Critical Asset Identification Methodology. William E. McEvoy Northeast Utilities

Similar documents
Standard CIP Cyber Security Critical Cyber As s et Identification

Standard CIP Cyber Security Critical Cyber As s et Identification

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION

This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective.

Procedure For NPCC Bulk Electric System Asset Database

New Brunswick 2018 Annual Implementation Plan Version 1

Standard CIP Cyber Security Critical Cyber Asset Identification

Standard CIP Cyber Security Critical Cyber Asset Identification

CIP Cyber Security Standards. Development Update

Standard CIP Cyber Security Electronic Security Perimeter(s)

Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities

Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities

Disclaimer Executive Summary Introduction Overall Application of Attachment Generation Transmission...

Implementing Cyber-Security Standards

A. Introduction 1. Title: 2. Number: 3. Purpose: 4. Applicability: 4.1. Functional Entities: Balancing Authority Distribution Provider

Standard Development Timeline

Standard CIP Cyber Security Security Management Controls

Reliability Standard Audit Worksheet 1

NERC Overview and Compliance Update

Québec Reliability Standards Compliance Monitoring and Enforcement Program Implementation Plan Annual Implementation Plan

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

Physical Security Reliability Standard Implementation

2017 MRO Performance Areas and an Update on Inherent Risk Assessments

Alberta Reliability Standard Cyber Security Incident Reporting and Response Planning CIP-008-AB-5

NB Appendix CIP NB-0 - Cyber Security Recovery Plans for BES Cyber Systems

Standard Development Timeline

Standard CIP-006-1a Cyber Security Physical Security

NB Appendix CIP NB-0 - Cyber Security Personnel & Training

CIP Cyber Security Personnel & Training

Cyber Security and Substation Equipment Overview

Compliance: Evidence Requests for Low Impact Requirements

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

Cyber Attacks on Energy Infrastructure Continue

Grid Security & NERC

Standard Development Timeline

Draft CIP Standards Version 5

Standard CIP Cyber Security Electronic Security Perimeter(s)

Alberta Reliability Standard Cyber Security Electronic Security Perimeter(s) CIP-005-AB-5

Cyber Security Reliability Standards CIP V5 Transition Guidance:

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith

Standard CIP Cyber Security Systems Security Management

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

Purpose. ERO Enterprise-Endorsed Implementation Guidance

CIP Cyber Security Configuration Change Management and Vulnerability AssessmentsManagement

Access Control and CIP 10/20/2011

Implementation Plan for Version 5 CIP Cyber Security Standards

requirements in a NERC or Regional Reliability Standard.

DRAFT. Cyber Security Communications between Control Centers. March May Technical Rationale and Justification for Reliability Standard CIP-012-1

Project Cyber Security - Order No. 791 Identify, Assess, and Correct; Low Impact; Transient Devices; and Communication Networks Directives

Standard Development Timeline

CIP Standards Development Overview

ERO Enterprise Registration Practice Guide: Distribution Provider directly connected Determinations Version 2: July 5, 2018

Standards Authorization Request Form

A. Introduction. Page 1 of 22

Blackout 2003 Reliability Recommendations

Standard CIP Cyber Security Incident Reporting and Response Planning

Violation Risk Factor and Violation Severity Level Justifications Project Modifications to CIP Standards

Title. Critical Infrastructure Protection Getting Low with a Touch of Medium. CanWEA Operations and Maintenance Summit 2018.

Lesson Learned CIP Version 5 Transition Program CIP : Communications and Networking Cyber Assets Version: October 6, 2015

CIP Cyber Security Personnel & Training

Implementation Plan. Project CIP Version 5 Revisions. January 23, 2015

Standard CIP-006-3c Cyber Security Physical Security

CIP Cyber Security Systems Security Management

NERC Staff Organization Chart 2015 Budget

This draft standard is being posted for an initial comment and ballot. The draft includes modifications to meet the directives of FERC Order No. 791.

Impacts and Implementation: NERC Reliability Standards, Compliance Initiatives, and Regulatory Activities

CIP Version 5 Evidence Request User Guide

Standard CIP 005 2a Cyber Security Electronic Security Perimeter(s)

Implementation Plan. Project CIP Version 5 Revisions 1. January 23, 2015

NERC CIP Information Protection

Project Retirement of Reliability Standard Requirements

Categorizing Cyber Systems

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016

CIP Cyber Security Recovery Plans for BES Cyber Systems

CIP Cyber Security Critical Cyber Asset Identification. Rationale and Implementation Reference Document

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

CIP Cyber Security Security Management Controls. Standard Development Timeline

Bulk Electric System Definition Changes and Reporting

Supplemental Information

Standard CIP Cyber Security Physical Security

CIP Cyber Security Recovery Plans for BES Cyber Systems

CIP Cyber Security Security Management Controls. A. Introduction

Appendix A3 - Northeast Power Coordinating Council (NPCC) 2015 CMEP Implementation Plan for Entities within the U.S.

A. Introduction. B. Requirements and Measures

Low Impact Generation CIP Compliance. Ryan Walter

CIP Cyber Security Recovery Plans for BES Cyber Systems

CIP Cyber Security Information Protection

Standard CIP-006-4c Cyber Security Physical Security

DRAFT Reliability Standard Audit Worksheet 1

Standard CIP 007 3a Cyber Security Systems Security Management

CIP Cyber Security Incident Reporting and Response Planning

Standard CIP Cyber Security Physical Security

Violation Risk Factor and Violation Severity Level Justification Project Modifications to CIP-008 Cyber Security Incident Reporting

CIP Cyber Security Physical Security of BES Cyber Systems

RELIABILITY COMPLIANCE ENFORCEMENT IN ONTARIO

Internal Controls Evaluation (ICE) Tony Eddleman, P.E. NERC Compliance Manager Nebraska Public Power District

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1,

TOP for Transmission Operators

Summary of FERC Order No. 791

Risk-Based Compliance Monitoring & Enforcement Oversight Framework. FRCC Spring Compliance Workshop April 14 16, 2015

Transcription:

Critical Asset Identification Methodology William E. McEvoy Northeast Utilities

Disclaimer This NPCC TFIST workshop provides a forum for the presentation and discussion of member experience in the implementation of compliance programs for the NERC CIP Cyber Security Standards. Materials presented or discussed are the presenters own interpretation and recommendations and do not necessarily represent those of their organizations or NPCC. May 15, 2008 2

CIP002 - Identifying Critical Cyber Assets Audit Deliverables - Measures M1 - A documented risk-based methodology (RBM) used to identify an entity s Critical Assets M2 - A list of Critical Assets M3 - A list of Critical Cyber Assets M4 - Proof of an annual review and approval of 1) the list of Critical Assets and 2) the list of Critical Cyber Assets by a senior manager or designee 3

CIP002 - Identifying Critical Cyber Assets Bulk Electric System Assets CIP002 R1.2.1 - R1.2.7 Filtering Identifying Critical Assets Inputs Risk Based Assessment Measure 1 Critical Assets Cyber Assets Filtering Essential to operation of Critical Asset and meets CIP002-R3 Output list of CAs Measure 2 Measure 4 Annual Review and Approval Critical Cyber Assets Output list of CCAs Measure 3 4

Implementation Examples May 15, 2008 5

Enterprise Risk Management Process The NU Executives and Board adopted a Enterprise Risk Management process for managing the principal risks of the organization Risk management at the enterprise level incorporates several key components including: Identification, Assessment, Cataloguing, Assigning ownership, Managing within approved risk tolerances, Communicating, Continuous monitoring, and Annual reviewing of the key business risks. Risk management actively assesses the principal risks that have been identified for the business or for certain corporate initiatives, such as Cyber Security.

The Cyber Security - Enterprise Risk Management Process

Critical Asset Identification Method NU has applied the NU Enterprise Risk Management process in order to meet NERC requirements for applying a risk based methodology to identify critical assets, and associated critical cyber assets. Critical Asset Decision Trees NU has developed Critical Asset Decision Trees to identify and classify Critical Assets as required by NU-NERC CIP-002-1, R2. A decision tree has been developed for the following subgroups: Transmission Generation Control Centers The end result of the application of the decision trees provide NU with the necessary data to develop the Critical Asset list

Critical Assets Identification Transmission Substations A Substation that meets any of the following criteria is included as a critical asset: ISO key facilities Bulk Power Station by NPCC Criteria A-10 Ties to balancing authorities Connecting to a non-nu owned generating unit > 300MW System Protection System Type I or II 9

Transmission Critical Asset Decision Tree

Critical Assets Identification Control Centers A Control Center that meets any of the following criteria is a critical asset: Perform primary or back-up command and control functions for assets listed on CA List Has any distribution level SCADA control over transmission assets on the CA list that might create conditions such as a transfer trip Capable of controlling load shedding of 300MW or greater 11

Critical Assets Identification Control Centers

Critical Assets Identification Generation A Generation Unit that meets any of the following criteria is included as a critical asset: Part of NPCC Blackstart Capability Plan Connected to >100KV Reliability Must Run Required for voltage support Special protection system for N-1 13

Critical Assets Identification Generation

Critical Cyber Assets Identification

Non-Critical Cyber Assets to be protected - Identification

General Comments Closing Use the Industry Guidelines being published NPCC B-27 NERC CIPC Critical Asset Identification Guideline (near future) Work with your Balancing Authority (ISO) to ensure consistency within that area Document, document, document May 15, 2008 17

? Questions or Comments? May 15, 2008 18