This month’s edition of Information Security magazine reveals that the North American Electric Reliability Council (NERC), the oversight body for the U.S.’s bulk electric systems, will unveil new compliance standards focused on procedural changes related to the protection of critical infrastructure.
According to the article, security managers at electric utilities will see the biggest change in the area of documentation. “Security managers will have to demonstrate that processes and procedures are in place, policies are enforced, and assets are tracked. External and internal security audits will also become a way of life”, the story states.
Lynn Constantini, NERC chief information officer, states, “As long as you have a good understanding… of your operational networks and commercial networks, and put controls in place…, that’s what is important.”
It is clear that if you are not currently faced with complying with a government regulation centered on protecting electronic data, you soon will. Taking the initiative now to invest in an automated solution for identifying, tracking and reporting on your critical configuration controls will not only save you from a costly manual exercise in the future, it will provide you with a more efficient IT operation today. Remember, it’s only a matter of time before it’s your turn anyway.
