INTEGRATED RISK MANAGEMENT
SOLUTION BRIEF
Karta’s NERC compliance ecosystem Built on
kartacorp.com
Table of contents
Introduction Your comprehensive NERC Compliance Solution Partnerships that power excellence
GRC solution & expansion opportunities Third-party governance solutions IT & security risk management solutions Regulatory & corporate compliance management Audit management solutions Resilience management Enterprise & operational risk management solutions
Tenable OT Security CIP-003-5.1a CIP-003-8 CIP-004-6 R4 and R5 CIP-005-6 R2 CIP-006-6 CIP-007-6 CIP-008-6 CIP-009-6 CIP-010-4 R1, R2, R3
RSA Security CIP-004 access control CIP-007 authentication CIP-005 secure remote access
2 3 4
5 5 5 6 7 8 9
10 10 10 11 11 11 12 12 13 13
14 14 14 14
Introduction
Electric utilities today face increasing complexities in adhering to NERC compliance standards. Karta brings a GRC solution to simplify, streamline, and reinforce your NERC compliance operations. Powered by state-ofthe-art technology and aligned with industry-specific requirements, Karta offers unmatched efficiency and confidence in your NERC compliance journey.
At a glance Customized for NERC compliance Tailored software that understands the intricacies of NERC regulations.
Real-time reporting Obtain insights instantly for superior management decisions.
Automated compliance tasks Replace manual, error-prone activities with automated, precise operations.
Evidence repository Streamlined audits with organized, easily accessible evidence.
Achieve NERC compliance excellence
STRATEGIC PARTNERS WITH
Karta’s NERC solution is built on Onspring, the awardwinning GRC platform. Onspring is trusted by hundreds of large enterprises worldwide, including government and utility clients in North America to help manage multiple dimensions of risk in a single platform.
2
Your comprehensive NERC compliance solution Karta's GRC platform isn't just another compliance software. It was created with the intrinsic details of NERC regulations in mind to ensure a fit that feels custom-built for electric utilities. Imagine replacing the tediousness of manual, error-prone activities with a system that seamlessly integrates compliance tasks into daily operations. With Karta, that's a reality. Its automated functionalities mean that incomplete tasks or oversights are a thing of the past, with the system ensuring accountability through automatic escalations. Our solution doesn't just stop at automating tasks. Customized dashboards provide electric utilities with a complete understanding of their compliance posture. This heightened visibility ensures proactive measures, always keeping you a step ahead in your compliance journey. Furthermore, Karta's virtual evidence repository streamlines audit processes. No more stress-filled nights before audits; with all evidence organized and instantly accessible, audits are a smoother, more efficient endeavor. This powerful solution has many huge benefits: Monitoring of all NERC regulatory changes Making you audit-ready Managing recurring tasks Managing potential risk areas And these strengths are magnified by strategic partnerships with other industry experts and associations. All Karta solutions can be implemented when you need arises, and at your own pace.
Redefining the NERC compliance landscape Karta isn't just about compliance—it’s about mastering it. By providing electric utilities with a fusion of state-of-the-art technology, industry-specific customizations and the strength of strategic partnerships, Karta is the gold standard in NERC compliance management. Choosing Karta sets you on a transformative NERC compliance journey underpinned by clarity, efficiency, and confidence.
3
Partnerships that power excellence
Onspring The Karta NERC Compliance Management Solution is built on the industry-leading GRC platform, Onspring. Because of the modularity of Onspring, we can integrate our NERC compliance solution with many other use cases that are key to the electric utility sector, such as risk, audit and asset management.
Tenable Pairing with Tenable provides a holistic approach to OT infrastructure management. From a unified dashboard view of all assets to proactive compliance measures, Tenable OT Security offerings are comprehensive. The emphasis on detailed asset insights means vulnerabilities are always in the spotlight, ready to be addressed. This partnership ensures centralized policy management, heightened situational awareness, and efficient tracking of network changes.
RSA Security Partnering with RSA Security provides utilities with the ability to take advantage of two-factor authentication (2FA) and multifactor authentication (MFA). This level of user security can help organizations in the energy sector meet the requirements of the North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards.
4
GRC ecosystem expansion opportunities
Third-party / vendor risk CIP-013-2 – CYBER SECURITY – SUPPLY CHAIN RISK MANAGEMENT This standard requires responsible entities to have processes in place to manage cybersecurity risks from their supply chain, making the Onspring solution's third-party risk management and security risk monitoring particularly relevant. CIP-011-2 – CYBER SECURITY – INFORMATION PROTECTION Even though this standard primarily deals with protecting BES cyber system information, if third parties have access to this data, monitoring their adherence to information protection standards becomes essential. CIP-005-6 – CYBER SECURITY – ELECTRONIC SECURITY PERIMETER(S) This standard touches on remote access, and if third parties require remote access, then monitoring their security controls and protocols becomes vital. FAC-014-2 – SYSTEM OPERATING LIMITS METHODOLOGY FOR THE PLANNING HORIZON If third parties are involved in establishing system operating limits, their methodologies and practices would need oversight.
Risk management CIP-002-5.1A – BES CYBER SYSTEM CATEGORIZATION Onspring's capability to determine which assets are critical aligns with this standard's requirements for identifying and categorizing BES cyber systems. CIP-003-8 – SECURITY MANAGEMENT CONTROLS The IT & security policy program management use case can support the documentation and management of cyber security policies required by this standard. CIP-005-6 – ELECTRONIC SECURITY PERIMETER(S) The solutions focus on detecting and responding to attacks. Combined with the cyber incident & breach response use case, the solutions support the requirements for electronic access monitoring and logging.
5
CIP-007-6 – SYSTEMS SECURITY MANAGEMENT Several use cases, including IT security vulnerabilities program and IT controls assurance, can aid in the security management of BES cyber systems, from vulnerability assessments to patch management. CIP-008-6 – INCIDENT REPORTING AND RESPONSE PLANNING The cyber incident & breach response use case is directly aligned with this standard's requirements to identify, classify, and respond to cyber security incidents. CIP-009-6 – RECOVERY PLANS FOR BES CYBER SYSTEMS The solution's focus on identifying and remediating security deficiencies supports this standard's emphasis on recovery plans for BES cyber systems. CIP-011-2 – INFORMATION PROTECTION The features provided by Onspring, such as documenting and communicating security policies and the information security management system, support the requirements for information protection. EOP-004-4 – EVENT REPORTING Onspring's cyber incident & breach response could assist utilities in the structured reporting of incidents, ensuring that significant events are documented and reported as per this standard. EOP-008-2 – LOSS OF CONTROL CENTER FUNCTIONALITY Onspring's capabilities to detect and respond to IT-related incidents can be instrumental in preparing for and managing scenarios where control center functionality is compromised. PRC-005-6 – PROTECTION MAINTENANCE AND TESTING While primarily focused on physical maintenance and testing, the structured approach of Onspring's IT risk management might offer utilities methodologies that can be applied in the context of this standard.
Regulatory change CIP-003-8 – SECURITY MANAGEMENT CONTROLS The policy program management and controls assurance program management use cases align directly with the need to have cyber security policies and procedures in place and ensure they are aligned with regulatory requirements. CIP-008-6 – INCIDENT REPORTING AND RESPONSE PLANNING The system's comprehensive regulatory compliance functionalities can help ensure timely and compliant reporting of cyber security incidents. CIP-009-6 – RECOVERY PLANS FOR BES CYBER SYSTEMS The systematic review and approval processes supported by the solution can aid in ensuring recovery plans are updated in line with regulatory changes. PER-005-2 – SYSTEM PERSONNEL TRAINING The solutions focus on aligning policies with compliance obligations and can assist utilities in ensuring their training programs are up to date with regulatory requirements.
kartacorp.com
6
PRC-005-6 – PROTECTION SYSTEM MAINTENANCE AND TESTING The capabilities of Onspring to document and track regulatory obligations can ensure that maintenance and testing activities align with to document and track regulatory obligations can ensure that maintenance and testing activities align with NERC requirements.NERC requirements. EOP-004-4 – EVENT REPORTING The corporate obligations management feature can help ensure that utilities remain compliant with event reporting regulations. PRC-019-2 – COORDINATING OF GENERATING UNIT OR PLANT CAPABILITIES, VOLTAGE REGULATING CONTROLS, AND PROTECTION As this standard relates to coordination and controls, the controls assurance program management and financial controls monitoring features can be leveraged to ensure compliance. PRC-024-3 – GENERATOR FREQUENCY AND VOLTAGE PROTECTIVE RELAY SETTINGS The ability of the solution to manage controls and monitor their performance can aid utilities in ensuring that relay settings are compliant with this standard.
Audit management For all the NERC standards, the following features are available through Karta's partnership with Onspring. RISK-SCOPED AUDITS NERC CIP and O&P compliance areas are vast. With Onspring, audits are scoped based on risk, ensuring that high-risk areas, be it in operations, planning, or critical infrastructure, are audited with the depth they require. This ensures resources are efficiently allocated and critical compliance areas are effectively covered. STREAMLINED ISSUE MANAGEMENT Onspring's issues management use case is invaluable for utilities. Given the operational complexity of utilities, findings from NERC CIP and O&P audits can be numerous. Onspring ensures these findings are mapped to the corporate structure, ensuring clear accountability. This clarity ensures that remediation plans are both actionable and targeted. AUDIT CONSISTENCY The audit engagements & workpapers use case ensures a consistent audit process across the utility. This is especially crucial for utilities that may operate across various regions or have multiple facilities. Consistency ensures that NERC CIP and O&P compliance standards are uniformly applied and audited. PROACTIVE AUDIT PLANNING The audit planning and quality use case not only aids in planning but also ensures that the right personnel are on the right audits. Given the specialized nature of utility operations, ensuring that auditors with the right expertise are on the appropriate audits is crucial. Furthermore, for compliance areas that might undergo updates or revisions, such as NERC standards, proactive planning ensures the utility is always prepared.
7
5
Tenable OT Security
CIP-002-5.1A Tenable OT Security offers an automated solution to effectively manage and secure operational technology devices in line with the NERC CIP-002-5.1a standard. Key to cyber security is the mantra, "You can't secure what you don't know exists." Addressing this principle, Tenable OT Security can automatically discover, map, and maintain an updated inventory of all OT devices in a network, including dormant ones and crucial details like firmware versions and serial numbers. Tenable OT Security aids in the identification of devices that align with NERC's definition of a cyber asset, providing a comprehensive list of potential cyber assets, which helps utilities pinpoint their BES cyber systems. Even for low-impact plants where full identification might not be mandatory, Tenable OT Security assists in understanding the types and quantities of BES cyber systems present, streamlining the creation of a network diagram. This automated approach supersedes the need for complex manual processes, ensuring efficient and error-free asset management essential for compliance with NERC CIP-002-5.1a. CIP-003-8 Within the Karta ecosystem, Tenable OT Security plays a pivotal role in ensuring the stringent compliance demands of NERC CIP-003 are not only met but surpassed. The OT landscape is dynamic, and any unauthorized access can lead to significant vulnerabilities. Addressing this, Tenable OT Security offers realtime alerting capabilities for any unauthorized OT environment activities, thereby fortifying the defense mechanisms. But Tenable OT Security's capabilities extend beyond just real-time alerting. It's instrumental in the proactive enforcement of security management policies, providing an additional layer of protection. The intricate world of OT activities, be it controller engineering tasks such as logic updates, firmware management, or configuration changes, requires meticulous monitoring. Tenable OT Security stands out in this arena, offering full-scope auditing of all these operations. Every single activity, from its origin, the precise commands deployed, the devices it affects, to its specific impact, is meticulously tracked. By attaching timestamps to each operation, Tenable OT Security ensures traceability, which is critical for accountability and responsibility assessment. Such an exhaustive audit trail isn't just about tracking; it's a robust tool that empowers grid owners and operators to pinpoint, prevent, and counteract malicious or accidental activities that might jeopardize plant operations. In synergy with the Karta ecosystem, Tenable OT Security exemplifies how state-of-the-art OT security measures can seamlessly integrate into a holistic risk management framework, offering utilities unparalleled clarity, control, and compliance assurance.
10
CIP-004-6 R4 and R5
CIP-004-6 R4 and R5 Tenable OT Security emerges as a foundational pillar for electric utilities striving to ensure compliance with the access management and revocation requirements of NERC CIP-004-6 R4 and R5. At its core, security and immediate response to potential threats are paramount. Given that controllers like PLCs inherently lack robust access control measures, Tenable OT Security bridges this security gap with its patented technology. Real-time notification is crucial in an age where timely detection and response can mean the difference between regular operations and a potential grid catastrophe. Tenable OT Security ensures that utilities are immediately informed of unauthorized access attempts to controllers, or any suspicious changes made to controller logic. By enabling utilities to establish access policies, Tenable OT Security offers a two-fold security measure: it deters unauthorized entities from accessing controllers, and even if an authorized individual breaches policy by, for instance, altering controller logic, alerts are immediately sent out. Moreover, Tenable OT Security's unique approach of performing daily scans on each controller and downloading its configuration file adds another layer of security. By contrasting these files with previous versions and highlighting changes, utilities can swiftly detect and act upon unauthorized modifications. This proactive detection and alerting mechanism, which surpasses the capabilities of conventional anomaly detection systems, bolsters a utility's defense against potential vulnerabilities and positions Tenable OT Security as an invaluable asset in ensuring adherence to NERC CIP-004-6 R4 and R5. CIP-005-6 R2 Tenable OT Security plays a pivotal role in strengthening the security of OT infrastructures, particularly when it comes to monitoring remote access, a vital aspect of NERC CIP-005-6 R2 compliance. The platform actively identifies and chronicles any form of remote access to OT assets. More critically, should such access be newly initiated, unauthorized, or both, Tenable OT Security promptly sends real-time alerts complete with comprehensive connection details. This quick alert mechanism allows security personnel to promptly identify potential perimeter breaches, ensuring the consistent safety of the system. Beyond the already recognized controls on interactive remote access, it's noteworthy that the CIP-005 R2.4 provision, introduced in 2019 alongside CIP-013 (the new supply chain security standard), mandates NERC entities to proficiently identify and oversee not only interactive remote access sessions but also machine-tomachine ones. Tenable OT Security stands out in its capability by offering these real-time alerts for both types of remote accesses, ensuring utilities are always a step ahead in monitoring and maintaining their OT infrastructure in compliance with NERC standards. CIP-006-6 Tenable OT Security stands out in its unparalleled ability to detect changes made to controllers through direct physical access. Whether someone connects via a serial cable or a USB device, Tenable OT Security immediately identifies any modifications and promptly triggers an alert. Such a feature ensures heightened security by keeping the security personnel informed about any physical access to the device and the consequent changes made. This aids in rapid threat identification and mitigation, reinforcing the integrity of the OT infrastructure in line with NERC CIP-006-6 standards.
11
CIP-007-6 Tenable OT Security offers a robust suite of tools specifically tailored for bolstering security in line with NERC CIP-007-6. At its core, Tenable OT Security utilizes rule-based anomaly detection, allowing power generation owners or operators to tailor network policies based on their internal regulations or in anticipation of future NERC CIP standards. This deterministic approach ensures pinpoint accuracy with no false positives. For R1.1 (Ports and Services), Tenable OT Security proactively monitors and issues alerts about open and extraneous ports on vital devices. Beyond just monitoring, it also scrutinizes network traffic and flags any connections that breach the prescribed list of necessary ports. Addressing R3 (Malicious Code Prevention), Tenable OT Security stands vigilant against malevolent activities within the network. It can detect malware distribution, anomalous communications, and both indirect and direct attacks on controllers, ensuring real-time alerts for security staff to take swift action. Lastly, in alignment with R4 (Security Event Monitoring), Tenable OT Security is primed to: R4.1: Log all unauthorized electronic interactions on controllers in real time, thus facilitating instantaneous reaction to cybersecurity incidents and subsequent forensic examinations. R4.2: Generate real-time alerts for security breaches on controllers. For instance, if an unauthorized user accesses a controller or undertakes prohibited actions, immediate alerts ensure quick response. In essence, Tenable OT Security crafts a comprehensive security shield in line with NERC CIP-007-6, arming utilities with the tools to monitor, detect, and respond efficiently to myriad threats. CIP-008-6 Tenable OT Security is specifically engineered to bolster incident response strategies for OT networks, ensuring swift identification and action against potential cybersecurity threats. The platform achieves this through: 1. Proactive monitoring: Tenable OT Security issues real-time alerts upon detecting threats, unusual behavior, or unauthorized activities on OT devices. This immediate notification facilitates timely investigations to discern if a cybersecurity incident is unfolding. 2. Audit trail insights: Complementing its monitoring capabilities, Tenable OT Security maintains a detailed audit trail of all actions and modifications made to control devices. This documentation aids in determining the nature and severity of any detected anomalies. 3. Forensic support: In instances where deeper forensic analysis is warranted, Tenable OT Security's comprehensive audit trail becomes an essential resource, offering unparalleled visibility into OT operations and changes. Collectively, Tenable OT Security's features empower security teams with the tools they need to swiftly identify, delve into, and address cybersecurity incidents, ensuring a robust defense mechanism for OT networks.
12
CIP-009-6 Tenable OT Security is instrumental in ensuring efficient recovery planning, execution, and testing for OT infrastructures, aligning seamlessly with the mandates of NERC CIP-009-6. Comprehensive audit trails: Tenable OT Security meticulously logs all changes across devices in the OT landscape. This granular visibility ensures that any changes, discrepancies, or anomalies are recorded, serving as a foundational resource for recovery planning. Backup and storage support (CIP-009 R1): Leveraging its patented active querying feature, Tenable OT Security consistently captures a controller's baseline configurations and activities. This allows the system to uncover device properties and alterations that might remain undetected over standard network surveillance. It retains historical baselines of devices to allow for backup and recovery. Tenable OT Security's capabilities are pivotal for utilities to meet and exceed the NERC CIP-009-6 standards. It enables emphasizing quick, reliable recovery and configuration control. CIP-010-4 R1, R2, R3 Tenable OT Security stands out with its real-time alerting and comprehensive monitoring capabilities, which align closely with configuration and vulnerability mandates. Here are its key features: Comprehensive audit trail: Tenable OT Security offers an exhaustive record of all OT control device activities. This includes noting alterations in a controller's logic, whether initiated over a network or via direct physical access. Such real-time alerts empower utilities to address and comply with configuration monitoring mandates. Up-to-date vulnerability monitoring: Tenable OT Security maintains an always-current inventory of software and firmware versions on controllers. By cross-referencing this with a list of known vulnerabilities (using NVD Data), Tenable OT Security can proactively notify users about potential vulnerabilities specific to their devices. Moreover, its integration with other Tenable platforms ensures a centralized view and response mechanism for cyber exposure and risk scenarios. Configuration change management (CIP-010 R1): Tenable OT Security automates the process of setting a controller's baseline configuration and perpetually oversees any deviations from this. Users are instantly informed about all changes, and security personnel receive alerts about unsanctioned changes, bolstering both security and audit readiness. Configuration monitoring (CIP-010 R2): With a requirement to monitor every 35 days for deviations from the baseline, Tenable OT Security simplifies this by auto-detecting and alerting on any configuration shifts. This not only enhances efficiency but also ensures prompt reactions to unauthorized modifications. Vulnerability assessments (CIP-010-2 table R3): Tenable OT Security adopts a dual methodology of passive network surveillance and active querying to deliver a comprehensive vulnerability evaluation of devices. It generates a precise risk score, lists open ports, and offers an up-to-date risk perspective not merely based on "last seen traffic." When a solely passive assessment is needed, the platform gleans insights from network traffic, though it may not capture changes made via direct connections like serial cables. Assessment documentation: Eliminating manual effort, Tenable OT Security automatically crafts an intricate vulnerability assessment report. This ensures users get accurate, timely insights, rather than relying on potentially outdated manual reports. In a nutshell, Tenable OT Security presents an advanced solution for utilities, offering both configuration monitoring and vulnerability assessment capabilities, ensuring both security and compliance with regulations. 13
RSA Security
Two-factor authentication (2FA) or multifactor authentication (MFA can help organizations in the energy sector meet the requirements of the North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards. NERC CIP standards are designed to ensure the security and reliability of the electrical grid, and they include access control and authentication requirements. Here's how 2FA/MFA can assist in meeting NERC CIP requirements: CIP-004 ACCESS CONTROL NERC CIP requires organizations to implement access controls to protect critical cyber assets. 2FA/MFA adds a layer of security beyond just username and password, making it more difficult for unauthorized individuals to gain access to critical systems and data. RSA also provides role-based access control (RBAC) for end users. CIP-007 AUTHENTICATION NERC CIP specifies requirements for strong user authentication. 2FA/MFA satisfies these requirements by requiring users to provide two or more authentication factors, such as something they know (password), something they have (smart card or token), or something they are (biometric data like fingerprint or retina scan). CIP-005 SECURE REMOTE ACCESS Many utilities and energy companies need to provide remote access to maintain and monitor critical systems. Implementing 2FA/MFA for remote access ensures that only authorized personnel can access these systems, reducing the risk of unauthorized access and cyberattacks. Electronic security perimeters: 2FA/MFA can be used to strengthen security around electronic security perimeters by requiring multiple authentication factors to access these critical areas. By implementing 2FA/MFA, organizations can significantly strengthen their security posture, reduce the risk of unauthorized access, and enhance their ability to comply with NERC CIP requirements. However, it's important to note that NERC CIP compliance involves a holistic approach to cybersecurity, and 2FA/MFA is just one of many security measures that need to be implemented to meet the standards.
14
Get started
Request a live personalized demo Get a close look at Karta’s NERC Compliance Management Solution & get your questions answered live. REQUEST A LIVE DEMO
Speak with a solution specialist EMAIL US
USA (770) 631-5988 Canada (416) 342-0813
kartacorp.com
231211