Ad Hoc Smart Grid Executive Committee. February 10, 2011 New Orleans, LA

Size: px
Start display at page:

Download "Ad Hoc Smart Grid Executive Committee. February 10, 2011 New Orleans, LA"

Transcription

1 Ad Hoc Smart Grid Executive Committee February 10, 2011 New Orleans, LA

2 Agenda Time Topic and Location Lead 3:00 3:10p Welcome & Introductions George Bjelovuk, AEP 3:10 3:40p Regulatory Trends for Cyber Security Annabelle Lee, EPRI 3:40 4:15p EPRI Security & Privacy R&D for :15 4:45p Regulatory Trends for Interoperability Standards Galen Rasche, EPRI Erfan Ibrahim, EPRI Annabelle Lee, EPRI 4:45 5:00p Wrap-up and Adjourn George Bjelovuk, AEP 2

3 Regulatory Trends on Cyber Security Annabelle Lee Technical Executive - Cyber Security 3

4 Current Status... Mandatory cyber security standards for the federal government are developed by the National Institute of Standards and Technology (NIST) The Department of Homeland Security (DHS) in coordination with other federal sector specific agencies (SSAs), has developed voluntary guidance The base document is the National Infrastructure Protection Plan (NIPP) Each SSA, in collaboration with the appropriate Sector Coordinating Council (SCC), developed a Sector Specific Plan Each plan is updated annually The Department of Energy (DOE) is the SSA for the energy sector, including the electric sector Energy, IT, communications, chemical, transportation, etc Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 24

5 Current Status... NERC developed the Critical Infrastructure Protection (CIPs) for the bulk power system The Smart Grid Interoperability Panel (SGIP) Cyber Security Working Group (CSWG) published National Institute of Standards and Technology Interagency Report (NISTIR) 7628, Guidelines for Smart Grid Cyber Security The document is guidance and voluntary Provides cyber security requirements at a high level Has been referenced by three states and adopted by China and Sweden DOE included security requirements in the American Recovery and Reinvestment Act (ARRA) of 2009 Grant winners are required to develop a system security plan 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 25

6 Current Trends... The NERC CIPs are being revised The mandatory implementation date for the NERC CIPs , version 3 was October 1, 2010 CIP Cyber Security - Critical Cyber Asset Identification recently updated to Version 4 Initial assessment is that the new definition will not significantly increase the number of critical cyber assets FERC and NIST are assessing the results of the FERC technical conference Some state PUCs were watching FERC for guidance H.R. 174: Homeland Security Cyber and Physical Infrastructure Protection Act of 2011 Includes prioritized critical infrastructures 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 26

7 Current Trends... GAO Report GAO : Electricity Grid Modernization Positive comments on the tasks that NIST performed on the Smart Grid Outstanding issues: NIST did not address cyber-physical attacks FERC does not have enforcement authority in the Energy Independence and Security Act of 2007 Fragmentation of the regulatory environment complicates smart grid interoperability and cyber security Report includes recommendations DOE IG Report - IG-0846, Jan 26, 2011, Federal Energy Regulatory Commission's Monitoring of Power Grid Cyber Security Criticisms of the NERC CIPs With new Congress - not clear what the priorities and trends will be 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 27

8 Questions? 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 58

9 Electric Sector Security & Privacy Plans for 2011 Galen Rasche Technical Executive Erfan Ibrahim Technical Executive Ad-Hoc Smart Grid Executive Committee 2011-Feb-10

10 Contents PDU Cyber Security R&D Portfolio National Electric Sector Cyber Security Organization EPRI Security and Privacy Initiative 10

11 EPRI s Cyber Security Focus for

12 EPRI 2011 Cyber Security R&D Portfolio 12

13 EPRI Cyber Security Resources Staffing Three Technical Executives One Senior Project Manager Three Project Engineers Lab capabilities Substation lab in Knoxville Interconnects between Charlotte, Knoxville, and Lenox Advisory structure Ad hoc Security and Privacy Executive Committee 13

14 EPRI Cyber Security Projects and Programs PDU Base Program For 2011: NERC CIP and DHS ICS JWG Coordination and Reporting Lemnos Testing for Security Configuration Profiles DNP4 Security Interoperability Testing Smart Energy Profile 2.0 Security Testing Procedures & Penetration Testing NESCO: Focal point for utilities, federal agencies, regulators, and researchers Organize the collection, analysis, and dissemination of infrastructure vulnerabilities and threats Cyber Security standards and requirements evaluation Research Projects: Secure Smart Grid Communications Cryptographic Key Management Tools and Templates For Measuring Security Posture Best Practices for NERC CIP Compliance 14

15 National Electric Sector Cyber Security Organization (NESCO) Vision: Provide a focal point for bringing together utilities, federal agencies, regulators, and researchers to address the electric sector security threats Objectives: Focus cyber security R&D priorities Identify and disseminate best practices Organize the collection, analysis, and dissemination of infrastructure vulnerabilities and threats 15

16 NESCO Project Structure Cyber Incident Data Center (EnergySec): Identify / receive threat information Forensics Vulnerability analysis Categorize threats Disseminate threat information to asset owners and operators R&D Industry Advisory Board: Provide technical oversight for the project for direction setting and content creation Facilitate outreach in the industry for greater participation and implementation Populated by industry groups, federal agencies, regulators R&D Team (EPRI and EnergySec): Review NIST, NERC and other cyber security requirements and results Assess existing power system and cyber security standards to meet the security requirements of the power system Develop risk mitigation strategies, best practices and metrics Test security technologies in labs and pilot projects 16

17 EPRI Led Team Supporting DOE NESCO National/ Commercial Research Labs Oak Ridge National Lab Sandia National Lab Idaho National Lab National Renewable Energy Laboratory Palo Alto Research Center SRI Telcordia Academia University of Houston Mladen Kezunovic (Texas A&M University) UCLA UC Berkeley University of Minnesota Smart Grid Consortium Subject-Matter Experts N-Dimension Inguardians Arc Technical EnerNex Xanthus Consulting International 17

18 NESCO Work Flow 18

19 EPRI Members Call to Action for NESCO Communicate critical security and privacy issues to EPRI to facilitate RD&D project identification (e.g., relating to NERC Compliance, SGIG and SGDP Cyber Security Assessment Plan) Volunteer cyber security technical staff to participate in NESCO Working Groups Volunteer senior cyber security experts to sit on NESCO advisory board 19

20 EPRI Cyber Security and Privacy Initiative Cross-sector initiative (Power Delivery, Generation, and Nuclear) Leverage lessons learned and address common concerns Address gaps in current industry security and privacy R&D work Forum for designing and implementing collaborative R&D projects to meet long-term security needs of the electric sector Ad-Hoc Electric Sector Security and Privacy Executive Committee Provides strategic advice and guidance on EPRI security and privacy R&D activities Contributions from IOUs, co-ops, ISOs, and municipals Involvement at the CIO-level 20

21 Near Term Goals of EPRI Cyber Security Research Initiative Develop the organizational structure and populate the Ad- Hoc Security and Privacy Executive Committee Organize and populate working groups to perform the RD&D projects 1Q11 2Q11 3Q11 4Q11 Create focused task forces for areas of interest Identify 1 st set of high priority RD&D projects 21

22 Security and Privacy Initiative Research Areas 22

23 Questions? Galen Rasche Erfan Ibrahim 23

24 FERC Smart Grid Technical Conference - January 2011 Annabelle Lee Technical Executive Cyber Security 24

25 Background... Energy Independence and Security Act (EISA) of 2007, Title XIII, Section 1305 National Institute of Standards and Technology (NIST) to coordinate the development of a framework That includes protocols and modern standards for information management To achieve interoperability of Smart Grid devices and systems At any time after NIST has reached sufficient consensus in FERC's judgment FERC shall institute a rule making proceeding to adopt such standards and protocols as may be necessary to insure Smart Grid functionality and interoperability in Interstate transmission of electric power and Regional and wholesale electricity markets. New roles for both FERC and NIST Significant pressure for NIST to move forward on the standards 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 25 2

26 FERC Technical Conference Held January 31, 2011 at FERC 571&CalType=%20&CalendarID=116&Date=01/31/2011&Vie w=listview All five commissioners attended Presentations by George Arnold, National Coordinator for Smart Grid Interoperability Two panels NIST process used for reviewing and selecting the five families of standards Smart Grid interoperability standards development and identification process going forward 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 26 2

27 FERC Technical Conference Initial families of standards posted by NIST IEC substation automation IEC common Information model IEC common information model IEC TASE 2/ICCP IEC security All 13 panel members, in response to a question from Chairman Wellinghoff, stated there was not sufficient consensus for adoption 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 27 2

28 Issues Raised at the FERC Technical Conference What is the definition of "adoption"? Adoption involves significant policy issues What is the definition of consensus? Applicable to the Smart Grid? Technical content reviewed and accepted by experts? Applicable to interoperability? 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 28 2

29 Issues Raised at the FERC Technical Conference Standards are a snapshot in time How do you allow for innovation? Not sufficient discussion on the context for using the standard Need further review on functionality and interoperability Significant technical cyber security issues Limitations to access of the standards 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 29 2

30 What's Next?... FERC is accepting comments on the presentations and the questions posted Comments due March 2, 2011 Comments on comments due March 16, 2011 May be supplemental questions posted... The path forward is not clear Both NIST and FERC are assessing the results of the technical conference Many state PUCs were waiting for FERC to perform the rule making 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 30 2

31 Questions? 2011 Electric Power Power Research Research Institute, Institute, Inc. All rights Inc. All reserved. rights reserved. 31 5

32 EPRI s Role Going Forward EPRI will very quickly develop a series of white papers on the adoption of standards by the electric utility industry The first white paper will present an adoption roadmap for standards in the electric utility industry The second and third white papers will provide mappings of CIM and to the adoption roadmap The fourth white paper will be a case study of a utility who has adopted one of the five NIST standard. 32

33 EPRI s Role Going Forward Wayne Longcore (Consumers Energy), Phil Slack (FPL) and Chris Knudsen (PG&E) have already volunteered to help develop the white papers George Arnold likes what is being proposed George Arnold has asked that EPRI organize a technical workshop to discuss the adoption of standards by the electric utility industry. 33

Electric Sector Security & Privacy Plans for 2011

Electric Sector Security & Privacy Plans for 2011 Electric Sector Security & Privacy Plans for 2011 Galen Rasche Technical Executive Erfan Ibrahim Technical Executive Ad-Hoc Smart Grid Executive Committee 2011-Feb-10 Contents PDU Cyber Security R&D Portfolio

More information

Smart Grid Standards and Certification

Smart Grid Standards and Certification Smart Grid Standards and Certification June 27, 2012 Annabelle Lee Technical Executive Cyber Security alee@epri.com Current Environment 2 Current Grid Environment Legacy SCADA systems Limited cyber security

More information

Managing SCADA Security. NISTIR 7628 and the NIST/SGIP CSWG. Xanthus. May 25, Frances Cleveland

Managing SCADA Security. NISTIR 7628 and the NIST/SGIP CSWG. Xanthus. May 25, Frances Cleveland Managing SCADA Security NISTIR 7628 and the NIST/SGIP CSWG May 25, 2011 Frances Cleveland fcleve@xanthus-consulting.com Xanthus Consulting International Topics NISTIR 7628 NIST/SGIP CSWG and its Subgroups

More information

136 FERC 61,039 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. [Docket No. RM ] Smart Grid Interoperability Standards

136 FERC 61,039 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. [Docket No. RM ] Smart Grid Interoperability Standards 136 FERC 61,039 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION [Docket No. RM11-2-000] Smart Grid Interoperability Standards (Issued July 19, 2011) AGENCY: Federal Energy Regulatory Commission.

More information

Interoperability and Standardization: The NIST Smart Grid Framework

Interoperability and Standardization: The NIST Smart Grid Framework Interoperability and Standardization: The NIST Smart Grid Framework GridWeek Asia George W. Arnold, Eng.Sc.D. National Coordinator for Smart Grid Interoperability National Institute of Standards and Technology

More information

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013 Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013 Purpose and Scope The purpose of the Electricity Sub-Sector Coordinating Council (ESCC) is to facilitate and support

More information

NIST Smart Grid Activities

NIST Smart Grid Activities NIST Smart Grid Activities George W. Arnold, Eng.Sc.D. National Coordinator for Smart Grid Interoperability National Institute of Standards and Technology ANSI/ESO Public Conference October 12, 2011 Example:

More information

EPRI Research Overview IT/Security Focus. Power Delivery & Energy Utilization Sector From Generator Bus Bar to End Use

EPRI Research Overview IT/Security Focus. Power Delivery & Energy Utilization Sector From Generator Bus Bar to End Use EPRI Research Overview IT/Security Focus November 29, 2012 Mark McGranaghan VP, Power Delivery and Utilization Power Delivery & Energy Utilization Sector From Generator Bus Bar to End Use Transmission

More information

Physical Security Reliability Standard Implementation

Physical Security Reliability Standard Implementation Physical Security Reliability Standard Implementation Attachment 4b Action Information Background On March 7, 2014, the Commission issued an order directing NERC to submit for approval, within 90 days,

More information

Cybersecurity for the Electric Grid

Cybersecurity for the Electric Grid Cybersecurity for the Electric Grid Electric System Regulation, CIP and the Evolution of Transition to a Secure State A presentation for the National Association of Regulatory Utility Commissioners March

More information

Grid Security & NERC

Grid Security & NERC Grid Security & NERC Janet Sena, Senior Vice President, Policy and External Affairs Southern States Energy Board 2017 Associate Members Winter Meeting February 27, 2017 Recent NERC History Energy Policy

More information

NIST Smart Grid Interoperability Framework

NIST Smart Grid Interoperability Framework NIST Smart Grid Interoperability Framework Jerry FitzPatrick National Institute of Standards and Technology (NIST) Gaithersburg, MD 20899 fitzpa@nist.gov 2010 IEEE Power & Energy Society General Meeting

More information

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com Cybersecurity Presidential Policy Directive Frequently Asked Questions kpmg.com Introduction On February 12, 2013, the White House released the official version of the Presidential Policy Directive regarding

More information

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016 Grid Security & NERC Council of State Governments The Future of American Electricity Policy Academy Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016 1965 Northeast blackout

More information

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 I. Vision A highly reliable and secure bulk power system in the Electric Reliability Council of Texas

More information

Smart Grid Cyber Security Strategy and Requirements

Smart Grid Cyber Security Strategy and Requirements DRAFT NISTIR 7628 Smart Grid Cyber Security Strategy and Requirements The Smart Grid Interoperability Panel Cyber Security Working Group February 2010 DRAFT NISTIR 7628 Smart Grid Cyber Security Strategy

More information

Statement for the Record

Statement for the Record Statement for the Record of Seán P. McGurk Director, Control Systems Security Program National Cyber Security Division National Protection and Programs Directorate Department of Homeland Security Before

More information

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1,

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1, EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1, 2008 www.morganlewis.com Overview Reliability Standards Enforcement Framework Critical Infrastructure Protection (CIP)

More information

Security Metrics. February 25, Annabelle Lee Senior Technical Executive

Security Metrics. February 25, Annabelle Lee Senior Technical Executive Security Metrics February 25, 2015 Annabelle Lee Senior Technical Executive alee@epri.com Cybersecurity Capability Maturity Model (C2M2) Overview Expansion Project and Comparative Analysis Framework Implementation

More information

UNITED STATES OF AMERICA BEFORE THE U.S. DEPARTMENT OF COMMERCE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY

UNITED STATES OF AMERICA BEFORE THE U.S. DEPARTMENT OF COMMERCE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY UNITED STATES OF AMERICA BEFORE THE U.S. DEPARTMENT OF COMMERCE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY COMMENTS OF THE NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION ON NIST FRAMEWORK AND ROADMAP

More information

Why you should adopt the NIST Cybersecurity Framework

Why you should adopt the NIST Cybersecurity Framework Why you should adopt the NIST Cybersecurity Framework It s important to note that the Framework casts the discussion of cybersecurity in the vocabulary of risk management Stating it in terms Executive

More information

Secure Remote Substation Access Interest Group Kickoff Meeting

Secure Remote Substation Access Interest Group Kickoff Meeting Secure Remote Substation Access Interest Group Kickoff Meeting June 5, 2013 Scott Sternfeld, Project Manager Smart Grid Substation & Cyber Security Research Labs ssternfeld@epri.com Utility co-chair: John

More information

Recent Issues in Electric Grid Physical Security

Recent Issues in Electric Grid Physical Security Recent Issues in Electric Grid Physical Security Paul W. Parfomak, Ph.D. Congressional Research Service pparfomak@crs.loc.gov Carnegie Mellon University Electricity Industry Center October 8, 2014 What

More information

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management Remarks of Marcus Sachs, Senior Vice President and the Chief Security Officer North American Electric Reliability

More information

Time Synchronization and Standards for the Smart Grid

Time Synchronization and Standards for the Smart Grid Time Synchronization and Standards for the Smart Grid Tom Nelson National Institute of Standards and Technology 2011 NIST - ATIS - Telcordia Workshop on Synchronization in Telecommunication Systems (WSTS

More information

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Facts expressed in this presentation are Facts Opinions express in this presentation are solely my own The voices I

More information

Measurement Challenges and Opportunities for Developing Smart Grid Testbeds

Measurement Challenges and Opportunities for Developing Smart Grid Testbeds Measurement Challenges and Opportunities for Developing Smart Grid Testbeds 10th Carnegie Mellon Conference on the Electricity Industry April 1, 2015 Paul Boynton boynton@nist.gov Testbed Manager Smart

More information

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Facts expressed in this presentation are Facts Opinions express in this presentation are solely my own The voices I

More information

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith OPUC Workshop March 13, 2015 Cyber Security Electric Utilities Portland General Electric Co. Travis Anderson Scott Smith 1 CIP Version 5 PGE Implementation Understanding the Regulations PGE Attended WECC

More information

Industry role moving forward

Industry role moving forward Industry role moving forward Discussion with National Research Council, Workshop on the Resiliency of the Electric Power Delivery System in Response to Terrorism and Natural Disasters February 27-28, 2013

More information

Smart Grid and Cyber Security

Smart Grid and Cyber Security Smart Grid and Cyber Security Annabelle Lee Senior Cyber Security Strategist Computer Security Division National Institute of Standards and Technology December 10, 2009 President s Cyberspace Policy Review

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2015-2018 CIPC Executive Committee Updated: December 13, 2016 NERC Report Title Report Date I Table of Contents Preface... iv Executive Summary...

More information

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 June 2, 2014

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 June 2, 2014 Federal Energy Regulatory Commission Order No. 791 June 2, 2014 67 and 76 67. For the reasons discussed below, the Commission concludes that the identify, assess, and correct language, as currently proposed

More information

Cyber Security Standards Drafting Team Update

Cyber Security Standards Drafting Team Update Cyber Security Standards Drafting Team Update Michael Assante, VP & Chief Security Officer North American Electric Reliability Corp. February 3, 2008 Overview About NERC Project Background Proposed Modifications

More information

Critical Infrastructure Protection Version 5

Critical Infrastructure Protection Version 5 Critical Infrastructure Protection Version 5 Tobias Whitney, Senior CIP Manager, Grid Assurance, NERC Compliance Committee Open Meeting August 9, 2017 Agenda Critical Infrastructure Protection (CIP) Standards

More information

Standard Development Timeline

Standard Development Timeline Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard is adopted by the NERC Board of Trustees (Board).

More information

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT Mitigation Framework Leadership Group (MitFLG) Charter DRAFT October 28, 2013 1.0 Authorities and Oversight The Mitigation Framework Leadership Group (MitFLG) is hereby established in support of and consistent

More information

Implementing Executive Order and Presidential Policy Directive 21

Implementing Executive Order and Presidential Policy Directive 21 March 26, 2013 Implementing Executive Order 13636 and Presidential Policy Directive 21 Mike Smith, Senior Cyber Policy Advisor, Office of Electricity Delivery and Energy Reliability, Department of Energy

More information

On the Leading Edge: The National Electrical Infrastructure and Smart Grid

On the Leading Edge: The National Electrical Infrastructure and Smart Grid On the Leading Edge: The National Electrical Infrastructure and Smart Grid Paul A. Molitor Director, Smart Grid National Electrical Manufacturers Association (NEMA) Agenda Smart Grid in the United States

More information

HPH SCC CYBERSECURITY WORKING GROUP

HPH SCC CYBERSECURITY WORKING GROUP HPH SCC A PRIMER 1 What Is It? The cross sector coordinating body representing one of 16 critical infrastructure sectors identified in Presidential Executive Order (PPD 21) A trust community partnership

More information

NIST SmartGrid Update. Paul Myrda Technical Executive Power Systems Engineering Research Center August 10, 2009

NIST SmartGrid Update. Paul Myrda Technical Executive Power Systems Engineering Research Center August 10, 2009 NIST SmartGrid Update Paul Myrda Technical Executive Power Systems Engineering Research Center August 10, 2009 Overview NIST was mandated by Congress in the Energy Independence and Security Act (EISA)

More information

ANSI Homeland Security Standards Panel (ANSI-HSSP) Open Forum for Standards Developers

ANSI Homeland Security Standards Panel (ANSI-HSSP) Open Forum for Standards Developers ANSI Homeland Security Standards Panel (ANSI-HSSP) Presented by Dan Bart Co-Char, ANSI-HSSP 1 Overview Will address the following ANSI-HSSP items: Rationale Mission Structure Selected accomplishments Looking

More information

FERC's Revised Critical Infrastructure Protection Demands Active Vigilance

FERC's Revised Critical Infrastructure Protection Demands Active Vigilance RESEARCH North America Power and Utilities Smart Grid FERC's Revised Critical Infrastructure Protection Demands Active Vigilance New Designation Includes All Cyber Assets Connected to Bulk Electric System

More information

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 PPD-21: CI Security and Resilience On February 12, 2013, President Obama signed Presidential Policy Directive

More information

FERC Reliability Technical Conference Panel III: ERO Performance and Initiatives ESCC and the ES-ISAC

FERC Reliability Technical Conference Panel III: ERO Performance and Initiatives ESCC and the ES-ISAC : ERO Performance and Initiatives June 4, 2015 Chairman Bay, Commissioners, and fellow panelists, I appreciate the opportunity to address the topics identified for the third panel of today s important

More information

ARRA State & Local Energy Assurance Planning & Implementation

ARRA State & Local Energy Assurance Planning & Implementation State Energy Policy and Technology Outlook Conference February 2, 2010, Washington, DC ARRA State & Local Energy Assurance Planning & Implementation Alice Lippert Senior Technical Advisor Office of Electricity

More information

Critical Infrastructure Partnership

Critical Infrastructure Partnership Critical Infrastructure Partnership Overview Chris Boyer AVP Global Public Policy December 11, 2017 2016 AT&T Intellectual Property. All rights reserved. AT&T, Globe logo, Mobilizing Your World and DIRECTV

More information

National Policy and Guiding Principles

National Policy and Guiding Principles National Policy and Guiding Principles National Policy, Principles, and Organization This section describes the national policy that shapes the National Strategy to Secure Cyberspace and the basic framework

More information

Communications and Electric Power Sectors:

Communications and Electric Power Sectors: Communications and Electric Power Sectors: Need for Common Situation Awareness and Tools DIMACS Workshop on Algorithmic Decision Theory for the Smart Grid October 25, 2010 Daniel C. Hurley, Jr. Director,

More information

Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA. The African Internet Governance Forum - AfIGF Dec 2017, Egypt

Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA. The African Internet Governance Forum - AfIGF Dec 2017, Egypt Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA The African Internet Governance Forum - AfIGF2017 5 Dec 2017, Egypt Agenda Why? Threats Traditional security? What to secure?

More information

March 6, Dear Electric Industry Vendor Community: Re: Supply Chain Cyber Security Practices

March 6, Dear Electric Industry Vendor Community: Re: Supply Chain Cyber Security Practices March 6, 2019 Dear Electric Industry Vendor Community: Re: Supply Chain Cyber Security Practices On July 21, 2016, the Federal Energy Regulatory Commission (FERC) directed the North American Electric Reliability

More information

History of NERC December 2012

History of NERC December 2012 History of NERC December 2012 Timeline Date 1962-1963 November 9, 1965 1967 1967-1968 June 1, 1968 July 13-14, 1977 1979 1980 Description Industry creates an informal, voluntary organization of operating

More information

The NIST Cybersecurity Framework

The NIST Cybersecurity Framework The NIST Cybersecurity Framework U.S. German Standards Panel 2018 April 10, 2018 Adam.Sedgewick@nist.gov National Institute of Standards and Technology About NIST Agency of U.S. Department of Commerce

More information

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21 National and Cyber Security Branch Presentation for Gridseccon Quebec City, October 18-21 1 Public Safety Canada Departmental Structure 2 National and Cyber Security Branch National and Cyber Security

More information

THE WHITE HOUSE. Office of the Press Secretary. EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS

THE WHITE HOUSE. Office of the Press Secretary. EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS THE WHITE HOUSE Office of the Press Secretary EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS February 12, 2013 PRESIDENTIAL POLICY DIRECTIVE/PPD-21 SUBJECT: Critical

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2013-2016 CIPC Executive Committee 5/14/2013 3353 Peachtree Road NE Suite 600, North Tower Atlanta, Georgia 30326 404-446-2560 www.nerc.com Table

More information

NARUC. Winter Committee Meetings. Staff Subcommittee On Gas

NARUC. Winter Committee Meetings. Staff Subcommittee On Gas NARUC Winter Committee Meetings Staff Subcommittee On Gas February 12, 2017 { NARUC Staff Subcommittee on Gas Who is NAESB and what does it do? Background Origin and Scope: The North American Energy Standards

More information

ERO Enterprise Strategic Planning Redesign

ERO Enterprise Strategic Planning Redesign ERO Enterprise Strategic Planning Redesign Mark Lauby, Senior Vice President and Chief Reliability Officer Member Representatives Committee Meeting February 10, 2016 Strategic Planning Redesign Current

More information

Green California Summit. Paul Clanon Executive Director California Public Utilities Commission April 19, 2011

Green California Summit. Paul Clanon Executive Director California Public Utilities Commission April 19, 2011 Green California Summit Paul Clanon Executive Director California Public Utilities Commission April 19, 2011 1 Presentation Overview What is Smart Grid Why Smart Grid California s Commitment to Smart Grid

More information

TERRORISM LIAISON OFFICER OUTREACH PROGRAM - (TLOOP)

TERRORISM LIAISON OFFICER OUTREACH PROGRAM - (TLOOP) To: Bay Area UASI Approval Authority From: Mike Sena, Director NCRIC/HIDTA Date: January 10, 2019 Re: Item 7: NCRIC Annual Report and Proposed FY19 Allocation Recommendation: Approve $4,454,066 from the

More information

Scope Cyber Attack Task Force (CATF)

Scope Cyber Attack Task Force (CATF) Scope Cyber Attack Task Force (CATF) PART A: Required for Committee Approval Purpose This document defines the scope, objectives, organization, deliverables, and overall approach for the Cyber Attack Task

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2018-2019 CIPC Executive Committee Updated:xxxxxxxx NERC Report Title Report Date I Table of Contents Preface... iii CIPC Organizational Structure...

More information

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 January 23, 2015

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 January 23, 2015 Federal Energy Regulatory Commission Order No. 791 January 23, 2015 67 and 76 67. For the reasons discussed below, the Commission concludes that the identify, assess, and correct language, as currently

More information

Framework for Improving Critical Infrastructure Cybersecurity

Framework for Improving Critical Infrastructure Cybersecurity Framework for Improving Critical Infrastructure Cybersecurity May 2017 cyberframework@nist.gov Why Cybersecurity Framework? Cybersecurity Framework Uses Identify mission or business cybersecurity dependencies

More information

Incentives for IoT Security. White Paper. May Author: Dr. Cédric LEVY-BENCHETON, CEO

Incentives for IoT Security. White Paper. May Author: Dr. Cédric LEVY-BENCHETON, CEO White Paper Incentives for IoT Security May 2018 Author: Dr. Cédric LEVY-BENCHETON, CEO Table of Content Defining the IoT 5 Insecurity by design... 5 But why are IoT systems so vulnerable?... 5 Integrating

More information

Standard CIP 005 4a Cyber Security Electronic Security Perimeter(s)

Standard CIP 005 4a Cyber Security Electronic Security Perimeter(s) A. Introduction 1. Title: Cyber Security Electronic Security Perimeter(s) 2. Number: CIP-005-4a 3. Purpose: Standard CIP-005-4a requires the identification and protection of the Electronic Security Perimeter(s)

More information

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION NARUC Energy Regulatory Partnership Program The Public Services Regulatory Commission of Armenia and The Iowa Utilities Board Janet Amick Senior Utility

More information

Cybersecurity Overview

Cybersecurity Overview Cybersecurity Overview DLA Energy Worldwide Energy Conference April 12, 2017 1 Enterprise Risk Management Risk Based: o Use of a risk-based approach for cyber threats with a focus on critical systems where

More information

PIPELINE SECURITY An Overview of TSA Programs

PIPELINE SECURITY An Overview of TSA Programs PIPELINE SECURITY An Overview of TSA Programs Jack Fox Pipeline Industry Engagement Manager Surface Division Office of Security Policy & Industry Engagement May 5, 2014 TSA and Pipeline Security As the

More information

Updates to the NIST Cybersecurity Framework

Updates to the NIST Cybersecurity Framework Updates to the NIST Cybersecurity Framework NIST Cybersecurity Framework Overview and Other Documentation October 2016 Agenda: Overview of NIST Cybersecurity Framework Updates to the NIST Cybersecurity

More information

SMART GRID TESTING & CERTIFICATION COMMITTEE (SGTCC) STATUS AND OVERVIEW. May 2011

SMART GRID TESTING & CERTIFICATION COMMITTEE (SGTCC) STATUS AND OVERVIEW. May 2011 SMART GRID TESTING & CERTIFICATION COMMITTEE (SGTCC) STATUS AND OVERVIEW May 2011 SGTCC OVERVIEW The Smart Grid Testing & Certification Committee (SGTCC) is a standing committee of the Smart Grid Interoperability

More information

ДОБРО ПОЖАЛОВАТЬ SIEMENS AG ENERGY MANAGEMENT

ДОБРО ПОЖАЛОВАТЬ SIEMENS AG ENERGY MANAGEMENT ДОБРО ПОЖАЛОВАТЬ SIEMENS AG ENERGY MANAGEMENT ENERGY AUTOMATION - SMART GRID Restricted Siemens AG 20XX All rights reserved. siemens.com/answers Frederic Buchi, Energy Management Division, Siemens AG Cyber

More information

Homeland Security Institute. Annual Report. pursuant to. Homeland Security Act of 2002

Homeland Security Institute. Annual Report. pursuant to. Homeland Security Act of 2002 Homeland Security Institute Annual Report pursuant to Homeland Security Act of 2002 July 1, 2005 Homeland Security Institute ANNUAL REPORT Introduction Established in April 2004, the Homeland Security

More information

DOE s Roles and Responsibilities for Energy Sector Cybersecurity

DOE s Roles and Responsibilities for Energy Sector Cybersecurity Written Testimony of Under Secretary Mark Menezes U.S. Department of Energy Before the Subcommittee on Energy Committee on Energy and Commerce U.S. House of Representatives March 14, 2018 Introduction

More information

United States Government Cloud Standards Perspectives

United States Government Cloud Standards Perspectives United States Government Cloud Standards Perspectives in the context of the NIST initiative to collaboratively build a USG Cloud Computing Technology Roadmap NIST Mission: To promote U.S. innovation and

More information

S&T Stakeholders Conference

S&T Stakeholders Conference S&T Stakeholders Conference Risk-Informed Requirements Process Col. Merrick Krause, USAF (Ret.) Director Infrastructure Analysis & Strategy Division U.S. Department of Homeland Security June 2-5, 2008

More information

Cyber Security Incident Report

Cyber Security Incident Report Cyber Security Incident Report Technical Rationale and Justification for Reliability Standard CIP-008-6 January 2019 NERC Report Title Report Date I Table of Contents Preface... iii Introduction... 1 New

More information

This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective.

This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective. Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective. Description of Current Draft

More information

Cyber Security For Utilities Risks, Trends & Standards. IEEE Toronto March 22, Doug Westlund Senior VP, AESI Inc.

Cyber Security For Utilities Risks, Trends & Standards. IEEE Toronto March 22, Doug Westlund Senior VP, AESI Inc. Cyber Security For Utilities Risks, Trends & Standards IEEE Toronto March 22, 2017 Doug Westlund Senior VP, AESI Inc. Agenda Cyber Security Risks for Utilities Trends & Recent Incidents in the Utility

More information

Executive Order on Coordinating National Resilience to Electromagnetic Pulses

Executive Order on Coordinating National Resilience to Electromagnetic Pulses Executive Order on Coordinating National Resilience to Electromagnetic Pulses The Wh... Page 1 of 11 EXECUTIVE ORDERS Executive Order on Coordinating National Resilience to Electromagnetic Pulses INFRASTRUCTURE

More information

Emergency Management BC Update

Emergency Management BC Update Emergency Management BC Update Provincial Emergency Program Emergency Management BC Update on Initiatives Union of BC Municipalities 2016 Conference September 29, 2016 Agenda Emergency Management BC Overview

More information

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure March 2015 Pamela Curtis Dr. Nader Mehravari Katie Stewart Cyber Risk and Resilience Management Team CERT

More information

Risk: Security s New Compliance. Torsten George VP Worldwide Marketing and Products, Agiliance Professional Strategies - S23

Risk: Security s New Compliance. Torsten George VP Worldwide Marketing and Products, Agiliance Professional Strategies - S23 Risk: Security s New Compliance Torsten George VP Worldwide Marketing and Products, Agiliance Professional Strategies - S23 Agenda Market Dynamics Organizational Challenges Risk: Security s New Compliance

More information

EPRI Smart Grid R&D Overview

EPRI Smart Grid R&D Overview EPRI Smart Grid R&D Overview September 5 th 2008 Erfan Ibrahim, Ph. D. Technical Executive CIO Initiative Lead Electric Power Research Institute (EPRI) Electric Power Research Institute Collaboration..Technical

More information

The Office of Infrastructure Protection

The Office of Infrastructure Protection The Office of Infrastructure Protection National Protection and Programs Directorate Department of Homeland Security Organisation for the Prohibition of Chemical Weapons September 13, 2011 Overall Landscape

More information

CYBERSECURITY TRAINING EXERCISE KMU TRAINING CENTER NOVEMBER 7, 2017

CYBERSECURITY TRAINING EXERCISE KMU TRAINING CENTER NOVEMBER 7, 2017 CYBERSECURITY TRAINING EXERCISE KMU TRAINING CENTER NOVEMBER 7, 2017 Sponsored by: Kansas Municipal Utilities Kansas Municipal Energy Agency Kansas Power Pool CYBERSECURITY TRAINING EXERCISE DATE November

More information

National Infrastructure Protection Plan (NIPP) Transportation Sector Specific Plan (TSSP) and The TSSP R&D Working Group

National Infrastructure Protection Plan (NIPP) Transportation Sector Specific Plan (TSSP) and The TSSP R&D Working Group National Infrastructure Protection Plan (NIPP) Transportation Sector Specific Plan (TSSP) and The TSSP R&D Working Group AASHTO Special Committee on Transportation Security & The National Cooperative Highway

More information

Exploring the Maturity of Risk Management Process in Government: An Integrated ERM Model at the U.S. Department of Education

Exploring the Maturity of Risk Management Process in Government: An Integrated ERM Model at the U.S. Department of Education Exploring the Maturity of Risk Management Process in Government: An Integrated ERM Model at the U.S. Department of Education FEDERAL STUDENT AID ENTERPRISE RISK MANAGEMENT GROUP Cynthia Vitters 1. ERM

More information

ICS-CERT Year in Review. Industrial Control Systems Cyber Emergency Response Team

ICS-CERT Year in Review. Industrial Control Systems Cyber Emergency Response Team ICS-CERT Year in Review Industrial Control Systems Cyber Emergency Response Team 2012 What s Inside Welcome 1 Organization 3 Outreach 4 Industrial Control Systems Joint Working Group 5 Advanced Analytical

More information

Ontario Energy Board Cyber Security Framework

Ontario Energy Board Cyber Security Framework Ontario Energy Board Cyber Security Framework Accelerating compliance using Security-as-a-Service (SECaaS) Office: 888.876.0504 Email: info@stratejm.com Website: www.stratejm.com About this Whitepaper

More information

Electric Power Research Institute. Smart Grid. Program Overview

Electric Power Research Institute. Smart Grid. Program Overview Smart Grid Program Description Program Overview For 2010, EPRI is offering three strategic collections of research projects or programs in virtual programs. These virtual programs have been designed to

More information

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium Securing Cyber Space & America s Cyber Assets: Threats, Strategies & Opportunities September 10, 2009, Crystal Gateway Marriott, Arlington,

More information

ENISA EU Threat Landscape

ENISA EU Threat Landscape ENISA EU Threat Landscape 24 th February 2015 Dr Steve Purser ENISA Head of Department European Union Agency for Network and Information Security www.enisa.europa.eu Agenda ENISA Areas of Activity Key

More information

Views on the Framework for Improving Critical Infrastructure Cybersecurity

Views on the Framework for Improving Critical Infrastructure Cybersecurity This document is scheduled to be published in the Federal Register on 12/11/2015 and available online at http://federalregister.gov/a/2015-31217, and on FDsys.gov Billing Code: 3510-13 DEPARTMENT OF COMMERCE

More information

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016 Standards Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016 Balancing Authority Reliability-based Controls Reliability Benefits Data requirements for Balancing Authority (BA)

More information

CIO Workshop Wrap Up & Next Steps

CIO Workshop Wrap Up & Next Steps CIO Workshop Wrap Up & Next Steps November 30, 2012 Matt Wakefield Area Manager, Smart Grid (Information & Communication Technologies) Thank you for your Participation & Thank You DTE for Hosting Goals

More information

Cyber Threats? How to Stop?

Cyber Threats? How to Stop? Cyber Threats? How to Stop? North American Grid Security Standards Jessica Bian, Director of Performance Analysis North American Electric Reliability Corporation AORC CIGRE Technical Meeting, September

More information

DRAFT. Cyber Security Communications between Control Centers. March May Technical Rationale and Justification for Reliability Standard CIP-012-1

DRAFT. Cyber Security Communications between Control Centers. March May Technical Rationale and Justification for Reliability Standard CIP-012-1 DRAFT Cyber Security Communications between Control Centers Technical Rationale and Justification for Reliability Standard CIP-012-1 March May 2018 NERC Report Title Report Date I Table of Contents Preface...

More information

Standard CIP Cyber Security Electronic Security Perimeter(s)

Standard CIP Cyber Security Electronic Security Perimeter(s) A. Introduction 1. Title: Cyber Security Electronic Security Perimeter(s) 2. Number: CIP-005-2 3. Purpose: Standard CIP-005-2 requires the identification and protection of the Electronic Security Perimeter(s)

More information

CCISO Blueprint v1. EC-Council

CCISO Blueprint v1. EC-Council CCISO Blueprint v1 EC-Council Categories Topics Covered Weightage 1. Governance (Policy, Legal, & Compliance) & Risk Management 1.1 Define, implement, manage and maintain an information security governance

More information