SmartGrid. Implications of Cloud Computing. New Technology in the Utility Environment

Similar documents
G. Larry Clark Principal Engineer Power Delivery Alabama Power Company, A Southern Company

WEI Conference SDG&E TCRI Project April 25, 2018 Mark Fowler, CISSP

Southern Company Smart Grid

NERC CIP Information Protection

Smart Distribution Technology

DUKE ENERGY OHIO SMART GRID / GRID MODERNIZATION. Don Schneider GM, Smart Grid Field Deployment May 24, 2012

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith

Low Impact Generation CIP Compliance. Ryan Walter

What You Should Know About Communication Systems: Business Strategies and Options

Access Control and CIP 10/20/2011

Smart Grid vs. The NERC CIP

Data Inventory and Classification, Physical Devices and Systems ID.AM-1, Software Platforms and Applications ID.AM-2 Inventory

SECURITY AND DATA REDUNDANCY. A White Paper

Cloud-Based Data Security

Employee Security Awareness Training Program

Securing the Grid and Your Critical Utility Functions. April 24, 2017

NERC Monitoring and Situational Awareness Conference: Loss of Control Center Procedures and Testing Practices

Standard CIP Cyber Security Critical Cyber Asset Identification

Keys to a more secure data environment

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION

Standard CIP Cyber Security Critical Cyber Asset Identification

Guide to cyber security/cip specifications and requirements for suppliers. September 2016

Appendix I: LOAD OPERATING AGREEMENT

HIPAA Compliance and OBS Online Backup

Cybersecurity for the Electric Grid

Lesson Learned CIP Version 5 Transition Program

AMI Applications at SDG&E Metering America March 24, 2009 Ted M. Reguly Smart Meter Program Director SDG&E

SDG&E s Accomplishments and Future Plans

Standard CIP Cyber Security Systems Security Management

NW NATURAL CYBER SECURITY 2016.JUNE.16

Title. Critical Infrastructure Protection Getting Low with a Touch of Medium. CanWEA Operations and Maintenance Summit 2018.

Cyber Security Panel Discussion Gary Hayes, SVP & CIO Technology Operations. Arkansas Joint Committee on Energy March 16, 2016

Conservation Voltage Reduction with AMI

Consolidated Privacy Notice

Cybersecurity Overview

Grid Modernization at SDG&E

PG&E Advanced Metering Assessment for Residential Electric Customers. September 2, 2010

CIP V5 Implementation Study SMUD s Experience

ISO/IEC TR TECHNICAL REPORT

High performance monitoring & Control ACE3600 Remote Terminal Unit

Hosted Testing and Grading

Security Standards for Electric Market Participants

Recent Issues in Electric Grid Physical Security

TECHNICAL AND ORGANIZATIONAL DATA SECURITY MEASURES

Cyber Security Updates and Trends Affecting the Real Estate Industry

IEC Vaasa Seminar 21st October Contents

Redefining Renewables SCADA

Cyber Security for Renewable Energy Systems

UCOP ITS Systemwide CISO Office Systemwide IT Policy. UC Event Logging Standard. Revision History. Date: By: Contact Information: Description:

Southern California Edison. Leading the Way in Electricity TM

EHS Steering Team Meting, 2008

ДОБРО ПОЖАЛОВАТЬ SIEMENS AG ENERGY MANAGEMENT

IAM Security & Privacy Policies Scott Bradner

Interconnection and Transmission

Healthcare HIPAA and Cybersecurity Update

Smart Solutions Smarter Grid

2 nd Annual NERC Monitoring and Situational Awareness Conference: FPL s Operational Technology Center

Securing IEDs against Cyber Threats in Critical Substation Automation and Industrial Control Systems

ASERCOM cyber-security guideline for connected HVAC/R equipment

Sacramen Sacr t amen o t Municipal Utility Dis t Dis rict t SMUD May Ma 10,

You Might Know Us As. Copyright 2016 TierPoint, LLC. All rights reserved.

The Terrorism Threat to Physical Assets

Securing Industrial Control Systems

The NIS Directive and Cybersecurity in

Identity-Based Cyber Defense. March 2017

March 6, Dear Electric Industry Vendor Community: Re: Supply Chain Cyber Security Practices

THE NEXUS OF LEAK DETECTION & ASSET MANAGEMENT

Standard CIP 007 4a Cyber Security Systems Security Management

SCADA Training - T&D Automation

NERC Transmission Availability Data System (TADS): Element Identifier Data Submission Addendum

SmartSacramento Distribution Automation

This webinar brought to you by the Relion product family

Data Centers & Technology:

Evaluation of Business Cases for Smart Grid Solutions Kenny Mercado, Senior VP Electric Operations

LTI Security Services. Intelligent & integrated Approach to Cyber & Digital Security

CIP Cyber Security Personnel & Training

California State Polytechnic University, Pomona. Server and Network Security Standard and Guidelines

Information Security Policy

Our Power & Control line of Business offers solutions that safely distribute power to your home or business. Our product range includes Low/Medium

Data Classification, Security, and Privacy

Phasor Technology Research Road Map to Improve Grid Reliability and Market Efficiency. Presented to TAC on April 5, 2005 and PAC on April 22, 2005

October 05, ECE 421 Session 12. Utility SCADA and Automation. Presented by: Chris Dyer

Stem Beach Solar 1041 Application

Question 1: What steps can organizations take to prevent incidents of cybercrime? Answer 1:

FDIC InTREx What Documentation Are You Expected to Have?

CIP Cyber Security Systems Security Management

Copyright 2013 OSIsoft, LLC. 1

Mission Critical MPLS in Utilities

MONITORING SOLUTIONS FOR Power & Utilities

Cyber Risks in the Boardroom Conference

Memorandum. This memorandum requires Committee action.

HIPAA COMPLIANCE AND DATA PROTECTION Page 1

Cyber Threats? How to Stop?

New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines

TECHNICAL AND ORGANIZATIONAL DATA SECURITY MEASURES

GE Enterprise Solutions. Digital Energy

Peter Overgaauw Pascal Stijns 27 Oct 2016 EXPERION PKS CONTROLS ELECTRICAL SYSTEMS TOO!

Security in grid control centers: Spectrum Power TM Cyber Security

2017 Annual Meeting of Members and Board of Directors Meeting

Jose Molina Sales Manager, Global Asset - RTU500 Series (Germany)

Transcription:

1 SmartGrid Implications of Cloud Computing New Technology in the Utility Environment

PG&E Territory Characteristics 70,000 square miles of diverse topography Approximately 20,000 employees Energy Services to approximately 15 million people Over 9 million SmartMeters (Electric & Gas) 1,008,186 Transformers 6,833 MW of Generation 18,616 miles of electric transmission circuits 120,000 miles of electric distribution circuits Regulated by the California Public Utilities Commission (CPUC) 2

The Cloud Data at Rest Utility Application Landscape Hosted off site today SmartMeter Systems Demand Response CAISO Electric Head End System Hosted Meter Data Management Gas Head End PG&E Data Center Vendor Hosted Customer 3

Security Risk Management PG&E utilizes the following five information classifications: PG&E Public Anything produced for public review and available to anyone inside or outside the company. This includes materials such as press releases, advertisements, or bill inserts. PG&E Internal Information intended primarily for use within PG&E, such as organization charts, personnel numbers, and company email messages. Distribution should be limited based on business need to know, and access controls are required. PG&E Confidential Information such as trade secrets, customer or employee information, and passwords that should be shared solely on a business need to know basis. PG&E Confidential data must be encrypted for storage and transmission if electronic and, if printed, protected through controlled physical access, such as a locked filing cabinet. PG&E Restricted or PG&E Privileged (Law only) Information such as Social Security Numbers, undisclosed financial information, and protected health information should be shared solely on a business need to know basis. Data must be for storage and transmission encrypted if electronic and, if printed, protected through controlled physical access. Note that PG&E Privileged is only used by Law. 4

Networks - Critical Infrastructure ODN (air-gapped secure network) - SCADA UDN Traditional IT MPLS Physical Isolation and Connectivity Operational Data Network Utility Data Network Multiprotocol Label Switching Packet Level Network Path 5

Volt / VAR on the test network Test Network Set Voltage 1 Negotiating Network Access in the test environment is not trivial LabView Interface LabView Driver Set Voltage 2 Set Voltage 3 UPS #1 LabView Driver TCP/IP Meter Farm Read Voltage UIQ System Access Point Node Simulator 4.1 Remote Access Firewall UDN ODN CVR Software Adjust Voltage Load Tap Changer Line Capacitor Line Regulator 6

Security is Physical Control of assets is critical to our business: San Jose Mercury News June 4 th, 2013 In the early-morning hours of April 16, someone opened fire at the utility's substation on Metcalf Road near Highway 101. The gunshots damaged five transformers and caused cooling oil to leak from a transformer bank, and the damage prompted state regulators to urge electricity conservation in the ensuing days. AT&T phone service in the area was also affected. 7

Safety and Reliability SmartMeter Performance Statistics The Cloud Interval data supplied from SmartMeter systems for billing within 48 hours of expected delivery as a percentage of expected interval data. 8

9 Thank you Art Anderson arthur.anderson@pge.com

North American Electric Reliability Corporation Critical Infrastructure Protection (CIP) standards Version 5 now requires the following: Encryption Role-based instead of risk-based classifications Multiple levels of compliance Low, Medium and High Impact (in theory, a company could have 10 facilities of which six are low impact facilities, three are medium impact facilities, and one is a high impact facility) New terminology (such as BES Cyber Asset) All serial connections are to be considered Multi-factor authentication requirements Triggers are required to be defined for recovery plans All software (COTS and custom) must be known All security patches from the beginning of time on each device must be known 10