Electric Utilities: Securing the Perimeter Florida

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.

Local Companies

Sunera LLC
813-541-9361
777 S. Harbour Island Blvd.
Tampa, FL
Avacuna LLC
954-719-5126
6308 La Costa Drive Ste D
Boca Raton, FL
Engineering Services & Sales
(954) 455-0806
1920 E Hallandale Beach Blv Ste 607
Hallandale, FL
Omni Partners
(954) 748-9800
Fort Lauderdale, FL
A F Management of South Florida
(954) 885-1021
Hollywood, FL
Mia Management Group Inc
(305) 666-1264
1200 S Alhambra Cir
Coral Gables, FL
Success Connection
(941) 966-3665
1518 Pelican Point Dr
Sarasota, FL
Ddlt Consulting
(305) 705-0100
17555 Atlantic Blvd
Sunny Isles Beach, FL
Maximum Potential Intl
(305) 672-1190
294 S Hibiscus Dr
Miami Beach, FL
Best Payment Solutions
(813) 849-1295
3450 Buschwood Park Dr Ste 230
Tampa, FL



From the Editors of CIOSC

The Comment Period for Draft 4 of the NERC CIP Standards recently expired. Under a revised implementation plan, this suite of Cyber Security Standards (formally known as CIP-002 through CIP-009) will go into effect June 1, 2006. In this article we look at one of these standards, CIP-005, in some detail, and then recommend some best practices for perimeter security. We'll also discuss the need for securing Supervisory Control and Data Acquisition (SCADA) networks utilizing the Inter-control Center Communications Protocol (ICCP) protocol.

The requirements for CIP-005

CIP-005 "requires the identification and protection of the electronic security perimeter inside which all critical cyber assets reside, as well as all access points on the perimeter." The standard contains six requirements:

  • R1. Electronic Security Perimeter Responsible entities must identify the electronic security perimeter and identify access points to it. The electronic perimeter must be inside the physical perimeter, and all cyber assets inside the perimeter are to be protected. Cyber assets that control/monitor the perimeter are to be defined as Critical Assets. A special case is made for dial-up access using non-routable protocols.
  • R2. Electronic Access Controls Responsible entities must ensure that only necessary ports and services are enabled. They must secure dial-up access. And they must identify access controls and authentication methods.
  • R3. Monitoring Electronic Access Controls For dial-up-accessible Critical Assets that use non-routable protocols, responsible entities must implement and document monitoring processes at each access point to the dial-up device (where technically feasible). They are also responsible for detecting unauthorized access attempts. In addition, they are responsible for 24x7 monitoring and periodic review of access logs.
  • R4. Cyber Vulnerability Assessment Responsible entities must produce a document identifying the vulnerability assessment process, and conduct a review to verify that only ports and services required for operations at these access points are enabled. They are also responsible for the discovery of all access points to the perimeter; a review of the controls for default accounts, passwords, and network management community strings; and the documentation of the results of the assessment, the action plan to remediate or mitigate vulnerabilities, and the status of the action plan.
  • R5. Documentation Review and Maintenance Responsible entities must ensure that all documentation reflects current configurations and processes that it is reviewed at least annually.

As CIP-002 through CIP-009 in their entirety make clear, until utility companies can ensure that all internal systems and networks are "hardened," perimeter security will be a critical first layer of defense.

Best practices

To meet these needs, effective practices should include the following at the network gateway:

  • In light of the limited IT resources in some distributed control system (DCS) environments, the purchase of an integrated solution that combines firewall, intrusion detection, and antivirus technologies in a comprehensive gateway solution is recommended. Purchasing separate firewall, intrusion detection, and antivirus technologies from different vendors can be costly to purchase, deploy, and update.
  • The firewall solution that is deployed should include both "stateful" inspection and full application inspection -- in other words, a "hybrid" firewall. It should be noted here that some companies assume a firewall alone provides sufficient gateway security. But according to the recent FBI/CSI report, one-third of all cyber attacks penetrate firewalls. Moreover, according to a recent Internet Security Threat Report, 54% of all attacks in the first six months of 2005 were so-called "blended threats," which are not addressed by firewalls.
  • Due to the multiple protocols used in the DCS environment, the intrusion detection device that is deployed should use both anomaly-based and signature-based protection.
  • The antivirus solution that is deployed should scan for at least 60,000 viruses and provide proactive protection via both signature-based and heuristics-based scanning. The antivirus solution is best deployed at the gateway, to minimize performance impact and facilitate updates. A solution that has received a high Evaluation Assurance Level (EAL), such as EAL level 4 or higher, is recommended.

Securing ICCP connections

It is also essential that electric utility companies proactively detect and prevent malicious attacks against their SCADA networks utilizing the ICCP protocol. ICCP is the primary protocol used to communicate real-time data, schedule, and control command exchanges between the energy control centers that operate these SCADA networks and remote terminal units (RTUs) and substations. While it has been developed with built-in security, in today's interconnected environment additional security measures are critical for enabling uninterrupted operations for transmission, generation, and independent service operators.

ICCP security signatures are available for appliances offering real time intrusion prevention (IPS) and detection to proactively protect critical enterprise assets. These signatures were developed to address not just known attacks, but also for protection against new and unknown exploits.
 
The signatures were lab tested by leading ICCP provider SISCO for three months, using live ICCP traffic, and produced no false positives. This testing also included a known attack procedure, which had previously resulted in crashed systems, and the signatures correctly "triggered" against this known attack.
 
The bottom line is that the ICCP protocol is one of most critical areas that must be addressed in terms of cyber security.

Conclusion

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.
 
These best practices recognize that there are many areas to cover, and there is no silver bullet. Indeed, it's an ongoing process. These best practices also require genuine (and perhaps unprecedented) collaboration between engineering, operations, and IT. Ultimately, they are designed to help electric utility companies find a balance between optimal NERC CIP compliance and profitable, cost-effective operations.

Featured Local Company

Sunera LLC

Sunera is a business and technology risk advisory consulting firm.

813-541-9361
777 S. Harbour Island Blvd.
Tampa, FL
www.sunera.com

Sunera is a leading provider of business and technology risk management and consulting services throughout the United States and Canada. Our partners and professionals are dedicated to helping organizations achieve and sustain cost-effective corporate governance.


Regional Articles
- Electric Utilities: Securing the Perimeter Altamonte Springs FL
- Electric Utilities: Securing the Perimeter Apopka FL
- Electric Utilities: Securing the Perimeter Arcadia FL
- Electric Utilities: Securing the Perimeter Atlantic Beach FL
- Electric Utilities: Securing the Perimeter Auburndale FL
- Electric Utilities: Securing the Perimeter Avon Park FL
- Electric Utilities: Securing the Perimeter Bartow FL
- Electric Utilities: Securing the Perimeter Belle Glade FL
- Electric Utilities: Securing the Perimeter Boca Raton FL
- Electric Utilities: Securing the Perimeter Bonita Springs FL
- Electric Utilities: Securing the Perimeter Boynton Beach FL
- Electric Utilities: Securing the Perimeter Bradenton FL
- Electric Utilities: Securing the Perimeter Brandon FL
- Electric Utilities: Securing the Perimeter Brooksville FL
- Electric Utilities: Securing the Perimeter Cantonment FL
- Electric Utilities: Securing the Perimeter Cape Coral FL
- Electric Utilities: Securing the Perimeter Casselberry FL
- Electric Utilities: Securing the Perimeter Chipley FL
- Electric Utilities: Securing the Perimeter Clearwater FL
- Electric Utilities: Securing the Perimeter Clermont FL
- Electric Utilities: Securing the Perimeter Clewiston FL
- Electric Utilities: Securing the Perimeter Cocoa Beach FL
- Electric Utilities: Securing the Perimeter Cocoa FL
- Electric Utilities: Securing the Perimeter Crawfordville FL
- Electric Utilities: Securing the Perimeter Crestview FL
- Electric Utilities: Securing the Perimeter Crystal River FL
- Electric Utilities: Securing the Perimeter Dade City FL
- Electric Utilities: Securing the Perimeter Dania FL
- Electric Utilities: Securing the Perimeter Daytona Beach FL
- Electric Utilities: Securing the Perimeter Debary FL
- Electric Utilities: Securing the Perimeter Deerfield Beach FL
- Electric Utilities: Securing the Perimeter Defuniak Springs FL
- Electric Utilities: Securing the Perimeter Deland FL
- Electric Utilities: Securing the Perimeter Delray Beach FL
- Electric Utilities: Securing the Perimeter Deltona FL
- Electric Utilities: Securing the Perimeter Destin FL
- Electric Utilities: Securing the Perimeter Dunedin FL
- Electric Utilities: Securing the Perimeter Dunnellon FL
- Electric Utilities: Securing the Perimeter Englewood FL
- Electric Utilities: Securing the Perimeter Eustis FL
- Electric Utilities: Securing the Perimeter Fernandina Beach FL
- Electric Utilities: Securing the Perimeter Fort Lauderdale FL
- Electric Utilities: Securing the Perimeter Fort Myers FL
- Electric Utilities: Securing the Perimeter Fort Pierce FL
- Electric Utilities: Securing the Perimeter Fort Walton Beach FL
- Electric Utilities: Securing the Perimeter Gainesville FL
- Electric Utilities: Securing the Perimeter Green Cove Springs FL
- Electric Utilities: Securing the Perimeter Gulf Breeze FL
- Electric Utilities: Securing the Perimeter Haines City FL
- Electric Utilities: Securing the Perimeter Hallandale FL
- Electric Utilities: Securing the Perimeter Hialeah FL
- Electric Utilities: Securing the Perimeter Hobe Sound FL
- Electric Utilities: Securing the Perimeter Holiday FL
- Electric Utilities: Securing the Perimeter Hollywood FL
- Electric Utilities: Securing the Perimeter Homestead FL
- Electric Utilities: Securing the Perimeter Homosassa FL
- Electric Utilities: Securing the Perimeter Hudson FL
- Electric Utilities: Securing the Perimeter Immokalee FL
- Electric Utilities: Securing the Perimeter Inverness FL
- Electric Utilities: Securing the Perimeter Jacksonville Beach FL
- Electric Utilities: Securing the Perimeter Jacksonville FL
- Electric Utilities: Securing the Perimeter Jensen Beach FL
- Electric Utilities: Securing the Perimeter Jupiter FL
- Electric Utilities: Securing the Perimeter Key West FL
- Electric Utilities: Securing the Perimeter Kissimmee FL
- Electric Utilities: Securing the Perimeter Labelle FL
- Electric Utilities: Securing the Perimeter Lady Lake FL
- Electric Utilities: Securing the Perimeter Lake City FL
- Electric Utilities: Securing the Perimeter Lake Mary FL
- Electric Utilities: Securing the Perimeter Lake Placid FL
- Electric Utilities: Securing the Perimeter Lake Wales FL
- Electric Utilities: Securing the Perimeter Lake Worth FL
- Electric Utilities: Securing the Perimeter Lakeland FL
- Electric Utilities: Securing the Perimeter Land O Lakes FL
- Electric Utilities: Securing the Perimeter Largo FL
- Electric Utilities: Securing the Perimeter Leesburg FL
- Electric Utilities: Securing the Perimeter Lehigh Acres FL
- Electric Utilities: Securing the Perimeter Live Oak FL
- Electric Utilities: Securing the Perimeter Longwood FL
- Electric Utilities: Securing the Perimeter Loxahatchee FL
- Electric Utilities: Securing the Perimeter Lutz FL
- Electric Utilities: Securing the Perimeter Lynn Haven FL
- Electric Utilities: Securing the Perimeter Marco Island FL
- Electric Utilities: Securing the Perimeter Marianna FL
- Electric Utilities: Securing the Perimeter Melbourne FL
- Electric Utilities: Securing the Perimeter Merritt Island FL
- Electric Utilities: Securing the Perimeter Miami Beach FL
- Electric Utilities: Securing the Perimeter Miami FL
- Electric Utilities: Securing the Perimeter Miami Lakes FL
- Electric Utilities: Securing the Perimeter Middleburg FL
- Electric Utilities: Securing the Perimeter Milton FL
- Electric Utilities: Securing the Perimeter Miramar FL
- Electric Utilities: Securing the Perimeter Mount Dora FL
- Electric Utilities: Securing the Perimeter Mulberry FL
- Electric Utilities: Securing the Perimeter Naples FL
- Electric Utilities: Securing the Perimeter Navarre FL
- Electric Utilities: Securing the Perimeter New Port Richey FL
- Electric Utilities: Securing the Perimeter New Smyrna Beach FL
- Electric Utilities: Securing the Perimeter Niceville FL
- Electric Utilities: Securing the Perimeter Nokomis FL
- Electric Utilities: Securing the Perimeter North Fort Myers FL
- Electric Utilities: Securing the Perimeter North Miami Beach FL
- Electric Utilities: Securing the Perimeter North Palm Beach FL
- Electric Utilities: Securing the Perimeter North Port FL
- Electric Utilities: Securing the Perimeter Ocala FL
- Electric Utilities: Securing the Perimeter Ocoee FL
- Electric Utilities: Securing the Perimeter Okeechobee FL
- Electric Utilities: Securing the Perimeter Oldsmar FL
- Electric Utilities: Securing the Perimeter Opa Locka FL
- Electric Utilities: Securing the Perimeter Orange City FL
- Electric Utilities: Securing the Perimeter Orange Park FL
- Electric Utilities: Securing the Perimeter Orlando FL
- Electric Utilities: Securing the Perimeter Ormond Beach FL
- Electric Utilities: Securing the Perimeter Oviedo FL
- Electric Utilities: Securing the Perimeter Palatka FL
- Electric Utilities: Securing the Perimeter Palm Bay FL
- Electric Utilities: Securing the Perimeter Palm Beach FL
- Electric Utilities: Securing the Perimeter Palm Beach Gardens FL
- Electric Utilities: Securing the Perimeter Palm City FL
- Electric Utilities: Securing the Perimeter Palm Coast FL
- Electric Utilities: Securing the Perimeter Palm Harbor FL
- Electric Utilities: Securing the Perimeter Palmetto FL
- Electric Utilities: Securing the Perimeter Panama City Beach FL
- Electric Utilities: Securing the Perimeter Panama City FL
- Electric Utilities: Securing the Perimeter Pembroke Pines FL
- Electric Utilities: Securing the Perimeter Pensacola FL
- Electric Utilities: Securing the Perimeter Pinellas Park FL
- Electric Utilities: Securing the Perimeter Plant City FL
- Electric Utilities: Securing the Perimeter Pompano Beach FL
- Electric Utilities: Securing the Perimeter Ponte Vedra Beach FL
- Electric Utilities: Securing the Perimeter Port Charlotte FL
- Electric Utilities: Securing the Perimeter Port Orange FL
- Electric Utilities: Securing the Perimeter Port Richey FL
- Electric Utilities: Securing the Perimeter Port Saint Lucie FL
- Electric Utilities: Securing the Perimeter Punta Gorda FL
- Electric Utilities: Securing the Perimeter Riverview FL
- Electric Utilities: Securing the Perimeter Rockledge FL
- Electric Utilities: Securing the Perimeter Safety Harbor FL
- Electric Utilities: Securing the Perimeter Saint Augustine FL
- Electric Utilities: Securing the Perimeter Saint Cloud FL
- Electric Utilities: Securing the Perimeter Saint Petersburg FL
- Electric Utilities: Securing the Perimeter Sanford FL
- Electric Utilities: Securing the Perimeter Sarasota FL
- Electric Utilities: Securing the Perimeter Satellite Beach FL
- Electric Utilities: Securing the Perimeter Sebastian FL
- Electric Utilities: Securing the Perimeter Sebring FL
- Electric Utilities: Securing the Perimeter Seffner FL
- Electric Utilities: Securing the Perimeter Seminole FL
- Electric Utilities: Securing the Perimeter Spring Hill FL
- Electric Utilities: Securing the Perimeter Starke FL
- Electric Utilities: Securing the Perimeter Stuart FL
- Electric Utilities: Securing the Perimeter Summerfield FL
- Electric Utilities: Securing the Perimeter Sun City Center FL
- Electric Utilities: Securing the Perimeter Tallahassee FL
- Electric Utilities: Securing the Perimeter Tampa FL
- Electric Utilities: Securing the Perimeter Tarpon Springs FL
- Electric Utilities: Securing the Perimeter Titusville FL
- Electric Utilities: Securing the Perimeter Valrico FL
- Electric Utilities: Securing the Perimeter Venice FL
- Electric Utilities: Securing the Perimeter Vero Beach FL
- Electric Utilities: Securing the Perimeter Wauchula FL
- Electric Utilities: Securing the Perimeter Wesley Chapel FL
- Electric Utilities: Securing the Perimeter West Palm Beach FL
- Electric Utilities: Securing the Perimeter Winter Garden FL
- Electric Utilities: Securing the Perimeter Winter Haven FL
- Electric Utilities: Securing the Perimeter Winter Park FL
- Electric Utilities: Securing the Perimeter Winter Springs FL
- Electric Utilities: Securing the Perimeter Zephyrhills FL
Related Articles
- Looking Out for Insider Threats Florida
If the topic of protecting against insider threats makes many a government IT worker shudder, it's for good reason. Besides the millions of people employed by government agencies, the number of federal civil servants is on the rise, as is the number of people working for government-funded contractors and organizations that receive government grants. Add to that the number of postal workers and military personnel, and the "true size" of the federal government is around 14.6 million employees, according to Paul C. Light, government professor at New York University.
- Protection for Small Companies Florida
- The Perimeter Defense Fallacy Florida
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review Florida
- Mobility Electric Scooters Florida
- Automating NERC CIP Compliance Florida
- Securing Professional Graphic Design Services Florida
- Fellowes Pulsar-E Review Florida
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Florida
- A Roadmap for Securing Personal Data Florida

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History