CIPC Executive Committee Update CIPC Meeting Washington DC June 9, 2005 Stuart Brindley CIPC Chair Public Release.

Slides:



Advertisements
Similar presentations
NERC Critical Infrastructure Protection Advisory Group (CIP AG) Electric Industry Initiatives Reducing Vulnerability To Terrorism.
Advertisements

Security Education and Awareness Workshop January 15-16, 2004 Baltimore, MD.
NERC CIPC March 16, 2006 Roadmap to Secure Control Systems in the Energy Sector U.S. Department of Energy Office of Electricity Delivery and Energy Reliability.
Recent NERC Standards Activities RSC – Jan. 5, 2011 NSRS Update Date Meeting Title (optional)
National Infrastructure Protection Plan
Cyber Security and the Smart Grid George W. Arnold, Eng.Sc.D. National Institute of Standards and Technology (NIST) U.S. Department of Commerce
WebCast 5 May 2003 NERC Cyber Security Standard Overview of Proposed Cyber Security Standard.
DHS, National Cyber Security Division Overview
NERC and Regional Efforts to Ensure Reliability Dave Nevius, NERC Sr. VP David Cook, NERC VP & General Counsel Louise McCarren, WECC CEO Don Benjamin,
Accessibility, Integrity, & Confidentiality: Security Challenges for E-Business Rodney J. Petersen University of Maryland & Educause/Internet2 Security.
Cyber Security Standard Workshop Status of Draft Cyber Security Standards Larry Bugh ECAR Standard Drafting Team Chair January 2005.
Averting Disaster - Grid Reliability Issues and Standards National Energy Restructuring Conference April 1, 2004 Washington, DC.
ELECTRICAL CRITICAL INFRASTRUCTURE SECURITY Charles Hookham, P.E., M.ASCE, VP, Utility Projects HDR Engineering 1.
K E M A, I N C. NERC Cyber Security Standards and August 14 th Blackout Implications OSI PI User Group April 20, 2004 Joe Weiss
CIPC Executive Comittee Update CIPC Conference Call September 16, 2004 Stuart Brindley CIPC Chair CIPC Confidentiality - Public.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
Federal Energy Regulatory Commission June Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
National Preparedness All Hazards Consortium Corey Gruber Assistant Deputy Administrator, National Preparedness National Preparedness.
Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation - ERO Perspective David R. Nevius and Michael J. Assante 2009 NRC Regulatory.
Security Guidelines Working Group Update CIPC Meeting Phoenix, AZ Mar 16, 2006 Seiki Harada SGWG Chair CIPC Confidentiality: Public Release.
Implementing the New Reliability Standards Status of Draft Cyber Security Standards CIP through CIP Larry Bugh ECAR Standard Drafting Team.
CIPC Executive Committee Update CIPC Meeting Denver CO September 29, 2005 Stuart Brindley CIPC Chair Public Release.
1 Crisis Response Task Force (CRTF) Proposal Tom Bowe (Chairman) CSO, PJM Interconnection Scott Heffentrager (Temp. Chairman) Physical Security.
FERC’s New Reliability Initiatives Kevin Kelly Director, Policy Analysis, OMTR Federal Energy Regulatory Commission NARUC Annual Meeting Nashville, TN.
CIP Program Highlights Member Representatives Committee October 28, 2008 Michael Assante, CSO
Control Systems Security Working Group Report CIPC Meeting Denver, CO September 2005 Tom Flowers Public Release.
Actions Affecting ERCOT Resulting From The Northeast Blackout ERCOT Board Of Directors Meeting April 20, 2004 Sam Jones, COO.
Overview of WECC and Regulatory Structure
Role for Electric Sector in Critical Infrastructure Protection R&D Presented to NERC CIPC Washington D.C. June 9, 2005 Bill Muston Public Release.
Item 5d Texas RE 2011 Budget Assumptions April 19, Texas RE Preliminary Budget Assumptions Board of Directors and Advisory Committee April 19,
WebCast 5 May 2003 Proposed NERC Cyber Security Standard Presentation to IT Standing Committee Stuart Brindley, IMO May 26, 2003.
CIPC Executive Committee Update CIPC Meeting Mesa AZ March 16, 2006 Barry Lawson CIPC Vice-Chair CIPC Confidentiality: Public Release.
The Electric Reliability Organization: Getting from here to there. Gerry Cauley Director, Standards ERO Project Manager ERO Slippery Slope NERC Today Uphill.
Standing Up The New Electric Reliability Organization Ellen P. Vancko North American Electric Reliability Council.
NERC and ESISAC Electricity Sector Information Sharing and Analysis Center Update March 2006 CIPC Confidentiality: Public Release.
Standards and Guidelines Working Group Status Updates 2005 Jun 09 Washington DC Critical Infrastructure Protection Committee Public Release.
CIPC Executive Committee Update-1 CIPC Meeting Long Beach CA March 17, 2005 Pat Laird Vice Chair Public Release.
1 Thoughts on ERCOT-Wide Critical Infrastructure Protection Committee Bill Muston October 31, 2006.
Financial Services Sector Coordinating Council (FSSCC) 2011 KEY FSSCC INITIATIVES 2011 Key FSSCC Initiatives Project Name: Project Description: All-Hazards.
Critical Infrastructure Protection Committee Report to NERC Standing Committees in Joint Session Long Beach, CA March 2005 Public Release.
Path Operator Implementation Task Force Vic Howell, Vice Chair Report to OC March 22, 2016.
Path Operator Implementation Task Force
NERC Cyber Security Standards Pre-Ballot Review
CIPC Outreach WG Update March 2006
CIPC Executive Committee Update
Understanding Existing Standards:
Larry Bugh ECAR Standard Drafting Team Chair January 2005
CIPC Relationships & Roles
Critical Infrastructure Protection Committee Report to NERC Standing Committees in Joint Session Long Beach, CA March 2005 Public Release.
Larry Bugh ECAR Standard Drafting Team Chair January 2005
Role for Electric Sector in Critical Infrastructure Protection R&D
NERC Critical Infrastructure Protection Advisory Group (CIP AG)
CIPC Executive Committee Update-1
Summary of the 2018 Winter Meetings
CIPC Executive Committee Update
CSSWG Status Report March 17-18, 2005 CIPC Meeting Long Beach, CA
NERC Cyber Security Standard
NERC Critical Infrastructure Protection Committee (CIPC) Executive Committee Public Release 29 September 2005.
Control Systems Security Working Group Report
Critical Infrastructure Protection Committee
NERC Reliability Standards Development Plan
Larry Bugh ECAR Standard Drafting Team Chair June 1, 2005
Strategic Planning Process
CIPC Executive Committee Update
UPDATE: Physical Security Guideline
Strategic Planning Process
Crisis Response Task Force (CRTF) Proposal
Security Guidelines Working Group Update
CIPC Executive Committee Report-2
NERC Reliability Standards Development Plan
Presentation transcript:

CIPC Executive Committee Update CIPC Meeting Washington DC June 9, 2005 Stuart Brindley CIPC Chair Public Release

CIPC Executive Committee ChairStuart Brindley (IESO, CEA) Vice-ChairLarry Bugh (ECAR) Vice-ChairPat Laird (Exelon) CyberJamey Sample (Cal-ISO) PhysicalBob Canada (Southern Co.) OperationsRoger Lampila (NY-ISO) PolicyBarry Lawson (NRECA) SecretaryLou Leffler (NERC) ● Executive Committee 2-year terms end December 2005 ● Need to “refresh” commitments of all CIPC members - letter to NERC Regional Managers later this year  opportunity for greater Owner/Operator involvement

CIPC Nominating TF Bob CanadaSERC Larry Dolci SPP Tom GlockWECC Mike HylandAPPA Roger LampilaNPCC

CIPC Executive Committee Activities ● NERC Board  Highlights - May 2 Stakeholder meeting and May 3 Board of Trustees meeting ● US/Canada Outage TF Recommendations ● Established the Electricity Sector Coordinating Council (ESCC) and the Government Coordinating Council (GCC)  ESCC = NERC President & CEO plus CIPC Executive Committee  GCC = DoE lead, plus DHS, FERC ● Public messaging

Critical Infrastructure Protection Committee Update Stakeholders Committee May 2, 2005

Key CIPC Initiatives ● Complete actions to address the US-Canada Outage TF Recommendations by end-2005 ● Continue to support the development of the Permanent cyber security standard  Plan to support implementation ● New and revised Security Guidelines and White Papers ● Contribute to DHS’ National Infrastructure Protection Plan ● Reach-out within our industry, and to other sectors

● DHS Plan for Sector Engagement  NERC is the Electricity Sector Coordinating Council  CIPC’s Executive Committee  President/CEO NERC  Government Energy Coordinating Council  DOE, DHS, FERC, possibly others  April 20, 2005 inaugural meeting  “One-stop shop” to address strategic issues Key CIPC Initiatives (cont’d)

DHS Plan for Sector Engagement Electricity

Electricity and Telecommunications Interdependencies ● Engaged with Telecom and Electric Power Interdependency Task Force  Task force reports to the President’s National Security Telecom Advisory Committee ● Topics include  Situational awareness  Incident management  Restoration priorities - electricity and telecom  Well-established local relationships  Inter-sector exercises ● Paper by late Summer 2005

New Security Guidelines Critical Infrastructure Protection Committee Board of Trustees May 3, 2005

Control Systems Security ● New guidelines for BoT approval  Patch Management for Control Systems  Control Systems to Business Network Electronic Connectivity ● Why are they necessary?  US - Canada Outage TF Recommendations related to cyber security  White paper prepared by CIPC’s Control Systems Security Working Group - “Common Vulnerabilities of Control Systems ”  Increased industry and government awareness to control systems security; DOE Lab demos  Support the U rgent A ction and P ermanent cyber security standards

Development Process ● Development began Q by CIPC’s Control Systems Security Working Group ● March 2005, agreed to fast-track ● During April  final draft to CIPC members  conducted Webex conference call to review  conducted vote

Patch Management for Control Systems How to keep control systems software current and secure ● Complexities associated with maintaining high availability required of control systems ● Key steps  Maintain asset inventory  Notification of new vulnerabilities  Assess risks of new vulnerabilities  Test and implement

Control Systems to Business Network Electronic Connectivity How to secure control systems from the vulnerabilities introduced when connected to business systems Key steps  Identify inventory and information flows  User authentication  Defence in depth  Control and monitor access

Results of Vote ● Quorum established, both passed  Patch Management for Control Systems (85.1%)  Control Systems to Business Network Electronic Connectivity (74.0%) ● Reasons for “no” votes:  Generally, “more time to get it right”  Some concerns with “the speeded-up process”, rather than “content”  Language needs even further emphasis of non- mandatory nature  Definitions presume those in latest draft of Permanent Cyber Security Standard

US/Canada Outage TF Recommendations ● Final Task Force report expected June-05 (Canadian government assigned task of coordinating response to Security-related recommendations) ● Since Jan-05, several conference calls:  CIPC EC and government (DOE, DHS, NRCan, PSEPC)  CEA and Canadian government ● mid-Jan-05, provided CIPC members with a table of security recommendations and actions ● Table has since been updated to reflect recent CIPC Work Plan accomplishments ● CIPC commitments compete, or on-target

ESCC and GCC

● “Inaugural” meeting April 20  ESCC: Gent, Brindley, Leffler, Canada, Lampila, Lawson (Johnson, Hyland, Brown invited as observers)  GCC: De Alvarez, Friedman, Kenchington, Caverley, Carrier plus ~10 others Topics: ● Interim NIPP: Energy Sector-Specific plan provided to ESCC  Targeting to provide comments by Jul-05  Don’t forget value of response/recovery ● Protecting information (CEII, PCII) ● National Asset Database  ESCC position: Continue to question the need for government to have a list of infrastructure assets.

ESCC and GCC (cont’d) ● FACA requirements (Federal Advisory Committee Act)  Formal recognition that ESCC provides advice to government  But FACA requires open and public disclosure  Brindley, Laird participating in Sector Partnership Model Working Group, reporting to NIAC…lawyers deliberating… ● HSIN Status  Need to map information flows - who gets what ● Technology Roadmap

Public Messaging Our industry is doing a lot to manage threats to our critical infrastructure. Are we getting that message out to help manage public perceptions?

Key Messages - Readiness ● We take an all-hazards, all-threats approach to security and emergency preparedness  Natural threats  Man-made threats (cyber & physical attacks) ● Not just recovery, but mitigation and prevention  Tested through drills and exercises ● Keep government informed - recovery ● Key Messages - Experience  During the [Blackout]…draw on local experiences

Key Messages - US/Canada Blackout TF Recommendations ● Identify those systems critical to supporting the reliability of the grid ● Secure the perimeter to those systems ● Manage and monitor access to those systems ● Screen and train staff ● Conducting vulnerability assessments to ensure appropriate measures are in-place ● … and we were already meeting many of these ●... and we’re working to improve and exceed

Key Messages - Our Biggest Challenge? ● Maintaining and raising awareness  Address today’s threats  Keeping aware of emerging threats  Fill in the blanks: oWhat are your vulnerabilities? oWhat are you doing about them?

Key Messages - the Stump Question The Question: ● “So what about all those people saying how vulnerable the grid is?” The Answer: ● From my own experience…  We have taken action  The industry is taking action ● … but “never say never”

Public Messaging: Go-Forward ● Public statements need to be situation- dependent ● CIPC Exec Ctee and NERC staff as resources  Brindley/Laird/Bugh/Leffler  Ellen Vancko, NERC Director - Communications & Government Affairs