More NERC CIP Version 5 Details Emerge

Recently, NERC posted an Industry Webinar entitled “Version 5 CIP Standards: A Focus on ‘Correcting Deficiencies’”. Readers should take the time to quickly review the slides associated with this webinar as the slides point out some important philosophical shifts between NERC CIP version 4 and NERC CIP version 5. Importance of Correcting Deficiencies Among the important updates are the following proposed values of CIP v5: Importance of process to correct deficiencies Greater alignment of << More >>

OT and IT – One Size Does Not Fit All

When it comes to power generation, chemical processing or oil production, not all computer networks can be treated equal. Though they appear to share similar technologies, information technology (IT) networks and operational technology (OT) networks are two very different environments. For one, OT systems tend to include several specialized systems like SCADA, that are not found anywhere in the IT world. Second, there cannot be downtime in OT networks – ever. They must be managed 24/7, 365, wi << More >>

Silver Springs Cloud Services – Tipping Point for Utility Cloud Services ?

Silver Springs officially announced the cloud services for management of the meter networks [1] . Several of us have predicted this happening though there were several factors which were slowing the trend. The facts are simple – Utilities have started deploying networks at a scale that they have never deployed before at a very rapid scale and there is very little chance that the ramp up in skill set to manage the operations will match to the scale of deployments. Outsourcing in the utility << More >>

Complying with NERC CIP v4 and Preparing for v5

NERC has moved quickly to address shortcomings and lack of clarity in previous versions of CIP standards. Recently, FERC approved the latest version, NERC CIP v4 Standards, which attempts to provide additional compliance standards for organizations. However, from a requirement standpoint, there were no major changes between v3 and v4, and organizations have been able to focus on properly fulfilling all the requirement standards. In a contributed article with HS Today, Jacob Kitchel, senior manag << More >>

ICSJWG – Key Takeaways

If you attended the recent ICSJWG Spring 2012 conference, you likely attended the panel that Industrial Defender organized entitled “Key Takeaways from S4 and Project Basecamp.” Moderated by Bob Lockhart from Pike Research, the members of the panel included: Markus Braendle, ABB Robert McComber, Telvent/Schnieder Graham Speake, Yokogowa Brad Hegrat, Rockwell/Allen-Bradley Jonathan Pollet, Red Tiger Security Jacob Kitchel, Industrial Defender There were a lot of good questions, strong opin << More >>

2011 NERC Grid Security Exercise After Action Report Review

What is the 2011 NERC Grid Security Exercise After Action Report? Think of the After Action Report as a “lessons learned” from the annual security exercise. NERC GridEx 2011 is an exercise “designed to validate the readiness of the Electricity Sub-sector to respond to a cyber incident, strengthen utilities’ crisis response functions, and provide input for internal security program improvements.” Including key stakeholders, the participants came from Canada and the U.S., as well as gove << More >>