Electric Utilities: Securing the Perimeter Illinois

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.

Local Companies

Rowan Technology Group
(847) 680-9420
1590 S Milwaukee Ave
Libertyville, IL
Heidenreich J L & Assocs
(847) 697-8191
1309 Robinhood Dr
Elgin, IL
Itelegence
(708) 836-9779
5 Westbrook Corporate
Westchester, IL
Haake
(815) 730-9970
3807 Leominster Ave
Joliet, IL
Edge Group the
(708) 344-1969
1332 Westchester Blvd
Westchester, IL
Cit Small Business Lending
(847) 540-0850
148 Glen Rd
Hawthorn Woods, IL
Uretek USA Inc
(309) 756-0464
448 3rd St W
Milan, IL
Major Solutions Development Corporation Inc
(773) 660-8858
310 W 105th
Chicago, IL
Garner & Lloyds Inc
(773) 380-3030
8604 W Catalpa Ave Ste 901
Chicago, IL
Pertan Group the
(217) 356-1348
44 E Main St
Champaign, IL



From the Editors of CIOSC

The Comment Period for Draft 4 of the NERC CIP Standards recently expired. Under a revised implementation plan, this suite of Cyber Security Standards (formally known as CIP-002 through CIP-009) will go into effect June 1, 2006. In this article we look at one of these standards, CIP-005, in some detail, and then recommend some best practices for perimeter security. We'll also discuss the need for securing Supervisory Control and Data Acquisition (SCADA) networks utilizing the Inter-control Center Communications Protocol (ICCP) protocol.

The requirements for CIP-005

CIP-005 "requires the identification and protection of the electronic security perimeter inside which all critical cyber assets reside, as well as all access points on the perimeter." The standard contains six requirements:

  • R1. Electronic Security Perimeter Responsible entities must identify the electronic security perimeter and identify access points to it. The electronic perimeter must be inside the physical perimeter, and all cyber assets inside the perimeter are to be protected. Cyber assets that control/monitor the perimeter are to be defined as Critical Assets. A special case is made for dial-up access using non-routable protocols.
  • R2. Electronic Access Controls Responsible entities must ensure that only necessary ports and services are enabled. They must secure dial-up access. And they must identify access controls and authentication methods.
  • R3. Monitoring Electronic Access Controls For dial-up-accessible Critical Assets that use non-routable protocols, responsible entities must implement and document monitoring processes at each access point to the dial-up device (where technically feasible). They are also responsible for detecting unauthorized access attempts. In addition, they are responsible for 24x7 monitoring and periodic review of access logs.
  • R4. Cyber Vulnerability Assessment Responsible entities must produce a document identifying the vulnerability assessment process, and conduct a review to verify that only ports and services required for operations at these access points are enabled. They are also responsible for the discovery of all access points to the perimeter; a review of the controls for default accounts, passwords, and network management community strings; and the documentation of the results of the assessment, the action plan to remediate or mitigate vulnerabilities, and the status of the action plan.
  • R5. Documentation Review and Maintenance Responsible entities must ensure that all documentation reflects current configurations and processes that it is reviewed at least annually.

As CIP-002 through CIP-009 in their entirety make clear, until utility companies can ensure that all internal systems and networks are "hardened," perimeter security will be a critical first layer of defense.

Best practices

To meet these needs, effective practices should include the following at the network gateway:

  • In light of the limited IT resources in some distributed control system (DCS) environments, the purchase of an integrated solution that combines firewall, intrusion detection, and antivirus technologies in a comprehensive gateway solution is recommended. Purchasing separate firewall, intrusion detection, and antivirus technologies from different vendors can be costly to purchase, deploy, and update.
  • The firewall solution that is deployed should include both "stateful" inspection and full application inspection -- in other words, a "hybrid" firewall. It should be noted here that some companies assume a firewall alone provides sufficient gateway security. But according to the recent FBI/CSI report, one-third of all cyber attacks penetrate firewalls. Moreover, according to a recent Internet Security Threat Report, 54% of all attacks in the first six months of 2005 were so-called "blended threats," which are not addressed by firewalls.
  • Due to the multiple protocols used in the DCS environment, the intrusion detection device that is deployed should use both anomaly-based and signature-based protection.
  • The antivirus solution that is deployed should scan for at least 60,000 viruses and provide proactive protection via both signature-based and heuristics-based scanning. The antivirus solution is best deployed at the gateway, to minimize performance impact and facilitate updates. A solution that has received a high Evaluation Assurance Level (EAL), such as EAL level 4 or higher, is recommended.

Securing ICCP connections

It is also essential that electric utility companies proactively detect and prevent malicious attacks against their SCADA networks utilizing the ICCP protocol. ICCP is the primary protocol used to communicate real-time data, schedule, and control command exchanges between the energy control centers that operate these SCADA networks and remote terminal units (RTUs) and substations. While it has been developed with built-in security, in today's interconnected environment additional security measures are critical for enabling uninterrupted operations for transmission, generation, and independent service operators.

ICCP security signatures are available for appliances offering real time intrusion prevention (IPS) and detection to proactively protect critical enterprise assets. These signatures were developed to address not just known attacks, but also for protection against new and unknown exploits.
 
The signatures were lab tested by leading ICCP provider SISCO for three months, using live ICCP traffic, and produced no false positives. This testing also included a known attack procedure, which had previously resulted in crashed systems, and the signatures correctly "triggered" against this known attack.
 
The bottom line is that the ICCP protocol is one of most critical areas that must be addressed in terms of cyber security.

Conclusion

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.
 
These best practices recognize that there are many areas to cover, and there is no silver bullet. Indeed, it's an ongoing process. These best practices also require genuine (and perhaps unprecedented) collaboration between engineering, operations, and IT. Ultimately, they are designed to help electric utility companies find a balance between optimal NERC CIP compliance and profitable, cost-effective operations.

Related Articles
- Looking Out for Insider Threats Illinois
If the topic of protecting against insider threats makes many a government IT worker shudder, it's for good reason. Besides the millions of people employed by government agencies, the number of federal civil servants is on the rise, as is the number of people working for government-funded contractors and organizations that receive government grants. Add to that the number of postal workers and military personnel, and the "true size" of the federal government is around 14.6 million employees, according to Paul C. Light, government professor at New York University.
- Securing Professional Graphic Design Services Illinois
- The Perimeter Defense Fallacy Illinois
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Illinois
- Fellowes Pulsar-E Review Illinois
- Automating NERC CIP Compliance Illinois
- A Roadmap for Securing Personal Data Illinois
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review Illinois
- Mobility Electric Scooters Illinois
- Protection for Small Companies Illinois
Regional Articles
- Electric Utilities: Securing the Perimeter Addison IL
- Electric Utilities: Securing the Perimeter Algonquin IL
- Electric Utilities: Securing the Perimeter Alsip IL
- Electric Utilities: Securing the Perimeter Alton IL
- Electric Utilities: Securing the Perimeter Arlington Heights IL
- Electric Utilities: Securing the Perimeter Aurora IL
- Electric Utilities: Securing the Perimeter Barrington IL
- Electric Utilities: Securing the Perimeter Bartlett IL
- Electric Utilities: Securing the Perimeter Batavia IL
- Electric Utilities: Securing the Perimeter Belleville IL
- Electric Utilities: Securing the Perimeter Bellwood IL
- Electric Utilities: Securing the Perimeter Belvidere IL
- Electric Utilities: Securing the Perimeter Bensenville IL
- Electric Utilities: Securing the Perimeter Berwyn IL
- Electric Utilities: Securing the Perimeter Bloomingdale IL
- Electric Utilities: Securing the Perimeter Bloomington IL
- Electric Utilities: Securing the Perimeter Blue Island IL
- Electric Utilities: Securing the Perimeter Bolingbrook IL
- Electric Utilities: Securing the Perimeter Bourbonnais IL
- Electric Utilities: Securing the Perimeter Bridgeview IL
- Electric Utilities: Securing the Perimeter Buffalo Grove IL
- Electric Utilities: Securing the Perimeter Calumet City IL
- Electric Utilities: Securing the Perimeter Carbondale IL
- Electric Utilities: Securing the Perimeter Carol Stream IL
- Electric Utilities: Securing the Perimeter Carpentersville IL
- Electric Utilities: Securing the Perimeter Champaign IL
- Electric Utilities: Securing the Perimeter Chicago Heights IL
- Electric Utilities: Securing the Perimeter Chicago IL
- Electric Utilities: Securing the Perimeter Cicero IL
- Electric Utilities: Securing the Perimeter Clarendon Hills IL
- Electric Utilities: Securing the Perimeter Collinsville IL
- Electric Utilities: Securing the Perimeter Country Club Hills IL
- Electric Utilities: Securing the Perimeter Crete IL
- Electric Utilities: Securing the Perimeter Crystal Lake IL
- Electric Utilities: Securing the Perimeter Danville IL
- Electric Utilities: Securing the Perimeter Decatur IL
- Electric Utilities: Securing the Perimeter Deerfield IL
- Electric Utilities: Securing the Perimeter Dekalb IL
- Electric Utilities: Securing the Perimeter Des Plaines IL
- Electric Utilities: Securing the Perimeter Dolton IL
- Electric Utilities: Securing the Perimeter Downers Grove IL
- Electric Utilities: Securing the Perimeter East Moline IL
- Electric Utilities: Securing the Perimeter East Peoria IL
- Electric Utilities: Securing the Perimeter East Saint Louis IL
- Electric Utilities: Securing the Perimeter Edwardsville IL
- Electric Utilities: Securing the Perimeter Effingham IL
- Electric Utilities: Securing the Perimeter Elgin IL
- Electric Utilities: Securing the Perimeter Elk Grove Village IL
- Electric Utilities: Securing the Perimeter Elmhurst IL
- Electric Utilities: Securing the Perimeter Elmwood Park IL
- Electric Utilities: Securing the Perimeter Evanston IL
- Electric Utilities: Securing the Perimeter Evergreen Park IL
- Electric Utilities: Securing the Perimeter Fairview Heights IL
- Electric Utilities: Securing the Perimeter Franklin Park IL
- Electric Utilities: Securing the Perimeter Freeport IL
- Electric Utilities: Securing the Perimeter Galesburg IL
- Electric Utilities: Securing the Perimeter Glen Ellyn IL
- Electric Utilities: Securing the Perimeter Glendale Heights IL
- Electric Utilities: Securing the Perimeter Glenview IL
- Electric Utilities: Securing the Perimeter Godfrey IL
- Electric Utilities: Securing the Perimeter Granite City IL
- Electric Utilities: Securing the Perimeter Grayslake IL
- Electric Utilities: Securing the Perimeter Gurnee IL
- Electric Utilities: Securing the Perimeter Harvey IL
- Electric Utilities: Securing the Perimeter Harwood Heights IL
- Electric Utilities: Securing the Perimeter Hazel Crest IL
- Electric Utilities: Securing the Perimeter Highland Park IL
- Electric Utilities: Securing the Perimeter Hinsdale IL
- Electric Utilities: Securing the Perimeter Homewood IL
- Electric Utilities: Securing the Perimeter Jacksonville IL
- Electric Utilities: Securing the Perimeter Joliet IL
- Electric Utilities: Securing the Perimeter Kankakee IL
- Electric Utilities: Securing the Perimeter Kewanee IL
- Electric Utilities: Securing the Perimeter La Grange IL
- Electric Utilities: Securing the Perimeter Lake Bluff IL
- Electric Utilities: Securing the Perimeter Lake Villa IL
- Electric Utilities: Securing the Perimeter Lake Zurich IL
- Electric Utilities: Securing the Perimeter Lansing IL
- Electric Utilities: Securing the Perimeter Lemont IL
- Electric Utilities: Securing the Perimeter Libertyville IL
- Electric Utilities: Securing the Perimeter Lisle IL
- Electric Utilities: Securing the Perimeter Lockport IL
- Electric Utilities: Securing the Perimeter Lombard IL
- Electric Utilities: Securing the Perimeter Loves Park IL
- Electric Utilities: Securing the Perimeter Machesney Park IL
- Electric Utilities: Securing the Perimeter Matteson IL
- Electric Utilities: Securing the Perimeter Mattoon IL
- Electric Utilities: Securing the Perimeter Maywood IL
- Electric Utilities: Securing the Perimeter Mchenry IL
- Electric Utilities: Securing the Perimeter Melrose Park IL
- Electric Utilities: Securing the Perimeter Midlothian IL
- Electric Utilities: Securing the Perimeter Mokena IL
- Electric Utilities: Securing the Perimeter Moline IL
- Electric Utilities: Securing the Perimeter Morris IL
- Electric Utilities: Securing the Perimeter Morton Grove IL
- Electric Utilities: Securing the Perimeter Morton IL
- Electric Utilities: Securing the Perimeter Mount Prospect IL
- Electric Utilities: Securing the Perimeter Mundelein IL
- Electric Utilities: Securing the Perimeter Murphysboro IL
- Electric Utilities: Securing the Perimeter Naperville IL
- Electric Utilities: Securing the Perimeter New Lenox IL
- Electric Utilities: Securing the Perimeter Niles IL
- Electric Utilities: Securing the Perimeter Normal IL
- Electric Utilities: Securing the Perimeter North Chicago IL
- Electric Utilities: Securing the Perimeter Northbrook IL
- Electric Utilities: Securing the Perimeter O Fallon IL
- Electric Utilities: Securing the Perimeter Oak Forest IL
- Electric Utilities: Securing the Perimeter Oak Lawn IL
- Electric Utilities: Securing the Perimeter Oak Park IL
- Electric Utilities: Securing the Perimeter Orland Park IL
- Electric Utilities: Securing the Perimeter Palatine IL
- Electric Utilities: Securing the Perimeter Palos Hills IL
- Electric Utilities: Securing the Perimeter Park Forest IL
- Electric Utilities: Securing the Perimeter Park Ridge IL
- Electric Utilities: Securing the Perimeter Pekin IL
- Electric Utilities: Securing the Perimeter Peoria IL
- Electric Utilities: Securing the Perimeter Plainfield IL
- Electric Utilities: Securing the Perimeter Prospect Heights IL
- Electric Utilities: Securing the Perimeter Quincy IL
- Electric Utilities: Securing the Perimeter Riverdale IL
- Electric Utilities: Securing the Perimeter Rochelle IL
- Electric Utilities: Securing the Perimeter Rock Falls IL
- Electric Utilities: Securing the Perimeter Rock Island IL
- Electric Utilities: Securing the Perimeter Rockford IL
- Electric Utilities: Securing the Perimeter Rolling Meadows IL
- Electric Utilities: Securing the Perimeter Romeoville IL
- Electric Utilities: Securing the Perimeter Roscoe IL
- Electric Utilities: Securing the Perimeter Roselle IL
- Electric Utilities: Securing the Perimeter Round Lake IL
- Electric Utilities: Securing the Perimeter Saint Charles IL
- Electric Utilities: Securing the Perimeter Schaumburg IL
- Electric Utilities: Securing the Perimeter Skokie IL
- Electric Utilities: Securing the Perimeter South Elgin IL
- Electric Utilities: Securing the Perimeter South Holland IL
- Electric Utilities: Securing the Perimeter Springfield IL
- Electric Utilities: Securing the Perimeter Streamwood IL
- Electric Utilities: Securing the Perimeter Streator IL
- Electric Utilities: Securing the Perimeter Sycamore IL
- Electric Utilities: Securing the Perimeter Taylorville IL
- Electric Utilities: Securing the Perimeter Tinley Park IL
- Electric Utilities: Securing the Perimeter Urbana IL
- Electric Utilities: Securing the Perimeter Vernon Hills IL
- Electric Utilities: Securing the Perimeter Villa Park IL
- Electric Utilities: Securing the Perimeter Waukegan IL
- Electric Utilities: Securing the Perimeter West Chicago IL
- Electric Utilities: Securing the Perimeter Westchester IL
- Electric Utilities: Securing the Perimeter Westmont IL
- Electric Utilities: Securing the Perimeter Wheaton IL
- Electric Utilities: Securing the Perimeter Wheeling IL
- Electric Utilities: Securing the Perimeter Wilmette IL
- Electric Utilities: Securing the Perimeter Wood Dale IL
- Electric Utilities: Securing the Perimeter Woodridge IL
- Electric Utilities: Securing the Perimeter Woodstock IL
- Electric Utilities: Securing the Perimeter Zion IL
Related Articles
- A Roadmap for Securing Personal Data Illinois
Protecting the personal information of customers and employees requires going beyond the obvious measures of safeguarding it from outsider intrusion, particularly in this era of heightened awareness of data theft. Savvy CIOs must make an extra effort to protect storage devices, laptops, and backup tapes, even as they rely on more traditional network and system protection to secure personal data.
- Mobility Electric Scooters Illinois
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Illinois
- Fellowes Pulsar-E Review Illinois
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review Illinois
- Looking Out for Insider Threats Illinois
- Securing Professional Graphic Design Services Illinois
- Protection for Small Companies Illinois
- The Perimeter Defense Fallacy Illinois
- Automating NERC CIP Compliance Illinois

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History