110 likes | 248 Views
MRO Cyber Security. May 31, 2007 Compliance Workshop. MRO CIP Working Group. Participants David Batz Alliant Energy Marc Child GRE Greg Frasor Manitoba Hydro James Phillips WAPA Active in CIP Work Identifying Resources for the Region. MRO CIP Contact. Clark Liu Alternate NERC CIPC
E N D
MRO Cyber Security May 31, 2007 Compliance Workshop
MRO CIP Working Group • Participants • David Batz Alliant Energy • Marc Child GRE • Greg Frasor Manitoba Hydro • James Phillips WAPA • Active in CIP Work • Identifying Resources for the Region
MRO CIP Contact • Clark Liu • Alternate NERC CIPC • Cyber Security • What but not How. • If it sounds like I’m saying “if you do this, you’ll be compliant.” I’m not even if I do say that. I cannot evaluate your efforts prior to an audit.
Content • Motivation towards AW for 2010 • Key Elements • Useful Links on the NERC Website • David Batz • Q&A with Dave and Marc Child
Motivation • Penalties • CIP002-009 AW by 2010, SC by 2008. • NERC Implementation Plan • Additional Work • Mitigation Plans • Timelines • Driving the number of Violations to 0.
Key Elements • Senior Management Support • Defend the work • Assures that cross departmental work is accepted. • Identifies key individuals that can be help accountable.
Key Elements • Understanding the Standards • Divide the requirements by department or function of your organization. • Assess your current state. • Determine what areas need clarification. Understand the language used in the Standard.
Key Elements • Gap Analysis • Identify the gaps. • Plan and coordinate efforts to be in compliance. • AW 2010 means C in 2009. • Policies/Procedures need to be in affect for 12 months.
Useful Links • http://www.nerc.com/~filez/standards/Reliability_Standards.html#Critical_Infrastructure_Protection - Implantation Plan • http://www.nerc.com/~filez/standards/Cyber-Security-Permanent.html - NERC CIP FAQ
Alliant Energy • Dave Batz, • Cyber Security Risk Manager • CISSP, GSEC, GSNA • Alliant Energy Security & Facility Services
Questions • David Batz (CISSP, GSEC, GSNA) and Marc Child (CISSP)