Automating NERC CIP Compliance New York

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.

Local Companies

Workers Comp Control
(315) 471-2627
241 W Fayette St
Syracuse, NY
Koenig Managmnt Ltd
(845) 639-1072
120 N Main St
New City, NY
Ghad Field Management
(845) 223-6150
Poughquag, NY
Checks & Balances Ny
(212) 242-1684
200 W 18th St
New York, NY
E Nde Realty Corp
(718) 293-6423
45 Elliot Pl
Bronx, NY
All Risk Management Inc
(914) 633-4022
Depot Plz
New Rochelle, NY
Forbes Management
(516) 466-6983
505 Northern Blvd Ste 304
Great Neck, NY
Next Generation Radiology Mgmt
(516) 546-6627
1991 Smith St
Merrick, NY
Jcc In Manhattan
(646) 505-4444
334 Amsterdam Ave
New York, NY
Synchronous Manufacturing Technologies Inc
(914) 763-8365
207 Ridgefield Ave
South Salem, NY



By Tom Schmidt

Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible. By minimizing error-prone manual processes, he explained, companies can eliminate the fragmentation and duplication of efforts to avoid deploying redundant or unnecessary solutions.

A recent study by the IT Policy Compliance Group vividly underscores the risks related to manual processes. According to the study:

"In one form or another, human error is the overwhelming cause of sensitive data loss, responsible for 75% of all occurrences. User error is directly responsible for one in every two cases, while violations of policy -- intended, accidental and inadvertent -- are responsible for one in every four cases." ("Taking Action to Protect Sensitive Data," February 2007)

This article looks at some of the challenges the electric power industry currently faces in improving cyber security, followed by an overview of the steps companies can take to automate NERC CIP compliance.

Cyber security challenges
Improving cyber security in the electric power industry is challenging for several reasons. Chief among them:

  • Increased interconnectivity SCADA/EMS and DCS systems were initially designed with efficiency and reliability -- rather than security -- in mind. These systems are increasingly being integrated with business information systems, thus introducing new vulnerabilities.
  • Remote access requirements At the same time, company engineers, contractors, and others require remote access to plant/power system control systems via modem or other means to maintain 24/7 operations. Unfortunately, this access introduces additional vulnerability points and could lead to the unleashing of viruses or malicious code within the control systems.
  • Nonstop operations The nonstop operational requirement of utility control systems complicates security implementation and testing because systems can never be taken offline.
  • Standardization The drive to improve operational efficiency and drive costs down is also leading to increasing standardization of control system technologies and use of off-the-shelf IT technologies. SCADA/EMS and DCS are increasingly implemented on Microsoft Windows and Linux operating system-based platforms. In parallel with this trend, technical information about these standards is increasingly available in trade journals and online, enabling would-be attackers to identify vulnerabilities that can be used to attack SCADA/EMS and DCS systems.
  • Shortage of resources Another significant challenge is the shortage of security resources in key areas of the electric power industry -- for example, in energy control centers. Most control centers are not staffed 24/7 with IT and security experts, and such staffing wouldn't be economically feasible. This complicates interpretation of security logs and other activities related to maintaining security around the clock.

Gearing up for NERC CIP compliance
Formidable as these challenges to enhancing security are, it is also the case that the need for security has never been more acute, especially now that it has been formalized as a regulatory requirement. In general, most electric power utilities are in the planning stages of compliance with NERC CIP. Compliance, needless to say, is a complex issue, touching on many areas of operation. For the sake of discussion, let's focus on automating the highly repetitive and manually intensive IT control-related portion of compliance. 

One reason automation has become critical is that auditors will demand proof of due care that IT security policies are sufficient, in place, and effective. Consider, too, this finding from that IT Policy Compliance Group study:

"A challenge uniquely found among the organizations with the fewest data losses is classifying data. Moreover, the prioritized responses being taken by the leaders are unlike all other organizations, and include ... automating IT controls and procedures for protecting sensitive data."

Conclusion
IT compliance is an ongoing process, not a one-time event, and it requires automation to reduce cost and inefficiencies. Moreover, much of the cost of compliance involves IT security tasks that require weekly or even daily activities. Many electric power companies are working on new and better methods for implementing these activities in order to reduce the costs of NERC CIP compliance and improve overall IT security.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Regional Articles
- Automating NERC CIP Compliance Albany NY
- Automating NERC CIP Compliance Amityville NY
- Automating NERC CIP Compliance Amsterdam NY
- Automating NERC CIP Compliance Arverne NY
- Automating NERC CIP Compliance Astoria NY
- Automating NERC CIP Compliance Auburn NY
- Automating NERC CIP Compliance Babylon NY
- Automating NERC CIP Compliance Baldwin NY
- Automating NERC CIP Compliance Baldwinsville NY
- Automating NERC CIP Compliance Ballston Spa NY
- Automating NERC CIP Compliance Bay Shore NY
- Automating NERC CIP Compliance Bayside NY
- Automating NERC CIP Compliance Beacon NY
- Automating NERC CIP Compliance Bellerose NY
- Automating NERC CIP Compliance Bellmore NY
- Automating NERC CIP Compliance Bethpage NY
- Automating NERC CIP Compliance Binghamton NY
- Automating NERC CIP Compliance Brentwood NY
- Automating NERC CIP Compliance Brewster NY
- Automating NERC CIP Compliance Brockport NY
- Automating NERC CIP Compliance Bronx NY
- Automating NERC CIP Compliance Bronxville NY
- Automating NERC CIP Compliance Brooklyn NY
- Automating NERC CIP Compliance Buffalo NY
- Automating NERC CIP Compliance Cambria Heights NY
- Automating NERC CIP Compliance Camillus NY
- Automating NERC CIP Compliance Canandaigua NY
- Automating NERC CIP Compliance Centereach NY
- Automating NERC CIP Compliance Central Islip NY
- Automating NERC CIP Compliance Clifton Park NY
- Automating NERC CIP Compliance Cohoes NY
- Automating NERC CIP Compliance College Point NY
- Automating NERC CIP Compliance Commack NY
- Automating NERC CIP Compliance Copiague NY
- Automating NERC CIP Compliance Coram NY
- Automating NERC CIP Compliance Corning NY
- Automating NERC CIP Compliance Corona NY
- Automating NERC CIP Compliance Cortland NY
- Automating NERC CIP Compliance Cortlandt Manor NY
- Automating NERC CIP Compliance Deer Park NY
- Automating NERC CIP Compliance Delmar NY
- Automating NERC CIP Compliance Depew NY
- Automating NERC CIP Compliance Dunkirk NY
- Automating NERC CIP Compliance East Amherst NY
- Automating NERC CIP Compliance East Aurora NY
- Automating NERC CIP Compliance East Elmhurst NY
- Automating NERC CIP Compliance East Islip NY
- Automating NERC CIP Compliance East Meadow NY
- Automating NERC CIP Compliance East Northport NY
- Automating NERC CIP Compliance East Setauket NY
- Automating NERC CIP Compliance East Syracuse NY
- Automating NERC CIP Compliance Elmhurst NY
- Automating NERC CIP Compliance Elmira NY
- Automating NERC CIP Compliance Elmont NY
- Automating NERC CIP Compliance Endicott NY
- Automating NERC CIP Compliance Fairport NY
- Automating NERC CIP Compliance Far Rockaway NY
- Automating NERC CIP Compliance Farmingdale NY
- Automating NERC CIP Compliance Farmingville NY
- Automating NERC CIP Compliance Floral Park NY
- Automating NERC CIP Compliance Flushing NY
- Automating NERC CIP Compliance Forest Hills NY
- Automating NERC CIP Compliance Franklin Square NY
- Automating NERC CIP Compliance Fredonia NY
- Automating NERC CIP Compliance Freeport NY
- Automating NERC CIP Compliance Fresh Meadows NY
- Automating NERC CIP Compliance Fulton NY
- Automating NERC CIP Compliance Garden City NY
- Automating NERC CIP Compliance Glen Cove NY
- Automating NERC CIP Compliance Glen Oaks NY
- Automating NERC CIP Compliance Glens Falls NY
- Automating NERC CIP Compliance Gloversville NY
- Automating NERC CIP Compliance Great Neck NY
- Automating NERC CIP Compliance Hamburg NY
- Automating NERC CIP Compliance Hauppauge NY
- Automating NERC CIP Compliance Hempstead NY
- Automating NERC CIP Compliance Hicksville NY
- Automating NERC CIP Compliance Hilton NY
- Automating NERC CIP Compliance Holbrook NY
- Automating NERC CIP Compliance Hollis NY
- Automating NERC CIP Compliance Hopewell Junction NY
- Automating NERC CIP Compliance Horseheads NY
- Automating NERC CIP Compliance Howard Beach NY
- Automating NERC CIP Compliance Huntington NY
- Automating NERC CIP Compliance Huntington Station NY
- Automating NERC CIP Compliance Islip NY
- Automating NERC CIP Compliance Ithaca NY
- Automating NERC CIP Compliance Jackson Heights NY
- Automating NERC CIP Compliance Jamaica NY
- Automating NERC CIP Compliance Jamestown NY
- Automating NERC CIP Compliance Kew Gardens NY
- Automating NERC CIP Compliance Kings Park NY
- Automating NERC CIP Compliance Kingston NY
- Automating NERC CIP Compliance Lancaster NY
- Automating NERC CIP Compliance Larchmont NY
- Automating NERC CIP Compliance Latham NY
- Automating NERC CIP Compliance Levittown NY
- Automating NERC CIP Compliance Lindenhurst NY
- Automating NERC CIP Compliance Little Neck NY
- Automating NERC CIP Compliance Liverpool NY
- Automating NERC CIP Compliance Lockport NY
- Automating NERC CIP Compliance Long Beach NY
- Automating NERC CIP Compliance Long Island City NY
- Automating NERC CIP Compliance Lynbrook NY
- Automating NERC CIP Compliance Mahopac NY
- Automating NERC CIP Compliance Malone NY
- Automating NERC CIP Compliance Mamaroneck NY
- Automating NERC CIP Compliance Manhasset NY
- Automating NERC CIP Compliance Manlius NY
- Automating NERC CIP Compliance Maspeth NY
- Automating NERC CIP Compliance Massapequa NY
- Automating NERC CIP Compliance Massapequa Park NY
- Automating NERC CIP Compliance Massena NY
- Automating NERC CIP Compliance Mastic NY
- Automating NERC CIP Compliance Melville NY
- Automating NERC CIP Compliance Merrick NY
- Automating NERC CIP Compliance Middle Village NY
- Automating NERC CIP Compliance Middletown NY
- Automating NERC CIP Compliance Mineola NY
- Automating NERC CIP Compliance Monroe NY
- Automating NERC CIP Compliance Monsey NY
- Automating NERC CIP Compliance Mount Kisco NY
- Automating NERC CIP Compliance Mount Vernon NY
- Automating NERC CIP Compliance Nanuet NY
- Automating NERC CIP Compliance New City NY
- Automating NERC CIP Compliance New Hartford NY
- Automating NERC CIP Compliance New Hyde Park NY
- Automating NERC CIP Compliance New Paltz NY
- Automating NERC CIP Compliance New Rochelle NY
- Automating NERC CIP Compliance New Windsor NY
- Automating NERC CIP Compliance New York NY
- Automating NERC CIP Compliance Newburgh NY
- Automating NERC CIP Compliance Niagara Falls NY
- Automating NERC CIP Compliance North Babylon NY
- Automating NERC CIP Compliance North Tonawanda NY
- Automating NERC CIP Compliance Nyack NY
- Automating NERC CIP Compliance Oakland Gardens NY
- Automating NERC CIP Compliance Oceanside NY
- Automating NERC CIP Compliance Ogdensburg NY
- Automating NERC CIP Compliance Olean NY
- Automating NERC CIP Compliance Oneonta NY
- Automating NERC CIP Compliance Orchard Park NY
- Automating NERC CIP Compliance Ossining NY
- Automating NERC CIP Compliance Oswego NY
- Automating NERC CIP Compliance Ozone Park NY
- Automating NERC CIP Compliance Patchogue NY
- Automating NERC CIP Compliance Pearl River NY
- Automating NERC CIP Compliance Peekskill NY
- Automating NERC CIP Compliance Penfield NY
- Automating NERC CIP Compliance Pittsford NY
- Automating NERC CIP Compliance Plainview NY
- Automating NERC CIP Compliance Plattsburgh NY
- Automating NERC CIP Compliance Port Chester NY
- Automating NERC CIP Compliance Port Jefferson Station NY
- Automating NERC CIP Compliance Port Washington NY
- Automating NERC CIP Compliance Potsdam NY
- Automating NERC CIP Compliance Poughkeepsie NY
- Automating NERC CIP Compliance Queens Village NY
- Automating NERC CIP Compliance Queensbury NY
- Automating NERC CIP Compliance Rego Park NY
- Automating NERC CIP Compliance Rensselaer NY
- Automating NERC CIP Compliance Richmond Hill NY
- Automating NERC CIP Compliance Ridgewood NY
- Automating NERC CIP Compliance Riverhead NY
- Automating NERC CIP Compliance Rochester NY
- Automating NERC CIP Compliance Rockaway Park NY
- Automating NERC CIP Compliance Rockville Centre NY
- Automating NERC CIP Compliance Rome NY
- Automating NERC CIP Compliance Ronkonkoma NY
- Automating NERC CIP Compliance Roosevelt NY
- Automating NERC CIP Compliance Rosedale NY
- Automating NERC CIP Compliance Rye NY
- Automating NERC CIP Compliance Saint Albans NY
- Automating NERC CIP Compliance Saint James NY
- Automating NERC CIP Compliance Saratoga Springs NY
- Automating NERC CIP Compliance Saugerties NY
- Automating NERC CIP Compliance Sayville NY
- Automating NERC CIP Compliance Scarsdale NY
- Automating NERC CIP Compliance Schenectady NY
- Automating NERC CIP Compliance Selden NY
- Automating NERC CIP Compliance Shirley NY
- Automating NERC CIP Compliance Smithtown NY
- Automating NERC CIP Compliance South Ozone Park NY
- Automating NERC CIP Compliance South Richmond Hill NY
- Automating NERC CIP Compliance Spencerport NY
- Automating NERC CIP Compliance Spring Valley NY
- Automating NERC CIP Compliance Springfield Gardens NY
- Automating NERC CIP Compliance Staten Island NY
- Automating NERC CIP Compliance Stony Brook NY
- Automating NERC CIP Compliance Suffern NY
- Automating NERC CIP Compliance Sunnyside NY
- Automating NERC CIP Compliance Syosset NY
- Automating NERC CIP Compliance Syracuse NY
- Automating NERC CIP Compliance Tarrytown NY
- Automating NERC CIP Compliance Tonawanda NY
- Automating NERC CIP Compliance Troy NY
- Automating NERC CIP Compliance Uniondale NY
- Automating NERC CIP Compliance Utica NY
- Automating NERC CIP Compliance Valley Stream NY
- Automating NERC CIP Compliance Vestal NY
- Automating NERC CIP Compliance Wantagh NY
- Automating NERC CIP Compliance Wappingers Falls NY
- Automating NERC CIP Compliance Watertown NY
- Automating NERC CIP Compliance Watervliet NY
- Automating NERC CIP Compliance Webster NY
- Automating NERC CIP Compliance West Babylon NY
- Automating NERC CIP Compliance West Hempstead NY
- Automating NERC CIP Compliance West Islip NY
- Automating NERC CIP Compliance Westbury NY
- Automating NERC CIP Compliance White Plains NY
- Automating NERC CIP Compliance Whitestone NY
- Automating NERC CIP Compliance Woodhaven NY
- Automating NERC CIP Compliance Woodside NY
- Automating NERC CIP Compliance Wyandanch NY
- Automating NERC CIP Compliance Yonkers NY
- Automating NERC CIP Compliance Yorktown Heights NY
Related Local Event
Direct Marketing Math and Finance Seminar
Dates: 6/2/2009 - 6/2/2009
Location: DMA Seminar Center
New York, NY
View Details
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History