Key Insights for NERC CIP-015 Compliance: Anomaly Detection vs. Detecting Anomalous Activity
ID: a9fd3513-7ed9-5748-bc22-f14b13f5aeac
STIX ID: report--a9fd3513-7ed9-5748-bc22-f14b13f5aeac
Feed Name: Dragos Blog
**Executive summary:** This Dragos blog explains the proposed NERC CIP-015 Internal Network Security Monitoring (INSM) requirements driven by FERC/NERC and focuses on R1.2’s mandate to detect anomalous network activity; it describes four complementary detection approaches—behavioral, indicators, configuration, and modeling—and argues that combining them reduces false positives, improves contextual response, and helps utilities meet compliance while positioning the Dragos Platform as a solution for implementing these detection capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
