RIUNIONE ESPLORATIVA PER UNA CANDIDATURA ITALIANA ALLINIZIATIVA EUROPEA ERN-CIP CYBERSECURITY ENEA – Lungotevere Thaon di Revel, 76 – ROMA Esperienza maturata.

Slides:



Advertisements
Similar presentations
1 Landis+Gyr Confidential Analyst Presentation November 2008`1 Confidential Company Overview & Update DRAFT November 2008 Cyber-Security & Interoperability.
Advertisements

Expanding LTE for Devices European Commission Information Society and Media The aim of EXATED is to realise the vision of a new scalable.
SOA for EGovernment 1 Emergency Services Enterprise Framework: A Service-Oriented Approach Sukumar Dwarkanath COMCARE Michael Daconta Oberon Associates.
Critical Infrastructure Protection Policy Priorities Sara Pinheiro European Commission DG Home Affairs.
TIA/ANSI Presentation on New and Novel Topic (NNT) Agenda Item 7 Smart Grid David Su DOCUMENT #:GSC14-PLEN-013 R2 FOR:Presentation SOURCE:TIA/ANSI/NIST.
International Telecommunication Union An Insight into BDT Programme 3 Marco Obiso ICT Applications and Cybersecurity Division Telecommunication Development.
1 Study into IPS Suitability for Air-Ground ATM Communication Carsten Underbjerg, Ericsson Member of Helios Study Consortium European Organisation for.
Impact of Smart Grid, ICT on Environment and Climate Change David Su Advanced Network Technologies National Institute of Standards and Technology ITU Symposium.
TC 57 IEC TC57 WG15 - Security Status & Roadmap, July 2008 Frances Cleveland Convenor WG15.
European Rail Agency Workshop 29 th September 2011 (Lille) Dr Björn Paulsson (UIC) Dr Stephen Ingleton (Newcastle University) REDUCING THE OCCURRENCES.
Proactively Preventing Freight Wagon Derailment Innotrans | Berlin| 18 th September Dr Björn Paulsson (UIC) Grigory Kozyr(UIC) Gordana Vasic (NewRail.
Geneva, Switzerland, September 2014 Smart Grid cyber security within IEC TC57 WG15 Fernando Alvarez, Cyber Security Technical PM ABB Switzerland.
Copyright © 2014 American Water Works Association Water Sector Approach to Process Control System Security.
DESEREC, an ICT for Trust and Security project DESEREC: Dependability and Security by Enhanced Reconfigurability.
The French approach to CIIP ENISA workshop. Coordination of CIP in France ANSSI 2 A cross-ministerial issue The General Secretariat for Defense and National.
Cyber Security and the Smart Grid George W. Arnold, Eng.Sc.D. National Institute of Standards and Technology (NIST) U.S. Department of Commerce
Cyber Security in Implementing Modern Grid Automation Systems Vijayan SR CIGRE SC D2 Tutorials & Colloquium on SMART GRID Mysore, 13 – 15 November 2013.
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
Security Offering. Cyber Security Solutions 2 Assessment Analysis & Planning Design & Architecture Development & Implementation O&M Critical Infrastructure.
National Cybersecurity Management System
Jeju, 13 – 16 May 2013Standards for Shared ICT HIS – Smart Grid Karen Bartleson, President, IEEE Standards Association Document No: GSC17-PLEN-72 Source:
K E M A, I N C. Current Status of Cyber Security Issues 2004 Keynote Address Joe Weiss January 20, 2004.
A project under the 7th Framework Programme CPS Workshop Stockholm 12/04/2010 Gunnar Björkman Project Coordinator A Security Project for the Protection.
Critical Information Infrastructure Protection: Urgent vs. Important Miguel Correia 2012 Workshop on Cyber Security and Global Affairs and Global Security.
| 1 Leveraging Research/Industry Collaboration for Cybersecurity Technology Adoption: The TCIPG Story Alfonso Valdes, University of Illinois On behalf.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
Cyber Security of Smart Grid Systems
K E M A, I N C. NERC Cyber Security Standards and August 14 th Blackout Implications OSI PI User Group April 20, 2004 Joe Weiss
Lessons Learned in Smart Grid Cyber Security
Shane Cherry Midge Simpson Critical Infrastructure Protection / Resilience Simulator May 29, 2009 Stuart Walsh:
Assurance Case Approach TECNALIA Inspiring Business Novara November, 2013 TRIAL WS.
Isdefe ISXXXX XX Your best ally Panel: Future scenarios for European critical infrastructures protection Carlos Martí Sempere. Essen.
SECURE –FORCE Project Christodoulos Keratidis Atlantis Consulting S.A. 1 st SEE-INNOVATION Know How Event Skopje, December 2006.
CSIAC is a DoD Information Analysis Center (IAC) sponsored by the Defense Technical Information Center (DTIC) Presentation to: Insider Threat SOAR Workshop.
Doc.: IEEE /0047r1 Submission SGIP Liaison Report to IEEE Following the SGIP (2.0) Inaugural Conference Nov 5-7, 2013 Date:
K E M A, I N C. Ten Steps To Secure Control Systems APPA 2005 Conference Session: Securing SCADA Networks from Cyber Attacks Memphis, TN April 18, 2005.
Dependable ICT for Utilities Proposal for DESIRE activities The CRIS Institute Hans Ottosson The International.
1 Smart Grid Cyber Security Annabelle Lee Senior Cyber Security Strategist Computer Security Division National Institute of Standards and Technology June.
Project co-funded by the European Commission within the 7th Framework Program (Grant Agreement No ) Business Convergence WS#2 Smart Grid Technologies.
Frankfurt (Germany), 6-9 June 2011 G. Dondossola, F. Garrone, J. Szanto RSE  Research context  Test bed architecture  Attack model  Attack experiments.
"The views expressed in this presentation are those of the author and do not necessarily reflect the views of the European Commission“ Future Internet.
Open Workshop,Pisa, November 2002 VI Framework: Integrated Project Dependable Systems and Information infrastructure - Research and Exploitation DeSIRE.
Jeju, 13 – 16 May 2013Standards for Shared ICT TIA TR-50 M2M-Smart Device Communications Dr. Jeffery Smith Chief Innovation and Technology Officer/EVP.
CIP 2015 Smart Grid Vulnerability Assessment Using National Testbed Networks IHAB DARWISHOBINNA IGBETAREQ SAADAWI.
Open Workshop,Pisa, November 2002 VI Framework: Integrated Project Dependability Foundations for Information infrastructures - Network of Excellence DeFINE.
EU activities against cyber crime Radomír Janský Unit - Fight against Organised Crime Directorate-General Justice, Freedom and Security (DG JLS) European.
1 1 Cybersecurity : Optimal Approach for PSAPs FCC Task Force on Optimal PSAP Architecture Working Group 1 Final Report December 10 th, 2015.
Session title: Protection of Smart Utility Grids Group edited strategy.
Urban Infrastructure and Its Protection Responding to the Unexpected Interest Group Report.
ERCOT IT Update Ken Shoquist VP, CIO Information Technology Board Meeting February 2004.
TÜBİTAK – BİLGEM – SGE Cyber Security Institute Asım Gençer Gökce TÜBİTAK BİLGEM Cyber Security Institute (SGE) Role: Cyber.
LSEC H2020-DS - & CIP Ulrich Seldeslachts, Brussels, January 27th, 2016.
Sicherheitsaspekte beim Betrieb von IT-Systemen Christian Leichtfried, BDE Smart Energy IBM Austria December 2011.
Security and Resilience Pat Looney Brookhaven National Laboratory April 2016.
Cyber security: Lithuanian National Regulatory Authority expertise in monitoring national networks resilience Dr. Rytis Rainys | rrt.lt at TAIEX Multi-beneficiary.
Digital Security Focus Area & Critical Infrastructure Protection in H2020 SC7 WP Aristotelis Tzafalias Trust and Security Unit DG Communications.
Eric Peirano, Ph.D., TECHNOFI, COO
Eric Peirano, Ph.D., TECHNOFI, COO
Crisis management related research at
Agenda Control systems defined
RESEARCH, EDUCATION, AND TRAINING FOR THE SMART GRID
David Sayago EU Research Funding Team Valorisation Centre.
An Urgent National Imperative
Trust and Security Unit
Opportunities in Horizon2020 in Cybersecurity call for proposals
Cybersecurity ATD technical
Presented by Prof. dr. Nermin Suljanović Elektroinštitut Milan Vidmar
Group Meeting Ming Hong Tsai Date :
Wenyu Ren, Timothy Yardley, Klara Nahrstedt
Cyber Security in a Risk Management Framework
Presentation transcript:

RIUNIONE ESPLORATIVA PER UNA CANDIDATURA ITALIANA ALLINIZIATIVA EUROPEA ERN-CIP CYBERSECURITY ENEA – Lungotevere Thaon di Revel, 76 – ROMA Esperienza maturata in ERSE G. Dondossola ERSE – Dpt. Sviluppo Sistema Elettrico 9 Luglio, 2009

2 Background Periodo: 20 anni Settore: elettrico Aree di attività 1.Specifiche formali, Validazione e Verifica Sistemi Real Time 2.Sistemi Distribuiti, Reti di comunicazione, Architetture ICT Automazione Stazione e Sistemi SCADA 3.Performance, Dependability, Cyber Security CIIP 4.CIIP - Risk Assessment 5.CIIP - Testbeds

Critical Information Infrastructure Protection – CIIP Infrastructures owned/operated/used by Power Utilities Fundamental to national and international SecurityEconomy Quality of life

PCS – ResTest Lab

PCS - ResTest

8 CRUTIAL is a RTD Project in the area of Critical Information Infrastructure Protection launched by the European Union under the Information Society Technologies priority of the Sixth Framework Programme. The project addresses new networked ICT systems for the management of the electric power grid, in which artefacts controlling the physical process of electricity transportation need to be connected with information infrastructures, through corporate networks (intranets), which are in turn connected to the Internet. CESI RICERCA electricity grid communication network Critical Utility InfrastructurAL Resilience FP IST modelling interdependent infrastructures resilient to both accidental failures and malicious attacks CRUTIALs innovative approach resides in attempting at casting them into new architectural patterns Objectives Investigation of models and architectures that cope with openness, heterogeneity and evolvability endured by electrical utilities infrastructures Analysis of critical scenarios which ICT faults provoke serious impact on the controlled electric power infrastructures Evaluation of distributed architectures enabling dependable control and management of the power grid Work Packages WP1 Identification and description of Control System Scenarios WP2 Interdependencies modelling WP3 Testbed development WP4 Architectural solutions WP5 Analysis and evaluation of Control System Scenarios WP6 Dissemination WP7 Management

Standards NERC, IEC, IEEE, NIST, ISA IEC TC 57 WG 15 – Network Security, Protocol Security ISA WG4 TG5 – Security Metrics Cigrè – WG D2.22 – Information Security 1.Å. Torkilseng, S. Duckworth: "Security Frameworks for Electric Power Utilities - Some Practical Guidelines when developing frameworks including SCADA/Control System Security Domains", Electra, No. 241, December G. Dondossola: Risk Assessment of Information and Communication Systems - Analysis of some practices and methods in the Electric Power Industry, CIGRÉ Electra, No. 239, August M. Tritschler, G. Dondossola: Information Security Risk Assessment of Operational IT Systems at Electric Power Utilities, Paper D2-01 D03, Cigré D2 Colloquium, October 21-22, 2009, Fukuoka, Japan. 4.A. Bartels, L. Piètre-Cambacédès, S, Duckworth: Security Technologies Guideline – Practical Guidance for Deploying Security Technology within Electric Utility Data Networks, Electra, No. 244, June L. Piètre-Cambacédès, T. Kropp, J. Weiss, R Pellizzonni: Cybersecu­rity standards for the electric power industry – a survival kit – Paper D2-217, CIGRÉ Paris Session 2008, France 6.G. Ericsson, A. Bartels, D. Dondossola, Å. Torkilseng: Treatment of information security for electric power utilities – progress report from Cigré WG D2.22 Paper D2-213, Cigré Paris 2008 Session, France

11 Cyber Risk Assessment Tools

Exploitation at industrial level –To support the sector industry – decision processes and technological development - with security know-how –To set-up and experiment realistic attack scenarios –To mitigate the vulnerabilities of the standard application protocols (e.g. IEC , IEC , IEC 61850) –To facilitate the development of cyber security standards, guidelines and practices for industrial usage (e.g. NERC,, IEEE, NIST, ISA, IEC under development by the WG15-TC57) –To assess the capability of secure and redundant architectures to tolerate the threat hypotheses –To develop advanced technological solutions and tools –To offer a cyber security testing infrastructure for advanced SCADA, automation and control systems –To support risk assessment with statistics from experiments –To support on-line security analysis with monitoring, detection and recovery modules at research level –To feed in model based evaluations with experimental measures

13 Sicurezza Elettrica Piani di difesa flessibili/integrati/ multioperatore Esercizio Sistema Elettrico Risk Management Linee di difesa stratificate controlli stratificati Protezione ICT Sicurezza Infrastruttura Elettrica