| CIP-002-1 Critical Cyber Asset Identification |
Vulnerability Management |
Lumension® Scan provides complete asset discovery and inventory which enables clear and complete visibility to Cyber Assets which utilize the routable IP protocol within a control center (R3.1) or to communicate outside the Electronic Security Perimeter (R3.2). This capability aids the Responsible Entity in developing a list of Critical Cyber Assets to comply with R3. |
| CIP-003-1 Security Management Controls |
Data Protection |
Requirement R4 specifies that the Responsible Entity implement and document a program to identify, classify, and protect information associated with Critical Cyber Assets. Lumension® Device Control uniquely identifies and authorizes specific media, providing per-user/per-device user permissions and enforced encryption for removable storage. Lumension® Device Control enables information protection across media types (R4.1) while providing flexible reporting to aid in complying with the annual adherence assessment (R4.3). |
| Vulnerability Management |
Lumension® Security Configuration Management provides comprehensive policy & compliance management which aids the Responsible Entity in configuration management activities to identify, and document changes to hardware and software components of Critical Cyber Assets pursuant to the change control process (R6). |
| CIP-005-1 Electronic Security Perimeter |
Vulnerability Management Reporting and Compliance |
Lumension® Patch and Remediation provides complete asset discovery and inventory including a view of any non-critical Cyber Asset within a defined Electronic Security Perimeter. Along with Lumension® Enterprise Reporting, Lumension can assist the Responsible Entity in documenting interconnected Critical and non-critical Cyber Assets within the Electronic Security Perimeter, access point to the Electronic Security Perimeter and assets utilized for monitoring and control of the access points (R1.4 and R1.6) |
| Endpoint Protection Vulnerability Management |
Lumension® Application Control and Lumension® Patch and Remediation together provide automated application discovery, application whitelisting, comprehensive policy and compliance management and complete asset discovery capabilities. The Lumension® Content Wizard also provides scripting wizards that enable the Responsible Entity to monitor and restrict ports and services only to those required for operations and for monitoring as specified in the access control provision (R2.2). |
| Vulnerability Management Reporting and Compliance |
Lumension® Patch and Remediation along with Lumension® Scan provide heterogeneous platform and application support, extensive scanning functions and comprehensive reporting to comply with the vulnerability assessment requirements (R4.2-R4.5) |
| CIP-006-1: Physical Security of Critical Cyber Assets |
Vulnerability Management Reporting and Compliance Endpoint Protection Data Protection |
It is not obvious that software security solutions would have relevance to physical security requirements, however, R1.8 specifies that “Cyber Assets used in the access control and monitoring of the Physical Security Perimeter(s) shall be afforded the protective measures specified in” a subset of the CIPs, therefore software security solutions do play a role in an RE achieving physical security compliance. Lumension helps protect against vulnerabilities, report on compliance, secure endpoints, and protect data on removable devices. |
| CIP-007-1 Systems Security Management |
Vulnerability Management Endpoint Protection |
Similar to the Requirements of CIP005-1, restricting ports and services to only those required for normal and emergency operations (R2.1) and disabling ports and services prior to production use (R2.2), Lumension® Application Control, Lumension® Patch and Remediation, and Lumension® Content Wizard together provide automated application discovery, application whitelisting, comprehensive policy and compliance management capabilities and flexible content creation. |
| Vulnerability Management Reporting and Compliance |
The Security Patch Management Requirement (R3) for implementation, assessment and documentation are accommodated by Lumension® Patch and Remediation which provides intelligent patch and remediation, heterogeneous platform and application support and comprehensive reporting. Coupling these capabilities with baseline enforcement aids an RE in meeting the testing procedures required when there is significant change to the Cyber Assets (R1). |
| Endpoint Protection Vulnerability Management Reporting and Compliance |
The Malicious Software Prevention stipulation (R4.1) for Cyber Assets underscores the importance of utilizing tools to “detect, prevent, deter, and mitigate the introduction, exposure, and propagation of malware on all Cyber Assets”. As modern antivirus tools can not address all zero day threats, especially those which might be targeted attacks at fundamental infrastructure, Lumension® Application Control provides application whitelisting which utilizes kernel-level enforcement. A Defense in Depth strategy will still require update and documentation of antivirus signatures as dictated by R4.2, which can be aided through Lumension® Patch and Remediation. |
| Vulnerability Management Reporting and Compliance |
The Cyber Vulnerability Assessment requirement (R8) specifies a RE perform a cyber vulnerability assessment at least annually. Lumension® Patch and Remediation along with Lumension® Scan provide both network based and credentials-based production ready scanning, which does not compromise endpoint performance or stability, enabling a RE to meet its compliance target. |