New Cyber-Security Standards for N. American Power System

The North American Electric Reliability Corporation's board of trustees has approved changes that make cyber-security compliance for the electric industry more stringent.

» View Article

READER FEEDBACK
Preview
JT Keating
Wed, 2009-05-06 21:57

First, a disclaimer: I work for CoreTrace, a security software provider that is helping utilities stop malware and unapproved applications (NERC CIPs -007 & -003, respectively).

Having reviewed just those specific CIPs (which only changed slightly this go around), I believe that they still need to be to be changed to reflect their actual purpose, preventing the execution of any unauthorized code, rather than prescribing specific technologies—especially technologies that are completely inconsistent with the operational realities of the energy management systems that make up most of the grid's critical infrastructure.

reply
Joan Goodchild
Thu, 2009-05-07 13:33

Thanks JT,

Interesting feedback. Feel free to contact me at jgoodchild@cxo.com if you want to discuss further.

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.