The North America Electric Reliability Corporation (NERC) standards for Critical Infrastructure Protection (CIP-002 through CIP-009) carry heavy enforcement penalties for any entity that owns, operates, or uses any portion of the bulk power system. Fines for non-compliance are as high as $1M per day.
The NERC CIP requirements extend your Compliance obligations beyond the traditional approach dictated in SOX and other controls frameworks, with their focus primarily on Financial reporting and subsequent alignment to only the ERP logical systems.
Specifically the regulations extend your Compliance requirements into two areas that are unlikely to be covered by your current GRC software, namely Network security and Physical access controls.
You probably already have a set of individual products in place that address some of the discrete requirements, such as Network Firewalls and Virus monitoring software, but you are unlikely to have anything that allows you to comprehensively document, analyse and report on NERC/ CIP from a centralised viewpoint.
We can assist you in integrating your discrete solutions into an integrated Compliance solution, and have the expertise to help you selecting a software solution to pull together the parts into an integrated framework.
Where appropriate you may want to look at investing in the few solutions on the market that do address security across the Network, Logical and Physical levels, and follow this up with implementation assistance.
With our experience in implementing these solutions can leverage any work already performed to customise the delivered set of NERC/CIP Policies and Procedures, and allow you to quickly hit the ground running.