UCAIug: Smart Grid Security Face-To-Face Meeting – July AEP  UtiliSec Working Group  AMI-SEC Task Force UtiliSec WG Chair: Darren Reece Highfill.

Slides:



Advertisements
Similar presentations
Impact of Smart Grid, ICT on Environment and Climate Change David Su Advanced Network Technologies National Institute of Standards and Technology ITU Symposium.
Advertisements

Knoxville, TN Oct. 19, 2009 AMI-Enterprise Systems Requirements Specification Overview.
SG Security Working Group Face-to-Face Meeting – July Vancouver, BC  Usability Analysis Task Force  Cybersec-Interop Task Force  Embedded Systems.
Introduction Build and impact metric data provided by the SGIG recipients convey the type and extent of technology deployment, as well as its effect on.
Course: e-Governance Project Lifecycle Day 1
UCAIug HAN SRS v2.0 Summary August 12, Scope of HAN SRS in the NIST conceptual model.
May 2010 Slide 1 SG Communications Boot Camp Matt Gillmore 03/07/11.
Vendor Briefing May 26, 2006 AMI Overview & Communications TCM.
September 30, 2011 OASIS Open Smart Grid Reference Model: Standards Landscape Analysis.
UCAIug: AMI Security Update – September 2008  AMI-SEC Task Force  AMI Security Acceleration Project (ASAP) AMI-SEC Task Force Chair: Darren Reece Highfill,
The Voice of the Asset Owner ICSJWG – April Dallas  UCAIug  SG Security  ASAP-SG SG Security WG Chair: Darren Reece Highfill
Slide 1 UCAIug OpenSG OpenADE Automated Data Exchange Requirements NAESB ESPI Energy Services Provider Interface Standard Specification Overview November.
Cyber Security Working Group March 17, Smart Grid Cyber Security Strategy Establishment of a Cyber Security Coordination Task Group (CSCTG) Established.
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
Advanced Metering Infrastructure AMI Security Roadmap April 13, 2007.
UCAIug: Smart Grid Security OpenSG Face-to-Face (January 2010 – San Francisco, CA)  SG Security Working Group  AMI-SEC Task Force SG Security WG Chair:
Slide 1 UCAIug OpenSG OpenADE Automated Data Exchange Requirements NAESB ESPI Energy Services Provider Interface Standard Specification Overview.
# 1 Information Exchange Standards Development Collaboration for AMI and HAN For further information, contact: Wayne Longcore
EPRI Smart Grid Demonstration and CIM Standards Development
1 ISO/RTO Council Wholesale Demand Response Projects & OpenADR David Forfia.
SMART GRID: Privacy Awareness and Training – for PUCs/PSCs A Starting Point December 2011 SGIP-CSWG Privacy Group 1 DRAFT.
Jeju, 13 – 16 May 2013Standards for Shared ICT HIS – Smart Grid Karen Bartleson, President, IEEE Standards Association Document No: GSC17-PLEN-72 Source:
Enterprise Architecture
SMART GRID INTEROPERABILITY PANEL WINTER 2012 FACE-TO-FACE IRVING, TEXAS  DEC. 3-6, 2012 TECHNOLOGY ADOPTION AND THE VALUE OF INDUSTRY COLLABORATION William.
1 Connectivity Week 2010 How Can Standards Be Regulated? Thursday May 27 10:30AM-Noon Zahra Makoui.
Development Principles PHIN advances the use of standard vocabularies by working with Standards Development Organizations to ensure that public health.
Smart Grid Interoperability Standards George W. Arnold, Eng.Sc.D. National Coordinator for Smart Grid Interoperability National Institute of Standards.
Project Description: – Utility-driven, public-private collaborative project to develop system-level security requirements for smart grid technology Needs.
B usiness T echnology S olutions AMI – Advanced Metering Infrastructure Consumers Energy Mark Ortiz March 9, 2011.
AMI-SEC Task Force October 23 rd Face-To-Face Meeting – Knoxville, TN  Roadmap, ASAP Deliverables, & Outreach Darren Reece Highfill, CISSP EnerNex Corporation.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
McLean VA, May 3, 2010 SG Systems Systems Requirements Specification Approach Overview.
FirstEnergy / Jersey Central Power & Light Integrated Distributed Energy Resources (IDER) Joseph Waligorski FirstEnergy Grid-InterOp 2009 Denver, CO November.
Security Challenges for Customer Domain in the Smart Grid
Frankfurt (Germany), 6-9 June 2011 IT COMPLIANCE IN SMART GRIDS Martin Schaefer – Sweden – Session 6 – 0210.
Darren Highfill Chairing on behalf of Erich W. Gunther UtilityAMI Chairman/Facilitator Chairman/CTO – EnerNex Corporation Utility Industry.
Doc.: IEEE /0047r1 Submission SGIP Liaison Report to IEEE Following the SGIP (2.0) Inaugural Conference Nov 5-7, 2013 Date:
# 1 AMI Enterprise Task Force of the Utility AMI Working Group SRS Team Status Report (Palo Alto, Jan. 09) Joe Zhou.
Open Smart Grid Subcommittee Organization and Overview Erich W. Gunther UCAIug Board Member.
OpenSG - SG Communications May 2010 Slide 1 SG Communications DC Meeting AM2 Session Tuesday 5/4/2010 Network Interoperability.
Sandra C Security Advisor Energy Dan B Security Advisor Water
OpenSG Conformity IPRM Overview July 20, ITCA goals under the IPRM at a high level and in outline form these include: Organize the Test and Certification.
1 Smart Grid Cyber Security Annabelle Lee Senior Cyber Security Strategist Computer Security Division National Institute of Standards and Technology June.
OpenSG Status UCAIug Members Meeting Chris Knudsen – Chair Gary Stuebing – Vice-Chair November 9 th, 2009.
Smart Grid Interoperability Panel & ISO / RTO Council Smart Grid Projects David Forfia SGIP Governing Board Member – Stakeholder Category 21 ISO/RTO Sponsor.
Common Information Model - enabling data exchanges and interoperability in the electric utility industry P&E Magazine, May 2015 Power & Energy Magazine.
AMI Enterprise Developing Interoperability for Distribution Systems January 2009 Terry Mohn, Technology Strategist SDG&E Vice Chairman, GridWise Alliance.
Interoperability Standards and Next Generation Interconnectivity Pankaj Batra Chief (Engineering) CERC.
IEEE Activities in Smart Grid & Green Technologies Dr. Bilel Jamoussi South Africa 26 October 2009.
IEC TC57 Smart Grid Activities Scott Neumann USNC TA IEC TC57 November 6, 2009.
National Cybersecurity Center of Excellence Increasing the deployment and use of standards-based security technologies Mid-Atlantic Federal Lab Consortium.
Boot Camp - Conformity July 19, 2010 Detroit, USA.
1 1 Cybersecurity : Optimal Approach for PSAPs FCC Task Force on Optimal PSAP Architecture Working Group 1 Final Report December 10 th, 2015.
Erich W. Gunther UtilityAMI Chairman/Facilitator Chairman/CTO – EnerNex Corporation Jerry Melcher Onsite facilitator for this meeting.
Overview AMI-Enterprise For further information, contact: Wayne Longcore Chair of AMI-Enterprise Task Force, Board Of Directors.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
ISA99 - Industrial Automation and Controls Systems Security
Discussion - HITSC / HITPC Joint Meeting Transport & Security Standards Workgroup October 22, 2014.
June California Investor Owned Utilities (IOU) HAN vision statement development 15 June 2007.
“SG-Systems” ( Smart Grid – Operational Applications Integration ) Charter & Status Greg Robinson, Co-Chair, SG-Systems Brent Hodges, Chair, SG-Systems.
Sicherheitsaspekte beim Betrieb von IT-Systemen Christian Leichtfried, BDE Smart Energy IBM Austria December 2011.
May 2010 Slide 1 SG Communications Boot Camp Matt Gillmore 11/1/2010.
Enterprise Architectures Course Code : CPIS-352 King Abdul Aziz University, Jeddah Saudi Arabia.
AMI Enterprise Task Force of the Utility AMI Working Group
CIM Modeling for E&U - (Short Version)
Smart Grid Interoperability Standards
Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Smart Grid Overview] Date Submitted: [13.
IEC TC57 Smart Grid Activities
AMI Security Roadmap April 13, 2007.
Group Meeting Ming Hong Tsai Date :
Presentation transcript:

UCAIug: Smart Grid Security Face-To-Face Meeting – July AEP  UtiliSec Working Group  AMI-SEC Task Force UtiliSec WG Chair: Darren Reece Highfill

AMI Security Ecosystem

Customer The Grid AMI System System Operator Meter Data Manager Energy Trader ISO Field Tech Dispatcher Customer Rep Vendors & Third Parties AMI Security Ecosystem

Field Elements Issues Limited or no control over physical access Wide range of logical access control Resource constrained devices Large quantity of devices Requirements Device Identity Data Integrity Customer Privacy Considerations Intelligence? (How much?) Filtering?

Field Elements Network Management Ad-hoc Structure or Predefined (Prescriptive)? Integrity, Availability of Provisioning Mechanism Authentication Mechanism End-to-End or Step-by-Step? Bi-Directional (“Two-Way”) Pre-Shared or Public Key? Customer Devices Countermeasures Role-Based Access Control Least Privilege, Need-To-Know Unpredictable Credentials Intrusion Detection Tamper Detection

? Data Concentrator At a substation? Somewhere in the field? Who owns the property? Is there a fence? Does it use wireless technology? What kind of access controls are implemented?

? Data Concentrator How many homes are served? What is peak load? More than 300MW (~100,000 homes?)  NERC CIP? How does it authenticate / get authorized to the Data Center Aggregator?

Operations Center System Management Console Data Availability, Integrity Filtered View – No Financial Data Time Sensitive (Freshness) Field Communications Data Integrity Temporal Privilege Strict Procedures Detailed Accounting Meter Data Management System Data Integrity, Confidentiality Multiple Interfaces, Heterogeneous Constraints

Customer Representative Data Confidentiality, Integrity Filtered View – Billing Related Revenue Data Integrity, Confidentiality Non-Repudiation Public Interface Website Data Confidentiality Public (General Info) and Private (Customer) Views Consumer Portal Best Practices (e.g.: Financial Services)

Demand-Response Energy Trader Regulated Relationship Availability & Control Data Confidentiality, Integrity Negotiated “Contract” Similarities to Dealing with an External Entity Vendors & Third Parties External Entities Data Confidentiality Contractual Agreement Least Privilege, Need-To-Know

Smart Grid Landscape

UtiliSec Working Group Motivation:Motivation: –Part of a utility-led, electric power industry community effort (UCAIug) to define a common set of requirements for the procurement of new technologies Status:Status: –Suite of 4 deliverables completed in 2008 AMI Security Risk AssessmentAMI Security Risk Assessment AMI System Security Requirements (incorporates Architectural Description)AMI System Security Requirements (incorporates Architectural Description) AMI Security Component CatalogAMI Security Component Catalog AMI Security Implementation GuideAMI Security Implementation Guide –AMI System Security Requirements document ratified December, 2008 (“1.0”) Current Participation: Current Participation: –200+ Subscribers to Listserv across 8 countries and 4 continents –More than a dozen major North American utilities actively engaged –Broad mix of utilities, vendors, government, and academia

NIST CSCTG NIST chartered in EISA 2007 with development of Interoperability Framework for the smart gridNIST chartered in EISA 2007 with development of Interoperability Framework for the smart grid –Formed a series of Domain Expert Working Groups (DEWGs) to engage industry –2 face-to-face meetings in DC in past couple months NIST Cyber Security Coordination Task Group (CSCTG)NIST Cyber Security Coordination Task Group (CSCTG) –Cyber security focus for Interoperability Framework development

Issues Addressed: NIST CSCTG Led by Annabelle Lee, NISTLed by Annabelle Lee, NIST Focusing on high-level requirements for securing the smart grid across all stakeholdersFocusing on high-level requirements for securing the smart grid across all stakeholders –Utilities, Grid Operators, Regulators, Consumers, Third Parties Two active sub-groupsTwo active sub-groups –“Bottom-up” –Vulnerability Analysis

Issues Addressed: UtiliSec Chartered with developingChartered with developing –Detailed requirements –Best practices guidance for utilities procuring, implementing, and deploying smart grid technology Technology-specific, but vendor-agnostic guidanceTechnology-specific, but vendor-agnostic guidance Feed and accelerate SDO work (IEC, IEEE, etc.)Feed and accelerate SDO work (IEC, IEEE, etc.)

UCAIugUCAIug  Open Smart Grid (OpenSG) Subcommittee  UtiliSec Working Group Encompasses the AMI-SEC Task ForceEncompasses the AMI-SEC Task Force –(previously under UtilityAMI) Following on and expanding work done by AMI-SECFollowing on and expanding work done by AMI-SEC –AMI System Security Requirements (“AMI-SEC SSR”) published as “1.0” in December 2008 UtiliSec

Working Group Responsibilities Provide a charterProvide a charter Submit a project schedule and a monthly status reportSubmit a project schedule and a monthly status report Schedule meetings (in person or electronic)Schedule meetings (in person or electronic) Structure sub-working groups or ad-hoc groups as necessaryStructure sub-working groups or ad-hoc groups as necessary Seek OpenSG approval forSeek OpenSG approval for –Formal Document Release –Charter approval –Approval of task force and lower level chairs Working Group ConstitutionWorking Group Constitution

Organization & Communications Information exchangeInformation exchange –Intra-organizational Issue hand-off formIssue hand-off form Cross-representationCross-representation –Inter-organizational ParticipationParticipation OutreachOutreach Charter (1 slide PPT)Charter (1 slide PPT)

UtiliSec Charter Chartered with developing detailed security and assurance requirements and security best practices guidance for organizations throughout the lifecycle of smart grid technologyChartered with developing detailed security and assurance requirements and security best practices guidance for organizations throughout the lifecycle of smart grid technology Technology-specific, but vendor-agnostic guidanceTechnology-specific, but vendor-agnostic guidance Feed and accelerate SDO work (IEC, IEEE, etc.)Feed and accelerate SDO work (IEC, IEEE, etc.)

AMI-SEC Task Force AMI-SEC is concerned with securing AMI system elements.AMI-SEC is concerned with securing AMI system elements. –Contextual Definition: “…those measures that protect and defend AMI information and systems by assuring their ability to operate and perform in their intended manner in the face of malicious actions.” PurposePurpose –Produce technical specification Used by utilities to assess and procureUsed by utilities to assess and procure Used by OpenAMI – part of AMI/DR Reference DesignUsed by OpenAMI – part of AMI/DR Reference Design –Determine baseline level of detail Prescriptive in naturePrescriptive in nature Compliant products will have known functionality and robustnessCompliant products will have known functionality and robustness

Implementation Guide

Leveraging ASAP into UtiliSec

Project Description:Project Description: –Utility-driven, public-private collaborative project to develop system-level security requirements for smart grid technology Needs Addressed:Needs Addressed: –Utilities: specification in RFP –Vendors: reference in build process –Government: assurance of infrastructure security –Commissions: protection of public interests Approach:Approach: –Architectural team  produce material –Usability Analysis team  assess effectiveness –NIST, UtiliSec  review, approve Deliverables:Deliverables: –Strategy & Guiding Principles white paper –Security Profile Blueprint –3 Security Profiles: AMI, ADE, Communications –Usability Analysis ASAP-SG: Summary Schedule: Jun09 – Dec09 Budget: $3M ( $1.5M Utilities + $1.5M DOE) Performers: Utilities, EnerNex, Inguardians, SEI, ORNL Partners: DOE Release Path: NIST, UCAIug Contacts: Bobby Brown Darren Highfill Schedule: Jun09 – Dec09 Budget: $3M ( $1.5M Utilities + $1.5M DOE) Performers: Utilities, EnerNex, Inguardians, SEI, ORNL Partners: DOE Release Path: NIST, UCAIug Contacts: Bobby Brown Darren Highfill

Public-private collaborative projectPublic-private collaborative project –DOE, NIST, & utilities Purposes:Purposes: –Support the activities of the NIST CSCTG –Accelerate the work of the UtiliSec WG Participants:Participants: –Utilities, regulators, vendors, consultants, national laboratories, & academia ASAP-SG

Technical Coordination with NIST

Smart Grid Security Profile Blueprint Understandable and user-friendly framework, set of tools, and methodologyUnderstandable and user-friendly framework, set of tools, and methodology Derive and apply smart grid domain-specific security profilesDerive and apply smart grid domain-specific security profiles Delineates:Delineates: –Repeatable security risk assessment methodology –High-level Smart Grid policy set –Smart Grid policy to a domain requirement mapping process –Application security profile development process

Security Profiles Prescriptive, actionable guidance for how to build-in and implement security for smart grid functionalityPrescriptive, actionable guidance for how to build-in and implement security for smart grid functionality Tailored to a set of specific smart grid functions, such asTailored to a set of specific smart grid functions, such as –Advanced Metering Infrastructure –Automated Data Exchange –Network Topology –Outage Management –Etc.

Questions? UtiliSec Collaboration Site