{"id":105569,"date":"2025-03-12T15:09:43","date_gmt":"2025-03-12T07:09:43","guid":{"rendered":"https:\/\/version-2.com\/?p=105569"},"modified":"2025-03-12T15:13:37","modified_gmt":"2025-03-12T07:13:37","slug":"ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector","status":"publish","type":"post","link":"https:\/\/version-2.com\/en\/2025\/03\/ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector\/","title":{"rendered":"FERC and NERC: Cyber Security Monitoring for The Energy Sector"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"105569\" class=\"elementor elementor-105569\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-35fe5dd post-content elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"35fe5dd\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;cef08c3&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-409a2e9a\" data-id=\"409a2e9a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5a8be8f elementor-widget elementor-widget-text-editor\" data-id=\"5a8be8f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><img fetchpriority=\"high\" decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp?resize=1200%2C628&#038;ssl=1\" width=\"1200\" height=\"628\" \/><\/p><div class=\"elementor-widget-container\"><p>As cyber threats targeting critical infrastructure continue to evolve, the energy sector remains a prime target for malicious actors. Protecting the electric grid requires a strong regulatory framework and robust cybersecurity monitoring practices. In the United States, the Federal Energy Regulatory Commission (FERC) and the North American Electric Reliability Corporation (NERC) play key roles in safeguarding the power system against cyber risks.<\/p><p>\u00a0<\/p><p>Compliance with the NERC Critical Infrastructure Protection (NERC CIP) standards provides a baseline for mitigating security risk, but organizations should implement security technologies that help them streamline these processes.<\/p><h2>Who are FERC and NERC?<\/h2><p>The Federal Energy Regulatory Commission (FERC) is the governmental agency that oversees the power grid\u2019s reliability. Since the Energy Policy Act of 2005 that granted FERC these powers, the rise of smart technologies across the energy industry expanded. This led to the Energy Independence and Security Act of 2007 (EISA) which led to FERC and the National Institute of Standards and Technology (NIST) to coordinate cybersecurity reliability standards that protect the industry.<\/p><p>\u00a0<\/p><p>However, to develop these reliability standards, FERC certified the North American Electric Reliability Corporation (NERC). Currently, NERC has thirteen published and enforceable Critical Infrastructure Protection (CIP) standards plus one more awaiting approval.<\/p><h2>What are the NERC CIP requirements?<\/h2><p>The cybersecurity<a href=\"https:\/\/www.nerc.com\/pa\/Stand\/Pages\/ReliabilityStandards.aspx\"> Reliability Standards<\/a> are broken out across nine documents, each detailing the different requirements and controls for compliance.<\/p><p>\u00a0<\/p><h3>CIP-002: BES Cyber System Categorization<\/h3><p>This CIP creates \u201cbright-line\u201d criteria for how to categorize BES Cyber Systems based on impact that an outage would cause. The publication separates BES Cyber Systems into three general categories:<\/p><ul><li class=\"lazyloaded\">High Impact<\/li><li class=\"lazyloaded\">Medium Impact<\/li><li class=\"lazyloaded\">Low Impact<\/li><\/ul><p>\u00a0<\/p><h3>CIP-003-8: Security Management Controls<\/h3><p>This publication, with its most recent iteration being enforceable in April 2026, requires Responsible Entities to create policies, procedures, and processes for high or medium impact BES Cyber Systems, including:<\/p><ul><li class=\"nitro-lazy\"><strong>Cyber security awareness<\/strong>: training delivered every 15 calendar months<\/li><li class=\"nitro-lazy\"><strong>Physical security controls<\/strong>: protections for assets, locations within an asset containing low impact BES systems, and Cyber Assets<\/li><li class=\"nitro-lazy\"><strong>Electronic access controls<\/strong>: controls that limit inbound and outbound electronic access for assets containing low impact BES Cyber Systems<\/li><li class=\"nitro-lazy\"><strong>Cyber security incident response<\/strong>: identification, classification, and response to Cyber Security incidents, including establishing role and responsibilities for testing (every 36 months) and handling incidents, including updating Cyber Security Incident response plan within 180 days of a reportable incident<\/li><li class=\"nitro-lazy\">T<strong>ransient cyber asset and removable media malicious code risk mitigation: <\/strong>Plans for implementing, maintaining, and monitoring anti-virus, application allowlists, and other methods to detect malicious code<\/li><li class=\"nitro-lazy\"><strong>Vendor electronic remote access security controls: <\/strong>processes for remote access to mitigate risks, including ways to determine and disable remote access and detect known or suspected malicious communications from vendor remote access<\/li><\/ul><p>\u00a0<\/p><h3>CIP-004-7: Personnel &amp; Training<\/h3><p>Every Responsible Entity needs to have one or more documented processes and provide evidence to demonstrate implementation of:<\/p><ul><li class=\"nitro-lazy\">Security awareness training<\/li><li class=\"nitro-lazy\">Personnel risk assessments prior to granting authorized electronic or unescorted physical access<\/li><li class=\"nitro-lazy\">Access management programs<\/li><li class=\"nitro-lazy\">Access revocation programs<\/li><li class=\"nitro-lazy\">Access management, including provisioning, authorizing, and terminating access<\/li><\/ul><h3>CIP-005-7: Electronic Security Perimeter(s)<\/h3><p>To mitigate risks, Responsible Entities need to have controls for permitting known and controlled communications need documented processes and evidence of:<\/p><ul><li class=\"nitro-lazy\">Connection to network using a routable protocol protected by an Electronic Security Perimeter (ESP)<\/li><li class=\"nitro-lazy\">Permitting and documenting the reasoning for necessary communications while denying all other communications<\/li><li class=\"nitro-lazy\">Limiting network accessibility to management Interfaces<\/li><li class=\"nitro-lazy\">Performing authentication when allowing remove access through dial-up connectivity<\/li><li class=\"nitro-lazy\">Monitoring to detect known or suspected malicious communications<\/li><li class=\"nitro-lazy\">Implementation of controls, like encryption or physical access restrictions, to protect data confidentiality and integrity<\/li><li class=\"nitro-lazy\">Remote access management capabilities, multi-factor authentication and multiple methods for determining active vendor remote access<\/li><li class=\"nitro-lazy\">Multiple methods for disabling active vendor remote access<\/li><li class=\"nitro-lazy\">One or more methods to determine authenticated vendor-initiated remote access, terminating these remote connections, and controlling ability to reconnect<\/li><\/ul><p>\u00a0<\/p><p>Most of these requirements fall under the umbrella of <a href=\"https:\/\/graylog.org\/post\/centralized-log-management-for-network-monitoring\/\">network security monitoring<\/a>. For example, many organizations will implement tools like:<\/p><ul><li class=\"nitro-lazy\">Firewalls that allow or deny communications<\/li><li class=\"nitro-lazy\"><a href=\"https:\/\/graylog.org\/post\/do-you-need-ids-and-ips\/\">Intrusion detection system (IDS)\/Intrusion prevention system (IPS)<\/a> that monitor traffic and packets to either detect intrusions or proactively stop them<\/li><\/ul><p>\u00a0<\/p><p>Once organizations can define baselines for normal network traffic, they can implement detections that alert their security teams to potential incidents.<\/p><p><picture class=\"aligncenter wp-image-25959 size-full\"><img decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2022\/07\/Network-Activity.png.webp?resize=1674%2C896&#038;ssl=1\" width=\"1674\" height=\"896\" \/><\/picture><\/p><h3>CIP-006-6: Physical Security of BES Cyber Systems<\/h3><p>To prove management of physical access to these systems, Responsible Entities need documented processes and evidence that include:<\/p><ul><li class=\"nitro-lazy\">Physical security plan with defined operation or procedural controls for restricting physical access<\/li><li class=\"nitro-lazy\">Controls for managing authorized unescorted access<\/li><li class=\"nitro-lazy\">Monitoring for unauthorized physical access<\/li><li class=\"nitro-lazy\">Alarms or alerts for responding to detected unauthorized access<\/li><li class=\"nitro-lazy\">Logs that must be retained for 90 days for managing entry of individuals authorized for unescorted physical access<\/li><li class=\"nitro-lazy\">Visitor control program that includes continuous escort for visitors, logging visitors, and retaining visitor logs<\/li><li class=\"nitro-lazy\">Maintenance and testing programs for the physical access control system<\/li><\/ul><p>\u00a0<\/p><p>Many organizations use technologies to help manage physical security, like badges or smart alarms. By incorporating these technologies into the overarching cybersecurity monitoring, Responsible Entities can correlate activities across the physical and digital domains.<\/p><figure id=\"attachment_30315\" class=\"wp-caption aligncenter\" style=\"width: 1670px;\" aria-describedby=\"caption-attachment-30315\"><img decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/Security-Card-Access-Dark.png.webp?resize=1670%2C941&#038;ssl=1\" width=\"1670\" height=\"941\" \/><figcaption id=\"caption-attachment-30315\" class=\"wp-caption-text\">Example: Security Card Access in buildings showing entry and exit times.<\/figcaption><\/figure><p>\u00a0<\/p><p>By tracking both physical access and digital access to BES Cyber Systems, Responsible Entities can improve their overarching security posture, especially given the interconnection between physical and digital access to systems.<\/p><h3>CIP-007-6: System Security Management<\/h3><p>To prove that they have the technical, operational, and procedural system security management capabilities, Responsible Entities need documented processes and evidence that include:<\/p><ul><li class=\"nitro-lazy\"><strong>System hardening<\/strong>: disabling or preventing unnecessary remote access, protection against physical input\/output ports used for network connectivity, risk mitigation to prevent CPU or memory vulnerabilities<\/li><li class=\"nitro-lazy\"><strong>Patch management process:<\/strong> evaluating security patch applicability at least once every 35 calendar days and tracking, evaluating, and installing security patches<\/li><li class=\"nitro-lazy\"><strong>Malicious code prevention<\/strong>: methods for deterring, detecting, or preventing malicious code and mitigating the threat of detected malicious code<\/li><li class=\"nitro-lazy\"><strong>Monitoring for security events<\/strong>: logging security events per system capabilities, generating security event alerts, retaining security event logs, and reviewing summaries or samplings of logged security events<\/li><li class=\"nitro-lazy\"><strong>System access controls<\/strong>: authentication enforcement methods, identification and inventory of all known default or generic accounts, identification of people with authorized access to shared accounts, changing default passwords, technical or procedural controls for password-only authentication, including forced changes at least once every 15 calendar months, limiting the number of unsuccessful authentication attempts and generating<\/li><\/ul><p>\u00a0<\/p><p>Having a robust threat detection and incident response (TDIR) solution enables Responsible Parties to leverage user and entity behavior analytics (UEBA) with the rest of their log data so they can handle security functions like:<\/p><ul><li class=\"nitro-lazy\">Privileged access management (PAM)<\/li><li class=\"nitro-lazy\">Password policy compliance<\/li><li class=\"nitro-lazy\">Abnormal privilege escalation<\/li><li class=\"nitro-lazy\">Time spent accessing a resource<\/li><li class=\"nitro-lazy\"><a href=\"https:\/\/graylog.org\/post\/visualize-and-correlate-ids-alerts-with-open-source-tools\">Brute force attack detection<\/a><\/li><\/ul><p><picture class=\"aligncenter wp-image-15579 size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2023\/06\/Picture1-3.png.webp?resize=624%2C291&#038;ssl=1\" width=\"624\" height=\"291\" \/><\/picture><\/p><p>\u00a0<\/p><h3>CIP-008-6: Incident Reporting and Response Planning<\/h3><p>To mitigate risk to reliable operation, Responsible Entities need documented incident response plans and evidence that include:<\/p><ul><li class=\"nitro-lazy\">Processes for identifying, classifying, and responding to security incidents<\/li><li class=\"nitro-lazy\">Roles and responsibility for the incident response groups or individuals<\/li><li class=\"nitro-lazy\">Incident handling procedures<\/li><li class=\"nitro-lazy\">Testing incident response plan at least once every 15 calendar months<\/li><li class=\"nitro-lazy\">Retaining records for reportable and other security incidents<\/li><li class=\"nitro-lazy\">Reviewing, updating, and communicating lessons learned, changes to the plan based on lessons learned, notifying people of changes<\/li><\/ul><p>\u00a0<\/p><p>Security analytics enables Responsible Entities to enhance their incident detection and response capabilities. By building detections around <a href=\"https:\/\/graylog.org\/post\/what-is-the-mitre-attck-framework\/\">MITRE ATT&amp;CK tactics, techniques, and procedures (TTPs)<\/a>, security teams can connect the activities occurring in their environments with real-world activities to investigate an attacker\u2019s path faster. Further, with high-fidelity Sigma rule detections aligned to the ATT&amp;CK framework, Responsible Entities improve their incident response capabilities.<\/p><p><picture class=\"aligncenter wp-image-26006 size-large\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2024\/04\/Sigma-Rules-1024x617.png.webp?resize=1024%2C617&#038;ssl=1\" width=\"1024\" height=\"617\" \/><\/picture><\/p><p>\u00a0<\/p><p>In the aftermath of an incident or incident response test, organizations need to develop reports that enable them to identify lessons learned. These include highlighting:<\/p><ul><li class=\"nitro-lazy\">Key findings<\/li><li class=\"nitro-lazy\">Actions taken<\/li><li class=\"nitro-lazy\">Impact on stakeholders<\/li><li class=\"nitro-lazy\">Incident ID<\/li><li class=\"nitro-lazy\">Incident summary that includes type, time, duration, and affected systems\/data<\/li><\/ul><p>\u00a0<\/p><p>To improve processes, Responsible Entities need to organize the different pieces of evidence into an <a href=\"https:\/\/graylog.org\/post\/best-practices-for-writing-an-it-security-incident-report\/\">incident response report<\/a> that showcases the timeline of events.<\/p><p><picture class=\"aligncenter size-full wp-image-28691\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2024\/10\/Security_Guided-Analyst-Workflow_Investigations-Phishing-Attack-Timeline-View.png.webp?resize=1000%2C573&#038;ssl=1\" width=\"1000\" height=\"573\" \/><\/picture><\/p><p>\u00a0<\/p><p>Further, they need to capture crucial information about the incident, including:<\/p><ul><li class=\"nitro-lazy\">Nature of threat<\/li><li class=\"nitro-lazy\">Business impact<\/li><li class=\"nitro-lazy\">Immediate actions taken<\/li><li class=\"nitro-lazy\">When\/how incident occurred<\/li><li class=\"nitro-lazy\">Who\/what was affected<\/li><li class=\"nitro-lazy\">Overall scope<\/li><\/ul><p><picture class=\"aligncenter size-large wp-image-29070\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2024\/11\/Investigations-Phishing-Attack-1024x588.png.webp?resize=1024%2C588&#038;ssl=1\" width=\"1024\" height=\"588\" \/><\/picture><\/p><p>\u00a0<\/p><h3>CIP-009-6: Recovery Plans for BES Cyber Systems<\/h3><p>To support continued stability, operability, and reliability, Responsible Entities need documented recovery plans with processes and evidence for:<\/p><ul><li class=\"nitro-lazy\">Activation of recovery plan<\/li><li class=\"nitro-lazy\">Responder roles and responsibilities<\/li><li class=\"nitro-lazy\">Backup and storage of information required for recovery and verification of backups<\/li><li class=\"nitro-lazy\">Testing recovery plan at least once every 15 calendar months<\/li><li class=\"nitro-lazy\">Reviewing, updating, and communicating lessons learned, changes to the plan based on lessons learned, notifying people of changes<\/li><\/ul><p>\u00a0<\/p><h3>CIP-010-4: Configuration Change Management and Vulnerability Assessments<\/h3><p>To prevent and detect unauthorized changes, Responsible Entities need documentation and evidence of configuration change management and vulnerability assessment that includes:<\/p><ul><li class=\"nitro-lazy\">Authorization of changes that can alter behavior of one or more cybersecurity controls<\/li><li class=\"nitro-lazy\">Testing changes prior to deploying them in a production environment<\/li><li class=\"nitro-lazy\">Verifying identity and integrity of operating systems, firmware, software, or software patches prior to installation<\/li><li class=\"nitro-lazy\">Monitoring for unauthorized changes that can alter the behavior of one or more cybersecurity controls at least once every 35 calendar days, including at least one control for configurations affecting network accessibility, CPU and memory, installation, removal, or updates to operating systems, firmware, software, and cybersecurity patches, malicious code protection, security event logging or alerting, authentication methods, enabled or disabled account status<\/li><li class=\"nitro-lazy\">Engaging in vulnerability assessment at least once every 15 calendar months<\/li><li class=\"nitro-lazy\">Performing an active vulnerability assessment in a test environment and documenting the results at least once every 36 calendar months<\/li><li class=\"nitro-lazy\">Performing vulnerability assessments for new systems prior to implementation<\/li><\/ul><p>\u00a0<\/p><h3>CIP-011-3: Information Protection<\/h3><p>To prevent unauthorized access, Responsible Entities need documented information protection processes and evidence of:<\/p><ul><li class=\"nitro-lazy\">Methods for identifying, protecting, and securely handling BES Cyber System Information (BCSI)<\/li><li class=\"nitro-lazy\">Methods for preventing the unauthorized retrieval of BCSI prior to system disposal<\/li><\/ul><h3>CIP-012-1: Communications between Control Centers<\/h3><p>To protect the confidentiality, integrity, and availability assessment monitoring data transmitted between Control Centers, Responsible Entities need documented processes for and evidence of:<\/p><ul><li class=\"nitro-lazy\">Risk mitigation for unauthorized disclosure and modification or loss of availability of data<\/li><li class=\"nitro-lazy\">Identification of risk mitigation methods<\/li><li class=\"nitro-lazy\">Identification of where methods are implemented<\/li><li class=\"nitro-lazy\">Assignment of responsibilities when different Responsible Entities own or operate Control Centers<\/li><\/ul><p>\u00a0<\/p><p>To mitigate <a href=\"https:\/\/graylog.org\/post\/centralized-log-management-for-data-exfiltration\/\">data exfiltration risks<\/a>, Responsible Parties need to aggregate, correlate, and analyze log data across:<\/p><ul><li class=\"nitro-lazy\">Network traffic logs<\/li><li class=\"nitro-lazy\">Antivirus logs<\/li><li class=\"nitro-lazy\">UEBA solutions<\/li><\/ul><p>\u00a0<\/p><p>With visibility into abnormal data downloads, they can more effectively monitor communications between control centers.<\/p><p><picture class=\"aligncenter size-large wp-image-29963\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"alignnone size-full\" src=\"https:\/\/i0.wp.com\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2023\/03\/6.1-Network-Stats-1024x510.png.webp?resize=1024%2C510&#038;ssl=1\" width=\"1024\" height=\"510\" \/><\/picture><\/p><p>\u00a0<\/p><h3>CIP-013-2: Supply Chain Risk Management<\/h3><p>To mitigate supply chain risks, Responsible Entities need documented security controls and evidence of:<\/p><ul><li class=\"nitro-lazy\">Procurement processes for identifying and assessing security risks related to installing vendor equipment and software and switching vendors<\/li><li class=\"nitro-lazy\">Receiving notifications about vendor-identified incidents related to products or services<\/li><li class=\"nitro-lazy\">Coordinating responses to vendor-identified incidents related to products or services<\/li><li class=\"nitro-lazy\">Notifying vendors when no longer granting remote or onsite access<\/li><li class=\"nitro-lazy\">Vendor disclosure of known vulnerabilities related to products or services<\/li><li class=\"nitro-lazy\">Verifying software and patch integrity and authenticity<\/li><li class=\"nitro-lazy\">Coordination controls for vendor-initiated remote access<\/li><li class=\"nitro-lazy\">Review and obtain approval for the supply chain risk management plan<\/li><\/ul><p>\u00a0<\/p><h3>CIP-015-1: Internal Network Security Monitoring<\/h3><p>While this standard is currently awaiting approval by the NERC Board of Trustees, Responsible Entities should consider preparing for publication and enforcement with documented processes and evidence of monitoring internal networks\u2019 security, including the implementation of:<\/p><ul><li class=\"nitro-lazy\">Network data feeds using a risk-based rationale for monitoring network activity, including connections, devices, and network communications<\/li><li class=\"nitro-lazy\">Detections for anomalous network activity<\/li><li class=\"nitro-lazy\">Evaluating anomalous network activity<\/li><li class=\"nitro-lazy\">Retaining internal network security monitoring data<\/li><li class=\"nitro-lazy\">Protecting internal network security monitoring data<\/li><\/ul><p>\u00a0<\/p><h2>Graylog Security: Enabling the Energy Sector to Comply with NERC CIP<\/h2><p>Using <a href=\"https:\/\/www.graylog.org\/products\/security\/\">Graylog Security<\/a>, you can rapidly mature your TDIR capabilities without the complexity and cost of traditional Security Information and Event Management (SIEM) technology. Graylog Security\u2019s <a href=\"https:\/\/graylog.org\/products\/illuminate\/\">Illuminate bundles<\/a> include detection rulesets so that you have content, like <a href=\"https:\/\/graylog.org\/post\/the-ultimate-guide-to-sigma-rules\/\">\u00a0<\/a><a href=\"https:\/\/graylog.org\/post\/the-ultimate-guide-to-sigma-rules\/\">Sigma detections<\/a>, enabling you to uplevel your security alert, incident response, and threat hunting capabilities with correlations to ATT&amp;CK tactic, techniques, and procedures (TTPs).<\/p><p>By leveraging our cloud-native capabilities and out-of-the-box content, you gain immediate value from your logs. Our anomaly detection ML improves over time without manual tuning, adapting rapidly to new data sets, organizational priorities, and custom use cases so that you can automate key user and entity access monitoring.<\/p><p>With our intuitive user interface, you can rapidly investigate alerts. Our lightning-fast search capabilities enable you to search terabytes of data in milliseconds, reducing dwell times and shrinking investigations by hours, days, and weeks.<\/p><p>To learn how Graylog Security can help you implement robust threat detection and response, <a href=\"https:\/\/go2.graylog.org\/contact-sales\">contact us today.<\/a><\/p><p>\u00a0<\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2004c86 elementor-widget elementor-widget-shortcode\" data-id=\"2004c86\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"93504\" class=\"elementor elementor-93504\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6461a578 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"6461a578\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2f063c39\" data-id=\"2f063c39\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-14e1df2a elementor-widget elementor-widget-text-editor\" data-id=\"14e1df2a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>About Graylog\u00a0\u00a0<\/strong><br \/>At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We\u2019re committed to turning this vision into reality by providing Threat Detection &amp; Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective\u2014whether hosted by us, on-premises, or in your cloud\u2014but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>As cyber threats targeting critical infrastructure cont [&hellip;]<\/p>\n","protected":false},"author":149011790,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":true},"categories":[1303,1305,61],"tags":[1077,1304],"class_list":["post-105569","post","type-post","status-publish","format-standard","hentry","category-graylog","category-1305","category-press-release","tag-1077","tag-graylog"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FERC and NERC: Cyber Security Monitoring for The Energy Sector - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/graylog.org\/post\/ferc-and-nerc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FERC and NERC: Cyber Security Monitoring for The Energy Sector - Version 2\" \/>\n<meta property=\"og:description\" content=\"As cyber threats targeting critical infrastructure cont [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/graylog.org\/post\/ferc-and-nerc\/\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-12T07:09:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-03-12T07:13:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp\" \/>\n<meta name=\"author\" content=\"tracylamv2\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"tracylamv2\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"23 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/2025\\\/03\\\/ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector\\\/\"},\"author\":{\"name\":\"tracylamv2\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\"},\"headline\":\"FERC and NERC: Cyber Security Monitoring for The Energy Sector\",\"datePublished\":\"2025-03-12T07:09:43+00:00\",\"dateModified\":\"2025-03-12T07:13:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/2025\\\/03\\\/ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector\\\/\"},\"wordCount\":2097,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn-jnkep.nitrocdn.com\\\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\\\/assets\\\/images\\\/optimized\\\/rev-ed4d356\\\/graylog.org\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp\",\"keywords\":[\"2025\",\"Graylog\"],\"articleSection\":[\"Graylog\",\"2025\",\"Press Release\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/2025\\\/03\\\/ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector\\\/\",\"url\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/\",\"name\":\"FERC and NERC: Cyber Security Monitoring for The Energy Sector - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn-jnkep.nitrocdn.com\\\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\\\/assets\\\/images\\\/optimized\\\/rev-ed4d356\\\/graylog.org\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp\",\"datePublished\":\"2025-03-12T07:09:43+00:00\",\"dateModified\":\"2025-03-12T07:13:37+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn-jnkep.nitrocdn.com\\\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\\\/assets\\\/images\\\/optimized\\\/rev-ed4d356\\\/graylog.org\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp\",\"contentUrl\":\"https:\\\/\\\/cdn-jnkep.nitrocdn.com\\\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\\\/assets\\\/images\\\/optimized\\\/rev-ed4d356\\\/graylog.org\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/graylog.org\\\/post\\\/ferc-and-nerc\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FERC and NERC: Cyber Security Monitoring for The Energy Sector\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\",\"name\":\"tracylamv2\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"caption\":\"tracylamv2\"},\"url\":\"https:\\\/\\\/version-2.com\\\/en\\\/author\\\/tracylamv2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FERC and NERC: Cyber Security Monitoring for The Energy Sector - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/graylog.org\/post\/ferc-and-nerc\/","og_locale":"en_US","og_type":"article","og_title":"FERC and NERC: Cyber Security Monitoring for The Energy Sector - Version 2","og_description":"As cyber threats targeting critical infrastructure cont [&hellip;]","og_url":"https:\/\/graylog.org\/post\/ferc-and-nerc\/","og_site_name":"Version 2","article_published_time":"2025-03-12T07:09:43+00:00","article_modified_time":"2025-03-12T07:13:37+00:00","og_image":[{"url":"https:\/\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp","type":"","width":"","height":""}],"author":"tracylamv2","twitter_card":"summary_large_image","twitter_misc":{"Written by":"tracylamv2","Est. reading time":"23 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/graylog.org\/post\/ferc-and-nerc\/#article","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/2025\/03\/ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector\/"},"author":{"name":"tracylamv2","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365"},"headline":"FERC and NERC: Cyber Security Monitoring for The Energy Sector","datePublished":"2025-03-12T07:09:43+00:00","dateModified":"2025-03-12T07:13:37+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/zh\/2025\/03\/ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector\/"},"wordCount":2097,"commentCount":0,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/graylog.org\/post\/ferc-and-nerc\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp","keywords":["2025","Graylog"],"articleSection":["Graylog","2025","Press Release"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/graylog.org\/post\/ferc-and-nerc\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/version-2.com\/zh\/2025\/03\/ferc-and-nerc-cyber-security-monitoring-for-the-energy-sector\/","url":"https:\/\/graylog.org\/post\/ferc-and-nerc\/","name":"FERC and NERC: Cyber Security Monitoring for The Energy Sector - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/graylog.org\/post\/ferc-and-nerc\/#primaryimage"},"image":{"@id":"https:\/\/graylog.org\/post\/ferc-and-nerc\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp","datePublished":"2025-03-12T07:09:43+00:00","dateModified":"2025-03-12T07:13:37+00:00","breadcrumb":{"@id":"https:\/\/graylog.org\/post\/ferc-and-nerc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/graylog.org\/post\/ferc-and-nerc\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/graylog.org\/post\/ferc-and-nerc\/#primaryimage","url":"https:\/\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp","contentUrl":"https:\/\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-ed4d356\/graylog.org\/wp-content\/uploads\/2025\/02\/2305_GLLabs_MyFirstLoadBalancer26.jpg.webp"},{"@type":"BreadcrumbList","@id":"https:\/\/graylog.org\/post\/ferc-and-nerc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/"},{"@type":"ListItem","position":2,"name":"FERC and NERC: Cyber Security Monitoring for The Energy Sector"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365","name":"tracylamv2","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","caption":"tracylamv2"},"url":"https:\/\/version-2.com\/en\/author\/tracylamv2\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-rsJ","jetpack_featured_media_url":"","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/105569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/users\/149011790"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/comments?post=105569"}],"version-history":[{"count":7,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/105569\/revisions"}],"predecessor-version":[{"id":105576,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/105569\/revisions\/105576"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/media?parent=105569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/categories?post=105569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/tags?post=105569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}