Monday, October 10, 2011

Five Key Questions for NERC CIP Compliance

A few months back we hosted a webinar (see the recorded version) on the importance of Change Control Management for NERC CIP 002-009 compliance. Our knowledgeable host, Jeff Sherwood, put together a presentation highlighting his insights from many years as a cyber security consultant, specifically in the energy industry. Jeff posed five really good questions to ask yourself about the security of your company.

  1. Who should have access to what?
  2. Who does have access to what?
  3. Who could have access to what?
  4. Who did have access to what?
  5. Can we sustain our primary mission if everything fails?
If you can answer all of these questions and have the data to back it up, you have good grasp on complying with the NERC CIP standards. If you cannot answer these questions, take a hard look at getting software to automate change management, and watch our webinar to learn more. 

2 comments:

  1. Very good questions. Management of Personnel Eligibility list (PEL) generally answers Who should have access to what. The challenge is in Who does have access to what as it requires usage of manual review and software scans to determine current access. Who could have access is probable more aimed at open ports and services which need to be documented and scanned. Who did have access i think should be covered if 1-4 are managed properly. The last one is a big one requiring a comprehensive DR plan including a response plan and risk management.

    ReplyDelete
  2. Vinit - those are awesome additions. On the software side of the access equation, I have found that granting, and to a degree, determining, access often rests on the shoulders of the help/service desk. Which in many instances can be the wrong approach. In the past, I had to work very hard (with success) to push this responsibility back up through the organization. This was only achievable by partnering with specific leaders within the organization. Unfortunately, I often saw that this was a challenge many do not want to tackle. Thanks again for the feedback!

    ReplyDelete