Automating NERC CIP Compliance Michigan

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.

Local Companies

Manufacturing Management Associate
(269) 279-9057
14860 Mount Zion Rd
Three Rivers, MI
Professional Benefits Services Inc
(616) 285-9894
2959 Lucerne Dr SE Ste 205
Grand Rapids, MI
Skem Inc
(734) 214-0909
5119 Pontiac Trl
Whitmore Lake, MI
L Harding Enterprises Inc
(269) 383-6848
Kalamazoo, MI
AA Management Services
(313) 653-4720
15800 W McNichols Rd
Detroit, MI
Clinical Dynamics Inc
(517) 347-7903
2435 Seville Dr
Okemos, MI
Ajr Marketing
(586) 783-0546
39364 Ormsby St
Clinton Township, MI
Patient Resource Consultants
(616) 454-1189
120 Jefferson Ave SE
Grand Rapids, MI
Mount Olympus Corp
(269) 651-3780
1013 Cato Ln
Sturgis, MI
P P A Financial Concepts
(810) 579-0735
610 E Grand Blanc Rd
Grand Blanc, MI



By Tom Schmidt

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible. By minimizing error-prone manual processes, he explained, companies can eliminate the fragmentation and duplication of efforts to avoid deploying redundant or unnecessary solutions.

A recent study by the IT Policy Compliance Group vividly underscores the risks related to manual processes. According to the study:

"In one form or another, human error is the overwhelming cause of sensitive data loss, responsible for 75% of all occurrences. User error is directly responsible for one in every two cases, while violations of policy -- intended, accidental and inadvertent -- are responsible for one in every four cases." ("Taking Action to Protect Sensitive Data," February 2007)

This article looks at some of the challenges the electric power industry currently faces in improving cyber security, followed by an overview of the steps companies can take to automate NERC CIP compliance.

Cyber security challenges
Improving cyber security in the electric power industry is challenging for several reasons. Chief among them:

  • Increased interconnectivity SCADA/EMS and DCS systems were initially designed with efficiency and reliability -- rather than security -- in mind. These systems are increasingly being integrated with business information systems, thus introducing new vulnerabilities.
  • Remote access requirements At the same time, company engineers, contractors, and others require remote access to plant/power system control systems via modem or other means to maintain 24/7 operations. Unfortunately, this access introduces additional vulnerability points and could lead to the unleashing of viruses or malicious code within the control systems.
  • Nonstop operations The nonstop operational requirement of utility control systems complicates security implementation and testing because systems can never be taken offline.
  • Standardization The drive to improve operational efficiency and drive costs down is also leading to increasing standardization of control system technologies and use of off-the-shelf IT technologies. SCADA/EMS and DCS are increasingly implemented on Microsoft Windows and Linux operating system-based platforms. In parallel with this trend, technical information about these standards is increasingly available in trade journals and online, enabling would-be attackers to identify vulnerabilities that can be used to attack SCADA/EMS and DCS systems.
  • Shortage of resources Another significant challenge is the shortage of security resources in key areas of the electric power industry -- for example, in energy control centers. Most control centers are not staffed 24/7 with IT and security experts, and such staffing wouldn't be economically feasible. This complicates interpretation of security logs and other activities related to maintaining security around the clock.

Gearing up for NERC CIP compliance
Formidable as these challenges to enhancing security are, it is also the case that the need for security has never been more acute, especially now that it has been formalized as a regulatory requirement. In general, most electric power utilities are in the planning stages of compliance with NERC CIP. Compliance, needless to say, is a complex issue, touching on many areas of operation. For the sake of discussion, let's focus on automating the highly repetitive and manually intensive IT control-related portion of compliance. 

One reason automation has become critical is that auditors will demand proof of due care that IT security policies are sufficient, in place, and effective. Consider, too, this finding from that IT Policy Compliance Group study:

"A challenge uniquely found among the organizations with the fewest data losses is classifying data. Moreover, the prioritized responses being taken by the leaders are unlike all other organizations, and include ... automating IT controls and procedures for protecting sensitive data."

Conclusion
IT compliance is an ongoing process, not a one-time event, and it requires automation to reduce cost and inefficiencies. Moreover, much of the cost of compliance involves IT security tasks that require weekly or even daily activities. Many electric power companies are working on new and better methods for implementing these activities in order to reduce the costs of NERC CIP compliance and improve overall IT security.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Regional Articles
- Automating NERC CIP Compliance Adrian MI
- Automating NERC CIP Compliance Allegan MI
- Automating NERC CIP Compliance Allen Park MI
- Automating NERC CIP Compliance Alpena MI
- Automating NERC CIP Compliance Ann Arbor MI
- Automating NERC CIP Compliance Auburn Hills MI
- Automating NERC CIP Compliance Battle Creek MI
- Automating NERC CIP Compliance Bay City MI
- Automating NERC CIP Compliance Belleville MI
- Automating NERC CIP Compliance Benton Harbor MI
- Automating NERC CIP Compliance Berkley MI
- Automating NERC CIP Compliance Big Rapids MI
- Automating NERC CIP Compliance Bloomfield Hills MI
- Automating NERC CIP Compliance Brighton MI
- Automating NERC CIP Compliance Burton MI
- Automating NERC CIP Compliance Cadillac MI
- Automating NERC CIP Compliance Canton MI
- Automating NERC CIP Compliance Cheboygan MI
- Automating NERC CIP Compliance Clarkston MI
- Automating NERC CIP Compliance Clinton Township MI
- Automating NERC CIP Compliance Clio MI
- Automating NERC CIP Compliance Coldwater MI
- Automating NERC CIP Compliance Commerce Township MI
- Automating NERC CIP Compliance Comstock Park MI
- Automating NERC CIP Compliance Davison MI
- Automating NERC CIP Compliance Dearborn Heights MI
- Automating NERC CIP Compliance Dearborn MI
- Automating NERC CIP Compliance Detroit MI
- Automating NERC CIP Compliance Dowagiac MI
- Automating NERC CIP Compliance East Lansing MI
- Automating NERC CIP Compliance Eastpointe MI
- Automating NERC CIP Compliance Eaton Rapids MI
- Automating NERC CIP Compliance Escanaba MI
- Automating NERC CIP Compliance Farmington MI
- Automating NERC CIP Compliance Fenton MI
- Automating NERC CIP Compliance Ferndale MI
- Automating NERC CIP Compliance Flat Rock MI
- Automating NERC CIP Compliance Flint MI
- Automating NERC CIP Compliance Flushing MI
- Automating NERC CIP Compliance Fort Gratiot MI
- Automating NERC CIP Compliance Fraser MI
- Automating NERC CIP Compliance Garden City MI
- Automating NERC CIP Compliance Gaylord MI
- Automating NERC CIP Compliance Gladwin MI
- Automating NERC CIP Compliance Grand Blanc MI
- Automating NERC CIP Compliance Grand Haven MI
- Automating NERC CIP Compliance Grand Ledge MI
- Automating NERC CIP Compliance Grand Rapids MI
- Automating NERC CIP Compliance Grandville MI
- Automating NERC CIP Compliance Grosse Pointe MI
- Automating NERC CIP Compliance Hamtramck MI
- Automating NERC CIP Compliance Harper Woods MI
- Automating NERC CIP Compliance Harrison Township MI
- Automating NERC CIP Compliance Hazel Park MI
- Automating NERC CIP Compliance Highland Park MI
- Automating NERC CIP Compliance Hillsdale MI
- Automating NERC CIP Compliance Holland MI
- Automating NERC CIP Compliance Holly MI
- Automating NERC CIP Compliance Holt MI
- Automating NERC CIP Compliance Howell MI
- Automating NERC CIP Compliance Hudsonville MI
- Automating NERC CIP Compliance Inkster MI
- Automating NERC CIP Compliance Ionia MI
- Automating NERC CIP Compliance Jackson MI
- Automating NERC CIP Compliance Jenison MI
- Automating NERC CIP Compliance Kalamazoo MI
- Automating NERC CIP Compliance Lake Orion MI
- Automating NERC CIP Compliance Lansing MI
- Automating NERC CIP Compliance Lapeer MI
- Automating NERC CIP Compliance Lincoln Park MI
- Automating NERC CIP Compliance Livonia MI
- Automating NERC CIP Compliance Ludington MI
- Automating NERC CIP Compliance Macomb MI
- Automating NERC CIP Compliance Marquette MI
- Automating NERC CIP Compliance Midland MI
- Automating NERC CIP Compliance Monroe MI
- Automating NERC CIP Compliance Mount Clemens MI
- Automating NERC CIP Compliance Mount Morris MI
- Automating NERC CIP Compliance Mount Pleasant MI
- Automating NERC CIP Compliance Muskegon MI
- Automating NERC CIP Compliance New Baltimore MI
- Automating NERC CIP Compliance Niles MI
- Automating NERC CIP Compliance Northville MI
- Automating NERC CIP Compliance Novi MI
- Automating NERC CIP Compliance Oak Park MI
- Automating NERC CIP Compliance Okemos MI
- Automating NERC CIP Compliance Owosso MI
- Automating NERC CIP Compliance Petoskey MI
- Automating NERC CIP Compliance Pinckney MI
- Automating NERC CIP Compliance Plymouth MI
- Automating NERC CIP Compliance Pontiac MI
- Automating NERC CIP Compliance Port Huron MI
- Automating NERC CIP Compliance Portage MI
- Automating NERC CIP Compliance Redford MI
- Automating NERC CIP Compliance Rochester MI
- Automating NERC CIP Compliance Rockford MI
- Automating NERC CIP Compliance Romulus MI
- Automating NERC CIP Compliance Roseville MI
- Automating NERC CIP Compliance Royal Oak MI
- Automating NERC CIP Compliance Saginaw MI
- Automating NERC CIP Compliance Saint Clair Shores MI
- Automating NERC CIP Compliance Saint Johns MI
- Automating NERC CIP Compliance Saline MI
- Automating NERC CIP Compliance Sault Sainte Marie MI
- Automating NERC CIP Compliance South Haven MI
- Automating NERC CIP Compliance South Lyon MI
- Automating NERC CIP Compliance Southfield MI
- Automating NERC CIP Compliance Southgate MI
- Automating NERC CIP Compliance Sterling Heights MI
- Automating NERC CIP Compliance Sturgis MI
- Automating NERC CIP Compliance Swartz Creek MI
- Automating NERC CIP Compliance Taylor MI
- Automating NERC CIP Compliance Temperance MI
- Automating NERC CIP Compliance Three Rivers MI
- Automating NERC CIP Compliance Traverse City MI
- Automating NERC CIP Compliance Trenton MI
- Automating NERC CIP Compliance Troy MI
- Automating NERC CIP Compliance Utica MI
- Automating NERC CIP Compliance Walled Lake MI
- Automating NERC CIP Compliance Warren MI
- Automating NERC CIP Compliance Waterford MI
- Automating NERC CIP Compliance West Bloomfield MI
- Automating NERC CIP Compliance Westland MI
- Automating NERC CIP Compliance White Lake MI
- Automating NERC CIP Compliance Wixom MI
- Automating NERC CIP Compliance Wyandotte MI
- Automating NERC CIP Compliance Wyoming MI
- Automating NERC CIP Compliance Ypsilanti MI
- Automating NERC CIP Compliance Zeeland MI

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History