<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Microsoft Power and Utilities Blog : Euci conference on NERC</title><link>http://blogs.msdn.com/mspowerutilities/archive/tags/Euci+conference+on+NERC/default.aspx</link><description>Tags: Euci conference on NERC</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Cyber security and critical infrastructure protection -  Managing for success</title><link>http://blogs.msdn.com/mspowerutilities/archive/2008/08/12/cyber-security-and-critical-infrastructure-protection-managing-for-success.aspx</link><pubDate>Tue, 12 Aug 2008 14:52:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8850610</guid><dc:creator>MSPowerUtilities</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/mspowerutilities/comments/8850610.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mspowerutilities/commentrss.aspx?PostID=8850610</wfw:commentRss><description>&lt;P&gt;&lt;FONT face=georgia,palatino size=3&gt;To say that Utilities are meeting the challenges of a difficult age is probably the understatement of the decade. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=georgia,palatino size=3&gt;One need only &lt;/FONT&gt;&lt;A href="http://www.nerc.com/fileUploads/File/News/Executive-Remarks.072008.pdf" mce_href="http://www.nerc.com/fileUploads/File/News/Executive-Remarks.072008.pdf"&gt;&lt;FONT face=georgia,palatino size=3&gt;look at the comments of Rick Sergel&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=georgia,palatino size=3&gt;, president and CEO of the North American Electric Reliability Corporation (NERC), to the state regulators at the National Association of Regulatory Utility Commissioners (NARUC) summer meetings on July 20, where he outlines all the various measures being taken to increase cyber and physical asset security of the North American power system. &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face=georgia,palatino size=3&gt;Of note to utilities with Microsoft solutions in place, we believe our technologies will help address many of the very specific requirements that NERC is laying out. In particular, Sergel mentioned the following two critical infrastructure protection requirements: &lt;/FONT&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT face=georgia,palatino&gt;&lt;FONT size=3&gt;&lt;B&gt;CIP-003: Security Management Controls &lt;/B&gt;essentially requires entities to document a cyber security policy, review it annually, and make it accessible to appropriate staff, but appropriate staff only. It also requires each entity to document exceptions to the policy, review it annually, and closely control access to the plan. As one additional matter of course, the standard requires each entity to identify a cyber security contact within their organization and provide this information to NERC or their Regional Entity. &lt;/FONT&gt;&lt;/FONT&gt;
&lt;P&gt;&lt;B&gt;&lt;FONT face=georgia,palatino size=3&gt;&lt;/FONT&gt;&lt;/B&gt;
&lt;P&gt;&lt;FONT face=georgia,palatino&gt;&lt;FONT size=3&gt;&lt;B&gt;CIP-007: Systems Security Management &lt;/B&gt;essentially gives some basic requirements about IT maintenance, like installing anti-virus systems, downloading security patches, and securing unused access points (or ports) to critical cyber equipment. It also contains some requirements for logging user access, managing permissions and administrator privileges. Perhaps most importantly, it requires entities to assess cyber vulnerabilities annually and to document this assessment. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT face=georgia,palatino size=3&gt;We will be writing more about meeting &lt;/FONT&gt;&lt;A href="http://www.nerc.com/page.php?cid=2|20" mce_href="http://www.nerc.com/page.php?cid=2|20"&gt;&lt;FONT face=georgia,palatino size=3&gt;NERC reliability standards&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=georgia,palatino size=3&gt; in the future but for now you might look at the following discussions about NERC: &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face=georgia,palatino size=3&gt;Several Microsoft partners &lt;/FONT&gt;&lt;A href="https://www.euci.com/conferences/0708-nerc-reliability/" mce_href="https://www.euci.com/conferences/0708-nerc-reliability/"&gt;&lt;FONT face=georgia,palatino size=3&gt;sponsored the recent EUCI conference on NERC&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=georgia,palatino size=3&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/industry/manufacturing/utilities/whitepaper/nerc.mspx" mce_href="http://www.microsoft.com/industry/manufacturing/utilities/whitepaper/nerc.mspx"&gt;&lt;FONT face=georgia,palatino size=3&gt;Warren Causey wrote a Whitepaper on Microsoft’s role in complying with NERC standards&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=georgia,palatino size=3&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/business/peopleready/compliance/default.mspx" mce_href="http://www.microsoft.com/business/peopleready/compliance/default.mspx"&gt;&lt;FONT face=georgia,palatino size=3&gt;Using familiar Microsoft tools to reduce the complexity of compliance&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=georgia,palatino size=3&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d64dfb49-aa29-4a4b-8f5a-32c922e850ca&amp;amp;DisplayLang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d64dfb49-aa29-4a4b-8f5a-32c922e850ca&amp;amp;DisplayLang=en"&gt;&lt;FONT face=georgia,palatino size=3&gt;2007 Office System Document: Compliance Features in the 2007 Microsoft Office System&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=georgia,palatino size=3&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://technet.microsoft.com/en-us/regulatorycompliance/default.aspx" mce_href="http://technet.microsoft.com/en-us/regulatorycompliance/default.aspx"&gt;&lt;FONT face=georgia,palatino size=3&gt;Microsoft solutions for regulatory compliance&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=georgia,palatino size=3&gt; &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face=georgia,palatino size=3&gt;Of particular interest is the Energy Central Webcast entitled “Are you prepared for your next NERC/RRO Audit”.&amp;nbsp; In the Webcast Warren Causey of Energy Central along with Steve Rossi of Flexnova, Andre Chon of AUS Consulting and Pat vanMidde of San Diego Gas &amp;amp; Electric discuss the internal process, procedures and documentation responsibility NERC compliance and solutions for preventing NERC compliance activities from turning into a document management nightmare! &lt;/FONT&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/industry/manufacturing/utilities/demos/utils_NERC_webcast.wvx" mce_href="http://www.microsoft.com/industry/manufacturing/utilities/demos/utils_NERC_webcast.wvx"&gt;&lt;FONT face=georgia,palatino size=3&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=191 alt=clip_image001 src="http://blogs.msdn.com/blogfiles/mspowerutilities/WindowsLiveWriter/Cybersecurityandcriticalinfrastructurepr_6EB4/clip_image001_3.jpg" width=244 border=0 mce_src="http://blogs.msdn.com/blogfiles/mspowerutilities/WindowsLiveWriter/Cybersecurityandcriticalinfrastructurepr_6EB4/clip_image001_3.jpg"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8850610" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/mspowerutilities/archive/tags/Naruc/default.aspx">Naruc</category><category domain="http://blogs.msdn.com/mspowerutilities/archive/tags/Rick+Sergel/default.aspx">Rick Sergel</category><category domain="http://blogs.msdn.com/mspowerutilities/archive/tags/Nerc/default.aspx">Nerc</category><category domain="http://blogs.msdn.com/mspowerutilities/archive/tags/Security+Management+Controls/default.aspx">Security Management Controls</category><category domain="http://blogs.msdn.com/mspowerutilities/archive/tags/Euci+conference+on+NERC/default.aspx">Euci conference on NERC</category><category domain="http://blogs.msdn.com/mspowerutilities/archive/tags/systems+security+management/default.aspx">systems security management</category></item></channel></rss>