Utility operators in the United States and Canada must keep pace with the evolving and stringent regulatory requirements of the North American Electric Reliability Corporation’s (NERC) Critical Infrastructure Protection (CIP) standards. Maintaining compliance with NERC CIP has now become even more crucial as standards become stricter and fines more costly, as evidenced by the $10 million fine that was recently issued, the largest public fine in NERC CIP’s history.
As Forescout designs and develops new product features, we always strive to further simplify compliance with threat detection, operational awareness and ICS cybersecurity requirements for NERC CIP. With the release of ICS Patrol, our optional selective scanning module, we’ve proven our commitment to innovation and operational excellence for utilities.
With ICS Patrol, utility asset owners can achieve a deeper level of visibility not accessible with passive monitoring alone. With this optional module, users can access a host of new tools to help manage compliance with the evolving NERC CIP requirements.
Below are just a few of the NERC CIP requirements that ICS Patrol helps manage:
- USER ACTIVITY – ACCESS MANAGEMENT PROGRAM
CIP-004-6 R4.2 and CIP-004 R4.3
Requirement (CIP-004-6 R4.2):
How ICS Patrol Helps:
Requirement (CIP-004 R4.3):
- SYSTEM INFORMATION – SECURITY PATCH MANAGEMENT
Requirement (CIP-007-6 R2.1):
How ICS Patrol Helps:
Many NERC CIP requirements mandate documentation to prove that an organization has been compliant not only at a single point in time, but also that they have been compliant throughout the audit period. The ability to easily generate documentation of compliance through regularly scheduled queries assists with the mitigation plan reporting process and enforcement of policy.
- CONFIGURATION CHANGE MANAGEMENT
Requirement (CIP-010-2 R2.1):
How ICS Patrol™ Helps:
The ability to automatically identify these changes using ICS Patrol™ helps organizations save time and money by verifying both the configurations and ensuring auditable documentation exists.
ICS Patrol is yet another advancement that offers more visibility, control and choice to our customers. Streamlining NERC CIP compliance efforts is just one of the many benefits that SilentDefense 4.0 offers our customers.
If you want to learn more about ICS Patrol and how it streamlines compliance efforts with this ever-changing and critical set of standards, check out our solution brief.