{"id":2260,"date":"2021-02-16T09:00:10","date_gmt":"2021-02-16T09:00:10","guid":{"rendered":"https:\/\/itegriti.com\/kw022024\/?p=2260"},"modified":"2021-04-12T02:39:59","modified_gmt":"2021-04-12T02:39:59","slug":"an-introduction-to-nerc-cip-013-1","status":"publish","type":"post","link":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/","title":{"rendered":"An Introduction to NERC CIP-013-1"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-one-full fusion-column-first fusion-column-last\" style=\"--awb-bg-size:cover;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-column-wrapper-legacy\"><div class=\"fusion-text fusion-text-1\"><p>On October 1, 2020, the North American Electric Reliability Corporation (NERC) <a href=\"https:\/\/www.nerc.com\/_layouts\/15\/PrintStandard.aspx?standardnumber=CIP-013-1&amp;title=Cyber%20Security%20-%20Supply%20Chain%20Risk%20Management&amp;jurisdiction=United%20States\" target=\"_blank\" rel=\"noopener noreferrer\">CIP-013-1<\/a> standard, titled \u201cCyber Security &#8211; Supply Chain Risk Management\u201d, was enforced to address the vulnerabilities and threat vectors that external third parties in the supply chain can have on the Bulk Electric System (BES). Electric grid companies have 18 months from the effective date to prove compliance, increased monitoring, and oversight over their supply chains. Failure to do so can result in fines of up to $1M per day per outstanding violation.<\/p>\n<p>To safeguard North America\u2019s electricity supply against cyber risks and attacks, NERC has issued several critical infrastructure protection (CIP) standards. The <a href=\"https:\/\/www.nerc.com\/pa\/Stand\/Reliability%20Standards%20Complete%20Set\/RSCompleteSet.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">CIP-013-1 standard<\/a>, which has been <a href=\"https:\/\/www.ferc.gov\/media\/news-releases\/2018\/2018-4\/10-18-18-E-1.asp\" target=\"_blank\" rel=\"noopener noreferrer\">approved by FERC<\/a> in the fall of 2018, includes a set of regulatory requirements \u201cto mitigate cyber security risks to the reliable operation of the Bulk Electric System (BES)\u201d.<\/p>\n<p>Electric power and utility organizations have to comply with requirements to improve security against an increasing number of attacks that target supply chains, particularly those involving third-party providers. The new standards will help utility companies protect bulk electric systems by limiting their exposure to malware, tampering, and other cyber risks that can originate with third-party relationships. It is important to understand that third parties will also need to familiarize themselves with the CIP-013-1 to preserve business relationships with power and utility companies.<\/p>\n<h2 class=\"navy\">Why is CIP-013-1 required?<\/h2>\n<p>Development and enforcement of CIP-013-1 were mandated by the recognition of public entities and private industries of the changes in the cybersecurity landscape associated with supply chain vendors. To meet these security requirements and to enhance the security posture of the North American electric grid, FERC and NERC have recognized that supply chain risks affect power and utility companies, which rely increasingly on third parties for the reliable and safe operation of the grid. As a result, <a href=\"https:\/\/www.ferc.gov\/whats-new\/comm-meet\/2016\/072116\/E-8.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">FERC Order 829<\/a>, issued in July 2016, directed the North American Electric Corporation (NERC) to develop a CIP reliability standard that addresses \u201csupply chain risk management for industrial control system hardware, software, and computing and networking services associated with bulk electric system operations.\u201d<\/p>\n<p>On the federal level, the National Institute for Standards and Technology updated the NIST SP 800-53 ver 5 with an emphasis on third-party vendors and suppliers, while NIST 800-161 specifically addresses 19 areas of supply chain risk management. On the other hand, the international IEC\/ISA 62443 standard provides guidance focused on supply chain risk management.<\/p>\n<p>NERC CIP-013-1 comes at a time when third-party vulnerabilities and data breaches impact critical infrastructure and federal agencies. The most recent event, making the news headlines across the globe, is the SolarWinds breach which <a href=\"https:\/\/www.datacenterknowledge.com\/security\/list-known-solarwinds-breach-victims-grows-do-attack-vectors\" target=\"_blank\" rel=\"noopener noreferrer\">affected among others<\/a> the Departments of Energy, Defense, and Homeland Security, and companies such as Microsoft, Intel, Cisco, Nvidia, VMware, Belkin, and the cybersecurity firm FireEye, which was first to discover the attack.<\/p>\n<p>Research has demonstrated that supply chain breaches are among the <a href=\"https:\/\/www.itbusinessedge.com\/blogs\/data-security\/breaches-from-third-parties-are-the-costliest.html\" target=\"_blank\" rel=\"noopener noreferrer\">costliest cyber-attacks<\/a>. These attacks have caused downtime in major network infrastructure and derailed the physical operations of global companies. An attack of this nature could have potentially catastrophic results for both the American electric grid and the local communities.<\/p>\n<h2 class=\"navy\">What are the requirements?<\/h2>\n<p>The objective of NERC CIP-013-1 is \u201cto mitigate cybersecurity risks to the reliable operation of the BES by implementing security controls for supply chain risk management of BES Cyber Systems.\u201d To meet this goal, CIP-013-1 mandates responsible entities to \u201cdevelop one or more documented supply chain cybersecurity risk management plan(s) for high and medium impact BES Cyber Systems.\u201d These plans must be reviewed and approved every 15 months.<\/p>\n<p>According to the standard, the cybersecurity plan should include processes and procedures to address the following areas:<\/p>\n<ul>\n<li>Software integrity and authenticity<\/li>\n<li>Vendor remote access to BES cyber systems<\/li>\n<li>Information system planning and procurement<\/li>\n<li>Vendor risk management<\/li>\n<li>Procurement controls<\/li>\n<\/ul>\n<p>The documentation and enforcement of these processes for the procurement of BES Cyber Systems from third-party vendors will assist responsible entities to identify, assess, and mitigate cybersecurity risks to the BES resulting from vendor equipment and software.<\/p>\n<p>In addition, the plans should include incident response procedures to notify responsible entities on supply chain incidents and coordinate responses between utilities companies and suppliers. Other necessary requirements include:<\/p>\n<ul>\n<li>Remote access controls and policies for vendor personnel to access the BES<\/li>\n<li>Information sharing for the disclosure of known vulnerabilities by the vendor to the responsible entity<\/li>\n<li>Software integrity and authenticity verification and validation process of all software and patches supplied by a vendor to the network.<\/li>\n<\/ul>\n<h2 class=\"navy\">Towards CIP-013-1 compliance<\/h2>\n<p>CIP-013-1 only addresses high- and medium-risk BES cyber systems and does not provide any recommendations or best practices on how to meet compliance with the requirements. Responsible entities must make strategic decisions regarding the extent of compliance. These decisions could range from simply becoming and remaining compliant to rolling out compliance more broadly, encompassing low-impact BES as well, and potentially including the whole enterprise.<\/p>\n<p>This expanded strategy will deliver higher reliability and safety and greater cybersecurity resilience across the entire business to mitigate supply chain risks. This is a sensible decision since the same vendors and products are often used in conjunction with high-, medium-, and low-risk BES cyber systems.<\/p>\n<h2 class=\"navy\">How ITEGRITI can help<\/h2>\n<p>ITEGRITI helps protect some of the nation\u2019s most critical infrastructure, serving clients in the energy, healthcare, transportation, education, retail and financial sectors.\u00a0 Our portfolio includes <a href=\"https:\/\/itegriti.com\/kw022024\/compliance\/\">NERC compliance<\/a> projects since 2006, in all regions throughout the U.S. and Canada, supporting utilities, transmission, municipalities, cooperatives, and generation representing coal, natural gas, and renewables \u2013 wind, solar, hydro, and geothermal.<\/p>\n<p>We develop and implement programs that mitigate cyber and compliance risk, supported by internal controls to measure, monitor, and report ongoing program effectiveness. Our programs help companies avoid hacks and minimize business impact during a cybersecurity event. To learn how we can help you, <a href=\"https:\/\/itegriti.com\/kw022024\/contact\/\">contact<\/a> our experts.<\/p>\n<\/div><div class=\"fusion-clearfix\"><\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>What is NERC-013-1? Why is needed? What are the requirements? Let\u2019s examine NERC\u2019s Cyber Security &#8211; Supply Chain Risk Management standard.<\/p>\n","protected":false},"author":10,"featured_media":2262,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2179],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v22.0 (Yoast SEO v23.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>An Introduction to NERC CIP-013-1 - kw022024<\/title>\n<meta name=\"description\" content=\"What is NERC-013-1? Why is needed? What are the requirements? Let\u2019s examine NERC\u2019s Cyber Security - Supply Chain Risk Management standard.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"An Introduction to NERC CIP-013-1\" \/>\n<meta property=\"og:description\" content=\"What is NERC-013-1? Why is needed? What are the requirements? Let\u2019s examine NERC\u2019s Cyber Security - Supply Chain Risk Management standard.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\" \/>\n<meta property=\"og:site_name\" content=\"kw022024\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/itegriti\" \/>\n<meta property=\"article:published_time\" content=\"2021-02-16T09:00:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-12T02:39:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Anastasios Arampatzis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@TassosAramp\" \/>\n<meta name=\"twitter:site\" content=\"@itegriti\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anastasios Arampatzis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\"},\"author\":{\"name\":\"Anastasios Arampatzis\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673\"},\"headline\":\"An Introduction to NERC CIP-013-1\",\"datePublished\":\"2021-02-16T09:00:10+00:00\",\"dateModified\":\"2021-04-12T02:39:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\"},\"wordCount\":1216,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg\",\"articleSection\":[\"Compliance\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\",\"name\":\"An Introduction to NERC CIP-013-1 - kw022024\",\"isPartOf\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg\",\"datePublished\":\"2021-02-16T09:00:10+00:00\",\"dateModified\":\"2021-04-12T02:39:59+00:00\",\"description\":\"What is NERC-013-1? Why is needed? What are the requirements? Let\u2019s examine NERC\u2019s Cyber Security - Supply Chain Risk Management standard.\",\"breadcrumb\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage\",\"url\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg\",\"contentUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg\",\"width\":800,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/itegriti.com\/kw022024\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"An Introduction to NERC CIP-013-1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"name\":\"ITEGRITI\",\"description\":\"cybersecurity | compliance | managed services\",\"publisher\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\",\"name\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"contentUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"width\":600,\"height\":100,\"caption\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/itegriti\",\"https:\/\/x.com\/itegriti\",\"https:\/\/www.linkedin.com\/company\/itegriti\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673\",\"name\":\"Anastasios Arampatzis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g\",\"caption\":\"Anastasios Arampatzis\"},\"description\":\"Anastasios Arampatzis is a retired Hellenic Air Force officer with over 20 years\u2019 worth of experience in managing IT projects and evaluating cybersecurity. During his service in the Armed Forces, he was assigned to various key positions in national, NATO and EU headquarters and has been honoured by numerous high-ranking officers for his expertise and professionalism. He was nominated as a certified NATO evaluator for information security. Anastasios\u2019 interests include among others cybersecurity policy and governance, ICS and IoT security, encryption, and certificates management. He is also exploring the human side of cybersecurity - the psychology of security, public education, organizational training programs, and the effect of biases (cultural, heuristic and cognitive) in applying cybersecurity policies and integrating technology into learning. He is intrigued by new challenges, open-minded and flexible. Currently, he works as a cybersecurity content writer for Bora - IT Security Marketing. Tassos is a member of the non-profit organization Homo Digitalis.\",\"sameAs\":[\"http:\/\/www.welcometobora.com\",\"https:\/\/www.linkedin.com\/in\/anastasiosarampatzis\/\",\"https:\/\/x.com\/TassosAramp\"],\"url\":\"https:\/\/itegriti.com\/kw022024\/author\/anastasios-arampatiz\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"An Introduction to NERC CIP-013-1 - kw022024","description":"What is NERC-013-1? Why is needed? What are the requirements? Let\u2019s examine NERC\u2019s Cyber Security - Supply Chain Risk Management standard.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/","og_locale":"en_US","og_type":"article","og_title":"An Introduction to NERC CIP-013-1","og_description":"What is NERC-013-1? Why is needed? What are the requirements? Let\u2019s examine NERC\u2019s Cyber Security - Supply Chain Risk Management standard.","og_url":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/","og_site_name":"kw022024","article_publisher":"https:\/\/www.facebook.com\/itegriti","article_published_time":"2021-02-16T09:00:10+00:00","article_modified_time":"2021-04-12T02:39:59+00:00","og_image":[{"width":800,"height":450,"url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg","type":"image\/jpeg"}],"author":"Anastasios Arampatzis","twitter_card":"summary_large_image","twitter_creator":"@TassosAramp","twitter_site":"@itegriti","twitter_misc":{"Written by":"Anastasios Arampatzis","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#article","isPartOf":{"@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/"},"author":{"name":"Anastasios Arampatzis","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673"},"headline":"An Introduction to NERC CIP-013-1","datePublished":"2021-02-16T09:00:10+00:00","dateModified":"2021-04-12T02:39:59+00:00","mainEntityOfPage":{"@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/"},"wordCount":1216,"commentCount":0,"publisher":{"@id":"https:\/\/itegriti.com\/kw022024\/#organization"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage"},"thumbnailUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg","articleSection":["Compliance"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/","url":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/","name":"An Introduction to NERC CIP-013-1 - kw022024","isPartOf":{"@id":"https:\/\/itegriti.com\/kw022024\/#website"},"primaryImageOfPage":{"@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage"},"thumbnailUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg","datePublished":"2021-02-16T09:00:10+00:00","dateModified":"2021-04-12T02:39:59+00:00","description":"What is NERC-013-1? Why is needed? What are the requirements? Let\u2019s examine NERC\u2019s Cyber Security - Supply Chain Risk Management standard.","breadcrumb":{"@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#primaryimage","url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg","contentUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2021\/02\/itegriti_nerc-cip-013-1.jpg","width":800,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itegriti.com\/kw022024\/"},{"@type":"ListItem","position":2,"name":"An Introduction to NERC CIP-013-1"}]},{"@type":"WebSite","@id":"https:\/\/itegriti.com\/kw022024\/#website","url":"https:\/\/itegriti.com\/kw022024\/","name":"ITEGRITI","description":"cybersecurity | compliance | managed services","publisher":{"@id":"https:\/\/itegriti.com\/kw022024\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/itegriti.com\/kw022024\/#organization","name":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services","url":"https:\/\/itegriti.com\/kw022024\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/","url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","contentUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","width":600,"height":100,"caption":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/itegriti","https:\/\/x.com\/itegriti","https:\/\/www.linkedin.com\/company\/itegriti\/"]},{"@type":"Person","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/6fa12fbccd5abc86c2ce14ffbb619673","name":"Anastasios Arampatzis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adff645e812a27c2d07dd3c43fc9cd32?s=96&d=mm&r=g","caption":"Anastasios Arampatzis"},"description":"Anastasios Arampatzis is a retired Hellenic Air Force officer with over 20 years\u2019 worth of experience in managing IT projects and evaluating cybersecurity. During his service in the Armed Forces, he was assigned to various key positions in national, NATO and EU headquarters and has been honoured by numerous high-ranking officers for his expertise and professionalism. He was nominated as a certified NATO evaluator for information security. Anastasios\u2019 interests include among others cybersecurity policy and governance, ICS and IoT security, encryption, and certificates management. He is also exploring the human side of cybersecurity - the psychology of security, public education, organizational training programs, and the effect of biases (cultural, heuristic and cognitive) in applying cybersecurity policies and integrating technology into learning. He is intrigued by new challenges, open-minded and flexible. Currently, he works as a cybersecurity content writer for Bora - IT Security Marketing. Tassos is a member of the non-profit organization Homo Digitalis.","sameAs":["http:\/\/www.welcometobora.com","https:\/\/www.linkedin.com\/in\/anastasiosarampatzis\/","https:\/\/x.com\/TassosAramp"],"url":"https:\/\/itegriti.com\/kw022024\/author\/anastasios-arampatiz\/"}]}},"_links":{"self":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/2260"}],"collection":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/comments?post=2260"}],"version-history":[{"count":4,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/2260\/revisions"}],"predecessor-version":[{"id":2264,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/posts\/2260\/revisions\/2264"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/media\/2262"}],"wp:attachment":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/media?parent=2260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/categories?post=2260"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/tags?post=2260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}