NERC Alert System Overview



Similar documents
EASTPOINTE SECURE E MAIL SYSTEM SETUP INSTRUCTIONS

Provider Express Obtaining Login Access. Information for Network Providers

New World Construction FTP service User Guide

AURORA Vulnerability Background

EJGH Encryption User Tip Sheet of 8

MSGCU SECURE MESSAGE CENTER

JPMorgan Chase Treasury Workstation. Certification Setup Guide Version 2.0

ArtfulBits Password Reset Web Part

Directory and Messaging Services Enterprise Secure Mail Services

QUICK INSTALLATION GUIDE ACTIVATE

Secure Client Guide

New Help Desk Ticketing System

TIMS Web Getting Started Industry User Guide United States Department of the Interior Information Technology Division

Secure Actions for Recipients

The Cancer Institute NSW Grants Management System User Guide

Orbital ATK Secure Receiving Encrypted Messages. Why Orbital ATK Secure ? Initial Orbital ATK Secure Notification

Monash Health Self Service

DATA PROTECTION. OneWorld Encrypted Messages USER GUIDE

Patient Portal: Policies and Procedures & User Reference Guide

Login Instructions. 1. Type web URL into your browser s address bar.

RSA Authentication Manager 7.1 Security Best Practices Guide. Version 2

Selection Manager: Quick Start Guide

DSI File Server Client Documentation

Payment Card Industry (PCI) Compliance. Management Guidelines

FileCloud Security FAQ

Supplier Information Security Addendum for GE Restricted Data

TriCore Secure Web Gateway User Guide 1

electronic Declaration of Interests System (edis) User Guide

U.S. Bank Secure Mail

Using Internet or Windows Explorer to Upload Your Site

MOBILE APP TRAINING MANUAL

Instructions For Opening UHA Encrypted

Centralized Self-service Password Reset: From the Web and Windows Desktop

ABB solar inverters. User s manual ABB Remote monitoring portal

Sophos Mobile Control User guide for Android. Product version: 4

All Colleagues Landing Page

Access and Login. Single Sign On Reference. Signoff

HTTPS GATEWAY INSTRUCTIONS

Sophos Mobile Control User guide for Android

NovaTech NERC CIP Compliance Document and Product Description Updated June 2015

Service Desk R11.2 Upgrade Procedure - Resetting USD passwords and unlocking accounts in etrust Web Admin

Honeywell Secure External User Guide August 2013

User Management Guide

MC EDT Designee Maintenance Procedure Summary. Ministry of Health and Long-Term Care

Wakefield Council Secure and file transfer User guide for customers, partners and agencies

CREDIT CARD SECURITY POLICY PCI DSS 2.0

Welcome to HomeTown Bank s Secure ! User Guide

NETWORK AND CERTIFICATE SYSTEM SECURITY REQUIREMENTS

Bell Mobile Device Management (MDM)

econtrol 3.5 for Active Directory & Exchange Self-Service Guide

AD Self Password Reset Installation and configuration

Cloud Services. Anti-Spam. Admin Guide

UNIFIED MEETING 5 SECURITY WHITEPAPER INFO@INTERCALL.COM INTERCALL.COM

PaymentNet Federal Card Solutions Cardholder FAQs

SCADA Compliance Tools For NERC-CIP. The Right Tools for Bringing Your Organization in Line with the Latest Standards

Sophos Mobile Control SaaS startup guide. Product version: 6

Active Directory Self-Service FAQ

North American Electric Reliability Corporation: Critical Infrastructure Protection, Version 5 (NERC-CIP V5)

Secure Portal. A Step-by-Step Guide for Using KRS ZixCorp Secure Solution

Acunetix Web Vulnerability Scanner. Getting Started. By Acunetix Ltd.

GE Intelligent Platforms. Meeting NERC Change Control Requirements for HMI/SCADA and Control Systems

ClicktoFax Service Usage Manual

Document Management Portal User Guide

CISCO SECURE MAIL. External User Guide. 1/15/15 Samson V.

Remote Desktop for Spiceworks

TOTAL DEFENSE MOBILE SECURITY USER S GUIDE

Hallpass Instructions for Connecting to Mac with a Mac

OHIO BUSINESS GATEWAY USER ACCOUNT UPDATE GUIDE FOR PASSWORD RESET AND ACCOUNT SECURITY FUNCTIONALITY

Cyber Security Compliance (NERC CIP V5)

Using McAfee Quarantine Manager

Bahamas Tax Information Exchange Portal Documentation

Registering and Activating a License on the Cisco ISA500 Security Appliance

BlackBerry Enterprise Service 10. Universal Device Service Version: Administration Guide

Password Reset Server User Guide

Table of Contents. Lesson 5: Assign Delegate...30 Objectives Assign A Delegate Edit Delegate Permissions... 33

PII Compliance Guidelines


YSU Secure Wireless Connect Guide Windows XP Home/Professional/Media Center/Tablet PC Edition

Security Policy JUNE 1, SalesNOW. Security Policy v v

SWAN 15.1 Advance user information What s new in SWAN? Introduction of the new user interface. Last update: 28th April 2015

AD Self-Service Suite for Active Directory

REDCap project creation is not possible in the Mobile App

Information Security Risk Assessment Checklist. A High-Level Tool to Assist USG Institutions with Risk Analysis

How To Secure An Rsa Authentication Agent

Net2 Anywhere - Installation

Hot Spot (Unsecured) Wireless Access Initial Setup and Login for MCC_HOTSPOT

Version /10. Xerox ColorQube 9301/9302/9303 Internet Services

Windows Operating Systems. Basic Security

CIP Supply Chain Risk Management (RM ) Statement of Jacob S. Olcott Vice President, BitSight Technologies January 28, 2016

FDIC Secure Procedures for External Users April 23, 2010

TASK TDSP Web Portal Project Cyber Security Standards Best Practices

GTS Software Pty Ltd. Remote Desktop Services

Retention & Destruction

How To Encrypt An From A Cell Phone To A Pc Or Ipad (For A Partner) With A Cisco Encryption Solution (For Partners)

FormFire Application and IT Security. White Paper

Wireless Guest Server User Provisioning Instructions

Information Technology Branch Access Control Technical Standard

Transcription:

NERC Alert System Overview Todd Thompson, CIP Investigator todd.thompson@nerc.net Chris Lada, Situation Awareness Coordinator chris.lada@nerc.net

About NERC: Mission To ensure the reliability of the North American bulk power system Develop & enforce reliability standards Assess current and future reliability Analyze system events & recommend improved practices Encourage active participation by all stakeholders Pursue mandatory standards across North America 2

Why Alerts? Events Analysis: Single event Based on findings of single event analysis Trends Multiple events displaying similar causal or contributory causes Generic finding Equipment or practice showing generic problem Technical finding Technical analysis reveals potential or repeated problem 3

Why Alerts? Critical Infrastructure Protection & ES-ISAC Examples (Not Limited to): US CERT Vulnerability Disclosure e.g. Boreas and ABB alerts Public Vulnerability Disclosure e.g. RealWin SCADA advisory The release of exploitation code or tools e.g. GE Fanuc advisory Release of a malicious code cyber security 4

Purpose Provide a secure alert distribution and response system to inform the electric industry of potential reliability vulnerabilities and threats to the bulk power system

Capabilities Notify the entire industry of an alert via email within minutes Acknowledge and Respond for multiple entities Track acknowledgements, responses, and nonresponsive entities Upload response documentation, if required or as needed Provide flexible user administration for entities Automatic reminders for approaching due dates

Web Address ALL alert notifications will be sent from: alerts@nercalerts.com Users must login to the system to view alerts https://www.nercalerts.com/ Alerts will not be attached or inserted into emails

Alert Type and Handling Levels ALERT TYPE Industry Advisory No Reporting Required Recommendation to the Industry Acknowledgement and Response Essential Action Notifications HANDLING Public Private Sensitive Confidential Alert Type Color Code Handling Color Code

Handling Provisions Signifier Requirements Public: No Restrictions. Private: Restrict to Internal Use and Necessary Consultants / Third-Party Providers Sensitive: Internal Use Only (Do Not Distribute Outside Your Company) Confidential: Limited Internal Distribution Decided Upon by an Officer of the Company 9

Confidential Alerts Signifier Requirements Confidential: Limited Internal Distribution Decided Upon by an Officer of the Company ONLY Company Officers and PCCs have the ability to view alerts with Confidential Handling Instructions 10

User Account Roles and Expectations Company Officer Suggested that this person is designated as a company officer or maintains a position of vice president (or equivalent) or higher Approve responses and errata Primary Compliance Contact Responsible for timely acknowledgements, responses, and approvals May delegate permissions to others, but remains ultimately responsible Manage user accounts add users, remove users, and modify user permissions Can assign Company Officers

User Account Roles and Expectations Administrator Manage user accounts add users, remove users, and modify user permissions Cannot assign Company Officers Functional Group Member The term Functional Group is used to refer to a certain Registered Function (i.e. Transmission Owner) for a given entity Read Alerts Additional permissions can be granted by the PCC or Administrator

Customized Account Permissions Additional permissions can be granted at the Entity or Functional Group level. Permissions granted at the Entity level apply to all Functional Groups within the entity. Permissions granted at the Functional Group level do not apply to the entire entity.

Customized Permissions Hierarchy Account Permissions Region Permissions Can Acknowledge Can Respond Cannot Approve Functional Group Permissions Can Acknowledge Can Respond Can Approve

NERC Alert System Site Security and Managing Your Account

Login Go to https://www.nercalerts.com in your browser and type your email address and password. Click the Forgot your password? link to have your password sent to you. Three incorrect login attempts will lock your account for one hour.

Managing Your Account Information Click the My Account link to manage your: Contact Information Name Email Address Street Address Phone Number Password

Managing Your Account Information My Account link

Managing Your Account Information Change password Update personal information

Website Security Encrypted Hypertext Transfer Protocol Secure (HTTPS) communications Encrypted database Cisco Intrusion Prevention System Three failed access attempts cause an account lockout. Sessions automatically expire after a period of inactivity or when the browser window is closed.

Physical Security Facility access is restricted by keycards. Security guards are on-site 24/7. Server location is monitored by multiple CCTV cameras. Server cabinet is locked, 6-wall secure. Motion-sensitive video camera within server cabinet providing remote viewing.

NERC Alert System Responding to Alerts

Responding to Alerts Overview Receive the alert email notification. Acknowledge the alert.* Create a response. If necessary, edit the response. Approve the response.* If necessary, update the response with errata. * Required before due date.

Sample Alert Email URL

Logging In Address bar Login Go to https://www.nercalerts.com and type your email address and password.

Alert Response Process Receive Alert Email Acknowledge Alert Respond to Questions Approve Response Add and Approve Errata Required for Recommendations to the Industry Essential Actions Not Required for Industry Advisories (Receive/View Only)

Alert Response Process Receive Receive Alert Email Acknowledge Alert Respond to Questions Approve Response Add and Approve Errata ALL alert notification emails will be from: alerts@nercalerts.com Users must login to the system to view the alert

Alert Response Process Acknowledge Receive Alert Email Acknowledge Alert Respond to Questions Approve Response Add and Approve Errata Acknowledge for multiple entities

Alert Response Process Respond Receive Alert Email Acknowledge Alert Respond to Questions Approve Response Add and Approve Errata Respond to survey questions Upload documentation, if required or as needed Respond for multiple entities

Alert Response Process Approve Receive Alert Email Acknowledge Alert Respond to Questions Approve Response Add and Approve Errata A Company Officer or their designee must approve a response Responses must be approved individually

Alert Response Process Errata Receive Alert Email Acknowledge Alert Respond to Questions Approve Response Add and Approve Errata Errata allows you to change or clarify your response to the alert Errata must be re-approved by a Company Officer or their designee

Viewing the Response Status View the status of an alert at any time. The site tracks: when an alert was acknowledged and which user acknowledged it. when a response was added and edited and which user modified it. when the response was approved and which user approved it.

Viewing the Response Status Status button Click Status.

Viewing the Response Status Acknowledgement Status (Acknowledged) Response Status (Approved) Response Status (Not approved)

Status Report Who and When: Acknowledged an alert Last updated a response Approved a response Summary of alert status for user entities

Sample Recommendation

NERC Alerts Training Online Help and the Help Desk

Site Help Contents Step-by-step instructions for: Managing and responding to alerts Creating and configuring user accounts Frequently Asked Questions Help Desk Contact Information

Accessing the Site Help Help link Login and click Help.

Help Desk Support Contacting the Help Desk Phone: (866) 972-7192 Hours: Weekdays from 08:00 to 17:00 Central Help Desk is available to Provide user assistance View your entity membership and permissions Unlock accounts Cannot answer questions about specific alerts or change your permissions

Questions? Todd Thompson, CIP Investigator todd.thompson@nerc.net Chris Lada, Situation Awareness Coordinator chris.lada@nerc.net