ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI

Size: px
Start display at page:

Download "ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI"

Transcription

1 ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI Matt Mereness, ERCOT Compliance Director August 2015 Anfield Summit

2 Outline of discussion ERCOT Background Business Case for Internal Controls Building a Controls Program Assessing Controls Preparing for Recent Audit 2015 Audit Experience Broader GRC Implementation and Benefits 2 2

3 ERCOT BACKGROUND 3

4 ERCOT Background- Reliability Regions Electric Reliability Council of Texas the ERCOT grid: Covers 75% of Texas land Serves 85% of Texas load More than 40,500 miles of transmission lines 550+ generation units (more than 84,000 MW of capacity) Physical assets are owned by transmission providers and generators, including Municipal Utilities and Cooperatives ERCOT connections to other grids are limited to direct current (DC) ties (~1100 MW with SPP and Mexico) Peak Load was set on August 3, 2011 at 68,305 MW (today) 4

5 5 ERCOT Background Key Features of ERCOT Electrical island with several DC Ties Deregulated Market in 2000, Nodal 2010 Non-Profit System Operator funded by state Dispatches real-time energy market every 5 minutes Executes energy markets and settlement Facilitates retail switching 5

6 ERCOT Background - NERC Audit experiences Registered as BA, PC, RC, RP, TOP, TSP 2008 Compliance Violation Investigation Annual 693 Audit 2009 Annual 693 Audit 2009 CIP Spot Check 2010 Annual 693 Audit 2010 Annual CIP Audit 2011 FERC, NERC and Texas RE Investigation (Cold Weather) 2011 Three 693 Spot Checks (Laredo 2008, Valley 2011, 693 Clean-up) Spot Check (Cold Weather) 2012 Annual 693 Audit 2013 Annual CIP Audit 2015 Audit underway (note not 693 or CIP) 6

7 BUSINESS CASE FOR INTERNAL CONTROLS 7

8 Internal Reasons for Change Scope and Lessons Learned Historically ERCOT managed a relatively large number of controls using manual processes to maintain alignment with changing NERC requirements. For audits, managing people and evidence was challenging across departments Multiple department silos of responsibility/processes in meeting a requirement Organizing and reviewing evidence/rsaw responses is tedious and manually intensive ( s, sharepoint, meetings) Lack of centralization can create gaps and overlaps in data collection Often the quality of the audit is only as organized as the person responsible for assessing the requirements. Audits historically are an all-hands-on-deck exercise ERCOT committed to improving this manual and repeatable process 8

9 External Reasons for Change -Transitioning NERC Audit Approach Reliability Assurance Initiative (RAI) A national effort between the NERC, the Regional Entities, and registered entities to implement changes that enhance the effectiveness of the Compliance Monitoring and Enforcement Program (CMEP). o It is an effort to retool and refocus compliance and enforcement o RAI processes will focus on risk to grid reliability in developing scope of audit o RAI is a customized compliance approach with individualized scoping for each registered entity o To NERC not all requirements are created equally when it comes to audit scope & monitoring. o Risk factor for NERC Requirement (Risk factor in standard) o o o National risk focus (published CMEP plan) Regional risk focus (appendix of CMEP plan) Historical findings (consider ERCOT RFIs, audit scope, self-reports) 9

10 NERC Audit Changes Uncertainty of Internal Controls Evaluation (ICE) process 10

11 NERC Audit Changes 11

12 BUILDING CONTROLS PROGRAM 12

13 Internal Controls Controls building blocks 1. Define categories of internal controls Preventative, Detective, Corrective 2. Define & document internal controls with SMEs Procedures, Logs, Alarms 3. Define & document process flows and responsible parties Tabletop walk-throughs for complicated processes (across silos) 4. Map the controls to requirements Many requirements - relate - to - many controls 5. Develop test sequences Agree to process to observe control and see evidence of compliance 6. Optional- Automation and tracking for collection of evidence Implement system with built in business process flows and collection 13

14 Example of Internal Control (manual paperwork process) 14

15 Internal Controls Internal Controls in AlertEnterprise system q Centralized record of NERC requirements in effect at a point in time q Inventory of controls for requirements q Mapping of requirements to controls q Programmable business process flows for running assessments and evidence 15

16 Implementation Alert Roadmap 2Q2014 3Q2014 4Q2014 1Q2015 Initial NERC 693 & Protocols for System Operations and Planning Effort 6 week mapping effort for each business unit Quality check Close gaps Complete NERC self-certification Maintain update standards/protocols Maintain with changes to requirements NERC CIP Requirements Develop CIP v5 16

17 Compliance system- Requirement screenshot 17

18 Compliance Requirement mapped to multiple Internal Controls 18

19 ASSESSING CONTROLS 19

20 Internal Controls Assessments ERCOT performs periodic assessments to verify controls are effective. Assessments are performed based on risk ERCOT evaluates changes to requirements to ensure processes and controls are consistent with the changes. ERCOT s goal is to assess all NERC related controls at least once per year. 20

21 Control Assessment Life Cycle Compliance Initiates changes and execution of assessments. Business Analyst(s) Reviews assessment questions and gathers evidence. Business Owner/Manager Reviews and approves assessment and evidence. Effective with Date Compliance Final review, update in system as completed and effective. 21

22 Example- Control Assessment The screenshots below provide assessment details including the start date and the overall status and example of test questions to help determine if control is effective. Control/procedure is verified, evidence attached, and passed 22

23 Example of Assessment of Control to Multiple Requirements By testing this RUC procedure, you can assess/pass 3 requirements 23

24 PREPARING FOR RECENT AUDIT 24

25 Compliance Risk Methodology and Results Reqt Risk Factor NERC CMEP Audit History 4 Risk Levels Critical High Med Low Self- Report 25

26 Risk Methodology and Results ERCOT Compliance Risks Subset of NERC Requirements Subset of ERCOT Controls Controls inventory to prioritize and assess 26

27 Critical Requirement (Focus on Risks) 27

28 Reports of Critical Requirements and Controls 28

29 2015 AUDIT EXPERIENCE 29

30 NERC changes in auditing ERCOT 2015 Audit Scope 1200 Requirements à IRA 26 requirements à ICE 20 requirements Auditors will be onsite Sep

31 Audit timeline and details January RE advised ERCOT of being scheduled for Sept audit engagement. May 2015 RE advised ERCOT that IRA was complete and invited to engage in ICE. No interaction between ERCOT and RE during IRA evaluation Audit scope was unknown at this point, but told it would be focused ERCOT accepts voluntary ICE invitation May 2015 ERCOT received ICE notice. ICE scope for 26 requirements supporting 2 risk themes (represented the current scope of the forthcoming audit) 2 week deadline to respond with controls (provided powerpoint overview of controls program, applicable procedures/controls for each requirement, and listing of dates controls last assessed) June 2015 ERCOT received formal audit notice for 20 requirements Output (benefit) of ICE was that 6 of 26 requirements were removed from scope of audit. 40 days deadline to complete and file RSAWs and evidence for 20 requirements RSAWs filed and waiting for questions leading into the Sept tabletop and onsite audit activities. 31

32 Specific to TexasRE ICE Controls for ICE ERCOT submitted the inventory of key controls mapped to requirements. Assessments for ICE In its submission package ERCOT included a summary of the assessment history for the related controls. Overview of Internal Controls at ERCOT GRC System, terminology, goals 32

33 In summary Alert captured; - Narrative for how Reqt is met - Point-in-Time History of Requirement & Assessments - Links Requirement to Controls (Procedures, Software screens, etc) - Links to Owner(s) - Links to Evidence 33

34 BROADER GRC IMPLEMENTATION AND BENEFITS 34

35 Benefits of Alert Leveraging the tool to work for company Electronic/Query-able System of record Traceability for requirements, ownership in a database that can be queried Change control Provides quick summary of related/impacted changes- ripple effect 3 areas of change: Requirements, Staff, Controls/Procedures Auto-scheduling Calendar tripwires - Systemic reminders of Annual filings, certification, or authority sign-off Business owner configures frequency How often to be assessed for certain controls (accountability) 35

36 Benefits of Alert Management reports Aging reports (when was this requirement last changed or assessed) Status of annual assessment progress Risk levels Flag a requirement as high risk can map to and identify critical controls Helped ERCOT prepare for 2015 audit (assess 20% instead of 100% controls) NERC CIP v5 readiness path Assessment completion creates CIPv5 RSAW and evidence finish line 36

37 High Level Compliance Implementation (larger GRC) ICMP Support/SSAE16 Management of corp controls and changes to policies NERC 693 Support Processes/Dependencies/ CFR/ Changes INCREASING ERCOT Compliance Alert Scope of Requirements 800 SSAE/ICMP NERC CIP Support 1,200 NERC Processes/software/ 3,000 Protocols education (Cyber, Sec, IT) Protocol Must/Shall/Will Support Numerous new departments to interface with Audit Preparation SSAE, NERC, Protocol Range of methods Note- One effective access procedure/control may satisfy multiple reqts/frameworks 37

38 Extending it into different business areas Different Compliance Monitoring methods- SSAE60/CorpControls Attestation survey-only approach Alert-routed surveys with questions to execs where they confirm they are compliant Solicits changes and confirmation of compliance Quick execution/attestation Protocols Mapping/Traceability controls mapping approach Traceability/ownership/change management Connect words on rules to owner, narrative how they satisfy part of all, provide link to control NERC mapping and verification controls mapping with evidence approach Full traceability with testing, collecting evidence, and reviewing quality of results. 38

39 THANK YOU! 39

Audit-Ready SharePoint Applications

Audit-Ready SharePoint Applications Audit-Ready SharePoint Applications Page 1 of 16 July 7, 2015 Table of Contents 1 Overview... 3 2 Company Background... 4 3 Audit-Ready SharePoint Applications... 4 3.1 Audit-Ready Compliance Dashboard...

More information

The Electric Reliability Council of Texas (ERCOT) manages the flow of electric power to approximately 22 million Texas customers representing 85

The Electric Reliability Council of Texas (ERCOT) manages the flow of electric power to approximately 22 million Texas customers representing 85 The Electric Reliability Council of Texas (ERCOT) manages the flow of electric power to approximately 22 million Texas customers representing 85 percent of the state s electric load and 75 percent of the

More information

North American Electric Reliability Corporation: Critical Infrastructure Protection, Version 5 (NERC-CIP V5)

North American Electric Reliability Corporation: Critical Infrastructure Protection, Version 5 (NERC-CIP V5) Whitepaper North American Electric Reliability Corporation: Critical Infrastructure Protection, Version 5 (NERC-CIP V5) NERC-CIP Overview The North American Electric Reliability Corporation (NERC) is a

More information

2016 Business Plan and Budget. Texas Reliability Entity, Inc. Approved by Texas RE Board of Directors. Date: May 21, 2015

2016 Business Plan and Budget. Texas Reliability Entity, Inc. Approved by Texas RE Board of Directors. Date: May 21, 2015 2016 Business Plan and Texas Reliability Entity, Inc. Approved by Texas RE Board of Directors Date: May 21, 2015 1 Table of Contents Table of Contents... 2 Introduction... 3 Section A 2016 Business Plan

More information

Program Guide for Risk-based Compliance Monitoring and Enforcement Program. ERA-01 Rev. 1. NPCC Manager, Entity Risk Assessment

Program Guide for Risk-based Compliance Monitoring and Enforcement Program. ERA-01 Rev. 1. NPCC Manager, Entity Risk Assessment NPCC Entity Risk Assessment Program Guide for Risk-based Compliance Monitoring and Enforcement Program ERA-01 Rev. 1 Process Owner: NPCC Manager, Entity Risk Assessment Effective Date: 03/02/2015 Table

More information

Attached are the Board materials in relation to these agenda items. Item 4.3 1 ERCOT Public

Attached are the Board materials in relation to these agenda items. Item 4.3 1 ERCOT Public The Human Resources & Governance (HR&G) Committee is expected to consider HR&G Committee Agenda Item 4.3: Recommendation regarding Proposed 2016 ERCOT Key Performance Indicators (s) at its meeting on December

More information

CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments

CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:

More information

NERC CIP Implementation Prepared by David Grubbs City of Garland NERC Critical Infrastructure Protection Committee (CIPC) Municipal Systems are well represented on the NERC CIPC Committee David Grubbs,

More information

Standard CIP 007 3a Cyber Security Systems Security Management

Standard CIP 007 3a Cyber Security Systems Security Management A. Introduction 1. Title: Cyber Security Systems Security Management 2. Number: CIP-007-3a 3. Purpose: Standard CIP-007-3 requires Responsible Entities to define methods, processes, and procedures for

More information

Item 8.1: Third Quarter 2013KPIs Update

Item 8.1: Third Quarter 2013KPIs Update Item 8.1: Third Quarter 2013KPIs Update Paula Feuerbacher Strategic Projects Senior Advisor Human Resources and Governance Committee ERCOT Public November 18, 2013 2013 3rd Quarter Reporting Period YTD

More information

Summary of CIP Version 5 Standards

Summary of CIP Version 5 Standards Summary of CIP Version 5 Standards In Version 5 of the Critical Infrastructure Protection ( CIP ) Reliability Standards ( CIP Version 5 Standards ), the existing versions of CIP-002 through CIP-009 have

More information

Transmission Function Employees Job Titles and Descriptions 18 C.F.R 358.7(f)(1)

Transmission Function Employees Job Titles and Descriptions 18 C.F.R 358.7(f)(1) Date of Last Change to the Provided Information August 27 th, 2015 Director, Transmission Operations The employee in this position is responsible for effectively managing the operation of FirstEnergy Utilities

More information

Plans for CIP Compliance

Plans for CIP Compliance Testing Procedures & Recovery Plans for CIP Compliance DECEMBER 16, 2009 Developed with: Presenters Bart Thielbar, CISA Senior Research hanalyst Sierra Energy Group, a Division of Energy Central Primer

More information

Automating NERC CIP Compliance for EMS. Walter Sikora 2010 EMS Users Conference

Automating NERC CIP Compliance for EMS. Walter Sikora 2010 EMS Users Conference Automating NERC CIP Compliance for EMS Walter Sikora 2010 EMS Users Conference What do we fear? Thieves / Extortionists Enemies/Terrorists Stuxnet Malware Hacker 2025 Accidents / Mistakes 9/21/2010 # 2

More information

Entity Name ( Acronym) NCRnnnnn Risk Assessment Questionnaire

Entity Name ( Acronym) NCRnnnnn Risk Assessment Questionnaire Entity Name ( Acronym) NCRnnnnn Risk Assessment Questionnaire Upcoming Audit Date: March 16, 2015 Upcoming Audit Type: O&P Audit Start of Audit Period: March 16, 2012 Date Submitted: Table of Contents

More information

NERC Cyber Security. Compliance Consulting. Services. HCL Governance, Risk & Compliance Practice

NERC Cyber Security. Compliance Consulting. Services. HCL Governance, Risk & Compliance Practice NERC Cyber Security Compliance Consulting Services HCL Governance, Risk & Compliance Practice Overview The North American Electric Reliability Corporation (NERC) is a nonprofit corporation designed to

More information

How To Manage The Ercot Grid

How To Manage The Ercot Grid US MEXICO Cross-border trade Joel Mickey Director, Market Design & Development NARUC Summer Meeting Dallas, Texas North American ISOs and RTOs Independent System Operators and Regional Transmission Organizations

More information

CIP-003-5 Cyber Security Security Management Controls

CIP-003-5 Cyber Security Security Management Controls A. Introduction 1. Title: Cyber Security Security Management Controls 2. Number: CIP-003-5 3. Purpose: To specify consistent and sustainable security management controls that establish responsibility and

More information

ReliabilityFirst CIP Evidence List CIP-002 through CIP-009 are applicable to RC, BA, IA, TSP, TO, TOP, GO, GOP, LSE, NERC, & RE

ReliabilityFirst CIP Evidence List CIP-002 through CIP-009 are applicable to RC, BA, IA, TSP, TO, TOP, GO, GOP, LSE, NERC, & RE R1 Provide Risk Based Assessment Methodology (RBAM) R1.1 Provide evidence that the RBAM includes both procedures and evaluation criteria, and that the evaluation criteria are riskbased R1.2 Provide evidence

More information

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard Information Systems Audit and Controls Association Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard February 4, 2014 Tom Haberman, Principal, Deloitte & Touche LLP Reema Singh,

More information

Change and Configuration Management

Change and Configuration Management Change and Configuration Management for CIP Compliance OCTOBER 21, 2009 Developed with: Presenters Bart Thielbar, CISA Senior Research hanalyst Sierra Energy Group, a Division of Energy Central CIP-003,

More information

Compliance Open Webinar. Thursday, August 20th, 2015

Compliance Open Webinar. Thursday, August 20th, 2015 Compliance Open Webinar Thursday, August 20th, 2015 2 Upcoming Events CIP Advanced Concepts September 9-10, 2015 Compliance Open Webinar September 17, 2015 WECC CIPUG/CUG October 13-15, 2015 Compliance

More information

CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments

CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:

More information

Optimizing Wind Generation in ERCOT Nodal Market Resmi Surendran ERCOT Chien-Ning Yu ABB/Ventyx Hailong Hui ERCOT

Optimizing Wind Generation in ERCOT Nodal Market Resmi Surendran ERCOT Chien-Ning Yu ABB/Ventyx Hailong Hui ERCOT Optimizing Wind Generation in ERCOT Nodal Market Resmi Surendran ERCOT Chien-Ning Yu ABB/Ventyx Hailong Hui ERCOT FERC Conference on Increasing Real-Time and Day-Ahead Market Efficiency through Improved

More information

North American Electric Reliability Corporation. Compliance Monitoring and Enforcement Program. December 19, 2008

North American Electric Reliability Corporation. Compliance Monitoring and Enforcement Program. December 19, 2008 116-390 Village Boulevard Princeton, New Jersey 08540-5721 North American Electric Reliability Corporation Compliance Monitoring and Enforcement Program December 19, 2008 APPENDIX 4C TO THE RULES OF PROCEDURE

More information

NERC CIP Compliance 10/11/2011

NERC CIP Compliance 10/11/2011 NERC CIP Compliance 10/11/2011 Authored by Dan Barker, American Transmission Co. Ron Bender, Nebraska Public Power District Richard Burt, Minnkota Power Cooperative, Inc. Marc Child, Great River Energy

More information

Technology Solutions for NERC CIP Compliance June 25, 2015

Technology Solutions for NERC CIP Compliance June 25, 2015 Technology Solutions for NERC CIP Compliance June 25, 2015 2 Encari s Focus is providing NERC CIP Compliance Products and Services for Generation and Transmission Utilities, Municipalities and Cooperatives

More information

Standard CIP 007 3 Cyber Security Systems Security Management

Standard CIP 007 3 Cyber Security Systems Security Management A. Introduction 1. Title: Cyber Security Systems Security Management 2. Number: CIP-007-3 3. Purpose: Standard CIP-007-3 requires Responsible Entities to define methods, processes, and procedures for securing

More information

Service Restoration Priorities Plan - PUC Workshop. Kent Saathoff Vice President of Grid Operations and System Planning

Service Restoration Priorities Plan - PUC Workshop. Kent Saathoff Vice President of Grid Operations and System Planning TDU Curtailment Procedures and Service Restoration Priorities Plan - PUC Workshop Kent Saathoff Vice President of Grid Operations and System Planning November 3, 2011 February 2, 2011 Load Shed Event ERCOT

More information

CIP v5/v6 Implementation Plan CIP v5 Workshop. Tony Purgar October 2-3, 2014

CIP v5/v6 Implementation Plan CIP v5 Workshop. Tony Purgar October 2-3, 2014 CIP v5/v6 Implementation Plan CIP v5 Workshop Tony Purgar October 2-3, 2014 Revision History CIP v5/v6 Implementation Plan Change History Date Description Initial Release July 25, 2014 Revision V0.1 August-2014

More information

Transmission Planning in the ERCOT Interconnection

Transmission Planning in the ERCOT Interconnection Transmission Planning in the ERCOT Interconnection Warren Lasher Manager, Long-Term Planning and Policy Department of Energy Electricity Advisory Committee The ERCOT Interconnection The ERCOT Region is

More information

Semi-Annual Audit, Compliance, and Enterprise Risk Management Update

Semi-Annual Audit, Compliance, and Enterprise Risk Management Update Semi-Annual Audit, Compliance, and Enterprise Risk Management Update Steve Byone Chief Financial Officer February 20 th, 2007 Audit Update February 20 th, 2007 Page 2 2 Audit Update February 2007 ERCOT

More information

3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities.

3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities. A. Introduction 1. Title: Event Reporting 2. Number: EOP-004-2 3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities. 4. Applicability:

More information

Cyber Security Standards Update: Version 5

Cyber Security Standards Update: Version 5 Cyber Security Standards Update: Version 5 January 17, 2013 Scott Mix, CISSP CIP Technical Manager Agenda Version 5 Impact Levels Format Features 2 RELIABILITY ACCOUNTABILITY CIP Standards Version 5 CIP

More information

A. Introduction. B. Requirements. Standard PER-005-1 System Personnel Training

A. Introduction. B. Requirements. Standard PER-005-1 System Personnel Training A. Introduction 1. Title: System Personnel Training 2. Number: PER-005-1 3. Purpose: To ensure that System Operators performing real-time, reliability-related tasks on the North American Bulk Electric

More information

North American Electric Reliability Corporation (NERC) Cyber Security Standard

North American Electric Reliability Corporation (NERC) Cyber Security Standard North American Electric Reliability Corporation (NERC) Cyber Security Standard Symantec Managed Security Services Support for CIP Compliance Overviewview The North American Electric Reliability Corporation

More information

NERC Audit Definition

NERC Audit Definition Utilities & Energy Compliance & Ethics Conference NERC Audit Definition An engagement that provides assurance or conclusions on an evaluation of sufficient, appropriate evidence against stated criteria,

More information

ConnectivityWeek 2010

ConnectivityWeek 2010 SmartMeterTexas.com Access to the Smart Grid for all of Texas CenterPoint Energy Robert B. Frazier Director of Technology Houston Electric 1 WHO IS CENTERPOINT ENERGY? Public company traded on the New

More information

Voluntary Cybersecurity Initiatives in Critical Infrastructure. Nadya Bartol, CISSP, SGEIT, nadya.bartol@utc.org. 2014 Utilities Telecom Council

Voluntary Cybersecurity Initiatives in Critical Infrastructure. Nadya Bartol, CISSP, SGEIT, nadya.bartol@utc.org. 2014 Utilities Telecom Council Voluntary Cybersecurity Initiatives in Critical Infrastructure Nadya Bartol, CISSP, SGEIT, nadya.bartol@utc.org 2014 Utilities Telecom Council Utility cybersecurity environment is full of collaborations

More information

Keshav Sarin CIP Enforcement Analyst. BURP (Best User Reporting Practices) February 11, 2011 Marina del Rey, California

Keshav Sarin CIP Enforcement Analyst. BURP (Best User Reporting Practices) February 11, 2011 Marina del Rey, California Keshav Sarin CIP Enforcement Analyst BURP (Best User Reporting Practices) February 11, 2011 Marina del Rey, California Quiz How to review CIP items in the most effective manner? o Get the necessary information

More information

Role of CIM for Power System Model Exchange - ISO/RTO Exchanges with TOs

Role of CIM for Power System Model Exchange - ISO/RTO Exchanges with TOs Role of CIM for Power System Model Exchange - ISO/RTO Exchanges with TOs David Bogen Manager Transmission and Distribution Services Oncor Electric Delivery Presented By Margaret Goodrich, SISCO Practical

More information

Top Ten Compliance Issues for Implementing the NERC CIP Reliability Standard

Top Ten Compliance Issues for Implementing the NERC CIP Reliability Standard Top Ten Compliance Issues for Implementing the NERC CIP Reliability Standard The North American Electric Reliability Corporation 1 s (NERC) CIP Reliability Standard is the most comprehensive and pervasive

More information

CIP-003-6 R2 BES Assets Containing Low Impact BCS. Lisa Wood, CISA, CBRA, CBRM Compliance Auditor Cyber Security

CIP-003-6 R2 BES Assets Containing Low Impact BCS. Lisa Wood, CISA, CBRA, CBRM Compliance Auditor Cyber Security CIP-003-6 R2 BES Assets Containing Low Impact BCS Lisa Wood, CISA, CBRA, CBRM Compliance Auditor Cyber Security Slide 2 About Me Been with WECC for 5 years 1 ½ years as a Compliance Program Coordinator

More information

Secure Remote Substation Access Interest Group Part 3: Review of Top Challenges, CIPv5 mapping, and looking forward to 2014!

Secure Remote Substation Access Interest Group Part 3: Review of Top Challenges, CIPv5 mapping, and looking forward to 2014! Secure Remote Substation Access Interest Group Part 3: Review of Top Challenges, CIPv5 mapping, and looking forward to 2014! October 3, 2013 Scott Sternfeld, Project Manager Smart Grid Substation & Cyber

More information

Job Descriptions. Job Title Reports To Job Description TRANSMISSION SERVICES Manager, Transmission Services. VP Compliance & Standards

Job Descriptions. Job Title Reports To Job Description TRANSMISSION SERVICES Manager, Transmission Services. VP Compliance & Standards Updated July 11, 2013 Job Descriptions Job Title Reports To Job Description TRANSMISSION SERVICES VP Compliance & Standards Develops strategy and business plans for efficient, safe, reliable, regulatorycompliant

More information

September 29, 2014. Docket No. ER14- -000 Amendment to CAISO FERC Electric Tariff to Eliminate Annual External Operations Review

September 29, 2014. Docket No. ER14- -000 Amendment to CAISO FERC Electric Tariff to Eliminate Annual External Operations Review California Independent System Operator Corporation September 29, 2014 The Honorable Kimberly D. Bose Secretary Federal Energy Regulatory Commission 888 First Street, NE Washington, DC 20426 Re: California

More information

Tyson Jarrett CIP Enforcement Analyst. Best Practices for Security Patch Management October 24, 2013 Anaheim, CA

Tyson Jarrett CIP Enforcement Analyst. Best Practices for Security Patch Management October 24, 2013 Anaheim, CA Tyson Jarrett CIP Enforcement Analyst Best Practices for Security Patch Management October 24, 2013 Anaheim, CA A little about me Graduated from the University of Utah with a Masters in Information Systems

More information

TECHNOLOGY SOLUTIONS FOR THE INTERNAL AUDITOR

TECHNOLOGY SOLUTIONS FOR THE INTERNAL AUDITOR TECHNOLOGY SOLUTIONS FOR THE INTERNAL AUDITOR (BUY VS BUILD) APRIL 17, 2015 LEVERAGING TECHNOLOGY FOR AUDIT Utilizing Software to Administrate Audit Process 40% 35% 30% 37% Tools Leveraged 32% 36% Yes

More information

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions June 4, 2015. Electric Grid Operations

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions June 4, 2015. Electric Grid Operations San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions June 4, 2015 Electric Grid Operations Director Electric Grid Operations: Responsible for overall transmission

More information

NERC-CIP S MOST WANTED

NERC-CIP S MOST WANTED WHITE PAPER NERC-CIP S MOST WANTED The Top Three Most Violated NERC-CIP Standards What you need to know to stay off the list. www.alertenterprise.com NERC-CIP s Most Wanted AlertEnterprise, Inc. White

More information

ASSET Connect. The next level in Critical Environment Operational Efficiency

ASSET Connect. The next level in Critical Environment Operational Efficiency Connect The next level in Critical Environment Operational Efficiency 10-30% is the potential efficiency gain from optimized Data Centers and Critical Environments Operational Efficiency of Your Critical

More information

Standard CIP 004 3a Cyber Security Personnel and Training

Standard CIP 004 3a Cyber Security Personnel and Training A. Introduction 1. Title: Cyber Security Personnel & Training 2. Number: CIP-004-3a 3. Purpose: Standard CIP-004-3 requires that personnel having authorized cyber or authorized unescorted physical access

More information

NERC Cyber Security Standards

NERC Cyber Security Standards SANS January, 2008 Stan Johnson Manager of Situation Awareness and Infrastructure Security Stan.johnson@NERC.net 609-452-8060 Agenda History and Status of Applicable Entities Definitions High Level of

More information

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions August 10, 2015. Electric Grid Operations

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions August 10, 2015. Electric Grid Operations San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions August 10, 2015 Electric Grid Operations Director Electric Grid Operations: Responsible for overall transmission

More information

Top 10 Compliance Issues for Implementing Security Programs

Top 10 Compliance Issues for Implementing Security Programs www.dyonyx.com Top 10 Compliance Issues for Implementing Security Programs This White Paper articulates the top ten issues that we have encountered in the design and implementation of comprehensive Security

More information

The Firewall Audit Checklist Six Best Practices for Simplifying Firewall Compliance and Risk Mitigation

The Firewall Audit Checklist Six Best Practices for Simplifying Firewall Compliance and Risk Mitigation The Firewall Audit Checklist Six Best Practices for Simplifying Firewall Compliance and Risk Mitigation Copyright, AlgoSec Inc. All rights reserved The Need to Ensure Continuous Compliance Regulations

More information

IRA Risk Factors Update for CIP. Ben Christensen Senior Compliance Risk Analyst, Cyber Security October 14, 2015

IRA Risk Factors Update for CIP. Ben Christensen Senior Compliance Risk Analyst, Cyber Security October 14, 2015 IRA Risk Factors Update for CIP Ben Christensen Senior Compliance Risk Analyst, Cyber Security October 14, 2015 2 Agenda Why the changes? What s new? Example of a Risk Factor How does this effect CIP V5?

More information

Regulatory Compliance Management for Energy and Utilities

Regulatory Compliance Management for Energy and Utilities Regulatory Compliance Management for Energy and Utilities The Energy and Utility (E&U) sector is transforming as enterprises are looking for ways to replace aging infrastructure and create clean, sustainable

More information

Lessons Learned CIP Reliability Standards

Lessons Learned CIP Reliability Standards Evidence for a requirement was not usable due to a lack of identifying information on the document. An entity should set and enforce a "quality of evidence" standard for its compliance documentation. A

More information

Item 3: ERCOT Strategic Goals

Item 3: ERCOT Strategic Goals : ERCOT Strategic Goals Betty Day Vice President, Governance Risk & Compliance Human Resources and Governance Committee ERCOT Public October 12, 2015 Update on 2015 Strategic Goals ERCOT Public 2 Operational

More information

Security Solutions to Meet NERC-CIP Requirements. Kevin Staggs, Honeywell Process Solutions

Security Solutions to Meet NERC-CIP Requirements. Kevin Staggs, Honeywell Process Solutions Kevin Staggs, Honeywell Process Solutions Table of Contents Introduction...3 Nerc Standards and Implications...3 How to Meet the New Requirements...4 Protecting Your System...4 Cyber Security...5 A Sample

More information

GRADUATE RELIABILITY TRAINING PROGRAM. Initiation Date: September 2012

GRADUATE RELIABILITY TRAINING PROGRAM. Initiation Date: September 2012 GRADUATE RELIABILITY TRAINING PROGRAM Initiation Date: September 2012 Board Approved Date: May 2012 GRADUATE RELIABILITY TRAINING PROGRAM Program Description This program is intended for recent college

More information

NIST Cybersecurity Framework What It Means for Energy Companies

NIST Cybersecurity Framework What It Means for Energy Companies Daniel E. Frank J.J. Herbert Mark Thibodeaux NIST Cybersecurity Framework What It Means for Energy Companies November 14, 2013 Your Panelists Dan Frank J.J. Herbert Mark Thibodeaux 2 Overview The Cyber

More information

LSE Registration ERCOT Region. By Derrick Davis Texas RE Corporate Counsel

LSE Registration ERCOT Region. By Derrick Davis Texas RE Corporate Counsel LSE Registration ERCOT Region By Derrick Davis Texas RE Corporate Counsel Presentation Objectives Provide the history of LSE registration and appeals Direct Energy DOE Portsmouth NERC s request for re-hearing

More information

SecureVue Product Brochure

SecureVue Product Brochure SecureVue unifies next-generation SIEM, security configuration auditing, compliance automation and contextual forensic analysis into a single platform, delivering situational awareness, operational efficiency

More information

Updated November 20, 2015. Director, System Planning

Updated November 20, 2015. Director, System Planning Updated November 20, 2015 Job Descriptions Job Title Reports To Job Description SYSTEM PLANNING & SERVICES VP Compliance Manages the system planning and services staff. The director is responsible for

More information

Utility-Scale Applications of Microgrids: Moving Beyond Pilots Cyber Security

Utility-Scale Applications of Microgrids: Moving Beyond Pilots Cyber Security Boeing Defense, Space & Security Ventures Utility-Scale Applications of Microgrids: Moving Beyond Pilots Cyber Security Tristan Glenwright - Boeing BOEING is a trademark of Boeing Management Company. The

More information

The North American Electric Reliability Corporation ( NERC ) hereby submits

The North American Electric Reliability Corporation ( NERC ) hereby submits December 8, 2009 VIA ELECTRONIC FILING Kirsten Walli, Board Secretary Ontario Energy Board P.O Box 2319 2300 Yonge Street Toronto, Ontario, Canada M4P 1E4 Re: North American Electric Reliability Corporation

More information

Regulated Documents. A concept solution for SharePoint that enables FDA 21CFR part 11 compliance when working with digital documents

Regulated Documents. A concept solution for SharePoint that enables FDA 21CFR part 11 compliance when working with digital documents Regulated Documents A concept solution for SharePoint that enables FDA 21CFR part 11 compliance when working with digital documents Contents Life science industry challenges Regulated Documents our service

More information

Notable Changes to NERC Reliability Standard CIP-005-5

Notable Changes to NERC Reliability Standard CIP-005-5 MIDWEST RELIABILITY ORGANIZATION Notable Changes to NERC Reliability Standard CIP-005-5 Electronic Security Perimeter(s) Bill Steiner MRO Principal Risk Assessment and Mitigation Engineer MRO CIP Version

More information

NERC CIP VERSION 5 COMPLIANCE

NERC CIP VERSION 5 COMPLIANCE BACKGROUND The North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Reliability Standards define a comprehensive set of requirements that are the basis for maintaining

More information

UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION

UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION Technical Conference on Critical Infrastructure Protection Issues Identified in Order No. 791 Prepared Statement of Melanie Seader, Senior

More information

Convergence of Wholesale And Retail Markets: The Texas Experience

Convergence of Wholesale And Retail Markets: The Texas Experience Convergence of Wholesale And Retail Markets: The Texas Experience 1 COMMISSIONER KENNETH W. ANDERSON, JR. PUBLIC UTILITY COMMISSION OF TEXAS PRESENTATION FOR HARVARD ELECTRICITY POLICY GROUP JUNE 12, 2014

More information

ERCOT Monthly Operational Overview (March 2014) ERCOT Public April 15, 2014

ERCOT Monthly Operational Overview (March 2014) ERCOT Public April 15, 2014 ERCOT Monthly Operational Overview (March 2014) ERCOT Public April 15, 2014 Grid Operations & Planning Summary March 2014 Operations The peak demand of 54,549 MW on March 3 rd was greater than the mid-term

More information

Ecom Infotech. Page 1 of 6

Ecom Infotech. Page 1 of 6 Ecom Infotech Page 1 of 6 Page 2 of 6 IBM Q Radar SIEM Intelligence 1. Security Intelligence and Compliance Analytics Organizations are exposed to a greater volume and variety of threats and compliance

More information

Closing the Gap Between Wholesale and Retail

Closing the Gap Between Wholesale and Retail Closing the Gap Between Wholesale and Retail Transactive Energy Workshop March 28-29 Robert B. Burke GWAC MEMBER & PRINCIPAL ANALYST ISO NEW ENGLAND INC. Disclaimer This presentation represents the thoughts

More information

Dan T. Stathos, CPA* Associate Director

Dan T. Stathos, CPA* Associate Director Dan T. Stathos, CPA* dstathos@navigant.com Austin, Texas Direct: 512.493.5415 Professional Summary Dan Stathos, an in NCI s Austin, Texas office, has been involved with electric, gas, water and telephone

More information

Internal Controls And Good Utility Practices. Ruchi Ankleshwaria Manager, Compliance Risk Analysis

Internal Controls And Good Utility Practices. Ruchi Ankleshwaria Manager, Compliance Risk Analysis Internal Controls And Good Utility Practices Ruchi Ankleshwaria Manager, Compliance Risk Analysis 2 Introduction Joined WECC in March 2013 6 years of industry experience prior to joining WECC 4 years at

More information

How To Integrate Firstenergy'S Integrated Grid

How To Integrate Firstenergy'S Integrated Grid EPRI Smart Grid Demonstration Host Site Project FirstEnergy/JCP&L Host Site Overview/Update Integrated Distributed Energy Resources Management Joe Waligorski Technical Manager FE Technologies Eva Gardow

More information

NERC CIP Compliance with Security Professional Services

NERC CIP Compliance with Security Professional Services NERC CIP Compliance with Professional Services The North American Electric Reliability Corporation (NERC) is a nonprofit corporation designed to ensure that the bulk electric system in North America is

More information

Request for Quote For CA Single Sign-On Renewal_3-16_JT

Request for Quote For CA Single Sign-On Renewal_3-16_JT Electric Reliability Council of Texas, Inc. (ERCOT) Contract Administration and Procurement Request for Quote For CA Single Sign-On Renewal_3-16_JT Date of Release: March 4, 2016 1 1 GENERAL INFORMATION

More information

Industries Association. ERCOT Successes and Challenges

Industries Association. ERCOT Successes and Challenges Texas Renewable Energy Industries Association ERCOT Successes and Challenges Laura Doll Board Chair Electric Reliability Council of Texas November 7, 2011 ERCOT Overview The ERCOT market covers roughly

More information

TRIPWIRE NERC SOLUTION SUITE

TRIPWIRE NERC SOLUTION SUITE CONFIDENCE: SECURED SOLUTION BRIEF TRIPWIRE NERC SOLUTION SUITE TAILORED SUITE OF PRODUCTS AND SERVICES TO AUTOMATE NERC CIP COMPLIANCE u u We ve been able to stay focused on our mission of delivering

More information

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions. Electric Grid Operations

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions. Electric Grid Operations San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions Electric Grid Operations Director Electric Grid Operations: Responsible for overall transmission system operations

More information

NPCC Implementation of the NERC Compliance Monitoring And Enforcement Program (CMEP)

NPCC Implementation of the NERC Compliance Monitoring And Enforcement Program (CMEP) Northeast Power Coordinating Council, Inc. NPCC Implementation of the NERC Compliance Monitoring And CP-01 Rev.2 The NERC Rules of Procedure and the Regional Delegation Agreement are the overriding documents

More information

Pipeline Components Traceability Utilities companies new frontier

Pipeline Components Traceability Utilities companies new frontier www.pwc.com/us/utilities Pipeline Components Traceability Utilities companies new frontier PwC's US Power and Utilities Practice Pipeline components traceability 2012 is likely to be remembered as a pivotal

More information

OE-417 ELECTRIC EMERGENCY INCIDENT AND DISTURBANCE REPORT...

OE-417 ELECTRIC EMERGENCY INCIDENT AND DISTURBANCE REPORT... U.S. DEPARTMENT OF ENERGY OFFICE OF ELECTRICITY DELIVERY AND ENERGY RELIABILITY Washington, D.C. 20585 OMB No. 1901-0288 Expiration Date: 03/31/2018 Burden Per Response: 2.16 hours Revised: November 2014

More information

How To Monitor A Municipality

How To Monitor A Municipality UMHLABUYALINGANA MUNICIPALITY ACTIVITY MONITORING POLICY AND PROCEDURE Activity Monitoring Policy and Procedure Approval and Version Control Approval Process: Position or Meeting Number: Date: Originator

More information

EnergySec Partnered Webinar with MetricStream Transitioning to NERC CIP Version 5: What Does it Mean for Electric Utilities JANUARY 28, 2015

EnergySec Partnered Webinar with MetricStream Transitioning to NERC CIP Version 5: What Does it Mean for Electric Utilities JANUARY 28, 2015 EnergySec Partnered Webinar with MetricStream Transitioning to NERC CIP Version 5: What Does it Mean for Electric Utilities JANUARY 28, 2015 Housekeeping Items Submit questions using control panel Contact

More information

Preparing for the Convergence of Risk Management & Business Continuity

Preparing for the Convergence of Risk Management & Business Continuity Preparing for the Convergence of Risk Management & Business Continuity Disaster Recovery Journal Webinar Series September 5, 2012 2012 Strategic BCP, Inc. All rights reserved. strategicbcp.com 1 Today

More information

Certified Identity and Access Manager (CIAM) Overview & Curriculum

Certified Identity and Access Manager (CIAM) Overview & Curriculum Identity and access management (IAM) is the most important discipline of the information security field. It is the foundation of any information security program and one of the information security management

More information

Market Solutions to Loop Flow

Market Solutions to Loop Flow Market Solutions to Loop Flow Robert Pike Director, Market Design New York Independent System Operator Business Issues Committee September 9, 2009 1 Agenda Background Recommendation Next Steps Solution

More information

Implementation Plan for Version 5 CIP Cyber Security Standards

Implementation Plan for Version 5 CIP Cyber Security Standards Implementation Plan for Version 5 CIP Cyber Security Standards April 10September 11, 2012 Prerequisite Approvals All Version 5 CIP Cyber Security Standards and the proposed additions, modifications, and

More information

Olav Mo, Cyber Security Manager Oil, Gas & Chemicals, 28.09.2015 CASE: Implementation of Cyber Security for Yara Glomfjord

Olav Mo, Cyber Security Manager Oil, Gas & Chemicals, 28.09.2015 CASE: Implementation of Cyber Security for Yara Glomfjord Olav Mo, Cyber Security Manager Oil, Gas & Chemicals, 28.09.2015 CASE: Implementation of Cyber Security for Yara Glomfjord Implementation of Cyber Security for Yara Glomfjord Speaker profile Olav Mo ABB

More information

HVDC Transmission Line Project for Moving ERCOT Wind Into SERC

HVDC Transmission Line Project for Moving ERCOT Wind Into SERC HVDC Transmission Line Project for Moving ERCOT Wind Into SERC ERCOT RPG Meeting August 13, 2010 Agenda Pattern Energy Group SERC and ERCOT Market Drivers Southern Cross Project Overview Project Development

More information

IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP

IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP IT Audit Perspective on Continuous Auditing/Continuous Monitoring INTRODUCTION New demands from the board, senior organizational

More information

Safety Management Program

Safety Management Program Corrective Action Plan (CAP) Safety Management Program Submitted by TransCanada PipeLines Limited and its National Energy Board Regulated Subsidiaries to address non-compliant findings in the National

More information

The Finance & Audit (F&A) Committee is expected to consider F&A Committee Agenda Item 4: at its meeting on December 7, 2015.

The Finance & Audit (F&A) Committee is expected to consider F&A Committee Agenda Item 4: at its meeting on December 7, 2015. The Finance & Audit (F&A) Committee is expected to consider F&A Committee Agenda Item 4: Recommendation regarding Acceptance of 2015 Service Organization Control (SSAE 16) Audit Report at its meeting on

More information

Alberta Reliability Standard Cyber Security Configuration Change Management and Vulnerability Assessments CIP-010-AB-1

Alberta Reliability Standard Cyber Security Configuration Change Management and Vulnerability Assessments CIP-010-AB-1 A. Introduction 1. Title: 2. Number: 3. Purpose: To prevent and detect unauthorized changes to BES cyber systems by specifying configuration change management and vulnerability assessment requirements

More information

TRANSMISSION OPERATIONS (August 5, 2010)

TRANSMISSION OPERATIONS (August 5, 2010) TRANSMISSION OPERATIONS (August 5, 2010) Managing Director Transmission Operations: Paul B. Johnson The Managing Director - Transmission Operations is responsible for the safe, reliable, costeffective,

More information