Securing the Power Grid: Electric Light & Power and Utility Automation & Engineering T&D
SITE
SEARCH:



August 28, 2007

John Powers, Associate/Online Editor Security is a good foundation

Welcome to the Securing the Power Grid Newsletter! This is the first edition of our new quarterly electronic-newsletter that will keep you informed and up-to-date on everything you need to know about securing the nation's power grid.

Many things probably monopolize your utility's attention on a day-to-day basis, like increasing demand, power sags, and reliability. But taking care of those things wouldn't be possible if you didn't have a good foundation of security. So you'll want to pay attention to the articles we've collected here.

Tyler Williams, CEO of Wurldtech Security Technologies, issues a call to action in our first feature, urging the power industry to address cyber security threats. The next two features are useful check lists of a sort you can go through and see if your utility is looking at the right points of attack. Also, you may have already listened to the second episode of Currents, but we've included it here. In episode 2, we spoke with NERC's CEO and he gave a run down of NERC's cyber security standards. So if you have any questions about the standards, just click on that feature and get your answers straight from the boss.

As you can see, there's more to dive in to below and I'm going to let you get to it. I hope you enjoy the first edition of the Securing the Power Grid Newsletter. Don't hesitate to email me and let me know what you think.

Thank you for reading.

John M. Powers, online editor
jpowers@pennwell.com



Electric Light & Power
:: Home page
:: Current issue
:: Advertising info
:: Events of interest

Utility Automation
:: Home page
:: Current issue
:: Advertising info

DistribuTech
:: DistribuTECH home
:: Sponsorships
:: Call for Papers
:: PennWell Books

Energy Research
& Data
:: Statistics & Data
:: Industry Directories
:: Research Reports
:: Data for GIS
:: Maps & Atlases



PennEnergyJOBS
Job Quick Search
Commercial Project Administrator
San Jose, California SunWize Sat, 07 Nov 2009 04:34:39 -0800...

Sr. Project Manager
SunWize Sat, 07 Nov 2009 04:28:13 -0800...

Supervisor - Electrical/I&C Systems
Crystal River, FL Progress Energy Tue, 20 Oct 2009 05:00:00 -0700...

Capital Projects Procurement Specialist
Whiting, In BP Mon, 21 Sep 2009 05:00:00 -0700...

Electrical Engineer
SunWize Fri, 06 Nov 2009 23:40:01 -0800...



Contents

Feature Articles
  • Browns Ferry: Addressing America's real cyber security threat
  • SCADA security: 14 obvious points of attack
  • Five areas of cyber security you may be overlooking
  • Questions about NERC's cyber security standards? Let NERC CEO Rick Sergel fill you in on Currents
  • Oncor uses nanotechnology to fight copper wire theft
  • Study: resilience would enable L.A. businesses to mute effects of terrorist-caused blackout
  • UTC encourages utilities to start now on NERC CIP compliance

New Products
  • SCADAForum
  • Risk Mitigation technology platform
  • Flexiguard fence system
  • GuardTrax


Feature Articles

Browns Ferry: Addressing America's real cyber security threat
While the threat of attack by terrorists wielding bombs requires some physical access to a facility, the reality is that the cyber security threat to critical infrastructure systems may be more urgent because it can be mounted via the Internet from any country in the world.

SCADA security: 14 obvious points of attack
To reduce the probability of a successful cyber attack on a utility’s SCADA system, steps must be taken to eliminate potential points of vulnerability. However, what are the points at which an attacker will concentrate, and what types of attacks can be used?

Five areas of cyber security you may be overlooking
The goals of a prudent control system cyber security program should be to help make the utility more secure, maintain and when possible, improve system reliability and availability, and meet regulatory requirements. Let’s address five areas that may be overlooked in establishing or maintaining a prudent cyber security program.

Questions about NERC's cyber security standards? Let NERC CEO Rick Sergel fill you in on Currents
Do you have questions about NERC's cyber security standards? Why not get answers from the boss? In an exclusive interview, NERC president and CEO Rick Sergel discusses NERC's cyber security standards, the threat cyber attacks pose to utilities, and how NERC has adopted the goal of having "zero" events like the 2003 blackout.

Oncor uses nanotechnology to fight copper wire theft
Oncor Electric Delivery will use nanotechnology designed to discourage would-be criminals from stealing copper and help authorities find and prosecute thieves. The technology, which is invisible to the naked eye, marks Oncor equipment and particularly copper wire so that it can be identified after it has been stolen.

Study: resilience would enable L.A. businesses to mute effects of terrorist-caused blackout
Various forms of resilience would give Los Angeles County electricity customers the ability to mute the potential shock to their businesses of a terrorist-caused blackout by as much as 86 percent, study claims.



UTC encourages utilities to start now on NERC CIP compliance
Entities responsible for NERC compliance face a number of obstacles in their efforts to address cyber security: manpower is limited and utilities and transmission companies must prioritize work that keeps electricity flowing. But, utilities have no choice but to establish compliance programs now if they are going to be ready for NERC audits.

New Products
SCADAForum
Control Microsystems, a developer of advanced RTU/PLCs, SCADA host software, and intelligent sensors, announced the availability of SCADAForum, an interactive, virtual meeting place for Control Microsystems' customers and the SCADA industry. Leveraging the company's technical experience, SCADAForum offers threaded discussion groups, a powerful search engine and a technical resource library. SCADAForum contains detailed technical information and tips that will guide users along their development path. Moderated by CMI's technical staff, the virtual community enables users to freely discuss SCADA topics, applications, and experiences. Customers and SCADA users in general who wish to exchange ideas, product applications, and product feedback are invited to sign up for the free online service.
Control Microsystems
Visit the website to learn more.

Risk Mitigation technology platform
Driven by the exponential growth in malware incidents, malicious attacks by hackers, the increased threat of cyber-terrorism, and the substantial impact of insider attacks, organizations are seeking an effective means of protecting critical infrastructure systems. The Industrial Defender Risk Mitigation technology platform is an integrated Cyber Risk Protection technology designed specifically to monitor and protect both new and legacy real-time process control an SCADA systems. The Industrial Defender Risk Mitigation technology suite offers comprehensive security protection with the following components: security event monitoring; firewalls; unified threat management; network intrusion detection system; host intrusion detection system; and simple network management protocol. Each layer of the solution is built to accommodate and leverage the unique functional, performance and operational needs of real time process control and SCADA environments. The management console, network sensors and perimeter protection products are delivered pre-installed on computing hardware, while other elements of the solution are included in software. Industrial Defender professional security experts and their partners provide complete installation, customization and training services for your solution which will help to minimize deployment time and maximize cyber security protection.
Industrial Defender
Visit the website to learn more.

Flexiguard fence system
The Flexiguard fence system from Advanced Perimeter Systems Ltd. consists of a sensor cable which is attached to your existing or new security fence. It follows the contours of the perimeter so there is no loss of site usage. The Flexiguard fence system provides perimeter detection by detecting the intruder before they enter your property. This gives the alarm receiving center an early warning of an attack on your property. The Flexiguard sensor cable is fitted to new or existing fences using UV resistant cable ties or UV resistant plastic extrusion. It can be fitted to all metal security fences such as, chain link, weldmesh and palisade. Due to the technology used in the Flexiguard analyzer a high detection rate is achieved. The system can be used as stand-alone detection or as par t of an integrated system using CCTV cameras or Access control. The analyzer can trigger the camera control to move the camera to view the alarmed zone. Finally, the Flexiguard analyzer has an audio output facility allowing an operator in an alarm receiving center, or a guard on site to listen in to the interference on the fence created by an attack.
Advanced Perimeter Systems Ltd.
Visit the website to learn more.

GuardTrax
The new GuardTrax, from NovaTracker, is an end-to-end solution that allows security managers and supervisors to track, monitor and manage their field security personnel in real-time. GuardTrax acquires and sends real time GPS information on security officer location, activities and movements and makes them available for end users simply by logging onto an intuitive web interfaced program from any web browser. The GuardTrax Security Force Locator personal GPS tracking device, and the web program which utilizes GIS mapping and satellite imagery, is designed specifically to monitor and manage field level security personnel. GuardTrax also incorporates a SmartResponse system which will notify security managers of deficiencies, troubles, or incidents that their security officers might be encountering while on duty. With non-movement alerts, geo-fencing, and incident reporting capabilities, abandoned posts, sleeping guards and unproductive shifts will be virtually eliminated.
NovaTracker
Visit the website to learn more.






Electric Power Books

PennWell’s electric power books cover every aspect of the energy industry! We offer a complete line of business and nontechnical books for sales and marketing professionals, as well as technical titles for engineers. Our experts include Richard Baxter, Denise Warkentin-Glenn, and Tim Shaw. Shop our online bookstore here.


SUBSCRIPTION INFORMATION

To report distribution problems with this newsletter, send an email to: news@elp-media.com

Electric Light & Power and Utility Automation & Engineering T&D invites you to forward this newsletter to colleagues or associates who might be interested in our regular news summaries.

If you are a current subscriber, you can discontinue delivery of news from Electric Light & Power and Utility Automation & Engineering T&D e-newsletter by clicking this link:
@{confirmunsubscribelink:elp-media.com}@

You can also reply to the original e-mail and type "Unsubscribe" in the subject line. Or, if you prefer, you can write to us at:
PennWell Corporation
c/o E-mail Unsubscribe
1421 South Sheridan Road
Tulsa, OK 74112

If you do not subscribe to this newsletter and would like to receive it, please click this link: http://www.omeda.com/elp/

Electric Light & Power and Utility Automation & Engineering T&D subscribers may access complete current and archived stories online at: http://uaelp.pennnet.com/home.cfm?pc=ENL

Subscribers may access complete current and archived stories online by following these links: Utility Automation or Electric Light & Power




Copyright © 2007: PennWell, Tulsa OK; All rights reserved.