Report of ERCOT Critical Infrastructure Protection Working Group to ROS January 10, 2013 By: David Grubbs, CIPWG Chair
History of the CIPWG Although there was an earlier group, that had stopped meeting, the current CIPWG was reformed in 2006 with Lewis Griffin of Centerpoint as Chair. Although there was an earlier group, that had stopped meeting, the current CIPWG was reformed in 2006 with Lewis Griffin of Centerpoint as Chair. Early meetings averaged 10 to 15 persons. Early meetings averaged 10 to 15 persons. In 2009, Steve Martin of Oncor became Chair. In 2009, Steve Martin of Oncor became Chair.
Original Purpose of CIPWG The CIPWG was initially formed to assist attendees in implementation of the NERC CIP Standards. The CIPWG was initially formed to assist attendees in implementation of the NERC CIP Standards. Persons debated the intent of NERC standards and brought copies of their CIP policies for review and comments by the group. Persons debated the intent of NERC standards and brought copies of their CIP policies for review and comments by the group.
Format of the Meetings The meetings are broken up into two segments; an Open Session and a Closed Session. The meetings are broken up into two segments; an Open Session and a Closed Session. The Open session is an opportunity to discuss issues with TRE representatives. Also time is allocated for discussion of the NERC CIPC or other open meetings or requests for volunteers The Open session is an opportunity to discuss issues with TRE representatives. Also time is allocated for discussion of the NERC CIPC or other open meetings or requests for volunteers
Closed Portion The closed portion of the meeting is utilized for discussions of: The closed portion of the meeting is utilized for discussions of: –Security events that have occurred –Audit / compliance events –Interpretation of standards and how entities comply –Potential Security Concerns, including NERC Alerts and the background leading to the issuing of the Alerts
Agenda / Minutes Due to the sensitive nature of the discussions, either compliance or security related, no minutes are kept of any meetings. Due to the sensitive nature of the discussions, either compliance or security related, no minutes are kept of any meetings. The agenda is sent out to all persons on the CIPWG mailing list prior to the meeting. The agenda is sent out to all persons on the CIPWG mailing list prior to the meeting.
Non-Disclosure Agreements All persons attending the Closed portion of the meeting must sign a non-disclosure agreement All persons attending the Closed portion of the meeting must sign a non-disclosure agreement NDAs must be renewed each April 1. NDAs must be renewed each April 1. Persons must be a market participant or government employee Persons must be a market participant or government employee All NDAs are processed and approved by ERCOT Legal All NDAs are processed and approved by ERCOT Legal
Changing Role of CIPWG CIPWG originally formed to assist in initial compliance with NERC CIP Standards CIPWG originally formed to assist in initial compliance with NERC CIP Standards As the CIP Standards have been fully implemented, Registered Entities have needed less assistance for compliance As the CIP Standards have been fully implemented, Registered Entities have needed less assistance for compliance Actual Cyber and Physical security, rather than compliance, is the primary focus now. Actual Cyber and Physical security, rather than compliance, is the primary focus now.
Changing Role (con’t) Initially CIPWG made recommendations ERCOT representatives for NERC CIPC Initially CIPWG made recommendations ERCOT representatives for NERC CIPC Currently TRE MRC appoints representatives to NERC CIPC Currently TRE MRC appoints representatives to NERC CIPC Originally reported to the ERCOT Board, moved under ROS Originally reported to the ERCOT Board, moved under ROS Does not make comments or reports, may coordinate comments by individuals Does not make comments or reports, may coordinate comments by individuals
2012 Summary of Activities Held 12 monthly meetings (generally 1 st Friday of each month) Held 12 monthly meetings (generally 1 st Friday of each month) Attendance averaged about 35 with a peak of about 45. Attendance averaged about 35 with a peak of about 45. One additional joint meeting with SPP CIPWG (April) One additional joint meeting with SPP CIPWG (April) Worked with DOE/DHS to get 3 classified briefings on security topics in Texas. Worked with DOE/DHS to get 3 classified briefings on security topics in Texas.
2012 Summary of Activities (con’t) Attendance is divided with about half of attendees representing compliance staff and about half representing security Attendance is divided with about half of attendees representing compliance staff and about half representing security
Questions?