“ There seems to be no single entity that is creating an HDB (heterogeneous database system) to integrate all the disparate database management systems and present users with a single, unified query interface.” 10 This requires not just the standard bodies to be communicating with the manufacturers; it also involves manufacturers talking amongst each other to create a consortium. All things considered, no one entity will be the key driver for NERC compliance. End users, standards bodies, and international control systems vendors must unify efforts to achieve successful implementation.
cybersecurity-sis-market-researchWhile NERC arguably has the biggest influence, other outside companies, compliance bodies, and forums also support and enhance security operations in the energy sector. NERC is the strongest one because they are a delegated authority for the Federal Energy Regulatory Commission (FERC). They have australia mobile number list free regulatory oversight to mandate what security standards should be followed and they possess the ability to impose fines that have a significant financial impact. NERC has the ability to affect power companies on social media, to influence company culture, and to color their reputation. Despite their obvious influence, there is some doubt that NERC has the technical capability to do what needs to be done.
NERC CIPs must be complied with unless an entity exists in the federal space. Certain power plants on the federal side such as the TVA and Bonneville Power have additional work to do. They have to meet NERC CIPs compliance standards and also meet FISMA (Federal Information Security Management Act) and NIST (National Institutes of Standards and Technology) requirements and guidelines.