Font size
WorksheetsCyber Security Training - 2019
Total questions: 13
Worksheet time: 13mins
A BES Cyber Asset is an asset if rendered unavailable, degraded, or misused would, within 30 minutes of required operation, misoperation, or non-operation, adversely impact one or more Facilities, systems, or equipment which, if destroyed, degraded, or otherwise rendered unavailable when needed, would affect the reliable operation of the Bulk Electric System.
True
False
Which NERC CIP regulatory requirement(s) below become(s) effective January 1, 2020?
Drone physical and electronic access controls
Cyber security training
Low Impact BES Cyber System physical and electronic access controls
Cyber Security Incident response for Low Impact BES Cyber Systems
Compliance with NERC Critical Infrastructure Protection (CIP) Standards is required by law.
True
False
What are CIP High Impact areas?
Control rooms
EMS server rooms
EMS support rooms
Backup control centers
All substations
Low Impact Facilities include plants and substations below 100kV.
True
False
Upon job change or termination, physical access to High Impact areas must be disabled within 24 hours.
True
False
Physical and electronic contractor access to BES Cyber Systems is not regulated under NERC CIP requirements.
True
False
Which of the following is true for visitor access to High Impact area physical security perimeter (PSP)?
"Visitors" are defined as persons not employed or contracted with by Brazos Electric.
Visitors must be signed in and out of PSPs.
Visitors must be escorted at all times in PSPs.
Visitors must wear badges at all times in PSPs.
Visitors may be granted permission to make recordings or take photographs within a PSP.
Access to BES Cyber System Information (BCSI) must be controlled under CIP regulatory requirements.
True
False
Possible signs of a Cyber Security Incident include:
System alarm
Suspicious object
Substation break-in
Unexplained new user accounts, file changes, remote access requests and/or system reboots
Denials of service
Cyber Security risks include:
Unauthorized use of BES Cyber Assets
Unauthorized changes to BES Cyber Systems
Remote attacks (malicious code)
Malware spread by transient devices or removable media
Plugging into a yellow Ethernet port does not require EMS Administrator authorization.
True
False
Who must you always contact if you see a problem with physical security, computer systems, or if you suspect a cyber security incident?
General Manager
System Operator on Duty
PACS Administrator
EMS Administrator
