
In 2018, this organization needed to review the security of multiple Generating Plants within their fleet. In addition to their low impact OT environments, they wanted reassurance that the associated business network environments weren’t exposing their facilities to unnecessary risk. NST reviewed program documentation including network connectivity diagrams and patching procedures as well as firewall configurations and account management evidence. NST helped to identify risks to their low impact environments, including:
- Areas where security programs did not provide adequate procedural details,
- Instances where security programs were not consistently followed, and
- Risks associated with network architecture and configuration.
Following this engagement, this client began a “greenfield” development of transmission substations and Control Centers. With significant expansion underway, the organization needed assistance to develop a medium and high impact NERC CIP program for these new facility types. NST provided support throughout the entire process, including NERC registration, physical security assessments, network diagram and asset inventory development, and the creation of program elements that could not be carried over from preexisting sites. Upon completion of the development, NST supported a “dry run” Mock Audit of the compliance program to ensure the program was operationally feasible prior to compliance go-live.
After implementing the NERC CIP program across their new facilities, some of this client’s SMEs were unfamiliar with the larger suite of CIP Standards applicable to medium and high impact BES facilities, as well as how day-to-day operations fit into the bigger picture of NERC CIP compliance. As such, they requested NST’s help in developing a series of highly customized training modules to train SMEs on the specific activities this client uses to stay secure and compliant.
NST created a module for each applicable CIP Standard. These modules linked the organization’s unique approach to compliance back to the specific requirements contained in the Standard. To support this connection, NST included specific language from program documentation and procedures, as well as an explanation for how tools used to support compliance helped to achieve these goals. NST then presented each of these modules to specific audiences comprised of the business units and teams responsible for each respective Standard.
Since these initial projects, NST and this organization have continued to partner on various projects as needed to support their team. NST returns annually to support Vulnerability Assessments for medium and high impact BCS, as well as ad-hoc support including CIP-013 Risk Assessments and Mock Audits.