SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Hikvision attains ISO 37301 Certification for Compliance Management System
    • SentriGuard's role in sustainable security solutions
    • Axis joins CISA Secure by design for cybersecurity
    • Xtract One's SmartGateway enhances Nova Scotia security
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • What are emerging applications for physical security in transportation?
    • What is the most overlooked factor when installing security systems?
    • Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
    • How should security adapt to the unique aspects of healthcare?
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Alamo enhances security with Alcatel-Lucent solutions

    Alamo enhances security with Alcatel-Lucent solutions

    The University of Dundee implements HID for modern access control

    The University of Dundee implements HID for modern access control

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    SBB upgrades surveillance with Hanwha Vision cameras

    SBB upgrades surveillance with Hanwha Vision cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Technology Summit International 2025

    Technology Summit International 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    G2E Philippines 2025

    G2E Philippines 2025

    IFSEC India 2025

    IFSEC India 2025

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Hanwha Vision America
    Other Resources
    • eMagazines
    • Videos
    Aligning physical and cyber defence for total protection

    Aligning physical and cyber defence for total protection

    Understanding AI-powered video analytics

    Understanding AI-powered video analytics

    Modernizing access control

    Modernizing access control

    Enhancing physical access control using a self-service model

    Enhancing physical access control using a self-service model

About us Advertise
  • AI-powered video analytics
  • AI special report
  • Cyber security special report
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Check out our special report on Cybersecurity

Read now!

Electric grid security: A closer look at CIP-014-1 standard

Vicki Contavespi
Vicki Contavespi
Contact company
Contact LogRhythm
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • CIP-014-1 standard by FERC aims to boost grid security starting January 2015.
  • H.R. 3410 seeks bipartisan support to protect US electrical grid from EMP threats.
  • Transmission owners must implement CIP-014-1 security measures to address vulnerabilities.
The bill enjoys strong bipartisan support, but it remains to be seen whether it will become law
The FERC standard CIP-014-1 became effective, according to the Federal Register, on January 26, 2015

The electric power industry works with several federal agencies, including the Federal Energy Regulatory Commission (FERC), the Department of Homeland Security (DHS), and the Department of Energy (DOE) to improve sector-wide resilience for cyber threats. The industry also collaborates with the National Institute of Standards and Technology (NIST), the North American Electric Reliability Corporation (NERC), and federal intelligence and law enforcement agencies to strengthen its cyber security capabilities.

Are the standards anywhere close enough to actually be of service? We shall soon see because last November CIP-014-1 was approved. It is the Physical Security Reliability Standard, developed by the North American Electric Reliability Corporation and approved by the U.S. Federal Energy Regulatory Commission.

In December, the House of Representatives approved unanimously H.R. 3410, the Critical Infrastructure Protection Act (CIPA). This is the first time in four years that Congress has acted to begin to protect the nation’s electrical grid, and comes on the heels of CIP-014-1’s approval.  

Aim of the new bill

The bill enjoys strong bipartisan support, but it remains to be seen whether it will become law. It has been read in the Senate and referred to the Committee on Homeland Security and Governmental Affairs. Its purpose is to see that DHS:

  • Include in national planning scenarios the threat of electromagnetic pulse (EMP) which would entail the education of the owners and operators of critical infrastructure, as well as emergency planners and emergency responders at all levels of government of the threat of EMP events;
  • Engage in research and development aimed at mitigating the consequences of naturally occurring or man-caused EMP events;
  • Produce a comprehensive plan to protect and prepare the critical infrastructure of the American homeland against EMP events.

FERC’s standard CIP-014-1, has six requirements, including

Utilities must devise physical security plans for each of their respective transmission stations, transmission substations, and their primary control centre (one of the CIP-014-1 requirements)

  • Performing risk assessments periodically to identify weak transmission stations and substations;
  • The transmission owner must modify trouble spots accordingly and implement procedures for protecting sensitive or confidential information;
  • Transmission owners must let operators know there are issues so they can address them.
  • Owners and transmission operators must conduct an evaluation of the potential threats and vulnerabilities of a physical attack on each of its respective transmission stations, transmission substations, and primary control centers identified as critical under the first requirement;
  • Utilities must devise physical security plans for each of their respective transmission stations, transmission substations, and their primary control center;
  • Finally, they must have an unaffiliated third party with appropriate experience review its evaluation and security plan and then respond to the recommendations.

However, Todd Borandi, an industry veteran and information security architect, sees these regulations as a day late and a dollar short. He credits hackers for today’s push for regulations “because several groups made it a public point to demonstrate how easy it is to access sensitive systems and steal data, so the outcry from the private, public and even the government demanded regulations causing this whole cycle to start all over again.” The FERC standard became effective, according to the Federal Register, on January 26, 2015. It remains to be seen whether or not the boxes get checked in lieu of an improvement in physical security.

Wind - The savior?

Ironically, what might be of more help is a very simple solution: wind. LogRhythm’s Greg Foss says “Wind could be the saviour” because the Department of Energy is working on outputting windmill energy into batteries. Foss is senior security research engineer for Boulder, Colo.-based LogRhythm, a security intelligence firm.

One thing is to upgrade equipment, but as we’ve discovered that demands a huge money outlay, and as Foss says, “Right now, utilities have no real need to do this even though there have been 97 attacks against the grid so far this year.”

Foss’ company creates honeypots, which are traps for hackers. “Once they get in,” he says, “we can track them and learn.” He says that a so-called con pot is under development. It would simulate SCADA by running, for example, a gas main, a utility box or a water-heating system, which is a prime target for hackers who wish to fudge temperature readings and make things look cooler than they really are. 

His best advice is “Hire the right people, train them well and give them the tools to build solutions. Security isn’t that easy to learn and they have to have the tools to succeed.”

His company’s mantra is “not if, when,” and those words should resound loudly at all utility firms.

Find out about secure physical access control systems through layered cybersecurity practices.

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Physical security
  • Industrial security
  • Power plant security
  • Industrial security systems
  • Industrial surveillance
  • Cyber security
  • Related links
  • Articles by Vicki Contavespi
  • Related categories
  • Access control systems & kits
  • CCTV cameras
  • IP cameras
  • IP Dome cameras
  • Dome cameras
Related white papers
Aligning physical and cyber defence for total protection

Aligning physical and cyber defence for total protection

Download
Combining security and networking technologies for a unified solution

Combining security and networking technologies for a unified solution

Download
System design considerations to optimize physical access control

System design considerations to optimize physical access control

Download
Related articles
How physical security consultants ensure cybersecurity for end users

How physical security consultants ensure cybersecurity for end users

How managed detection and response enhances cybersecurity management in organisations

How managed detection and response enhances cybersecurity management in organisations

Drawbacks of PenTests and ethical hacking for the security industry

Drawbacks of PenTests and ethical hacking for the security industry

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Expert commentary
About this page

Boost your venue's security with integrated video surveillance systems - effortless installation, smart analytics and remote monitoring.

See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2025, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Understanding AI-powered video analytics
Understanding AI-powered video analytics
Security and surveillance technologies for the casino market
Security and surveillance technologies for the casino market
Modernizing access control
Modernizing access control
Addressing Cybersecurity Vulnerabilities in the Physical World
Addressing Cybersecurity Vulnerabilities in the Physical World
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec