CIP Overview
CIP Overview
Overview
Scope
History of CIP
Past Attacks
NERC-CIP
Standards Review
2
NERC-CIP Overview
The North American Electric Reliability Corporation (NERC) has adopted standards for the
protection and security of Critical Cyber Assets supporting the Bulk Electric System (i.e., the
power grid). This set of standards is known as the Critical Infrastructure Protection (CIP)
standards CIP-002 – CIP-011.
These standards for cyber security are mandatory and enforceable. Failure to comply with
any NERC CIP Standard may result in penalties or fines of up to $1,000,000 per day/per
incident.
3
NERC-CIP Scope
https://youtu.be/fJyWngDco3g
5
NERC-CIP History
STUXNET
2010
Attack Siemens PLCs
Iranian Uranium Factory
State sponsored
SHAMOON
2012
Attack Windows NT
Saudi Aramco
30,000 Computers
No Control/Process Systems
"Cutting Sword of Justice"
7
Past Physical Attacks
8
NERC-CIP Standards
10
NERC-CIP Standards
11
NERC-CIP Standards
CIP-005: Electronic
Security Perimeter(s)
(ESP)
Firewall rules and
policies
Electronic Access Point
Protect all BES Cyber
Assets
12
NERC-CIP Standards
14
NERC-CIP Standards
15
NERC-CIP Standards
16
NERC-CIP Standards
17
Questions?
18
19