Cyber Security Working Group



Similar documents
Cyber Security Working Group

NIST and the Smart Grid

NIST Coordination and Acceleration of Smart Grid Standards. Tom Nelson National Institute of Standards and Technology 8 December, 2010

Securing the Grid. Marianne Swanson, NIST Also Moderator Akhlesh Kaushiva (AK), DOE Lisa Kaiser, DHS Leonard Chamberlin, FERC Brian Harrell, NERC

Consulting International

Cybersecurity in the Utilities Sector Best Practices and Implementation 2014 Canadian Utilities IT & Telecom Conference September 24, 2014

National Institute of Standards and Technology Smart Grid Cybersecurity

Cybersecurity & Public Utility Commissions

Introduction to NISTIR 7628 Guidelines for Smart Grid Cyber Security

Testimony of Patrick D. Gallagher, Ph.D. Deputy Director

64th Annual National Moot Court Competition Regional Sponsors List

Grid Modernization and Smart Grid

Utility-Scale Applications of Microgrids: Moving Beyond Pilots Cyber Security

Button. Dr. Martin J. Burns President, Hypertek Inc. for NIST

National Bureau for Academic Accreditation And Education Quality Assurance PUBLIC HEALTH

Cyber Security and Privacy - Program 183

DEVELOPING A CYBERSECURITY POLICY ARCHITECTURE

Risk Management, Equipment Protection, Monitoring and Incidence Response, Policy/Planning, and Access/Audit

ZigBee IP Stack Overview Don Sturek Pacific Gas and Electric (PG&E) 2009 ZigBee Alliance. All rights reserved. 1

Bridging the knowledge gap between power engineering and cyber security: Imparting the interdisciplinary knowledge in cyber security for power systems

NIST Cloud Computing Program

future data and infrastructure

Cyber Infrastructure for the Smart Grid

Appendix D. Petersens Guide Listings for PhD in Public Policy

US News & World Report Best Undergraduate Engineering Programs: Specialty Rankings 2014 Rankings Published in September 2013

SGIG Cyber Security Program Review Process

Using Architecture to Guide Cybersecurity Improvements for the Smart Grid

RESEARCH CALL TO DOE/FEDERAL LABORATORIES. Cybersecurity for Energy Delivery Systems Research Call RC-CEDS

ADVANCED DISTRIBUTION MANAGEMENT SYSTEMS OFFICE OF ELECTRICITY DELIVERY & ENERGY RELIABILITY SMART GRID R&D

Highlights & Next Steps

Cyber Security. Smart Grid

DOE Cyber Security Policy Perspectives

US Department of Health and Human Services Exclusion Program. Thomas Sowinski Special Agent in Charge/ Reviewing Official

SOFTWARE AND HARD TARGETS: ENHANCING SMART GRID CYBER SECURITY IN THE AGE OF INFORMATION WARFARE. Energy Security Initiative

National Bureau for Academic Accreditation And Education Quality Assurance

Cyber Security Health Test

The NIST Definition of Cloud Computing

How Much Cyber Security is Enough?


Guideline for the Implementation of Coexistence for Broadband Power Line Communication Standards

Risk Management in Practice A Guide for the Electric Sector

IEEE-Northwest Energy Systems Symposium (NWESS)

Fast Facts About The Cyber Security Job Market

Green Cloud Computing: Case Study Sri Lanka & Pakistan

Cyber Security Risk Management: A New and Holistic Approach

Testimony of. Before the United States House of Representatives Committee on Oversight and Government Reform And the Committee on Homeland Security

THE 411 ON CYBERSECURITY, INFORMATION SHARING AND PRIVACY

ELECTRICITY SECTOR CYBERSECURITY RISK MANAGEMENT PROCESS GUIDELINE

National Bureau for Academic Accreditation And Education Quality Assurance

Cybersecurity in the Energy/Utility Sectors

Asset Management Challenges and Options, Including the Implications and Importance of Aging Infrastructure

What Risk Managers need to know about ICS Cyber Security

Cyber Security Presentation. Ontario Energy Board Smart Grid Advisory Committee. Doug Westlund CEO, N-Dimension Solutions Inc.

STATEMENT OF PATRICIA HOFFMAN ACTING ASSISTANT SECRETARY FOR ELECTRICITY DELIVERY AND ENERGY RELIABILITY U.S. DEPARTMENT OF ENERGY BEFORE THE

Homeland Open Security Technology HOST Program

Smart Meter Capabilities and Implications for Net Metering. MADRI Smart Meters and Distributed Resource Data Issues

Additional information >>> HERE <<<

Panel Session: Lessons Learned in Smart Grid Cybersecurity

National Cybersecurity Challenges and NIST. Donna F. Dodson Chief Cybersecurity Advisor ITL Associate Director for Cybersecurity

Cybersecurity and the Evolving Role of State Regulation: How it Impacts the California Public Utilities Commission

Cyber Risk to Help Shape Industry Trends in 2014

12/4/2013. Regulatory Updates. Eric M. Wright, CPA, CITP. Schneider Downs & Co., Inc. December 5, 2013

Framework for Improving Critical Infrastructure Cybersecurity

Facilitated Self-Evaluation v1.0

Community Cyber Security. Center for Infrastructure Assurance and Security

NISTIR 7359 Information Security Guide For Government Executives

Transcription:

Cyber Security Working Group National Institute of Standards and Technology U.S. Department of Commerce 1

Energy Independence and Security Act In the Energy Independence and Security Act (EISA) of 2007, Congress established the development of a Smart Grid as a national policy goal. Under EISA, NIST is directed to coordinate the development of a framework that includes protocols and model standards for information management to achieve interoperability of smart grid devices and systems as well as maintain the reliability and security of the electricity infrastructure. 2

NIST Three Phase Plan PHASE 1 Identify an initial set of existing consensus standards and develop a roadmap to fill gaps PHASE 2 Establish public/private Standards Panel to provide ongoing recommendations for new/revised standards PHASE 3 Testing and Certification Framework 2009 2010 3

President s Cyberspace Policy Review as the United States deploys new Smart Grid technology, the Federal government must ensure that security standards are developed and adopted to avoid creating unexpected opportunities for adversaries to penetrate these systems or conduct large-scale attacks. 4

Cyber Security Working Group (CSWG) To address the cross-cutting issue of cyber security, NIST established the Cyber Security Coordination Task Group (CSCTG) in March 2009. Moved under the NIST Smart Grid Interoperability Panel (SGIP) as a standing working group and was renamed the Cyber Security Working Group (SGIP CSWG). The CSWG now has more than 500 participants from the private sector (including vendors and service providers), academia, regulatory organizations, national research laboratories, and federal agencies. 5

The CSWG Management Team Marianne Swanson NIST Chair Bill Hunteman DOE, Vice Chair Alan Greenberg Boeing, Vice Chair Dave Dalva CISCO, Vice Chair Mark Enstrom Neustar, Secretary Tanya Brewer NIST Victoria Yan Booz Allen Hamilton Sandy Bacik - EnerNex 6

CSWG Meeting Info Weekly telecon Teleconference Day & Time: Mondays, 11am Eastern Time Call-in number: 866-793-6322 Participant passcode: 3836162 7

CWSG Subgroups and Leads AMI Security Group Darren Highfill, Ed Beroset Architecture Group Sandy Bacik Bottom Up Group Andrew Wright; Daniel Thanos Crypto and Key Management Group Daniel Thanos; Doug Biggs; Tony Metke Design Principles Group Daniel Thanos Privacy Group Rebecca Herold R & D Group Isaac Ghansah; Daniel Thanos Security Testing and Certification Group Nelson Hastings, Sandy Bacik, and Robert Former Standards Group Frances Cleveland Vulnerabilities Group Matt Carpenter, Matt Thomson 8

Guidelines for Smart Grid Cyber Security NIST Interagency Report 7628 - August 2010 Development of the document lead by NIST Represents significant coordination among Federal agencies Private sector Regulators Academics 9

NISTIR 7628 What it IS and IS NOT What it IS A tool for organizations that are researching, designing, developing, and implementing Smart Grid technologies May be used as a guideline to evaluate the overall cyber risks to a Smart Grid system during the design phase and during system implementation and maintenance Guidance for organizations Each organization must develop its own cyber security strategy (including a risk assessment methodology) for the Smart Grid. What it IS NOT It does not prescribe particular solutions It is not mandatory 10

New Activities Introduction to NISTIR 7628 20 Page description of the document content Written for utility or security personnel SGIP Priority Action Plan (PAP) Collaboration Cyber Security Review of Standards Completed - 5 Common Information Model Standards, NEMA Smart Meter Upgradeability Standard, 3 SAE Standards, the AEIC Metering Guidelines, the NAESBY Energy Usage Information, NIST Wireless Guidelines (future NISTIR), OASIS WS-Calendar Future - AMI Standards and Renewables Standards Ongoing work by some of the Subgroups 11

Outreach Completed University of Washington - Seattle, 20-21 July 2010 Cal Poly Pomona, 10-11 August 2010 CPUC San Francisco, 28-29 September 2010 University of Illinois Champaign, 5 November 2010 Georgia Tech Atlanta, 18-19 November 2010 (following NARUC meeting) 12

Outreach Going Forward Northeastern University Boston, MA 18 January 2010 New York PUC Albany, NY 19 January 2010 Ohio PUC Columbus, OH 26 January 2011 University of Maryland, Baltimore Co. Baltimore, MD 15 February 2011 Public Utility Commission of Texas 23 February 2011 13

How to Participate in CSWG NIST Smart Grid portal http://nist.gov/smartgrid Cyber Security Working Group Lead: Marianne Swanson (marianne.swanson@nist.gov) NIST Support: Tanya Brewer (tbrewer@nist.gov) Cyber Security Twiki site http://collaborate.nist.gov/twikisggrid/bin/view/smartgrid/cybersecurityctg 14