Supply Chain Standards
Compliance Essentials
Lew Folkerth, Principal Reliability Consultant Monthly Compliance Call May 20, 2019
Supply Chain Standards Compliance Essentials Lew Folkerth, - - PowerPoint PPT Presentation
Supply Chain Standards Compliance Essentials Lew Folkerth, Principal Reliability Consultant Monthly Compliance Call May 20, 2019 Overview Origin: FERC Order 829 Objectives Standards Software integrity and authenticity
Compliance Essentials
Lew Folkerth, Principal Reliability Consultant Monthly Compliance Call May 20, 2019
Forward Together • ReliabilityFirst
‒ Supply Chain Risk Management
‒ Vendor Remote Access
‒ Software Authenticity
authenticity
procurement controls
NOT Vendors
2
Forward Together • ReliabilityFirst
Cyber Systems (EACMS pending per Order 850)
Procurement
‒ Six areas required to be addressed
months) thereafter
3
Forward Together • ReliabilityFirst
vendor remote access sessions
‒ Interactive ‒ System-to-system
sessions in near-real-time
“disable” vendor remote access
in order to prevent unauthorized
4
Forward Together • ReliabilityFirst
‒ Operating systems or firmware ‒ Commercially available or open- source software ‒ Security patches
source
5
Forward Together • ReliabilityFirst
https://www.nerc.com/FilingsOrders/us/FERCOrdersRules/Order_Suppl yChain_20160721_RM15-14.pdf
https://www.nerc.com/FilingsOrders/us/NERC%20Filings%20to%20FER C%20DL/Petition%20Supply%20Chain%20Risk%20Management%20Fi ling.pdf
https://www.nerc.com/FilingsOrders/us/FERCOrdersRules/E- 2_NOPR%20on%20Supply%20Chain.pdf
https://www.nerc.com/FilingsOrders/us/FERCOrdersRules/Order%20No .%20850%20Supply%20Chain%20Risk%20Management%20Reliability %20Standards.pdf
https://www.nerc.com/comm/Pages/Reliability-and-Security- Guidelines.aspx
Tom.Hofstetter@nerc.net
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80 0-30r1.pdf
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80 0-39.pdf
Practices:
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800- 161.pdf
https://www.nerc.com/pa/comp/guidance/Pages/default.aspx
https://rfirst.org/KnowledgeCenter/Risk%20Analysis/CIP/ https://rfirst.org/KnowledgeCenter/Risk%20Analysis/CIP/CIP%20Library/0 %20-%20Lighthouse%20Supply%20Chain%2029-31.pdf
https://rfirst.org/ProgramAreas/EntityDev/AssistVisits/Pages/AssistVisits.a spx 6
Forward Together • ReliabilityFirst