SlideShare ist ein Scribd-Unternehmen logo
1 von 14
Welcome to Today’s Webinar:
NERC CIP – Manage, Maintain & Improve
Compliance with Internal Controls

Tuesday, January 14, 2014
11:30 a.m. EST
Sid Shaffer, Senior Manager
Robert Janusaitis, Senior Manager

icfi.com |

1
NERC RAI – Expected Aspects
• RAI - Reliability Assurance Initiative
– NERC change in compliance strategy

• Shift away from the ―Zero Tolerance‖ towards ―Risk Based‖
approach
• Fully implemented by 2016
– Similar to the enforcement timeline for v5 of CIP

• Use of traditional audit approaches (ie GAGAS, IIA)
• Greater focus on matters of greater risk
(Serious & Substantial)
• Larger emphasis on internal controls
icfi.com |

2
Our RAI Audit Experience
• RAI is a good thing
• Two week onsite audit was completed in 2.5 days
• How did we get there?
– Committed client team
– Controls based approach & Gap Analysis well before audit date
• Time to properly remediate concerns

– Use of Internal Controls concepts made evidence generation more
efficient
• Blue Text
• Attachment C
• RSAWs well written

– Mock Audit to prepare SMEs
– Open and honest communication with audit team

• RAI is not in its ‗final‘ state – closely watch this develop

icfi.com |

3
Internal Controls Components
Monitoring

Control Activities

 Assessment of a control system‘s

 Policies/procedures that ensure

performance over time.

management directives are
carried out.

 Combination of ongoing and

 Range of activities including

separate evaluation.

approvals, authorizations, verific
ations, recommendations, perfor
mance reviews, asset security
and SOD

 Management and supervisory
activities.

 Internal audit activities.

Information and Communication

Control Environment

 Pertinent information identified,

 Sets tone of organization-

captured and communicated in a
timely manner.

influencing control consciousness
of its people.

 Access to internal and externally

 Factors include integrity, ethical

generated information.

values, competence, authority, res
ponsibility.

 Flow of information that allows for
successful control actions from
instructions on responsibilities to
summary of findings for
management action.

 Foundation for all other

Risk Assessment

 Risk assessment is the
identification and analysis of
relevant risks to achieving the
entity‘s objectives-forming the
basis for determining control
activities.

components of control.
All five components must be in place
for a control to be effective.

Source: COSO Internal Control - Integrated Framework

icfi.com |

4
Controls
•

Definition
– control noun, often attributive : an action, method, or
law that limits the amount or growth of something.
(Merriam-Webster.com)

• i.e. limit the amount of risk

•

Everyday Examples of Controls
– Locking your vehicle when you park
– Assigning a passcode to your ATM
– Inspecting lawnmower (or other equipment) for
damage or defect
– Reviewing a bank statement for unauthorized
transactions

•

Controls are not always a “hindrance”
– A correctly designed and implemented control
may actually help you go faster
• i.e. brakes on a car

icfi.com |

When an organization
internalizes similar
activities as part of an
ongoing process, they
become “internal
controls”

5
Internal Controls
• Fundamental Concepts
– Geared to the achievement of objectives in one or more categories –
operations, reporting, and compliance
– A process consisting of ongoing tasks and activities – a means to an
end not an end in itself
– Effected by people – not merely about policy and procedure manuals,
systems, and forms, but about people and the actions they take at every
level of an organization to effect internal control
– Able to provide reasonable assurance – but not absolute assurance, to
an entity‘s senior management and board of directors
– Adaptable to the entity structure – flexible in application for the entire
entity or for a particular subsidiary, division, operating unit, or business
process
Source: COSO Internal Control - Integrated Framework, Executive Summary (May 2013)

icfi.com |

6
Types of Internal Controls
•

Preventative — Before
– Controls designed to prevent event or reduce risk
before occurrence
• Policies and procedures
• Training and education
• Access Restrictions

•

Detective — During
– Controls designed to discover event or reduce risk
during or after occurrence
• Log reviews & analysis
• Access reviews
• Vulnerability Assessments

•

Corrective — After
– Controls designed to address or reduce risk after
event occurrence or discovery
• Firmware updates
• Corrective Changes to access
• Restoration from Backup

icfi.com |

Controls may be
more than one type
Anti Virus Software
is typically all 3

7
Internal Controls Example
•

CIP-007 Controls
– R6: Security Status Monitoring — The Responsible Entity shall ensure that all
Cyber Assets within the Electronic Security Perimeter, as technically feasible,
implement automated tools or organizational process controls to monitor system
events that are related to cyber security

•

Preventative Controls:
– Policy and procedures
– Training
– Configuration standards defined & implemented

•

Detective Controls:
– Alerts to potential events via email
– Event analysis

•

Corrective Controls:
– Manual or automatic shut down of affected
IP addresses, ports, or services

icfi.com |

8
Internal Control Benefits
•
•
•
•
•
•

Improved detection of control deficiencies
Increased confidence in overall compliance
Efficiency opportunities – address multiple compliance objectives at once
Potential for reduced penalties for violations1
Provides for increased accountability and greater oversight
Allows for more efficient resource utilization
– Proactive vs. Reactive

•

From NERC RAI Q&A V1:
– Future audits could evaluate and test an entity‘s internal controls with a
reduced focus on the traditional audit
– Potential reduction in audit preparation activities
– Effective internal controls can support a determination of reduced
control risk for the entity

1Source:

NERC: Internal Controls; Their Role in Electric Reliability, and Effects on Compliance Monitoring (September 18, 2012)

icfi.com |

9
Applying Internal Controls Program to NERC & NERC CIP
• Not a ―Silver Bullet‖ to solve compliance
• Review existing processes, procedures and policies to determine if
they facilitate compliance with the Reliability Standards
• Document current internal controls to verify against a framework
– such as COSO

•
•
•
•

Maintain a process for corrective action
Identify accountable parties / Establish a command structure
Catalogue and document controls
Develop process for regular review and improvement of control
environment

icfi.com |

10
Internal Controls Program
• Management Controls Program should be able to:
–
–
–
–

Accurately log what has occurred
Maintain records of what has been done
Aggregate similar problems
Produce evidence to substantiate not only what you SAY happened, but
evidence what ACTUALLY happened
• Forms vs. System Logs

• Controls in an Internal Controls Program are:
– Defined & Documented
• All 8 control components defined

– Assigned
– Performed
– Monitored

icfi.com |

11
Monitor the Controls
• Reasons to Test
–
–
–
–

Ready for self certifications
Audit preparedness
Reduce risk of non-compliance
Great way to capture lessons learned and best practices

• Testing considerations
–
–
–
–
–

Use Test plans (scripts)
Select a sampling methodology
Test DESIGN and EFFECTIVENESS
Develop a schedule
Adjust testing focus based on Risk, Past Issues, Industry Concerns, etc.

• Capture and share lessons learned and best practices
icfi.com |

12
Example of an End State
• Manage
– Holistic corporate controls framework covers areas of business risk
(including NERC)
• Reduces redundancy (could apply to NERC, SOX, other compliance efforts)

• Maintain
– Ongoing operation of internal controls will ensure that compliance is
maintained

• Improve
– Reviewing & Revising steps to ensure internal controls are effective will
continuously improve the compliance efforts
– Corrective actions taken as a result of ongoing monitoring of the control
environment will improve overall risk profile

icfi.com |

13
Questions, Contact Information
•

ICF offers the following cyber security services:
–
–
–
–
–
–
–
–

•

Regulatory Monitoring and Policy Support
Compliance Program Evaluation
Compliance Assessments and Mock Audits
Cybersecurity Readiness
Mitigation and Implementation
Internal Controls and Audit Programs
Training
Managed Services

Familiar with multiple frameworks and methodologies
–
–
–
–
–
–
–

icfi.com |

NERC CIP
NRC 5.71 and NEI 08-09
NIST 800-53 and NISTIR-7628
COBIT
ISO17799/BS7799
ES-C2M2
COSO

Contact Information:
Sid Shaffer,
Senior Manger
Sid.Shaffer@icfi.com
+1.713.445.2019
Michael Sanchez, VP
Michael.Sanchez@icfi.com
+1.713.445.2002

14

Weitere ähnliche Inhalte

Mehr von ICF

Sustainable aviation fuels: A new route to net zero for the aviation industry
Sustainable aviation fuels: A new route to net zero for the aviation industrySustainable aviation fuels: A new route to net zero for the aviation industry
Sustainable aviation fuels: A new route to net zero for the aviation industryICF
 
Meeting and collaborating from a distance
Meeting and collaborating from a distanceMeeting and collaborating from a distance
Meeting and collaborating from a distanceICF
 
Planning & Designing for Accessible Experiences
Planning & Designing for Accessible ExperiencesPlanning & Designing for Accessible Experiences
Planning & Designing for Accessible ExperiencesICF
 
IEDC COVID-19 webinar
IEDC COVID-19 webinarIEDC COVID-19 webinar
IEDC COVID-19 webinarICF
 
Strategies for developing measurable goals
Strategies for developing measurable goalsStrategies for developing measurable goals
Strategies for developing measurable goalsICF
 
The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...
The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...
The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...ICF
 
How one team unlocked a cultural experience that created a movement
How one team unlocked a cultural experience that created a movementHow one team unlocked a cultural experience that created a movement
How one team unlocked a cultural experience that created a movementICF
 
Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)
Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)
Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)ICF
 
A National Review of Combined Heat and Power Programs in utility Energy Effic...
A National Review of Combined Heat and Power Programs in utility Energy Effic...A National Review of Combined Heat and Power Programs in utility Energy Effic...
A National Review of Combined Heat and Power Programs in utility Energy Effic...ICF
 
Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...
Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...
Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...ICF
 
Airport Competition Dynamics
Airport Competition DynamicsAirport Competition Dynamics
Airport Competition DynamicsICF
 
Assessing Child Vaccine Hesitancy using Mobile Panels
Assessing Child Vaccine Hesitancy using Mobile PanelsAssessing Child Vaccine Hesitancy using Mobile Panels
Assessing Child Vaccine Hesitancy using Mobile PanelsICF
 
MRO Market Update & Industry Trends
MRO Market Update & Industry TrendsMRO Market Update & Industry Trends
MRO Market Update & Industry TrendsICF
 
MRO Market Update and Industry Trends
MRO Market Update and Industry TrendsMRO Market Update and Industry Trends
MRO Market Update and Industry TrendsICF
 
Evaluation of the Impact of Fire and Rescue
Evaluation of the Impact of Fire and RescueEvaluation of the Impact of Fire and Rescue
Evaluation of the Impact of Fire and RescueICF
 
Smoothing the NEPA Process for Freight Rail
Smoothing the NEPA Process for Freight RailSmoothing the NEPA Process for Freight Rail
Smoothing the NEPA Process for Freight RailICF
 
Passenger Analytics: A Better Way to Manage Airports
Passenger Analytics: A Better Way to Manage AirportsPassenger Analytics: A Better Way to Manage Airports
Passenger Analytics: A Better Way to Manage AirportsICF
 
Latin American MRO Market Update & Industry Trends
Latin American MRO Market Update & Industry Trends Latin American MRO Market Update & Industry Trends
Latin American MRO Market Update & Industry Trends ICF
 
ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...
ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...
ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...ICF
 
2013 Global MRO Market Forecast & Trends
2013 Global MRO Market Forecast & Trends2013 Global MRO Market Forecast & Trends
2013 Global MRO Market Forecast & TrendsICF
 

Mehr von ICF (20)

Sustainable aviation fuels: A new route to net zero for the aviation industry
Sustainable aviation fuels: A new route to net zero for the aviation industrySustainable aviation fuels: A new route to net zero for the aviation industry
Sustainable aviation fuels: A new route to net zero for the aviation industry
 
Meeting and collaborating from a distance
Meeting and collaborating from a distanceMeeting and collaborating from a distance
Meeting and collaborating from a distance
 
Planning & Designing for Accessible Experiences
Planning & Designing for Accessible ExperiencesPlanning & Designing for Accessible Experiences
Planning & Designing for Accessible Experiences
 
IEDC COVID-19 webinar
IEDC COVID-19 webinarIEDC COVID-19 webinar
IEDC COVID-19 webinar
 
Strategies for developing measurable goals
Strategies for developing measurable goalsStrategies for developing measurable goals
Strategies for developing measurable goals
 
The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...
The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...
The Role of Government-Funded Assistance Programs on HIV Testing among Poor A...
 
How one team unlocked a cultural experience that created a movement
How one team unlocked a cultural experience that created a movementHow one team unlocked a cultural experience that created a movement
How one team unlocked a cultural experience that created a movement
 
Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)
Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)
Federal Dollars for Improving Energy Infrastructure Resilience (NASEO 2019)
 
A National Review of Combined Heat and Power Programs in utility Energy Effic...
A National Review of Combined Heat and Power Programs in utility Energy Effic...A National Review of Combined Heat and Power Programs in utility Energy Effic...
A National Review of Combined Heat and Power Programs in utility Energy Effic...
 
Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...
Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...
Assessing the Impact of Mentoring: Lessons Learned from a Research Study in W...
 
Airport Competition Dynamics
Airport Competition DynamicsAirport Competition Dynamics
Airport Competition Dynamics
 
Assessing Child Vaccine Hesitancy using Mobile Panels
Assessing Child Vaccine Hesitancy using Mobile PanelsAssessing Child Vaccine Hesitancy using Mobile Panels
Assessing Child Vaccine Hesitancy using Mobile Panels
 
MRO Market Update & Industry Trends
MRO Market Update & Industry TrendsMRO Market Update & Industry Trends
MRO Market Update & Industry Trends
 
MRO Market Update and Industry Trends
MRO Market Update and Industry TrendsMRO Market Update and Industry Trends
MRO Market Update and Industry Trends
 
Evaluation of the Impact of Fire and Rescue
Evaluation of the Impact of Fire and RescueEvaluation of the Impact of Fire and Rescue
Evaluation of the Impact of Fire and Rescue
 
Smoothing the NEPA Process for Freight Rail
Smoothing the NEPA Process for Freight RailSmoothing the NEPA Process for Freight Rail
Smoothing the NEPA Process for Freight Rail
 
Passenger Analytics: A Better Way to Manage Airports
Passenger Analytics: A Better Way to Manage AirportsPassenger Analytics: A Better Way to Manage Airports
Passenger Analytics: A Better Way to Manage Airports
 
Latin American MRO Market Update & Industry Trends
Latin American MRO Market Update & Industry Trends Latin American MRO Market Update & Industry Trends
Latin American MRO Market Update & Industry Trends
 
ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...
ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...
ICF MRO Market Forecast & Trends – Asia Pacific March 9-10, 2016 Airline E&M:...
 
2013 Global MRO Market Forecast & Trends
2013 Global MRO Market Forecast & Trends2013 Global MRO Market Forecast & Trends
2013 Global MRO Market Forecast & Trends
 

KĂźrzlich hochgeladen

Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture conceptP&CO
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...allensay1
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...amitlee9823
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Centuryrwgiffor
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperityhemanthkumar470700
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Whitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
Whitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLWhitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
Whitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon investment
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756dollysharma2066
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Sheetaleventcompany
 

KĂźrzlich hochgeladen (20)

Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Whitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
Whitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLWhitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
Whitefield CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business Potential
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 

NERC CIP: Manage, Maintain, and Improve Compliance with Internal Controls

  • 1. Welcome to Today’s Webinar: NERC CIP – Manage, Maintain & Improve Compliance with Internal Controls Tuesday, January 14, 2014 11:30 a.m. EST Sid Shaffer, Senior Manager Robert Janusaitis, Senior Manager icfi.com | 1
  • 2. NERC RAI – Expected Aspects • RAI - Reliability Assurance Initiative – NERC change in compliance strategy • Shift away from the ―Zero Tolerance‖ towards ―Risk Based‖ approach • Fully implemented by 2016 – Similar to the enforcement timeline for v5 of CIP • Use of traditional audit approaches (ie GAGAS, IIA) • Greater focus on matters of greater risk (Serious & Substantial) • Larger emphasis on internal controls icfi.com | 2
  • 3. Our RAI Audit Experience • RAI is a good thing • Two week onsite audit was completed in 2.5 days • How did we get there? – Committed client team – Controls based approach & Gap Analysis well before audit date • Time to properly remediate concerns – Use of Internal Controls concepts made evidence generation more efficient • Blue Text • Attachment C • RSAWs well written – Mock Audit to prepare SMEs – Open and honest communication with audit team • RAI is not in its ‗final‘ state – closely watch this develop icfi.com | 3
  • 4. Internal Controls Components Monitoring Control Activities  Assessment of a control system‘s  Policies/procedures that ensure performance over time. management directives are carried out.  Combination of ongoing and  Range of activities including separate evaluation. approvals, authorizations, verific ations, recommendations, perfor mance reviews, asset security and SOD  Management and supervisory activities.  Internal audit activities. Information and Communication Control Environment  Pertinent information identified,  Sets tone of organization- captured and communicated in a timely manner. influencing control consciousness of its people.  Access to internal and externally  Factors include integrity, ethical generated information. values, competence, authority, res ponsibility.  Flow of information that allows for successful control actions from instructions on responsibilities to summary of findings for management action.  Foundation for all other Risk Assessment  Risk assessment is the identification and analysis of relevant risks to achieving the entity‘s objectives-forming the basis for determining control activities. components of control. All five components must be in place for a control to be effective. Source: COSO Internal Control - Integrated Framework icfi.com | 4
  • 5. Controls • Definition – control noun, often attributive : an action, method, or law that limits the amount or growth of something. (Merriam-Webster.com) • i.e. limit the amount of risk • Everyday Examples of Controls – Locking your vehicle when you park – Assigning a passcode to your ATM – Inspecting lawnmower (or other equipment) for damage or defect – Reviewing a bank statement for unauthorized transactions • Controls are not always a “hindrance” – A correctly designed and implemented control may actually help you go faster • i.e. brakes on a car icfi.com | When an organization internalizes similar activities as part of an ongoing process, they become “internal controls” 5
  • 6. Internal Controls • Fundamental Concepts – Geared to the achievement of objectives in one or more categories – operations, reporting, and compliance – A process consisting of ongoing tasks and activities – a means to an end not an end in itself – Effected by people – not merely about policy and procedure manuals, systems, and forms, but about people and the actions they take at every level of an organization to effect internal control – Able to provide reasonable assurance – but not absolute assurance, to an entity‘s senior management and board of directors – Adaptable to the entity structure – flexible in application for the entire entity or for a particular subsidiary, division, operating unit, or business process Source: COSO Internal Control - Integrated Framework, Executive Summary (May 2013) icfi.com | 6
  • 7. Types of Internal Controls • Preventative — Before – Controls designed to prevent event or reduce risk before occurrence • Policies and procedures • Training and education • Access Restrictions • Detective — During – Controls designed to discover event or reduce risk during or after occurrence • Log reviews & analysis • Access reviews • Vulnerability Assessments • Corrective — After – Controls designed to address or reduce risk after event occurrence or discovery • Firmware updates • Corrective Changes to access • Restoration from Backup icfi.com | Controls may be more than one type Anti Virus Software is typically all 3 7
  • 8. Internal Controls Example • CIP-007 Controls – R6: Security Status Monitoring — The Responsible Entity shall ensure that all Cyber Assets within the Electronic Security Perimeter, as technically feasible, implement automated tools or organizational process controls to monitor system events that are related to cyber security • Preventative Controls: – Policy and procedures – Training – Configuration standards defined & implemented • Detective Controls: – Alerts to potential events via email – Event analysis • Corrective Controls: – Manual or automatic shut down of affected IP addresses, ports, or services icfi.com | 8
  • 9. Internal Control Benefits • • • • • • Improved detection of control deficiencies Increased confidence in overall compliance Efficiency opportunities – address multiple compliance objectives at once Potential for reduced penalties for violations1 Provides for increased accountability and greater oversight Allows for more efficient resource utilization – Proactive vs. Reactive • From NERC RAI Q&A V1: – Future audits could evaluate and test an entity‘s internal controls with a reduced focus on the traditional audit – Potential reduction in audit preparation activities – Effective internal controls can support a determination of reduced control risk for the entity 1Source: NERC: Internal Controls; Their Role in Electric Reliability, and Effects on Compliance Monitoring (September 18, 2012) icfi.com | 9
  • 10. Applying Internal Controls Program to NERC & NERC CIP • Not a ―Silver Bullet‖ to solve compliance • Review existing processes, procedures and policies to determine if they facilitate compliance with the Reliability Standards • Document current internal controls to verify against a framework – such as COSO • • • • Maintain a process for corrective action Identify accountable parties / Establish a command structure Catalogue and document controls Develop process for regular review and improvement of control environment icfi.com | 10
  • 11. Internal Controls Program • Management Controls Program should be able to: – – – – Accurately log what has occurred Maintain records of what has been done Aggregate similar problems Produce evidence to substantiate not only what you SAY happened, but evidence what ACTUALLY happened • Forms vs. System Logs • Controls in an Internal Controls Program are: – Defined & Documented • All 8 control components defined – Assigned – Performed – Monitored icfi.com | 11
  • 12. Monitor the Controls • Reasons to Test – – – – Ready for self certifications Audit preparedness Reduce risk of non-compliance Great way to capture lessons learned and best practices • Testing considerations – – – – – Use Test plans (scripts) Select a sampling methodology Test DESIGN and EFFECTIVENESS Develop a schedule Adjust testing focus based on Risk, Past Issues, Industry Concerns, etc. • Capture and share lessons learned and best practices icfi.com | 12
  • 13. Example of an End State • Manage – Holistic corporate controls framework covers areas of business risk (including NERC) • Reduces redundancy (could apply to NERC, SOX, other compliance efforts) • Maintain – Ongoing operation of internal controls will ensure that compliance is maintained • Improve – Reviewing & Revising steps to ensure internal controls are effective will continuously improve the compliance efforts – Corrective actions taken as a result of ongoing monitoring of the control environment will improve overall risk profile icfi.com | 13
  • 14. Questions, Contact Information • ICF offers the following cyber security services: – – – – – – – – • Regulatory Monitoring and Policy Support Compliance Program Evaluation Compliance Assessments and Mock Audits Cybersecurity Readiness Mitigation and Implementation Internal Controls and Audit Programs Training Managed Services Familiar with multiple frameworks and methodologies – – – – – – – icfi.com | NERC CIP NRC 5.71 and NEI 08-09 NIST 800-53 and NISTIR-7628 COBIT ISO17799/BS7799 ES-C2M2 COSO Contact Information: Sid Shaffer, Senior Manger Sid.Shaffer@icfi.com +1.713.445.2019 Michael Sanchez, VP Michael.Sanchez@icfi.com +1.713.445.2002 14

Hinweis der Redaktion

  1. The evolution of the CMEP program towards the RAI program often draws parallels to the SOX audit maturation progression – (by Charles Berardesco, NERC Senior VP & General Counsel)one away from testing everything – towards a greater reliance on management’s attestation of the controls and a more reasoned testing approach thereof-However practical application involves a bit of “reading the tea leaves, looking into the crystal ballShift away from the “Zero Tolerance” method of prior monitoring and enforcement towards a more “Risk Based” approach.Expected to use foundational audit approaches presented by:Generally Accepted Government Auditing Standards (GAGAS) Institute of Internal Auditors (IIA)Expected to be fully implemented by 2016Similar to the enforcement timeline for v5 of the CIP standardsExpected to place a greater focus on matters of greater risk (Serious & Substantial) and provide an alternate path forward for items that are deemed lesser risk (Moderate and Minor).Expected to place a larger emphasis on internal controls and provide a synergy between internal controls and the monitoring and enforcement process.
  2. Attachment C used by RFC, SERC, and othersRSAW well written = Clear & Concise, just the factsUncertainty around practical application of RAI“Serious & Substantial Risk” not yet defined“Successful Internal Compliance Program” not yet definedLots of currently moving parts – don’t know how they will all fit togetherFind, Fix, Track & Report process (FFT)“Identify, Assess, & Correct” (IAC) language in CIP v5 (and elsewhere)FERC Order of 11/22/2013 directs NERC to remove IAC language included in 17 requirements of CIPv5 and submit proposal to address within 1 year. Also details need distinguish “Successful Internal Compliance Program” from one that is inadequate.Either way - Internal Controls Programs will be the futureAdopting a comprehensive controls approach now will address ambiguity in the IAC language or other uncertainties – as it provides a stable platform from which to address risk
  3. Lots of Complexity / Things to think aboutFor NERCRAI, focus is primarily on Control Activity & Monitoring components Both the IIA and GAGAS endorse the COSO framework which aligns with the NERC Rules of Procedure, Appendix 4C (CMEP) §3.1
  4. CIP-007 example of a detective control might be: A ‘central’ logging mechanism and transmission to a third party service for the aggregation and analysis of security logs.
  5. Improved detection = Allows quicker response.
  6. NERC has said they are not asking management to reinvent their management practices. Merely taking inventory of those management practices already in place may address much of what is being asked for.process for corrective action = “Corrective Action Program”
  7. Without testing DESIGN controls can atrophy / become irrelevantTEST OF EFFECTIVENESS