NERC CIP Compliance Sebastian FL
- Automating NERC CIP Compliance Sebring FL
- Automating NERC CIP Compliance Seffner FL
- Automating NERC CIP Compliance Seminole FL
- Automating NERC CIP Compliance Spring Hill FL
- Automating NERC CIP Compliance Starke FL
- Automating NERC CIP Compliance Stuart FL
- Automating NERC CIP Compliance Summerfield FL
- Automating NERC CIP Compliance Sun City Center FL
- Automating NERC CIP Compliance Tallahassee FL
- Automating NERC CIP Compliance Tampa FL
- Automating NERC CIP Compliance Tarpon Springs FL
- Automating NERC CIP Compliance Titusville FL
- Automating NERC CIP Compliance Valrico FL
- Automating NERC CIP Compliance Venice FL
- Automating NERC CIP Compliance Vero Beach FL
- Automating NERC CIP Compliance Wauchula FL
- Automating NERC CIP Compliance Wesley Chapel FL
- Automating NERC CIP Compliance West Palm Beach FL
- Automating NERC CIP Compliance Winter Garden FL
- Automating NERC CIP Compliance Winter Haven FL
- Automating NERC CIP Compliance Winter Park FL
- Automating NERC CIP Compliance Winter Springs FL
- Automating NERC CIP Compliance Zephyrhills FL

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History