Electric Utilities: Securing the Perimeter New York

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.

Local Companies

The Great Neck Manhasset Community Child Care Partnership Inc
(516) 504-0150
3 Saint Pauls Pl
Great Neck, NY
Hempstead Town of
(516) 489-5000
Hempstead, NY
Happy Cleaning Man
(718) 531-1700
2334 Ralph Ave
Brooklyn, NY
M & M Management Co Llc
(212) 281-0001
2495 Adam Clayton Powell
New York, NY
Allomet Partners
(212) 370-9422
E 41st St
New York, NY
Deco Systems Inc
(212) 355-1448
415 E 52nd St
New York, NY
Amicus Business Consulting
(518) 452-2818
4 Airline Dr
Albany, NY
Kanick and Co
(716) 651-0111
Lancaster, NY
Impression Printing & Graphics
(212) 564-0200
200 W 37th St
New York, NY
Grady Assocs
(585) 271-3720
2604 Elmwood Ave Ste 327
Rochester, NY



From the Editors of CIOSC

The Comment Period for Draft 4 of the NERC CIP Standards recently expired. Under a revised implementation plan, this suite of Cyber Security Standards (formally known as CIP-002 through CIP-009) will go into effect June 1, 2006. In this article we look at one of these standards, CIP-005, in some detail, and then recommend some best practices for perimeter security. We'll also discuss the need for securing Supervisory Control and Data Acquisition (SCADA) networks utilizing the Inter-control Center Communications Protocol (ICCP) protocol.

The requirements for CIP-005

CIP-005 "requires the identification and protection of the electronic security perimeter inside which all critical cyber assets reside, as well as all access points on the perimeter." The standard contains six requirements:

  • R1. Electronic Security Perimeter Responsible entities must identify the electronic security perimeter and identify access points to it. The electronic perimeter must be inside the physical perimeter, and all cyber assets inside the perimeter are to be protected. Cyber assets that control/monitor the perimeter are to be defined as Critical Assets. A special case is made for dial-up access using non-routable protocols.
  • R2. Electronic Access Controls Responsible entities must ensure that only necessary ports and services are enabled. They must secure dial-up access. And they must identify access controls and authentication methods.
  • R3. Monitoring Electronic Access Controls For dial-up-accessible Critical Assets that use non-routable protocols, responsible entities must implement and document monitoring processes at each access point to the dial-up device (where technically feasible). They are also responsible for detecting unauthorized access attempts. In addition, they are responsible for 24x7 monitoring and periodic review of access logs.
  • R4. Cyber Vulnerability Assessment Responsible entities must produce a document identifying the vulnerability assessment process, and conduct a review to verify that only ports and services required for operations at these access points are enabled. They are also responsible for the discovery of all access points to the perimeter; a review of the controls for default accounts, passwords, and network management community strings; and the documentation of the results of the assessment, the action plan to remediate or mitigate vulnerabilities, and the status of the action plan.
  • R5. Documentation Review and Maintenance Responsible entities must ensure that all documentation reflects current configurations and processes that it is reviewed at least annually.

As CIP-002 through CIP-009 in their entirety make clear, until utility companies can ensure that all internal systems and networks are "hardened," perimeter security will be a critical first layer of defense.

Best practices

To meet these needs, effective practices should include the following at the network gateway:

  • In light of the limited IT resources in some distributed control system (DCS) environments, the purchase of an integrated solution that combines firewall, intrusion detection, and antivirus technologies in a comprehensive gateway solution is recommended. Purchasing separate firewall, intrusion detection, and antivirus technologies from different vendors can be costly to purchase, deploy, and update.
  • The firewall solution that is deployed should include both "stateful" inspection and full application inspection -- in other words, a "hybrid" firewall. It should be noted here that some companies assume a firewall alone provides sufficient gateway security. But according to the recent FBI/CSI report, one-third of all cyber attacks penetrate firewalls. Moreover, according to a recent Internet Security Threat Report, 54% of all attacks in the first six months of 2005 were so-called "blended threats," which are not addressed by firewalls.
  • Due to the multiple protocols used in the DCS environment, the intrusion detection device that is deployed should use both anomaly-based and signature-based protection.
  • The antivirus solution that is deployed should scan for at least 60,000 viruses and provide proactive protection via both signature-based and heuristics-based scanning. The antivirus solution is best deployed at the gateway, to minimize performance impact and facilitate updates. A solution that has received a high Evaluation Assurance Level (EAL), such as EAL level 4 or higher, is recommended.

Securing ICCP connections

It is also essential that electric utility companies proactively detect and prevent malicious attacks against their SCADA networks utilizing the ICCP protocol. ICCP is the primary protocol used to communicate real-time data, schedule, and control command exchanges between the energy control centers that operate these SCADA networks and remote terminal units (RTUs) and substations. While it has been developed with built-in security, in today's interconnected environment additional security measures are critical for enabling uninterrupted operations for transmission, generation, and independent service operators.

ICCP security signatures are available for appliances offering real time intrusion prevention (IPS) and detection to proactively protect critical enterprise assets. These signatures were developed to address not just known attacks, but also for protection against new and unknown exploits.
 
The signatures were lab tested by leading ICCP provider SISCO for three months, using live ICCP traffic, and produced no false positives. This testing also included a known attack procedure, which had previously resulted in crashed systems, and the signatures correctly "triggered" against this known attack.
 
The bottom line is that the ICCP protocol is one of most critical areas that must be addressed in terms of cyber security.

Conclusion

As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.
 
These best practices recognize that there are many areas to cover, and there is no silver bullet. Indeed, it's an ongoing process. These best practices also require genuine (and perhaps unprecedented) collaboration between engineering, operations, and IT. Ultimately, they are designed to help electric utility companies find a balance between optimal NERC CIP compliance and profitable, cost-effective operations.

Related Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines New York
While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
- Protection for Small Companies New York
- Mobility Electric Scooters New York
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review New York
- Looking Out for Insider Threats New York
- The Perimeter Defense Fallacy New York
- Fellowes Pulsar-E Review New York
- A Roadmap for Securing Personal Data New York
- Securing Professional Graphic Design Services New York
- Automating NERC CIP Compliance New York
Regional Articles
- Electric Utilities: Securing the Perimeter Albany NY
- Electric Utilities: Securing the Perimeter Amityville NY
- Electric Utilities: Securing the Perimeter Amsterdam NY
- Electric Utilities: Securing the Perimeter Arverne NY
- Electric Utilities: Securing the Perimeter Astoria NY
- Electric Utilities: Securing the Perimeter Auburn NY
- Electric Utilities: Securing the Perimeter Babylon NY
- Electric Utilities: Securing the Perimeter Baldwin NY
- Electric Utilities: Securing the Perimeter Baldwinsville NY
- Electric Utilities: Securing the Perimeter Ballston Spa NY
- Electric Utilities: Securing the Perimeter Bay Shore NY
- Electric Utilities: Securing the Perimeter Bayside NY
- Electric Utilities: Securing the Perimeter Beacon NY
- Electric Utilities: Securing the Perimeter Bellerose NY
- Electric Utilities: Securing the Perimeter Bellmore NY
- Electric Utilities: Securing the Perimeter Bethpage NY
- Electric Utilities: Securing the Perimeter Binghamton NY
- Electric Utilities: Securing the Perimeter Brentwood NY
- Electric Utilities: Securing the Perimeter Brewster NY
- Electric Utilities: Securing the Perimeter Brockport NY
- Electric Utilities: Securing the Perimeter Bronx NY
- Electric Utilities: Securing the Perimeter Bronxville NY
- Electric Utilities: Securing the Perimeter Brooklyn NY
- Electric Utilities: Securing the Perimeter Buffalo NY
- Electric Utilities: Securing the Perimeter Cambria Heights NY
- Electric Utilities: Securing the Perimeter Camillus NY
- Electric Utilities: Securing the Perimeter Canandaigua NY
- Electric Utilities: Securing the Perimeter Centereach NY
- Electric Utilities: Securing the Perimeter Central Islip NY
- Electric Utilities: Securing the Perimeter Clifton Park NY
- Electric Utilities: Securing the Perimeter Cohoes NY
- Electric Utilities: Securing the Perimeter College Point NY
- Electric Utilities: Securing the Perimeter Commack NY
- Electric Utilities: Securing the Perimeter Copiague NY
- Electric Utilities: Securing the Perimeter Coram NY
- Electric Utilities: Securing the Perimeter Corning NY
- Electric Utilities: Securing the Perimeter Corona NY
- Electric Utilities: Securing the Perimeter Cortland NY
- Electric Utilities: Securing the Perimeter Cortlandt Manor NY
- Electric Utilities: Securing the Perimeter Deer Park NY
- Electric Utilities: Securing the Perimeter Delmar NY
- Electric Utilities: Securing the Perimeter Depew NY
- Electric Utilities: Securing the Perimeter Dunkirk NY
- Electric Utilities: Securing the Perimeter East Amherst NY
- Electric Utilities: Securing the Perimeter East Aurora NY
- Electric Utilities: Securing the Perimeter East Elmhurst NY
- Electric Utilities: Securing the Perimeter East Islip NY
- Electric Utilities: Securing the Perimeter East Meadow NY
- Electric Utilities: Securing the Perimeter East Northport NY
- Electric Utilities: Securing the Perimeter East Setauket NY
- Electric Utilities: Securing the Perimeter East Syracuse NY
- Electric Utilities: Securing the Perimeter Elmhurst NY
- Electric Utilities: Securing the Perimeter Elmira NY
- Electric Utilities: Securing the Perimeter Elmont NY
- Electric Utilities: Securing the Perimeter Endicott NY
- Electric Utilities: Securing the Perimeter Fairport NY
- Electric Utilities: Securing the Perimeter Far Rockaway NY
- Electric Utilities: Securing the Perimeter Farmingdale NY
- Electric Utilities: Securing the Perimeter Farmingville NY
- Electric Utilities: Securing the Perimeter Floral Park NY
- Electric Utilities: Securing the Perimeter Flushing NY
- Electric Utilities: Securing the Perimeter Forest Hills NY
- Electric Utilities: Securing the Perimeter Franklin Square NY
- Electric Utilities: Securing the Perimeter Fredonia NY
- Electric Utilities: Securing the Perimeter Freeport NY
- Electric Utilities: Securing the Perimeter Fresh Meadows NY
- Electric Utilities: Securing the Perimeter Fulton NY
- Electric Utilities: Securing the Perimeter Garden City NY
- Electric Utilities: Securing the Perimeter Glen Cove NY
- Electric Utilities: Securing the Perimeter Glen Oaks NY
- Electric Utilities: Securing the Perimeter Glens Falls NY
- Electric Utilities: Securing the Perimeter Gloversville NY
- Electric Utilities: Securing the Perimeter Great Neck NY
- Electric Utilities: Securing the Perimeter Hamburg NY
- Electric Utilities: Securing the Perimeter Hauppauge NY
- Electric Utilities: Securing the Perimeter Hempstead NY
- Electric Utilities: Securing the Perimeter Hicksville NY
- Electric Utilities: Securing the Perimeter Hilton NY
- Electric Utilities: Securing the Perimeter Holbrook NY
- Electric Utilities: Securing the Perimeter Hollis NY
- Electric Utilities: Securing the Perimeter Hopewell Junction NY
- Electric Utilities: Securing the Perimeter Horseheads NY
- Electric Utilities: Securing the Perimeter Howard Beach NY
- Electric Utilities: Securing the Perimeter Huntington NY
- Electric Utilities: Securing the Perimeter Huntington Station NY
- Electric Utilities: Securing the Perimeter Islip NY
- Electric Utilities: Securing the Perimeter Ithaca NY
- Electric Utilities: Securing the Perimeter Jackson Heights NY
- Electric Utilities: Securing the Perimeter Jamaica NY
- Electric Utilities: Securing the Perimeter Jamestown NY
- Electric Utilities: Securing the Perimeter Kew Gardens NY
- Electric Utilities: Securing the Perimeter Kings Park NY
- Electric Utilities: Securing the Perimeter Kingston NY
- Electric Utilities: Securing the Perimeter Lancaster NY
- Electric Utilities: Securing the Perimeter Larchmont NY
- Electric Utilities: Securing the Perimeter Latham NY
- Electric Utilities: Securing the Perimeter Levittown NY
- Electric Utilities: Securing the Perimeter Lindenhurst NY
- Electric Utilities: Securing the Perimeter Little Neck NY
- Electric Utilities: Securing the Perimeter Liverpool NY
- Electric Utilities: Securing the Perimeter Lockport NY
- Electric Utilities: Securing the Perimeter Long Beach NY
- Electric Utilities: Securing the Perimeter Long Island City NY
- Electric Utilities: Securing the Perimeter Lynbrook NY
- Electric Utilities: Securing the Perimeter Mahopac NY
- Electric Utilities: Securing the Perimeter Malone NY
- Electric Utilities: Securing the Perimeter Mamaroneck NY
- Electric Utilities: Securing the Perimeter Manhasset NY
- Electric Utilities: Securing the Perimeter Manlius NY
- Electric Utilities: Securing the Perimeter Maspeth NY
- Electric Utilities: Securing the Perimeter Massapequa NY
- Electric Utilities: Securing the Perimeter Massapequa Park NY
- Electric Utilities: Securing the Perimeter Massena NY
- Electric Utilities: Securing the Perimeter Mastic NY
- Electric Utilities: Securing the Perimeter Melville NY
- Electric Utilities: Securing the Perimeter Merrick NY
- Electric Utilities: Securing the Perimeter Middle Village NY
- Electric Utilities: Securing the Perimeter Middletown NY
- Electric Utilities: Securing the Perimeter Mineola NY
- Electric Utilities: Securing the Perimeter Monroe NY
- Electric Utilities: Securing the Perimeter Monsey NY
- Electric Utilities: Securing the Perimeter Mount Kisco NY
- Electric Utilities: Securing the Perimeter Mount Vernon NY
- Electric Utilities: Securing the Perimeter Nanuet NY
- Electric Utilities: Securing the Perimeter New City NY
- Electric Utilities: Securing the Perimeter New Hartford NY
- Electric Utilities: Securing the Perimeter New Hyde Park NY
- Electric Utilities: Securing the Perimeter New Paltz NY
- Electric Utilities: Securing the Perimeter New Rochelle NY
- Electric Utilities: Securing the Perimeter New Windsor NY
- Electric Utilities: Securing the Perimeter New York NY
- Electric Utilities: Securing the Perimeter Newburgh NY
- Electric Utilities: Securing the Perimeter Niagara Falls NY
- Electric Utilities: Securing the Perimeter North Babylon NY
- Electric Utilities: Securing the Perimeter North Tonawanda NY
- Electric Utilities: Securing the Perimeter Nyack NY
- Electric Utilities: Securing the Perimeter Oakland Gardens NY
- Electric Utilities: Securing the Perimeter Oceanside NY
- Electric Utilities: Securing the Perimeter Ogdensburg NY
- Electric Utilities: Securing the Perimeter Olean NY
- Electric Utilities: Securing the Perimeter Oneonta NY
- Electric Utilities: Securing the Perimeter Orchard Park NY
- Electric Utilities: Securing the Perimeter Ossining NY
- Electric Utilities: Securing the Perimeter Oswego NY
- Electric Utilities: Securing the Perimeter Ozone Park NY
- Electric Utilities: Securing the Perimeter Patchogue NY
- Electric Utilities: Securing the Perimeter Pearl River NY
- Electric Utilities: Securing the Perimeter Peekskill NY
- Electric Utilities: Securing the Perimeter Penfield NY
- Electric Utilities: Securing the Perimeter Pittsford NY
- Electric Utilities: Securing the Perimeter Plainview NY
- Electric Utilities: Securing the Perimeter Plattsburgh NY
- Electric Utilities: Securing the Perimeter Port Chester NY
- Electric Utilities: Securing the Perimeter Port Jefferson Station NY
- Electric Utilities: Securing the Perimeter Port Washington NY
- Electric Utilities: Securing the Perimeter Potsdam NY
- Electric Utilities: Securing the Perimeter Poughkeepsie NY
- Electric Utilities: Securing the Perimeter Queens Village NY
- Electric Utilities: Securing the Perimeter Queensbury NY
- Electric Utilities: Securing the Perimeter Rego Park NY
- Electric Utilities: Securing the Perimeter Rensselaer NY
- Electric Utilities: Securing the Perimeter Richmond Hill NY
- Electric Utilities: Securing the Perimeter Ridgewood NY
- Electric Utilities: Securing the Perimeter Riverhead NY
- Electric Utilities: Securing the Perimeter Rochester NY
- Electric Utilities: Securing the Perimeter Rockaway Park NY
- Electric Utilities: Securing the Perimeter Rockville Centre NY
- Electric Utilities: Securing the Perimeter Rome NY
- Electric Utilities: Securing the Perimeter Ronkonkoma NY
- Electric Utilities: Securing the Perimeter Roosevelt NY
- Electric Utilities: Securing the Perimeter Rosedale NY
- Electric Utilities: Securing the Perimeter Rye NY
- Electric Utilities: Securing the Perimeter Saint Albans NY
- Electric Utilities: Securing the Perimeter Saint James NY
- Electric Utilities: Securing the Perimeter Saratoga Springs NY
- Electric Utilities: Securing the Perimeter Saugerties NY
- Electric Utilities: Securing the Perimeter Sayville NY
- Electric Utilities: Securing the Perimeter Scarsdale NY
- Electric Utilities: Securing the Perimeter Schenectady NY
- Electric Utilities: Securing the Perimeter Selden NY
- Electric Utilities: Securing the Perimeter Shirley NY
- Electric Utilities: Securing the Perimeter Smithtown NY
- Electric Utilities: Securing the Perimeter South Ozone Park NY
- Electric Utilities: Securing the Perimeter South Richmond Hill NY
- Electric Utilities: Securing the Perimeter Spencerport NY
- Electric Utilities: Securing the Perimeter Spring Valley NY
- Electric Utilities: Securing the Perimeter Springfield Gardens NY
- Electric Utilities: Securing the Perimeter Staten Island NY
- Electric Utilities: Securing the Perimeter Stony Brook NY
- Electric Utilities: Securing the Perimeter Suffern NY
- Electric Utilities: Securing the Perimeter Sunnyside NY
- Electric Utilities: Securing the Perimeter Syosset NY
- Electric Utilities: Securing the Perimeter Syracuse NY
- Electric Utilities: Securing the Perimeter Tarrytown NY
- Electric Utilities: Securing the Perimeter Tonawanda NY
- Electric Utilities: Securing the Perimeter Troy NY
- Electric Utilities: Securing the Perimeter Uniondale NY
- Electric Utilities: Securing the Perimeter Utica NY
- Electric Utilities: Securing the Perimeter Valley Stream NY
- Electric Utilities: Securing the Perimeter Vestal NY
- Electric Utilities: Securing the Perimeter Wantagh NY
- Electric Utilities: Securing the Perimeter Wappingers Falls NY
- Electric Utilities: Securing the Perimeter Watertown NY
- Electric Utilities: Securing the Perimeter Watervliet NY
- Electric Utilities: Securing the Perimeter Webster NY
- Electric Utilities: Securing the Perimeter West Babylon NY
- Electric Utilities: Securing the Perimeter West Hempstead NY
- Electric Utilities: Securing the Perimeter West Islip NY
- Electric Utilities: Securing the Perimeter Westbury NY
- Electric Utilities: Securing the Perimeter White Plains NY
- Electric Utilities: Securing the Perimeter Whitestone NY
- Electric Utilities: Securing the Perimeter Woodhaven NY
- Electric Utilities: Securing the Perimeter Woodside NY
- Electric Utilities: Securing the Perimeter Wyandanch NY
- Electric Utilities: Securing the Perimeter Yonkers NY
- Electric Utilities: Securing the Perimeter Yorktown Heights NY
Related Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines New York
While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
- A Roadmap for Securing Personal Data New York
- Securing Professional Graphic Design Services New York
- Tamerica Tashin 210epb Electric Plastic Comb Binding Machine Review New York
- Looking Out for Insider Threats New York
- Automating NERC CIP Compliance New York
- Protection for Small Companies New York
- The Perimeter Defense Fallacy New York
- Fellowes Pulsar-E Review New York
- Mobility Electric Scooters New York

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History