33
How to Balance NERC CIPv6 vs. NERC CIPv5 Compliance

How to Balance NERC CIPv6 vs. CIPv5 Compliance

Embed Size (px)

Citation preview

Page 1: How to Balance NERC CIPv6 vs. CIPv5 Compliance

How to Balance NERC CIPv6 vs. NERC CIPv5 Compliance

Page 2: How to Balance NERC CIPv6 vs. CIPv5 Compliance

2

Nick SantoraCEO

[email protected]

Twitter: @curricula

Tim ErlinSr. Director, Product Management

Tripwire

[email protected]

Twitter: @terlin

Page 3: How to Balance NERC CIPv6 vs. CIPv5 Compliance

3

Agenda

CIPv6 Changes

How CIPv6 Affects Your Personnel

Three Critical Steps to Take Before July

Q&A

Page 4: How to Balance NERC CIPv6 vs. CIPv5 Compliance

4

Changes in CIPv6

WORDSWORDSWORDS

Reading standards can be difficult

Page 5: How to Balance NERC CIPv6 vs. CIPv5 Compliance

5

Changes in CIPv6

Low Impact Assets Transient Devices and Removable Media

Logical Controls for Physical Security

Identifies, assesses and corrects

• CIP 003-6 • CIP-004-6• CIP-010-2

• CIP-006-6 • CIP-004-6• CIP-007-6• CIP-009-6• CIP-011-2

Page 6: How to Balance NERC CIPv6 vs. CIPv5 Compliance

6

Changes in CIPv6Low Impact Assets Transient Devices and

Removable MediaLogical Controls for Physical Security

Identifies, assesses and corrects

• CIP 003-6 • CIP-004-6• CIP-010-2

• CIP-006-6 • CIP-004-6• CIP-007-6• CIP-009-6• CIP-011-2

Attachment 1 Cyber Security Awareness Physical Security Controls Electronic Access Controls Cyber Security Incident

Response

Page 7: How to Balance NERC CIPv6 vs. CIPv5 Compliance

7

Changes in CIPv6Low Impact Assets Transient Devices and

Removable MediaLogical Controls for Physical Security

Identifies, assesses and corrects

• CIP 003-6 • CIP-004-6• CIP-010-2

• CIP-006-6 • CIP-004-6• CIP-007-6• CIP-009-6• CIP-011-2

Attachment 1 Cyber Security Awareness Physical Security Controls Electronic Access Controls Cyber Security Incident

Response

Attachment 2 Documentation Documentation Documentation Documentation

Page 8: How to Balance NERC CIPv6 vs. CIPv5 Compliance

8

Changes in CIPv6Low Impact Assets Transient Devices and

Removable MediaLogical Controls for Physical Security

Identifies, assesses and corrects

• CIP 003-6 • CIP-004-6• CIP-010-2

• CIP-006-6 • CIP-004-6• CIP-007-6• CIP-009-6• CIP-011-2

If you use transient cyber assets and removable media ….

…Then you need a plan for:• Transient Asset Management• Transient Asset Authorization• Vulnerability Mitigation• Malicious Code Mitigation• Unauthorized Use Mitigation

Removable Media Authorization

Removable Media Malicious Code Mitigation

Page 9: How to Balance NERC CIPv6 vs. CIPv5 Compliance

9

Changes in CIPv6Low Impact Assets Transient Devices and

Removable MediaLogical Controls for Physical Security

Identifies, assesses and corrects

• CIP 003-6 • CIP-004-6• CIP-010-2

• CIP-006-6 • CIP-004-6• CIP-007-6• CIP-009-6• CIP-011-2

If you use transient cyber assets and removable media ….

…Then you need a plan for:• Transient Asset Management• Transient Asset Authorization• Vulnerability Mitigation• Malicious Code Mitigation• Unauthorized Use Mitigation

Removable Media Authorization

Removable Media Malicious Code Mitigation … and training!

Effective Date Now April 1st 2017

Page 10: How to Balance NERC CIPv6 vs. CIPv5 Compliance

10

Changes in CIPv6Low Impact Assets Transient Devices and

Removable MediaLogical Controls for Physical Security

Identifies, assesses and corrects

• CIP 003-6 • CIP-004-6• CIP-010-2

• CIP-006-6 • CIP-004-6• CIP-007-6• CIP-009-6• CIP-011-2

If you can’t implement the required physical controls, you can implement compensating logical controls: - Encryption- Monitoring- “an equally effective logical control”

“The entity is under no obligation to justify or explain why it chose logicalprotections over physical protections identified in the requirement.”

Page 11: How to Balance NERC CIPv6 vs. CIPv5 Compliance

11

Changes in CIPv6Low Impact Assets Transient Devices and

Removable MediaLogical Controls for Physical Security

Identifies, assesses and corrects

• CIP 003-6 • CIP-004-6• CIP-010-2

• CIP-006-6 • CIP-004-6• CIP-007-6• CIP-009-6• CIP-011-2

FERC Order 791:

“[T]he Commission is concerned that the proposed language is overly-vague, lacking basic definition and guidance that is needed, for example, to distinguish a successful internal control program from one that is inadequate.”

Page 12: How to Balance NERC CIPv6 vs. CIPv5 Compliance

12

CIPv6 Compliance DatesIt’s not all about July 1st 2016

July 1st 2016

CIP-003-6 1.2 4/1/2017CIP-003-6 R2 4/1/2017CIP-003-6 A1-1 4/1/2017CIP-003-6 A1-2 9/1/2018CIP-003-6 A1-3 9/1/2018CIP-003-6 A1-4 4/1/2017CIP-006-6 1.10 7/1/2016 or 4/1/2017CIP-007-6 1.2 7/1/2016 or 4/1/2017CIP-010-2 R4 4/1/2017

Low Impact Assets

Conditional Deadlines

Transient/Removable

Page 13: How to Balance NERC CIPv6 vs. CIPv5 Compliance

13

How CIPv6 Affects Your Personnel

• Training program

• Awareness program

• Transient and Removable

• Risks to education

Page 14: How to Balance NERC CIPv6 vs. CIPv5 Compliance

14

Training Program

Page 15: How to Balance NERC CIPv6 vs. CIPv5 Compliance

15

What Is Required?

9 Objective Statements

Page 16: How to Balance NERC CIPv6 vs. CIPv5 Compliance

16

What Is Required?

Training Prior To Access

Page 17: How to Balance NERC CIPv6 vs. CIPv5 Compliance

17

What is Required?

Re-train Every CIP Year

Page 18: How to Balance NERC CIPv6 vs. CIPv5 Compliance

18

What Will Auditors Look For?

“Regurgitating the Requirement language does not constitute developing a policy, program,process, or procedure.”

WECC Presentation

Page 19: How to Balance NERC CIPv6 vs. CIPv5 Compliance

19

Role Based Training

Page 20: How to Balance NERC CIPv6 vs. CIPv5 Compliance

20

Awareness Program

Page 21: How to Balance NERC CIPv6 vs. CIPv5 Compliance

21

Awareness Program

High and Medium Low

Page 22: How to Balance NERC CIPv6 vs. CIPv5 Compliance

22

Transient and Removable

What Is Required?

Page 23: How to Balance NERC CIPv6 vs. CIPv5 Compliance

23

Transient and Removable

When?

Page 24: How to Balance NERC CIPv6 vs. CIPv5 Compliance

24

Transient and Removable

Why implement after training?

Page 25: How to Balance NERC CIPv6 vs. CIPv5 Compliance

25

Risks in Education

Not It Million Dollar Filing Cabinet

Page 26: How to Balance NERC CIPv6 vs. CIPv5 Compliance

26

Three Critical Steps

NERC CIPv5 Preparation

April 1st

Page 27: How to Balance NERC CIPv6 vs. CIPv5 Compliance

27

Three Critical Steps

NERC CIPv5 Preparation FOUND TIME

April 1st July 1st

Page 28: How to Balance NERC CIPv6 vs. CIPv5 Compliance

28

Three Critical Steps

NERC CIPv5 Preparation FOUND TIME

April 1st July 1st

What should you do with the time remaining before the July deadline?

Page 29: How to Balance NERC CIPv6 vs. CIPv5 Compliance

29

Critical Step 1: Conduct a Mock AuditThere is no compliance without audit

Identify areas of weakness in compliance or evidence.

Establish responses for actual audit Develop mitigation plans for non-compliance

Page 30: How to Balance NERC CIPv6 vs. CIPv5 Compliance

30

Critical Step 2: Review Your Training Programs

Page 31: How to Balance NERC CIPv6 vs. CIPv5 Compliance

31

Critical Step 3: Automate Or Die

Compliant Automated

Page 32: How to Balance NERC CIPv6 vs. CIPv5 Compliance

32

www.getcurricula.com www.tripwire.com

Page 33: How to Balance NERC CIPv6 vs. CIPv5 Compliance

tripwire.com | @TripwireInc

Q & A