EspañolPortuguês

IT Governance, Risk and Compliance Management

Industries > Energy & Utilities > NERC

NERC

With the mission of improving the bulk power system reliability and security in North America, NERC - North American Electric Reliability Council, develops and reinforces standards to ensure the system reliability, monitors the bulk power system, defines future adaptations, audits owners, operators, and users for preparedness; educates and trains industry personnel.

In May 2006, NERC started to use Critical Infrastructure Protection (CIP), which establishes a framework with the minimum requirements needed to ensure reliability and improve IT infrastructure supporting the system. This is the Cyber Security Framework.

NERC - CIP has issued nine reliability standards on cyber security with the purpose of identifying and protecting critical cyber assets:

  • NERC - CIP 001 1 - Sabotage Reporting
  • NERC - CIP 002 1 - Cyber Security - Critical Cyber Asset Identification
  • NERC - CIP 003 1 - Cyber Security - Security Management Controls
  • NERC - CIP 004 1 - Cyber Security - Personnel & Training
  • NERC - CIP 005 1 - Cyber Security - Electronic Security Perimeter(s)
  • NERC - CIP 006 1 - Cyber Security - Physical Security of Critical Cyber Assets
  • NERC - CIP 007 1 - Cyber Security - Systems Security Management
  • NERC - CIP 008 1 - Cyber Security - Incident Reporting and Response Planning
  • NERC - CIP 009 1 - Cyber Security - Recovery Plans for Critical Cyber Assets

To help electric utility firms comply with the North American Electric Reliability Council’s Critical Infrastructure Protection (NERC CIP) standards, Modulo has developed a specific Knowledge base that allows companies to identify and manage the controls required by the standard.

Modulo Risk Manager helps inventory assets supporting the system infrastructure and storing them in a centralized repository, implements a process for risk assessment and provides suggestions to implement controls defined by NERC-CIP based on best practices. It also ranks assets and identifies most critical Cyber Assets, therefore helping actions and investments to be prioritized.

Modulo Risk Manager allows the organization manage risks and ensure compliance with all the standards defined by NERC CIP in an integrated and user friendly way, eliminating silos and reducing costs.

How can Modulo Risk Manager help your business?

  • Repository of evidences and audit support
  • Cyber assets inventory and repository;
  • Risk Analysis of system-related technological assets, individuals and environments;
  • Integration with the business continuity Plan, helping manage Cyber Asset recovery plans and supporting tests;
  • Producing Executive and Technical Reports;
  • Producing Risk Scorecard with indices and metrics;
  • Improving decision making and contributing to prioritize actions and financial resources
  • Providing a Geo-referenced Risks overview
  • Providing detailed recommendations to support implementation of controls
  • Providing a framework that enables future activity to take place in a consistent and controlled manner
  • Controls maintenance;
  • Providing self-assessment process;

Information

United States

311 Claremont Avenue,
Montclair, New Jersey 07042
Toll free: 866-663-5802
Phone: 973 744 1617


Europe

Switzerland
46, Ch. Grand Montfleury.
1290 - Versoix - Geneva
Phone: +41 22 755-1216


Research and Development Center

Brazil

Rua da Quitanda, 106 - 1°
e 2° andares
Centro - Rio de Janeiro - RJ
Zip Code: 20091-005
Phone: + 55 (21) 2206-4651
Fax: + 55 (21) 2206-4720
Modulo © Copyright - All rights reserved.