<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Waterfall Security Solutions &#187; Regulations, Policies and Best Practices</title>
	<atom:link href="http://www.waterfallsecurity.com/category/knowledge/regulations/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.waterfallsecurity.com</link>
	<description>Waterfall Security Solutions</description>
	<lastBuildDate>Mon, 30 Jan 2012 12:37:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>NERC</title>
		<link>http://www.waterfallsecurity.com/nerc/</link>
		<comments>http://www.waterfallsecurity.com/nerc/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 09:24:14 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Regulations, Policies and Best Practices]]></category>

		<guid isPermaLink="false">http://waterfallsecurity.com/?p=1108</guid>
		<description><![CDATA[Critical National Infrastructure is under a constant, yet invisible, threat from cyber hacking and cyber terror attempts that are being launched from external networks. These attacks (mainly &#8211; from the Internet) are targeting industrial Process Control Networks (PCN), Supervisory Control and Data Acquisition (SCADA) Networks and lower level Distributed Control Systems (DCS) and Process Control [...]]]></description>
			<content:encoded><![CDATA[<p>Critical National Infrastructure is under a constant, yet invisible, threat from cyber hacking and cyber terror attempts that are being launched from external networks. These attacks (mainly &#8211; from the Internet) are targeting industrial Process Control Networks (PCN), Supervisory Control and Data Acquisition (SCADA) Networks and lower level Distributed Control Systems (DCS) and Process Control Systems (PCS) networks. <span id="more-1108"></span></p>
<p>In the Electricity Utilities’ domain, these critical networks control and operate the very machinery which powers modern day civilization. Throughout North America, electricity utilities are challenged with the task of complying with the reliability standards mandated by NERC (North American Electric Reliability Corporation).</p>
<p>The NERC-CIP (Critical Infrastructure Protection) standards, recently revised in May 2009, provide a cyber security framework for the identification and protection of Critical Cyber Assets to support reliable operation of the Bulk Electric System. The following whitepaper introduces the reader to the Waterfall One-Way™ unidirectional cyber security solution, and explains its ideal fit for achieving both powerful cyber-security as well as NERC-CIP compliance.</p>
<p>Many of Waterfall Unidirectional Security Gateway™ installations are designed and aimed to assist in achieving compliance to NERC regulations and requirements. The Waterfall technology consists of features, capabilities and design parameters which are aligned with NERC regulations and guidelines. These features includes, for example: non routable protocols, detection of unauthorized traffic, and, of course, the ability to provide the highest security level for Critical Assets and their respective Electronic perimeters.</p>
<p>For detailed information, including white papers, regarding archiving NERC compliance using Waterfall’s gateways – please contact us at <a href="mailto:info@waterfall-security.com">info@waterfall-security.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/nerc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NRC &amp; NIST 800.53</title>
		<link>http://www.waterfallsecurity.com/nrc-nist-800-53/</link>
		<comments>http://www.waterfallsecurity.com/nrc-nist-800-53/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 09:27:44 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Regulations, Policies and Best Practices]]></category>

		<guid isPermaLink="false">http://waterfallsecurity.com/?p=1113</guid>
		<description><![CDATA[NRC RG 5.71, currently in its Draft Final Rule, spells out the requirements for a cyber security plan to be submitted by the licensees for the NRC’s review and approval.  The licensee is required to “provide high assurance that digital computer and communication systems and networks are adequately protected against cyber attacks, up to and [...]]]></description>
			<content:encoded><![CDATA[<p>NRC RG 5.71, currently in its Draft Final Rule, spells out the requirements for a cyber security plan to be submitted by the licensees for the NRC’s review and approval.  The licensee is required to “provide high assurance that digital computer and communication systems and networks are adequately protected against cyber attacks, up to and including the design basis threat as described in Title 10 of the Code of Federal regulations (10CFR) Part73, Section 73.1.”<span id="more-1113"></span></p>
<p> The provisions in RG 5.71 require protection of all critical systems and networks and require of the licensee to implement controls that will defend these systems against any cyber attack that would adversely affect the availability, integrity and confidentiality of the critical system’s assets and data. The protection of critical assets and data is to be achieved through the, “implementation of state-of-the-art defense-in–depth protective strategies” RG 5.71 c (2), whose aim “to ensure   that the functions or tasks required to be performed by the critical assets … are maintained and carried out” RG 5.71 c (4) and “to prevent adverse effects from cyber attacks” (RG5.71 c (3)).</p>
<p> The controls referred to in NIST 800.53 and the recommendations relevant to those controls found in NIST 800.82, are defined in terms of three distinct classes; management, operational and technical. Each class is further divided into families of controls as per the table below.</p>
<p> The Waterfall One-Way<strong>™ </strong>Unidirectional Security Gateway provides specific responses to the control families mentioned in the following sections: <strong>Access Control, Audit and Accountability, Configuration Management, Media Protection, System and Information Integrity, System and Services Acquisition, Security Assessment and Authorization, Contingency Planning, Physical and Environmental Protection, System and Communications Protection. (AC, AU, CA, CM, CP, MP, PE, SA, SI and SC</strong>). Each of the relevant specific controls within these families as well as relevant recommendations made in NIST 800.82 will be discussed herein together with its corollary Waterfall One-Way™ response.</p>
<p> Please note that the controls, can be either directly relevant to Waterfall One Way™ technology, or supported by the technology but not directly linked to it or totally irrelevant and relate to other aspects of security. The following will discuss only the directly relevant controls which Waterfall One Way™ technology directly provides an answer to.</p>
<p>For detailed information, including white papers, regarding archiving NRC compliance using Waterfall’s gateways – please contact us at <a href="mailto:info@waterfall-security.com">info@waterfall-security.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/nrc-nist-800-53/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Other regulations and policies</title>
		<link>http://www.waterfallsecurity.com/other-regulations-and-policies/</link>
		<comments>http://www.waterfallsecurity.com/other-regulations-and-policies/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 09:30:56 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Regulations, Policies and Best Practices]]></category>

		<guid isPermaLink="false">http://waterfallsecurity.com/?p=1117</guid>
		<description><![CDATA[For detailed information, including white papers, regarding using Waterfall’s gateways under security policies and regulations – please contact us at info@waterfall-security.com.
]]></description>
			<content:encoded><![CDATA[<p>For detailed information, including white papers, regarding using Waterfall’s gateways under security policies and regulations – please contact us at <a href="mailto:info@waterfall-security.com">info@waterfall-security.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/other-regulations-and-policies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

