Electric Utilities: Securing the Perimeter Maryland

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.

Local Companies

Davies Consulting Inc
(301) 652-4535
6935 Wisconsin Ave
Chevy Chase, MD
Wealthengine.Com
(301) 215-5980
4339 Montgomery Ave
Bethesda, MD
Innovative Analysis
(410) 266-9652
2017 Renard Ct
Annapolis, MD
Ylk Systems Corp
(301) 854-0707
7450 Mink Hollow Rd
Highland, MD
Lclm Llc
(301) 593-2800
Silver Spring, MD
Washington Area Council of Engineering Laboratories Inc
(301) 588-8668
8811 Colesville Rd
Silver Spring, MD
Hinebaugh Business Services Llc
(301) 387-0050
Oakland, MD
Liebold & Associates Inc
(410) 544-3655
14 White Oak Ct
Severna Park, MD
Rsbp Llc
(301) 737-4737
Lexington Park, MD
Safe Sedation Management Llc
(301) 986-8010
7475 Wisconsin Crescent A
Bethesda, MD



From the Editors of CIOSC

The Comment Period for Draft 4 of the NERC CIP Standards recently expired. Under a revised implementation plan, this suite of Cyber Security Standards (formally known as CIP-002 through CIP-009) will go into effect June 1, 2006. In this article we look at one of these standards, CIP-005, in some detail, and then recommend some best practices for perimeter security. We'll also discuss the need for securing Supervisory Control and Data Acquisition (SCADA) networks utilizing the Inter-control Center Communications Protocol (ICCP) protocol.

The requirements for CIP-005

CIP-005 "requires the identification and protection of the electronic security perimeter inside which all critical cyber assets reside, as well as all access points on the perimeter." The standard contains six requirements:

  • R1. Electronic Security Perimeter Responsible entities must identify the electronic security perimeter and identify access points to it. The electronic perimeter must be inside the physical perimeter, and all cyber assets inside the perimeter are to be protected. Cyber assets that control/monitor the perimeter are to be defined as Critical Assets. A special case is made for dial-up access using non-routable protocols.
  • R2. Electronic Access Controls Responsible entities must ensure that only necessary ports and services are enabled. They must secure dial-up access. And they must identify access controls and authentication methods.
  • R3. Monitoring Electronic Access Controls For dial-up-accessible Critical Assets that use non-routable protocols, responsible entities must implement and document monitoring processes at each access point to the dial-up device (where technically feasible). They are also responsible for detecting unauthorized access attempts. In addition, they are responsible for 24x7 monitoring and periodic review of access logs.
  • R4. Cyber Vulnerability Assessment Responsible entities must produce a document identifying the vulnerability assessment process, and conduct a review to verify that only ports and services required for operations at these access points are enabled. They are also responsible for the discovery of all access points to the perimeter; a review of the controls for default accounts, passwords, and network management community strings; and the documentation of the results of the assessment, the action plan to remediate or mitigate vulnerabilities, and the status of the action plan.
  • R5. Documentation Review and Maintenance Responsible entities must ensure that all documentation reflects current configurations and processes that it is reviewed at least annually.

As CIP-002 through CIP-009 in their entirety make clear, until utility companies can ensure that all internal systems and networks are "hardened," perimeter security will be a critical first layer of defense.

Best practices

To meet these needs, effective practices should include the following at the network gateway:

  • In light of the limited IT resources in some distributed control system (DCS) environments, the purchase of an integrated solution that combines firewall, intrusion detection, and antivirus technologies in a comprehensive gateway solution is recommended. Purchasing separate firewall, intrusion detection, and antivirus technologies from different vendors can be costly to purchase, deploy, and update.
  • The firewall solution that is deployed should include both "stateful" inspection and full application inspection -- in other words, a "hybrid" firewall. It should be noted here that some companies assume a firewall alone provides sufficient gateway security. But according to the recent FBI/CSI report, one-third of all cyber attacks penetrate firewalls. Moreover, according to a recent Internet Security Threat Report, 54% of all attacks in the first six months of 2005 were so-called "blended threats," which are not addressed by firewalls.
  • Due to the multiple protocols used in the DCS environment, the intrusion detection device that is deployed should use both anomaly-based and signature-based protection.
  • The antivirus solution that is deployed should scan for at least 60,000 viruses and provide proactive protection via both signature-based and heuristics-based scanning. The antivirus solution is best deployed at the gateway, to minimize performance impact and facilitate updates. A solution that has received a high Evaluation Assurance Level (EAL), such as EAL level 4 or higher, is recommended.

Securing ICCP connections

It is also essential that electric utility companies proactively detect and prevent malicious attacks against their SCADA networks utilizing the ICCP protocol. ICCP is the primary protocol used to communicate real-time data, schedule, and control command exchanges between the energy control centers that operate these SCADA networks and remote terminal units (RTUs) and substations. While it has been developed with built-in security, in today's interconnected environment additional security measures are critical for enabling uninterrupted operations for transmission, generation, and independent service operators.

ICCP security signatures are available for appliances offering real time intrusion prevention (IPS) and detection to proactively protect critical enterprise assets. These signatures were developed to address not just known attacks, but also for protection against new and unknown exploits.
 
The signatures were lab tested by leading ICCP provider SISCO for three months, using live ICCP traffic, and produced no false positives. This testing also included a known attack procedure, which had previously resulted in crashed systems, and the signatures correctly "triggered" against this known attack.
 
The bottom line is that the ICCP protocol is one of most critical areas that must be addressed in terms of cyber security.

Conclusion

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.
 
These best practices recognize that there are many areas to cover, and there is no silver bullet. Indeed, it's an ongoing process. These best practices also require genuine (and perhaps unprecedented) collaboration between engineering, operations, and IT. Ultimately, they are designed to help electric utility companies find a balance between optimal NERC CIP compliance and profitable, cost-effective operations.

Related Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maryland
While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
- A Roadmap for Securing Personal Data Maryland
- Looking Out for Insider Threats Maryland
- Protection for Small Companies Maryland
- Automating NERC CIP Compliance Maryland
- Fellowes Pulsar-E Review Maryland
- The Perimeter Defense Fallacy Maryland
- Mobility Electric Scooters Maryland
- Securing Professional Graphic Design Services Maryland
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review Maryland
Regional Articles
- Electric Utilities: Securing the Perimeter Annapolis MD
- Electric Utilities: Securing the Perimeter Baltimore MD
- Electric Utilities: Securing the Perimeter Bel Air MD
- Electric Utilities: Securing the Perimeter Beltsville MD
- Electric Utilities: Securing the Perimeter Bethesda MD
- Electric Utilities: Securing the Perimeter Bowie MD
- Electric Utilities: Securing the Perimeter Brooklyn MD
- Electric Utilities: Securing the Perimeter Capitol Heights MD
- Electric Utilities: Securing the Perimeter Catonsville MD
- Electric Utilities: Securing the Perimeter Chevy Chase MD
- Electric Utilities: Securing the Perimeter Clinton MD
- Electric Utilities: Securing the Perimeter Cockeysville MD
- Electric Utilities: Securing the Perimeter College Park MD
- Electric Utilities: Securing the Perimeter Columbia MD
- Electric Utilities: Securing the Perimeter Crofton MD
- Electric Utilities: Securing the Perimeter Cumberland MD
- Electric Utilities: Securing the Perimeter Derwood MD
- Electric Utilities: Securing the Perimeter District Heights MD
- Electric Utilities: Securing the Perimeter Dundalk MD
- Electric Utilities: Securing the Perimeter Edgewood MD
- Electric Utilities: Securing the Perimeter Elkridge MD
- Electric Utilities: Securing the Perimeter Elkton MD
- Electric Utilities: Securing the Perimeter Ellicott City MD
- Electric Utilities: Securing the Perimeter Essex MD
- Electric Utilities: Securing the Perimeter Forest Hill MD
- Electric Utilities: Securing the Perimeter Fort Washington MD
- Electric Utilities: Securing the Perimeter Frederick MD
- Electric Utilities: Securing the Perimeter Frostburg MD
- Electric Utilities: Securing the Perimeter Gaithersburg MD
- Electric Utilities: Securing the Perimeter Germantown MD
- Electric Utilities: Securing the Perimeter Glen Burnie MD
- Electric Utilities: Securing the Perimeter Greenbelt MD
- Electric Utilities: Securing the Perimeter Gwynn Oak MD
- Electric Utilities: Securing the Perimeter Hagerstown MD
- Electric Utilities: Securing the Perimeter Halethorpe MD
- Electric Utilities: Securing the Perimeter Havre De Grace MD
- Electric Utilities: Securing the Perimeter Hyattsville MD
- Electric Utilities: Securing the Perimeter Jessup MD
- Electric Utilities: Securing the Perimeter Joppa MD
- Electric Utilities: Securing the Perimeter Kensington MD
- Electric Utilities: Securing the Perimeter La Plata MD
- Electric Utilities: Securing the Perimeter Lanham MD
- Electric Utilities: Securing the Perimeter Laurel MD
- Electric Utilities: Securing the Perimeter Lexington Park MD
- Electric Utilities: Securing the Perimeter Lusby MD
- Electric Utilities: Securing the Perimeter Lutherville Timonium MD
- Electric Utilities: Securing the Perimeter Middle River MD
- Electric Utilities: Securing the Perimeter Millersville MD
- Electric Utilities: Securing the Perimeter Montgomery Village MD
- Electric Utilities: Securing the Perimeter Mount Airy MD
- Electric Utilities: Securing the Perimeter Nottingham MD
- Electric Utilities: Securing the Perimeter Odenton MD
- Electric Utilities: Securing the Perimeter Olney MD
- Electric Utilities: Securing the Perimeter Owings Mills MD
- Electric Utilities: Securing the Perimeter Oxon Hill MD
- Electric Utilities: Securing the Perimeter Parkville MD
- Electric Utilities: Securing the Perimeter Pasadena MD
- Electric Utilities: Securing the Perimeter Pikesville MD
- Electric Utilities: Securing the Perimeter Potomac MD
- Electric Utilities: Securing the Perimeter Randallstown MD
- Electric Utilities: Securing the Perimeter Reisterstown MD
- Electric Utilities: Securing the Perimeter Rockville MD
- Electric Utilities: Securing the Perimeter Rosedale MD
- Electric Utilities: Securing the Perimeter Salisbury MD
- Electric Utilities: Securing the Perimeter Severn MD
- Electric Utilities: Securing the Perimeter Severna Park MD
- Electric Utilities: Securing the Perimeter Silver Spring MD
- Electric Utilities: Securing the Perimeter Suitland MD
- Electric Utilities: Securing the Perimeter Sykesville MD
- Electric Utilities: Securing the Perimeter Takoma Park MD
- Electric Utilities: Securing the Perimeter Temple Hills MD
- Electric Utilities: Securing the Perimeter Towson MD
- Electric Utilities: Securing the Perimeter Upper Marlboro MD
- Electric Utilities: Securing the Perimeter Waldorf MD
- Electric Utilities: Securing the Perimeter Westminster MD
- Electric Utilities: Securing the Perimeter Windsor Mill MD
Related Articles
- Automating NERC CIP Compliance Maryland
Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.
- The Perimeter Defense Fallacy Maryland
- Fellowes Pulsar-E Review Maryland
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maryland
- Looking Out for Insider Threats Maryland
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review Maryland
- Mobility Electric Scooters Maryland
- A Roadmap for Securing Personal Data Maryland
- Securing Professional Graphic Design Services Maryland
- Protection for Small Companies Maryland

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History