On July 22, 2015, The Federal Energy Regulatory Commission (FERC) proposed new critical infrastructure protection (CIP) standards to address concerns over the cyber threat posed by an increasingly global supply chain. Specifically, FERC is concerned with the potential introduction of vulnerabilities into the grid by the hardware and software components of Supervisory Control and Data Acquisition (SCADA) devices and other grid control systems. This type of vulnerability struck Dell Computers in 2010, when motherboards it procured from an international supplier were shipped containing malware. Although the attack was discovered, it was not until after some products had already been received by customers. Like the computer industry, components of grid control systems are made by a globally diverse supply chain which is largely outside the reach of U.S. regulatory authority.
Continue reading →