ellen_messmer
Senior Editor, Network World

Federal security rules fueling energy company anxiety

News
Sep 28, 20066 mins

SCADA systems seen as vulnerable to cyberattack.

The nation’s energy companies are scrambling to meet government regulations going into effect as soon as January that in part are designed to safeguard the computer-based control systems for electricity and gas distribution from cyberattacks.

SAN FRANCISCO — The nation’s energy companies are scrambling to meet government regulations going into effect as soon as January that in part are designed to safeguard the computer-based control systems for electricity and gas distribution from cyberattacks.

Top energy IT officials say they are challenged to meet the new rules because the massive systems control and data acquisition (SCADA) systems used to manage their resources increasingly are based on Windows and Unix but weren’t really designed with network security in mind. The systems often don’t work easily with antivirus software and can be tough to patch, they say.

In addition, the SCADA systems increasingly share the same corporate network as other business applications, but the people running the SCADA and voice/data networks are on separate teams. “In companies I’ve seen, they choose to be separate,” said Evon Salle, senior information systems auditor at OGE Energy, in Oklahoma City, and a forum participant at the IT Security World Conference here.

Congress took up the cause of greater SCADA security after a massive power blackout in the summer of 2003, passing legislation that has led to the creation of nine Critical Infrastructure Protection (CIP) rules.

These were devised under the aegis of the North American Electric Reliability Council (NERC), the trade group recently chosen by the Federal Energy Regulatory Commission to set mandatory security standards for the energy sector. NERC also is expected to be in charge of rules enforcement, which could include dishing out million-dollar fines for noncompliance.

The CIP rules cover areas such as reporting sabotage, ensuring physical security, monitoring and running antivirus controls, and doing patch updates on all critical assets, including control centers, substations and SCADA systems.

Energy companies say they’re prodding SCADA operations groups to work with the corporate IT departments to impose firewalls, access control, encryption and antivirus controls if they weren’t there before. But technical challenges remain.

“A lot of times you won’t have virus protection in a SCADA environment,” Salle said.

“Virus software, such as from McAfee and Symantec, thinks the SCADA system is a virus and that’s why you can’t run it.”

The biggest risk is “SCADA not having a firewall, while also having Internet access,” she added.

Energy companies acknowledge that their SCADA systems haven’t been immune to virus outbreaks.

“We’ve had viruses hit one of our plants,” said Charles Simons, manager of firewall integrity management at BP Global. The company immediately firewalled off its process-control networks and put corporate IT security in control of industrial systems.

Complying with the CIP guidelines to cordon off SCADA and apply a battery of security controls is proving difficult for some.

“It’s quite a culture change for us, especially for substations and generators,” said Sharon Edwards, project manager for implementing the cybersecurity guidelines at Duke Energy. So far, Duke Energy hasn’t been able to identify vendors that would help in implementing the enormous log collection and management and other requirements dictated by CIP.

“We may have to develop one ourselves,” Edwards said.

That will involve combining expertise in the IT and SCADA groups, she said. “But in SCADA, we haven’t gotten to the place of having good communications,” she said, adding, “I don’t think we’re unique in that.”

Edwards noted that one idea under discussion for achieving CIP compliance would entail equipping employees with two PCs on their desktop, one for access for secure accounts and the other for e-mail and Internet access.

Several energy companies said they are prodding SCADA vendors, such as Honeywell, Foxboro and Wonderware, to meet the security challenges brought by CIP.

“SCADA systems manage valves and pressures,” said Jay White, global architect for information protection, policies and standards, at Chevron’s IT division. “They’re mission-critical. If you lose control over them, you could have an irreversible environmental impact.”

Upgrading SCADA systems, often designed to last more than a decade and traditionally proprietary in their underlying software, could prove expensive and energy company customers could wind up footing much of the bill.

“The electric companies will have to pay to implement the standards and it will reflect in the rates,” predicted Robert Schainker, technical executive for strategic planning in the office of innovation at Electric Power Research Institute, a nonprofit organization in Palo Alto for research on energy and the environment.

Enforcing the rules

One of the biggest uncertainties about the new security regime is how NERC will carry out its newly acquired mission in network security.

“NERC is no longer a volunteer organization, it’s a regulatory organization,” Schainker said, adding that this is appropriate because the industry will benefit from improved network security. “There will be hackers out there, and more terrorists, and we have to be ready to meet these challenges.”

Several industry insiders last week acknowledged that SCADA systems, some now Web-based, are known to be open enough to be fairly easily hackable, whether by insiders or outsiders. While some hacking-based disruptions have occurred in SCADA systems, no major cyberattack has occurred.

Schainker predicts that when NERC begins imposing fines for noncompliance, there will be an eruption of lawsuits. In the end, court decisions will probably guide how this new cybersecurity regulation evolves.

Some corporations, including Duke Energy, acknowledge they have fought the imposition of CIP. Their reluctance stems in part from the fact that the Department of Homeland Security is pushing them to supply detailed proprietary information about how they operate.

“There’s a lot of push-back from industry on this,” Edwards said.

Meanwhile, the Department of Defense has long worked under a strict regimen for SCADA systems, which exist on Navy ships, said Herbert Armstrong, IT security director at the Navy’s Warfare Training Center in Ingleside, Texas.

“The SCADA systems are subject to review, and we separate them from the rest of the network,” Armstrong said. Strong authentication, including the Defense Department’s Common Access Card and biometrics, are needed to prove identity to access SCADA systems. “We’re most concerned about the insider threat,” he said.

But Armstrong acknowledged the private sector may face an even tougher challenge than the military in SCADA security, because corporations, facing different financial pressures, may have greater need to combine data from both business and SCADA systems, making it hard to cordon one off from the other.