CG1410-Read

Reader Feedback: Consider All the NERC CIP Standards

Oct. 17, 2014
If You Are Interested in NERC CIP Standards, You May Want to Start by Reading the Proposed Standards

[This comment is in response to Joe Weiss' "Unfettered" blog post, "NERC CIP and Keeping Lights On—Are They the Same?"]

In fairness to NERC, and what looks to be an overall thought to increase FUD over actual reporting, it seems that you must have stumbled into the "NERC CIPS" [sic] SDT meeting on CIP-005-5. That standard is actually focused solely on boundary control systems.

If you are interested in NERC CIP standards, you may want to start by reading the proposed standards that the SDT has put out for draft on the updated version 5.1, available at NERC's website. You'll first notice that there are a lot more standards than simply CIP-005-5, including some you may want to also look into, such as CIP-007-5, CIP-010-5, etc. Those deal with the systems themselves, including configuration, hardening and other crucial activities.

Posting that the utility industry is not taking security seriously when only looking at a single standard really stinks of poor research and reporting. For full disclosure, I do work for a utility, and we have many staff members associated with CIP activities, both at the compliance and drafting level.

To say utilities do not value security is like saying McDonalds doesn't value its french fries. It is where money is made and people are served; if the power isn't on, there is no money to be made (and fines of up to $1 million per day to be paid). Companies are very serious about security, and have been putting major upward pressure on the few manufacturers of equipment out there to modernize. Until then, we can minimize attack footprints, take things completely off line, air gap and take other standard risk mitigation measures that compose any good company's layered security approaches.

W. Doring
[email protected]

Sponsored Recommendations

2024 Industry Trends | Oil & Gas

We sit down with our Industry Marketing Manager, Mark Thomas to find out what is trending in Oil & Gas in 2024. Not only that, but we discuss how Endress+Hau...

Level Measurement in Water and Waste Water Lift Stations

Condensation, build up, obstructions and silt can cause difficulties in making reliable level measurements in lift station wet wells. New trends in low cost radar units solve ...

Temperature Transmitters | The Perfect Fit for Your Measuring Point

Our video introduces you to the three most important selection criteria to help you choose the right temperature transmitter for your application. We also ta...

2024 Industry Trends | Gas & LNG

We sit down with our Industry Marketing Manager, Cesar Martinez, to find out what is trending in Gas & LNG in 2024. Not only that, but we discuss how Endress...