Latest NERC CIP addresses control-system supply chain – Combined Cycle Journal

Latest NERC CIP addresses control-system supply chain

Just as plant owner/operators should “be prepared for an ever-changing cybersecurity attack surface, they should also plan to control their own destinies with respect to regulatory compliance,” noted a panel of experts during a webinar hosted by NAES Corporation titled “NERC CIP-003-9: What you need to know about the new requirements and how to comply.”

If you are one of the 72% of organizations who don’t have full visibility into their control-system supply chains, the 47% of organizations who don’t have the internal resources to manage operational technology (OT)/industrial cybersecurity (ICS) incidents, or the 75% of ICS networks successfully attacked by malicious external actors, don’t fret. NAES NERC/CIPS Services, and its partners, Network Perception and ABS Group, also scheduled two follow-on webinars which deep-crawl through the weeds of this latest compliance challenge.

For those of you whose plants are categorized as “low-impact” BES (bulk electricity system) assets and don’t think this latest standard affects you, think again. “NERC is coming for you,” these experts stressed.

One of the major implications of CIP-003-9 is that “plants should no longer rely on their control system OEMs for compliance or security [two different things].” “There are limits to risk transfer,” they say. Owner/operators, and other “responsible entities” (as referred to in NERC language), must now seek full supply-chain visibility.

Why? For one, a malicious actor can attack all users of a specific plant software (that is, many BES assets) by infiltrating the third-party vendor supplying or servicing that software. This looms large when you consider that the vast majority of combined-cycle control systems in America are sourced from only a few gas-turbine vendors and one or two control-system OEMs (along with the skids and subsystems with PLCs and other devices from a variety of vendors networked into the control system).

“You’d be surprised how frequently control system vendors traffic through their remote access points, and how unaware plant staff are,” observed one expert. Section 6.3 of the new standard, approved by FERC in March, requires one or more methods for detecting known or suspected in/outbound malicious communications through vendor electronic remote access points.

This means plants need comprehensive remote access solutions, and perhaps a full network model. “If two hosts haven’t communicated,” you can’t know whether they could have communicated or not.” A model helps you understand what could happen, not what did happen, these experts stressed.

perihoki perihoki perihoki perihoki perihoki duta76 duta76 duta76 duta76 duta76 bocoran petir scatter beruntun gates of olympus perihoki mantan admin perihoki ungkap trik modal kecil main starlight princess update seru pgsoft mahjong ways perihoki hadirkan fitur eksklusif rahasia spin santuy mahjong ways 2 perihoki jamin profit besar teknik combo maxwin mahjong wins 3 pakai scatter hitam di perihoki bongkar pola gampang menang gates of olympus di duta76 wild west gold maxwin menggiurkan di dunia koboi duta76 kesempatan emas duta76 mahjong ways pgsoft gacor malam ini trik duta76 paling mudah banjir scatter di pgsoft mahjong ways duta76 luncurkan buku panduan menang mahjong wins 3 Irama putaran memicu scatter lebih awal Memecahkan pola spin memicu kemenangan Mengatur spin jackpot lebih mudah tertangkap Pola berulang mengantar pemain menuju jutaan Spin tepat menuju cuan tanpa henti Hiburan jadi penghasilan berkat mahjong Permainan mahjong memudahkan scatter hitam turun Putaran pelan jalan turunnya scatter Putaran tepat sasaran amankan scatter Strategi tajam memancing scatter lebih cepat Awal spin mahjong dibanjiri scatter hitam Kecepatan dan irama menangkap scatter hitam Menang besar mahjong berawal dari scatter Momentum tepat menggandakan hasil Spin awal mengubah hari member baru Cara sukses mendapatkan multiplier maksimal mahjong ways Mengontrol permainan perkalian mahjong ways Pemain elite pola kemenangan mahjong ways Rahasia pola harian mahjong ways selalu profit Strategi spin perlahan mahjong ways mahjong ways 2 rtp gacor mahjong ways 2 profit maksimal mahjong ways cetak profit maksimal mahjong ways 2 warisan trik gacor mahjong ways 2 jackpot tercepat kisah inspiratif mahjong ways jackpot sweet bonanza mahjong ways gacor tanpa pola mahjong ways anti rungkat keuntungan vip mahjong ways pola scatter universal untuk semua mahjong spin simpel modal tipis scatter hitam waktu sakral spin scatter hitam auto jp modal receh full wild mahjong pola presisi spin otomatis rahasia menang beruntun gabungan pola aneh mahjong1 gampang jp abc1131 modal kecil maxwin berkali tukang ojek singkawang cuan mahjongways2 tempo teratur scatter hitam muncul sendiri budi andalkan rtp abc1131 jp besar pesta spin manual waktu main paling cuan wild auto nempel banjir kemenangan anda jackpot jalan bareng scatter rahasia cerdas permainan Setir tak bergerak jempol sopir angkot aktif di mahjong Teknik pintar membuka jalur pola rahasia
Scroll to Top