On-site Cyber Security and NERC CIP Assessment Siemens Energy, Inc., a supplier of instrumentation, controls & electrical solutions, as well as turnkey power plants, can assist you in your overall cyber security compliance process. Siemens is one of the very few companies with an in-house private Cyber Emergency Response Team (CERT). We can help you achieve NERC critical infrastructure protection (CIP) compliance. Siemens’ on-site cyber security and NERC CIP Assessments are designed to help you identify any existing security vulnerabilities in your control systems, related IT infrastructures and beyond. Published by and copyright © 2009: Siemens Energy, Inc. Instrumentation, Controls & Electrical 1345 Ridgeland Parkway Alpharetta, GA 30004 USA Tel: (678) 256-1500 Fax: (678) 256-1553 Siemens AG Energy Sector Freyeslebenstrasse 1 91058 Erlangen, Germany www.siemens.com/energy/cybersecurity Order No. E50001-E230-A128-X-76US Printed in USA 871 COLMO1D DA 0608.5 All rights reserved. Subject to change without prior notice. Trademarks mentioned in this docu-ment are the property of Siemens AG, its affiliates, or their respective owners. The information in this document contains general descriptions of the technical options available, which may not apply in all cases. The required technical options should therefore be specified in the contract. Together with our cyber security alliance partners, we provide comprehensive security audits to assess your compliance with NERC CIP-002 through CIP-009. The assessment is conducted by Siemens cyber security experts and, as needed, with experts from our alliance partners. The process includes evaluating your current control systems, and related cyber systems to assess whether they meet the controls relevant CIP-005, 007 and 009 sections. These sections can be addressed separately from the overall assessment. As a result of this assessment, Siemens will provide a detailed report documenting all the findings. Customized recommendations also will be offered to improve and enhance your cyber security, that would allow you to meet and maintain NERC CIP compliance. Siemens Power Plant Automation (SPPA™) systems are designed with enhanced security configuration and architecture to meet NERC CIP standards. Our innovative SPPA-T3000 control system is ”NERC CIPReady.” Our offering On-site CIP-002- CIP-009 assessments On-site CIP-005, CIP-007 and CIP-009 controls and associated cyber infrastructure assessments. Maintenance of NERC CIP compliance annual assessments. Solutions and upgrades to achieve and maintain NERC CIP compliance. On-site Cyber Security and NERC CIP Assessments The controls relevant assessment includes but is not limited to: Electronic security perimeters and DMZs Systems security management Recovery plans, as well as back up and restore procedures. The NERC CIP-002 through CIP-009 overall compliance assessment is carried out in conjunction with our cyber security alliance partners. A detailed report generated after the onsite assessment includes a recommended customized roadmap to reduce and mitigate security vulnerabilities and achieve CIP compliance. For more information, please contact your local Siemens representative. On-site Cyber Security and NERC CIP Assessment Answers for energy. Cyber Security insert.indd 1 4/14/09 1:43:53 PM