Earlier this month, as the coronavirus accelerated its alarming sprint across North America, NERC requested that FERC defer a number of looming deadlines for Reliability Standards. For the cybersecurity-related standards (CIP-005-6, CIP-010-3, and CIP-013-1), NERC requested a 3-month delay to “help ensure grid reliability amid the impacts posed by the coronavirus outbreak, a public health emergency that is unprecedented in modern times.”
It certainly sounds like a sensible proposal, and last Friday FERC granted the request, stating it was “... reasonable to provide them additional flexibility to properly allocate resources to address the impacts of COVID-19.” The “them” in this case are the utilities involved in the operation of our electric power grid.
We have a particular interest in the CIP-013-1 standard that focuses on supply chain risk management. It’s kind of our bread and butter here at aDolus. In fact, we delivered a training session to a great group at the last NERC CIPC meeting in early March on how to use our FACT platform to help with CIP-013 compliance without introducing onerous internal processes. (Back in the day, when people could actually sit within 6 feet of each other.)
While the need for these standards is overwhelming, I think we can all agree that the current COVID-19 emergency is an unprecedented, added strain on the operators of the electric grid. In their joint news release, FERC and NERC note the goal of helping utilities to “...focus their resources on keeping people safe and the lights on during this unprecedented public health emergency” and they specifically recognize the need to “focus on keeping their own people safe.”
I can only imagine the additional steps and processes each utility is having to develop and implement — practically overnight. Keeping their workforce adequately distanced and protected, disinfecting control equipment, vehicles, and entire substations… the list goes on. The necessary precautions will take immense planning and effort. These aren’t the kinds of jobs you can do from home and keeping this particular workforce safe, healthy, and focused is critical.
We can wait a few months to comply with the upcoming CIP standards.
Here’s a list of the cybersecurity-specific standards that have been delayed (courtesy of John Hoffman at NERC):
CIP-005-6 – Cyber Security – Electronic Security Perimeter(s) | delayed to October 1, 2020 |
CIP-010-3 – Cyber Security – Configuration Change Management and Vulnerability Assessments | delayed to October 1, 2020 |
CIP-013-1 – Cyber Security – Supply Chain Risk Management | delayed to October 1, 2020 |
You can read the full order here.
Stay safe and wash your hands!
Eric Byres
Eric is widely recognized as one of the world’s leading experts in the field of OT, IT and IoT software supply chain security. He is the inventor of the Tofino Security technology – the most widely deployed OT-specific firewall in the world. When not setting the product vision, or speaking at a conference, Eric can be found cranking away on his gravel bike.
Stay up to date
Browse Posts
- May 2024
- February 2024
- December 2023
- October 2023
- April 2023
- March 2023
- February 2023
- October 2022
- April 2022
- February 2022
- December 2021
- November 2021
- August 2021
- July 2021
- June 2021
- May 2021
- February 2021
- January 2021
- December 2020
- September 2020
- August 2020
- July 2020
- May 2020
- April 2020
- January 2020
- October 2019
- September 2019
- November 2018
- September 2018
- May 2018
Browse by topics
- Supply Chain Management (16)
- SBOM (15)
- Vulnerability Tracking (15)
- #supplychainsecurity (10)
- Regulatory Requirements (10)
- VEX (8)
- EO14028 (6)
- ICS/IoT Upgrade Management (6)
- malware (6)
- ICS (5)
- vulnerability disclosure (5)
- 3rd Party Components (4)
- Partnership (4)
- Press-release (4)
- #S4 (3)
- Software Validation (3)
- hacking (3)
- industrial control system (3)
- Code Signing (2)
- Legislation (2)
- chain of trust (2)
- #nvbc2020 (1)
- DoD CMMC (1)
- Dragonfly (1)
- Havex (1)
- Log4Shell (1)
- Log4j (1)
- Trojan (1)
- USB (1)
- Uncategorized (1)
- energy (1)
- medical (1)
- password strength (1)
- pharmaceutical (1)
Post a comment