The world is being quietly rearranged by people who write very long documents.


The title they went with Critical Infrastructure Protection Reliability Standard CIP-015-1-Cyber Security-Internal Network Security Monitoring Noisy translates that to

Power grid operators must now monitor cyber threats inside their physical security systems


US regulators just approved a new rule that forces power grid operators to monitor for cyber threats inside their internal networks. This means they must now extend their cyber surveillance to systems that control physical access, like electronic gates and monitoring cameras.
For years, cyber security for critical infrastructure focused on keeping external threats out. This new rule shifts the focus to what happens once an attacker is already inside the network, or if an internal system itself is compromised. It means that the physical security of a power plant is now explicitly linked to its cyber security, forcing operators to integrate these two previously separate domains.
Watch for new procurement notices from power grid operators for integrated cyber-physical security systems, or for reports of increased spending on internal network monitoring tools.

If you insist
Read the original →