|
Standard
|
Summary of Requirements
|
Solutions
|
|
CIP-002-1 Critical Cyber Asset Identification
|
All network assets must be audited to identify Critical Cyber Assets. A risk-based assessment methodology should be utilized with annual reviews.
|
How does SecureWorks Help?
These requirements mandate the need to identify your Critical Cyber Assets through risk-based assessments of your network.
Using a risk-based methodology aligned with CIP requirements, SecureWorks’ Security and Risk Consulting team can help you regularly audit your IT systems and identify Critical Cyber Assets (CIP-002-1 R3).
- Security and Risk Consulting
|
|
CIP-003-1 Security Management Controls
|
Policies with adherence monitoring and change control must be documented and in place.
Change control policies and processes must be adhered to.
Definitions and documentation on access control levels for critical assets such as Internet facing systems and critical backend solutions. Solutions should be in place to mitigate risks.
|
How does SecureWorks Help?
These requirements mandate having minimum security management controls in place to protect Critical Cyber Assets.
SecureWorks’ Security and Risk Consulting team can evaluate your security management controls, identify gaps in your security management program and make recommendations for addressing any deficiencies (CIP-003-1 R1 through R6). We can also assess your security program to determine if CIP security policies are being followed in practice.
Additionally, our Managed Firewall and Managed NIPS/NIDS services provide full lifecycle device management, including change and configuration management. All changes are tracked and documented within the SecureWorks Portal, allowing you to easily demonstrate compliance with change control policies and procedures (CIP-003-1 R6)
- Managed Firewall
- Managed Intrusion Prevention and Detection
- Security and Risk Consulting
|
|
CIP-004-1 Personnel and Training
|
Employees should be trained on policies, access controls and general awareness issues around Social Engineering.
Background checks should be performed on all users with access to computer assets.
|
How does SecureWorks Help?
These requirements direct that personnel having authorized access (either cyber or physical) have an appropriate level of personnel risk assessment, training and security awareness.
SecureWorks’ Security and Risk Consulting team can review your personnel and training policies, identify areas of weakness and audit the practice of personnel and training policies.
- Security and Risk Consulting
|
|
CIP-005-1 Electronic Security Protection
|
An Electronic Security Perimeter should be established that provides the following:
- Disable ports and services that are not required
- Monitor and Log Access 24x7x365
- Perform Annual Vulnerability Assessments (at a minimum)
- Documentation of Network Changes
|
How does SecureWorks Help?
These requirements mandate the identification and protection of an Electronic Security Perimeter within which all Critical Cyber Assets reside. All perimeter access points are also must be identified and protected.
SecureWorks’ Security and Risk Consulting team can perform the required Annual Vulnerability Assessments, as well as help you identify your Critical Cyber Assets and evaluate your Electronic Security Perimeter to determine if it meets CIP requirements (CIP-005-1 R4).
Our Managed Firewall service removes the burden of firewall management by providing you with a 24x7x365 team of experts. Our firewall experts will audit policies to ensure they align with CIP requirements (CIP-005-1 R2), perform on-going rule-set changes and monitor these devices for any signs of attack.
SecureWorks’ Security Monitoring service can provide 24x7 monitoring of your network access points by certified security professionals (CIP-005-1 R3). Additionally, our Managed Security Services feature detailed web-based reporting through the SecureWorks Portal. This allows you to easily demonstrate compliance with CIP-005-1 requirements (R5).
- Managed Firewall
- Security Monitoring
- Security and Risk Consulting
|
|
CIP-006-1 Physical Security Program
|
Physical Security controls should be documented and implemented that provide perimeter monitoring and logging along with robust access controls. All cyber assets used for Physical Security are considered Critical and should be treated as such.
|
How does SecureWorks Help?
These requirements ensure the implementation of a physical security program which protects Critical Cyber Assets.
SecureWorks’ Security and Risk Consulting team can review your physical security controls, as well as perform physical security assessments, and make recommendations for areas of in need of improvement in regards to the CIP standards.
- Security and Risk Consulting
|
|
CIP-007-1 Systems Security Management
|
All methods, processes and procedures for securing Critical Assets and all technology solutions should be well-defined and include automated controls. System and network events should be monitored automatically with alerts sent to key personnel.
An annual vulnerability assessment should be performed.
|
How does SecureWorks Help?
These requirements call for the definition of methods, processes, and procedures for securing Critical Cyber Assets and non-critical Cyber Assets within the Electronic Security Perimeter.
SecureWorks’ Security and Risk Consulting team can provide the required annual vulnerability assessment of your Systems Security Management methods, processes and procedures (CIP 007-1 R8).
SecureWorks’ Security Monitoring and Security Information and Event Management (SIEM) services specifically address CIP 007-1 R6 which requires utilities to monitor system events that are related to cyber security (R6.1), maintain logs for ninety calendar days (R6.3, R6.4), and maintain records documenting that logs have been reviewed (R6.5)
Additionally, SecureWorks’ Managed NIPS and Managed HIPS services detect, prevent, deter, and mitigate the introduction, exposure, and propagation of malware (CIP-007-1 R4).
- Managed Intrusion Prevention and Detection
- Managed Host Intrusion Prevention
- Security Monitoring
- SIM On-Demand
- Security and Risk Consulting
|
|
CIP-008-1 Incident Response and Reporting
|
All cyber security incidents should be addressed by an internal computer incident response team (CIRT) and reported to the Electricity Sector Information Sharing and Analysis Center (ES ISAC).
|
How does SecureWorks Help?
This requirement mandates having a Cyber Security Incident Response Plan that addresses the classification, response and reporting of Cyber Security Incidents related to Critical Cyber Assets.
SecureWorks’ Security and Risk Consulting team can work with you to develop your Incident Response Plan and ensure that it exceeds minimum CIP requirements for classification, response, reporting and documentation as indicated in CIP-008-1 R1 and R2.
Also, SecureWorks’ Managed Security Services help you identify, classify and respond to security incidents. Our certified security professionals provide 24x7x365 enterprise-wide security monitoring and escalation to prevent and respond to security incidents.
- Managed Firewall
- Managed Intrusion Prevention and Detection
- Managed Host Intrusion Prevention
- Security Monitoring
- SIM On-Demand
- Security and Risk Consulting
|
|
CIP-009-1 Disaster Recovery
|
A disaster recovery plan should be created and tested with annual drills
|
How does SecureWorks Help?
This requirement calls for having a recovery plan(s) in place for Critical Cyber Assets. These plans should follow established business continuity and disaster recovery techniques and practices.
SecureWorks’ Security and Risk Consulting team can audit your recovery plans to identify any gaps that should be addressed in order to successfully backup and restore Critical Cyber Assets (CIP-009-1 R4).
- Security and Risk Consulting
|