Transcription of Cyber Intrusion Guide for System Operators
1 Reliability Guideline 1 Cyber Intrusion Guide for System Operators : Version 2 2 Applicability 3 Reliability Coordinators (RC), Balancing Authorities (BA), Transmission Operators (TOP), Generator 4 Operators (GOP), and Distribution Providers (DP). 5 Preamble 6 It is in the public interest for NERC to develop guidelines that are useful for maintaining and enhancing the 7 reliability of the Bulk Electric System (BES). The subgroups of the Reliability and Security Technical 8 Committee (RSTC) in accordance with the RSTC charter1 are authorized by the NERC Board of Trustees to 9 develop reliability and security guidelines. These guidelines establish a voluntary code of practice on a 10 particular topic for consideration and use by BES users, owners, and Operators . These guidelines are 11 coordinated by the technical committees and include the collective experience, expertise, and judgment of 12 the industry.
2 The objective of this reliability guideline is to distribute key practices and information on 13 specific issues critical to appropriately maintaining BES reliability. Reliability guidelines are not to be used 14 to provide binding norms or create parameters by which compliance to NERC Reliability Standards are 15 monitored or enforced. While the incorporation of guideline practices is strictly voluntary, reviewing, 16 revising, or developing a program using these practices is highly encouraged to promote and achieve 17 appropriate BES reliability. 18 Metrics 19 Pursuant to the Commission s Order on January 19, 2021, North American Electric Reliability Corporation, 20 174 FERC 61,030 (2021), reliability guidelines shall now include metrics to support evaluation during 21 triennial review consistent with the RSTC Charter2. 22 Baseline Metrics 23 Performance of the BPS prior to and after a reliability guideline, as reflected in NERC s State of 24 Reliability Report and reliability assessments ( , the Long Term Reliability Assessment and 25 seasonal assessments); 26 The use and effectiveness of a reliability guideline as reported by industry via survey; and 27 Industry assessment of the extent to which a reliability guideline is addressing risk as reported via 28 survey 29 Specific Metrics 30 The RSTC or any of its subcommittees can modify and propose metrics specific to the guideline in order to 31 measure and evaluate its effectiveness.
3 32 1 2 Reliability Guideline: Cyber Intrusion Guide for System Operators Version 2 2 Approved by the Reliability and Security Technical Committee on DATE Background and Purpose 33 System Operators are uniquely positioned to recognize Cyber threats to the BES. Through direct access to 34 Cyber Assets, and direct contact with field personnel, Operators may be the first to recognize real-time 35 threats to System security. They may also be targets of social engineering Operators are 36 potentially the first and last line of defence against Cyber threats. This fact notwithstanding, it is the System 37 Operator organization that establishes and sustains the conditions necessary for individual System 38 Operators to successfully meet their responsibilities in real time. 39 The Real Time Operating Subcommittee (RTOS) recognizes not all organizations are the same, so this 40 guidance is general and is based on the assumption that each entity has an approved Cyber Security Incident 41 recognition, response and reporting process in place to follow any time a Cyber Security Incident has been 42 identified, assessed, and confirmed.
4 43 The following guideline will assist System Operators in recognizing events that may be an indicator of a 44 Cyber -attack, and how and when to share information with others. While this Cyber Intrusion Guide was 45 created for electric System Operators , the principles within are applicable to any Operators or support staff 46 engaged in maintaining Reliable Operation of the BES. The intent is to increase cross-discipline familiarity 47 and recognition of when to ask a question or raise an issue, not to make cybersecurity professionals out of 48 System Operators or vice versa, consistent with ongoing findings from the Department of Energy s 49 CyOTE 50 This document is intended to be used as a Guide only. It is not intended to detract or conflict with an entity s 51 Cyber Security Incident response plan. Rather, the Guide should highlight the plans to Operators so that they 52 can understand their role and what their company expects them to do.
5 Developers of Cyber Security 53 Incident response plans are encouraged to consider Operators perspective when creating their 54 organization s plans. 55 As noted above, Reliability Guidelines are not to be used to provide binding norms or create parameters by 56 which compliance to standards is monitored or enforced. 57 Contents 58 A. Could this be a sign of an attack? Recognizing indicators of potentially malicious activity 59 B. Initial Actions and Internal Notifications 60 C. Response Actions and External Notifications 61 D. Summary 62 3 For an overview of Social Engineering and Phishing attacks, please refer to US-CERT Security Tip ST04-14 at 4 See for more information, particularly the Methodology paper linked from there. Reliability Guideline: Cyber Intrusion Guide for System Operators Version 2 3 Approved by the Reliability and Security Technical Committee on DATE A.
6 Could this be a sign of an attack? Recognizing indicators of potentially 63 malicious activity 64 As threats to Cyber Assets are continually evolving, it is difficult to provide a comprehensive list of anomalies 65 that may require investigation or a response. Rather, an operator s familiarity with their systems, awareness 66 and a questioning attitude likely provide the greatest value. Real-time operating staff should be vigilant in 67 asking themselves why their Cyber Assets are responding unusually. The System Operator should be asking 68 their Information Technology (IT) support to investigate any strange, unusual behavior, whenever it is 69 detected. Similar to physical security concerns, Operators should be encouraged to say something when 70 they see something. It is understood that increased vigilance may result in false positive reports. However, 71 it is better to play it safe when Cyber Assets are behaving unusually.
7 72 Examples of anomalies that may require attention: 73 Workstation unexpectedly locked out and/or receive a message indicates password has been 74 changed 75 Pointer or mouse cursor moving by itself 76 Files / messages flashing / suspicious pop-ups appear on the screen 77 New icons appear on desktop or in start menu 78 System is unusually slow or unresponsive 79 Simultaneous loss of operational support systems ( , Heating, Ventilation, and Air 80 Conditioning (HVAC), Fire Suppression, phone/communications) 81 Observing unusual System activity or alarms from Cyber Assets. For example: 82 Simultaneous loss of multiple components of the Energy Management Systems (EMS), 83 Supervisory Control and Data Acquisition (SCADA) System 84 Multiple breaker operations during a non-storm event 85 Any unexplainable manual operations 86 Multiple perceived suspicious readings 87 Requests for information about the System (social engineering attempts) 88 Unexpected System shutdown or reboot 89 Complete loss of SCADA capabilities that support Real-time operations.
8 90 Erratic EMS/SCADA System equipment behaviour, messages/alarms, or degradation of 91 performance, especially when more than one device exhibits the same behaviour 92 Anti-malware application alerts on operator Human Machine Interface(s) 93 Unexpected user account authentication lockouts or change in user privileges 94 Calls from data partners (other entities who see your data) to verify suspicious data being 95 received via communication associations/exchange 96 Reliability Guideline: Cyber Intrusion Guide for System Operators Version 2 4 Approved by the Reliability and Security Technical Committee on DATE B. Initial Actions and Internal Notifications 97 When unusual System behavior is observed, take any immediate steps outlined in your Cyber Security 98 Incident response plan. As soon as possible, contact your Cyber security team and follow their instructions. 99 When describing the issue, include details on the observed and potential impacts of the situation.
9 This will 100 help responders as they work through the identification, containment, eradication, and recovery phases of 101 incident response. Depending on an entity s Cyber Security Incident response plan, this may require an 102 operator to: 103 Contact EMS, Operational Technology (OT), IT, and Cyber security personnel. 104 Notify the other Operators on duty. 105 Notify field personnel working in or around potentially involved facilities. 106 C. Response Actions and External Notifications 107 Once your organization s Cyber Security Incident response plan has been initiated, follow the reporting 108 instructions of the plan. This may involve: 109 Notifying other control centers adjacent, distribution via Reliability Coordinator Information 110 System (RCIS), etc. 111 Receiving legal guidance on allowable release of information, or Cyber security staff assuming 112 responsibility for confidential communications related to the incident.
10 113 Cyber security staff isolating certain equipment for containment, forensic analysis, evidence 114 retention, and recovery. 115 Law enforcement personnel requesting particular actions to preserve evidence. Reliable 116 operations should be maintained through a coordinated response between law enforcement, 117 operations, and an entity s physical/ Cyber security teams. 118 As the incident response progresses, be prepared to take actions as documented in your organization s 119 Operating Plan. These could include implementing specific Operating Procedures as a result of incident 120 response activities ( , changing the status of equipment or monitoring and control systems to support 121 investigation), or general Operating Processes as proactive steps ( , declaring a conservative operations 122 status). 123 D. Summary 124 Due to their unique role in operating the BES, System Operators may be the first to observe unusual 125 behavior.