Are the NERC CIPs a roadmap for attacking the electric grid?

Feb. 25, 2011

The NERC CIPs have a number of characteristics that make them a roadmap for attacking the electric grid.

The NERC CIPs have a number of characteristics that make them a roadmap for attacking the electric grid.

- They were developed by the NERC consensus process. The process is long, arduous, and inherently a “low bar”. As such, the process results in trying to make it easier on the “attackee” than trying to make it more difficult on the attacker.
- The CIPS are public and can be easily found on the Internet. Not only are the CIPs available, but so are the discussions behind the development of the CIPs. This is no different than other open standards processes.
- The CIPS are applied “uniformly” across all electric utilities in North America. What works against one can utility can work against multiple utilities.  As Mike Assante stated in his recent Senate testimony, the NERC CIPs are static and predictable. This means the CIPs cannot be responsive to newly discovered threats such as Stuxnet. Consequently, a successful, coordinated cyber attack, especially with new threats, is very possible.
- The CIPS identify what is in scope, but more importantly what is out of scope. This defies all logic for security as a potential attacker now knows what is left unprotected. The attacker can use the unprotected asset to get at the “protected” asset. So much for securing critical assets.
- The CIPs provide a timetable for implementation. Consequently, a potential attacker knows how much time is available to develop an attack for those assets in scope. Those assets out of scope have no timetable.

What more can an attacker ask for?

What can the public ask for?
- End-to-end security of the grid – no exclusions
- Use available technology to secure control systems and develop appropriate technology where needed
- Mandate development of control system cyber security policies
- Regulate cyber security of the electric grid
- Hold executives accountable

Joe Weiss

Sponsored Recommendations

2024 Industry Trends | Oil & Gas

We sit down with our Industry Marketing Manager, Mark Thomas to find out what is trending in Oil & Gas in 2024. Not only that, but we discuss how Endress+Hau...

Level Measurement in Water and Waste Water Lift Stations

Condensation, build up, obstructions and silt can cause difficulties in making reliable level measurements in lift station wet wells. New trends in low cost radar units solve ...

Temperature Transmitters | The Perfect Fit for Your Measuring Point

Our video introduces you to the three most important selection criteria to help you choose the right temperature transmitter for your application. We also ta...

2024 Industry Trends | Gas & LNG

We sit down with our Industry Marketing Manager, Cesar Martinez, to find out what is trending in Gas & LNG in 2024. Not only that, but we discuss how Endress...