Gaining and Continuously Maintaining NERC Compliance

Electrical System Reliability in the Digital Age

When it comes to something as critical as electric delivery in North America, even a minor IT problem can cause major havoc. Since a vast majority of the power grid is controlled with IT assets, ensuring continual system uptime of these assets is extremely critical. As such, the North American Electric Reliability Corporation, which is a non-profit organization that exists to ensure reliable electric delivery, has established Critical Infrastructure Protection (CIP) Cyber Security Standards. These standards help to provide a delivery infrastructure that delivers electric power to millions of users each and every second.

 

Changes to critical files and configurations could be catastrophic given that electrical power is such a part of our daily lives. When blackouts occur, it can have dire consequences; businesses can’t run critical systems, traffic controls don’t function, and hospitals lose the ability to power critical lifesaving devices. We take for granted that our lights will turn on when we flip the switch or plug in our computer to the wall. The electrical power transmission system in North America certainly has a reasonably high rate of reliability, but a recent government announcement in early April that hackers had penetrated computers that control the power grid, should give all of us pause.


Is Detection of Potentially Harmful Changes Enough?

While complying with the Critical Infrastructure Protection Cyber Security Standards is certainly a step in the right direction, like all compliance requirements, simply being “in compliance” is simply not enough. What happens when a hacker circumvents your network protections and alters critical files or system configurations? Some products will alert you to these changes, but how long does it take someone to respond to those alerts? Sure, they will be aware that a change has occurred, but what if that change is embedded somewhere within a very large file? How do you quickly find the change and remedy it? What if the change happens at a time when IT security personnel are unavailable, or perhaps occupied with another problem? With something as vital as electrical power delivery, every second is critical. What if you were able to proactively respond to a potentially devastating change, thus ensuring that your transmission system stays in a constant state of integrity?

 

The CimTrak Solution

You deploy a number of security solutions to keep your network safe, but even with significant defenses in place, bad things can still happen. As a last line of defense, CimTrak works by detecting changes to critical files and configurations. Covering a broad range of operating systems including Windows, HP-UX, Linux, AIX and Solaris systems, CimTrak easily fits into your SCADA and business environment. Its’ cutting edge technology gives you the capability to proactively mitigate system changes that can make you non-compliant and worse yet, cause critical power transmission systems to fail. Systems are growing more and more complex. The recent move towards “smart grid” technologies only heightens this complexity. Ensuring 100% system reliability has become more important than ever. The ability to respond to a potential problem in real-time, without human intervention, should be a high priority for your organization.

Header Image: 
Solutions

right_common for home,cimcor and cimtrak

get a quotevideoEvaluate

Join Us At These Upcoming Events:

Information Systems Security Association-Kentuckiana Chapter

 

September 3rd., 2010

Louisville, KY

www.issa-kentuckiana.org

 

Indiana Security and Privacy Network Technology Showcase

 

November 18th., 2010

Indianapolis, IN

www.inspn.org