Automating NERC CIP Compliance Maryland

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.

Local Companies

Powers Home Management Corp
(410) 496-0766
4230 Herrera Ct
Randallstown, MD
Fse
(301) 762-0387
Rockville, MD
Phoenix Health Systems Inc
(301) 869-7300
9200 Wightman Rd
Montgomery Village, MD
Pinnacle Associate Inc
(301) 946-0960
12707 Parkland Dr
Rockville, MD
Management Consulting Group Llc the
(410) 778-7000
10182 Forrest Ln
Chestertown, MD
Kotzker Law Office
(301) 260-2810
3300 Olney Sandy Spring R
Olney, MD
The Cib Group Llc
(410) 366-3433
619 Stoney Spring Dr
Baltimore, MD
Beacon Associates
(410) 638-7279
900 S Main St
Bel Air, MD
Ocf Environmental Consulting Llc
(410) 654-5759
11155 Dolfield Blvd
Owings Mills, MD
Houston McCreary & Assoc Inc
(301) 499-2377
7108 Valley Park Rd
Capitol Heights, MD



By Tom Schmidt

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible. By minimizing error-prone manual processes, he explained, companies can eliminate the fragmentation and duplication of efforts to avoid deploying redundant or unnecessary solutions.

A recent study by the IT Policy Compliance Group vividly underscores the risks related to manual processes. According to the study:

"In one form or another, human error is the overwhelming cause of sensitive data loss, responsible for 75% of all occurrences. User error is directly responsible for one in every two cases, while violations of policy -- intended, accidental and inadvertent -- are responsible for one in every four cases." ("Taking Action to Protect Sensitive Data," February 2007)

This article looks at some of the challenges the electric power industry currently faces in improving cyber security, followed by an overview of the steps companies can take to automate NERC CIP compliance.

Cyber security challenges
Improving cyber security in the electric power industry is challenging for several reasons. Chief among them:

  • Increased interconnectivity SCADA/EMS and DCS systems were initially designed with efficiency and reliability -- rather than security -- in mind. These systems are increasingly being integrated with business information systems, thus introducing new vulnerabilities.
  • Remote access requirements At the same time, company engineers, contractors, and others require remote access to plant/power system control systems via modem or other means to maintain 24/7 operations. Unfortunately, this access introduces additional vulnerability points and could lead to the unleashing of viruses or malicious code within the control systems.
  • Nonstop operations The nonstop operational requirement of utility control systems complicates security implementation and testing because systems can never be taken offline.
  • Standardization The drive to improve operational efficiency and drive costs down is also leading to increasing standardization of control system technologies and use of off-the-shelf IT technologies. SCADA/EMS and DCS are increasingly implemented on Microsoft Windows and Linux operating system-based platforms. In parallel with this trend, technical information about these standards is increasingly available in trade journals and online, enabling would-be attackers to identify vulnerabilities that can be used to attack SCADA/EMS and DCS systems.
  • Shortage of resources Another significant challenge is the shortage of security resources in key areas of the electric power industry -- for example, in energy control centers. Most control centers are not staffed 24/7 with IT and security experts, and such staffing wouldn't be economically feasible. This complicates interpretation of security logs and other activities related to maintaining security around the clock.

Gearing up for NERC CIP compliance
Formidable as these challenges to enhancing security are, it is also the case that the need for security has never been more acute, especially now that it has been formalized as a regulatory requirement. In general, most electric power utilities are in the planning stages of compliance with NERC CIP. Compliance, needless to say, is a complex issue, touching on many areas of operation. For the sake of discussion, let's focus on automating the highly repetitive and manually intensive IT control-related portion of compliance. 

One reason automation has become critical is that auditors will demand proof of due care that IT security policies are sufficient, in place, and effective. Consider, too, this finding from that IT Policy Compliance Group study:

"A challenge uniquely found among the organizations with the fewest data losses is classifying data. Moreover, the prioritized responses being taken by the leaders are unlike all other organizations, and include ... automating IT controls and procedures for protecting sensitive data."

Conclusion
IT compliance is an ongoing process, not a one-time event, and it requires automation to reduce cost and inefficiencies. Moreover, much of the cost of compliance involves IT security tasks that require weekly or even daily activities. Many electric power companies are working on new and better methods for implementing these activities in order to reduce the costs of NERC CIP compliance and improve overall IT security.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Regional Articles
- Automating NERC CIP Compliance Annapolis MD
- Automating NERC CIP Compliance Baltimore MD
- Automating NERC CIP Compliance Bel Air MD
- Automating NERC CIP Compliance Beltsville MD
- Automating NERC CIP Compliance Bethesda MD
- Automating NERC CIP Compliance Bowie MD
- Automating NERC CIP Compliance Brooklyn MD
- Automating NERC CIP Compliance Capitol Heights MD
- Automating NERC CIP Compliance Catonsville MD
- Automating NERC CIP Compliance Chevy Chase MD
- Automating NERC CIP Compliance Clinton MD
- Automating NERC CIP Compliance Cockeysville MD
- Automating NERC CIP Compliance College Park MD
- Automating NERC CIP Compliance Columbia MD
- Automating NERC CIP Compliance Crofton MD
- Automating NERC CIP Compliance Cumberland MD
- Automating NERC CIP Compliance Derwood MD
- Automating NERC CIP Compliance District Heights MD
- Automating NERC CIP Compliance Dundalk MD
- Automating NERC CIP Compliance Edgewood MD
- Automating NERC CIP Compliance Elkridge MD
- Automating NERC CIP Compliance Elkton MD
- Automating NERC CIP Compliance Ellicott City MD
- Automating NERC CIP Compliance Essex MD
- Automating NERC CIP Compliance Forest Hill MD
- Automating NERC CIP Compliance Fort Washington MD
- Automating NERC CIP Compliance Frederick MD
- Automating NERC CIP Compliance Frostburg MD
- Automating NERC CIP Compliance Gaithersburg MD
- Automating NERC CIP Compliance Germantown MD
- Automating NERC CIP Compliance Glen Burnie MD
- Automating NERC CIP Compliance Greenbelt MD
- Automating NERC CIP Compliance Gwynn Oak MD
- Automating NERC CIP Compliance Hagerstown MD
- Automating NERC CIP Compliance Halethorpe MD
- Automating NERC CIP Compliance Havre De Grace MD
- Automating NERC CIP Compliance Hyattsville MD
- Automating NERC CIP Compliance Jessup MD
- Automating NERC CIP Compliance Joppa MD
- Automating NERC CIP Compliance Kensington MD
- Automating NERC CIP Compliance La Plata MD
- Automating NERC CIP Compliance Lanham MD
- Automating NERC CIP Compliance Laurel MD
- Automating NERC CIP Compliance Lexington Park MD
- Automating NERC CIP Compliance Lusby MD
- Automating NERC CIP Compliance Lutherville Timonium MD
- Automating NERC CIP Compliance Middle River MD
- Automating NERC CIP Compliance Millersville MD
- Automating NERC CIP Compliance Montgomery Village MD
- Automating NERC CIP Compliance Mount Airy MD
- Automating NERC CIP Compliance Nottingham MD
- Automating NERC CIP Compliance Odenton MD
- Automating NERC CIP Compliance Olney MD
- Automating NERC CIP Compliance Owings Mills MD
- Automating NERC CIP Compliance Oxon Hill MD
- Automating NERC CIP Compliance Parkville MD
- Automating NERC CIP Compliance Pasadena MD
- Automating NERC CIP Compliance Pikesville MD
- Automating NERC CIP Compliance Potomac MD
- Automating NERC CIP Compliance Randallstown MD
- Automating NERC CIP Compliance Reisterstown MD
- Automating NERC CIP Compliance Rockville MD
- Automating NERC CIP Compliance Rosedale MD
- Automating NERC CIP Compliance Salisbury MD
- Automating NERC CIP Compliance Severn MD
- Automating NERC CIP Compliance Severna Park MD
- Automating NERC CIP Compliance Silver Spring MD
- Automating NERC CIP Compliance Suitland MD
- Automating NERC CIP Compliance Sykesville MD
- Automating NERC CIP Compliance Takoma Park MD
- Automating NERC CIP Compliance Temple Hills MD
- Automating NERC CIP Compliance Towson MD
- Automating NERC CIP Compliance Upper Marlboro MD
- Automating NERC CIP Compliance Waldorf MD
- Automating NERC CIP Compliance Westminster MD
- Automating NERC CIP Compliance Windsor Mill MD

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History