Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration...
Transcript of Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration...
![Page 1: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/1.jpg)
1
Substation CIP Change Management Program
SPP CIP Users Group Dawn Berndt June 2014
![Page 2: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/2.jpg)
2
Agenda Background Substation CIP Change Management Program Challenges Lessons Learned
![Page 3: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/3.jpg)
3
Xcel Energy Background Serves 3.4 million electric customers in 8 states Three Operating Companies
Northern States Power (NSP) Public Service Company (PSCo) Southwestern Public Service (SPS)
NERC Compliance Regions MRO (NSP) WECC (PSCo) SPP (SPS)
![Page 4: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/4.jpg)
4
CIP Change Control Substations
78 CIP substations with 1,100 Critical Cyber Assets 16,000 work orders per year at CIP substations More than 100 change control forms processed
each year Opportunity for change control errors is large
Change Control Program continues to evolve
![Page 5: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/5.jpg)
5
CIP Change Control Key Players
CIP Consultant
Substation Field Engineering
Project Initiator
Engineering
Operations & Maintenance
Field Technician
![Page 6: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/6.jpg)
6
CIP Substation Change Control
Pro
ject
/Wor
k In
tiatit
edC
IP S
ubst
atio
n / C
yber
Ass
ets
7 D
AYS
23 D
AYS
CIP Consultant
Project InitiatorsSFE -Substation Field Engineering
SED – Substation Engineering DesignSCE – Substation Commissioning
EngineeringSPE – System Protection Engineering
CO&M
YesNo
Store Project Spreadsheet in
ProjectWise
CIP Sub <AND>Cyber Assets
Impacted?
Record all affected Cyber
Assets in Spreadsheet
Update CIP ESP Diagram
Done
CIP Project Spreadsheet
Change Control not needed,
inform InitiatorProcess Done
Update CIP Asset Inventory
Issue Project Spreadsheet
to field
PROJECTS Small Capital or Maintenance Large Capital Small Special O&M Install or Upgrades
Normal or Emergency Maintenance
YesCIP Project
SpreadsheetRecord device information on Spreadsheet
Perform required configuration and testing
activities
Return data to CIP
Consultant
Substation Work
Is Substation Work Complete?<OR>
Has remote connectivity been established for the first time?
Yes 7 DAYS Start
Complete Project Spreadsheet
documentation
No
CIP Substation Change ControlP
roje
ct/W
ork
Intia
tited
CIP Consultant
Project InitiatorsSFE -Substation Field Engineering
SED – Substation Engineering DesignSCE – Substation Commissioning
EngineeringSPE – System Protection Engineering
Substation O&M
YesNo
CIP Sub <AND> Cyber Assets
Impacted?
CIP Project Spreadsheet
PROJECTS Small Capital or Maintenance Large Capital Small Special O&M Install or Upgrades
Normal or Emergency Maintenance
YesCIP Project
SpreadsheetRecord device information on Spreadsheet
Perform required configuration and testing
activities
![Page 7: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/7.jpg)
7
CIP Substation Change Control
Pro
ject
/Wor
k In
tiatit
edC
IP S
ubst
atio
n / C
yber
Ass
ets
7 D
AYS
23 D
AYS
CIP Consultant
Project InitiatorsSFE -Substation Field Engineering
SED – Substation Engineering DesignSCE – Substation Commissioning
EngineeringSPE – System Protection Engineering
Substation O&M
YesNo
Store Project Spreadsheet in
ProjectWise
CIP Sub <AND> Cyber Assets
Impacted?
Record all affected Cyber
Assets in Spreadsheet
Update CIP ESP Diagram
Done
CIP Project Spreadsheet
Change Control not needed,
inform InitiatorProcess Done
Update CIP Asset Inventory
Issue Project Spreadsheet
to field
PROJECTS Small Capital or Maintenance Large Capital Small Special O&M Install or Upgrades
Normal or Emergency Maintenance
YesCIP Project
SpreadsheetRecord device information on Spreadsheet
Perform required configuration and testing
activities
Return data to CIP
Consultant
Substation Work
Is Substation Work Complete?<OR>
Has remote connectivity been established for the first time?
Yes 7 DAYS Start
Complete Project Spreadsheet
documentation
No
C
IP S
ubst
atio
n / C
yber
Ass
ets
YesNo
Record all affected Cyber
Assets in Spreadsheet
CIP Project Spreadsheet
Change Control not needed,
inform InitiatorProcess Done
Issue Project Spreadsheet
to field
YesCIP Project
SpreadsheetRecord device information on Spreadsheet
Perform required configuration and testing
activities
Substation Work
Is Substation Work Complete?<OR>
Has remote connectivity been established for the first time?
Yes 7 DAYS Start
No
![Page 8: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/8.jpg)
8
CIP Substation Change Control
Pro
ject
/Wor
k In
tiatit
edC
IP S
ubst
atio
n / C
yber
Ass
ets
7 D
AYS
23 D
AYS
CIP Consultant
Project InitiatorsSFE -Substation Field Engineering
SED – Substation Engineering DesignSCE – Substation Commissioning
EngineeringSPE – System Protection Engineering
Substation O&M
YesNo
Store Project Spreadsheet in
ProjectWise
CIP Sub <AND> Cyber Assets
Impacted?
Record all affected Cyber
Assets in Spreadsheet
Update CIP ESP Diagram
Done
CIP Project Spreadsheet
Change Control not needed,
inform InitiatorProcess Done
Update CIP Asset Inventory
Issue Project Spreadsheet
to field
PROJECTS Small Capital or Maintenance Large Capital Small Special O&M Install or Upgrades
Normal or Emergency Maintenance
YesCIP Project
SpreadsheetRecord device information on Spreadsheet
Perform required configuration and testing
activities
Return data to CIP
Consultant
Substation Work
Is Substation Work Complete?<OR>
Has remote connectivity been established for the first time?
Yes 7 DAYS Start
Complete Project Spreadsheet
documentation
No
C
7
DA
YS23
DA
YS
Store Project Spreadsheet in
ProjectWise
Update CIP ESP Diagram
Done
Update CIP Asset Inventory
Return data to CIP
Consultant
Yes 7 DAYS Start
Complete Project Spreadsheet
documentation
![Page 9: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/9.jpg)
9
![Page 10: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/10.jpg)
10
![Page 11: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/11.jpg)
11
![Page 12: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/12.jpg)
12
![Page 13: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/13.jpg)
13
![Page 14: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/14.jpg)
14
![Page 15: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/15.jpg)
15
![Page 16: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/16.jpg)
16
CIP Change Control Challenges
Manual change control process Rely on personnel to initiate change control for CIP substations Multiple departments required to fill out information
Depend on human performance for documentation Time Accuracy Completeness
Large number of people had access to CIP Substations Almost 25% were external parties (other utilities, contractors) Paring this list down
Training and awareness for all affected personnel on correct procedure
![Page 17: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/17.jpg)
17
CIP Change Control Lessons Learned
Workflow automation is crucial when dealing with many touch points in CIP Substations Identify process handoffs and consider controls
Importance of ongoing training and awareness Employee turnover Contractors/Consultants Face-to-face is valuable with field resources
Implementing compliance ‘controls’ can help prevent and detect issues
![Page 18: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/18.jpg)
18
CIP Change Control Controls Implemented
Established controls to help identify substation work requiring change control upfront Automated biweekly report to review new work orders Established process for checking CIP status on new substation
design projects Implemented manual security testing of access points Conduct bi-weekly change control meetings in each Operating
Company with Engineering, Operations and CIP Compliance groups Quarterly monitoring program Implemented tagging of disconnected device cables Installed access point “CIP notice” labels
![Page 19: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/19.jpg)
19
CIP Change Control Improved Field Awareness
![Page 20: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/20.jpg)
20
Port plugs and locks to prevent inadvertent connections
Technician guide for connecting and making changes to cyber assets in the Electronic Security Perimeter
Restructuring process documentation Change control awareness posters in CIP substations
CIP Change Control Controls In Development
![Page 21: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/21.jpg)
21
Implement additional controls Asset management solution (not Excel spreadsheets) Investigate automation solutions
Change control workflow Configuration management
Evaluate viability of additional testing facilities
CIP Change Control Preparation for CIP V5
![Page 22: Substation CIP Change Management Program · CIP Change Control Lessons Learned ... Configuration management Evaluate viability of additional testing facilities CIP Change Control](https://reader034.fdocuments.in/reader034/viewer/2022051822/5febecad58f99453f3117be5/html5/thumbnails/22.jpg)
22
Questions?