Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: New version of the NERC CIP standards

$
0
0

I'm not sure where you got this nice summary, but I went looking here: CIP Standards

 

And I started looking at the "Subject to Future Enforcement" sections.

 

In short, I don't think LEM is the tool for this particular part of CIP compliance.  Patch Manager could certainly help you inventory installed software; manage security and critical updates for Microsoft and third-party products; and produce reports to present to auditors showing what devices are(n't) up to date with all current vulnerabilities addressed.  Patch Manager could at least assist with 1.1.1, 1.1.2, 1.1.3 and 1.1.5.  Patch is not a system imaging tool, though.

 

LEM and NPM could probably help with 1.1.4 in as much as LEM can collect data from network devices connected to those logical ports and alert off of traffic it sees, and NPM could track the performance of those network devices.

 

However, looking at other sections, there's plenty of work for the LEM to do: things like information protection, change management (and to a more limited degree the vulnerability assessments), incident reporting and response.

 

  • FIM and USB Defender (parts of the LEM Agent) can both help with information protection, as well as auditing who is touching what.
  • Change management is a big reason to have an auditing platform like LEM, since it can track all changes and produce reports and alerts.
  • Vulnerability Assessments: no Solarwinds product will do the same job that something like a Nessus scanner will do.  However, if your LEM is working correctly, you should be able to watch Nessus or a pen-test proceed through the network, and get reporting and information on where you're vulnerable and what sort of things to look for.
  • Incident Alerting is all part of rules and correlations in LEM: if you see X happen, respond with Y and make sure it ends up in mailbox Z and report A.  LEM has that covered.

 

I hope that helps.


Viewing all articles
Browse latest Browse all 5385

Trending Articles