NERC Security Guideline for the Supply Chain Cyber Security Risk Management Lifecycle

Leverage these best practices to improve supply chain cyber security risk management in your critical infrastructure organization.
By:
Scott Lang
,
VP, Product Marketing
June 14, 2023
Share:
Blog nerc supply chain risk management 0623

In response to damaging supply chain attacks such as SolarWinds, Kaseya and Colonial Pipeline, the North American Electric Reliability Corporation (NERC) published a Security Guideline for the Supply Chain Cyber Security Risk Management Lifecycle. The Guideline recommends that critical infrastructure organizations such as electric utilities, natural gas providers and others identify, assess and mitigate supply chain cyber security risks to their critical operational technology (OT) assets. OT system disruptions, such as those cause by supply chain incidents, can cause utility outages and have wide-ranging and negative impacts on society as a whole.

This post examines the key steps in identifying, assessing and mitigating supply chain cyber security risks according to the NERC Security Guideline, and reviews best practices for reducing the risks to critical infrastructure.

Identifying Risks

Chapter 1 of the Guideline states that, “The organization’s first objective in the supply chain cyber security risk management process is to identify risks to its critical OT assets that could have a high impact, or a high likelihood of compromise, depending on the supplier.”

To address this Guideline, build:

  • A two-axis scoring methodology based on likelihood of compromise and impact to the organization, creating a heat map-like matrix to plot risks into.
  • Automated rules to assign scores if a supplier’s answer to an assessment question fails to achieve an acceptable risk threshold, thereby plotting risks into the matrix.
  • Reporting to sort risks by the highest score in the matrix.
  • Custom remediations to recommend to the supplier to mitigate the risk.

Preceding this, however, conduct a profiling and tiering assessment to track and quantify inherent risks for all suppliers. From this inherent risk assessment, your team can automatically classify and tier suppliers (including identifying those deemed as critical); set appropriate levels of further diligence off of this baseline; and determine the scope of ongoing assessments.

Assessing Risks

Chapter 2 of the Security Guideline states that, “Once the organization has identified risks, it needs to assess its vendors to determine the degree of risk they pose with respect to each risk that was identified; in most cases, the vendor assessment will be conducted via a questionnaire.”

To achieve this requirements, automate risk assessments to extend the visibility, efficiency and scale of your supply chain risk management program across every stage of the supplier lifecycle. Leverage a library that includes hundreds of standardized assessment templates, with customization capabilities and built-in workflow and remediation to automate everything from survey collection and analysis to risk rating and reporting. Be sure that your assessment platform of choice includes specific assessments for critical infrastructure reporting and best practices, such as the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity.

As part of the risk assessment process, continuously track and analyze external threats to suppliers by monitoring the Internet and dark web for cyber threats and vulnerabilities. Monitoring sources should include criminal forums; onion pages; dark web special access forums; threat feeds; paste sites for leaked credentials; security communities; code repositories; vulnerability databases; and data breach databases.

An important capability at this step is to correlate continuous monitoring results against assessment responses to validate controls. This cannot be accomplished by using spreadsheets for risk assessments or disjointed tools for cyber security monitoring.

Mitigating Risks

Chapter 3 of the Guideline recommends that the organization ask the vendor to mitigate risks identified in the assessment. The goal of risk mitigation should be to bring its value down to an acceptable level in order to reduce the likelihood and/or impact of the risk.

The Guideline says this can be accomplished through RFP or contractual enforcement, but required remediations are also an important post-contract enforcement. See some selected mitigations from the Guideline in the table below.

Suggested Mitigations Best Practices

Include RFP language identifying security risks and any mitigations the vendor must undertake to address those risks.

Centralize and automate the distribution, comparison, and management of requests for proposals (RFPs) and requests for information (RFIs) as part of vendor selection decisions. Doing so will ensure that suppliers are selected based on critical cyber security measures.

Include contract language documenting the vendor’s commitment to implement specific security controls, provide for the organization to review the vendor’s progress, and identify methods for future communication on these matters.

Centralize the distribution, discussion, retention, and review of supplier contracts. Managing supply contracts this way will ensure that you have the proper security clauses and enforcements built into the contract.

Define specific remediations.

Deliver recommended remediations to suppliers based on risk assessment results to ensure that suppliers address risks in a timely and satisfactory manner. Track remediations to conclusion with defined owners – inside your organization and in your supplier’s organization.

Procurements and Installations

Chapter 4 of the Guideline requires that supply chain cyber security risk mitigations be considered throughout the lifecycle of a product or service to reduce the level of risk that was initially assessed as high. This will require a baseline procurement risk assessment at the start of the procurement process followed by:

Updating the Risk Management Plan

Chapter 5 of the Guideline suggests that a supply chain cyber security risk management plan be updated at least annually. This will involve identifying new risks, re-assessing suppliers, and reviewing mitigations accordingly – with tasks addressed in chapters 1-3 repeated as necessary.

To optimize your program to address the entire supplier risk lifecycle, continuously update:

  • Governing policies, standards, systems and processes to protect systems
  • Organizational roles and responsibilities (e.g., RACI)
  • Supplier inventories and criticality
  • Risk scoring rules and thresholds based on your organization’s risk tolerance
  • Assessment and monitoring methodologies based on supplier criticality
  • Fourth-party and Nth-party mapping to understand your extended supplier ecosystem
  • Sources of continuous cyber security monitoring data
  • Key performance indicators (KPIs) and key risk indicators (KRIs)
  • Compliance and contractual reporting requirements against service levels
  • Incident response requirements
  • Risk and internal stakeholder reporting
  • Risk mitigation and remediation strategies

Align Your TPRM Program with 14 Industry Standards

Download this guide to review industry standards with specific TPRM requirements, and discover best practices for simplifying compliance.

Read Now
Featured resource compliance handbook industry standards

Next Steps: Meeting NERC Security Guidelines for the Supply Chain Cyber Security Risk Management Lifecycle

The NERC Security Guidelines for the Supply Chain Cyber Security Risk Management Lifecycle provide foundational recommendations for mitigating the cyber security risks introduced to your critical infrastructure organization. For help in implementing these best practices, schedule a demonstration today.

Tags:
Share:
Leadership scott lang
Scott Lang
VP, Product Marketing

Scott Lang has 25 years of experience in security, currently guiding the product marketing strategy for Prevalent’s third-party risk management solutions where he is responsible for product content, launches, messaging and enablement. Prior to joining Prevalent, Scott was senior director of product marketing at privileged access management leader BeyondTrust, and before that director of security solution marketing at Dell, formerly Quest Software.

  • Ready for a demo?
  • Schedule a free personalized solution demonstration to see if Prevalent is a fit for you.
  • Request a Demo