Tripwire has released the results of a survey on North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) compliance and found that NERC CIP compliance is severely lacking.
“Based on these results, only 30 percent of the industry feel they lack a clear understanding of the standards,” said Patrick Miller, partner and managing principal at The Anfield Group, a critical infrastructure security and compliance consultancy.
“In reality, I think that number is higher. After we dig into the details and actually start implementing and auditing NERC CIPv5, I suspect many will realize their initial degree of understanding was overly optimistic.”
Key findings include:
- 70 percent believe they have a clear understanding of all the current NERC CIP requirements.
- 77 percent believe NERC CIP compliance is necessary to ensure the cybersecurity of the Bulk Electric System.
- 70 percent, however, do not believe that NERC CIP compliance is sufficient to ensure the cybersecurity of the Bulk Electric System.
“It is encouraging that a majority of respondents acknowledge the value of NERC CIP compliance and the key role it plays in energy cybersecurity,” said Jeff Simon, director of service solutions for Tripwire.
“Most respondents also acknowledge that NERC CIP compliance alone is not sufficient to ensure cybersecurity – they know compliance is just the start of an effective cybersecurity strategy.”
Tripwire has helped more than 140 registered entities achieve and maintain NERC CIP compliance since 2008, and continues to invest in tools and processes that automate and simplify NERC CIP compliance.
The online survey was conducted from July through September 2013 and evaluated the attitudes of more than 100 IT professionals involved with NERC CIP compliance.
For more information about this survey, please visit: https://www.tripwire.com/company/research/update-nerc-survey-data/.
- Adam Meyer on Implementing the Cyber Security Framework
- Don’t Reinvent the Wheel: Phil Agcaoili on the Cyber Security Framework
- NIST: It’s Time to Abandon Control Frameworks as We Know Them
- NERC CIP Version 5: One Giant Leap
P.S. Have you met John Powers, supernatural CISO?
Title image courtesy of ShutterStock