A blog by Digital Bond tracks developments in NERC/FERC, and generally in the area of control system security. A recent entry by Jason Holcomb  points to a DOE project called Bandolier that looks like it will deliver significant leverage to those tasked with compliance in the energy/utility industry. Essentially, the project will deliver templates for hardended system configurations that can be *automatically* checked and reported on by Nessus. This is a great development, and the project is worth paying attention to,  as it will allow some of the compliance data to be pulled automatically out of Nessus.

And by the way, the Digital Bond website is a great resource for information on SCADA, control system security, and NERC/FERC compliance.