Our Experience:
♦ Offering NERC compliance assistance
since April 2007
♦ NERC compliance assistance at over
90 locations
♦ NERC compliance assistance in all 8 NERC
regions
♦ Participated in RRO, NERC and FERC audits
♦ Met with FERC to discuss CIP, Cyber Security and Cyber Related
Advisories
On August 14, 2003, the largest blackout in North American history occurred, impacting an estimated
50 million people in the United States and Canada, resulting in financial losses of approximately $6 billion. In response
to this event, the North American Electric Reliability Corporation was certified as the Electric Reliability Organization
to mandate standards and requirements to ensure the reliability of the Bulk Electric System. Compliance with NERC and regional
reliability standards is now mandatory and enforceable, non-compliance can carry significant financial penalties. All bulk
power system owners, operators, and users must comply.
We can help. Contact
msanchez@sirsol.com or 713-888-7233 for additional information.
Key NERC questions your organization
should be able to answer:
♦ Have you identified the right evidence, for each requirement, to satisfy compliance?
♦
What is your process for gathering and retaining compliance evidence?
♦ Do you have processes in place to ensure ongoing compliance?
♦ Beyond CIP, what has your organization done to protect cyber assets?
We Team With You to Achieve Success
Our Services:
♦ CIP and Reliability Standards Compliance
♦ Audit Preparatory Assistance
♦ Business Process Design and Evaluation
♦ Compliance Policy and Procedure Development
♦
Compliance Program Development
♦ Compliance System Recommendations
♦ Cyber Security Best Practice Development
♦ Gap Analysis
♦ Internal Controls Development and
Test Program Creation
♦ Mock Compliance Assessments
♦ Monitor and Summarize NERC Requirement Changes
♦ NERC CIP and Cyber Security Training Development
♦
Ongoing Compliance Assessments
♦ Project Management
♦ Remediation Recommendations and Assistance
♦ Staff Augmentation
Our Credentials:
♦ CBCP
♦ CISA
♦ CISM
♦ CISSP
A successful NERC compliance effort avoids the penalties for non-compliance
(including up to $1 million per violation per day and public posting of the violation) and helps avoid the risk of substantial
liability when a company is found to contribute to reliability issues with the bulk electric system. However, it also should
mitigate operational and financial risks, support business goals and objectives, and capture savings associated with proper
scoping and planning (otherwise implementation costs escalate drastically as mandatory compliance dates near).
Our Relevant
Experience:
♦ Responsible for developing and executing a sustainable compliance program for a large
power
generation company and its subsidiaries to address newly mandated NERC, FERC and RRO
requirements.
♦ Managed IT security, change management,
disaster recovery, business continuity, production
applications, databases and hardware for a $12-billion energy corporation
which included the
technology management and support for pipeline, chemical plant, and salt dome storage
facilities.
♦ Assisted in the IT rebuild and
redesign of a power generation company that produced 12,000
megawatts of electricity.
♦ Implemented a web-based enterprise compliance management system
that captures and
retains evidence required
to demonstrate compliance with applicable FERC, NERC and other
regulatory compliance requirements.
♦ Responsible
for coordinating participation in the development of Reliability Standards, including
providing oral
or written comments or coordinating such oral written testimony by personnel or
consultants.
♦ Assisted in development and implementation of IT policies, procedures,
and internal controls
where an assessment by an external audit firm resulted in zero IT compliance deficiencies.
♦ Interviewed subject matter experts to create business process
flowcharts and detailed process
narratives for various compliance activities.
♦ Designed process and developed content for a NERC CIP Control Self Assessment Tool.
Our
Firm: ♦ Began operations in 1998
♦ 70+ energy clients
♦ Over 850,000 hours of designing, implementing
and testing risk controls
♦ Over 300 consultants who average
15 years of experience
♦ For
more information on our firm, please visit www.sirsol.com
We can help. Contact msanchez@sirsol.com or 713-888-7233 for additional information.