NERC Critical Infrastructure Protection Advisory Group (CIP AG) Electric Industry Initiatives Reducing Vulnerability To Terrorism.

Slides:



Advertisements
Similar presentations
NERC Cyber Security Standards Pre-Ballot Review. Background Presidents Commission on Critical Infrastructure Protection PDD-63 SMD NOPR NERC Urgent Action.
Advertisements

HIPAA Security Presentation to The American Hospital Association Dianne Faup Office of HIPAA Standards November 5, 2003.
EMS Checklist (ISO model)
Homeland Security at the FCC July 10, FCCs Homeland Security Focus Interagency Partnerships Industry Partnerships Infrastructure Protection Communications.
Confidential & Proprietary to Cooper Compliance Corporation Revised September 8, 2014 AUDiT-READY TM.
Recent NERC Standards Activities RSC – Jan. 5, 2011 NSRS Update Date Meeting Title (optional)
1 Pipeline Security Presented to: Pipeline Safety Trust New Orleans, Louisiana November 5, 2010.
HIPAA: FEDERAL REGULATIONS REGARDING PATIENT SECURITY.
WebCast 5 May 2003 NERC Cyber Security Standard Overview of Proposed Cyber Security Standard.
Cyber Security 2005 ERCOT COMPLIANCE ROLLOUT Lane Robinson Reliability Analyst.
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
Jeffery J. Gust IOWA INDUSTRIAL ENERGY GROUP FALL CONFERENCE Tuesday, October 14, 2014 MidAmerican Energy Company.
Complying With The Federal Information Security Act (FISMA)
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
Update: Physical Guideline UPDATE: Physical Security Guideline UPDATED Physical Response Security Guideline Public Release.
Lisa Wood, CISA, CBRM, CBRA Compliance Auditor, Cyber Security
National Incident Management System 5-Year Training Plan Al Fluman, Acting Director Incident Management Systems Division (IMSD), National Integration Center.
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation - ERO Perspective David R. Nevius and Michael J. Assante 2009 NRC Regulatory.
ACADs (08-006) Covered Keywords Commission, regulation, advisory, standards. Description This presentation provides general information about each of the.
Integration of Variable Generation Task Force Preliminary Conclusions and Actions.
Implementing the New Reliability Standards Status of Draft Cyber Security Standards CIP through CIP Larry Bugh ECAR Standard Drafting Team.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
Overview of WECC and Regulatory Structure
Securing Critical Chemical Assets: The Responsible Care ® Security Code Protection of Hazardous Installations from Intentional Adversary Acts European.
Status Report for Critical Infrastructure Protection Advisory Group
Role for Electric Sector in Critical Infrastructure Protection R&D Presented to NERC CIPC Washington D.C. June 9, 2005 Bill Muston Public Release.
Item 5d Texas RE 2011 Budget Assumptions April 19, Texas RE Preliminary Budget Assumptions Board of Directors and Advisory Committee April 19,
Disaster Recover Planning & Federal Information Systems Management Act Requirements December 2007 Central Maryland ISACA Chapter.
WebCast 5 May 2003 Proposed NERC Cyber Security Standard Presentation to IT Standing Committee Stuart Brindley, IMO May 26, 2003.
1 RIC 2009 Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation George Wilson NRR/ADES/DE/EEEB March 11, 2009.
The Electric Reliability Organization: Getting from here to there. Gerry Cauley Director, Standards ERO Project Manager ERO Slippery Slope NERC Today Uphill.
Piemonte Workshop 1 11 September 2006 Paolo Salieri European Commission DG ENTR-H4 Security research in FP7.
Problem Areas Updates Penalties FRCC Compliance Workshop September / October
America’s Natural Gas Utilities’ Distribution Pipelines November 2, 2006 The Connection To the Customer.
Unclassified  1 Critical Infrastructure Protection Chuck Whitley EMS User’s Group June 9, 1999.
Employee Privacy at Risk? APPA Business & Financial Conference Austin, TX September 25, 2007 Scott Mix, CISSP Manager of Situation Awareness and Infrastructure.
NFPA 1600 Disaster/Emergency Management and Business Continuity Programs.
NERC and ESISAC Electricity Sector Information Sharing and Analysis Center Update March 2006 CIPC Confidentiality: Public Release.
November 2, 2006 LESSONS FROM CIPAG 1 Lessons from Critical Infrastructure Group Bill Bojorquez November 2, 2006.
Introduction and Overview of Information Security and Policy By: Hashem Alaidaros 4/10/2015 Lecture 1 IS 332.
Craig Williams Market Interface Manager August 21, 2014 ISAS, Portland, OR.
ERCOT IT Update Ken Shoquist VP, CIO Information Technology Board Meeting February 2004.
Overview July 2011 INMM Nuclear Security and Physical Protection Technical Division.
Critical Infrastructure Protection Committee Report to NERC Standing Committees in Joint Session Long Beach, CA March 2005 Public Release.
SEC 480 assist Expect Success/sec480assistdotcom FOR MORE CLASSES VISIT
1 Presented by David Thompson, TIA December 14, 2005 NFPA 1600 and Emergency Communications.
Reliability Standard TPL Transmission System Planned Performance for Geomagnetic Disturbance Events September 28, 2016 TPL Standard Status.
NRC’s 10 CFR Part 37 Program Review of Radioactive Source Security
Community Health Centers of Arkansas Hazard Vulnerability Assessment Workshop August 11, 2017 Mark Fuller.
Planning Geomagnetic Disturbance Task Force (PGDTF) Update to the ROS
ERCOT Technical Advisory Committee June 2, 2005
ESSENTIALS OF A PHYSICAL SECURITY SYSTEMS RISK ASSESSMENT
NERC Cyber Security Standards Pre-Ballot Review
Understanding Existing Standards:
CIPC Relationships & Roles
Role for Electric Sector in Critical Infrastructure Protection R&D
NERC Critical Infrastructure Protection Advisory Group (CIP AG)
Proposed RISC 2014 Deliverables, Activities, and Calendar
NERC Cyber Security Standard
The Electric Reliability Organization: Getting from here to there.
Group Meeting Ming Hong Tsai Date :
NERC Reliability Standards Development Plan
Larry Bugh ECAR Standard Drafting Team Chair June 1, 2005
UPDATE: Physical Security Guideline
Securing Critical Chemical Assets: The Responsible Care® Security Code
What Is VQIP? FDA required to establish a program to provide for the expedited review of food imported by voluntary participants. Eligibility is limited.
CIPC Executive Committee Report-2
NERC Reliability Standards Development Plan
Presentation transcript:

NERC Critical Infrastructure Protection Advisory Group (CIP AG) Electric Industry Initiatives Reducing Vulnerability To Terrorism

September 11, 2001 Industry Implications Significant change to the Security Environment Increased Security focus and costs Threat of imposed Federal and State legislation Company over-reaction Company under-reaction

Post 9/11 Reactions

CIP AG Overview

Security Guidelines Guiding Principles Each company defines and identifies its own critical facilities and functions. Each company assesses the usefulness of the Guidelines individually and adapts them as needed. The Guidelines are living documents, expected to change. Implemented and supported by workshops for industry

Initiatives l CIPAG w Security Guidelines w Threat Conditions and Response w FERC Assist w Spare Parts Database w PKI

Security Guidelines Executive Summary l The Guidelines describe ã general approaches ã considerations ã practices ã planning philosophies l The Guidelines are NOT a cookbook for protection.

Security Guidelines Definitions l Critical Facility Any facility or combination of facilities, if severely damaged or destroyed would: â have a significant impact on the ability to serve large quantities of customers for an extended period of time, â have a detrimental impact to the reliability or operability of the energy grid, or ã cause significant risk to National security, National economic security, or public health and safety.

Security Guidelines Guideline Topics Vulnerability and Risk Assessment Threat Response Emergency Management Continuity of Business Processes Communications Physical Security IT/Cyber Security Employment Screening Protecting Sensitive Information

Security Guidelines Guideline Topics l Vulnerability and Risk Assessment Helps identify critical facilities, their vulnerabilities, and countermeasures. l Threat Response Helps in developing plans for enhanced security.

Security Guidelines Guideline Topics Emergency Management Better prepares companies to respond to a spectrum of threats, both physical and cyber. Continuity of Business Practices Reduces the likelihood of prolonged interruptions and enhances prompt resumption of operations after interruptions occur.

Security Guidelines Guideline Topics Communications Enhances the effectiveness of threat response, emergency management, and business continuity plans. Physical /Cyber Security Mitigates the impact of threats through deterrence, prevention, detection, limitation, and corrective action.

Security Guidelines Guideline Topics Employment Screening Provides strategies to mitigate insider threats. Protecting Sensitive Information Production, storage, transmission, and disposal of both physical and electronic information

Security Guidelines Reference Documents An Approach to Action for the Electricity Sector ( NERC, June 2001) Threat Alert Levels and Physical Response Guidelines (NERC, November 2001) Threat Alert Levels and Cyber Response Guidelines (NERC, March 2002)

ThreatCon and Response Guidelines The Guidelines l Define Threat Alert Levels for Alerts issued by â ES-ISAC â NIPC â Other government agencies (Excludes facilities regulated by the NRC) l Ensure that electric Threat Alert Levels are consistent with information from other sources l Provide examples of security measures l Supported with workshops

ThreatCon and Response Guidelines Threat Alerts / Threat Conditions l Can be issued â for a specific geographic area â for a specific facility â by category - such as a specific type of facility

Threat Alert Level Definitions THREATCON - NORMAL l Applies when no known threat exists. l Is equivalent to normal daily conditions. l Security measures should be maintainable indefinitely. THREATCON - LOW l Applies when a general threat exists with no specific threat directed against the electric industry. l Additional security measures are recommended. l Added security should be maintainable for an indefinite period with minimum impact on the organization.

Threat Alert Level Definitions THREATCON-MEDIUM l Applies with increased or more predictable threat to the electric industry. l Implementation of additional security measures is expected. l Increased measures are anticipated to last for a defined time. l Significant increases in corporate resources will be required. THREATCON-HIGH l Applies when an incident occurs or a credible threat is imminent. l Maximum security measures are necessary and are expected to: ã cause hardships on personnel, ã seriously impact normal operations, and ã may be economically unsustainable for more than a short time.

FERC Request l FERC requested NERC to develop security standards for inclusion to Standard Market Design NOPR l CIPAG picked-up the Gauntlet l NERC BoT approved CIPAG participation on June 14, 2002

FERC Request l Minimum Daily Requirements w Achievable w Granular w Cyber focused w Inter-connection focused

FERC Request l Final draft to FERC July 26 l SMD NOPR released July 31 for general public review, comment l Final SMD ruling late October or early November l Effective date of compliance 2004 l Annual signed self certification

FERC Request l All future standards to be developed and maintained by NERC l All future FERC rule making on standards will refer to NERC standards

Spare Equipment Database l Expanding database created in 1989 l Spare EHV transformers in case of national emergencies l Web based on a secure server l Other equipment to be included

PKI l Needed because of the reliance on computer based systems and applications l Evaluate potential Certificate Authorities l Develop an integrated PKI architecture and deployment strategy l Resolve technical issues l Create web based training materials

ES ISAC l PDD #63 Identified electricity as on e of the eight critical infrastructures l NERC sector coordinator for electricity l IAW Program l Website l CIPAG oversight body for ISAC l Collect, Analyze and Disseminate information

Pulling Together

Available on the Web Committees CIPAG Related Files

One Last Thought! Security is always excessive until its not enough