The North American Electric Reliability Corporation is a nonprofit corporation tasked with ensuring the reliability and security of the bulk power transmission system in North America (the U.S., Canada, and part of Mexico). NERC is a federally designated Electric Reliability Organization that develops and enforces reliability standards including those for Critical Infrastructure Protection, or CIP Standards, and requirements for planning and operating the collective bulk power system.
Asset owners who are not compliant with NERC CIP standards can be fined up to $1 million per infraction. List of current fines
The Federal Energy Regulatory Commission approved the Security and Reliability Standards proposed by NERC in 2008, making those standards (including CIP) mandatory for users, owners, and operators of the bulk electric power system. Initial compliance auditing began in June 2009, with covered entities responsible for proving compliance with all provisions of NERC by the end of June 2011.
NERC's standards, including those governing critical infrastructure, apply to a range of entities that "materially impact" the reliability of the bulk power system. In general, these entities are owners, operators, and users of any portion of the bulk power system. More specifically, NERC identifies entities that serve specific functions in the electric power network, such as generator owners and generator operators, as well as transmission owners and transmission operators (providers that own or operate the wires that connect the generators and transmission networks to customers).
FoxGuard provides a wide range of services and solutions that help entities identify and mitigate gaps in the security of their systems and prepare for NERC CIP audits.
|
CIP Requirement |
Supporting Products/Services |
|---|---|
|
CIP-002: Critical Cyber Asset Identification |
|
|
CIP-005: Electronic Security Perimeter(s) |
|
|
CIP-007: Systems Security Management
Most violated CIP as of 08/31/11 |
Access Management |
|
CIP-009: Recovery Plans for Critical Cyber Assets |