SlideShare une entreprise Scribd logo
1  sur  20
Slide Header…

Standards of Excellence

Automating the
Compliance Lab for
CIP Version 5

Chuck Reynolds
Chief Technology Officer,
TSI

Wednesday, October 30, 2013

QualiSystems Proprietary & Confidential
Speakers
• NERC = North American Electric Reliability Corporation
• Non-profit corporation
• Charter: ensure reliability, adequacy and security
• Maintains comprehensive planning and operations
standards

• CIP = Critical Infrastructure Protection
• NERC CIP Standards 002-011
• Ensure protection of critical cyber assets
• 8 primary standards, 41 requirements, 164 subrequirements
• Mandatory compliance for all major electric companies
Accelerating Pace of CIP Standards Development
• Electric utilities required to retain:
•
•

12 months of auditable data, documents and records on their
information security controls
Specific logs for 90 days

• Currently being audited based on CIP version 3
• Mandated to become fully compliant with version 4 by April of 2014
• However, CIP version 5 drafted and is awaiting final approval
•
•

More comprehensive and specific device standards
Version 6 in the works and may usurp version 5 deployment

• Getting ahead of the game is a smart move given the flux
•

One major entity is already implementing version 5 tests!
More Rigorous Device Certification Standards
•

CIP 007 - Systems Security Management
•
•

Account tests / Password tests

•

Patch tests

•

•

Log tests

•

New device/OS/topology certification

•

Regular baseline regression testing

•

Security software configuration validation

Antivirus tests

CIP 010 - Configuration Change Management and Vulnerability
Assessments
•

Baseline tests / Comparison tests

•

Port scan tests

•

Vulnerability Assessments (EISP)
• Fines for compliance violations
up to $1M per day
• Since CIP compliance standards
were published in 2008,
more than $150 million in
fines have been levied
• 80% of pre-production test lab
equipment & personnel can be
devoted to CIP compliance
testing
 No live inventory visibility
 Offline test topology design

 Chaotic connectivity, costly disconnects
 Lack of device configuration base-lining
 Manual provisioning/testing
 Manual report generation
•

Compliance Risk
• Lack of test integrity and repeatability due to operator
errors, process variance
• Manual processes difficult to document
• Incomplete reporting—manual analysis can’t digest voluminous test
results data
• Personnel struggle to keep pace with compliance test coverage
requirements

•

CAPEX/OPEX Waste
• Large ratio of test setup to actual testing
• Days spent in the setup process for a 2 hour test - Very

•
•

low asset utilization.
Millions of dollars in capital equipment only 15% to 20%
utilized
Wasted real-estate and power costs
•

Infrastructure Management
• Live inventory, connectivity control

•

Test Equipment Resource Sharing
• Integrated test environment design, reservation and scheduling

•

Device Provisioning
• Automated base-lining procedures, device configuration

•

Test Automation
• Automate manual test procedures
• Test IP sharing, reuse, repeatability

•

Reporting and Documentation
• Automated certification reporting and audit trail documentation
• Reduced risk of non-compliance and real attacks
• All resources are managed in a single repository
• Tag devices according to user-defined parameters
• Easily find the required type of device you need
• Track and report device utilization
• Draw the topology route requirement
• No need to remember or lookup physical cabling
• Actual connectivity is invisible to the end user

• Manual and automated patching
• Generate patching table reports and emails
• Automatically control L1 Switches





MRV
ONPATH
Apcon
Curtiss-Wright
• Replace the static diagram with a live workspace
•
•
•
•
•

Drag & drop devices
Draw required connections and activate
Directly provision devices
Power up and down devices
Directly open CLIs to devices
• Central calendar-based scheduling
• Plan ahead lab operations
• Resolve allocation conflicts
• Locate device availability in a snap
•

Embedded integration with lab resources
•
•
•
•
•
•

•

Customize your own provisioning
•
•
•
•

•

Control interfaces
GUI
Scripts
Leading testing vendors
Custom drivers
Third Party Apps

No need to program
Quick and standard reuse
Simple graphical flowchart
Easy device response analysis

Examples
•
•
•

Automatic discovery
Validate setup
Nightly maintenance run

Telnet, SSH, Web Services, Serial…
Windows, Java, Web…
TCL, Perl, Python, PowerShell…
Ixia, Spirent, Shenick, MRV, ONPATH…
NET, Exe, LabVIEW, ActiveX,…
NMAP, iPerf, MSBA, WireShark, ….
Test Automation Example--Looping NMAP test
•

Drag & Drop

•

Flow Chart Test

•

Easy parallelism

•

Tools
•
•
•
•

•

Wide spectrum
Open architecture
Add your own
Standard use

Share
•
•

Assets
Knowledge
Compliance Tracking Dashboards and Reports
• Dashboards
• At a glance views
of compliance
• Real-time remote
viewing for
auditors

• Custom Reports
• Structured to
match CIP
reporting
requirements
Efficiency and Savings from Automating the Test Lab

MANUAL

AUTOMATED
Lab Maturity Model
• From CHAOS to COMPLIANCE

• Effective and Efficient Lab Resources
• Faster test cycles, Increased utilization, Improved value

• Ensure compliance, protect the bottom line
• Incorporate best test practices as part of the business model

• Create Eco-System with Suppliers to Coordinate Testing
•

Shared tests, lab management practices
Q&A
Thank You
Visit us:
www.qualisystems.com/demo
www.tsieda.com

Contenu connexe

Tendances

Server and application monitoring webinars [Applications Manager] - Part 3
Server and application monitoring webinars [Applications Manager] - Part 3Server and application monitoring webinars [Applications Manager] - Part 3
Server and application monitoring webinars [Applications Manager] - Part 3ManageEngine, Zoho Corporation
 
Unittest og coverage målinger i udviklingsmiljøet hos Deif Windpower
Unittest og coverage målinger i udviklingsmiljøet hos Deif WindpowerUnittest og coverage målinger i udviklingsmiljøet hos Deif Windpower
Unittest og coverage målinger i udviklingsmiljøet hos Deif WindpowerInfinIT - Innovationsnetværket for it
 
Rockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation
 
Server and application monitoring webinars [Applications Manager] - Part 2
Server and application monitoring webinars [Applications Manager] - Part 2Server and application monitoring webinars [Applications Manager] - Part 2
Server and application monitoring webinars [Applications Manager] - Part 2ManageEngine, Zoho Corporation
 
Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law
Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law
Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law SkyLaw Professional Corporation
 
Server and application monitoring webinars [Applications Manager] - Part 4
Server and application monitoring webinars [Applications Manager] - Part 4Server and application monitoring webinars [Applications Manager] - Part 4
Server and application monitoring webinars [Applications Manager] - Part 4ManageEngine, Zoho Corporation
 
Managing 4,000 devices across 20+ remote sites on a single console
Managing 4,000 devices across 20+ remote sites on a single consoleManaging 4,000 devices across 20+ remote sites on a single console
Managing 4,000 devices across 20+ remote sites on a single consoleManageEngine, Zoho Corporation
 
Configlets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration ManagerConfiglets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration ManagerManageEngine, Zoho Corporation
 
Dashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centreDashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centreManageEngine, Zoho Corporation
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightManageEngine, Zoho Corporation
 
OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.ManageEngine, Zoho Corporation
 
Logs as Data: Using Logs to track Web Application Performance
Logs as Data: Using Logs to track Web Application PerformanceLogs as Data: Using Logs to track Web Application Performance
Logs as Data: Using Logs to track Web Application PerformanceTrevor Parsons
 
Global Airline giant's application performance monitoring solution!
Global Airline giant's application performance monitoring solution!Global Airline giant's application performance monitoring solution!
Global Airline giant's application performance monitoring solution!ManageEngine, Zoho Corporation
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshootingManageEngine, Zoho Corporation
 

Tendances (20)

Server and application monitoring webinars [Applications Manager] - Part 3
Server and application monitoring webinars [Applications Manager] - Part 3Server and application monitoring webinars [Applications Manager] - Part 3
Server and application monitoring webinars [Applications Manager] - Part 3
 
Unittest og coverage målinger i udviklingsmiljøet hos Deif Windpower
Unittest og coverage målinger i udviklingsmiljøet hos Deif WindpowerUnittest og coverage målinger i udviklingsmiljøet hos Deif Windpower
Unittest og coverage målinger i udviklingsmiljøet hos Deif Windpower
 
Rockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCA
 
Server and application monitoring webinars [Applications Manager] - Part 2
Server and application monitoring webinars [Applications Manager] - Part 2Server and application monitoring webinars [Applications Manager] - Part 2
Server and application monitoring webinars [Applications Manager] - Part 2
 
Resume_New
Resume_NewResume_New
Resume_New
 
Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law
Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law
Get Your Head In the Clouds: The Use of Cloud Computing in the Practice of Law
 
Server and application monitoring webinars [Applications Manager] - Part 4
Server and application monitoring webinars [Applications Manager] - Part 4Server and application monitoring webinars [Applications Manager] - Part 4
Server and application monitoring webinars [Applications Manager] - Part 4
 
Managing 4,000 devices across 20+ remote sites on a single console
Managing 4,000 devices across 20+ remote sites on a single consoleManaging 4,000 devices across 20+ remote sites on a single console
Managing 4,000 devices across 20+ remote sites on a single console
 
OpUtils Free training
OpUtils Free training OpUtils Free training
OpUtils Free training
 
Free training on NCM - Discovery & Disaster recovery
Free training on NCM - Discovery & Disaster recovery Free training on NCM - Discovery & Disaster recovery
Free training on NCM - Discovery & Disaster recovery
 
Network fault management and IT automation training
Network fault management and IT automation trainingNetwork fault management and IT automation training
Network fault management and IT automation training
 
Configlets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration ManagerConfiglets, compliance, RBAC & reports - Network Configuration Manager
Configlets, compliance, RBAC & reports - Network Configuration Manager
 
Dashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centreDashboards, widgets, business views & 3D-data centre
Dashboards, widgets, business views & 3D-data centre
 
Free NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings rightFree NetFlow Analyzer training - Getting the initial settings right
Free NetFlow Analyzer training - Getting the initial settings right
 
OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.OpManager training - Device discovery and classification.
OpManager training - Device discovery and classification.
 
Network and server performance monitoring training
Network and server performance monitoring trainingNetwork and server performance monitoring training
Network and server performance monitoring training
 
Overview and features of NCM
Overview and features of NCMOverview and features of NCM
Overview and features of NCM
 
Logs as Data: Using Logs to track Web Application Performance
Logs as Data: Using Logs to track Web Application PerformanceLogs as Data: Using Logs to track Web Application Performance
Logs as Data: Using Logs to track Web Application Performance
 
Global Airline giant's application performance monitoring solution!
Global Airline giant's application performance monitoring solution!Global Airline giant's application performance monitoring solution!
Global Airline giant's application performance monitoring solution!
 
Free Netflow analyzer training - diagnosing_and_troubleshooting
Free Netflow analyzer  training - diagnosing_and_troubleshootingFree Netflow analyzer  training - diagnosing_and_troubleshooting
Free Netflow analyzer training - diagnosing_and_troubleshooting
 

Similaire à Automating Compliance Lab for CIP Version 5 Testing

6 Steps to Implementing a World Class Testing Ecosystem Final
6 Steps to Implementing a World Class Testing Ecosystem Final6 Steps to Implementing a World Class Testing Ecosystem Final
6 Steps to Implementing a World Class Testing Ecosystem FinalEggplant
 
6 Top Tips to a Testing Strategy That Works
6 Top Tips to a Testing Strategy That Works6 Top Tips to a Testing Strategy That Works
6 Top Tips to a Testing Strategy That WorksEggplant
 
Agile infrastructure
Agile infrastructureAgile infrastructure
Agile infrastructureTarun Rajput
 
Intuit continuous performance testing for code camp temp
Intuit continuous performance testing for code camp tempIntuit continuous performance testing for code camp temp
Intuit continuous performance testing for code camp tempRamakrishna Kollipara
 
Monitoring at the Speed of DevOps
Monitoring at the Speed of DevOpsMonitoring at the Speed of DevOps
Monitoring at the Speed of DevOpsDevOps.com
 
Challenges in Practicing High Frequency Releases in Cloud Environments
Challenges in Practicing High Frequency Releases in Cloud Environments Challenges in Practicing High Frequency Releases in Cloud Environments
Challenges in Practicing High Frequency Releases in Cloud Environments Liming Zhu
 
Production Ready Microservices at Scale
Production Ready Microservices at ScaleProduction Ready Microservices at Scale
Production Ready Microservices at ScaleRajeev Bharshetty
 
USING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITY
USING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITYUSING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITY
USING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITYwle-ss
 
20110812 CyberTAN presentation
20110812 CyberTAN presentation20110812 CyberTAN presentation
20110812 CyberTAN presentationRichard Hsu
 
Quick wins in the NetOps Journey by Vincent Boon, Opengear
Quick wins in the NetOps Journey by Vincent Boon, OpengearQuick wins in the NetOps Journey by Vincent Boon, Opengear
Quick wins in the NetOps Journey by Vincent Boon, OpengearMyNOG
 
Neotys PAC - Ian Molyneaux
Neotys PAC - Ian MolyneauxNeotys PAC - Ian Molyneaux
Neotys PAC - Ian MolyneauxNeotys_Partner
 
Characerizing and Validating QoS in the Emerging IoT Network
Characerizing and Validating QoS in the Emerging IoT NetworkCharacerizing and Validating QoS in the Emerging IoT Network
Characerizing and Validating QoS in the Emerging IoT NetworkHans Ashlock
 
(ISM301) Engineering Netflix Global Operations In The Cloud
(ISM301) Engineering Netflix Global Operations In The Cloud(ISM301) Engineering Netflix Global Operations In The Cloud
(ISM301) Engineering Netflix Global Operations In The CloudAmazon Web Services
 
Self Service for IT Infrastructure
Self Service for IT Infrastructure Self Service for IT Infrastructure
Self Service for IT Infrastructure Cisco DevNet
 
Engineering Netflix Global Operations in the Cloud
Engineering Netflix Global Operations in the CloudEngineering Netflix Global Operations in the Cloud
Engineering Netflix Global Operations in the CloudJosh Evans
 
RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup
RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup
RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup Ricoh India Limited
 
David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...
David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...
David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...InfluxData
 
SCQAA-SF Meeting on May 21 2014
SCQAA-SF Meeting on May 21 2014 SCQAA-SF Meeting on May 21 2014
SCQAA-SF Meeting on May 21 2014 Sujit Ghosh
 

Similaire à Automating Compliance Lab for CIP Version 5 Testing (20)

6 Steps to Implementing a World Class Testing Ecosystem Final
6 Steps to Implementing a World Class Testing Ecosystem Final6 Steps to Implementing a World Class Testing Ecosystem Final
6 Steps to Implementing a World Class Testing Ecosystem Final
 
6 Top Tips to a Testing Strategy That Works
6 Top Tips to a Testing Strategy That Works6 Top Tips to a Testing Strategy That Works
6 Top Tips to a Testing Strategy That Works
 
Agile infrastructure
Agile infrastructureAgile infrastructure
Agile infrastructure
 
Intuit continuous performance testing for code camp temp
Intuit continuous performance testing for code camp tempIntuit continuous performance testing for code camp temp
Intuit continuous performance testing for code camp temp
 
Monitoring at the Speed of DevOps
Monitoring at the Speed of DevOpsMonitoring at the Speed of DevOps
Monitoring at the Speed of DevOps
 
Challenges in Practicing High Frequency Releases in Cloud Environments
Challenges in Practicing High Frequency Releases in Cloud Environments Challenges in Practicing High Frequency Releases in Cloud Environments
Challenges in Practicing High Frequency Releases in Cloud Environments
 
Production Ready Microservices at Scale
Production Ready Microservices at ScaleProduction Ready Microservices at Scale
Production Ready Microservices at Scale
 
USING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITY
USING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITYUSING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITY
USING NEAR-REAL TIME MONITORING TO IMPROVE EQUIPMENT RELIABILITY
 
QualiSystems-Brief TestShell
QualiSystems-Brief TestShellQualiSystems-Brief TestShell
QualiSystems-Brief TestShell
 
20110812 CyberTAN presentation
20110812 CyberTAN presentation20110812 CyberTAN presentation
20110812 CyberTAN presentation
 
Quick wins in the NetOps Journey by Vincent Boon, Opengear
Quick wins in the NetOps Journey by Vincent Boon, OpengearQuick wins in the NetOps Journey by Vincent Boon, Opengear
Quick wins in the NetOps Journey by Vincent Boon, Opengear
 
Neotys PAC - Ian Molyneaux
Neotys PAC - Ian MolyneauxNeotys PAC - Ian Molyneaux
Neotys PAC - Ian Molyneaux
 
Journey to the center of DevOps - v6
Journey to the center of DevOps - v6Journey to the center of DevOps - v6
Journey to the center of DevOps - v6
 
Characerizing and Validating QoS in the Emerging IoT Network
Characerizing and Validating QoS in the Emerging IoT NetworkCharacerizing and Validating QoS in the Emerging IoT Network
Characerizing and Validating QoS in the Emerging IoT Network
 
(ISM301) Engineering Netflix Global Operations In The Cloud
(ISM301) Engineering Netflix Global Operations In The Cloud(ISM301) Engineering Netflix Global Operations In The Cloud
(ISM301) Engineering Netflix Global Operations In The Cloud
 
Self Service for IT Infrastructure
Self Service for IT Infrastructure Self Service for IT Infrastructure
Self Service for IT Infrastructure
 
Engineering Netflix Global Operations in the Cloud
Engineering Netflix Global Operations in the CloudEngineering Netflix Global Operations in the Cloud
Engineering Netflix Global Operations in the Cloud
 
RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup
RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup
RPASS - Ricoh Proactive ServiceS for Remote Monitoring & Backup
 
David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...
David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...
David Henthorn [Rose-Hulman Institute of Technology] | Illuminating the Dark ...
 
SCQAA-SF Meeting on May 21 2014
SCQAA-SF Meeting on May 21 2014 SCQAA-SF Meeting on May 21 2014
SCQAA-SF Meeting on May 21 2014
 

Dernier

How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesBernd Ruecker
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Farhan Tariq
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observabilityitnewsafrica
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integrationmarketing932765
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesMuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesManik S Magar
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Kaya Weers
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationKnoldus Inc.
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI AgeCprime
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfNeo4j
 

Dernier (20)

How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architectures
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesMuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog Presentation
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI Age
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdf
 

Automating Compliance Lab for CIP Version 5 Testing

  • 1. Slide Header… Standards of Excellence Automating the Compliance Lab for CIP Version 5 Chuck Reynolds Chief Technology Officer, TSI Wednesday, October 30, 2013 QualiSystems Proprietary & Confidential
  • 3. • NERC = North American Electric Reliability Corporation • Non-profit corporation • Charter: ensure reliability, adequacy and security • Maintains comprehensive planning and operations standards • CIP = Critical Infrastructure Protection • NERC CIP Standards 002-011 • Ensure protection of critical cyber assets • 8 primary standards, 41 requirements, 164 subrequirements • Mandatory compliance for all major electric companies
  • 4. Accelerating Pace of CIP Standards Development • Electric utilities required to retain: • • 12 months of auditable data, documents and records on their information security controls Specific logs for 90 days • Currently being audited based on CIP version 3 • Mandated to become fully compliant with version 4 by April of 2014 • However, CIP version 5 drafted and is awaiting final approval • • More comprehensive and specific device standards Version 6 in the works and may usurp version 5 deployment • Getting ahead of the game is a smart move given the flux • One major entity is already implementing version 5 tests!
  • 5. More Rigorous Device Certification Standards • CIP 007 - Systems Security Management • • Account tests / Password tests • Patch tests • • Log tests • New device/OS/topology certification • Regular baseline regression testing • Security software configuration validation Antivirus tests CIP 010 - Configuration Change Management and Vulnerability Assessments • Baseline tests / Comparison tests • Port scan tests • Vulnerability Assessments (EISP)
  • 6. • Fines for compliance violations up to $1M per day • Since CIP compliance standards were published in 2008, more than $150 million in fines have been levied • 80% of pre-production test lab equipment & personnel can be devoted to CIP compliance testing
  • 7.  No live inventory visibility  Offline test topology design  Chaotic connectivity, costly disconnects  Lack of device configuration base-lining  Manual provisioning/testing  Manual report generation
  • 8. • Compliance Risk • Lack of test integrity and repeatability due to operator errors, process variance • Manual processes difficult to document • Incomplete reporting—manual analysis can’t digest voluminous test results data • Personnel struggle to keep pace with compliance test coverage requirements • CAPEX/OPEX Waste • Large ratio of test setup to actual testing • Days spent in the setup process for a 2 hour test - Very • • low asset utilization. Millions of dollars in capital equipment only 15% to 20% utilized Wasted real-estate and power costs
  • 9. • Infrastructure Management • Live inventory, connectivity control • Test Equipment Resource Sharing • Integrated test environment design, reservation and scheduling • Device Provisioning • Automated base-lining procedures, device configuration • Test Automation • Automate manual test procedures • Test IP sharing, reuse, repeatability • Reporting and Documentation • Automated certification reporting and audit trail documentation • Reduced risk of non-compliance and real attacks
  • 10. • All resources are managed in a single repository • Tag devices according to user-defined parameters • Easily find the required type of device you need • Track and report device utilization
  • 11. • Draw the topology route requirement • No need to remember or lookup physical cabling • Actual connectivity is invisible to the end user • Manual and automated patching • Generate patching table reports and emails • Automatically control L1 Switches     MRV ONPATH Apcon Curtiss-Wright
  • 12. • Replace the static diagram with a live workspace • • • • • Drag & drop devices Draw required connections and activate Directly provision devices Power up and down devices Directly open CLIs to devices
  • 13. • Central calendar-based scheduling • Plan ahead lab operations • Resolve allocation conflicts • Locate device availability in a snap
  • 14. • Embedded integration with lab resources • • • • • • • Customize your own provisioning • • • • • Control interfaces GUI Scripts Leading testing vendors Custom drivers Third Party Apps No need to program Quick and standard reuse Simple graphical flowchart Easy device response analysis Examples • • • Automatic discovery Validate setup Nightly maintenance run Telnet, SSH, Web Services, Serial… Windows, Java, Web… TCL, Perl, Python, PowerShell… Ixia, Spirent, Shenick, MRV, ONPATH… NET, Exe, LabVIEW, ActiveX,… NMAP, iPerf, MSBA, WireShark, ….
  • 15. Test Automation Example--Looping NMAP test • Drag & Drop • Flow Chart Test • Easy parallelism • Tools • • • • • Wide spectrum Open architecture Add your own Standard use Share • • Assets Knowledge
  • 16. Compliance Tracking Dashboards and Reports • Dashboards • At a glance views of compliance • Real-time remote viewing for auditors • Custom Reports • Structured to match CIP reporting requirements
  • 17. Efficiency and Savings from Automating the Test Lab MANUAL AUTOMATED
  • 18. Lab Maturity Model • From CHAOS to COMPLIANCE • Effective and Efficient Lab Resources • Faster test cycles, Increased utilization, Improved value • Ensure compliance, protect the bottom line • Incorporate best test practices as part of the business model • Create Eco-System with Suppliers to Coordinate Testing • Shared tests, lab management practices
  • 19. Q&A

Notes de l'éditeur

  1. Our speakers today are:QualiSystems’ Vice-President of Marketing, Alex Henthorn-Iwane. Prior to joining QualiSystems, Alex was Vice-President of Marketing at Packet Design, Inc., a provider of network management software, and has 20+ years of experience in product management, marketing and technical roles at networking and security technology providers. For more information, please check out our website at qualisystems.com.Who is TSI? Briefly, TSI is Technical Systems Integrators, enterprise solution integrator specializing Test Lifecycle Management tools with over 27 years of doing business in North America. One of our speakers will be TSI’s Chief Technology Officer, Chuck Reynolds. Chuck is the founder and chief technologist at TSI, enterprise solution integrator specializing Test Lifecycle Management tools for over 27 years. Prior to founding TSI, Chuck was a senior Application engineer at Hewlett Packard and a lead Test Automation Engineer at Martin Marietta Aerospace, and has 30+ years of experience in product management and delivering technical solutions to leading edge customers in a variety of markets.And now, I’ll turn it over to you, Chuck.
  2. Chuck: (1:15)Thank you, Welcome to today’s webinar:As you heard in our introduction, I’ve been involved in test, engineering and QA labs most of my career, so I know first hand the pain, frustration and sometimes chaos that comes with your daily routines. In today’s webinar :We will review some of what is NERC and CIP Compliance Standards NERC came about after some disastrous failures in the power grid some years ago. Since then NERC has been quite busy ensuring that our power grid is reliable and secure for allNERC has developed a set of Critical Infrastructure Protection guidelines or standards that provided for a uniform standard across the companies involved in providing our power so that it remains secure and reliable for all.
  3. Chuck: (1:15)The CIP audit requirements have mainly been documentation and reporting standards around process verification and validation to date. There are many software packages and databases available that address these reporting standards that most Energy companies have adopted in one form or another. What’s new in the version 5 and most likely subsequent releases of the standards is the more detailed device standards which imply significant engineering effort to complete. Since these engineering efforts must drive the report generation and are likely to be repeated time and time again, there are significant costs associated with these typically manual engineering tasks that must be performed on the hardware devices in the test and production lab. Let’s take a look at some of these new tasks.
  4. Chuck: (1:15)**This is not trivial**These are just some of the new requirements found in the version 5 release. Most of these require a knowledgeable telecom or IT test engineer to manually perform and while these are critical tasks they are tedious and time consuming for test engineers to perform and require extensive provisioning and setup before the test can even begin. Allocating the topology, checking the baseline previous results, comparing against the baseline and the generating the reports necessary can occupy these valuable company resources and prevent them from focusing on more appropriate issues. Even non-CIP related testing can occur for things like new product interoperability testing and compatibility testing in these same labs with the same manual processes and extensive use of valuable company assets (Engineers and Devices).
  5. Chuck So what happens if you don’t make the commitment to ensuring these standards are not met? Not an option within the Energy Entities – this has to be addressed or the fines are substantial. So how can we tell if we are running our CIP and interoperability test lab(s) efficiently?
  6. Chuck **Narrative picture**--Alex try a shotJust take a look at your own lab and see if these items apply to your lab. Are your test engineers manually performing the tests and manually updating report spreadsheets and documents? If so, then there is an opportunity to automate and speed up your compliance testing and reporting efforts as well as decrease the costs and use of resources meeting the compliance requirements.
  7. Chuck Lack of automation for CIP Version 5 requirements creates compliance risk and wastethat can add up to significant losses to your entity. Manual processes are never a good thing because too often things can slip through the cracks. With CIP testing you cannot afford even a single failure due to human oversightsThen consider the capital and operating waste. Does expensive equipment sit around idle in your lab? Do you even know how often devices are being utilized in the lab? All that equipment powered up while not being used? On top of all of this, let’s not forget the real risk lurking behind CIP testing which is falling victim to a cyber security attack that results in down customer time. So what does it take to automate your CIP compliance testing – Let’s turn it over to Alex to discuss the ingredients of a Successful CIP Lab Automation.Alex?
  8. AlexIf you’re considering automation for your CIP compliance and pre-production test lab environment, you’ll want to look for a solution or architecture that can address some key points that we’ll cover in the following slides.
  9. Alex
  10. Alex
  11. Alex
  12. Alex
  13. Alex - you want to focus on the 3rd party apps here.
  14. Alex:Chuck – You have a technical use case of how automation can be applied to CIP cyber security testing—would you mind sharing about that?Chuck:Sure, this is right out of the CIP specification. Here’s an example of how you can dynamically check a large number of devices and profile all their ports to ensure there are no ports or services that shouldn’t be open on the collection of devices. The NMAP results can be validated and checked against previously run NMAP results to make sure that the CIP baseline is met regardless of software or firmware upgrades or just plain changes by users. The same thing can be done against software releases, password checking, baseline configuration validation across all of the devices in the lab. Alex:Now that the automation has run and the results are checked the data needs to be aggregated and used to generate compliance reports….
  15. Alex
  16. Alex
  17. Alex and Chuck