The SGIP TCC Interoperability. How do we know if a standard s certification programs will work?

Similar documents
SMART GRID TESTING & CERTIFICATION COMMITTEE (SGTCC) STATUS AND OVERVIEW. May 2011

Standards to Products. James Mater QualityLogic

NIST Smart Grid Activities

Interoperability Process Reference Manual (IPRM)

Copyright protected. Use is for Single Users only via a VHP Approved License. For information and printed versions please see

Symantec Data Center Transformation

I. Contact Information: Lynn Herrick Director, Technology Integration and Project Management Wayne County Department of Technology

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure

Electric Sector Security & Privacy Plans for 2011

ISO/ IEC (ITSM) Certification Roadmap

Title Core TIs Optional TIs Core Labs Optional Labs. All None 1.1.6, 1.1.7, and Network Math All None None 1.2.5, 1.2.6, and 1.2.

CONCLUSIONS AND RECOMMENDATIONS

Module 3. Overview of TOGAF 9.1 Architecture Development Method (ADM)

Standards: Implementation, Certification and Testing Work group Friday, May 8, :00 Pm-1:30 Pm ET.

Demystifying Governance, Risk, and Compliance (GRC) with 4 Simple Use Cases. Gen Fields Senior Solution Consultant, Federal Government ServiceNow

NIST Smart Grid Interoperability Framework

Embedding Privacy by Design

EXIN Expert in IT Service Management based on ISO/IEC Preparation Guide

NFPA Edition

Business Architecture Implementation Workshop

PDA Trainer Certification Process V 1.0

February Introduction to Wi-SUN Alliance

THE SMART GRID INTEROPERABILITY LAB

Information Security Continuous Monitoring (ISCM) Program Evaluation

einfrastructures Concertation Event

Measurement Challenges and Opportunities for Developing Smart Grid Testbeds

Ontario Smart Grid Forum: Support Presentation. Tuesday, March 8 th 2011

Overview on Test & Certification in Wi-SUN Alliance. Chin-Sean SUM Certification Program Manager Wi-SUN Alliance

SALESFORCE CERTIFIED SALES CLOUD CONSULTANT

Identity Assurance Framework: Realizing The Identity Opportunity With Consistency And Definition

5.10 CUSTOMER SPECIFIC DESIGN AND ENGINEERING SERVICES (L )

Security Automation Developer Days Winter 2010 Conference Preliminary High Level Agenda

EVALUATION AND APPROVAL OF AUDITORS. Deliverable 4.4.3: Design of a governmental Social Responsibility and Quality Certification System

SDLC Maturity Models

Strategic & Operational Planning:

SEPA HBI2G WG Home/Building/Industry-to-Grid Working Group

Smart Grid Task Force Scope

Microsoft SDL 한국마이크로소프트보안프로그램매니저김홍석부장. Security Development Lifecycle and Building Secure Applications

HIT Policy Committee. Recommendations by the Certification and Adoption Workgroup. Paul Egerman Marc Probst, Intermountain Healthcare.

Magento Enterprise Edition Customer Support Guide

IT SECURITY OFFICER. Department: Information Technology. Pay Range: Professional 18

Smart Grid and Cyber Security

NEMA Standards Publication SG-IPRM Smart Grid Interoperability Process Reference Manual

for TOGAF Practitioners Hands-on training to deliver an Architecture Project using the TOGAF Architecture Development Method

Time Synchronization and Standards for the Smart Grid

Graded Unit title: Computing: Networking: Graded Unit 2

INFORMATION TECHNOLOGY NETWORK ADMINISTRATOR ANALYST Series Specification Information Technology Network Administrator Analyst II

ITIL Managing Across the Lifecycle Course

Data Governance. Mark Plessinger / Julie Evans December /7/2017

BUILDING CYBERSECURITY CAPABILITY, MATURITY, RESILIENCE

Enterprise Business. Solution Partner Program Guideline

Request for Proposals for Design/Engineering Support Services (RFP No MBI-01)

Understanding the Open Source Development Model. » The Linux Foundation. November 2011

A Working Paper of the EastWest Institute Breakthrough Group. Increasing the Global Availability and Use of Secure ICT Products and Services

Priority Action Plan (PAP) Creation Form

Criteria for SQF Training Courses

Ad Hoc Smart Grid Executive Committee. February 10, 2011 New Orleans, LA

The Africa Utilities Telecom Council Johannesburg CC, South Africa 1 st December, 2015

Developing a Model for Cyber Security Maturity Assessment

OWASP - SAMM. OWASP 12 March The OWASP Foundation Matt Bartoldus Gotham Digital Science

Experiences with conformance test procedures for IEC Edition 2 System and IED configuration tools

Project Management Pre-Implementation Project status reporting Post Implementation Assessment Phase Solidify Project Scope

CONTINUOUS PROFESSIONAL DEVELOPMENT (CPD) POLICY

IoT & SCADA Cyber Security Services

Title Core TIs Optional TIs Core Labs Optional Labs. 1.1 WANs All None None None. All None None None. All None 2.2.1, 2.2.4, 2.2.

PRODUCT SAFETY PROFESSIONAL CERTIFICATION PROGRAM DETAILS. Overview

NCSF Foundation Certification

Introducing Cyber Observer

Standards Readiness Criteria. Tier 2

FOUNDATION CERTIFICATE IN INFORMATION SECURITY v2.0 INTRODUCING THE TOP 5 DISCIPLINES IN INFORMATION SECURITY SUMMARY

Request For Proposal (RFP) Online Certification Platform

Gain Control Over Your Cloud Use with Cisco Cloud Consumption Professional Services

Demystifying GRC. Abstract

Project Management Certification

V-PWR Data Center Program Guide

Certification Report

Cyber Partnership Blueprint: An Outline

Implementing ITIL v3 Service Lifecycle

EXAM PREPARATION GUIDE

Final Project Report

INFORMATION TECHNOLOGY ONE-YEAR PLAN

AWS Service Delivery Program AWS Server Migration Service (SMS) Consulting Partner Validation Checklist

CDISC Operating Procedure COP-001 Standards Development

SERVICE DESIGN ITIL INTERMEDIATE TRAINING & CERTIFICATION

TERMS OF REFERENCE. Special Committee (SC) 223

NIS Standardisation ENISA view

PREPARE FOR TAKE OFF. Accelerate your organisation s journey to the Cloud.

DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure

NCHRP Project Impacts of Connected Vehicles and Automated Vehicles on State and Local Transportation Agencies

Organization of Scientific Area Committees for Forensic Science (OSAC)

Making the most of DCIM. Get to know your data center inside out

Achilles System Certification (ASC) from GE Digital

Effective COBIT Learning Solutions Information package Corporate customers

Choosing the Right Cybersecurity Assessment Tool Michelle Misko, TraceSecurity Product Specialist

Status of activities Joint Working Group on standards for Smart Grids in Europe

SERVICE TRANSITION ITIL INTERMEDIATE TRAINING & CERTIFICATION

Standards and Test Procedures for Interconnection and Interoperability (GMLC 1.4.1)

Title Core TIs Optional TIs Core Labs Optional Labs. All None 1.1.4a, 1.1.4b, 1.1.4c, 1.1.5, WAN Technologies All None None None

Cybersecurity-Related Information Sharing Guidelines Draft Document Request For Comment

Accelerate Your Enterprise Private Cloud Initiative

Transcription:

The SGIP TCC Interoperability Assessment Maturity Model How do we know if a standard s certification programs will work? 1

Agenda The problem defined SGIP TCC approach Interoperability Maturity Assessment Metrics Collecting maturity metric information The meaning of the assessment What next? 2

SGIP TCC WG 3 members Acknowledgements Especially Pete Cain of Agilent for all the work with scoring and the spreadsheet EnerNex work on Conformity Landscape (http://collaborate.nist.gov/twiki-sggrid/bin/view/smartgrid/sgipdocumentsandreferencessgtcc) Member Organization Assignment James Mater Quality Logic Chair John Adams Honeywell Controls Co-Chair: Thomas Farese Telcordia Osmand Sakr NTS Mark Engstrom NeuStar Kent Dickson Tendril Co-Chair: Pete Cain Agilent Scribe: Bruce Muschlitz EnerNex Mark Ortiz Consumers Energy Rudi Shubert IEEE Phil Beecher Beecher Communication Consultants Rik Drummond Drummond Group TCC Chair Clint Powell Powell Wireless Commsulting Emily O Brien KEMA Mladen Kezunovic Texas A&M 3

The SGIP TCC Challenge Establish an industry standard process for how to design and manage test and certification programs (TCPs) for a Smart Grid standard NONE EXISTS today! Wide variation in Smart Grid standards: low-level communications protocols (ipv6) to application software interface definitions (OpenADE) Gain cooperation of TCP owners for Smart Grid standards Assess maturity of different TCPs Influence changes to improve TCPs (including establishing new ones) 4

The SGIP TCC Approach Develop an Interoperability Maturity Assessment Model (IMAM) for Standards Test and Certification Activities Use IMAM to develop a Maturity Assessment Questionnaire Apply as a screening and measurement tool Prioritize TCC actions with each standard Develop an Interoperability Process Reference Manual (IPRM) as a guide to best practices for TCPs Assess TCPs against the IPRM Use IPRM assessment to Identify areas for improvement and assistance Determine recommended list of mature standards test programs Determine priority for assisting TCPs Organize an SGIP Test Action Plan (TAP) team to work with priority TCPs 5

TCP Assessment Issues The indicators and causes of such issues will vary considerably as will the remedies that should be applied. Agreement on best practices among standards test and certification programs that will produce in-the-field interoperable and interchangeable products Flexibility to apply across a broad range of standards types Finding objective reviewers to conduct maturity assessments. Avoiding political efforts to change the assessments Re-assessment after a certain period when a TCP has made progress Deciding what is threshold for "certifying readiness of standards for cyber security validation, interop and conformance testing." 6

Near-Term Goals Identify several candidate Smart Grid standard test programs (from the NIST A List ) that can/will meet our requirements for interoperability /conformance program quality Program needs to be in place. Program needs to meet SGIP criteria for maturity Conduct maturity assessments and apply the results to determine TCC actions and priorities Identify several candidate standards that could benefit from SGIP assistance in setting up or improving TCPs Develop some form of approved list for standards that meet (or provisionally meet) SGIP TCC requirements 7

IMAM The Interoperability Maturity Assessment Model 4 Filter Metrics: 8 Assessment Metrics Filters critical characteristics for success Assessments deeper evaluation of specific strengths and weaknesses of a program Already used as a pilot and preliminary assessment for Smart Grid standards test and certification programs 8

[ Filtering Metrics 9

Filter Metric 1: ITCA Does the SSO Have an ITCA? Or ITCA = Interoperability Test and Certification Authority To the extent that a strong, well-supported, independent organization exist which can define, administer and maintain a formal certification program, the value of the program and resulting interoperability will improve. An ITCA is responsible for specifying test and certification requirements, defining the programs, selecting and certifying labs or test organizations, managing the certification requirements, etc. GREEN: ITCA is functioning and achieving goals YELLOW: ITCA exists but with marginal results RED: No ITCA exists or is operating

Filter Metric 2: Technical Specification Structure A look at the SDO/SSO technical specification or guide for a standard, if one exists, can help assess the likelihood that an ITCA will be successful in developing and managing a test and certification program. For instance, best practices for technical specifications include: A specific conformance section in the specification facilitates test and certification. Few options or private extensions will make it easier to develop test and certification programs for than standards that have a significant number of optional features and functions. Thorough and clear specification can make implementing an interoperable product easier than an incomplete or ambiguous specification. GREEN : Structured to support interoperable products YELLOW: Numerous options and extensions without adequate interoperability guidelines RED: Poorly structured, ambiguous 11

Filter Metric 3: Product Development Status Are products being delivered claiming conformance to a specific standard? Are customers attempting to implement such products? A No means it is premature to judge the effectiveness or maturity of a standards interoperability test or certification program. This does not prevent evaluating other characteristics of the standards activity but the fewer the products in the market the more important the value of the Assessment. GREEN: 2 nd generation products are in the field YELLOW: Products are in evaluation but not shipping RED: There are no products in development 12

Filter Metric 4: Customer Experience (Customers for products built to a standard) What experience are customers having with the products as far as interoperability is concerned? What are the customer expectations for interoperability? Are they being met? How severe are the issues in terms of effort to deploy? Are they actually preventing deployment or changing the deployment strategy to accommodate the problems? Do the issues prevent substitution of one vendor s product for another? Products are either meeting interoperability expectations of customers or not. GREEN: Products in use, few interop problems YELLOW: Some interop problems encountered RED: Significant interop problems in the field 13

Questionnaire: 120 questions across the 12 metrics Yes/No/Next Six Months/NA responses Excel spreadsheet that automatically computes ratings on each metric Scoring < 25% YES RED traffic light Data Collection 25% - 75% - YELLOW traffic light > 75% YES GREEN traffic light Collaborative assessment initially (2-3 hours) Likely to become self-administered tool to prepare for IPRM assessment 14

Questionnaire Sample Customer Maturity and Discipline 1 Do Requests for Products (RFPs) typically include requirements for conformance and interoperability certification to the relevant standards? Yes Planned / Some do No N/A Comment or supporting evidence 2 Are customers aware of a certification or other interoperability validation program? 3 Do they judge it to provide value? Summary level view 4 Are they requiring a certification of some sort by an independent 3 rd party prior to consideration of new technology in the market? 5 Are customers independently verifying interoperability claims of vendors? 6 For this standard, does it make sense that products from different vendors for the same application can be substituted for one another without the need for specialized software or integration efforts? 7 If yes to 7, do customers require that there are at least two vendors for products that provide comparable functionality? 15

Traffic Light Example 16

What Does the Maturity Assessment Mean? Assessment is high-level, quick look at a standard s text program Valuable for: Self-assessment for improvement roadmap TCC assessment for prioritizing actions of TCC SGIP metric to influence adopted standards catalog for Smart Grid Incentives for test and certification organizations Useful program feedback External benchmarking Data to influence focus and budget on test programs Key factor in achieving approved Smart Grid standard status 17

Status and What Next? Status: completed initial product and archived 10+ ITCAs piloted and results compiled anonymously Opportunities? Adapt to act as pre-qualification tool for ITCAs planning to complete an IPRM Assessment Use as starting point for a Smart Grid Standard Maturity Assessment Model add metrics for other aspects of standard maturity 18

IPRM and IMAM Coverage IPRM Topics IPRM Model IPRM and OSI Model End-End Interop Test ITCA Categories 1-5 Test Process Management Certification Testing Governance (17) Lab Qualification (4) Technical (5) Inheritance (4) Version Control (4) Test General (6) Test Conformance (4) Test Product Interop (9) Test System Interop (2) Test Performance (2) Tools (3) Technical Lead (4) Improvements (8) Security (11) General Test Policies (6) Test Suite Specification (13) Test Profile Attributes (6) Interoperability Test and Certification Authority (5) Technical Specification Structure (8) Product Development and Deployment Status (2) Customer Experience (8) Customer Maturity and Discipline (8) Common Questions for all Certification Programs ( Conformance Testing (3) Interoperability Testing (5) Security Testing (3) Security Evaluation of Standard (10) Published Test Procedures Reference Implementation Independent Test Labs (8) Feedback to Standard (6) Conformance Checklist (6) Supplemental Test Tools and Test Suites (5) Sustainability of Test Program (5) IMAM Topics 19

IMAM and IPRM Coverage IPRM Requirements Best Practices Concepts IPRM Topics IMAM Topics Governance (17) Lab Qualification (4) Technical (5) Inheritance (4) Version Control (4) Test General (6) Test Conformance (4) Test Product Interop (9) Test System Interop (2) Test Performance (2) Tools (3) Technical Lead (4) Improvements (8) Security (11) General Test Policies (6) Test Suite Specification (13) Test Profile Attributes (6) IPRM Model IPRM and OSI Model End-End Interop Test ITCA Categories 1-5 Test Process Management Certification Testing Interoperability Test and Certification Authority (5) Technical Specification Structure (8) Product Development and Deployment Status (2) Customer Experience (8) Customer Maturity and Discipline (8) Common Questions for all Certification Programs ( Conformance Testing (3) Interoperability Testing (5) Security Testing (3) Security Evaluation of Standard (10) Published Test Procedures Reference Implementation Independent Test Labs (8) Feedback to Standard (6) Conformance Checklist (6) Supplemental Test Tools and Test Suites (5) Sustainability of Test Program (5) IMAM (x) = number of questions. IPRM (x) = number of requirements

Conclusions SGIP TCC developing ground-breaking processes and tools for assessing maturity of standard test and certifications programs Tools valuable to standards test programs SGIP NIST Smart Grid industry Still in development and test stage Future depends on TCC goals in 2011 21

Resources EnerNex EXISTING CONFORMITY ASSESSMENT PROGRAM LANDSCAPE, Version 0.82, February 19, 2010 LINK AT HTTP://COLLABORATE.NIST.GOV/TWIKI- SGGRID/BIN/VIEW/SMARTGRID/SGIPDOCUMENTSANDREFERENCESS GTCC INTEROPERABILITY KNOWLEDGE BASE (IKB) SGIP CATALOG OF STANDARDS HTTP://COLLABORATE.NIST.GOV/TWIKI- SGGRID/BIN/VIEW/SMARTGRID/SGIPCATALOGOFSTANDARDS The great minds of WG 3! 22