Critical Infrastructure Protection (CIP) relates to the preparedness and response to serious incidents for the overall critical infrastructure. For the past several years, NERC CIP reliability standards have moved up in position as some of the most violated standards. At SOS Intl, our NERC CIP services encompass Decision Directive 63 and a broad range of solutions that assist with existing as well as emerging challenges within the energy industry.
Using a three phased approach, our SOS Intl consultants individually customize each NERC CIP project taking into account the number of facilities as well as registration types. Our consultants take a risk-based approach to addressing NERC CIP compliance requirements while monitoring Smart Grid interoperability and other technological developments in the energy industry. Our three phased approach consists of:
- Assessing the governance, regulatory and compliance environment
- Developing and implementing a transformation plan
- Monitoring, reviewing and sustaining transformation
By first assessing the governance, regulatory and compliance environment, SOS Intl can provide multiple service options to support the NERC CIP compliance requirements such as:
- Audit Preparation
- Mock Audit
- Spot Checking
- Gap Analysis
- Self Reporting Assistance
- Self Certification
- NERC Data Submittals
- Critical Cyber Asset Identification
The second phase provides support in the development and enhancement of the Risk-Based Assessment Methodology required by NERC CIP-002 R1. We help tailor a set of NERC CIP compliant policies and procedures covering such topics as:
- Information Security Policy
- Logical Access Policy
- Physical Access Policy
- Systems Development Life Cycle Policy
- Change Management Policy
- Incident Handling Policy
- Disaster Recovery Plan
SOS Intl can also support enhancements in the IT security infrastructure in areas such as:
- Advanced Persistent Threat Evaluation
- Remote Access
- Encryption
- Single Sign-On
- Identity Management
- Logical Access and Provisioning
- SCADA/EMS Security
- Vulnerability Assessment
The last phase is to monitor, review and sustain transformation plans supporting the ongoing compliance activities of our clients. Our consultants use the SOS Intl
Compliance Tracking Tool (CTT) to provide a means for support to review policies and procedures, compliance activities throughout the audit period and maintenance of compliance documentation. Our
Managed Compliance Service (MCS) is designed to meet the need for an organization which must outsource various components of its compliance program.