NERC to utilities: Reduce cyber security risk

In a letter to the electric utility industry, Michael Assante, chief security officer for NERC (National Electric Reliability Corporation), is delivering a diplomatic but pointed message: By trying to avoid regulation, utilities are putting the electrical system at risk. In this case, cyber security risks may have increased because of the way some electric utilities are approaching regulatory c...

05/01/2009


In a letter to the electric utility industry, Michael Assante, chief security officer for NERC (National Electric Reliability Corporation), is delivering a diplomatic but pointed message: By trying to avoid regulation, utilities are putting the electrical system at risk. In this case, cyber security risks may have increased because of the way some electric utilities are approaching regulatory compliance.

New regulations intended to protect the bulk electric grid are aimed at assets that have been classified as “critical.” The specific definition identifies assets that “if destroyed, degraded, or otherwise rendered unavailable, would affect the reliability or operability of the Bulk Electric System.” In an apparent effort to avoid regulation, utilities are reporting that they have relatively few plants and parts of their distribution networks that qualify under the definition.

NERC’s view is that the utilities are not really considering how interconnected all the parts of the system are and are therefore drastically undercounting those that should fall appropriately under the regulation. Assante’s suggestion is that utilities perform their analysis again beginning with the assumption that all assets are critical unless there are clear reasons that they can be ruled out, rather than the reverse.

As the letter states, “NERC is requesting that entities take a fresh, comprehensive look at their risk-based methodology and their resulting list of CAs [critical assets] with a broader perspective on the potential consequences to the entire interconnected system of not only the loss of assets that they own or control, but also the potential misuse of those assets by intelligent threat actors. Although it is the responsibility of the Registered Entities to identify and safeguard applicable CAs, NERC and the Regional Entities will jointly review the significant number of…entities that reported having no CAs to determine the root cause(s) and suggest appropriate corrective actions, if necessary.”

www.nerc.com





No comments
The Engineers' Choice Awards highlight some of the best new control, instrumentation and automation products as chosen by...
The System Integrator Giants program lists the top 100 system integrators among companies listed in CFE Media's Global System Integrator Database.
The Engineering Leaders Under 40 program identifies and gives recognition to young engineers who...
This eGuide illustrates solutions, applications and benefits of machine vision systems.
Learn how to increase device reliability in harsh environments and decrease unplanned system downtime.
This eGuide contains a series of articles and videos that considers theoretical and practical; immediate needs and a look into the future.
Intelligent, efficient PLC programming: Cost-saving programming languages are available now; Automation system upgrades; Help from the cloud; Improving flow control; System integration tips
Smarter machines require smarter systems; Fixing PID, part 3; Process safety; Hardware and software integration; Legalities: Integrated lean project delivery
Choosing controllers: PLCs, PACs, IPCs, DCS? What's best for your application?; Wireless trends; Design, integration; Manufacturing Day; Product Exclusive
PLCs, robots, and the quest for a single controller; how OEE is key to automation solutions.
This article collection contains several articles on improving the use of PID.
Learn how Industry 4.0 adds supply chain efficiency, optimizes pricing, improves quality, and more.

Find and connect with the most suitable service provider for your unique application. Start searching the Global System Integrator Database Now!

Special report: U.S. natural gas; LNG transport technologies evolve to meet market demand; Understanding new methane regulations; Predictive maintenance for gas pipeline compressors
Cyber security cost-efficient for industrial control systems; Extracting full value from operational data; Managing cyber security risks
Drilling for Big Data: Managing the flow of information; Big data drilldown series: Challenge and opportunity; OT to IT: Creating a circle of improvement; Industry loses best workers, again