Published on Utilities Telecom Council (http://www.utc.org)
Program: 2008 NERC Cyber Security Conference
By
Created 01/10/2008 - 12:45

2008 NERC Cyber Security Conference
04/03/2008 through 04/04/2008

7:00am-8:00am
04/03/2008
Continental Breakfast

7:00am-5:00pm
04/03/2008
Meeting Registration

8:00am-8:15am
04/03/2008
Welcome and Conference Agenda Review
Join us for a quick welcome session as we present the objectives of the NERC Cyber Security Conference for attendees.

8:15am-9:15am
04/03/2008
Review of NERC Compliance Timeline and Updates
Scott Mix, Manager-Situation Awareness & Infrastructure Security, NERC



NERC CIP Standards are in effect! Could your system withstand a NERC Audit? Come hear how things are going in regards to the CIP standards including what else you should be doing to make sure you are ready – if you are one of the lucky few that receive an audit. With fines that can range up to a million dollars per day, per instance, mitigating this financial risk is HUGE for your utility company. This session, taught by a NERC expert, will review everything you need to have in place and what to expect as NERC starts the official review process.

9:30am-10:30am
04/03/2008
State of the Industry Panel & Case Studies
Jonathan Pollet, Vice President-Professional Services, Industrial Defender
Ori Artman, Chief Technology Officer, Teltone Corporation

Andrew Bartels, Chief Technology Officer, Aegis Technologies

Joe Gould, Director of Sales, USA, RuggedCom, Inc.

This session will be a spontaneous and candid open forum discussion with several technology partners on the direction of the industry. Specifically, vendor partners will share their views on the challenges and opportunities as they describe their customer’s efforts to comply. Joining them will be some of their customers who will give their opinion on the industry direction for 2008 and beyond. This comprehensive, thought-provoking and interactive session is a must attend event and sets the stage for the rest of the conference.

10:30am-10:45am
04/03/2008
Networking Break

10:45am-12:00pm
04/03/2008
Overview of 10-Step Guide to NERC Compliance

Jonathan Pollet, Vice President-Professional Services, Industrial Defender

There are 10-Steps that are guaranteed to help guide your utility through NERC Compliance in an organized, logical fashion. This session presents this 10-Step process and helps form the backbone of the rest of the conference. Come hear how these steps fit together overall before we delve into each one at a time.

  • Step 1: Building the Team
  • Step 2: Asset Identification and Perimeters (CIP-002, 005, 006)
  • Step 3: Assessing Documentation Requirements (CIP-002-009)
  • Step 4: Security Management Controls & Training (CIP-003, 004)
  • Step 5: Assessing Physical Security Readiness (CIP-006)
  • Step 6: Assessing Cyber Security Readiness (CIP-005, 007)
  • Step 7: Incident Reporting Process and Recovery Plans (CIP-008, 009)
  • Step 8: Implementing Technology to Automate Compliance Requirements
  • Step 9: Implementing Processes to Collect Compliance Documentation
  • Step 10: NERC CIP Readiness Audit (Pre-Audit Assessment)


12:00pm-1:00pm
04/03/2008
Networking Lunch

1:00pm-2:00pm
04/03/2008
Roundtable Discussion: Compare Compliance Strategies
This roundtable discussion provides a “Gut Check” based on peers to determine what’s inside everyone’s perimeters. The discussion will scrutinize asset identification methodologies, critical asset identification methodologies, restriction of physical access and define critical assets and critical cyber assets. This session will also give attendees a good idea of how other utilities are making these choices and applying them to the utility framework.

2:00pm-4:00pm
04/03/2008
Vendor Technology Discussion
Jonathan Pollet, Vice President-Professional Services, Industrial Defender Ori Artman, Chief Technology Officer, Teltone Corporation Andrew Bartels, Chief Technology Officer, Aegis Technologies Joe Gould, Director of Sales, USA, RuggedCom, Inc.

This panel will feature leading technology partners, discussing new technologies, and their perspective on how utilities can best capitalize on the latest innovations. Learn what is new in the market place and how you can reap the benefits associated with the technology deployment. This session also will provide an understanding of how these new technologies will complement your existing technologies.



4:00pm-4:15pm
04/03/2008
Networking Break

4:15pm-5:00pm
04/03/2008
Roundtable Discussions: Integrating Technologies
This roundtable discussion will give you the opportunity to meet with your peers and discuss what technologies are currently being used. This session will feature lessons learned from other utilities on what has worked so far in regards to technology strategies. This is the best way to see for yourself what falls under the NERC evaluation and best practices others have applied to this aspect of the assessment. This session will also give you the opportunity to discuss the possibility of integrating technologies together.

4:45pm-5:00pm
04/03/2008
Quick Recap from Day 1

5:30pm-7:00pm
04/03/2008
Networking Reception

7:00am-12:00pm
04/04/2008
Registration

8:00am-9:00am
04/04/2008
Incident Response and Recovery Planning

Jonathan Pollet, Vice President-Professional Services, Industrial Defender

This session will deal with Step 7 which highlights the incident reporting process and recovery plans. Speakers will go into detail on how to build an incidence response plan, how to leverage technology for incidence response and how to formulate backup and restore strategies. Once these issues have been addressed, panel members will go into how they’ve managed to exercise the overall plans.



9:00am-9:45am
04/04/2008
Using Technology to Automate Compliance Processes

Ori Artman, Chief Technology Officer, Teltone Corporation

Next up is the actual implementation involved in Steps 8 and 9. This session will delve into the details of automating compliance requirements and collecting compliance documentation using technology. This process will help utilities streamline the process and perform at a higher level overall.



9:45am-10:00am
04/04/2008
Networking Break

10:00am-10:45am
04/04/2008
Preparing for a NERC Pre-Audit Assessment

Jonathan Pollet, Vice President-Professional Services, Industrial Defender

This session will help utilities determine what it means to be “ready” for the NERC CIP Readiness Audit. There are explicit pre-audit assessment processes that utilities should be doing to ensure that the live NERC audit is a success. This session will provide those best practice ideas to make sure utilities are ready for the main event.



10:45am-11:45am
04/04/2008
Closing Session
This session will provide a recap of the entire conference and give attendees a chance to ask questions about overall NERC compliance in light of all the sessions.

12:00pm-12:00pm
04/04/2008
Conference Adjourns



2008 NERC Cyber Security Conference [1]
Registration [2] Program [3] Accommodations [4]  Sponsorships [5]

Source URL (retrieved on 10/07/2008 - 09:31): http://www.utc.org/node/453

Links:
[1] http://www.utc.org/node/452
[2] http://www.utc.org/node/454
[3] http://www.utc.org/node/453
[4] http://www.utc.org/utc/2008-nerc-cyber-security-conference-accommodations
[5] http://www.utc.org/utc/2008-nerc-cyber-security-conference-sponsorships