NERC CIP Compliance Made Easy for the Entire Supply Chain
Choose a fully customizable solution for your Utility
Fortress Platform Enables CIP Automation via IRM
Compliance Management
Designed to enable utilities to reduce their O&M spend on compliance through automation, orchestration and predefined workflow templates that can be modified to reflect internal processes.
Implementation
Fortress Platform implementation services designed to quickly create a centralized, enterprise security management data repository and dashboard
Integration
A strength of Fortress Platform is its ability to flexibly ingest various sources of IT and OT data provide customized views of prioritized event data and alerts
Security & Compliance Combined
Integration Risk Management Core Components
Workflow & Automation
- Security nomenclature based on the MITRE ATT&CK Matrix (Q4 2020)
- Compliance Workflows – based on NERC CIP Standards and the NERC Evidence Request Tool
- Custom workflow integration based on internal policy and procedure language and controls structure
Asset & Vendor Management – CIP-002 Integration
- Asset Identification
- Asset Classification
- Asset Management & Monitoring
- CIP-013 Compliance Management
- 3rd Party Risk Management
- Enterprise Vendor Management
Threat Monitoring & Mitigation
- Fortress-tailorable workflow allows you to integrate your existing threat mitigation into the tool, enabling you fine-grain control over your identification, reporting and resolution cycles
- Respond to threats by assessing inventory to see if the threat is applicable and perform remediation
- Known vulnerabilities and threats analyzed against the inventory to determine susceptibility based on CVE/CWE/ICS vulnerability vs asset in inventory and presenting action to be performed
Vulnerability & Patch Management
- ICS/OT patch management & governance
- Baseline configuration for each in scope asset stored in AM Module
- Ports and services inventories tied to the AM Module
- Known vulnerabilities linked with each asset within the AM Module
- Using the A2V model, patch testing and validation services can be leveraged against other utilities using the same technology footprint for lower costs
- Using Scanning or OT management software to determine versions and susceptibility
- FP tracks compliance status for the NERC CIP program & remediation efforts
Compliance Management
- Presenting Compliance Artifacts in a manner consistent with NERC, FERC and Regions
- Heavy focus on Evidence Request Repository Consistency
- RSAW-based internal assessment reviews
- Compliance Performance Activity Dashboard – indicate where possible noncompliance is occurring in real-time
- Any compliance risk transfer will be coordinated with NERC and Regions prior to contract execution to maximize transparency in the process
- Compliance with CMMC
- Compliance with Executive Order and 889b
Access Management
- Integration with IDM and other access management platforms
- Tracing access rights in relation to CIP Applicable Assets and Compliance Artifacts
- Workflow templates designed to ensure access compliance traceability and artifact review activities
FORTRESS IN THE NEWS
Mixed Reactions on Looming DOE NOPR for Bulk Power System Security
The Department of Energy (DOE) will issue a notice of proposed rule-making (NOPR) to implement President Trump’s broad bulk power system (BPS) security executive order (EO) “later this fall,” a DOE official confirmed to POWER on Oct. 5. Though the...
Power Sector, Federal Entities Scramble to Close Supply Chain Security Gaps
Marking another major federal effort to address potential supply chain risks to the bulk power system (BPS), the Federal Energy Regulatory Commission (FERC) on Sept. 17 sought industry’s perspective on a number of important considerations,...
FERC investigates risk of foreign adversary-supplied bulk power equipment, with focus on Huawei, ZTE
If utilities are forced to pull suspect components from the grid then the cost implications could be significant, according to Tobias Whitney, vice president of energy security solutions at Fortress Information Security. The average utility could...
Get in touch
Want to find out how Fortress can solve problems specific to your business? Let’s connect.
Contact Sales
189 S Orange Ave #1950, Orlando, FL 32801
(407) 573.6800
sales@fortressinfosec.com
COPYRIGHT © 2019. FORTRESS INFORMATION SECURITY. ALL RIGHTS RESERVED. PRIVACY POLICY