CRAIG LIGHTNER SUPERVISOR AUTOMATION AND CONTROL · CRAIG LIGHTNER SUPERVISOR AUTOMATION AND...

Post on 24-Jul-2020

2 views 0 download

Transcript of CRAIG LIGHTNER SUPERVISOR AUTOMATION AND CONTROL · CRAIG LIGHTNER SUPERVISOR AUTOMATION AND...

CRAIGLIGHTNER

SUPERVISORAUTOMATIONAND

CONTROL

2

2

TypesofNaturalGasCompanies

• GasProduction- WellHeadProduction,LandfillProduction,FrackingProduction

• GasTransportation- InterstatePipelines

• GasLDC- LocalDistributionCompany

2

RedundancyofService• Ourproductisourenergysource– Itpowersourgenerators– Itpowersourpneumaticbackupsystems

• Pipesareloopedmuchlikeacommunicationringnetwork

• WemaintainanindependentpressuremonitoringsystemnotconnectedtoourICSnetwork

EntitiesVyingtoRegulatetheNaturalGasIndustry

DHS– DepartmentofHomelandSecurityCFATS- ChemicalFacilityAnti-TerrorismStandards(DHSSubcommittee)

DOE– DepartmentofEnergyDOT– DepartmentofTransportation(Regulatestransportationpipelines)

FERC– FederalEnergyRegulatoryCommission(Regulatestransportationpipelines,anAdministrationunderDOT)

EntitiesVyingtoRegulatetheNaturalGasIndustry

PHMSA– PipelineandHazardousMaterialSafetyAdministration(RegulatesALLNaturalGasControlRooms,anAdministrationunderDOT)

NERC- NorthAmericanElectricReliabilityCorporation(RegulatestheElectricIndustry,CIPstandards)

TSA– TransportationSecurityAdministrationPSC– PublicServiceCommissionsAGA– AmericanGasAssociation

MethodsEmployedforSecurity

1. NetworkIsolation2. StaffSupport(OnSite,Vetted)3. NOUnescortedRemoteAccess4. NOfiletransportintotheinfrastructure5. Sanitizedtransportoutoftheinfrastructure6. NOWirelesscommunications7. Dailyvirussignatures

MethodsEmployedforSecurity

8. MonthlyOSpatching9. QuarterlyICSpatching10. EncryptedMWandRFtraffic11. VPNtunnelandCertifiedApplicationTraffic12. Eventandtrafficloggingwithanalysis13. Failovertothebackupsystemmonthly14. PracticeICPquarterly

MethodsEmployedforSecurity

15. PracticeBCPannually16. PracticeRegionalSimulationswithExternal

Resources(Fire,Police,OtherGasCompanies,FBI,DHS,Vendors,etc.)semi-annually

Challenges

1. WehaveaLargeTerritorywithexposedinfrastructure

2. Weareconcernedaboutthesupplychain3. Weareconcernedaboutinsidercapabilities4. Weareconcernedaboutpenetrationtesting

oftheproductionnetwork

Questions