Automating NERC CIP Compliance Georgia

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.

Local Companies

Wheelhouse Advisors LLC
404-805-9203
1170 Peachtree Street, NE
Atlanta, GA
Sequel Inc
(770) 418-1513
2765 Factor Walk Blvd
Suwanee, GA
Management Options Consulting Corp
(770) 422-7365
4214 Rockpoint Dr NW
Kennesaw, GA
Bradley Steven Associates
(706) 820-2639
13292 Scenic Hwy
Lookout Mountain, GA
Promaker Marketing
(770) 716-8420
525 Georgia Ave
Fayetteville, GA
Croye and Associates Inc
(678) 319-0633
5170 Courton St
Alpharetta, GA
Southern Mortgage and Realty
(706) 343-0085
115 W Jefferson St
Madison, GA
Charles Gilbert Associates
(770) 642-1704
Mtn Park
Atlanta, GA
Summit the Group Inc
(770) 935-0100
3805 Crestwood Pkwy NW
Duluth, GA
Executive Financial Solutions
(404) 876-9187
1720 Peachtree St NW
Atlanta, GA



By Tom Schmidt

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible. By minimizing error-prone manual processes, he explained, companies can eliminate the fragmentation and duplication of efforts to avoid deploying redundant or unnecessary solutions.

A recent study by the IT Policy Compliance Group vividly underscores the risks related to manual processes. According to the study:

"In one form or another, human error is the overwhelming cause of sensitive data loss, responsible for 75% of all occurrences. User error is directly responsible for one in every two cases, while violations of policy -- intended, accidental and inadvertent -- are responsible for one in every four cases." ("Taking Action to Protect Sensitive Data," February 2007)

This article looks at some of the challenges the electric power industry currently faces in improving cyber security, followed by an overview of the steps companies can take to automate NERC CIP compliance.

Cyber security challenges
Improving cyber security in the electric power industry is challenging for several reasons. Chief among them:

  • Increased interconnectivity SCADA/EMS and DCS systems were initially designed with efficiency and reliability -- rather than security -- in mind. These systems are increasingly being integrated with business information systems, thus introducing new vulnerabilities.
  • Remote access requirements At the same time, company engineers, contractors, and others require remote access to plant/power system control systems via modem or other means to maintain 24/7 operations. Unfortunately, this access introduces additional vulnerability points and could lead to the unleashing of viruses or malicious code within the control systems.
  • Nonstop operations The nonstop operational requirement of utility control systems complicates security implementation and testing because systems can never be taken offline.
  • Standardization The drive to improve operational efficiency and drive costs down is also leading to increasing standardization of control system technologies and use of off-the-shelf IT technologies. SCADA/EMS and DCS are increasingly implemented on Microsoft Windows and Linux operating system-based platforms. In parallel with this trend, technical information about these standards is increasingly available in trade journals and online, enabling would-be attackers to identify vulnerabilities that can be used to attack SCADA/EMS and DCS systems.
  • Shortage of resources Another significant challenge is the shortage of security resources in key areas of the electric power industry -- for example, in energy control centers. Most control centers are not staffed 24/7 with IT and security experts, and such staffing wouldn't be economically feasible. This complicates interpretation of security logs and other activities related to maintaining security around the clock.

Gearing up for NERC CIP compliance
Formidable as these challenges to enhancing security are, it is also the case that the need for security has never been more acute, especially now that it has been formalized as a regulatory requirement. In general, most electric power utilities are in the planning stages of compliance with NERC CIP. Compliance, needless to say, is a complex issue, touching on many areas of operation. For the sake of discussion, let's focus on automating the highly repetitive and manually intensive IT control-related portion of compliance. 

One reason automation has become critical is that auditors will demand proof of due care that IT security policies are sufficient, in place, and effective. Consider, too, this finding from that IT Policy Compliance Group study:

"A challenge uniquely found among the organizations with the fewest data losses is classifying data. Moreover, the prioritized responses being taken by the leaders are unlike all other organizations, and include ... automating IT controls and procedures for protecting sensitive data."

Conclusion
IT compliance is an ongoing process, not a one-time event, and it requires automation to reduce cost and inefficiencies. Moreover, much of the cost of compliance involves IT security tasks that require weekly or even daily activities. Many electric power companies are working on new and better methods for implementing these activities in order to reduce the costs of NERC CIP compliance and improve overall IT security.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

Wheelhouse Advisors LLC

404-805-9203
1170 Peachtree Street, NE
Atlanta, GA
www.WheelhouseAdvisors.com

Related Articles
- Business Networking Georgia
Whether you're looking for referral clients, qualified employees or a job, networking is an effective and low cost approach. Read on to learn about key networking methods and opportunities.
- Business Startup Georgia
- Corporate Retreats Georgia
- Corporate Relocation Georgia
- Corporate Gifts Georgia
- Human Resource Management Georgia
- Trade Show Booths Georgia
- Promotional Products Georgia
- Exhibitions Georgia
- Office Supplies Georgia
Regional Articles
- Automating NERC CIP Compliance Acworth GA
- Automating NERC CIP Compliance Albany GA
- Automating NERC CIP Compliance Alpharetta GA
- Automating NERC CIP Compliance Americus GA
- Automating NERC CIP Compliance Athens GA
- Automating NERC CIP Compliance Atlanta GA
- Automating NERC CIP Compliance Augusta GA
- Automating NERC CIP Compliance Austell GA
- Automating NERC CIP Compliance Baxley GA
- Automating NERC CIP Compliance Blairsville GA
- Automating NERC CIP Compliance Brunswick GA
- Automating NERC CIP Compliance Buford GA
- Automating NERC CIP Compliance Calhoun GA
- Automating NERC CIP Compliance Canton GA
- Automating NERC CIP Compliance Carrollton GA
- Automating NERC CIP Compliance Cartersville GA
- Automating NERC CIP Compliance Cedartown GA
- Automating NERC CIP Compliance Chatsworth GA
- Automating NERC CIP Compliance Columbus GA
- Automating NERC CIP Compliance Conyers GA
- Automating NERC CIP Compliance Cordele GA
- Automating NERC CIP Compliance Covington GA
- Automating NERC CIP Compliance Cumming GA
- Automating NERC CIP Compliance Dacula GA
- Automating NERC CIP Compliance Dahlonega GA
- Automating NERC CIP Compliance Dallas GA
- Automating NERC CIP Compliance Dalton GA
- Automating NERC CIP Compliance Dawsonville GA
- Automating NERC CIP Compliance Decatur GA
- Automating NERC CIP Compliance Douglas GA
- Automating NERC CIP Compliance Douglasville GA
- Automating NERC CIP Compliance Dublin GA
- Automating NERC CIP Compliance Duluth GA
- Automating NERC CIP Compliance Eatonton GA
- Automating NERC CIP Compliance Elberton GA
- Automating NERC CIP Compliance Ellenwood GA
- Automating NERC CIP Compliance Ellijay GA
- Automating NERC CIP Compliance Evans GA
- Automating NERC CIP Compliance Fairburn GA
- Automating NERC CIP Compliance Fayetteville GA
- Automating NERC CIP Compliance Fitzgerald GA
- Automating NERC CIP Compliance Flowery Branch GA
- Automating NERC CIP Compliance Forest Park GA
- Automating NERC CIP Compliance Fort Benning GA
- Automating NERC CIP Compliance Fort Valley GA
- Automating NERC CIP Compliance Gainesville GA
- Automating NERC CIP Compliance Griffin GA
- Automating NERC CIP Compliance Grovetown GA
- Automating NERC CIP Compliance Hartwell GA
- Automating NERC CIP Compliance Hephzibah GA
- Automating NERC CIP Compliance Hinesville GA
- Automating NERC CIP Compliance Jesup GA
- Automating NERC CIP Compliance Jonesboro GA
- Automating NERC CIP Compliance Kennesaw GA
- Automating NERC CIP Compliance Kingsland GA
- Automating NERC CIP Compliance La Fayette GA
- Automating NERC CIP Compliance Lagrange GA
- Automating NERC CIP Compliance Lawrenceville GA
- Automating NERC CIP Compliance Lilburn GA
- Automating NERC CIP Compliance Lithia Springs GA
- Automating NERC CIP Compliance Lithonia GA
- Automating NERC CIP Compliance Loganville GA
- Automating NERC CIP Compliance Mableton GA
- Automating NERC CIP Compliance Macon GA
- Automating NERC CIP Compliance Marietta GA
- Automating NERC CIP Compliance Mcdonough GA
- Automating NERC CIP Compliance Milledgeville GA
- Automating NERC CIP Compliance Monroe GA
- Automating NERC CIP Compliance Morrow GA
- Automating NERC CIP Compliance Moultrie GA
- Automating NERC CIP Compliance Newnan GA
- Automating NERC CIP Compliance Norcross GA
- Automating NERC CIP Compliance Peachtree City GA
- Automating NERC CIP Compliance Powder Springs GA
- Automating NERC CIP Compliance Ringgold GA
- Automating NERC CIP Compliance Riverdale GA
- Automating NERC CIP Compliance Rockmart GA
- Automating NERC CIP Compliance Rome GA
- Automating NERC CIP Compliance Rossville GA
- Automating NERC CIP Compliance Roswell GA
- Automating NERC CIP Compliance Saint Simons Island GA
- Automating NERC CIP Compliance Savannah GA
- Automating NERC CIP Compliance Sharpsburg GA
- Automating NERC CIP Compliance Smyrna GA
- Automating NERC CIP Compliance Snellville GA
- Automating NERC CIP Compliance Statesboro GA
- Automating NERC CIP Compliance Stockbridge GA
- Automating NERC CIP Compliance Stone Mountain GA
- Automating NERC CIP Compliance Suwanee GA
- Automating NERC CIP Compliance Thomaston GA
- Automating NERC CIP Compliance Thomasville GA
- Automating NERC CIP Compliance Thomson GA
- Automating NERC CIP Compliance Tifton GA
- Automating NERC CIP Compliance Toccoa GA
- Automating NERC CIP Compliance Tucker GA
- Automating NERC CIP Compliance Valdosta GA
- Automating NERC CIP Compliance Vidalia GA
- Automating NERC CIP Compliance Villa Rica GA
- Automating NERC CIP Compliance Warner Robins GA
- Automating NERC CIP Compliance Waycross GA
- Automating NERC CIP Compliance Winder GA
- Automating NERC CIP Compliance Woodstock GA
Related Articles
- Human Resource Management Georgia
HR Management is increasingly challenging in today's complex business environment. For this reason HR managers must be comfortable with a variety of disciplines even if they're not solely responsible.
- Corporate Relocation Georgia
- Trade Show Booths Georgia
- Corporate Retreats Georgia
- Business Networking Georgia
- Promotional Products Georgia
- Office Supplies Georgia
- Business Startup Georgia
- Exhibitions Georgia
- Corporate Gifts Georgia

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History