Information Sharing Analysis Engagement. Launched recruiting efforts, hired one cyber analysis specialist in 2017

Size: px
Start display at page:

Download "Information Sharing Analysis Engagement. Launched recruiting efforts, hired one cyber analysis specialist in 2017"

Transcription

1 E-ISAC Update Bill Lawrence, Director of the E-ISAC Charlotte de Seibert, Principal Physical Security Analyst Philip Daigle, Senior Cybersecurity Analyst Critical Infrastructure Protection Committee Jacksonville, FL March 6-7,

2 Agenda Long-term Strategic Plan background 2017 Accomplishments Strategic plan framework Key activities Q1/Q Deliverables GridEx IV update Physical security update Cyber security update 2

3 Background The E-ISAC underwent a strategic review with the Electricity Subsector Coordinating Council (ESCC) in 2015 Under the ESCC, the Member Executive Committee (MEC) was created and serves as a CEO-led stakeholder advisory group MEC input was used on the E-ISAC Long-term Strategic Plan developed in 2017 The plan was approved by the NERC Board in 2017 and included in the NERC Business Plan and Budget for implementation in

4 2017 Accomplishments Launched portal Information Sharing Analysis Engagement Shared over 210 cyber bulletins (140 member-posted; 71 E-ISAC-posted) and 165 physical bulletins (64 memberposted; 101 E-ISAC-posted) Provided content to three NERC Alerts on: Modular Malware Targeting Electric Industry Assets in Ukraine Advanced Persistent Threat Actor Targeting Electric Industry and Other Critical Sectors Supply Chain Risk Gathered GridEx IV lessons learned and recommendations Adopted internationally accepted Traffic Light Protocol for information handling Facilitated 12 monthly E-ISAC and CRISP webinars Facilitated two CRISP member workshops and threat briefings Participated in NRECA RC3 Cyber Security Summits for information sharing best practices Launched recruiting efforts, hired one cyber analysis specialist in 2017 Launched the Embedded Industry Augmentation program Collaborated with CIPC Security Metrics Working Group on new security metrics and data sources Produced a security risk assessment for the MRO Security Advisory Council Produced 51 Weekly, 12 Monthly, 1 Mid-Year, and 1 End of Year reports Produced 12 MonthlyCRISP Analysis reports Conducted GridEx IV: over 6,500 participants (up 50% from GridEx III), over 450 organizations (up 30% from GridEx III) Conducted GridSecCon 2017 with over 500 participants (an increase of 20% from GridSecCon 2016) Enhanced CRISP Participation from 25 to 27 companies CRISP governance group of 15 companies Independent audit of PNNL security practices, data handling Formalized partnership with Downstream Natural Gas ISAC Established MEC user group governance team (UNITE, ISO/RTO Council, Large Public Power Council) Increased active E-ISAC Portal membership from 2,500 to over 3,200 from Q1 to Q3 Partnered with DARPA on a cyber security program for electric utilities linked to the GridEx program Partnered with the University of Illinois at Urbana-Champaign and its new Industry University Cooperative Research Center Discussed malware solutions pipeline research effort with DOE and National Laboratory system Enhanced international engagement: Performed Cyber Risk Preparedness Assessment in Mexico Initiated collaboration with the Japan Electricity ISAC and European E-ISAC (to be continued in 2018) 4

5 2017 Accomplishments Launched portal Information Sharing Analysis Engagement Shared over 210 cyber bulletins (140 member-posted; 71 E-ISAC-posted) and 165 physical bulletins (64 memberposted; 101 E-ISAC-posted) Provided content to three NERC Alerts on: Modular Malware Targeting Electric Industry Assets in Ukraine Advanced Persistent Threat Actor Targeting Electric Industry and Other Critical Sectors Supply Chain Risk Gathered GridEx IV lessons learned and recommendations Adopted internationally accepted Traffic Light Protocol for information handling Facilitated 12 monthly E-ISAC and CRISP webinars Facilitated two CRISP member workshops and threat briefings Participated in NRECA RC3 Cyber Security Summits for information sharing best practices Launched recruiting efforts, hired one cyber analysis specialist in 2017 Launched the Embedded Industry Augmentation program Collaborated with CIPC Security Metrics Working Group on new security metrics and data sources Produced a security risk assessment for the MRO Security Advisory Council Produced 51 Weekly, 12 Monthly, 1 Mid-Year, and 1 End of Year reports Produced 12 MonthlyCRISP Analysis reports Conducted GridEx IV: over 6,500 participants (up 50% from GridEx III), over 450 organizations (up 30% from GridEx III) Conducted GridSecCon 2017 with over 500 participants (an increase of 20% from GridSecCon 2016) Enhanced CRISP Participation from 25 to 27 companies CRISP governance group of 15 companies Independent audit of PNNL security practices, data handling Formalized partnership with Downstream Natural Gas ISAC Established MEC user group governance team (UNITE, ISO/RTO Council, Large Public Power Council) Increased active E-ISAC Portal membership from 2,500 to over 3,200 from Q1 to Q3 Partnered with DARPA on a cyber security program for electric utilities linked to the GridEx program Partnered with the University of Illinois at Urbana-Champaign and its new Industry University Cooperative Research Center Discussed malware solutions pipeline research effort with DOE and National Laboratory system Enhanced international engagement: Performed Cyber Risk Preparedness Assessment in Mexico Initiated collaboration with the Japan Electricity ISAC and European E-ISAC (to be continued in 2018) 5

6 Strategic Plan E-ISAC Strategic Plan Vision: To be a world class, trusted source of quality analysis and rapid sharing of electricity industry security information Supported by: NERC Board of Trustees Electricity Subsector Coordinating Council (ESCC) ESCC Members Executive Committee (MEC) Information Sharing Analysis Engagement Accelerate sharing and high priority notifications Enhance portal Improve information flow and security Build trust and show value CRISP CYOTE CAISS Strategic Vendor Partnerships Hire and develop exceptional employees Leverage information sharing technologies and resources to enhance analytical capability Prioritize products and services Metrics benchmarking Evaluate 24x7 Operations (future) World Class ISAC 6

7 Key Activities Update E-ISAC Critical Broadcast Program Operationalized the rapid information sharing capability of the E-ISAC 1,208 individuals from 245 organizations joined the call CRISP (CRISP Governance Committee Activities) Established E-ISAC local access to CRISP data Governance Committee organized, charter under development Further expanding Membership Base target minimum of four companies joining Identifying and evaluating opportunities to lower cost of participation Developing Strategic Plan Portal Launch Launched December 19, 2017 Providing post-production support Commence planning for portal enhancements, including potential data visualization, authentication, user management, and registration 7

8 Key Activities Update User Communities Developing user communities governance and implementation plan Implementing and testing user community capability Automated Information Sharing Developing and piloting CAISS analytic capabilities Evaluating pros and cons in moving ahead with ThreatConnect platform Industry Augmentation Program Completed week with participating analysts from NYPA and SRP Built trust while exchanging expertise and understanding of threats and response processes 8

9 2018 Q1 and Q2 Deliverables Q1 Q Information Sharing Accelerate sharing and high-priority notifications Establish and exercise Deploy HF capability Join quarterly DHS HF radio tests Critical Broadcast process Gather requirements, develop plan, and issue RFP for Event Management tool Develop and pilot CAISS information sharing capabilities Obtain credentials for staff access to DHS National Cybersecurity and Communications Integration Center Evaluate strategic vendor partnerships Enhance Portal Plan and begin implementations of Portal enhancements including potential data visualization, authentication, user management, and registration Circulate draft GridEx IV reports Improve information access Release GridEx IV reports Join quarterly DHS secure video teleconference tests with industry clearance holders Build work plan with ESCC and CIPC to accomplish GridEx recommendations and lessons learned 9

10 2018 Q1 and Q2 Deliverables Q1 Q Analysis Hire cyber analyst #1 Hire physical security manager and analyst Enhance CRISP data analysis with E-L-K technologies Acquire and develop high quality resources Hire cyber analyst #2 Develop requirements and RFP for contracted analyst support Develop embedded industry augmentation program Develop and pilot CAISS analytic capabilities Leverage technology Evaluate new analytical capabilities Evaluate deployment DOE malware forensics tools and dropbox Prioritize products and services Hire cyber analyst #3 Metrics benchmarking Hire cyber analyst #4 Implement embedded industry augmentation program Gather requirements and develop plan and RFP for data warehouse and analyst workbench Benchmark security metric data Continue work with CIPC Security Metrics Working Group 10

11 2018 Q1 and Q2 Deliverables Q Q2 Engagement Add CRISP participants Hire Member Services manager Expand industry relationships and collaboration SANS ICS Summit Enhance Energy (ONG, DNG) and cross-sector ISAC relationships (FS, Water, Comms, Nuclear) MEC MEC and CIPC GridSecCon strategic planning Build trust and value via user communities Promote unclassified workshops Establish monthly CRISP classified workshops with DOE and Pacific Northwest National Laboratory Develop user community governance and User management registration integration additional portal requirements Define relationship with Cyber Mutual Assistance program Strengthen governmental, institutional, and private sector relationships Establish recurring meetings with DOE, DHS, FERC OEIS Establish MOU with Canadian Cyber Incident Response Centre Strengthen private sector relationships (e.g., SANS, CEATI, etc.) Continue work on trilateral MOU with Japan E-ISAC and European Energy ISAC GridSecCon call for presentations and training MEC and CIPC 11

12 Mission statement GridEx is an unclassified public/private exercise designed to simulate a coordinated cyber and physical attack with operational impacts on electric and other critical infrastructures across North America to improve security, resiliency, and reliability 12

13 GridEx Objectives Exercise incident response plans Expand local and regional response Engage critical interdependencies Improve communication Gather lessons learned Engage senior leadership 13

14 Exercise Components Move 0 Pre-Exercise Distributed Play (2 days) Executive Tabletop (1/2 day) Preparation Identification Containment Reliability Coordinators Support and Vendors Utilities Injects and info sharing by and phone E-ISAC and BPSA Fed/State/Prov Agencies Executive Tabletop Operators may participate in Cyber Intrusion detection activities Players across the stakeholder landscape will participate from their local geographies Facilitated discussion engages senior decision makers in reviewing distributed play and exploring policy triggers 14

15 Participation 6500 Participants 206 Electric utilities 452 Organizations 17 Cross-sector partners 10 States (2 full-scale) 15

16 Active and Observing GridEx Exercise Participation % % % % % % 57% 36 47% GridEx 2011 (76) GridEx II (231) GridEx III (364) GridEx IV (452) Active Observing 16

17 GridEx IV Communications NERC Crisis Action Team Electricity Subsector Coordinating Council (ESCC) Regional Entities Trade Associations Energy GCC Other SCCs Unified Coordination Group (UCG) or non-us equiv. Executive Coordination NERC Bulk Power System Awareness (BPSA) E-ISAC Electricity Information Sharing & Analysis Center DOE Department of Energy DHS NCCIC ICS-CERT US-CERT Other Federal Agencies US: FBI, FERC, DOD Canada: Public Safety Canada, NRCan, RCMP, CSIS, CCIRC Vendor Support IT, ICS, ISP, Anti-virus Other Critical Infrastructures Telecommunications Oil & Gas others Bulk-Power System Entities Coordinated Operations Reliability Coordinators, Balancing Authorities, Generator Operators, Transmission Operators, Load Serving Entities, etc. ExCon GridEx IV Exercise Control NERC staff, GEWG, BAH, Nat l Labs, SMEs for Sim-cell, et al. Coordination with Government Local, State/Provincial Government Governors / Premiers Emergency Management Organizations Emergency Operations Centers / Fusion Centers Local FBI, PSAs National Guard PUCs, PSCs 17

18 Cyber shares 204 Physical Security shares 364 OE-417s submitted 244 EOP-004s submitted 132 Utilities participating in Cyber Mutual Assistance 43 Information Sharing with the E-ISAC 18

19 Where s the Cavalry? Relationship building with partners (e.g. cross-sector, law enforcement, emergency managers, etc.) What is the State/Federal Government s role during a Grid Emergency? E-ISAC Portal improvements Greater cross-sector participation Preliminary Findings GridEx IV Distributed Play Public Affairs and Corporate Communications vs. Incorrect or Misleading information Communication resiliency (e.g. WPS, GETS, HF Radio, etc.) Electric Utility RC emergency communications Cyber Mutual Assistance On-keyboard cyber training Active Lead Planners 19

20 Executive Tabletop Overview Five-hour Executive Tabletop held on November 16, 2017, the second day of the large-scale GridEx IV security and emergency response exercise. Parallel, separate tabletops were held in Canada and Australia Objective: Engage senior industry and government leadership in a robust discussion of the policy issues, decisions, and actions needed to respond to protect and restore the reliable operation of the grid 20

21 Executive Tabletop Themes Extraordinary Measures 21

22 Phased Scenario Discussion One Day After Three Days After Two Weeks After Attacks Begin For each phase after attacks begin: Participants role-play actions and the decisions needed to respond to the situation, restore power, and secure the grid Identify any gaps 22

23 Tabletop Discussion Situation assessment and initial response by industry and government Communications between utilities and with local, state, and federal government Utility liaison with state emergency operations centers Immediate government priority: Stop the Attacks Utility liaison with National Guard Grid Emergency Operations Utilities have the authority to implement emergency actions (e.g., shed load) to maintain grid operation Utilities coordinate with local and state government to identify highpriority customers 23

24 Tabletop Discussion Share sensitive information Need to distribute information quickly and declassify if necessary Decide national level priorities When resources are limited, balance local, state, and national interests Critical infrastructure interdependencies Communications, financial services, natural gas, and critical manufacturing sectors as life-line sectors Utility finances to fund recovery and restoration 24

25 Way Forward GridEx IV Reports will be complete by end of March, 2018 GridEx V Initial Planning Meeting will be held November

26 E-ISAC Physical Security Update Charlotte de Sibert, Principal Physical Security Analyst CIPC March 3, 2018 TLP: WHITE 26

27 Incident Reporting Reporting Submit requests for information, incident or trend related questions, regional analysis requests etc. to Continue reporting events via E-ISAC portal, o When reporting incidents, provide as many details as possible to provide context Location (city, state, region etc.) Impact (customer outages, financial) Has this type of incident occurred before? Mitigation actions taken 27

28 Incidents by Type Overview Q1 Incidents of Note Axe incident in CA Suspicious Activity Events Emotionally unstable individuals inside substation Drone/UAS events Security Equipment theft Copper price monitoring/theft 28

29 Items of Interest Activist/Eco-Terrorist group overview Foreign Terrorist Organization group overview Revised Suspicious Activity Bulletin 2018 Initiatives Increased voluntary sharing Increased analyst context Industry sourced articles and whitepaper sharing 29

30 PSAG Overview of PSAG 2017 Activity New Members Plan for

31 E-ISAC Cyber Update Philip Daigle, Senior Cybersecurity Analyst, E-ISAC CIPC March 6, 2018 TLP: WHITE 31

32 Summary of 2018 Cyber Topics of Interest Malware Targeting Safety Instrumented Systems (SISs) Spear-phishing of Several members Generalized phishing of members 32

33 Summary of 2018 Cryptocurrency Mining Malicious cryptocurrency mining, or cryptojacking, is becoming more prevalent as the price of Bitcoin and other cryptocurrencies skyrocket. In the past few months many threat actors have shifted away from ransomware to using cryptocurrency miners. Compared to ransomware, cryptojacking takes little to no interaction and can generate currency over an extended period of time. 33

34 34

35 ESCC Update Kaitlin Brennan, Manager Cyber and Infrastructure Security, EEI Critical Infrastructure Protection Committee Meeting March 6-7, 2018

36 ESCC Update 2018 Schedule: May 7, 2018 in Washington, DC July 11-12, 2018 at Idaho National Laboratories October 9-10, 2018 in the Washington, DC / Baltimore, MD area Summary of Conclusions November 2017 Puerto Rico Response Threat Information Sharing ESCC-Government Engagement ESCC Vision and Planning Strategic Committee Cross-Sector Coordination 2 RELIABILITY ACCOUNTABILITY

37 3 RELIABILITY ACCOUNTABILITY

38 Legislative Update Kaitlin Brennan, Manager Cyber and Infrastructure Security, EEI Critical Infrastructure Protection Committee Meeting March 6-7, 2018

39 Legislative Update S.79 Securing Energy Infrastructure Act Sens. King (I-ME) & Risch (R-ID) S.141/H.R Space Weather Research and Forecasting Act National Defense Authorization Act (H.R. 2810; P.L ) Cyber SAFETY Act of 2018 (S.2392) Sen. Daines Other possibilities: Expanding background investigations of critical utility personnel Standalone energy bills or as part of an infrastructure package Active Cyber Defense Act Rep. Graves (R-GA) S Sen. Reed (D-RI) Data breach legislation 2 RELIABILITY ACCOUNTABILITY

40 3 RELIABILITY ACCOUNTABILITY

41 NERC Control Systems Security Working Group Carter Manucy, FMPA Michael Mertz, PNM Resources Critical Infrastructure Protection Committee Meeting March 6-7, 2018

42 Critical Infrastructure Protection Committee 2 RELIABILITY ACCOUNTABILITY

43 CSSWG Update Status Update Document review Need for more volunteers Future efforts & projects 3 RELIABILITY ACCOUNTABILITY

44 4 RELIABILITY ACCOUNTABILITY

45 Security Training Working Group David Godfrey Critical Infrastructure Protection Committee Meeting March 6-7, 2018

46 Security Training WG Charter CIPC will provide meeting attendees with an opportunity to participate in physical, cyber, and operational security training, as well as, educational outreach opportunities. Current Members Tobias Whitney, Ross Johnson, John Breckenridge, Carl Herron, Charlotte de Sibert, Jake Schmitter, Bill Lawrence, John Gasstrom, Michele Wright, Amelia Sawyer and David Godfrey. 2 RELIABILITY ACCOUNTABILITY

47 Security Training WG Latest Activities Continue to have monthly conference calls. March 2018 Training Review March 2018 Emergency/Incident Response Management - The STWG had 4 outstanding speakers discussing 3 uniquely different storm events; o Chris Vicino Los Angeles Dept Water & Power Corporate Security Response and Challenges to the Southern California Wildfires o Bert Sausse III CenterPoint Energy Corporate Response and Challenges to Hurricane Harvey o John R. Large & Carlos Morales Florida Power & Light - Corporate Security Response and Challenges to Hurricane Irma 3 RELIABILITY ACCOUNTABILITY

48 Security Training WG 2018 Training Schedule June 2018 Supply Chain Risk Management o Carl Herron E-ISAC/NERC o Tobias Whitney E-ISAC/NERC September 2018 Transient Cyber Asset(s) - (Panel Discussion) Next Steps The SWTG is looking for training topic recommendations for 2019 CIPC Meetings, please contact a STWG Member with your ideas We continue to seek and secure volunteer speakers CIPC Actions Questions and/or suggestions for today s discussion 4 RELIABILITY ACCOUNTABILITY

49 5 RELIABILITY ACCOUNTABILITY

50 NERC Compliance and Enforcement Input Working Group Paul Crist, LES Lisa Carrington, APS Damon Ounsworth, SaskPower Critical Infrastructure Protection Committee Meeting March 6-7, 2018

51 Update: Held two monthly CEIWG Calls Reviewed the 2018 Work Plans Discussed the CIP Implications of Cloud Computing Pilot Developed a proposal for the Cloud Implementation Guidance Project Phased Approach CIP Access Management Phase 1 C(E)IWG Charter Update/Review Implementation Guidance Update Membership Update 2 RELIABILITY ACCOUNTABILITY

52 2018 work plan Development of implementation guidance on cloud computing Other requests for Implementation Guidance development from CIPC Charter Review Annual Update o New Name Compliance Input Working Group? o New (Vice)Chair appointed by the Executive Committee (EC) o Participant List Update 3 RELIABILITY ACCOUNTABILITY

53 Cloud Implementation Guidance Project 4 RELIABILITY ACCOUNTABILITY

54 CIP Access Management Program 5 RELIABILITY ACCOUNTABILITY

55 CIP Access Management Program 6 RELIABILITY ACCOUNTABILITY

56 CIP Access Revocation 7 RELIABILITY ACCOUNTABILITY

57 Charter Update Items of note Propose the new name of Compliance Input Working Group (CIWG) Removed references for anything related to enforcement Added a bullet to review Lessons Learned that the CIPC EC deems further industry follow-up is needed Added a bullet to develop Implementation Guidance where needed under the direction of the CIPC EC Under Deliverables and Work Schedule o added the work plan is in the CIPC Strategic Plan Revised the following bullet o Provide CIPC consensus feedback to NERC Compliance Assurance and Compliance Enforcement on the effectiveness of the CMEP tools and processes when possible 8 RELIABILITY ACCOUNTABILITY

58 Compliance Guidance Development Update Current Status of Documents under Development NEI/NERC PRA Guidance o NERC- Endorsed Shared Facilities o NERC-Endorsed VoIP in Control Centers o Submitted to NERC for endorsement (Posted on NERC Site) 9 RELIABILITY ACCOUNTABILITY

59 Meetings NERC CIPC Compliance and Enforcement Input Working Group Update Meetings o Next Conference Call April 12, 2018 at 1:00 p.m. Central o Subgroup calls as needed o Second Thursday of the Month at 1:00 p.m. Central 10 RELIABILITY ACCOUNTABILITY

60 11 RELIABILITY ACCOUNTABILITY

Compliance Monitoring and Enforcement Program Technology Project Update

Compliance Monitoring and Enforcement Program Technology Project Update Compliance Monitoring and Enforcement Program Technology Project Update Stan Hoptroff, Vice President, Chief Technology Officer and Director of Information Technology Technology and Security Committee

More information

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016 Standards Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016 Balancing Authority Reliability-based Controls Reliability Benefits Data requirements for Balancing Authority (BA)

More information

ERO Enterprise IT Projects Update

ERO Enterprise IT Projects Update ERO Enterprise IT Projects Update Stan Hoptroff, Vice President, Chief Technology Officer and Director of Information Technology Technology and Security Committee Meeting November 6, 2018 Agenda ERO IT

More information

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016 Grid Security & NERC Council of State Governments The Future of American Electricity Policy Academy Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016 1965 Northeast blackout

More information

Grid Security & NERC

Grid Security & NERC Grid Security & NERC Janet Sena, Senior Vice President, Policy and External Affairs Southern States Energy Board 2017 Associate Members Winter Meeting February 27, 2017 Recent NERC History Energy Policy

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2015-2018 CIPC Executive Committee Updated: December 13, 2016 NERC Report Title Report Date I Table of Contents Preface... iv Executive Summary...

More information

Agenda Technology and Security Committee February 7, :15 a.m.-12:15 p.m. Eastern

Agenda Technology and Security Committee February 7, :15 a.m.-12:15 p.m. Eastern Agenda Technology and Security Committee February 7, 2018 11:15 a.m.-12:15 p.m. Eastern Hilton Fort Lauderdale Marina 1881 SE 17 th Street Fort Lauderdale, FL 33316 Conference Room: Grand Ballroom (1st

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2018-2019 CIPC Executive Committee Updated:xxxxxxxx NERC Report Title Report Date I Table of Contents Preface... iii CIPC Organizational Structure...

More information

E-ISAC Long-Term Strategic Plan April 24, 2017

E-ISAC Long-Term Strategic Plan April 24, 2017 TLP: WHITE Recommended Audience: General public. No restrictions for sharing. E-ISAC Long-Term Strategic Plan April 24, 2017 Executive Summary The Electricity Information Sharing and Analysis Center (E-ISAC),

More information

NERC Critical Infrastructure Protection Committee (CIPC) Highlights

NERC Critical Infrastructure Protection Committee (CIPC) Highlights NERC Critical Infrastructure Protection Committee (CIPC) Highlights Mike Kraft, Basin Electric Power Cooperative MRO Board of Directors Meeting March 17, 2016 Midwest Reliability Organization Standards

More information

Cybersecurity Overview

Cybersecurity Overview Cybersecurity Overview DLA Energy Worldwide Energy Conference April 12, 2017 1 Enterprise Risk Management Risk Based: o Use of a risk-based approach for cyber threats with a focus on critical systems where

More information

Industry role moving forward

Industry role moving forward Industry role moving forward Discussion with National Research Council, Workshop on the Resiliency of the Electric Power Delivery System in Response to Terrorism and Natural Disasters February 27-28, 2013

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2013-2016 CIPC Executive Committee 5/14/2013 3353 Peachtree Road NE Suite 600, North Tower Atlanta, Georgia 30326 404-446-2560 www.nerc.com Table

More information

Efficiency and Effectiveness of Stakeholder Engagement

Efficiency and Effectiveness of Stakeholder Engagement Efficiency and Effectiveness of Stakeholder Engagement Michael Walker, Senior Vice President and Chief Enterprise Risk and Strategic Development Officer Member Representatives Committee Meeting February

More information

PIPELINE SECURITY An Overview of TSA Programs

PIPELINE SECURITY An Overview of TSA Programs PIPELINE SECURITY An Overview of TSA Programs Jack Fox Pipeline Industry Engagement Manager Surface Division Office of Security Policy & Industry Engagement May 5, 2014 TSA and Pipeline Security As the

More information

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013 Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013 Purpose and Scope The purpose of the Electricity Sub-Sector Coordinating Council (ESCC) is to facilitate and support

More information

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21 National and Cyber Security Branch Presentation for Gridseccon Quebec City, October 18-21 1 Public Safety Canada Departmental Structure 2 National and Cyber Security Branch National and Cyber Security

More information

GridEx IV Initial Lessons Learned and Resilience Initiatives

GridEx IV Initial Lessons Learned and Resilience Initiatives GridEx IV Initial Lessons Learned and Resilience Initiatives LeRoy T. Bunyon, MBA, CBCP Sr. Lead Analyst, Business Continuity 2017 GridEx IV GridEx is a NERC-sponsored, North American grid resilience exercise

More information

Electric Power Industry s Approach to Grid Security

Electric Power Industry s Approach to Grid Security Electric Power Industry s Approach to Grid Security Richard Ward, Director, National Security Policy Edison Electric Institute (EEI) Cybersecurity & Privacy Policy Academy November 2, 2017 San Francisco,

More information

FERC Reliability Technical Conference Panel III: ERO Performance and Initiatives ESCC and the ES-ISAC

FERC Reliability Technical Conference Panel III: ERO Performance and Initiatives ESCC and the ES-ISAC : ERO Performance and Initiatives June 4, 2015 Chairman Bay, Commissioners, and fellow panelists, I appreciate the opportunity to address the topics identified for the third panel of today s important

More information

Private Sector Clearance Program (PSCP) Webinar

Private Sector Clearance Program (PSCP) Webinar Private Sector Clearance Program (PSCP) Webinar Critical Infrastructure Protection Committee November 18, 2014 Nathan Mitchell, ESCC Clearance Liaison Agenda History NERC CIPC Private Sector Clearance

More information

CALIFORNIA CYBERSECURITY TASK FORCE

CALIFORNIA CYBERSECURITY TASK FORCE CALIFORNIA CYBERSECURITY TASK FORCE Advancing California s cybersecurity priorities through public, private, corporate, and academic sector collaboration. Agenda Task Force Overview California Cybersecurity

More information

The Office of Infrastructure Protection

The Office of Infrastructure Protection The Office of Infrastructure Protection National Protection and Programs Directorate Department of Homeland Security Organisation for the Prohibition of Chemical Weapons September 13, 2011 Overall Landscape

More information

Critical Infrastructure Protection Version 5

Critical Infrastructure Protection Version 5 Critical Infrastructure Protection Version 5 Tobias Whitney, Senior CIP Manager, Grid Assurance, NERC Compliance Committee Open Meeting August 9, 2017 Agenda Critical Infrastructure Protection (CIP) Standards

More information

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium Securing Cyber Space & America s Cyber Assets: Threats, Strategies & Opportunities September 10, 2009, Crystal Gateway Marriott, Arlington,

More information

Testimony. Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON

Testimony. Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON Testimony Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON Defending Our Democracy: Building Partnerships to Protect America

More information

Statement for the Record

Statement for the Record Statement for the Record of Seán P. McGurk Director, Control Systems Security Program National Cyber Security Division National Protection and Programs Directorate Department of Homeland Security Before

More information

Electric Reliability Organization Enterprise Operating Plan

Electric Reliability Organization Enterprise Operating Plan Electric Reliability Organization Enterprise Operating Plan Approved by the NERC Board of Trustees: November 2017 NERC Report Title Report Date I Table of Contents Preface... iii Introduction... 1 Vision,

More information

Standards. Howard Gugel, Senior Director of Standards and Education Board of Trustees Meeting May 11, 2017

Standards. Howard Gugel, Senior Director of Standards and Education Board of Trustees Meeting May 11, 2017 Standards Howard Gugel, Senior Director of Standards and Education Board of Trustees Meeting May 11, 2017 WECC Reliability Standards Development Procedures Background Reflect change in NERC Compliance

More information

Chapter X Security Performance Metrics

Chapter X Security Performance Metrics Chapter X Security Performance Metrics Page 1 of 10 Chapter X Security Performance Metrics Background For many years now, NERC and the electricity industry have taken actions to address cyber and physical

More information

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 I. Vision A highly reliable and secure bulk power system in the Electric Reliability Council of Texas

More information

Agenda Critical Infrastructure Protection Committee March 6, :00 p.m. 5:00 p.m. Eastern March 7, :00 a.m. Noon Eastern

Agenda Critical Infrastructure Protection Committee March 6, :00 p.m. 5:00 p.m. Eastern March 7, :00 a.m. Noon Eastern Agenda Critical Infrastructure Protection Committee March 6, 2018 1:00 p.m. 5:00 p.m. Eastern March 7, 2018 8:00 a.m. Noon Eastern Hyatt Regency Jacksonville Riverfront 225East Coastline Drive Jacksonville,

More information

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure Executive Order 13800 Update July 2017 In Brief On May 11, 2017, President Trump issued Executive Order 13800, Strengthening

More information

ARRA State & Local Energy Assurance Planning & Implementation

ARRA State & Local Energy Assurance Planning & Implementation State Energy Policy and Technology Outlook Conference February 2, 2010, Washington, DC ARRA State & Local Energy Assurance Planning & Implementation Alice Lippert Senior Technical Advisor Office of Electricity

More information

Physical Security Reliability Standard Implementation

Physical Security Reliability Standard Implementation Physical Security Reliability Standard Implementation Attachment 4b Action Information Background On March 7, 2014, the Commission issued an order directing NERC to submit for approval, within 90 days,

More information

NERC Staff Organization Chart

NERC Staff Organization Chart NERC Staff Organization Chart President and CEO Administrative Associate Director to the Office of the CEO Associate Director, Member Relations and MRC Secretary Senior Vice President and Chief Reliability

More information

Standards. Howard Gugel, Senior Director of Standards and Education Board of Trustees Meeting November 9, 2017

Standards. Howard Gugel, Senior Director of Standards and Education Board of Trustees Meeting November 9, 2017 Standards Howard Gugel, Senior Director of Standards and Education Board of Trustees Meeting November 9, 2017 2018-2020 Reliability Standards Development Plan Status Posted for industry comment June 26

More information

Greg Garcia President, Garcia Cyber Partners Former Assistant Secretary for Cyber Security and Communications, U.S. Department of Homeland Security

Greg Garcia President, Garcia Cyber Partners Former Assistant Secretary for Cyber Security and Communications, U.S. Department of Homeland Security 1 Greg Garcia President, Garcia Cyber Partners Former Assistant Secretary for Cyber Security and Communications, U.S. Department of Homeland Security 2 Government Services 3 Business Education Social CYBERSPACE

More information

Department of Homeland Security Updates

Department of Homeland Security Updates American Association of State Highway and Transportation Officials Special Committee on Transportation Security and Emergency Management 2016 Critical Infrastructure Committee Joint Annual Meeting Department

More information

Critical Infrastructure Protection Committee Draft Minutes September 16-17, 2014

Critical Infrastructure Protection Committee Draft Minutes September 16-17, 2014 Critical Infrastructure Protection Committee Draft Minutes September 16-17, 2014 Hyatt Regency Vancouver 655 Burrard Street Vancouver, BC, Canada V6C2R7 The Critical Infrastructure Protection Committee

More information

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Facts expressed in this presentation are Facts Opinions express in this presentation are solely my own The voices I

More information

DHS Cybersecurity: Services for State and Local Officials. February 2017

DHS Cybersecurity: Services for State and Local Officials. February 2017 DHS Cybersecurity: Services for State and Local Officials February 2017 Department of Established in March of 2003 and combined 22 different Federal departments and agencies into a unified, integrated

More information

Chapter X Security Performance Metrics

Chapter X Security Performance Metrics Chapter X Security Performance Metrics Page 1 of 9 Chapter X Security Performance Metrics Background For the past two years, the State of Reliability report has included a chapter for security performance

More information

ICS-CERT Year in Review. Industrial Control Systems Cyber Emergency Response Team

ICS-CERT Year in Review. Industrial Control Systems Cyber Emergency Response Team ICS-CERT Year in Review Industrial Control Systems Cyber Emergency Response Team 2012 What s Inside Welcome 1 Organization 3 Outreach 4 Industrial Control Systems Joint Working Group 5 Advanced Analytical

More information

BEFORE THE U.S. HOUSE OF REPRESENTATIVES COMMITTEE ON ENERGY AND COMMERCE SUBCOMMITTEE ON ENERGY

BEFORE THE U.S. HOUSE OF REPRESENTATIVES COMMITTEE ON ENERGY AND COMMERCE SUBCOMMITTEE ON ENERGY STATEMENT OF SCOTT I. AARONSON EXECUTIVE DIRECTOR, SECURITY AND BUSINESS CONTINUITY EDISON ELECTRIC INSTITUTE AND SECRETARIAT MEMBER ELECTRICITY SUBSECTOR COORDINATING COUNCIL BEFORE THE U.S. HOUSE OF

More information

Welcome Mike Kraft, MRO SAC Member

Welcome Mike Kraft, MRO SAC Member 11/16/2016 Welcome Mike Kraft, MRO SAC Member Basin Electric Power Cooperative Please submit questions to the meeting moderator. Questions will be answered at the end of the webinar. NOTICE The is an industry

More information

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION. Foundation for Resilient Societies ) Docket No.

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION. Foundation for Resilient Societies ) Docket No. UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION Foundation for Resilient Societies ) Docket No. AD17-9-000 COMMENTS OF THE NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION IN OPPOSITION

More information

History of NERC January 2018

History of NERC January 2018 History of NERC January 2018 Date 1962 1963 The electricity industry created an informal, voluntary organization of operating personnel to facilitate coordination of the bulk power system in the United

More information

NERC Staff Organization Chart 2015 Budget

NERC Staff Organization Chart 2015 Budget NERC Staff Organization Chart President and CEO (Dept. 2100) Executive Assistant (Dept. 2100) Associate Director, Member Relations and MRC Secretary (Dept. 2100) Senior Vice President and Chief Reliability

More information

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith OPUC Workshop March 13, 2015 Cyber Security Electric Utilities Portland General Electric Co. Travis Anderson Scott Smith 1 CIP Version 5 PGE Implementation Understanding the Regulations PGE Attended WECC

More information

HPH SCC CYBERSECURITY WORKING GROUP

HPH SCC CYBERSECURITY WORKING GROUP HPH SCC A PRIMER 1 What Is It? The cross sector coordinating body representing one of 16 critical infrastructure sectors identified in Presidential Executive Order (PPD 21) A trust community partnership

More information

Global Resilience Federation Trust. Collaboration. Community. Cindy Donaldson President, Global Resilience Federation October 2017

Global Resilience Federation Trust. Collaboration. Community. Cindy Donaldson President, Global Resilience Federation October 2017 Global Resilience Federation Trust. Collaboration. Community. Cindy Donaldson President, Global Resilience Federation October 2017 Global Resilience Federation is a non-profit organization committed to

More information

December 10, Statement of the Securities Industry and Financial Markets Association. Senate Committee on Banking, Housing, and Urban Development

December 10, Statement of the Securities Industry and Financial Markets Association. Senate Committee on Banking, Housing, and Urban Development December 10, 2014 Statement of the Securities Industry and Financial Markets Association Senate Committee on Banking, Housing, and Urban Development Hearing Entitled Cybersecurity: Enhancing Coordination

More information

The Africa Utilities Telecom Council Johannesburg CC, South Africa 1 st December, 2015

The Africa Utilities Telecom Council Johannesburg CC, South Africa 1 st December, 2015 The Africa Utilities Telecom Council Johannesburg CC, South Africa 1 st December, 2015 Utilities Telecom Council Global Focus on Utility Information and Communications Technology (ICT) Formed more than

More information

Reliability Standards Development Plan

Reliability Standards Development Plan Reliability Standards Development Plan Steven Noess, Director of Standards Development Standards Oversight and Technology Committee Meeting November 1, 2016 2017-2019 Reliability Standards Development

More information

Grid Security Exercise (GridEx II)

Grid Security Exercise (GridEx II) Grid Security Exercise (GridEx II) After-Action Report March 2014 1 of 26 3353 Peachtree Road NE Suite 600, North Tower Atlanta, GA 30326 404-446-2560 www.nerc.com Table of Contents Preface... 3 Executive

More information

DHS Supply Chain Activity: Cross-Sector Supply Chain Working Group and Strategy on Global Supply Chain Security

DHS Supply Chain Activity: Cross-Sector Supply Chain Working Group and Strategy on Global Supply Chain Security DHS Supply Chain Activity: Cross-Sector Supply Chain Working Group and Strategy on Global Supply Chain Security Josha Jordan U.S. Department of Homeland Security National Protection and Programs Directorate

More information

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1,

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1, EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1, 2008 www.morganlewis.com Overview Reliability Standards Enforcement Framework Critical Infrastructure Protection (CIP)

More information

Department of Defense. Installation Energy Resilience

Department of Defense. Installation Energy Resilience Department of Defense Installation Energy Resilience Lisa A. Jung DASD (Installation Energy) OASD(Energy, Installations and Environment) 19 June 2018 Installation Energy is Energy that Powers Our Military

More information

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2019 NERC Staff Organization Chart Budget 2019 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Officer Senior Vice President, General Counsel and Corporate

More information

EARTH Ex 2017 Middle Planning Conference

EARTH Ex 2017 Middle Planning Conference EARTH Ex 2017 Middle Planning Conference 20 April 2017 Emergency All-sector Response to Transnational Hazards Exercise 23 August 2017 1 EARTH Ex 2017 MPC Sector Objectives Review EARTH Ex Plan, Concepts

More information

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management Remarks of Marcus Sachs, Senior Vice President and the Chief Security Officer North American Electric Reliability

More information

Cyber Security Incident Report

Cyber Security Incident Report Cyber Security Incident Report Technical Rationale and Justification for Reliability Standard CIP-008-6 January 2019 NERC Report Title Report Date I Table of Contents Preface... iii Introduction... 1 New

More information

DHS Cybersecurity. Election Infrastructure as Critical Infrastructure. June 2017

DHS Cybersecurity. Election Infrastructure as Critical Infrastructure. June 2017 DHS Cybersecurity Election Infrastructure as Critical Infrastructure June 2017 Department of Homeland Security Safeguard the American People, Our Homeland, and Our Values Homeland Security Missions 1.

More information

Water Information Sharing and Analysis Center

Water Information Sharing and Analysis Center SUPERCHARGE YOUR SECURITY Water Information Sharing and Analysis Center DHS Hunt and Incident Response Team September 12, 2018 SUPERCHARGE YOUR SECURITY Presenter Brian Draper, DHS NCCIC HIRT Slides and

More information

Panelists. Moderator: Dr. John H. Saunders, MITRE Corporation

Panelists. Moderator: Dr. John H. Saunders, MITRE Corporation SCADA/IOT Panel This panel will focus on innovative & emerging solutions and remaining challenges in the cybersecurity of industrial control systems ICS/SCADA. Representatives from government and infrastructure

More information

DOE s Roles and Responsibilities for Energy Sector Cybersecurity

DOE s Roles and Responsibilities for Energy Sector Cybersecurity Written Testimony of Under Secretary Mark Menezes U.S. Department of Energy Before the Subcommittee on Energy Committee on Energy and Commerce U.S. House of Representatives March 14, 2018 Introduction

More information

2 nd Cybersecurity Workshop Test and Evaluation to Meet the Advanced Persistent Threat

2 nd Cybersecurity Workshop Test and Evaluation to Meet the Advanced Persistent Threat 2 nd Cybersecurity Workshop Test and Evaluation to Meet the Advanced Persistent Threat Faye Francy Aviation ISAC February 2015 Company Organization Corporate Defense, Space & Security Boeing Capital Corporation

More information

ERO Enterprise Strategic Planning Redesign

ERO Enterprise Strategic Planning Redesign ERO Enterprise Strategic Planning Redesign Mark Lauby, Senior Vice President and Chief Reliability Officer Member Representatives Committee Meeting February 10, 2016 Strategic Planning Redesign Current

More information

National Cyber Security Strategy - Qatar. Michael Lewis, Deputy Director

National Cyber Security Strategy - Qatar. Michael Lewis, Deputy Director National Cyber Security Strategy - Qatar Michael Lewis, Deputy Director 2 Coordinating a National Approach to Cybersecurity ITU Pillars of Cybersecurity as a Reference Point providing the collected best

More information

Live Webinar: Best Practices in Substation Security November 17, 2014

Live Webinar: Best Practices in Substation Security November 17, 2014 Live Webinar: Best Practices in Substation Security November 17, 2014 1 Agenda & Panelists Welcome & Introduction - Allan Wick, CFE, CPP, PSP, PCI, CBCP Enterprise Security Manager-CSO Tri-State Generation

More information

DHS Election Task Force Updates. Geoff Hale, Elections Task Force

DHS Election Task Force Updates. Geoff Hale, Elections Task Force 1 DHS Election Task Force Updates Geoff Hale, Elections Task Force Geoffrey.Hale@hq.dhs.gov ETF Updates Where we ve made progress Services EI-ISAC/ National Cyber Situational Awareness Room What we ve

More information

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT Mitigation Framework Leadership Group (MitFLG) Charter DRAFT October 28, 2013 1.0 Authorities and Oversight The Mitigation Framework Leadership Group (MitFLG) is hereby established in support of and consistent

More information

Election Infrastructure Security: The How and Why of It

Election Infrastructure Security: The How and Why of It Election Infrastructure Security: The How and Why of It Minnesota County Auditor Election Training Conference May 3, 2018 Contents Election Infrastructure Security Overview Cyber and Physical Security

More information

Cyber Partnership Blueprint: An Outline

Cyber Partnership Blueprint: An Outline Approved for Public Release; Distribution Unlimited. 13-3851 The MITRE Corporation Cyber Partnership Blueprint: An Outline October 26, 2013 Copyright 1997-2013, The MITRE Corporation. All rights reserved.

More information

TERRORISM LIAISON OFFICER OUTREACH PROGRAM - (TLOOP)

TERRORISM LIAISON OFFICER OUTREACH PROGRAM - (TLOOP) To: Bay Area UASI Approval Authority From: Mike Sena, Director NCRIC/HIDTA Date: January 10, 2019 Re: Item 7: NCRIC Annual Report and Proposed FY19 Allocation Recommendation: Approve $4,454,066 from the

More information

GridEx IV Panel Discussion

GridEx IV Panel Discussion GridEx IV Panel Discussion NERC GridSecCon October, 2016 1 Generation 254 GW Transmission Geography 120,000 Miles 22 States GridEx IV Panel Discussion Focus on Operations NERC GridSecCon October 20, 2016

More information

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting May 5, 2016

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting May 5, 2016 Standards Howard Gugel, Director of Standards Board of Trustees Meeting May 5, 2016 Real-time Monitoring and Analysis Reliability Benefits Ensure entities have capabilities for maintaining high quality

More information

NATIONAL ELECTRIC GRID SECURITY AND RESILIENCE ACTION PLAN

NATIONAL ELECTRIC GRID SECURITY AND RESILIENCE ACTION PLAN NATIONAL ELECTRIC GRID SECURITY AND RESILIENCE ACTION PLAN Product of the Executive Office of the President DECEMBER 2016 Table of Contents Introduction................................... 1 Structure

More information

NGA Governor s Energy Advisors Energy Policy Institute Resiliency Panel

NGA Governor s Energy Advisors Energy Policy Institute Resiliency Panel U.S. DEPARTMENT OF ENERGY Infrastructure Security & Energy Restoration Prepare. Respond. Adapt. NGA Governor s Energy Advisors Energy Policy Institute Resiliency Panel Puesh M. Kumar Director, Preparedness

More information

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2019 NERC Staff Organization Chart Budget 2019 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel and Corporate

More information

Scope Cyber Attack Task Force (CATF)

Scope Cyber Attack Task Force (CATF) Scope Cyber Attack Task Force (CATF) PART A: Required for Committee Approval Purpose This document defines the scope, objectives, organization, deliverables, and overall approach for the Cyber Attack Task

More information

ERO Reliability Risk Priorities Report. Peter Brandien, Reliability Issues Steering Committee Chair WECC Reliability Workshop March 21, 2018

ERO Reliability Risk Priorities Report. Peter Brandien, Reliability Issues Steering Committee Chair WECC Reliability Workshop March 21, 2018 ERO Reliability Risk Priorities Report Peter Brandien, Reliability Issues Steering Committee Chair WECC Reliability Workshop March 21, 2018 Reliability Issues Steering Committee (RISC) Background 2 RISC

More information

Standard Development Timeline

Standard Development Timeline Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard is adopted by the NERC Board of Trustees (Board).

More information

Welcome to the CyberSecure My Business Webinar Series We will begin promptly at 2pm EDT All speakers will be muted until that time

Welcome to the CyberSecure My Business Webinar Series We will begin promptly at 2pm EDT All speakers will be muted until that time TM Plan. Protect. Respond. Welcome to the CyberSecure My Business Webinar Series We will begin promptly at 2pm EDT All speakers will be muted until that time Registration is open for the April webinar:

More information

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION NARUC Energy Regulatory Partnership Program The Public Services Regulatory Commission of Armenia and The Iowa Utilities Board Janet Amick Senior Utility

More information

COUNTERING IMPROVISED EXPLOSIVE DEVICES

COUNTERING IMPROVISED EXPLOSIVE DEVICES COUNTERING IMPROVISED EXPLOSIVE DEVICES FEBRUARY 26, 2013 COUNTERING IMPROVISED EXPLOSIVE DEVICES Strengthening U.S. Policy Improvised explosive devices (IEDs) remain one of the most accessible weapons

More information

Standing Together for Financial Industry Resilience Quantum Dawn 3 After-Action Report. November 19, 2015

Standing Together for Financial Industry Resilience Quantum Dawn 3 After-Action Report. November 19, 2015 Standing Together for Financial Industry Resilience Quantum Dawn 3 After-Action Report November 19, 2015 Table of contents Background Exercise objectives Quantum Dawn 3 (QD3) cyberattack scenario QD3 results

More information

The Office of Infrastructure Protection

The Office of Infrastructure Protection The Office of Infrastructure Protection National Protection and Programs Directorate Department of Homeland Security Regional Resiliency Assessment Program 2015 State Energy Risk Assessment Workshop April

More information

Response to Wood Buffalo Wildfire KPMG Report. Alberta Municipal Affairs

Response to Wood Buffalo Wildfire KPMG Report. Alberta Municipal Affairs Response to Wood Buffalo Wildfire KPMG Report Alberta Municipal Affairs Background To ensure continuous enhancement and improvement of Alberta s public safety system, the Alberta Emergency Management Agency

More information

CIP Version 5 Transition. Steven Noess, Director of Compliance Assurance Member Representatives Committee Meeting November 12, 2014

CIP Version 5 Transition. Steven Noess, Director of Compliance Assurance Member Representatives Committee Meeting November 12, 2014 CIP Version 5 Transition Steven Noess, Director of Compliance Assurance Member Representatives Committee Meeting November 12, 2014 Purpose of the Transition Program Transitioning entities confident in

More information

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS The Saskatchewan Power Corporation (SaskPower) is the principal supplier of power in Saskatchewan with its mission to deliver power

More information

June 5, 2018 Independence, Ohio

June 5, 2018 Independence, Ohio June 5, 2018 Independence, Ohio The Office of Infrastructure Protection National Protection and Programs Directorate Department of Homeland Security Securing the Nation at the Community Level 2018 Cuyahoga

More information

American Association of Port Authorities Port Security Seminar & Expo Cyber Security Preparedness and Resiliency in the Marine Environment

American Association of Port Authorities Port Security Seminar & Expo Cyber Security Preparedness and Resiliency in the Marine Environment American Association of Port Authorities Port Security Seminar & Expo Cyber Security Preparedness and Resiliency in the Marine Environment July 20, 2017 DECIDEPLATFORM.COM The new Reality of Cyber Security

More information

Briefing to National Association of Regulatory Utility Commissioners

Briefing to National Association of Regulatory Utility Commissioners Critical Infrastructure Threat Information Sharing Framework Briefing to National Association of Regulatory Utility Commissioners February 12, 2017 The Info Sharing Problem 2 Because I m a Government Employee

More information

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION ) )

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION ) ) UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION Cyber Security Incident Reporting Reliability Standards ) ) Docket Nos. RM18-2-000 AD17-9-000 COMMENTS OF THE NORTH AMERICAN ELECTRIC

More information

Agenda Technology and Security Committee November 6, :15 a.m.-12:00 p.m. Eastern

Agenda Technology and Security Committee November 6, :15 a.m.-12:00 p.m. Eastern Agenda Technology and Security Committee November 6, 2018 11:15 a.m.-12:00 p.m. Eastern Grand Hyatt Atlanta in Buckhead 3300 Peachtree Rd NE Atlanta, GA 30305 Conference Room: Grand Ballroom - Lower Lobby

More information

Incident Response Services

Incident Response Services Services Enhanced with Supervised Machine Learning and Human Intelligence Empowering clients to stay one step ahead of the adversary. Secureworks helps clients enable intelligent actions to outsmart and

More information

U.S. Department of Homeland Security Office of Cybersecurity & Communications

U.S. Department of Homeland Security Office of Cybersecurity & Communications U.S. Department of Homeland Security Office of Cybersecurity & Communications Council of State Governments Cybersecurity Session November 3, 2017 Cybersecurity & Communications (CS&C) CS&C s Mission ensure

More information

History of NERC December 2012

History of NERC December 2012 History of NERC December 2012 Timeline Date 1962-1963 November 9, 1965 1967 1967-1968 June 1, 1968 July 13-14, 1977 1979 1980 Description Industry creates an informal, voluntary organization of operating

More information