<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AssurX Blog&#187; Electric Reliability</title>
	<atom:link href="http://blog.assurx.com/tag/electric-reliability/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.assurx.com</link>
	<description>Compliance, quality and risk: Straight talk for regulated industries</description>
	<lastBuildDate>Thu, 09 Feb 2012 16:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The Next Steps to Prepare for NERC&#8217;s FFT Reporting</title>
		<link>http://blog.assurx.com/2011/10/17/the-next-steps-to-prepare-for-nercs-fft-reporting/</link>
		<comments>http://blog.assurx.com/2011/10/17/the-next-steps-to-prepare-for-nercs-fft-reporting/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 13:49:36 +0000</pubDate>
		<dc:creator>Trey Kirkpatrick</dc:creator>
				<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Trey Kirkpatrick]]></category>
		<category><![CDATA[Corrective Action]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=3516</guid>
		<description><![CDATA[To continue the discussion on NERC’s new compliance enforcement initiative – Find, Fix, Track and Report (FFT Report),  there are a couple important things to consider as this new process is implemented. NERC and the Regional Entities (RE) will be watching and reviewing the registered entities on prompt self-reporting of the potential violation, risk associated [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_2982" class="wp-caption alignleft" style="width: 160px"><a href="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg"><img class="size-full wp-image-2982" title="Trey Kirkpatrick" src="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Vice President, Energy &amp; Utilities Compliance, AssurX Inc.</p></div>
<p>To continue the discussion on <a href="http://blog.assurx.com/2011/10/03/managing-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation/">NERC’s new compliance enforcement initiative – Find, Fix, Track and Report (FFT Report)</a>,  there are a couple important things to consider as this new process is implemented.</p>
<p><a href="http://www.nerc.com" target="_blank">NERC</a> and the Regional Entities (RE) will be watching and reviewing the registered entities on prompt self-reporting of the potential violation, risk associated with the discovered issue, and the mitigating activities; either ones completed or the tasks that are underway.  The Regional Entities will be assigning a unique tracking number for the self-reports as they do now.  What will now take place during their evaluation is the severity of the risk to BPS, and the time discovered by the registered entity to the time reported to the RE.  NERC and the Regional Entities still urge all registered entities to notify their region as soon as a possible violation is discovered.</p>
<p>Registered entities with a <a href="http://www.assurx.com/nerc/index.html" target="_blank">strong compliance program</a> will identify the potential violation and investigate internally with the proper resources as quickly as possible.  They will take immediate <a href="http://www.assurx.com/nerc/index.html#CAPA">corrective actions to mitigate the discovered issue.</a>  The registered entity will enter the issue into their corrective action tracking system and disposition to appropriate individual/department.  Such tracking systems trend and categorize all level of issues to assist management with identification of trends and areas of improvement.  This might initiate an internal self-assessment or even a root cause evaluation if the level has been determined severe.</p>
<p>The<a href="http://www.nerc.com/fileUploads/File/News/A_CEI_30SEP11.pdf" target="_blank"> initiative</a> that was submitted to <a href="http://www.ferc.gov" target="_blank">FERC</a> on September 30, 2011, stated that the registered entity’s compliance program, mitigation and corrective action programs, internal controls and culture of compliance will have an impact on how the Regional Entities evaluate the potential violation.  Key elements to promote these internal behaviors within an organization are:</p>
<ul>
<li>Effective identification</li>
<li>Objective self-assessments</li>
<li>Internal evaluations, tracking, fixing, and trending issues</li>
</ul>
<p>Identification of even low-level issues can help prevent larger issues that could have a major impact on the BPS.  The proper environment that encourages employees to bring up and identify issues is an important step.  This can only be done if management fosters this environment and encourages and rewards employees for discovering issues.  Senior management that demonstrates this will be taking the proper steps for building a strong culture of compliance.</p>
<p>The next FFT Report blog post will discuss the importance of an internal self-assessment program looking at all aspects of a good compliance program to ensure that the registered entity build and maintain strong internal programs.</p>
<p>You can follow <a href="http://twitter.com/CATSWebER">Trey on Twitter.</a></p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;linkname=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;linkname=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;linkname=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;linkname=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;linkname=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;linkname=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;linkname=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F17%2Fthe-next-steps-to-prepare-for-nercs-fft-reporting%2F&amp;title=The%20Next%20Steps%20to%20Prepare%20for%20NERC%26%238217%3Bs%20FFT%20Reporting" id="wpa2a_2"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/10/17/the-next-steps-to-prepare-for-nercs-fft-reporting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Managing NERC&#8217;s new Compliance Enforcement Initiative: Find, Fix, Track and Reporting Implementation</title>
		<link>http://blog.assurx.com/2011/10/03/managing-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation/</link>
		<comments>http://blog.assurx.com/2011/10/03/managing-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 13:04:55 +0000</pubDate>
		<dc:creator>Trey Kirkpatrick</dc:creator>
				<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Regulatory]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Trey Kirkpatrick]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Utilities]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=3462</guid>
		<description><![CDATA[On September 30th, 2011, NERC filed a new version of the Compliance Enforcement Initiative.  This is something that NERC, the Regional Entities, and the registered entities have been working on for a long time.  The primary focus has always been ensuring reliability of the Bulk Power System.  The registered entities have spent a lot of [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_2982" class="wp-caption alignleft" style="width: 160px"><a href="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg"><img class="size-full wp-image-2982" title="Trey Kirkpatrick" src="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Vice President, Energy &amp; Utilities Compliance, AssurX Inc.</p></div>
<p>On September 30<sup>th</sup>, 2011, <a href="http://www.nerc.com/fileUploads/File/News/A_CEI_30SEP11.pdf" target="_blank">NERC filed a new version of the Compliance Enforcement Initiative</a>.  This is something that NERC, the Regional Entities, and the registered entities have been working on for a long time.  The primary focus has always been ensuring reliability of the Bulk Power System.  The registered entities have spent a lot of time and resources on implementation of the NERC and regional standards.  With my experience on both the utility side and the regulated side, I have personally seen the time it can take to process minor violations through the existing enforcement process.</p>
<p>This new process will be a huge improvement on moving potential violations through the pipeline and letting the regulator and entities focus on the higher risk to reliability.  NERC released their press statement that summarizes the new initiative:</p>
<blockquote><p><em>“Through this initiative, NERC is looking to treat matters based upon the risk associated with them,” said Gerry Cauley, president and chief executive officer at NERC. “By identifying, mitigating and resolving issues that do not pose a serious risk to the reliability of the bulk power system, more resources can be focused on violations that do pose a risk to the grid.&#8221;</em></p>
<p><em>The compliance initiative is comprised of three possible tracks: dismissal; find, fix, track and report; and notice of penalty. The dismissal and notice of penalty tracks remain as currently managed; however, the find, fix, track and report track identifies possible violations that are of lesser risk to the grid and allows registered entities to mitigate them with no penalty or sanction applied. The registered entity must provide a statement of completion of mitigation activities, which is subject to verification by the Regional Entity.</em></p>
<p><em>The new initiative is a paradigm shift in how issues are processed, and reflects a risk-informed approach that recognizes all possible violations are not equal and should not be treated in the same manner. By focusing resources on violations that have a serious risk to the reliability of the bulk power system, NERC is able to better fulfill its mission to ensure the reliability of the bulk power system of North America.</em></p></blockquote>
<p><a href="http://blog.assurx.com/2011/05/03/taking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance/">I have written in previous blog</a> posts the importance of registered entities to have a strong <a href="http://www.assurx.com/pdf/AssurXCultureofCompliance.pdf">Culture of Compliance</a>, including senior management accountability, proper compliance support, and instituting an internal <a href="http://www.assurx.com/capa.html">corrective action program</a>.  Many of the larger utilities that have nuclear facilities have had this in place for many years.  The mid-size and smaller companies still are trying to manage compliance by spreadsheets.</p>
<p>With the new compliance initiative that allows potential violations to be internally identified and managed through the “Find, Fix. Track and Report (FFT Report)” will allow all entities to improve their internal compliance program.  With the proper procedures, training, and software system, the the registered entities can identify potential issues entered into the software system and take the appropriate internal actions.  Corrective actions can be assigned, implemented and tracked to completion.  The <a href="http://www.assurx.com/nerc/index.html">AssurX software</a> has been used for years to track issues, store reports and documentation, trend similar issues so that management can take steps to improve performance.  Reports and dashboards are in place to be reviewed by the organization.</p>
<p>More importantly, registered entities are now going to have the opportunity to show the regulators that they have a strong compliance culture in place.  When the regulator comes in for spot checks or audits, the registered entity should take this opportunity to demonstrate that they have implemented a FFT Reporting process and that any information or trending can readily be available from their compliance software application.  Some regions are actually giving scores to entities on how their Culture of Compliance is compared to other entities.  AssurX has worked with our customers by consulting them on how to implement corrective action programs, track and trend identified issues.</p>
<div id="attachment_3470" class="wp-caption aligncenter" style="width: 442px"><a href="http://blog.assurx.com/wp-content/uploads/2011/10/FFTScreenshot.jpg"><img class="size-full wp-image-3470" title="FFTScreenshot" src="http://blog.assurx.com/wp-content/uploads/2011/10/FFTScreenshot.jpg" alt="NERC FFT" width="432" height="257" /></a><p class="wp-caption-text">AssurX&#39;s solution already addresses NERC&#39;s new FFT Initiative</p></div>
<p>We have actually been working to prepare for the roll-out of the “Find, Fix, Track and Report” compliance initiative, and have developed a process specific to the FFT Report requirements such as adding risk calculations, repeatable offenses, and VRF/VSL as identified with a particular standard.  <a href="http://www.assurx.com/contact.html">Contact us</a> to find out more information on how AssurX can support your organization on not just monitoring standards, automating self-certifications, and managing evidence through document management; but to help build a strong Culture of Compliance and implement a robust FFT Reporting process.</p>
<p>You can also <a href="http://twitter.com/CATSWebER">follow Trey on Twitter</a>.</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;linkname=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;linkname=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;linkname=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;linkname=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;linkname=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;linkname=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;linkname=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F10%2F03%2Fmanaging-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation%2F&amp;title=Managing%20NERC%26%238217%3Bs%20new%20Compliance%20Enforcement%20Initiative%3A%20Find%2C%20Fix%2C%20Track%20and%20Reporting%20Implementation" id="wpa2a_4"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/10/03/managing-nercs-new-compliance-enforcement-initiative-find-fix-track-and-reporting-implementation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Do You Know About Heavyweight NERC CIP 011-1?</title>
		<link>http://blog.assurx.com/2011/07/26/do-you-know-about-heavyweight-nerc-cip-011-1/</link>
		<comments>http://blog.assurx.com/2011/07/26/do-you-know-about-heavyweight-nerc-cip-011-1/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 13:44:26 +0000</pubDate>
		<dc:creator>Ron Lepofsky</dc:creator>
				<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Regulatory]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Utilities]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=3278</guid>
		<description><![CDATA[Electrical utilities are already challenged with the process of becoming certified for compliance with the NERC CIP standard for IT security. The NERC CIP standard is evolving, thank goodness. Perhaps you haven’t noticed the innocuous sounding proposed new standard now in the creation process. To me it looks like the heavyweight in the list of otherwise fairly [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_3284" class="wp-caption alignleft" style="width: 160px"><a href="http://www.ere-security.com"><img class="size-full wp-image-3284 " title="RonL" src="http://blog.assurx.com/wp-content/uploads/2011/07/RonL.png" alt="Ron Lepofsky" width="150" height="150" /></a><p class="wp-caption-text">Ron Lepofsky, President, ERE Information Security Auditors</p></div>
<p>Electrical utilities are already challenged with the process of becoming certified for compliance with the <a href="http://www.nerc.com/">NERC CIP standard</a> for IT security.</p>
<p>The NERC CIP standard is evolving, thank goodness. Perhaps you haven’t noticed the innocuous sounding proposed new standard now in the creation process. To me it looks like the heavyweight in the list of otherwise fairly general standards.</p>
<p>It’s called <a href="http://www.nerc.com/filez/standards/Project_2008-06_Cyber_Security_PhaseII_Standards.html">CIP 011-1 BES Cyber System Protection (in draft)</a> and can be found at the end of the NERC CIP list of standards.</p>
<p>In order to understand this new standard in context, it is useful to look at the <a href="http://www.ere-security.ca/NERC_CIP_Compliance_Audit.html">other existing standards</a> which are as follows:</p>
<p style="padding-left: 30px;">CIP 001-1 Sabotage Detection<br />
CIP 002-1 Critical Cyber Asset Identification<br />
CIP 003-1 Security Management Controls<br />
CIP 004-1 Personnel and Training<br />
CIP 005-1 Electronic Security Perimeter(s)<br />
CIP 006-1 Physical Security of Critical Cyber Assets<br />
CIP 007-1 Systems Security Management<br />
CIP 008-1 Incident Reporting and Response Planning<br />
CIP 009-1 Recovery Plans for Critical Cyber Assets<br />
CIP 010-1 BES Cyber System Categorization ( in draft)<br />
CIP 011-1 BES Cyber System Protection (in draft)</p>
<p><strong>What’s Different about CIP 011-1</strong></p>
<p><a href="http://www.nerc.com/docs/standards/sar/CIP-011-1_2010May3.pdf">NERC CIP 011-1</a> puts a knockout punch into NERC CIP by defining very specific control points. These control points do not contradict other CIP standards but instead are drilldowns and complementary to them.</p>
<p>In my opinion 011-1 control points resemble NIST security control points defined in the document: <a href="http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf">Recommended Security Controls for Federal Information Systems and Organizations</a>. The 011-1 control points, which I have listed below for clarity, will be costly to implement and to audit but I think they are specifying critical requirements to harden our electrical security grid.</p>
<p style="padding-left: 30px;">CIP-011-1 Table R3 – Cyber Security Training<br />
CIP-011-1 Table R3 – Cyber Security Training<br />
CIP-011-1 Table R5 – Physical Security for BES Cyber Systems<br />
CIP-011-1 Table R5 – Physical Security for BES Cyber Systems<br />
CIP-011-1 Table R6 – Physical Access Control Systems<br />
CIP-011-1 Table R7 – Account Management Specifications<br />
CIP-011-1 Table R8 – Account Management Implementation<br />
CIP-011-1 Table R9 – Access Revocation<br />
CIP-011-1 Table R9 – Access Revocation<br />
CIP-011-1 Table R10 – Account Access Control Specifications<br />
CIP-011-1 Table R11 – Wireless and Remote Electronic Access Documentation<br />
CIP-011-1 Table R12 – Wireless and Remote Electronic Access Management<br />
CIP-011-1 Table R13 – Remote Access Revocation<br />
CIP-011-1 Table R14 – Wireless and Remote Electronic Access Controls<br />
CIP-011-1 Table R15 – Malicious Code<br />
CIP-011-1 Table R16 – Security Patch Management<br />
CIP-011-1 Table R17 – System Hardening<br />
CIP-011-1 Table R18 – Security Event Monitoring<br />
CIP-011-1 Table R19 – Communications and Data Integrity<br />
CIP-011-1 Table R20 – Electronic Boundary Protection<br />
CIP-011-1 Table R21 – System Boundary Protection<br />
CIP-011-1 Table R22 – Protective Cyber Systems<br />
CIP-011-1 Table R23 – Configuration Change Management<br />
CIP-011-1 Table R23 – Configuration Change Management<br />
CIP-011-1 Table R24 – Information Protection<br />
CIP-011-1 Table R25 – Media Sanitization<br />
CIP-011-1 Table R26 – Maintenance<br />
CIP-011-1 Table R27 – Cyber Security Incident Response Plan Specifications<br />
CIP-011-1 Table R28 – Cyber Security Incident Response Plan Testing Specifications<br />
CIP-011-1 Table R29 – Cyber Security Incident Response Plan Review, Update, and Communication Specifications<br />
CIP-011-1 Table R30 – Recovery Plan Specifications<br />
CIP-011-1 Table R31 – Recovery Plan Testing Specifications<br />
CIP-011-1 Table R32 – Recovery Plan Review, Update, and Communication Specifications</p>
<p>Wouldn’t it knock us all out if we find out critically important NIST standards are finally implemented by the custodians of our electrical grid?</p>
<p>Have a secure week. Ron Lepofsky CISSP, CISM, BA. SC. (mechanical) <a href="http://www.ere-security.ca/">www.ere-security.ca</a></p>
<p>&nbsp;</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;linkname=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;linkname=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;linkname=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;linkname=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;linkname=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;linkname=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;linkname=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F26%2Fdo-you-know-about-heavyweight-nerc-cip-011-1%2F&amp;title=Do%20You%20Know%20About%20Heavyweight%20NERC%20CIP%20011-1%3F" id="wpa2a_6"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/07/26/do-you-know-about-heavyweight-nerc-cip-011-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Handle NERC&#8217;s Risk-Based Reliability Compliance Monitoring</title>
		<link>http://blog.assurx.com/2011/07/07/how-to-handle-nercs-risk-based-reliability-compliance-monitoring/</link>
		<comments>http://blog.assurx.com/2011/07/07/how-to-handle-nercs-risk-based-reliability-compliance-monitoring/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 14:50:13 +0000</pubDate>
		<dc:creator>Trey Kirkpatrick</dc:creator>
				<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Trey Kirkpatrick]]></category>
		<category><![CDATA[NERC]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=3238</guid>
		<description><![CDATA[As the Electric Reliability Organization (ERO) enters it’s fourth year as a mandatory entity, NERC and the Regional Entities have been working with the registered entities, FERC, and other stakeholders to improve reliability.  One of the latest topics being discussed at reliability workshops and meetings is the implementation of Risk-Based Reliability Compliance Monitoring.  What does [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_2982" class="wp-caption alignleft" style="width: 160px"><a href="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg"><img class="size-full wp-image-2982" title="Trey Kirkpatrick" src="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Vice President, Energy &amp; Utilities Compliance, AssurX Inc.</p></div>
<p>As the Electric Reliability Organization (ERO) enters it’s fourth year as a mandatory entity, <a href="http://www.nerc.com" target="_blank">NERC</a> and the Regional Entities have been working with the registered entities, <a href="http://www.ferc.gov" target="_blank">FERC</a>, and other stakeholders to improve reliability.  One of the latest topics being discussed at reliability workshops and meetings is the implementation of Risk-Based Reliability Compliance Monitoring.  What does this mean to a registered entity and how best to prepare for this change?</p>
<p>NERC and the Regional Entities have gathered enough data over the last four years to start the assessment to develop a risk-based reliability program.  Many mature industries have adopted the same type of approach in the past.  NERC has started to identify the core set of critical reliability standards to be audited and what areas are most crucial for reliability.  NERC has also been working over the years to assist registered entities on how to build strong compliance programs and what it takes to implement a culture of compliance within an organization.</p>
<p>NERC has identified some of the criteria to start developing a Risk-Based Reliability program, they include:</p>
<ul>
<li>NERC top 20 list of allegedly violated reliability standards</li>
<li>High Violation Risk Factor (VRF)</li>
<li>Violation Risk Index (VRI)</li>
<li>Past reliability events and major reliability issues</li>
<li>Input from Regional Entities; especially from the audit teams and enforcement groups</li>
<li>Assessment of registered entities compliance program and compliance culture</li>
</ul>
<p>Some Regional Entities are developing their own Compliance Surveys that will be sent out to their registered entities.  AssurX Compliance Services division has <a href="http://www.assurx.com/pdf/AssurXCultureofCompliance.pdf" target="_blank">developed a white-paper outlining some of the key issues</a> an organization should focus on to build an internal culture of compliance.  As the ERO matures, more attention should focus on sharing lessons-learned from events, improving critical reliability standards, and how a registered entity mitigates identified issues.</p>
<p>We will be writing more about the Risk-based Reliability Compliance monitoring program in future weeks.  <a href="http://www.assurx.com/pdf/AssurXCultureofCompliance.pdf" target="_blank">Review our white-paper</a> and <a href="http://www.assurx.com/contact.html" target="_blank">contact</a> us if you have more questions.</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;linkname=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;linkname=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;linkname=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;linkname=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;linkname=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;linkname=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;linkname=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F07%2F07%2Fhow-to-handle-nercs-risk-based-reliability-compliance-monitoring%2F&amp;title=How%20to%20Handle%20NERC%26%238217%3Bs%20Risk-Based%20Reliability%20Compliance%20Monitoring" id="wpa2a_8"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/07/07/how-to-handle-nercs-risk-based-reliability-compliance-monitoring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>71.6% of all NERC Fines for the May 26th Period Were CIP Related Violations</title>
		<link>http://blog.assurx.com/2011/05/31/71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations/</link>
		<comments>http://blog.assurx.com/2011/05/31/71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations/#comments</comments>
		<pubDate>Tue, 31 May 2011 19:17:11 +0000</pubDate>
		<dc:creator>James Holler</dc:creator>
				<category><![CDATA[James Holler]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[NERC]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=3155</guid>
		<description><![CDATA[The NERC fines for the May 26th period are out and 71.6% of all financial penalties were CIP related. This is a clear indicator that registered entities are having troubles with CIP-004, CIP-007, CIP-008 and CIP-009. There were fines for all of the other CIP requirements, but the four mentioned requirements seem to be the [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.nerc.com/filez/enforcement/index.html" target="_blank">NERC fines for the May 26th period are out</a> and 71.6% of all financial penalties were CIP related. This is a clear indicator that registered entities are having troubles with CIP-004, CIP-007, CIP-008 and CIP-009. There were fines for all of the other CIP requirements, but the four mentioned requirements seem to be the biggest headaches. We have also heard from NERC and FERC that Registered Entities are still not completing their Internal Compliance Programs as directed by FERC.</p>
<p>To view the latest NERC fines, go to <a href="http://www.linkedin.com/redirect?url=http%3A%2F%2Fwww%2Enerc%2Ecom%2Ffilez%2Fenforcement%2Findex%2Ehtml&amp;urlhash=fme4&amp;_t=tracking_anet" target="blank">http://www.nerc.com/filez/enforcement/index.html</a></p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;linkname=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;linkname=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;linkname=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;linkname=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;linkname=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;linkname=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;linkname=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F31%2F71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations%2F&amp;title=71.6%25%20of%20all%20NERC%20Fines%20for%20the%20May%2026th%20Period%20Were%20CIP%20Related%20Violations" id="wpa2a_10"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/05/31/71-6-of-all-nerc-fines-for-the-may-26th-period-were-cip-related-violations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Taking a Utility From a Culture of Complacency to a Culture of Compliance</title>
		<link>http://blog.assurx.com/2011/05/03/taking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance/</link>
		<comments>http://blog.assurx.com/2011/05/03/taking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance/#comments</comments>
		<pubDate>Tue, 03 May 2011 14:37:13 +0000</pubDate>
		<dc:creator>Trey Kirkpatrick</dc:creator>
				<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Quality Management]]></category>
		<category><![CDATA[Regulatory]]></category>
		<category><![CDATA[Trey Kirkpatrick]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Utilities]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=3073</guid>
		<description><![CDATA[As the Electric Reliability Organization (ERO) continues to mature and provide leadership for electric reliability, there have been many changes over the last four years. One of the most recent NERC initiatives is working with the industry on reliability excellence with a risk-based approach. Gerry Cauley, President and CEO of NERC, has continuously emphasized the [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_2982" class="wp-caption alignright" style="width: 160px"><a href="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg"><img class="size-full wp-image-2982 " title="Trey Kirkpatrick" src="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Vice President, Energy &amp; Utilities Compliance</p></div>
<p>As the <a href="http://www.nerc.com/files/NERC_Rules_of_Procedure_EFFECTIVE_20080321.pdf" target="_blank">Electric Reliability Organization</a> (ERO) continues to mature and provide leadership for electric reliability, there have been many changes over the last four years.  One of the most recent NERC initiatives is working with the industry on reliability excellence with a risk-based approach.  <a href="http://www.nerc.com/news_pr.php?npr=455" target="_blank">Gerry Cauley, President and CEO of NERC</a>, has continuously emphasized the &#8220;Five Key Success Factors&#8221; for building a foundation of public trust.  These five key success factors include:</p>
<ol>
<li>Risked based approach, with reliability performance measurably improving</li>
<li>Reliability-learning, self-correcting industry</li>
<li>Culture of compliance, enforcement backstop</li>
<li>Commitment to security/resilience of grid</li>
<li>Positive relationships and reputation</li>
</ol>
<p><a href="http://www.nerc.com" target="_blank">NERC</a> and the Regional Entities will start conducting more reviews and assessments on registered entities regarding “Risk Based Compliance Monitoring.”  All Regions are moving toward evaluations of internal compliance programs based on the <a href="http://www.nerc.com/files/March%202011%20Workshop_Day%20Two%20Presentations.pdf" target="_blank">FERC “13 questions” provided in the 2005 orders</a>.  Some Regional Entities are already sending surveys to their entities trying to learn more about the internal compliance culture in these organizations.  They will be reviewing internal processes and procedures.  They will also review such things as: the number of violations discovered via audits or investigations, repeat violations, number of mitigation plans, etc.</p>
<blockquote><p><em>FERC Orders</em></p>
<p>Policy Statement on Enforcement <em>Docket No. PL06-1-000, 113 FERC ¶ 61,068 (October 20, 2005)</em></p>
<p>Revised Policy Statement on Enforcement <em>Docket No. PL08-3-000, 123 FERC ¶ 61,156 (May 18, 2008)</em></p>
<p>Policy Statement on Compliance <em>Docket No. PL09-1-000,125 FERC ¶ 61,058 (October 16, 2008)</em><em> </em></p>
<p>Policy Statement on Penalty Guidelines <em>Docket No. PL10-4-000, 130 FERC ¶ 61,220 (March 18, 2010)  suspended on April 15, 2010</em></p>
<p>Revised Policy Statement on Penalty Guidelines <em>Docket No. PL10-4-000,132 FERC ¶ 61,216 (October 17, 2010)</em></p></blockquote>
<p>Many businesses in a regulated industry such as financial, life sciences, and nuclear industry have lived through these changes and have continuously improved their internal compliance and regulatory programs.  Many have built strong Culture of Compliance programs. I have seen and been a part of some very strong Culture of Compliance programs.  Some of the key elements of these programs are senior management involvement that provides strong leadership and holding individuals accountable.  This is so important when implementing the critical elements of a Culture of Compliance.</p>
<p>Another important part of building a better compliance culture is establishing an organization that self-identifyies and self-corrects issues.  One of the most important aspects of this internal initiative is implementing a robust <a href="http://www.assurx.com/CAPA.html">corrective and preventive action (CAPA) program</a>.  Every individual in an organization must be trained on the process and tools of this program; management must continuously support the employees identifying issues; and preventative steps must be assigned and completed.</p>
<p><a href="http://blog.assurx.com/wp-content/uploads/2011/05/CAPADrawing.png"><img class="aligncenter size-full wp-image-3088" title="CAPADrawing" src="http://blog.assurx.com/wp-content/uploads/2011/05/CAPADrawing.png" alt="Corrective and Preventive Action (CAPA) Workflow" width="468" height="288" /></a></p>
<p>AssurX has developed a white paper on how to build the key elements of the “Culture of Compliance” program. <a href="http://www.assurx.com/pdf/AssurXCultureofCompliance.pdf">Download your copy here to learn more</a>.</p>
<p>You can also follow <a href="http://twitter.com/catsweber" target="_blank">Trey on Twitter</a>.</p>
<p>&nbsp;</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;linkname=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;linkname=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;linkname=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;linkname=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;linkname=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;linkname=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;linkname=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F05%2F03%2Ftaking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance%2F&amp;title=Taking%20a%20Utility%20From%20a%20Culture%20of%20Complacency%20to%20a%20Culture%20of%20Compliance" id="wpa2a_12"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/05/03/taking-a-utility-from-a-culture-of-complacency-to-a-culture-of-compliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Introducing AssurX One: A complete, affordable, single source compliance solution for small- to medium-sized utility companies</title>
		<link>http://blog.assurx.com/2011/04/28/introducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies/</link>
		<comments>http://blog.assurx.com/2011/04/28/introducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 17:43:15 +0000</pubDate>
		<dc:creator>Tamar June</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Product News]]></category>
		<category><![CDATA[Tamar June]]></category>
		<category><![CDATA[AssurX]]></category>
		<category><![CDATA[Energy]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Utilities]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=3028</guid>
		<description><![CDATA[The AssurX One program provides small- to medium-sized utility companies a single source solution to implement a world-class compliance management system. Included are best practice pre-configured workflows, dashboards with real time metrics, automatic regulatory updates, a secure (SAS 70 Type II certified) OnDemand system, Web-based implementation and training, along with industry focused Webinars and workshops. [...]]]></description>
			<content:encoded><![CDATA[<p>The AssurX One program provides small- to medium-sized utility companies a single source solution to implement a world-class compliance management system.  Included are best practice pre-configured workflows, dashboards with real time metrics, automatic regulatory updates, a secure (SAS 70 Type II certified) OnDemand system, Web-based implementation and training, along with industry focused Webinars and workshops.</p>
<div id="attachment_3030" class="wp-caption aligncenter" style="width: 442px"><img class="size-full wp-image-3030" title="AssurXOneBlogScreen" src="http://blog.assurx.com/wp-content/uploads/2011/04/AssurXOneBlogScreen.png" alt="" width="432" height="228" /><p class="wp-caption-text">Built-in metrics, robust help files and an easy dashboard-centric user interface require minimal training to get up and running quickly.</p></div>
<p>AssurX One system consistently tracks, measures and demonstrates compliance for an array of NERC and regional standards and requirements, including annual policy reviews, to asset and cyber security management, and document control.</p>
<p><em>Included in the AssurX One program:</em></p>
<ol>
<li>Best practices, pre-configured workflows (NERC gap analysis, self-certification schedules/calendars, document control, cyber security management), dashboards and metrics.</li>
<li>Hosted on a secure, OnDemand system with preloaded NERC and regional standards and automatic regulatory updates.</li>
<li>Web-based implementation and training. Tutorials provided for each workflow.</li>
<li>Exclusive industry focused compliance Webinars and workshops.</li>
</ol>
<p>For more information, <a href="http://www.assurx.com/pdf/AssurXOneBrochure.pdf" target="_blank">download the detailed brochure (PDF):</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;linkname=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;linkname=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;linkname=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;linkname=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;linkname=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;linkname=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;linkname=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F28%2Fintroducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies%2F&amp;title=Introducing%20AssurX%20One%3A%20A%20complete%2C%20affordable%2C%20single%20source%20compliance%20solution%20for%20small-%20to%20medium-sized%20utility%20companies" id="wpa2a_14"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/04/28/introducing-assurx-one-a-complete-affordable-single-source-compliance-solution-for-small-to-medium-sized-utility-companies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trey Kirkpatrick joins AssurX as Vice President, Energy and Utilities Compliance</title>
		<link>http://blog.assurx.com/2011/04/20/trey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance/</link>
		<comments>http://blog.assurx.com/2011/04/20/trey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 16:01:32 +0000</pubDate>
		<dc:creator>Tamar June</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Tamar June]]></category>
		<category><![CDATA[AssurX]]></category>
		<category><![CDATA[Energy]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=2977</guid>
		<description><![CDATA[AssurX is pleased to announce the appointment of Trey Kirkpatrick as Vice President, Energy and Utilities Compliance.  Prior to joining AssurX, Trey served as Manager, Compliance Implementation and Registration for the Northeast Power Coordinating Council (NPCC) where he was responsible for registering all entities that met the requirements of the NERC Statement of Registry Criteria. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.assurx.com"></a></p>
<p><a href="http://www.assurx.com"> </a></p>
<p><a href="http://www.assurx.com" target="_blank"></a></p>
<p><a href="http://www.assurx.com" target="_blank"> </a></p>
<div id="attachment_2982" class="wp-caption alignleft" style="width: 160px"><a href="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg"><img class="size-full wp-image-2982" title="Trey Kirkpatrick" src="http://blog.assurx.com/wp-content/uploads/2011/04/Treyk.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Trey Kirkpatrick, Vice President, Energy and Utilities Compliance, AssurX</p></div>
<p><a href="http://www.assurx.com">AssurX</a> is pleased to announce the appointment of Trey Kirkpatrick as Vice President, Energy and Utilities Compliance.  Prior to joining AssurX, Trey served as Manager, Compliance Implementation and Registration for the <a href="http://www.npcc.org/" target="_blank">Northeast Power Coordinating Council</a> (NPCC) where he was responsible for registering all entities that met the requirements of the <a href="http://www.nerc.com/files/Statement_Compliance_Registry_Criteria-V5-0.pdf" target="_blank">NERC Statement of Registry Criteria</a>. NPCC has over 305 companies registered that are responsible for over 600 functional responsibilities as owners, operators and users of the bulk-power system.</p>
<p>While at NPCC, Trey was chairman of the NPCC Compliance Committee (CC) reporting directly to the NPCC Board of Directors.  As chairman, he worked closely with NPCC staff and stakeholders to continuously improve the compliance monitoring and enforcement process at NPCC.  He was also chairman of the NERC and Regional Entities – Registration and Certification Working Group (RCWG) where he worked with the eight (8) regional entities and NERC on setting strategic priorities for registration and certification within North America.</p>
<p>Prior to NPCC, Trey served as Manager, Reliability Compliance at <a href="http://www.nu.com" target="_blank">Northeast Utilities</a> where he was the lead manager representing Northeast Utilities’ Operating Companies’ strategic and operational interests with the North American Electric Reliability Council (NERC). While at Northeast Utilities, he was in charge of oversight of all matters related to reliability rules, including rules development, internal compliance assessments, compliance reporting, compliance audits conducted by sanctioned regulatory authorities, and developed and maintained all necessary records demonstrating Northeast Utilities’ compliance on a system-wide basis.   Trey was also a representative on the NERC Compliance and Certification Committee (CCC), which is a stakeholder body working closely with NERC and Regional Entities.</p>
<p>Trey comes to AssurX with an extensive background in energy and utilities having spent the past 20 years in various engineering and compliance positions in the industry; including in nuclear power generations and transmission. He will contribute his leadership skills in expanding <a href="http://www.assurx.com/nerc" target="_blank">AssurX’s compliance products and services in North America’s energy and utilities industry</a>.</p>
<p>You can follow Trey on Twitter: <a href="http://twitter.com/CATSWebER" target="_blank">http://twitter.com/CATSWebER</a></p>
<p>&nbsp;</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;linkname=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;linkname=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;linkname=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;linkname=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;linkname=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;linkname=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;linkname=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F04%2F20%2Ftrey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance%2F&amp;title=Trey%20Kirkpatrick%20joins%20AssurX%20as%20Vice%20President%2C%20Energy%20and%20Utilities%20Compliance" id="wpa2a_16"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/04/20/trey-kirkpatrick-joins-assurx-as-vice-president-energy-and-utilities-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Top 10 FERC Enforceable Standards in 2010</title>
		<link>http://blog.assurx.com/2011/03/22/the-top-10-ferc-enforceable-standards-in-2010/</link>
		<comments>http://blog.assurx.com/2011/03/22/the-top-10-ferc-enforceable-standards-in-2010/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 19:36:17 +0000</pubDate>
		<dc:creator>Tamar June</dc:creator>
				<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[Tamar June]]></category>
		<category><![CDATA[Energy]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=2897</guid>
		<description><![CDATA[Last year we blogged about the top 10 FERC enforceable actions for the NERC standards, with PRC-005-1 violations leading the pack. As you can see in the chart below, 8 out of the top 10 violations are CIP related. So, what changed? According to Trey Kirkpatrick, VP, Energy and Utilities Compliance for AssurX, &#8220;With the [...]]]></description>
			<content:encoded><![CDATA[<p>Last year <a href="http://blog.assurx.com/2010/04/21/the-top-10-ferc-enforceable-standards-in-2009/">we blogged about the top 10 FERC enforceable actions for the NERC standards</a>, with <a href="http://www.assurx.com/nerc/PRC005.html">PRC-005-1</a> violations leading the pack. As you can see in the chart below, 8 out of the top 10 violations are CIP related. So, what changed?</p>
<p><a href="http://blog.assurx.com/wp-content/uploads/2011/03/FERCTOP10.jpg"><img class="aligncenter size-full wp-image-2901" title="FERCTOP10" src="http://blog.assurx.com/wp-content/uploads/2011/03/FERCTOP10.jpg" alt="FERC Top 10 Enforceable 2010" width="443" height="283" /></a></p>
<p>According to Trey Kirkpatrick, VP, Energy and Utilities Compliance for <a href="http://www.assurx.com/nerc">AssurX</a>, &#8220;With the emergence of the CIP standards into the NERC and Regional Entities CMEP program, registered entities are self-reporting more CIP violations.  The entities are finding that documentation of personnel training and system security management continue to be an area for improvement. The registered entities are taking action with proper mitigation plans that are approved by the Regional Entities and NERC. They are also continuing to learn from other areas such as; nuclear power and health sciences how to instill a &#8216;Culture of Compliance&#8217; in their workforce.&#8221;</p>
<p>And, as stated in <a href="http://www.nerc.com/fileUploads/File/newsletters/NERCNews_2011-02.pdf">NERC&#8217;s February 2011 Newsletter</a>:</p>
<blockquote><p>The Department of Energy (DOE) is launching an initiative to enhance cyber security on the electric grid. The initiative, led by the 		Department¹s Office of Electricity Delivery and Energy Reliability (OE), the National Institute of Standards and Technology (NIST), and 	the North American Electric Reliability Corporation (NERC), will be an open collaboration with representatives from across the public 		and private sectors to develop a cybersecurity risk management process guideline for the electric sector.</p></blockquote>
<p>The Regional Entities and NERC are also performing more on-site audits and spot-checks. They are discovering implementation inconsistencies between entities and are sharing those lessons learned with FERC and the registered entities.  NERC has standard teams currently revising the next version of the CIP standards.  AssurX will continue to follow these revisions in updates to our readers in future blogs.</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;linkname=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;linkname=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;linkname=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;linkname=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;linkname=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;linkname=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;linkname=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F03%2F22%2Fthe-top-10-ferc-enforceable-standards-in-2010%2F&amp;title=The%20Top%2010%20FERC%20Enforceable%20Standards%20in%202010" id="wpa2a_18"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/03/22/the-top-10-ferc-enforceable-standards-in-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NERC Is Getting Serious About Financial Penalties</title>
		<link>http://blog.assurx.com/2011/02/28/nerc-is-getting-serious-about-financial-penalties/</link>
		<comments>http://blog.assurx.com/2011/02/28/nerc-is-getting-serious-about-financial-penalties/#comments</comments>
		<pubDate>Mon, 28 Feb 2011 16:28:46 +0000</pubDate>
		<dc:creator>James Holler</dc:creator>
				<category><![CDATA[Electric Reliability]]></category>
		<category><![CDATA[James Holler]]></category>
		<category><![CDATA[Energy]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>

		<guid isPermaLink="false">http://blog.assurx.com/?p=2878</guid>
		<description><![CDATA[As is evident by the latest round of financial penalties (February 23, 2011) from NERC, the time for forgiveness is over. $1,145,500 in financial penalties were handed down to 24 organizations according the latest statistics — and none were zero dollar fines. With penalties ranging from $3,000 all the way up to a whopping $450,000, [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_2318" class="wp-caption alignleft" style="width: 160px"><a href="http://blog.assurx.com/wp-content/uploads/2010/09/JamesHoller21.jpg"><img class="size-full wp-image-2318" title="JamesHoller2" src="http://blog.assurx.com/wp-content/uploads/2010/09/JamesHoller21.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">James Holler, Founder, Abidance Consulting</p></div>
<p>As is evident by the <a href="http://www.nerc.com/filez/enforcement/index.html" target="_blank">latest round of financial penalties</a> (February 23, 2011) from NERC, the time for forgiveness is over. $1,145,500 in financial penalties were handed down to 24 organizations according the latest statistics — and none were zero dollar fines.</p>
<p>With penalties ranging from $3,000 all the way up to a whopping $450,000, and with the average penalty at just under $48,000, now is the time to ensure that your NERC compliance program is tightened down.</p>
<p>In the past, we have stressed the importance of training your staff; testing your various procedures as well as maintenance programs for completeness and accuracy; and, using different methods and methodologies to ensure your NERC compliance program is complete and ready to be audited by your Regional Entity and/or NERC at a moment&#8217;s notice.</p>
<p>So, with that said, let’s go back over a check-list of the areas that you will need to ensure are addressed in order to keep from having your organization&#8217;s name listed on the <a href="http://www.nerc.com/filez/enforcement/index.html" target="_blank">NERC Enforcement Actions Web page</a>.</p>
<p>The following list is in no particular order, so don’t think you need to follow this in chronological order.</p>
<ul>
<li>Internal Compliance Program (FERC Required — FERC released a guidance document on this back in 2008 — use it!)</li>
<li>Pandemic (Critical Assets Only — Use the CIKR documentation on the DHS website as guidance)</li>
<li>Facility Ratings Methodology (it better be more than one or two pages — ours average 39 pages)</li>
<li>Maintenance and Testing programs for PRC-005 (don’t forget to include the basis for your testing AND the intervals — if in doubt, use the ANSI or IEEE standards as your basis)</li>
<li>CIP-001 training for your staff (having your staff sign a piece of paper that they may or may not have read isn’t going to cut it, use a real training program)</li>
</ul>
<p>This is a partial list of what needs to be addressed so that you don’t become a statistic. As I stress to our clients, don’t overlook anything. If in doubt, ask someone who knows what they are doing and preferably someone who has been down the audit path before. Always remember, just because you passed your last audit, doesn’t mean you are going to pass your next one. Stay alert, stay focused and above all, stay calm, it’s not as bad as it seems.</p>
<p>James Holler is founder of <a title="Abidance Consulting" href="http://www.abidanceconsulting.com/" target="_blank">Abidance Consulting</a>.</p>
<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;linkname=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;linkname=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;linkname=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;linkname=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;linkname=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;linkname=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" title="Email" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a class="a2a_button_printfriendly" href="http://www.addtoany.com/add_to/printfriendly?linkurl=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;linkname=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" title="PrintFriendly" rel="nofollow" target="_blank"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/icons/printfriendly.png" width="16" height="16" alt="PrintFriendly"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.assurx.com%2F2011%2F02%2F28%2Fnerc-is-getting-serious-about-financial-penalties%2F&amp;title=NERC%20Is%20Getting%20Serious%20About%20Financial%20Penalties" id="wpa2a_20"><img src="http://blog.assurx.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.assurx.com/2011/02/28/nerc-is-getting-serious-about-financial-penalties/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

