Utilities Choose Pure-Play Solution to Help Enforce Adherence to NERC CIP v5 Standards and Automatically Generate Evidence to Prove CIP v5 Compliance
PLANO, TX. — January 13, 2016 – SigmaFlow, a leading provider of compliance process execution solutions for NERC Critical Infrastructure Protection (CIP) and 693 compliance management, today announced workflow templates that help to expedite the deployment of SigmaFlow’s NERC CIP Compliance Manager to better adhere to the NERC CIP v5 standard requirements.
SigmaFlow’s current Compliance Manager customer-base consists of utilities in the US and Canada, varying in size from very large publicly owned utilities to smaller cooperatives and municipalities– with representation in each of the eight NERC regions. The SigmaFlow NERC CIP v5 model provides functionality that automates and streamlines the collection of evidence, document management and data-driven reporting required to adhere to the NERC CIP v5 standards.
The April 2016 deadline, which requires utilities to adhere to the NERC CIP v5 standards, adds many new and redefined compliance expectations for electric utilities. The challenge of transitioning from version 3 to version 5 can be complicated and often costly for utilities that are not adequately prepared. There are also many utilities coming under CIP for the first time due to the new brightline impact criteria in v5, requiring them to build an entire CIP program to prove their adherence to the standards, with processes in place to ensure their audit readiness.
SigmaFlow’s Compliance Manager provides a comprehensive platform for NERC compliance that includes Document Management, RSAW Automation, Data Management, Recurring Schedule Management, Workflow, Dashboards, Reporting and Integration. The automated platform provides utilities and renewables with a reliable solution to handle the complexities of managing and adhering to the NERC CIP standards and maintaining audit readiness.
The SigmaFlow platform’s 36 workflow templates provide customers with substantial flexibility. Alternatively, customers can choose a custom deployment option and work with SigmaFlow partners or their own consultants to develop unique processes. Once deployed, the SigmaFlow solution automatically kicks-off recurring compliance work items as they come due with pre-built compliance workflows that enforce compliance rules and generate/collect the evidence that proves compliance.
“Our Compliance Manager solution enables utilities to work smart and automate the processes to comprehensively manage NERC CIP compliance,” said Terry Schurter, vice president of NERC Solutions at SigmaFlow. “We have automated a lot of the heavy lifting associated with RSAW generation, change management, access management and evidence collection, and also removed the burden of keeping up with the changing standards through regular content updates.”
View list of supported NERC CIP Standard Controls included in the SigmaFlow Model.
Key Modules in the SigmaFlow Compliance Manager:
- Associate to one or more Requirements by checking a box
- Support all evidence document types
- Version history automatically maintained by solution
- Template Engine for automating RSAWs
- RSAW data collected in the solution
- RSAW Templates automatically populated from RSAW data collected
- All RSAW Templates provided by SigmaFlow
- One-click RSAW package generation, including RSAW and Evidence
- NERC CIP Relational Database
- Includes all major data objects and their relationships, such as:
- Facilities, Systems, Assets, Access Rights, People, Training, Security Awareness, etc.
- Recurring Scheduler automatically creates and initiates Workflow and Tasks as needed
- Ticket System provides transactional history for all Recurring Work
- Includes all mandatory NERC recurring work items for CIP Version 5
Work in Progress
- Email notifications sent out for all Tasks
- Dashboards and Reports provide “at a glance” oversight and issue identification
- Reminders for Tasks approaching completion date ensures work is completed on time
Closed-Loop Controls Framework™
- Workflows ensure all evidence is generated/collected in the process
- Closed Loop Workflow controls included for all Standards and Requirements, such as
- Classifications, Access Rights, Policies, Testing, Training, PRA, Patches, etc.
- Integration to collect Provisioned Data (baselines, local accounts, etc.)
- API integration with Tripwire available
- XML Hot Folders provide simple means to collect provisioned data from any solution