Talk With an Expert

NERC CIP Patch Management and Cisco IOS Trains

NERC CIP Patch Management and Cisco IOS Trains (PDF, 2.42MB)Published: 14 Sep, 2015
Created by:
Aaron Prazan

NERC CIP Version 5 is challenging many organizations with mandatory patch management requirements. The requirements are intended to be general for any managed system with a defined source for patches or security updates. However, the picture gets muddier for Cisco network devices, because the vendor issues frequent new versions of the operating system along multiple user trains, not patches to any static version. In addition, the proprietary SCADA systems to which NERC requirements apply do not lend themselves to frequent patching. This paper will describe the requirements for patching under NERC's requirements and propose a set of processes an entity using such devices in a tightly controlled SCADA control system might use to satisfy the requirements.