
October 31, 2019 • Garrett Garitano
Winning at IT security for the energy industry is critical. With poor security in energy, the safety and health of people across the nation will be at risk. Hospitals will go dark. Traffic lights will malfunction. The economy will suffer, and people may lose jobs. All of this can be prevented by implementing better IT […]
Winning at IT security for the energy industry is critical. With poor security in energy, the safety and health of people across the nation will be at risk. Hospitals will go dark. Traffic lights will malfunction. The economy will suffer, and people may lose jobs. All of this can be prevented by implementing better IT security for the energy industry. We’ll show how to get started and cut through the chaos of cybersecurity.
The Path To IT Security Clarity: Design Your IT Security Requirements First
To develop a successful IT security program, you need to start by setting goals. You might be tempted to set a goal like “we will have no IT security failures.” Unfortunately, that goal may not be achievable. Instead, we recommend pursuing different objectives such as enforcing a robust IT security program throughout the organization. You may also add in access management KPIs to demonstrate your controls. To ensure your IT security program is comprehensive, you first need to gather your requirements.
Energy Industry IT Security Requirements
Consult the following resources to gather energy industry-specific security requirements.
These resources illustrate some of the specific energy industry IT security requirements and standards you must follow. If your energy facility is regulated by a specific agency, make sure you contact that organization to confirm their needs. Confirming your alignment with these best practices is an excellent first step. It shows that you are keeping up with your peers. This is only the beginning of the journey, however.
IT Security Best Practices: Look Beyond Your Industry’s Security Ideas
Modeling what happens within the energy industry will help you develop your minimum requirements. However, success in IT security ultimately requires that you take a proactive philosophy. Ask yourself: what are the best practices from other industries that we can model? To jump start your thinking, consider these questions.
Identify The Gap In IT Security Practices
Now that you have clarified your IT security requirements, you need to compare that vision to your current situation. By conducting this analysis, you will find out where to focus your efforts. Focus is crucial because the IT security department — even in a nuclear power plant — still has to operate with limited resources.
To start your self-assessment, examine the following areas.
If you have followed the process to this stage, you have achieved two important milestones. First, you have clarified your IT security requirements. Second, you have critically examined your organization for gaps and problems. Assessing your organization to find problems is rarely fun; however, it is far better to detect problems on your own than have others expose them.
Your Next Step To Better Energy Industry IT Security
Discovering gaps in your IT security is crucial. However, that awareness alone will not generate improved security. Your next step is to choose one priority area, like password management, and assign a project manager to lead the implementation. As that area is fully developed, you can then move your project emphasis to the next most significant gap in IT security.