Electric Utilities: Securing the Perimeter Michigan

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.

Local Companies

Rural Management Group Ltd
(989) 742-4020
24340 Veterans Memorial Hw
Hillman, MI
Designers Management Group Llc
(616) 974-3005
6143 28th St SE
Grand Rapids, MI
Project Innovations
(248) 476-7577
22000 Springbrook Ave Ste 104
Farmington Hills, MI
Roegan Enterprises
(313) 659-0060
Detroit, MI
Signature Inc
(734) 426-2000
4701 Midway Dr
Dexter, MI
New Angle Communications
(248) 641-8680
2304 Oak River Ct
Troy, MI
Computech Services Inc
(313) 563-8184
4460 Gertrude St
Dearborn Heights, MI
Lapeer County of
(810) 245-1648
1800 Imlay City Rd
Lapeer, MI
S E Corp
(248) 350-9224
24768 Lahser Rd
Southfield, MI
Work From Home
(269) 556-0847
3804 Lincoln Ave
Saint Joseph, MI



From the Editors of CIOSC

The Comment Period for Draft 4 of the NERC CIP Standards recently expired. Under a revised implementation plan, this suite of Cyber Security Standards (formally known as CIP-002 through CIP-009) will go into effect June 1, 2006. In this article we look at one of these standards, CIP-005, in some detail, and then recommend some best practices for perimeter security. We'll also discuss the need for securing Supervisory Control and Data Acquisition (SCADA) networks utilizing the Inter-control Center Communications Protocol (ICCP) protocol.

The requirements for CIP-005

CIP-005 "requires the identification and protection of the electronic security perimeter inside which all critical cyber assets reside, as well as all access points on the perimeter." The standard contains six requirements:

  • R1. Electronic Security Perimeter Responsible entities must identify the electronic security perimeter and identify access points to it. The electronic perimeter must be inside the physical perimeter, and all cyber assets inside the perimeter are to be protected. Cyber assets that control/monitor the perimeter are to be defined as Critical Assets. A special case is made for dial-up access using non-routable protocols.
  • R2. Electronic Access Controls Responsible entities must ensure that only necessary ports and services are enabled. They must secure dial-up access. And they must identify access controls and authentication methods.
  • R3. Monitoring Electronic Access Controls For dial-up-accessible Critical Assets that use non-routable protocols, responsible entities must implement and document monitoring processes at each access point to the dial-up device (where technically feasible). They are also responsible for detecting unauthorized access attempts. In addition, they are responsible for 24x7 monitoring and periodic review of access logs.
  • R4. Cyber Vulnerability Assessment Responsible entities must produce a document identifying the vulnerability assessment process, and conduct a review to verify that only ports and services required for operations at these access points are enabled. They are also responsible for the discovery of all access points to the perimeter; a review of the controls for default accounts, passwords, and network management community strings; and the documentation of the results of the assessment, the action plan to remediate or mitigate vulnerabilities, and the status of the action plan.
  • R5. Documentation Review and Maintenance Responsible entities must ensure that all documentation reflects current configurations and processes that it is reviewed at least annually.

As CIP-002 through CIP-009 in their entirety make clear, until utility companies can ensure that all internal systems and networks are "hardened," perimeter security will be a critical first layer of defense.

Best practices

To meet these needs, effective practices should include the following at the network gateway:

  • In light of the limited IT resources in some distributed control system (DCS) environments, the purchase of an integrated solution that combines firewall, intrusion detection, and antivirus technologies in a comprehensive gateway solution is recommended. Purchasing separate firewall, intrusion detection, and antivirus technologies from different vendors can be costly to purchase, deploy, and update.
  • The firewall solution that is deployed should include both "stateful" inspection and full application inspection -- in other words, a "hybrid" firewall. It should be noted here that some companies assume a firewall alone provides sufficient gateway security. But according to the recent FBI/CSI report, one-third of all cyber attacks penetrate firewalls. Moreover, according to a recent Internet Security Threat Report, 54% of all attacks in the first six months of 2005 were so-called "blended threats," which are not addressed by firewalls.
  • Due to the multiple protocols used in the DCS environment, the intrusion detection device that is deployed should use both anomaly-based and signature-based protection.
  • The antivirus solution that is deployed should scan for at least 60,000 viruses and provide proactive protection via both signature-based and heuristics-based scanning. The antivirus solution is best deployed at the gateway, to minimize performance impact and facilitate updates. A solution that has received a high Evaluation Assurance Level (EAL), such as EAL level 4 or higher, is recommended.

Securing ICCP connections

It is also essential that electric utility companies proactively detect and prevent malicious attacks against their SCADA networks utilizing the ICCP protocol. ICCP is the primary protocol used to communicate real-time data, schedule, and control command exchanges between the energy control centers that operate these SCADA networks and remote terminal units (RTUs) and substations. While it has been developed with built-in security, in today's interconnected environment additional security measures are critical for enabling uninterrupted operations for transmission, generation, and independent service operators.

ICCP security signatures are available for appliances offering real time intrusion prevention (IPS) and detection to proactively protect critical enterprise assets. These signatures were developed to address not just known attacks, but also for protection against new and unknown exploits.
 
The signatures were lab tested by leading ICCP provider SISCO for three months, using live ICCP traffic, and produced no false positives. This testing also included a known attack procedure, which had previously resulted in crashed systems, and the signatures correctly "triggered" against this known attack.
 
The bottom line is that the ICCP protocol is one of most critical areas that must be addressed in terms of cyber security.

Conclusion

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.
 
These best practices recognize that there are many areas to cover, and there is no silver bullet. Indeed, it's an ongoing process. These best practices also require genuine (and perhaps unprecedented) collaboration between engineering, operations, and IT. Ultimately, they are designed to help electric utility companies find a balance between optimal NERC CIP compliance and profitable, cost-effective operations.

Related Articles
- Automating NERC CIP Compliance Michigan
Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.
- A Roadmap for Securing Personal Data Michigan
- Mobility Electric Scooters Michigan
- Protection for Small Companies Michigan
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Michigan
- The Perimeter Defense Fallacy Michigan
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review Michigan
- Fellowes Pulsar-E Review Michigan
- Looking Out for Insider Threats Michigan
- Securing Professional Graphic Design Services Michigan
Regional Articles
- Electric Utilities: Securing the Perimeter Adrian MI
- Electric Utilities: Securing the Perimeter Allegan MI
- Electric Utilities: Securing the Perimeter Allen Park MI
- Electric Utilities: Securing the Perimeter Alpena MI
- Electric Utilities: Securing the Perimeter Ann Arbor MI
- Electric Utilities: Securing the Perimeter Auburn Hills MI
- Electric Utilities: Securing the Perimeter Battle Creek MI
- Electric Utilities: Securing the Perimeter Bay City MI
- Electric Utilities: Securing the Perimeter Belleville MI
- Electric Utilities: Securing the Perimeter Benton Harbor MI
- Electric Utilities: Securing the Perimeter Berkley MI
- Electric Utilities: Securing the Perimeter Big Rapids MI
- Electric Utilities: Securing the Perimeter Bloomfield Hills MI
- Electric Utilities: Securing the Perimeter Brighton MI
- Electric Utilities: Securing the Perimeter Burton MI
- Electric Utilities: Securing the Perimeter Cadillac MI
- Electric Utilities: Securing the Perimeter Canton MI
- Electric Utilities: Securing the Perimeter Cheboygan MI
- Electric Utilities: Securing the Perimeter Clarkston MI
- Electric Utilities: Securing the Perimeter Clinton Township MI
- Electric Utilities: Securing the Perimeter Clio MI
- Electric Utilities: Securing the Perimeter Coldwater MI
- Electric Utilities: Securing the Perimeter Commerce Township MI
- Electric Utilities: Securing the Perimeter Comstock Park MI
- Electric Utilities: Securing the Perimeter Davison MI
- Electric Utilities: Securing the Perimeter Dearborn Heights MI
- Electric Utilities: Securing the Perimeter Dearborn MI
- Electric Utilities: Securing the Perimeter Detroit MI
- Electric Utilities: Securing the Perimeter Dowagiac MI
- Electric Utilities: Securing the Perimeter East Lansing MI
- Electric Utilities: Securing the Perimeter Eastpointe MI
- Electric Utilities: Securing the Perimeter Eaton Rapids MI
- Electric Utilities: Securing the Perimeter Escanaba MI
- Electric Utilities: Securing the Perimeter Farmington MI
- Electric Utilities: Securing the Perimeter Fenton MI
- Electric Utilities: Securing the Perimeter Ferndale MI
- Electric Utilities: Securing the Perimeter Flat Rock MI
- Electric Utilities: Securing the Perimeter Flint MI
- Electric Utilities: Securing the Perimeter Flushing MI
- Electric Utilities: Securing the Perimeter Fort Gratiot MI
- Electric Utilities: Securing the Perimeter Fraser MI
- Electric Utilities: Securing the Perimeter Garden City MI
- Electric Utilities: Securing the Perimeter Gaylord MI
- Electric Utilities: Securing the Perimeter Gladwin MI
- Electric Utilities: Securing the Perimeter Grand Blanc MI
- Electric Utilities: Securing the Perimeter Grand Haven MI
- Electric Utilities: Securing the Perimeter Grand Ledge MI
- Electric Utilities: Securing the Perimeter Grand Rapids MI
- Electric Utilities: Securing the Perimeter Grandville MI
- Electric Utilities: Securing the Perimeter Grosse Pointe MI
- Electric Utilities: Securing the Perimeter Hamtramck MI
- Electric Utilities: Securing the Perimeter Harper Woods MI
- Electric Utilities: Securing the Perimeter Harrison Township MI
- Electric Utilities: Securing the Perimeter Hazel Park MI
- Electric Utilities: Securing the Perimeter Highland Park MI
- Electric Utilities: Securing the Perimeter Hillsdale MI
- Electric Utilities: Securing the Perimeter Holland MI
- Electric Utilities: Securing the Perimeter Holly MI
- Electric Utilities: Securing the Perimeter Holt MI
- Electric Utilities: Securing the Perimeter Howell MI
- Electric Utilities: Securing the Perimeter Hudsonville MI
- Electric Utilities: Securing the Perimeter Inkster MI
- Electric Utilities: Securing the Perimeter Ionia MI
- Electric Utilities: Securing the Perimeter Jackson MI
- Electric Utilities: Securing the Perimeter Jenison MI
- Electric Utilities: Securing the Perimeter Kalamazoo MI
- Electric Utilities: Securing the Perimeter Lake Orion MI
- Electric Utilities: Securing the Perimeter Lansing MI
- Electric Utilities: Securing the Perimeter Lapeer MI
- Electric Utilities: Securing the Perimeter Lincoln Park MI
- Electric Utilities: Securing the Perimeter Livonia MI
- Electric Utilities: Securing the Perimeter Ludington MI
- Electric Utilities: Securing the Perimeter Macomb MI
- Electric Utilities: Securing the Perimeter Marquette MI
- Electric Utilities: Securing the Perimeter Midland MI
- Electric Utilities: Securing the Perimeter Monroe MI
- Electric Utilities: Securing the Perimeter Mount Clemens MI
- Electric Utilities: Securing the Perimeter Mount Morris MI
- Electric Utilities: Securing the Perimeter Mount Pleasant MI
- Electric Utilities: Securing the Perimeter Muskegon MI
- Electric Utilities: Securing the Perimeter New Baltimore MI
- Electric Utilities: Securing the Perimeter Niles MI
- Electric Utilities: Securing the Perimeter Northville MI
- Electric Utilities: Securing the Perimeter Novi MI
- Electric Utilities: Securing the Perimeter Oak Park MI
- Electric Utilities: Securing the Perimeter Okemos MI
- Electric Utilities: Securing the Perimeter Owosso MI
- Electric Utilities: Securing the Perimeter Petoskey MI
- Electric Utilities: Securing the Perimeter Pinckney MI
- Electric Utilities: Securing the Perimeter Plymouth MI
- Electric Utilities: Securing the Perimeter Pontiac MI
- Electric Utilities: Securing the Perimeter Port Huron MI
- Electric Utilities: Securing the Perimeter Portage MI
- Electric Utilities: Securing the Perimeter Redford MI
- Electric Utilities: Securing the Perimeter Rochester MI
- Electric Utilities: Securing the Perimeter Rockford MI
- Electric Utilities: Securing the Perimeter Romulus MI
- Electric Utilities: Securing the Perimeter Roseville MI
- Electric Utilities: Securing the Perimeter Royal Oak MI
- Electric Utilities: Securing the Perimeter Saginaw MI
- Electric Utilities: Securing the Perimeter Saint Clair Shores MI
- Electric Utilities: Securing the Perimeter Saint Johns MI
- Electric Utilities: Securing the Perimeter Saline MI
- Electric Utilities: Securing the Perimeter Sault Sainte Marie MI
- Electric Utilities: Securing the Perimeter South Haven MI
- Electric Utilities: Securing the Perimeter South Lyon MI
- Electric Utilities: Securing the Perimeter Southfield MI
- Electric Utilities: Securing the Perimeter Southgate MI
- Electric Utilities: Securing the Perimeter Sterling Heights MI
- Electric Utilities: Securing the Perimeter Sturgis MI
- Electric Utilities: Securing the Perimeter Swartz Creek MI
- Electric Utilities: Securing the Perimeter Taylor MI
- Electric Utilities: Securing the Perimeter Temperance MI
- Electric Utilities: Securing the Perimeter Three Rivers MI
- Electric Utilities: Securing the Perimeter Traverse City MI
- Electric Utilities: Securing the Perimeter Trenton MI
- Electric Utilities: Securing the Perimeter Troy MI
- Electric Utilities: Securing the Perimeter Utica MI
- Electric Utilities: Securing the Perimeter Walled Lake MI
- Electric Utilities: Securing the Perimeter Warren MI
- Electric Utilities: Securing the Perimeter Waterford MI
- Electric Utilities: Securing the Perimeter West Bloomfield MI
- Electric Utilities: Securing the Perimeter Westland MI
- Electric Utilities: Securing the Perimeter White Lake MI
- Electric Utilities: Securing the Perimeter Wixom MI
- Electric Utilities: Securing the Perimeter Wyandotte MI
- Electric Utilities: Securing the Perimeter Wyoming MI
- Electric Utilities: Securing the Perimeter Ypsilanti MI
- Electric Utilities: Securing the Perimeter Zeeland MI
Related Articles
- Fellowes Pulsar-E Review Michigan
The Fellowes Pulsar-E is the least expensive electric plastic comb binding machine that is offered by Fellowes.It is an electric version of the manual Pulsar 300 comb binding machine with virtually all of the same features.This machine has a distinctive and stylish contemporary look that is designed to fit inside a small or medium sized office environment.
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Michigan
- Protection for Small Companies Michigan
- Looking Out for Insider Threats Michigan
- A Roadmap for Securing Personal Data Michigan
- Mobility Electric Scooters Michigan
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review Michigan
- Securing Professional Graphic Design Services Michigan
- The Perimeter Defense Fallacy Michigan
- Automating NERC CIP Compliance Michigan

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History