70 likes | 92 Views
Learn about the differences between standards 1200 and 1300, identifying critical cyber assets, addressing personnel issues, and implementation plan considerations. Get prepared for 1st Quarter 2005 compliance. Contact Larry Bugh for more information.
E N D
WebCast on DraftCyber Security Standard 1300October 18, 2004
Standard 1300 • 1200 vs. 1300 • Identifying Critical Cyber Assets • Addressing Personnel Issues • Implementation Plan Issues Standard 1300 Webcast
1200 vs. 1300 • Two separate standards • 1st Qtr 2005 compliance to 1200 • 1300 uses 1200 as a starting point • 1300 intended to “raise the bar” Standard 1300 Webcast
Identifying Critical Cyber Assets • Multi-step process (use risk-based analysis) • Identify critical bulk electric facilities • Identify cyber assets at those facilities • Identify critical cyber assets • Not all bulk electric facilities are affected Standard 1300 Webcast
Addressing Personnel Issues • What are the issues? • Disclosure of screening results • What to do about/with screening results • Did we go too far? • Used UA 1200, comments to 1200 renewal ballot, 1300 SAR, and Blackout Report as references. • Tried to clarify 1200. Standard 1300 Webcast
Implementation Plan Issues • Drafting Team recognizes impact of scope change • Implementation plan will phase in new requirements (need input on realistic time-frames) Standard 1300 Webcast
Questions??? Contact info: Larry Bugh – ECAR 330.580.8017 larryb@ecar.org http://www.nerc.com/ Standard 1300 Webcast