BS Information Systems – University of Redlands BS Information Systems – University of Redlands AS Electronic Technology AS Electronic Technology Project.

Slides:



Advertisements
Similar presentations
Federal Energy Regulatory Commission July Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
Advertisements

WECC/TEPPC Response to DOE Funding Opportunity Status Update June 29, 2009 Bradley Nickell Renewable Integration and Planning Director.
2007 Goals. Introduction Western Electricity Coordinating Council (WECC) will be primarily defined throughout the 2007 year by Electric Reliability.
NERC Orientation Joint Guidance Committee WECC Leadership
CIP Cyber Security – Security Management Controls
PER
PER Update & Compliance Lessons Learned
Confidential & Proprietary to Cooper Compliance Corporation Revised September 8, 2014 AUDiT-READY TM.
Allan Wick, CFE, CPP, PSP, PCI, CBCP Chief Security Officer WECC Joint Meeting October 8, 2014.
Gcpud1 CRITICAL INFRASTRUCTURE PROTECTION NERC 1200 CIP CRITICAL INFRASTRUCTURE PROTECTION NERC 1200 CIP
Compliance Application Notice Process Update and Discussion with NERC MRC.
Cyber Security 2005 ERCOT COMPLIANCE ROLLOUT Lane Robinson Reliability Analyst.
Cyber Security Plan Implementation Presentation to CMBG Glen Frix, Duke Energy June 20,
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
1 Value now. Value over time. © Copyright 2009, OSIsoft Inc. All rights Reserved. Using OSIsoft to Become Compliant James Cosgrove, Northeast Utilities.
Dr. Julian Lo Consulting Director ITIL v3 Expert
1 Eric T. Whitley Selected Relevant Experience Background Eric T. Whitley President & CEO 1831 Iron Point Road, Suite 140 Folsom, CA Tel: (916)
Environmental Management Systems An Overview With Practical Applications.
COSO Framework A company should include IT in all five COSO components: –Control Environment –Risk Assessment –Control activities –Information and communication.
Jeffery J. Gust IOWA INDUSTRIAL ENERGY GROUP FALL CONFERENCE Tuesday, October 14, 2014 MidAmerican Energy Company.
Electric Power Infrastructure: Status and Challenges for the Future Mark Lauby Director, Reliability Assessments and Performance Analysis.
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
Information Security Compliance System Owner Training Richard Gadsden Information Security Office Office of the CIO – Information Services Sharon Knowles.
GOP and QSE Relationship Jeff Whitmer Manager, Compliance Assessments Talk with Texas RE June 25, 2012.
Lisa Wood, CISA, CBRM, CBRA Compliance Auditor, Cyber Security
City of Leesburg Electric Department Internal Compliance Program (ICP)
Federal Energy Regulatory Commission June Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
1 Arizona Corporation Commission BTA Workshop Presenter: Steven Cobb May 23, 2008.
Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation - ERO Perspective David R. Nevius and Michael J. Assante 2009 NRC Regulatory.
Organize to improve Data Quality Data Quality?. © 2012 GS1 To fully exploit and utilize the data available, a strategic approach to data governance at.
APPA RELIABILITY STANDARDS & COMPLIANCE SYMPOSIUM Case Study: City Utilities of Springfield, MO January 11, 2007.
How To Prepare For A CIP Audit Scott Barker CISSP, CISA CIP Compliance Workshop Baltimore, MD August 19-20, 2009.
Integration of Variable Generation Task Force Preliminary Conclusions and Actions.
1 DOE IMPLEMENTATION WORKSHOP ASSESSING MY EMS Steven R. Woodbury
Implementing the New Reliability Standards Status of Draft Cyber Security Standards CIP through CIP Larry Bugh ECAR Standard Drafting Team.
Texas Regional Entity Update Sam Jones Interim CEO and President Board of Directors July 18, 2006.
Actions Affecting ERCOT Resulting From The Northeast Blackout ERCOT Board Of Directors Meeting April 20, 2004 Sam Jones, COO.
1 Texas Regional Entity 2008 Budget Update May 16, 2007.
Overview of WECC and Regulatory Structure
Anne Arundel County COOP Kick-Off Office of Emergency Management Jim Weed, Director
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
RIGHT OF WAY BEST PRACTICES FOR LOCAL PUBLIC AGENCIES.
Status Report for Critical Infrastructure Protection Advisory Group
Mandatory Electric Reliability Standards and Transmission Expansion Suedeen G. Kelly Commissioner Federal Energy Regulatory Commission The Canadian Institute.
Item 5d Texas RE 2011 Budget Assumptions April 19, Texas RE Preliminary Budget Assumptions Board of Directors and Advisory Committee April 19,
Reliability Assurance Initiative (RAI) 101 Ben Christensen Senior Compliance Risk Analyst, Cyber Security.
Bill Lewis, Compliance Team Lead NERC Reliability Working Group May 16, 2013 Texas RE Update Talk with Texas RE April 25, 2013.
The Electric Reliability Organization: Getting from here to there. Gerry Cauley Director, Standards ERO Project Manager ERO Slippery Slope NERC Today Uphill.
Information Security 14 October 2005 IT Security Unit Ministry of IT & Telecommunications.
COMPLIANCE ROLLOUT Vann Weldon Compliance Training Administrator March 23, 2005 NERC FUNCTIONAL MODEL REVIEW.
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
November 2, 2006 LESSONS FROM CIPAG 1 Lessons from Critical Infrastructure Group Bill Bojorquez November 2, 2006.
Assessment Report No. 9 Workshop Mandatory Reliability Standards (MRS) Teleconference Bridge Details: (Vancouver) Toll Free.
1 Power System Restoration. 2 Not Active 3 4 Compliance Audit Process APPA E&O Technical Conference – Atlanta April 16, 2007.
ERCOT IT Update Ken Shoquist VP, CIO Information Technology Board Meeting February 2004.
Learn Integrated Management System Documentation Process with Ready-to-use EQHSMS Documentation Kit
The Electric Reliability Organization NERC’s Proposal for a Strong and Effective ERO FRCC System Operator Seminar Spring 2006.
FERC’s Division of Reliability Federal Energy Regulatory Commission – Open Meeting Washington, DC October 6, 2004 Joseph H. McClelland Director, Division.
MOPC Meeting Oct , 2016 Little Rock, AR
ERCOT Technical Advisory Committee June 2, 2005
NERC Cyber Security Standards Pre-Ballot Review
Understanding Existing Standards:
Background (history, process to date) Status of CANs
Cybersecurity Special Public Meeting/Commission Workshop for Natural Gas Utilities September 27, 2018.
NERC Cyber Security Standard
The Electric Reliability Organization: Getting from here to there.
Mandatory Reliability Standards
Larry Bugh ECAR Standard Drafting Team Chair June 1, 2005
Reliability Assurance Initiative (RAI) 101
Overview of WECC and Regulatory Structure
Presentation transcript:

BS Information Systems – University of Redlands BS Information Systems – University of Redlands AS Electronic Technology AS Electronic Technology Project Management Certification Program- UCSD Project Management Certification Program- UCSD Michael Espinoza 22 Years SDG&E, 22 Years SDG&E, Sr EMS Hardware Analyst Sr EMS Hardware Analyst EMS Hardware Supervisor EMS Hardware Supervisor Infra Project Technical Lead Infra Project Technical Lead

Agenda Purpose Purpose NERC CIP Standards NERC CIP Standards Standards Standards Goals/Challenges Goals/Challenges Establishing Project Direction Establishing Project Direction Project Roadmap Project Roadmap Communication is Essential Communication is Essential Feedback Feedback Disclaimer – This presentation represents my own personal interpretation. Disclaimer – This presentation represents my own personal interpretation.

Purpose of CIP Cyber Security Standards Ensure that all entities responsible for the reliability of the Bulk Electric Systems in North America identify and protect Critical Cyber Assets that control or could impact the reliability of the Bulk Electric Systems. Ensure that all entities responsible for the reliability of the Bulk Electric Systems in North America identify and protect Critical Cyber Assets that control or could impact the reliability of the Bulk Electric Systems.

NERC is made up of eight regions that oversee the reliability and operation of the Bulk Electric System. >All Electric Generation and Transmission agencies report to one of these regions.  SDG&E reports to the WECC, Western Area reporting agency, > All regions must comply with NERC CIP Standards. North American Electric Systems Overview

CIP-002 Critical Cyber Asset Identification CIP-003 Security Management Controls CIP-004 Personnel & Training CIP-005 Electronic Security Perimeters CIP-006 Physical Security Of Critical Cyber Assets CIP-007 Systems Security Management CIP-008 Incident Reporting And Response Planning CIP-009 Recovery Plans For Critical Cyber Assets NERC CYBER SECURITY 8 Standards NERC CIP

41 Requirements

 Compliant (C) - means the entity meets the full intent of the requirements and is beginning to maintain required “data,” “documents,” “documentation,” “logs,” and “records”  Auditably Compliant (AC) - means the entity meets the full intent of the requirement and can demonstrate compliance to an auditor, including 12-calendar-months of auditable “data,” “documents,” “documentation,” “logs,” and “records” 2009 Audit Preparation - Compliance Levels 2010

Penalty Matrix* Violation Severity Level Violation Risk Factor LowerModerateHighSevere Range Limits LowHighLowHighLowHighLowHigh Lower $1,000 $3,000 $2,000 $7,500 $3,000 $15,000 $5,000 $25,000 Medium $2,000 $30,000 $4,000 $100,000$6,000 $200,000$10,000$335,000 High $4,000$125,000$8,000$300,000$12,000$625,000$20,000$1,000,000 FERC statutory limit: $1,000,000,000 per day, per violation Other limits may apply in Canada *Matrix undergoing revision

Comply with new NERC CIP Cyber Security Standards in advance of the required deadlines Comply with new NERC CIP Cyber Security Standards in advance of the required deadlines GOAL Obstacles Not Withstanding: Obstacles Not Withstanding: - Significant effort is required - Significant effort is required - Additional funding and / or personnel - Additional funding and / or personnel may be needed may be needed

CIP Standards Applicability to the following Functions Generation Owner Generation Owner Generator Operator Generator Operator Transmission Owner Transmission Owner Transmission Operator Transmission Operator Load Serving Entity Load Serving Entity

STANDARD CIP-001 CIP-002 CIP-003 CIP-004 CIP-005 CIP-006 CIP-007 CIP-008 CIP-009 Corporate Security Information Technology Grid OperationsHuman Resources Regulatory                   

WECC NERC & FERC Corp Security IT Regulatory Electric Ops HR Facilities Project Links “The Challenge” Organizational Links Internal Auditing *The key for success -> Ensure all Organizations have the same goal.

1.Enterprise Environmental factors 2.Organizational Process Assets 3.Roles and Responsibilities 4.Project organization Charts 5.Staffing Mgmnt plan 1.Pre-assignment 2.Negotiation 3.Acquisition 4.Virtual Teams Tools & TechniquesInputsOutputs 1.Project staff assignments 2.Resource availability 3.Staffing Management plan (updates) Acquire Project Teams (PMBOK  Guide)

1. Build Processes 3. Audit Sign Off NERC CIP PROJECT PYRAMID 2. Mgmt Approvals

Populate master CCA access list from existing worksheets CONCEPT PROCESS EXAMPLE Grid Operations, Human Resources, Corporate Security, IT

Establishing Project Direction Develop a master project plan Develop a master project plan Assign qualified members to each internal NERC team Assign qualified members to each internal NERC team Use standardized templates for documentation Use standardized templates for documentation Run an ongoing gap analysis to identify redundant and missed processes Run an ongoing gap analysis to identify redundant and missed processes

Communications Updates/Feedback Executive Updates - Monthly Executive Updates - Monthly –CEO/VP –Directors –Managers Team Feedback Team Feedback –Monitor Teams for resource requirements –Establish monthly goals for Levels of Compliance –Review Team suggestions Utilize Tools/Resources Utilize Tools/Resources –Consultants, wicf · Western Interconnection Compliance Forum, Common Data site (SharePoint), Ticklers

Purpose Purpose NERC CIP Standards NERC CIP Standards Standards Standards Goals/Challenges Goals/Challenges Establishing Project Direction Establishing Project Direction Project Roadmap Project Roadmap Communication is Essential Communication is Essential Feedback Feedback Review

Feedback