SlideShare a Scribd company logo
1 of 12
Download to read offline
Reference Architecture for Electric
Energy OT and Accompanying Profiles
2
The SEI ETF is a working group composed of senior government, industry, and nonprofit representatives, stood up by the
Secretary of Energy as mandated by Sec. 5726 of the 2020 NDAA.
Through review of existing reference models and architectures, the Technical Project Team tasked with evaluating technology
and standards identified a gap that there is no existing commonly accepted reference architecture for ICS. To produce a new
model for ICS, the TPT reviewed 16 existing models—including the Purdue Enterprise Reference Architecture and
Methodology and DHS’s recommended practices for improving ICS cybersecurity through defense-in-depth strategies—and
developed a cumulative list of core elements that would fill gaps to make a more broadly applicable reference architecture
structure to build unique ICS profiles onto. Specifically, the TPT prioritized developing this reference architecture
 specifically for the electrical sector,
 not limited to localized industrial processes,
 focused on properties of information passing between devices, and
 flexible enough to reflect advances in technology and design practices.
To this end, the TPT developed the SEI ETF Reference Architecture for Electric Energy OT (RA) from which other domain-
specific profiles could be derived. Upon reaching consensus, the team further developed specific profiles for substation,
generation, distributed energy resources, and operation/network control center.
The RA and profiles are presented as a stack of six levels grouped into four zones. Each level contains a set of devices and
systems, with the physical processes and field devices on the lowest level and a hierarchy of processes and technical controls
in each level above. The profiles also include new conceptual elements: security features and participating parties assigned
to each of the six levels of the model.
The SEI ETF Reference Architecture for Electric Energy OT serves as a baseline for the other profiles and introduces elements
common to all the profiles, such as the five columns across all levels (security level/name, typical device examples, function,
security features, actors). The Generic Profile includes six security levels spread across four zones: physical assets, operations,
enterprise, and public. Zones are separated by demilitarized zones (DMZs), network segments typically located between two
firewalls.
Moving towards security implementation, the RA and profiles can be used as a starting point for the Engineered
Cybersecurity Process flow, as detailed in slide 11.
3/8/2022
Introduction
3 3/8/2022
Reference Architecture for Electric Energy OT
Level 4 – Business/
Enterprise Level
Level 3 – Control
Center Level
Level 2 – Facility
Level
Level 1 – Subsystem
Level
Level 0 –
Process level
Level 5 – Internet
/Cloud Level
NCITs
Merging
Units
Protection
Breaker
I/O
CT/PT
Merging
Units
Indicators
Sensors
RTU /
Gateways
Local
HMIs
Domain Name
System Server
Public Cloud
Servers
Web
Servers
Domain
Controllers
Business
Servers
Operator
Workstations
SCADA/
Application Servers
Database
Servers
I/O Servers
Domain
Controller
Engineering
Workstations
Data Acquisition, Telemetry,
Process Control
Physical
Assets
Zone
Operations
Zone
Enterprise
Zone
External
Communication
Internal Business
Communication
Subsystem
Controllers
IEDs
Monitoring
Internal Operational
Communication
Process Data Conversion, Local
Control, Asset Monitoring
Physical Process Interface
Private
Cloud
Servers
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
DMZ – Web Servers, Email Servers, Remote Access Server
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Public
Zone
Security
Features
Participating
Parties
Typical Device
Examples
Security Level/
Name
Function
Note: RA does not include all possible security implementations (e.g. data diode vs firewall for ingress protection
4 3/8/2022
Substation Profile
• Risk Assessment
• Security Awareness
• Security Training
• Access Control Policies
• Management and Review
• IDS/IPS
• Network Monitoring
devices
• Encryption Control
• SIEM
• IT Manager
• Business strategy
• Planning
• OT Manager
• SCADA
• Operations & Maintenance
• EMS Support
• Remote Employees
• OT and IT Services
• Vendors
• 3rd Party Service providers
• OEM/vendors
• Remote monitoring
• Device software updates
• OT Manager
• Eng/Designer
• Relay Tech
• Field Service Tech
Level 4 – Business/
Enterprise Level
Level 3 – Control
Center Level
Level 2 – Facility
Level
Level 1 – Subsystem
Level
Level 0 –
Process level
Level 5 – Internet
/Cloud Level
NCITs Merging Units
Protection
Breaker I/O
CT/PT Merging Units Indicators
Sensors
RTU /
Gateways
Local
HMIs
Web Servers
Email Servers
Web
Servers
Domain
Controllers
Business
Servers
Operator
Workstations
SCADA/Application Servers
Database
Servers
I/O Servers
Domain
Controller
Engineering
Workstations
Data Acquisition, Telemetry,
Process Control
Physical
Assets
Zone
Operations
Zone
Enterprise
Zone
External
Communication
Internal Business
Communication
Bay Controllers
IEDs
Monitoring
Internal Operational
Communication
Process Data Conversion, Local
Control, Asset Monitoring
Physical Process Interface
Enterprise
Desktops
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
DMZ – Web Servers, Email Servers, Remote Access Server
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Public
Zone
Private/
Utility
Cloud
Cloud servers
Security Level/
Name
Typical Devices Function
Security
Features
Participating
Parties
• Access Control Policies
• Device Hardening
• Security Logging
• Patch Management
• Malware Protection
• Data Integrity Protection
• IDS/IPS
5 3/8/2022
Generation Profile
• Risk Assessment
• Security Awareness
• Security Training
• IT Manager
• Business strategy
• Planning
• 3rd Party Service providers
• OEM/vendors
• Remote monitoring
• Device software updates
Level 4 – Business/
Enterprise Level
Level 3 – Control
Center Level
Level 2 – Facility
Level (Plant/Site)
Level 1 – Subsystem
Level
(Generating Unit)
Level 0 –
Process level
Level 5 – Internet
/Cloud Level
Actuators
Protection
Breaker I/O
CT/PT Merging Units
Indicators Sensors
RTU /Gateways Historian
Web
Servers
Email
Servers
Web Servers
Domain Controllers Business Servers
Operator
Workstations
SCADA/
Application Servers
Database
Servers
I/O
Servers
Domain
Controller
Engineering
Workstations
Data Acquisition, Telemetry,
Process Control, Local Control
Physical
Assets
Zone
Operations
Zone
Enterprise
Zone
External
Communication
Internal Business
Communication
Subsystem
Controllers
IEDs
PLCs
Monitoring
Internal Operational
Communication
Process Data Conversion, Asset
Monitoring
Physical Process Interface
Private Cloud Servers
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
DMZ – Web Servers, Email Servers, Remote Access Server
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Public
Zone
Public Cloud
servers
Local HMIs
DCS/TCS
Security Level/
Name
Typical Devices Function
Security
Features
Participating
Parties
• OT Manager
• Operators
• Eng/Designer
• Relay Tech
• Field Service Tech
• Access Control Policies
• Device Hardening
• Security Logging
• Patch Management
• Malware Protection
• Data Integrity Protection
• IDS/IPS
• Access Control Policies
• Management and Review
• IDS/IPS
• Network Monitoring
devices
• Encryption Control
• SIEM
• OT Manager
• SCADA
• Operations & Maintenance
• EMS Support
• Remote Employees
• OT and IT Services
• Vendors
6 3/8/2022
Generation Physical Asset Zone (Expanded
Profile)
Level 2 – Facility
Level (Plant/Site)
Level 1 – Subsystem
Level
(Generating Unit) Protection
RTU /Gateways Historian
Engineering
Workstations
Data Acquisition, Telemetry,
Process Control, Local Control
Subsystem
Controllers
IEDs
PLCs
Monitoring
Process Data Conversion, Asset
Monitoring
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Local HMIs
DCS/TCS
Subsystem 1
Level 1 –
Subsystem Level
(Generating Unit)
Level 0 –
Process level
Actuators
Protection
Breaker I/O
CT/PT
Merging
Units
Indicators
Sensors
Engineering
Workstations
Subsystem
Controllers
IEDs
PLCs
Monitoring
Local HMIs
DCS/TCS
Subsystem 2
Level 1 –
Subsystem Level
(Generating Unit)
Level 0 –
Process level
Actuators
Protection
Breaker I/O
CT/PT
Merging
Units
Indicators
Sensors
Engineering
Workstations
Subsystem
Controllers
IEDs
PLCs
Monitoring
Local HMIs
DCS/TCS
7 3/8/2022
Distributed Energy Resources (DER) Profile
Level 4 – Business/
Enterprise Level
Level 3 – Control
Center Level
Level 2 – Facility
Level
Level 1 – Subsystem
Level
Level 0 –
Process level
Level 5 – Internet
/Cloud Level
Domain Name
System Server
Public Cloud
Servers
Web
Servers
Domain
Controllers
Business
Servers
Operator
Workstations
SCADA/Application Servers
Database
Servers
I/O Servers
Domain
Controller
Data Acquisition, Telemetry,
Process Control, Local Control
Physical
Assets
Zone
Operations
Zone
Enterprise
Zone
External
Communication
Internal Business
Communication
Internal Operational
Communication
Process Data Conversion, Local
Control, Asset Monitoring
Physical Process Interface
Private
Cloud
Servers
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
DMZ – Web Servers, Email Servers, Remote Access Server
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Public
Zone
• Risk Assessment
• Security Awareness
• Security Training
• IT Manager
• Business strategy
• Planning
• 3rd Party Service providers
• OEM/vendors
• Remote monitoring
• Device software updates
Private/
Utility
Cloud
Merging
Units
PMU
Breaker I/O
CT/PT
Merging
Units
Indicators
Protective
Relays
Engineering
Workstations
Subsystem
Controllers
IEDs
PLCs
Monitoring Local HMIs
RTU /Gateways
Local HMIs
Automation
Controllers
Not captured: Parallel control architectures
Engineering
Workstations
Net Metering
Security Level/
Name
Typical Devices Function
Security
Features
Participating
Parties
• OT Manager
• Solar farm/wind
farm/hydro site operator
• Relay Tech
• Field Service Tech
• Local Station SCADA
Network Monitoring
• Local Device Monitoring
• Ground State Truth Side
Channel Monitoring
• IDS/IPS
• Access Control Policies
• Management and Review
• IDS/IPS
• Network Monitoring
devices
• Encryption Control
• SIEM
• OT Manager
• SCADA
• Operations & Maintenance
• EMS Support
• Remote Employees
• OT and IT Services
• Vendors
8
DER DMZ
3/8/2022
Regional Utility Scale DER Profile
Level 4 – Business/
Enterprise Level
Level 5 – Internet
/Cloud Level
Domain Name System
Server, Webserver,
Email
Public Cloud Servers,
VPN/Remote Access
Server
Enterprise
Users
Domain
Controllers
Business
Servers
Enterprise
Zone
Regional Utility External Business
Communication
Regional Utility Business
Operations/ Communication
Private Cloud
Servers
Public
Zone
Historian
Human Machine Interfaces
Jump/Diagnostic Host
Patch/Backup Server
Regional Utility Operation
Aggregation
Security Level/
Name
Typical Devices Function
PV Site N
DER DMZ
Historian
Human Machine Interfaces
Jump/Diagnostic Host
Patch/Backup Server
Business and Operations
Communication
Level 3 – Control
Center Level
Level 2 – Local
Facility Level
Level 1 – Subsytem
Controller Level
Level 0 – Process/
Field Level
Internal DER Site
Operational
Communication
Process Data Conversion,
Local Control, Asset
Monitoring
Data Acquisition,
Telemetry, Process
Control, Local Control
Physical Process
Interface
Operator HMI
Workstations
SCADA/Application Servers
Database
Servers
I/O Servers
Domain
Controller
RTU/
Gateways
Protective Relays
Net Metering
Engineering
Workstations
Automation
Controllers
IEDs
PLCs Monitoring
Subsystem
Controllers
Local HMIs
Local HMIs
Engineering
Workstations
Indicators
CT/PT
Merging
Units
Breaker
I/O
Merging
Units
PMU
Wind Site N+1
DER DMZ
Historian
Human Machine Interfaces
Jump/Diagnostic Host
Patch/Backup Server
Business and Operations
Communication
Level 3 – Control
Center Level
Level 2 – Local
Facility Level
Level 1 – Subsytem
Controller Level
Level 0 – Process/
Field Level
Internal DER Site
Operational
Communication
Process Data Conversion,
Local Control, Asset
Monitoring
Data Acquisition,
Telemetry, Process
Control, Local Control
Physical Process
Interface
Operator HMI
Workstations
SCADA/Application Servers
Database
Servers
I/O Servers
Domain
Controller
RTU/
Gateways
Protective Relays
Net Metering
Engineering
Workstations
Automation
Controllers
IEDs
PLCs Monitoring
Subsystem
Controllers
Local HMIs
Local HMIs
Engineering
Workstations
Indicators
CT/PT
Merging
Units
Breaker
I/O
Merging
Units
PMU
Hybrid Site N
DER DMZ
Historian
Human Machine Interfaces
Jump/Diagnostic Host
Patch/Backup Server
Business and Operations
Communication
Level 3 – Control
Center Level
Level 2 – Local
Facility Level
Level 1 – Subsytem
Controller Level
Level 0 – Process/
Field Level
Internal DER Site
Operational
Communication
Process Data Conversion,
Local Control, Asset
Monitoring
Data Acquisition,
Telemetry, Process
Control, Local Control
Physical Process
Interface
Operator HMI
Workstations
SCADA/Application Servers
Database
Servers
I/O Servers
Domain
Controller
RTU/
Gateways
Protective Relays
Net Metering
Engineering
Workstations
Automation
Controllers
IEDs
PLCs Monitoring
Subsystem
Controllers
Local HMIs
Local HMIs
Engineering
Workstations
Indicators
CT/PT
Merging
Units
Breaker
I/O
Merging
Units
PMU
9
Level 3.2 –
Network Control
and Database Level
Level 3.1 –
Communication
Level
Level 4 – Business/
Enterprise Level
• OT Manager
• Maintenance
• OT Services
• IT Services
• Vendors
• EMS Support
• Remote Employees
• Network monitoring
devices
• IDS/IPS
• Encryption Control
• Access Control
• SIEM
Level 5 – Internet
DMZ/Cloud Level
• Risk Assessment
• Security Awareness
• Security Training
• Access Control Policies
• Management and
Review
• IDS/IPS
• IT Manager
• Business strategy
• Planning
• OT Manager
• SCADA
• Operations
• EMS Support
• Remote Employees
• 3rd Party Service providers
• OEM/vendors
• Remote monitoring
• Device software
updates
Web
Servers
Email
Servers
Cloud
Servers
Web
Servers
Domain
Controllers
Business
Servers
Enterprise
Desktops
Operations
Zone
Enterprise
Zone
Level 3.3 –
Operator Room
Operator
Workstations
Domain
Controller
Engineering
Workstations
SCADA/
Application
Servers
Database
Servers
I/O
Servers
Situational
Awareness
Network
Monitoring
Historian
Servers
HMI/Map
board
Front End Processor collecting Data from the Stations
and Substations and sending control signals to the
Stations and Substations
Comms
to
RC/BA
Comms to
Neighboring Entities
Comms between Main
and Backup Control
Center
RAS
Public
Zone
External
Communication
Internal Business
Communication
Patch Server, Electronic Access Control or Monitoring Systems, Physical
Access Control System, Vulnerability Scanner, Baseline Server, Anti-virus
Server, Log Server Private/
Utility
Cloud
DMZ –
Internal
Operational
Communication
Control Center Profile
Security Level/
Name
Typical Devices Function
Security
Features
Participating
Parties
3/8/2022
10
Distribution Substation
Transmission Substation Generation Plant
Level 3.2 –
Network Control
and Database Level
Level 3.1 –
Communication
Level
Level 4 – Business/
Enterprise Level
Level 5 – Internet
DMZ/Cloud Level
Web
Servers
Email
Servers
Cloud
Servers
Web
Servers
Domain
Controllers
Business
Servers
Enterprise
Desktops
Operations
Zone
Enterprise
Zone
Level 3.3 –
Operator Room
Operator
Workstations
Domain
Controller
Engineering
Workstations
SCADA/
Application
Servers
Database
Servers
I/O
Servers
Situational
Awareness
Network
Monitoring
Historian
Servers
HMI/Map
board
Front End Processor collecting Data from the Stations
and Substations and sending control signals to the
Stations and Substations
Coms to
RC/BA
Coms to Neighboring
Entities
Coms between Main and
Backup Control Center
RAS
Public
Zone
Patch Server, Electronic Access Control or Monitoring Systems, Physical
Access Control System, Vulnerability Scanner, Baseline Server, Anti-virus
Server, Log Server Private/
Utility
Cloud
DMZ –
Security Level/
Name
Typical Devices
Control
Center
(Expanded
Profile)
Level 2 –
Facility Level
Level 1 –
Subsystem Level
Level 0 –
Process level
Protection
Breaker
I/O
CT/PT
Merging
Units
Indicators
Sensors
RTU
/Gateways
NCITs
Merging
Units
Engineering
Workstations
Data Acquisition, Telemetry,
Process Control, Local
Control
Subsystem
Controllers
IEDs
Monitoring
Process Data Conversion, Local
Control, Asset Monitoring
Physical Process Interface
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Local
HMIs
Physical
Assets
Zone
Level 2 –
Facility Level
Level 1 –
Subsystem Level
Level 0 –
Process level
Protection
Breaker
I/O
CT/PT
Merging
Units
Indicators
Sensors
RTU
/Gateways
NCITs
Merging
Units
Engineering
Workstations
Data Acquisition, Telemetry,
Process Control, Local
Control
Subsystem
Controllers
IEDs
Monitoring
Process Data Conversion, Local
Control, Asset Monitoring
Physical Process Interface
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Local
HMIs
Physical
Assets
Zone
Level 2 – Facility
Level (Plant/Site)
Level 1 – Subsystem
Level
(Generating Unit)
Level 0 –
Process level
Actuators
Protection
Breaker I/O
CT/PT Merging Units
Indicators Sensors
RTU /Gateways Historian
Engineering
Workstations
Data Acquisition, Telemetry,
Process Control, Local Control
Physical
Assets
Zone
Subsystem
Controllers
IEDs
PLCs
Monitoring
Process Data Conversion, Asset
Monitoring
Physical Process Interface
DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server
Local HMIs
DCS/TCS
3/8/2022
11
Engineered Cybersecurity Process Flow
Reference Architecture to Security Implementation
Reference
Architecture
• Starting point
used for
communication
and
organizational
awareness
Reference
Architecture
Profiles
• Templates for OT
control system
including
adaptation for
OT applications
Security
Concept
• High level
overview of the
main
cybersecurity
objectives
including
definitions of
security features ,
necessary
security
functions
Security
Design
• Detailed security
solution and
specification of
cyber assets,
security features
and
methodology to
support the
security concept
Security Risk
Assessment
• Cyber Asset
registry with
detailed
functions
• Hazard analysis
with
consequences
assessment
• Risk profile
developed
Security
Implementation
• Execution of the
security solution
per the security
design
System
Architecture
• Security overview
defining the
system
components,
interfaces, data
flow and the
preliminary
zoning of the
design
YOU ARE
HERE
3/8/2022
12
 AOO: Asset Owner-Operator
 ICS: Industrial Control System
 CESER: Office of Cybersecurity,
Energy Security, and Emergency
Response
 CT/PT: Current Transformer/Potential
Transformer
 DCS/TCS: Distributed Control
System/Transmission Control System
 DER: Distributed Energy Resource
 DMZ: Demilitarized Zone
 EMS: Energy Management System
 ENG: Engineering
 HMI: Human Machine Interface
 I&C: Instrumentation and Control
 IDS/IPS: Intrusion Detection
System/Intrusion Prevention System
 IED: Intelligent Electronic Device
 IEEE: Institute of Electrical and
Electronics Engineers
 INL: Idaho National Lab
 I/O: Input/Output
 IT: Information Technology
 NCIT: Non-Conventional Instrument
Transformers
 NDAA: National Defense
Authorization Act
 NIST: National Institute of Standards
and Technology
 NREL: National Renewable Energy
Laboratory
 O&M: Operations and Maintenance
 OEM: Original Equipment
Manufacturer
 OT: Operational Technology
 PLC: Programmable Logic Controller
 PMU: Phasor Measurement Unit
 RAS: Remote Access Server
 RC/BA: Reliability
Coordinator/Balancing Authority
 RTU: Remote Terminal Unit
 SCADA: Supervisory Control and
Data Acquisition
 SEI ETF: Securing Energy
Infrastructure Executive Task Force
 SIEM: Security Information and Event
Management
 VPN: Virtual Private Network
3/8/2022
Appendix A: Acronyms and Abbreviations

More Related Content

Similar to Reference Architecture for Electric Energy OT.pdf

Stop Wasting Energy on M2M
Stop Wasting Energy on M2MStop Wasting Energy on M2M
Stop Wasting Energy on M2MEurotech
 
Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...
Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...
Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...Deepak Shankar
 
Standardizing the tee with global platform and RISC-V
Standardizing the tee with global platform and RISC-VStandardizing the tee with global platform and RISC-V
Standardizing the tee with global platform and RISC-VRISC-V International
 
Sfa community of practice a natural way of building
Sfa community of practice  a natural way of buildingSfa community of practice  a natural way of building
Sfa community of practice a natural way of buildingChuck Speicher
 
Nist 800 82
Nist 800 82Nist 800 82
Nist 800 82majolic
 
Vibro box sitel midih-presentation oc2
Vibro box sitel midih-presentation oc2Vibro box sitel midih-presentation oc2
Vibro box sitel midih-presentation oc2MIDIH_EU
 
SDN_and_NFV_technologies_in_IoT_Networks
SDN_and_NFV_technologies_in_IoT_NetworksSDN_and_NFV_technologies_in_IoT_Networks
SDN_and_NFV_technologies_in_IoT_NetworksSrinivasa Addepalli
 
AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014KBIZEAU
 
It 443 lecture 1
It 443 lecture 1It 443 lecture 1
It 443 lecture 1elisha25
 
Real World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoTReal World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoTEurotech
 
Embedded Security and the IoT – Challenges, Trends and Solutions
Embedded Security and the IoT – Challenges, Trends and SolutionsEmbedded Security and the IoT – Challenges, Trends and Solutions
Embedded Security and the IoT – Challenges, Trends and SolutionsReal-Time Innovations (RTI)
 
SCADA Cyber Sec | ISACA 2013 | Patricia Watson
SCADA Cyber Sec | ISACA 2013 | Patricia WatsonSCADA Cyber Sec | ISACA 2013 | Patricia Watson
SCADA Cyber Sec | ISACA 2013 | Patricia WatsonPatricia M Watson
 
Software Defined Substation Intelligence, Automation and Control
Software Defined Substation Intelligence, Automation and ControlSoftware Defined Substation Intelligence, Automation and Control
Software Defined Substation Intelligence, Automation and ControlBastian Fischer
 
Bridging the Industrial IoT Gap
Bridging the Industrial IoT GapBridging the Industrial IoT Gap
Bridging the Industrial IoT GapMarty Pejko
 
Group 5 IoT Architecture Layer
Group 5 IoT Architecture LayerGroup 5 IoT Architecture Layer
Group 5 IoT Architecture LayerMarcus Maneja
 
Io t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425cIo t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425cCharles Li
 
IRJET- Security Analysis and Improvements to IoT Communication Protocols ...
IRJET-  	  Security Analysis and Improvements to IoT Communication Protocols ...IRJET-  	  Security Analysis and Improvements to IoT Communication Protocols ...
IRJET- Security Analysis and Improvements to IoT Communication Protocols ...IRJET Journal
 
Final Presentation
Final PresentationFinal Presentation
Final Presentationchris odle
 

Similar to Reference Architecture for Electric Energy OT.pdf (20)

Stop Wasting Energy on M2M
Stop Wasting Energy on M2MStop Wasting Energy on M2M
Stop Wasting Energy on M2M
 
Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...
Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...
Mastering IoT Design: Sense, Process, Connect: Processing: Turning IoT Data i...
 
Standardizing the tee with global platform and RISC-V
Standardizing the tee with global platform and RISC-VStandardizing the tee with global platform and RISC-V
Standardizing the tee with global platform and RISC-V
 
Sfa community of practice a natural way of building
Sfa community of practice  a natural way of buildingSfa community of practice  a natural way of building
Sfa community of practice a natural way of building
 
Nist 800 82
Nist 800 82Nist 800 82
Nist 800 82
 
Vibro box sitel midih-presentation oc2
Vibro box sitel midih-presentation oc2Vibro box sitel midih-presentation oc2
Vibro box sitel midih-presentation oc2
 
SDN_and_NFV_technologies_in_IoT_Networks
SDN_and_NFV_technologies_in_IoT_NetworksSDN_and_NFV_technologies_in_IoT_Networks
SDN_and_NFV_technologies_in_IoT_Networks
 
AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014
 
It 443 lecture 1
It 443 lecture 1It 443 lecture 1
It 443 lecture 1
 
Real World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoTReal World IoT Architectures and Projects with Eclipse IoT
Real World IoT Architectures and Projects with Eclipse IoT
 
Embedded Security and the IoT – Challenges, Trends and Solutions
Embedded Security and the IoT – Challenges, Trends and SolutionsEmbedded Security and the IoT – Challenges, Trends and Solutions
Embedded Security and the IoT – Challenges, Trends and Solutions
 
SCADA Cyber Sec | ISACA 2013 | Patricia Watson
SCADA Cyber Sec | ISACA 2013 | Patricia WatsonSCADA Cyber Sec | ISACA 2013 | Patricia Watson
SCADA Cyber Sec | ISACA 2013 | Patricia Watson
 
Software Defined Substation Intelligence, Automation and Control
Software Defined Substation Intelligence, Automation and ControlSoftware Defined Substation Intelligence, Automation and Control
Software Defined Substation Intelligence, Automation and Control
 
Bridging the Industrial IoT Gap
Bridging the Industrial IoT GapBridging the Industrial IoT Gap
Bridging the Industrial IoT Gap
 
Group 5 IoT Architecture Layer
Group 5 IoT Architecture LayerGroup 5 IoT Architecture Layer
Group 5 IoT Architecture Layer
 
Io t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425cIo t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425c
 
IRJET- Security Analysis and Improvements to IoT Communication Protocols ...
IRJET-  	  Security Analysis and Improvements to IoT Communication Protocols ...IRJET-  	  Security Analysis and Improvements to IoT Communication Protocols ...
IRJET- Security Analysis and Improvements to IoT Communication Protocols ...
 
Internet of things
Internet of thingsInternet of things
Internet of things
 
Internet of things
Internet of thingsInternet of things
Internet of things
 
Final Presentation
Final PresentationFinal Presentation
Final Presentation
 

Recently uploaded

(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCRsoniya singh
 
Top Call Girls In Arjunganj ( Lucknow ) ✨ 8923113531 ✨ Cash Payment
Top Call Girls In Arjunganj ( Lucknow  ) ✨ 8923113531 ✨  Cash PaymentTop Call Girls In Arjunganj ( Lucknow  ) ✨ 8923113531 ✨  Cash Payment
Top Call Girls In Arjunganj ( Lucknow ) ✨ 8923113531 ✨ Cash Paymentanilsa9823
 
Product Catalog Bandung Home Decor Design Furniture
Product Catalog Bandung Home Decor Design FurnitureProduct Catalog Bandung Home Decor Design Furniture
Product Catalog Bandung Home Decor Design Furniturem3resolve
 
(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCRsoniya singh
 
(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCRsoniya singh
 
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...LHelferty
 
(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCRsoniya singh
 
Delhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girl
Delhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girlDelhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girl
Delhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girlsoniya singh
 
Cheap Rate ➥8448380779 ▻Call Girls In Sector 56 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 56 GurgaonCheap Rate ➥8448380779 ▻Call Girls In Sector 56 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 56 GurgaonDelhi Call girls
 
Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝soniya singh
 
Top Call Girls In Indira Nagar Lucknow ( Lucknow ) 🔝 8923113531 🔝 Cash Payment
Top Call Girls In Indira Nagar Lucknow ( Lucknow  ) 🔝 8923113531 🔝  Cash PaymentTop Call Girls In Indira Nagar Lucknow ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment
Top Call Girls In Indira Nagar Lucknow ( Lucknow ) 🔝 8923113531 🔝 Cash Paymentanilsa9823
 
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCRsoniya singh
 
VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...
VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...
VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...aditipandeya
 
Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...
Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...
Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...anilsa9823
 
Cheap Rate ➥8448380779 ▻Call Girls In Sector 55 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 55 GurgaonCheap Rate ➥8448380779 ▻Call Girls In Sector 55 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 55 GurgaonDelhi Call girls
 
Cheap Rate ➥8448380779 ▻Call Girls In Sector 54 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 54 GurgaonCheap Rate ➥8448380779 ▻Call Girls In Sector 54 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 54 GurgaonDelhi Call girls
 
(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCRsoniya singh
 
(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCRsoniya singh
 
(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCRsoniya singh
 

Recently uploaded (20)

(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Safdarjung Enclave 🔝 Delhi NCR
 
Top Call Girls In Arjunganj ( Lucknow ) ✨ 8923113531 ✨ Cash Payment
Top Call Girls In Arjunganj ( Lucknow  ) ✨ 8923113531 ✨  Cash PaymentTop Call Girls In Arjunganj ( Lucknow  ) ✨ 8923113531 ✨  Cash Payment
Top Call Girls In Arjunganj ( Lucknow ) ✨ 8923113531 ✨ Cash Payment
 
Product Catalog Bandung Home Decor Design Furniture
Product Catalog Bandung Home Decor Design FurnitureProduct Catalog Bandung Home Decor Design Furniture
Product Catalog Bandung Home Decor Design Furniture
 
(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Siri Fort 🔝 Delhi NCR
 
(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Tikri Kalan 🔝 Delhi NCR
 
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
 
(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Babarpur 🔝 Delhi NCR
 
Pakistani Jumeirah Call Girls # +971559085003 # Pakistani Call Girls In Jumei...
Pakistani Jumeirah Call Girls # +971559085003 # Pakistani Call Girls In Jumei...Pakistani Jumeirah Call Girls # +971559085003 # Pakistani Call Girls In Jumei...
Pakistani Jumeirah Call Girls # +971559085003 # Pakistani Call Girls In Jumei...
 
Delhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girl
Delhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girlDelhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girl
Delhi Munirka 🔝 Call Girls Service 🔝 ( 8264348440 ) unlimited hard sex call girl
 
Cheap Rate ➥8448380779 ▻Call Girls In Sector 56 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 56 GurgaonCheap Rate ➥8448380779 ▻Call Girls In Sector 56 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 56 Gurgaon
 
Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Bawana Delhi reach out to us at 🔝8264348440🔝
 
Top Call Girls In Indira Nagar Lucknow ( Lucknow ) 🔝 8923113531 🔝 Cash Payment
Top Call Girls In Indira Nagar Lucknow ( Lucknow  ) 🔝 8923113531 🔝  Cash PaymentTop Call Girls In Indira Nagar Lucknow ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment
Top Call Girls In Indira Nagar Lucknow ( Lucknow ) 🔝 8923113531 🔝 Cash Payment
 
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
 
VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...
VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...
VIP 7001035870 Find & Meet Hyderabad Call Girls Secunderabad high-profile Cal...
 
Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...
Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...
Lucknow 💋 Escort Service in Lucknow ₹7.5k Pick Up & Drop With Cash Payment 89...
 
Cheap Rate ➥8448380779 ▻Call Girls In Sector 55 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 55 GurgaonCheap Rate ➥8448380779 ▻Call Girls In Sector 55 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 55 Gurgaon
 
Cheap Rate ➥8448380779 ▻Call Girls In Sector 54 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 54 GurgaonCheap Rate ➥8448380779 ▻Call Girls In Sector 54 Gurgaon
Cheap Rate ➥8448380779 ▻Call Girls In Sector 54 Gurgaon
 
(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Green Park 🔝 Delhi NCR
 
(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shiv Ram Park 🔝 Delhi NCR
 
(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Khanpur 🔝 Delhi NCR
 

Reference Architecture for Electric Energy OT.pdf

  • 1. Reference Architecture for Electric Energy OT and Accompanying Profiles
  • 2. 2 The SEI ETF is a working group composed of senior government, industry, and nonprofit representatives, stood up by the Secretary of Energy as mandated by Sec. 5726 of the 2020 NDAA. Through review of existing reference models and architectures, the Technical Project Team tasked with evaluating technology and standards identified a gap that there is no existing commonly accepted reference architecture for ICS. To produce a new model for ICS, the TPT reviewed 16 existing models—including the Purdue Enterprise Reference Architecture and Methodology and DHS’s recommended practices for improving ICS cybersecurity through defense-in-depth strategies—and developed a cumulative list of core elements that would fill gaps to make a more broadly applicable reference architecture structure to build unique ICS profiles onto. Specifically, the TPT prioritized developing this reference architecture  specifically for the electrical sector,  not limited to localized industrial processes,  focused on properties of information passing between devices, and  flexible enough to reflect advances in technology and design practices. To this end, the TPT developed the SEI ETF Reference Architecture for Electric Energy OT (RA) from which other domain- specific profiles could be derived. Upon reaching consensus, the team further developed specific profiles for substation, generation, distributed energy resources, and operation/network control center. The RA and profiles are presented as a stack of six levels grouped into four zones. Each level contains a set of devices and systems, with the physical processes and field devices on the lowest level and a hierarchy of processes and technical controls in each level above. The profiles also include new conceptual elements: security features and participating parties assigned to each of the six levels of the model. The SEI ETF Reference Architecture for Electric Energy OT serves as a baseline for the other profiles and introduces elements common to all the profiles, such as the five columns across all levels (security level/name, typical device examples, function, security features, actors). The Generic Profile includes six security levels spread across four zones: physical assets, operations, enterprise, and public. Zones are separated by demilitarized zones (DMZs), network segments typically located between two firewalls. Moving towards security implementation, the RA and profiles can be used as a starting point for the Engineered Cybersecurity Process flow, as detailed in slide 11. 3/8/2022 Introduction
  • 3. 3 3/8/2022 Reference Architecture for Electric Energy OT Level 4 – Business/ Enterprise Level Level 3 – Control Center Level Level 2 – Facility Level Level 1 – Subsystem Level Level 0 – Process level Level 5 – Internet /Cloud Level NCITs Merging Units Protection Breaker I/O CT/PT Merging Units Indicators Sensors RTU / Gateways Local HMIs Domain Name System Server Public Cloud Servers Web Servers Domain Controllers Business Servers Operator Workstations SCADA/ Application Servers Database Servers I/O Servers Domain Controller Engineering Workstations Data Acquisition, Telemetry, Process Control Physical Assets Zone Operations Zone Enterprise Zone External Communication Internal Business Communication Subsystem Controllers IEDs Monitoring Internal Operational Communication Process Data Conversion, Local Control, Asset Monitoring Physical Process Interface Private Cloud Servers DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server DMZ – Web Servers, Email Servers, Remote Access Server DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Public Zone Security Features Participating Parties Typical Device Examples Security Level/ Name Function Note: RA does not include all possible security implementations (e.g. data diode vs firewall for ingress protection
  • 4. 4 3/8/2022 Substation Profile • Risk Assessment • Security Awareness • Security Training • Access Control Policies • Management and Review • IDS/IPS • Network Monitoring devices • Encryption Control • SIEM • IT Manager • Business strategy • Planning • OT Manager • SCADA • Operations & Maintenance • EMS Support • Remote Employees • OT and IT Services • Vendors • 3rd Party Service providers • OEM/vendors • Remote monitoring • Device software updates • OT Manager • Eng/Designer • Relay Tech • Field Service Tech Level 4 – Business/ Enterprise Level Level 3 – Control Center Level Level 2 – Facility Level Level 1 – Subsystem Level Level 0 – Process level Level 5 – Internet /Cloud Level NCITs Merging Units Protection Breaker I/O CT/PT Merging Units Indicators Sensors RTU / Gateways Local HMIs Web Servers Email Servers Web Servers Domain Controllers Business Servers Operator Workstations SCADA/Application Servers Database Servers I/O Servers Domain Controller Engineering Workstations Data Acquisition, Telemetry, Process Control Physical Assets Zone Operations Zone Enterprise Zone External Communication Internal Business Communication Bay Controllers IEDs Monitoring Internal Operational Communication Process Data Conversion, Local Control, Asset Monitoring Physical Process Interface Enterprise Desktops DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server DMZ – Web Servers, Email Servers, Remote Access Server DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Public Zone Private/ Utility Cloud Cloud servers Security Level/ Name Typical Devices Function Security Features Participating Parties • Access Control Policies • Device Hardening • Security Logging • Patch Management • Malware Protection • Data Integrity Protection • IDS/IPS
  • 5. 5 3/8/2022 Generation Profile • Risk Assessment • Security Awareness • Security Training • IT Manager • Business strategy • Planning • 3rd Party Service providers • OEM/vendors • Remote monitoring • Device software updates Level 4 – Business/ Enterprise Level Level 3 – Control Center Level Level 2 – Facility Level (Plant/Site) Level 1 – Subsystem Level (Generating Unit) Level 0 – Process level Level 5 – Internet /Cloud Level Actuators Protection Breaker I/O CT/PT Merging Units Indicators Sensors RTU /Gateways Historian Web Servers Email Servers Web Servers Domain Controllers Business Servers Operator Workstations SCADA/ Application Servers Database Servers I/O Servers Domain Controller Engineering Workstations Data Acquisition, Telemetry, Process Control, Local Control Physical Assets Zone Operations Zone Enterprise Zone External Communication Internal Business Communication Subsystem Controllers IEDs PLCs Monitoring Internal Operational Communication Process Data Conversion, Asset Monitoring Physical Process Interface Private Cloud Servers DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server DMZ – Web Servers, Email Servers, Remote Access Server DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Public Zone Public Cloud servers Local HMIs DCS/TCS Security Level/ Name Typical Devices Function Security Features Participating Parties • OT Manager • Operators • Eng/Designer • Relay Tech • Field Service Tech • Access Control Policies • Device Hardening • Security Logging • Patch Management • Malware Protection • Data Integrity Protection • IDS/IPS • Access Control Policies • Management and Review • IDS/IPS • Network Monitoring devices • Encryption Control • SIEM • OT Manager • SCADA • Operations & Maintenance • EMS Support • Remote Employees • OT and IT Services • Vendors
  • 6. 6 3/8/2022 Generation Physical Asset Zone (Expanded Profile) Level 2 – Facility Level (Plant/Site) Level 1 – Subsystem Level (Generating Unit) Protection RTU /Gateways Historian Engineering Workstations Data Acquisition, Telemetry, Process Control, Local Control Subsystem Controllers IEDs PLCs Monitoring Process Data Conversion, Asset Monitoring DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Local HMIs DCS/TCS Subsystem 1 Level 1 – Subsystem Level (Generating Unit) Level 0 – Process level Actuators Protection Breaker I/O CT/PT Merging Units Indicators Sensors Engineering Workstations Subsystem Controllers IEDs PLCs Monitoring Local HMIs DCS/TCS Subsystem 2 Level 1 – Subsystem Level (Generating Unit) Level 0 – Process level Actuators Protection Breaker I/O CT/PT Merging Units Indicators Sensors Engineering Workstations Subsystem Controllers IEDs PLCs Monitoring Local HMIs DCS/TCS
  • 7. 7 3/8/2022 Distributed Energy Resources (DER) Profile Level 4 – Business/ Enterprise Level Level 3 – Control Center Level Level 2 – Facility Level Level 1 – Subsystem Level Level 0 – Process level Level 5 – Internet /Cloud Level Domain Name System Server Public Cloud Servers Web Servers Domain Controllers Business Servers Operator Workstations SCADA/Application Servers Database Servers I/O Servers Domain Controller Data Acquisition, Telemetry, Process Control, Local Control Physical Assets Zone Operations Zone Enterprise Zone External Communication Internal Business Communication Internal Operational Communication Process Data Conversion, Local Control, Asset Monitoring Physical Process Interface Private Cloud Servers DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server DMZ – Web Servers, Email Servers, Remote Access Server DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Public Zone • Risk Assessment • Security Awareness • Security Training • IT Manager • Business strategy • Planning • 3rd Party Service providers • OEM/vendors • Remote monitoring • Device software updates Private/ Utility Cloud Merging Units PMU Breaker I/O CT/PT Merging Units Indicators Protective Relays Engineering Workstations Subsystem Controllers IEDs PLCs Monitoring Local HMIs RTU /Gateways Local HMIs Automation Controllers Not captured: Parallel control architectures Engineering Workstations Net Metering Security Level/ Name Typical Devices Function Security Features Participating Parties • OT Manager • Solar farm/wind farm/hydro site operator • Relay Tech • Field Service Tech • Local Station SCADA Network Monitoring • Local Device Monitoring • Ground State Truth Side Channel Monitoring • IDS/IPS • Access Control Policies • Management and Review • IDS/IPS • Network Monitoring devices • Encryption Control • SIEM • OT Manager • SCADA • Operations & Maintenance • EMS Support • Remote Employees • OT and IT Services • Vendors
  • 8. 8 DER DMZ 3/8/2022 Regional Utility Scale DER Profile Level 4 – Business/ Enterprise Level Level 5 – Internet /Cloud Level Domain Name System Server, Webserver, Email Public Cloud Servers, VPN/Remote Access Server Enterprise Users Domain Controllers Business Servers Enterprise Zone Regional Utility External Business Communication Regional Utility Business Operations/ Communication Private Cloud Servers Public Zone Historian Human Machine Interfaces Jump/Diagnostic Host Patch/Backup Server Regional Utility Operation Aggregation Security Level/ Name Typical Devices Function PV Site N DER DMZ Historian Human Machine Interfaces Jump/Diagnostic Host Patch/Backup Server Business and Operations Communication Level 3 – Control Center Level Level 2 – Local Facility Level Level 1 – Subsytem Controller Level Level 0 – Process/ Field Level Internal DER Site Operational Communication Process Data Conversion, Local Control, Asset Monitoring Data Acquisition, Telemetry, Process Control, Local Control Physical Process Interface Operator HMI Workstations SCADA/Application Servers Database Servers I/O Servers Domain Controller RTU/ Gateways Protective Relays Net Metering Engineering Workstations Automation Controllers IEDs PLCs Monitoring Subsystem Controllers Local HMIs Local HMIs Engineering Workstations Indicators CT/PT Merging Units Breaker I/O Merging Units PMU Wind Site N+1 DER DMZ Historian Human Machine Interfaces Jump/Diagnostic Host Patch/Backup Server Business and Operations Communication Level 3 – Control Center Level Level 2 – Local Facility Level Level 1 – Subsytem Controller Level Level 0 – Process/ Field Level Internal DER Site Operational Communication Process Data Conversion, Local Control, Asset Monitoring Data Acquisition, Telemetry, Process Control, Local Control Physical Process Interface Operator HMI Workstations SCADA/Application Servers Database Servers I/O Servers Domain Controller RTU/ Gateways Protective Relays Net Metering Engineering Workstations Automation Controllers IEDs PLCs Monitoring Subsystem Controllers Local HMIs Local HMIs Engineering Workstations Indicators CT/PT Merging Units Breaker I/O Merging Units PMU Hybrid Site N DER DMZ Historian Human Machine Interfaces Jump/Diagnostic Host Patch/Backup Server Business and Operations Communication Level 3 – Control Center Level Level 2 – Local Facility Level Level 1 – Subsytem Controller Level Level 0 – Process/ Field Level Internal DER Site Operational Communication Process Data Conversion, Local Control, Asset Monitoring Data Acquisition, Telemetry, Process Control, Local Control Physical Process Interface Operator HMI Workstations SCADA/Application Servers Database Servers I/O Servers Domain Controller RTU/ Gateways Protective Relays Net Metering Engineering Workstations Automation Controllers IEDs PLCs Monitoring Subsystem Controllers Local HMIs Local HMIs Engineering Workstations Indicators CT/PT Merging Units Breaker I/O Merging Units PMU
  • 9. 9 Level 3.2 – Network Control and Database Level Level 3.1 – Communication Level Level 4 – Business/ Enterprise Level • OT Manager • Maintenance • OT Services • IT Services • Vendors • EMS Support • Remote Employees • Network monitoring devices • IDS/IPS • Encryption Control • Access Control • SIEM Level 5 – Internet DMZ/Cloud Level • Risk Assessment • Security Awareness • Security Training • Access Control Policies • Management and Review • IDS/IPS • IT Manager • Business strategy • Planning • OT Manager • SCADA • Operations • EMS Support • Remote Employees • 3rd Party Service providers • OEM/vendors • Remote monitoring • Device software updates Web Servers Email Servers Cloud Servers Web Servers Domain Controllers Business Servers Enterprise Desktops Operations Zone Enterprise Zone Level 3.3 – Operator Room Operator Workstations Domain Controller Engineering Workstations SCADA/ Application Servers Database Servers I/O Servers Situational Awareness Network Monitoring Historian Servers HMI/Map board Front End Processor collecting Data from the Stations and Substations and sending control signals to the Stations and Substations Comms to RC/BA Comms to Neighboring Entities Comms between Main and Backup Control Center RAS Public Zone External Communication Internal Business Communication Patch Server, Electronic Access Control or Monitoring Systems, Physical Access Control System, Vulnerability Scanner, Baseline Server, Anti-virus Server, Log Server Private/ Utility Cloud DMZ – Internal Operational Communication Control Center Profile Security Level/ Name Typical Devices Function Security Features Participating Parties 3/8/2022
  • 10. 10 Distribution Substation Transmission Substation Generation Plant Level 3.2 – Network Control and Database Level Level 3.1 – Communication Level Level 4 – Business/ Enterprise Level Level 5 – Internet DMZ/Cloud Level Web Servers Email Servers Cloud Servers Web Servers Domain Controllers Business Servers Enterprise Desktops Operations Zone Enterprise Zone Level 3.3 – Operator Room Operator Workstations Domain Controller Engineering Workstations SCADA/ Application Servers Database Servers I/O Servers Situational Awareness Network Monitoring Historian Servers HMI/Map board Front End Processor collecting Data from the Stations and Substations and sending control signals to the Stations and Substations Coms to RC/BA Coms to Neighboring Entities Coms between Main and Backup Control Center RAS Public Zone Patch Server, Electronic Access Control or Monitoring Systems, Physical Access Control System, Vulnerability Scanner, Baseline Server, Anti-virus Server, Log Server Private/ Utility Cloud DMZ – Security Level/ Name Typical Devices Control Center (Expanded Profile) Level 2 – Facility Level Level 1 – Subsystem Level Level 0 – Process level Protection Breaker I/O CT/PT Merging Units Indicators Sensors RTU /Gateways NCITs Merging Units Engineering Workstations Data Acquisition, Telemetry, Process Control, Local Control Subsystem Controllers IEDs Monitoring Process Data Conversion, Local Control, Asset Monitoring Physical Process Interface DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Local HMIs Physical Assets Zone Level 2 – Facility Level Level 1 – Subsystem Level Level 0 – Process level Protection Breaker I/O CT/PT Merging Units Indicators Sensors RTU /Gateways NCITs Merging Units Engineering Workstations Data Acquisition, Telemetry, Process Control, Local Control Subsystem Controllers IEDs Monitoring Process Data Conversion, Local Control, Asset Monitoring Physical Process Interface DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Local HMIs Physical Assets Zone Level 2 – Facility Level (Plant/Site) Level 1 – Subsystem Level (Generating Unit) Level 0 – Process level Actuators Protection Breaker I/O CT/PT Merging Units Indicators Sensors RTU /Gateways Historian Engineering Workstations Data Acquisition, Telemetry, Process Control, Local Control Physical Assets Zone Subsystem Controllers IEDs PLCs Monitoring Process Data Conversion, Asset Monitoring Physical Process Interface DMZ – Historian, Backup Director, Patch Server, Remote Access/Jump Server Local HMIs DCS/TCS 3/8/2022
  • 11. 11 Engineered Cybersecurity Process Flow Reference Architecture to Security Implementation Reference Architecture • Starting point used for communication and organizational awareness Reference Architecture Profiles • Templates for OT control system including adaptation for OT applications Security Concept • High level overview of the main cybersecurity objectives including definitions of security features , necessary security functions Security Design • Detailed security solution and specification of cyber assets, security features and methodology to support the security concept Security Risk Assessment • Cyber Asset registry with detailed functions • Hazard analysis with consequences assessment • Risk profile developed Security Implementation • Execution of the security solution per the security design System Architecture • Security overview defining the system components, interfaces, data flow and the preliminary zoning of the design YOU ARE HERE 3/8/2022
  • 12. 12  AOO: Asset Owner-Operator  ICS: Industrial Control System  CESER: Office of Cybersecurity, Energy Security, and Emergency Response  CT/PT: Current Transformer/Potential Transformer  DCS/TCS: Distributed Control System/Transmission Control System  DER: Distributed Energy Resource  DMZ: Demilitarized Zone  EMS: Energy Management System  ENG: Engineering  HMI: Human Machine Interface  I&C: Instrumentation and Control  IDS/IPS: Intrusion Detection System/Intrusion Prevention System  IED: Intelligent Electronic Device  IEEE: Institute of Electrical and Electronics Engineers  INL: Idaho National Lab  I/O: Input/Output  IT: Information Technology  NCIT: Non-Conventional Instrument Transformers  NDAA: National Defense Authorization Act  NIST: National Institute of Standards and Technology  NREL: National Renewable Energy Laboratory  O&M: Operations and Maintenance  OEM: Original Equipment Manufacturer  OT: Operational Technology  PLC: Programmable Logic Controller  PMU: Phasor Measurement Unit  RAS: Remote Access Server  RC/BA: Reliability Coordinator/Balancing Authority  RTU: Remote Terminal Unit  SCADA: Supervisory Control and Data Acquisition  SEI ETF: Securing Energy Infrastructure Executive Task Force  SIEM: Security Information and Event Management  VPN: Virtual Private Network 3/8/2022 Appendix A: Acronyms and Abbreviations