
In 2018, after onboarding nearly two dozen new substations to their list of BES assets, this organization needed a hand in completing their annual Vulnerability Assessments as well as commissioning VAs for all new Assets. NST quickly stepped in to support both projects.
For previously commissioned assets, NST conducted a standard NERC CIP VA in accordance with the organization’s program. This review was consistent with standard industry practices for Paper Vulnerability Assessments, including Network Discovery, Network Port and Service Identification, Vulnerability Review, and Wireless Review.
For newly commissioned, assets, NST employed a hybrid approach between a Paper and Active VA in order to ensure that the security of these new substations was certain. In addition to SME interviews and site walkdowns, NST used specialized scanning tools to search for wireless signals and listening ports on network devices. Further, NST assessed each open port to determine whether or not it would be required for normal or emergency operations.
Though the elements of an Active VA were not explicitly required for medium impact BCS, NST and the organization agreed that additional checks would provide confidence that the new facilities had been commissioned properly and in accordance with the organization’s controls for CIP-005, CIP-007, and CIP-010.
Since this initial project, NST has returned annually to help this organization complete their annual CIP-010 Paper Vulnerability Assessments. Throughout the years, NST consultants have become increasingly familiar and involved with this organization’s NERC CIP compliance program, leading to improved efficiency and process improvements.
Following the initial VA support, NST was requested once again to lend a hand with this organization’s monthly manual patch cycle. With so many substations in-scope, the organization maintained multiple facility designs, and as such, hosted a wide variety of manufacturers, models, and installed software.
This presented a unique challenge for a manual patch assessment, since each vendor’s website comes with its own unique layout, vocabulary, and level of detail. While some websites streamlined the process, others required extensive digging or manual data entry.
Though the organization felt confident in their abilities to perform the manual patch assessments, SMEs were already busy with day-to-day compliance responsibilities and feared that completing the process on their own would mean leaving other aspects of the program behind. Since NST’s involvement with this ongoing project, SMEs have had more time to perform work “on the program”, including improvements and enhancements that would otherwise be too much to complete within a month.