SlideShare a Scribd company logo
Accelerating Grid Modernization
More information available on SGIP.org
Securing Networked Infrastructure
for the Energy Sector
November 13, 2014
Accelerating Grid Modernization
More information available on SGIP.org
INTRODUCTION
Tanya Brewer, Senior Information Technology Researcher
National Institute of Standards & Technology (NIST)
SGIP Smart Grid Cybersecurity Committee (SGCC)
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
Smart Grid Interoperability Panel
orchestrates the work
behind power grid
modernization
Accelerating Grid Modernization
More information available on SGIP.org
• Optimizes resources and time
• Avoids proprietary vendor lock-in
• Helps build technology roadmaps
• Simplifies decision making
SGIP Reduces Risks and Costs
SGIP is a collaborative, transparent, and
trusted forum to share standards
information and practical, hands-on
knowledge about deployments from
industry experts.
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
Agenda
• Introduction Tanya Brewer
• Main Presentation Jim McCarthy
• Q&A
• Closing Tanya Brewer
This meeting, and all SGIP activities, are governed by SGIP By-laws and policies - Intellectual Property Rights Policy and Antitrust Policy.
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
Securing Networked Infrastructure for
the Energy Sector
Jim McCarthy
National Cybersecurity Center of Excellence
SGIP Webinar
November 13, 2014
Accelerating Grid Modernization
More information available on SGIP.org
ABOUT THE NCCOE
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
8
STRATEGY
Vision
‣ A secure cyber infrastructure that inspires technological innovation
and fosters economic growth
Mission
‣ Collaborate with innovators to provide real-world, standards-based
cybersecurity capabilities that address business needs
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
9
TENETS
Standards-based
Modular
Usable
Repeatable
Open and transparent
Commercially available
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
10
APPROACH
We seek problems that are:
‣ Broadly relevant
‣ Technology-based
‣ Addressable with multiple commercially available technologies
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
11
REFERENCE DESIGNS
Use cases
‣ Sector-specific challenges
‣ Identified through industry engagement
Building blocks
‣ Technology-specific challenges
‣ Identified through public engagement
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
12
MODEL
Engage
‣ Work with community of interest to define problem
Explore
‣ Map security characteristics to standards, controls and best practices
‣ Circulate drafts and incorporate feedback
Partner
‣ Invite technology vendors to collaborate in our labs
Build
‣ Collaborate on design components
‣ Incorporate feedback from experts in technology community
Show
‣ Demonstrate reference designs
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
13
MODEL
Form small community
of interest
Provide input and
feedback to NCCoE
Expand
community
of interest
Submit feedback
on use cases to
NCCoE
Offer insights
on use cases
Community
Of Interest
Support deployment, revision and
maintenance of products as part of the
practice guide
Collaborate to develop reference
designs
Evangelize on behalf
of reference design
and practice guide
Deploy, test and
provide feedback on
the reference design
Provide regular feedback on use case builds
Technology
Partners
Submit letters
of interest
Speak at
sector-
specific events
Work with
COI to identify
cybersecurity
challenges
Host
sector-
specific
workshop
Review &
circulate
pre-release
use cases
Revise &
publish
draft use
cases
Revise use
cases &
invite
participation
from
technology
partners
Receive
technology
partners
letters
of interest
Demonstrate
reference designs
Discuss
improvements &
modifications
Publish
reference
design and
practice
guide
Develop
composed
reference
design
Form
build
teams
Sign
CRADAs
Host
partner day
Accelerating Grid Modernization
More information available on SGIP.org
14
CORE PARTNERS
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
IDENTITY AND ACCESS
MANAGEMENT
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
16
OVERVIEW
Goals
‣ Authenticate individuals and systems
‣ Enforce authorization control policies
‣ Unify IdAM services
‣ Protect generation, transmission and distribution
Business value
‣ Reduce costs
‣ Increase efficiency
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
17
DESIRED SOLUTION CHARACTERISTICS
‣ Authentication
‣ Authorization
‣ Access control
‣ Federation
‣ Provisioning
‣ Do not break the grid
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
18
EXAMPLE COMPONENT LIST
‣ Services for authenticating and authorizing users based on identity, role,
third-party affiliation (e.g., federation) or other attributes (e.g., attribute based
access control)
‣ Services for authenticating and authorizing devices
‣ Identity and access governance capability that translates human-readable
access needs into machine-readable authorizations
‣ Services for whitelisting applications
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
19
EXAMPLE COMPONENT LIST
‣ ICS equipment, such as remote terminal units (RTUs), programmable logic
controllers (PLCs) and relays, along with associated software and
communications equipment (e.g., radios, encryptors)
‣ Physical access control devices that use standard communication
interfaces
‣ Security incident and event management (SIEM) or log analysis software
for monitoring access management events
‣ “Bump-in-the-wire” devices for augmenting OT with authentication,
authorization, access control, encrypted communication and logging
capabilities
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
20
SILOS
IT network OT network Physical system
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
21
THE IT-OT DIVIDE
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
22
COLLABORATORS
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
NEXT STEPS
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
24
NEXT STEPS
NCCoE:
‣ Finalize build architecture
Users and other interested parties:
‣ Participate in a use case community of interest
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
SITUATIONAL AWARENESS
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
26
OVERVIEW
Goals
‣ Improve OT availability
‣ Unify visibility across silos
‣ Detect anomalous conditions and remediate them
‣ Investigate events leading to anomalies and share findings
Business value
‣ Improves ability to detect security breaches or anomalous behavior
‣ Increases probability that investigations of attacks or anomalous system
behavior will reach successful conclusions
‣ Improves accountability and traceability
‣ Simplifies regulatory compliance
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
27
DESIRED SOLUTION CHARACTERISTICS
‣ Data visualization and analysis capabilities that help dispatchers
and security analysts view control system behavior and network
and physical security events as a cohesive whole
‣ Analysis and correlation capabilities that help dispatchers and
security analysts understand and identify security events and
predict how those events might affect control system operation
‣ Scalability sufficient to meet the needs of a large metropolitan
utility
‣ Mechanisms that ensure the accuracy and integrity of data
collected from remote facilities
‣ Ability to collect logs, traffic and operational data from a variety of
sources including servers, ICS equipment, networking
equipment, security appliances, issue tracking systems and
mobile devices
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
28
DESIRED SOLUTION CHARACTERISTICS
‣ Ability to allow dispatchers and security analysts to easily
automate common and repetitive investigative tasks
‣ Built-in information sharing capabilities that allow dispatchers
and security analysts to easily share and acquire new threat
indicators, correlation rules, mitigations and investigative
techniques
‣ Customizable interfaces that allow users to tailor the system
to meet specific business needs
‣ Automated report generation to aid utilities in demonstrating
compliance with relevant standards
‣ Intuitive user interfaces that are appropriate for utility
dispatchers with limited network security expertise or security
analysts with limited expertise in electric power
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
29
EXAMPLE COMPONENT LIST
‣ ICS equipment, such as RTUs, PLCs and relays, along with
associated software and communications equipment (e.g.,
radios, encryptors)
‣ SIEM or log analysis software
‣ “Bump-in-the-wire” devices for augmenting OT with encrypted
communication and logging capabilities
‣ Software for collecting, analyzing, visualizing and storing
operational control data (e.g., historians, outage management
systems, distribution management systems, human-machine
interfaces)
‣ Products that ensure the integrity and accuracy of data
collected from remote facilities
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
NEXT STEPS
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
31
NEXT STEPS
NCCoE:
‣ Invite vendors to submit letters of interest that will result in CRADAs
Users and other interested parties:
‣ Participate in a use case community of interest
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
Next
energy_nccoe@nist.gov240-314-6800
9600 Gudelsky Drive
Rockville, MD 20850
http://nccoe.nist.gov
Accelerating Grid Modernization
More information available on SGIP.org
QUESTIONS?
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
Cybersecurity Update
• Cloud Computing Considerations in the Smart Grid has now
been published for SGIP Members to view and download.
– http://members.sgip.org/apps/org/workgroup/sgip-
mmc/download.php/5953/latest
– Available to public in February 2015.
• Other resources at SGIP.org/Publications
– Framework for Improving Critical Infrastructure Cybersecurity
Core Mapping to National Institute of Standards and Technology
(NIST) Interagency Report (IR) 7628 Exclusive to Members
– Cybersecurity User's Guide (NISTIR 7628) - Smart Grid Cyber
Security Implementation Guidelines 30 pages
• Information on the SGIP Smart Grid Cybersecurity
Committee may be found at SGIP.org/SGCC
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
SGIP Reminders
• Next week on November 20: Another Free Webinar – “What’s
New with the Interoperability Process Reference Manual?” and
the Smart Grid Testing & Certification Committee
• December 8-9: Winter Members Meeting in Portland
– Conference on Transactive Energy also in Portland that week.
• Webinars & Publications on SGIP.org under “Information
Knowledge Base”
• Stay in Touch
– Twitter: @SGIPNews
– Join our LinkedIn Group: https://www.linkedin.com/groups/Smart-
Grid-Interoperability-Panel-SGIP-4145498
– Sign up for SGIP Newsletter, The Conductor
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
Accelerating Grid Modernization
More information available on SGIP.org
THANK YOU FOR YOUR PARTICIPATION
A FOLLOW-UP EMAIL WILL BE SENT WITH LINK TO
RECORDING AND SUPPORTING MATERIALS
Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector

More Related Content

What's hot

Lessons Learned from the NIST CSF
Lessons Learned from the NIST CSFLessons Learned from the NIST CSF
Lessons Learned from the NIST CSF
Digital Bond
 
Introduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity FrameworkIntroduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity Framework
Tuan Phan
 
Managing Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust PrinciplesManaging Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust Principles
ControlCase
 
CHIME Lead Forum - Seattle 2015
CHIME Lead Forum - Seattle 2015CHIME Lead Forum - Seattle 2015
CHIME Lead Forum - Seattle 2015
Health IT Conference – iHT2
 
NISTs Cybersecurity Framework -- Comparison with Best Practice
NISTs Cybersecurity Framework -- Comparison with Best PracticeNISTs Cybersecurity Framework -- Comparison with Best Practice
NISTs Cybersecurity Framework -- Comparison with Best Practice
David Ochel
 
Cybersecurity Framework - What are Pundits Saying?
Cybersecurity Framework - What are Pundits Saying?Cybersecurity Framework - What are Pundits Saying?
Cybersecurity Framework - What are Pundits Saying?
Jim Meyer
 
For Critical Infrastructure Protection
For Critical Infrastructure ProtectionFor Critical Infrastructure Protection
For Critical Infrastructure Protection
Priyanka Aash
 
From Air Gap to Air Control
From Air Gap to Air ControlFrom Air Gap to Air Control
From Air Gap to Air Control
EnergySec
 
Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...
Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...
Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...
EnergySec
 
AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014
KBIZEAU
 
NIST releases SP 800-160 Multi-discplinary approach to cybersecurity
NIST releases SP 800-160  Multi-discplinary approach to cybersecurityNIST releases SP 800-160  Multi-discplinary approach to cybersecurity
NIST releases SP 800-160 Multi-discplinary approach to cybersecurity
David Sweigert
 
Top 20 Security Controls for a More Secure Infrastructure
Top 20 Security Controls for a More Secure InfrastructureTop 20 Security Controls for a More Secure Infrastructure
Top 20 Security Controls for a More Secure Infrastructure
Infosec
 
GDPR
GDPRGDPR
Technologies for Security and Compliance by Ken McIntyre, Ercot
Technologies for Security and Compliance by Ken McIntyre, ErcotTechnologies for Security and Compliance by Ken McIntyre, Ercot
Technologies for Security and Compliance by Ken McIntyre, Ercot
TheAnfieldGroup
 
PCI DSS Compliance in the Cloud
PCI DSS Compliance in the CloudPCI DSS Compliance in the Cloud
PCI DSS Compliance in the Cloud
ControlCase
 
Utilizing the Critical Security Controls to Secure Healthcare Technology
Utilizing the Critical Security Controls to Secure Healthcare TechnologyUtilizing the Critical Security Controls to Secure Healthcare Technology
Utilizing the Critical Security Controls to Secure Healthcare Technology
EnclaveSecurity
 
Cybersecurity Assurance at CloudSec 2015 Kuala Lumpur
Cybersecurity Assurance  at CloudSec 2015 Kuala LumpurCybersecurity Assurance  at CloudSec 2015 Kuala Lumpur
Cybersecurity Assurance at CloudSec 2015 Kuala Lumpur
Alan Yau Ti Dun
 
TrustedAgent GRC for Vulnerability Management
TrustedAgent GRC for Vulnerability ManagementTrustedAgent GRC for Vulnerability Management
TrustedAgent GRC for Vulnerability Management
Tuan Phan
 
Auditing & Assessing The Risk Of Cloud Service Providers at Auditworld 2015 ...
Auditing & Assessing The  Risk Of Cloud Service Providers at Auditworld 2015 ...Auditing & Assessing The  Risk Of Cloud Service Providers at Auditworld 2015 ...
Auditing & Assessing The Risk Of Cloud Service Providers at Auditworld 2015 ...
Alan Yau Ti Dun
 
Cybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
Cybersecurity for Smart Grids: Technical Approaches to Provide CybersecurityCybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
Cybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
Leonardo ENERGY
 

What's hot (20)

Lessons Learned from the NIST CSF
Lessons Learned from the NIST CSFLessons Learned from the NIST CSF
Lessons Learned from the NIST CSF
 
Introduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity FrameworkIntroduction to NIST Cybersecurity Framework
Introduction to NIST Cybersecurity Framework
 
Managing Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust PrinciplesManaging Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust Principles
 
CHIME Lead Forum - Seattle 2015
CHIME Lead Forum - Seattle 2015CHIME Lead Forum - Seattle 2015
CHIME Lead Forum - Seattle 2015
 
NISTs Cybersecurity Framework -- Comparison with Best Practice
NISTs Cybersecurity Framework -- Comparison with Best PracticeNISTs Cybersecurity Framework -- Comparison with Best Practice
NISTs Cybersecurity Framework -- Comparison with Best Practice
 
Cybersecurity Framework - What are Pundits Saying?
Cybersecurity Framework - What are Pundits Saying?Cybersecurity Framework - What are Pundits Saying?
Cybersecurity Framework - What are Pundits Saying?
 
For Critical Infrastructure Protection
For Critical Infrastructure ProtectionFor Critical Infrastructure Protection
For Critical Infrastructure Protection
 
From Air Gap to Air Control
From Air Gap to Air ControlFrom Air Gap to Air Control
From Air Gap to Air Control
 
Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...
Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...
Essential Power Case Study: Protecting Critical Infrastructure From Cyber Att...
 
AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014AFAC session 2 - September 8, 2014
AFAC session 2 - September 8, 2014
 
NIST releases SP 800-160 Multi-discplinary approach to cybersecurity
NIST releases SP 800-160  Multi-discplinary approach to cybersecurityNIST releases SP 800-160  Multi-discplinary approach to cybersecurity
NIST releases SP 800-160 Multi-discplinary approach to cybersecurity
 
Top 20 Security Controls for a More Secure Infrastructure
Top 20 Security Controls for a More Secure InfrastructureTop 20 Security Controls for a More Secure Infrastructure
Top 20 Security Controls for a More Secure Infrastructure
 
GDPR
GDPRGDPR
GDPR
 
Technologies for Security and Compliance by Ken McIntyre, Ercot
Technologies for Security and Compliance by Ken McIntyre, ErcotTechnologies for Security and Compliance by Ken McIntyre, Ercot
Technologies for Security and Compliance by Ken McIntyre, Ercot
 
PCI DSS Compliance in the Cloud
PCI DSS Compliance in the CloudPCI DSS Compliance in the Cloud
PCI DSS Compliance in the Cloud
 
Utilizing the Critical Security Controls to Secure Healthcare Technology
Utilizing the Critical Security Controls to Secure Healthcare TechnologyUtilizing the Critical Security Controls to Secure Healthcare Technology
Utilizing the Critical Security Controls to Secure Healthcare Technology
 
Cybersecurity Assurance at CloudSec 2015 Kuala Lumpur
Cybersecurity Assurance  at CloudSec 2015 Kuala LumpurCybersecurity Assurance  at CloudSec 2015 Kuala Lumpur
Cybersecurity Assurance at CloudSec 2015 Kuala Lumpur
 
TrustedAgent GRC for Vulnerability Management
TrustedAgent GRC for Vulnerability ManagementTrustedAgent GRC for Vulnerability Management
TrustedAgent GRC for Vulnerability Management
 
Auditing & Assessing The Risk Of Cloud Service Providers at Auditworld 2015 ...
Auditing & Assessing The  Risk Of Cloud Service Providers at Auditworld 2015 ...Auditing & Assessing The  Risk Of Cloud Service Providers at Auditworld 2015 ...
Auditing & Assessing The Risk Of Cloud Service Providers at Auditworld 2015 ...
 
Cybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
Cybersecurity for Smart Grids: Technical Approaches to Provide CybersecurityCybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
Cybersecurity for Smart Grids: Technical Approaches to Provide Cybersecurity
 

Viewers also liked

Managed Security Service and Cloud Solutions
Managed Security Service and Cloud SolutionsManaged Security Service and Cloud Solutions
Managed Security Service and Cloud Solutions
Tony Zirnoon, CISSP
 
Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...
Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...
Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...
Kenneth de Brucq
 
Information Security Cost Effective Managed Services
Information Security Cost Effective Managed ServicesInformation Security Cost Effective Managed Services
Information Security Cost Effective Managed Services
Jorge Sebastiao
 
The Benefits of Security From a Managed Services Provider
The Benefits of Security From a Managed Services ProviderThe Benefits of Security From a Managed Services Provider
The Benefits of Security From a Managed Services Provider
CSI Solutions
 
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
Global Business Events
 
Managed Security Services from Symantec
Managed Security Services from SymantecManaged Security Services from Symantec
Managed Security Services from Symantec
Arrow ECS UK
 
Managed Services Presentation
Managed Services PresentationManaged Services Presentation
Managed Services Presentation
Scott Gombar
 
Sw keynote
Sw keynoteSw keynote
Sw keynote
gueste69f645
 

Viewers also liked (8)

Managed Security Service and Cloud Solutions
Managed Security Service and Cloud SolutionsManaged Security Service and Cloud Solutions
Managed Security Service and Cloud Solutions
 
Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...
Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...
Dell Solutions Tour 2015 - Security in the cloud, Ramses Gallego, Security St...
 
Information Security Cost Effective Managed Services
Information Security Cost Effective Managed ServicesInformation Security Cost Effective Managed Services
Information Security Cost Effective Managed Services
 
The Benefits of Security From a Managed Services Provider
The Benefits of Security From a Managed Services ProviderThe Benefits of Security From a Managed Services Provider
The Benefits of Security From a Managed Services Provider
 
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
 
Managed Security Services from Symantec
Managed Security Services from SymantecManaged Security Services from Symantec
Managed Security Services from Symantec
 
Managed Services Presentation
Managed Services PresentationManaged Services Presentation
Managed Services Presentation
 
Sw keynote
Sw keynoteSw keynote
Sw keynote
 

Similar to Securing Networked Infrastructure for the Energy Sector

PLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
PLNOG14: Firewalls In Modern Data Centers - Piotr WojciechowskiPLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
PLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
PROIDEA
 
SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...
SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...
SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...
Smart Grid Interoperability Panel
 
Big Data Analytics and Advanced Computer Networking Scenarios
Big Data Analytics and Advanced Computer Networking ScenariosBig Data Analytics and Advanced Computer Networking Scenarios
Big Data Analytics and Advanced Computer Networking Scenarios
Stenio Fernandes
 
SGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart Grid
SGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart GridSGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart Grid
SGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart Grid
Smart Grid Interoperability Panel
 
Network Rightsizing Best Practices Guide
Network Rightsizing Best Practices GuideNetwork Rightsizing Best Practices Guide
Network Rightsizing Best Practices Guide
Aruba, a Hewlett Packard Enterprise company
 
Countering Threats with the Elastic Stack at CERDEC/ARL
Countering Threats with the Elastic Stack at CERDEC/ARLCountering Threats with the Elastic Stack at CERDEC/ARL
Countering Threats with the Elastic Stack at CERDEC/ARL
Elasticsearch
 
Dynamic Line Rating: Principles - Applications - Benefits
Dynamic Line Rating: Principles - Applications - BenefitsDynamic Line Rating: Principles - Applications - Benefits
Dynamic Line Rating: Principles - Applications - Benefits
Leonardo ENERGY
 
Is Your Network Ready?
Is Your Network Ready?Is Your Network Ready?
Is Your Network Ready?
Brocade
 
Network barometer report 2014
Network barometer report 2014Network barometer report 2014
Network barometer report 2014
Mūniū Karanja
 
Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...
Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...
Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...
TheAnfieldGroup
 
Architecture and Practices on Cloud Interoperability and Portability
Architecture and Practices on Cloud Interoperability and PortabilityArchitecture and Practices on Cloud Interoperability and Portability
Architecture and Practices on Cloud Interoperability and Portability
Thomas Lee
 
Isaca cloud security presentation duncan unwin 16 jul13
Isaca cloud security presentation   duncan unwin 16 jul13Isaca cloud security presentation   duncan unwin 16 jul13
Isaca cloud security presentation duncan unwin 16 jul13
Duncan Unwin
 
Ramin elahi fog_computing_ecosystem_final_dec22_updated
Ramin elahi fog_computing_ecosystem_final_dec22_updatedRamin elahi fog_computing_ecosystem_final_dec22_updated
Ramin elahi fog_computing_ecosystem_final_dec22_updated
HarshitParkar6677
 
Ensuring the compliance, resiliency, and availability of business-critical ne...
Ensuring the compliance, resiliency, and availability of business-critical ne...Ensuring the compliance, resiliency, and availability of business-critical ne...
Ensuring the compliance, resiliency, and availability of business-critical ne...
Riverbed Technology
 
Cisco Analytics: Accelerate Network Optimization with Virtualization
Cisco Analytics: Accelerate Network Optimization with VirtualizationCisco Analytics: Accelerate Network Optimization with Virtualization
Cisco Analytics: Accelerate Network Optimization with Virtualization
Cisco Canada
 
BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...
BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...
BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...
ajrossman
 
Kovacs [FINAL] .pptx
Kovacs [FINAL] .pptxKovacs [FINAL] .pptx
Kovacs [FINAL] .pptx
FIWARE
 
Overall System Architecture of Big Data of Wind Power Based on IoT_20161...
Overall System Architecture of Big Data of Wind Power Based on IoT_20161...Overall System Architecture of Big Data of Wind Power Based on IoT_20161...
Overall System Architecture of Big Data of Wind Power Based on IoT_20161...
元 黄
 
Show & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdf
Show & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdfShow & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdf
Show & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdf
SIFOfgem
 
Community Networks: An Alternative Paradigm for Developing Network Infrastruc...
Community Networks: An Alternative Paradigm for Developing Network Infrastruc...Community Networks: An Alternative Paradigm for Developing Network Infrastruc...
Community Networks: An Alternative Paradigm for Developing Network Infrastruc...
APNIC
 

Similar to Securing Networked Infrastructure for the Energy Sector (20)

PLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
PLNOG14: Firewalls In Modern Data Centers - Piotr WojciechowskiPLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
PLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
 
SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...
SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...
SGIP May 22 Webinar "Getting to Truly Interoperable Power Grid Solutions: A U...
 
Big Data Analytics and Advanced Computer Networking Scenarios
Big Data Analytics and Advanced Computer Networking ScenariosBig Data Analytics and Advanced Computer Networking Scenarios
Big Data Analytics and Advanced Computer Networking Scenarios
 
SGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart Grid
SGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart GridSGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart Grid
SGIP Sri 2014-keynote Reducing Cost and Risk in the Interoperable Smart Grid
 
Network Rightsizing Best Practices Guide
Network Rightsizing Best Practices GuideNetwork Rightsizing Best Practices Guide
Network Rightsizing Best Practices Guide
 
Countering Threats with the Elastic Stack at CERDEC/ARL
Countering Threats with the Elastic Stack at CERDEC/ARLCountering Threats with the Elastic Stack at CERDEC/ARL
Countering Threats with the Elastic Stack at CERDEC/ARL
 
Dynamic Line Rating: Principles - Applications - Benefits
Dynamic Line Rating: Principles - Applications - BenefitsDynamic Line Rating: Principles - Applications - Benefits
Dynamic Line Rating: Principles - Applications - Benefits
 
Is Your Network Ready?
Is Your Network Ready?Is Your Network Ready?
Is Your Network Ready?
 
Network barometer report 2014
Network barometer report 2014Network barometer report 2014
Network barometer report 2014
 
Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...
Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...
Leveraging Technology to Enhance Security, Reliability & NERC-CIP Ver.5 Compl...
 
Architecture and Practices on Cloud Interoperability and Portability
Architecture and Practices on Cloud Interoperability and PortabilityArchitecture and Practices on Cloud Interoperability and Portability
Architecture and Practices on Cloud Interoperability and Portability
 
Isaca cloud security presentation duncan unwin 16 jul13
Isaca cloud security presentation   duncan unwin 16 jul13Isaca cloud security presentation   duncan unwin 16 jul13
Isaca cloud security presentation duncan unwin 16 jul13
 
Ramin elahi fog_computing_ecosystem_final_dec22_updated
Ramin elahi fog_computing_ecosystem_final_dec22_updatedRamin elahi fog_computing_ecosystem_final_dec22_updated
Ramin elahi fog_computing_ecosystem_final_dec22_updated
 
Ensuring the compliance, resiliency, and availability of business-critical ne...
Ensuring the compliance, resiliency, and availability of business-critical ne...Ensuring the compliance, resiliency, and availability of business-critical ne...
Ensuring the compliance, resiliency, and availability of business-critical ne...
 
Cisco Analytics: Accelerate Network Optimization with Virtualization
Cisco Analytics: Accelerate Network Optimization with VirtualizationCisco Analytics: Accelerate Network Optimization with Virtualization
Cisco Analytics: Accelerate Network Optimization with Virtualization
 
BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...
BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...
BBD Presentation - Using Standards and Technology to Create Efficiency in Ene...
 
Kovacs [FINAL] .pptx
Kovacs [FINAL] .pptxKovacs [FINAL] .pptx
Kovacs [FINAL] .pptx
 
Overall System Architecture of Big Data of Wind Power Based on IoT_20161...
Overall System Architecture of Big Data of Wind Power Based on IoT_20161...Overall System Architecture of Big Data of Wind Power Based on IoT_20161...
Overall System Architecture of Big Data of Wind Power Based on IoT_20161...
 
Show & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdf
Show & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdfShow & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdf
Show & Tell - Data & Digitalisation, Weather & Predictive Analytics.pdf
 
Community Networks: An Alternative Paradigm for Developing Network Infrastruc...
Community Networks: An Alternative Paradigm for Developing Network Infrastruc...Community Networks: An Alternative Paradigm for Developing Network Infrastruc...
Community Networks: An Alternative Paradigm for Developing Network Infrastruc...
 

More from Smart Grid Interoperability Panel

Overview of SGIP Member Ameren Illinois' Smart Grid Test Bed
Overview of SGIP Member Ameren Illinois' Smart Grid Test BedOverview of SGIP Member Ameren Illinois' Smart Grid Test Bed
Overview of SGIP Member Ameren Illinois' Smart Grid Test Bed
Smart Grid Interoperability Panel
 
Transactive Energy Webinar
Transactive Energy WebinarTransactive Energy Webinar
Transactive Energy Webinar
Smart Grid Interoperability Panel
 
SGIP Webinar “Regulatory Commission Members Discuss How SGIP Helps Shape Sm...
SGIP Webinar  “Regulatory Commission Members Discuss How SGIP Helps Shape  Sm...SGIP Webinar  “Regulatory Commission Members Discuss How SGIP Helps Shape  Sm...
SGIP Webinar “Regulatory Commission Members Discuss How SGIP Helps Shape Sm...
Smart Grid Interoperability Panel
 
Smart Grid Interoperablity December Emeeting 20131212 final
Smart Grid Interoperablity December Emeeting 20131212 finalSmart Grid Interoperablity December Emeeting 20131212 final
Smart Grid Interoperablity December Emeeting 20131212 final
Smart Grid Interoperability Panel
 
"How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo...
"How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo..."How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo...
"How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo...
Smart Grid Interoperability Panel
 
SGIP August 15, 2013 eMeeting - State of the Union
SGIP August 15, 2013 eMeeting - State of the UnionSGIP August 15, 2013 eMeeting - State of the Union
SGIP August 15, 2013 eMeeting - State of the Union
Smart Grid Interoperability Panel
 

More from Smart Grid Interoperability Panel (6)

Overview of SGIP Member Ameren Illinois' Smart Grid Test Bed
Overview of SGIP Member Ameren Illinois' Smart Grid Test BedOverview of SGIP Member Ameren Illinois' Smart Grid Test Bed
Overview of SGIP Member Ameren Illinois' Smart Grid Test Bed
 
Transactive Energy Webinar
Transactive Energy WebinarTransactive Energy Webinar
Transactive Energy Webinar
 
SGIP Webinar “Regulatory Commission Members Discuss How SGIP Helps Shape Sm...
SGIP Webinar  “Regulatory Commission Members Discuss How SGIP Helps Shape  Sm...SGIP Webinar  “Regulatory Commission Members Discuss How SGIP Helps Shape  Sm...
SGIP Webinar “Regulatory Commission Members Discuss How SGIP Helps Shape Sm...
 
Smart Grid Interoperablity December Emeeting 20131212 final
Smart Grid Interoperablity December Emeeting 20131212 finalSmart Grid Interoperablity December Emeeting 20131212 final
Smart Grid Interoperablity December Emeeting 20131212 final
 
"How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo...
"How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo..."How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo...
"How Today's Power Grid Implementation Choices Impact Future Smart Grid Deplo...
 
SGIP August 15, 2013 eMeeting - State of the Union
SGIP August 15, 2013 eMeeting - State of the UnionSGIP August 15, 2013 eMeeting - State of the Union
SGIP August 15, 2013 eMeeting - State of the Union
 

Recently uploaded

PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)
ahcitycouncil
 
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Jamesadhikaram land matter consultancy 9447464502
 
Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024
Texas Alliance of Groundwater Districts
 
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
Christina Parmionova
 
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
ssuser05e8f3
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Christina Parmionova
 
Border towns and spaces of (in)visibility.pdf
Border towns and spaces of (in)visibility.pdfBorder towns and spaces of (in)visibility.pdf
Border towns and spaces of (in)visibility.pdf
Scalabrini Institute for Human Mobility in Africa
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
Roger Valdez
 
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptxPUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
Marked12
 
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Christina Parmionova
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
SERUDS INDIA
 
原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样
原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样
原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样
yemqpj
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
ARCResearch
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
OECDregions
 
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
3woawyyl
 
Practical guide for the celebration of World Environment Day on june 5th.
Practical guide for the  celebration of World Environment Day on  june 5th.Practical guide for the  celebration of World Environment Day on  june 5th.
Practical guide for the celebration of World Environment Day on june 5th.
Christina Parmionova
 
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptxPAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS_Team
 
Researching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssssResearching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssss
DanielOliver74
 
2024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 402024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 40
JSchaus & Associates
 
Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019
Partito democratico
 

Recently uploaded (20)

PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)
 
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
 
Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024Texas Water Development Board Updates June 2024
Texas Water Development Board Updates June 2024
 
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
 
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
 
Border towns and spaces of (in)visibility.pdf
Border towns and spaces of (in)visibility.pdfBorder towns and spaces of (in)visibility.pdf
Border towns and spaces of (in)visibility.pdf
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
 
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptxPUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
 
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
 
原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样
原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样
原版制作(DPU毕业证书)德保罗大学毕业证Offer一模一样
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
 
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
原版制作(英国Southampton毕业证书)南安普顿大学毕业证录取通知书一模一样
 
Practical guide for the celebration of World Environment Day on june 5th.
Practical guide for the  celebration of World Environment Day on  june 5th.Practical guide for the  celebration of World Environment Day on  june 5th.
Practical guide for the celebration of World Environment Day on june 5th.
 
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptxPAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
 
Researching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssssResearching the client.pptxsxssssssssssssssssssssss
Researching the client.pptxsxssssssssssssssssssssss
 
2024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 402024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 40
 
Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019
 

Securing Networked Infrastructure for the Energy Sector

  • 1. Accelerating Grid Modernization More information available on SGIP.org Securing Networked Infrastructure for the Energy Sector November 13, 2014
  • 2. Accelerating Grid Modernization More information available on SGIP.org INTRODUCTION Tanya Brewer, Senior Information Technology Researcher National Institute of Standards & Technology (NIST) SGIP Smart Grid Cybersecurity Committee (SGCC) Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 3. Accelerating Grid Modernization More information available on SGIP.org Smart Grid Interoperability Panel orchestrates the work behind power grid modernization
  • 4. Accelerating Grid Modernization More information available on SGIP.org • Optimizes resources and time • Avoids proprietary vendor lock-in • Helps build technology roadmaps • Simplifies decision making SGIP Reduces Risks and Costs SGIP is a collaborative, transparent, and trusted forum to share standards information and practical, hands-on knowledge about deployments from industry experts. Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 5. Accelerating Grid Modernization More information available on SGIP.org Agenda • Introduction Tanya Brewer • Main Presentation Jim McCarthy • Q&A • Closing Tanya Brewer This meeting, and all SGIP activities, are governed by SGIP By-laws and policies - Intellectual Property Rights Policy and Antitrust Policy. Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 6. Accelerating Grid Modernization More information available on SGIP.org Securing Networked Infrastructure for the Energy Sector Jim McCarthy National Cybersecurity Center of Excellence SGIP Webinar November 13, 2014
  • 7. Accelerating Grid Modernization More information available on SGIP.org ABOUT THE NCCOE Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 8. Accelerating Grid Modernization More information available on SGIP.org 8 STRATEGY Vision ‣ A secure cyber infrastructure that inspires technological innovation and fosters economic growth Mission ‣ Collaborate with innovators to provide real-world, standards-based cybersecurity capabilities that address business needs Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 9. Accelerating Grid Modernization More information available on SGIP.org 9 TENETS Standards-based Modular Usable Repeatable Open and transparent Commercially available Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 10. Accelerating Grid Modernization More information available on SGIP.org 10 APPROACH We seek problems that are: ‣ Broadly relevant ‣ Technology-based ‣ Addressable with multiple commercially available technologies Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 11. Accelerating Grid Modernization More information available on SGIP.org 11 REFERENCE DESIGNS Use cases ‣ Sector-specific challenges ‣ Identified through industry engagement Building blocks ‣ Technology-specific challenges ‣ Identified through public engagement Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 12. Accelerating Grid Modernization More information available on SGIP.org 12 MODEL Engage ‣ Work with community of interest to define problem Explore ‣ Map security characteristics to standards, controls and best practices ‣ Circulate drafts and incorporate feedback Partner ‣ Invite technology vendors to collaborate in our labs Build ‣ Collaborate on design components ‣ Incorporate feedback from experts in technology community Show ‣ Demonstrate reference designs Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 13. Accelerating Grid Modernization More information available on SGIP.org 13 MODEL Form small community of interest Provide input and feedback to NCCoE Expand community of interest Submit feedback on use cases to NCCoE Offer insights on use cases Community Of Interest Support deployment, revision and maintenance of products as part of the practice guide Collaborate to develop reference designs Evangelize on behalf of reference design and practice guide Deploy, test and provide feedback on the reference design Provide regular feedback on use case builds Technology Partners Submit letters of interest Speak at sector- specific events Work with COI to identify cybersecurity challenges Host sector- specific workshop Review & circulate pre-release use cases Revise & publish draft use cases Revise use cases & invite participation from technology partners Receive technology partners letters of interest Demonstrate reference designs Discuss improvements & modifications Publish reference design and practice guide Develop composed reference design Form build teams Sign CRADAs Host partner day
  • 14. Accelerating Grid Modernization More information available on SGIP.org 14 CORE PARTNERS Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 15. Accelerating Grid Modernization More information available on SGIP.org IDENTITY AND ACCESS MANAGEMENT Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 16. Accelerating Grid Modernization More information available on SGIP.org 16 OVERVIEW Goals ‣ Authenticate individuals and systems ‣ Enforce authorization control policies ‣ Unify IdAM services ‣ Protect generation, transmission and distribution Business value ‣ Reduce costs ‣ Increase efficiency Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 17. Accelerating Grid Modernization More information available on SGIP.org 17 DESIRED SOLUTION CHARACTERISTICS ‣ Authentication ‣ Authorization ‣ Access control ‣ Federation ‣ Provisioning ‣ Do not break the grid Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 18. Accelerating Grid Modernization More information available on SGIP.org 18 EXAMPLE COMPONENT LIST ‣ Services for authenticating and authorizing users based on identity, role, third-party affiliation (e.g., federation) or other attributes (e.g., attribute based access control) ‣ Services for authenticating and authorizing devices ‣ Identity and access governance capability that translates human-readable access needs into machine-readable authorizations ‣ Services for whitelisting applications Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 19. Accelerating Grid Modernization More information available on SGIP.org 19 EXAMPLE COMPONENT LIST ‣ ICS equipment, such as remote terminal units (RTUs), programmable logic controllers (PLCs) and relays, along with associated software and communications equipment (e.g., radios, encryptors) ‣ Physical access control devices that use standard communication interfaces ‣ Security incident and event management (SIEM) or log analysis software for monitoring access management events ‣ “Bump-in-the-wire” devices for augmenting OT with authentication, authorization, access control, encrypted communication and logging capabilities Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 20. Accelerating Grid Modernization More information available on SGIP.org 20 SILOS IT network OT network Physical system Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 21. Accelerating Grid Modernization More information available on SGIP.org 21 THE IT-OT DIVIDE Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 22. Accelerating Grid Modernization More information available on SGIP.org 22 COLLABORATORS Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 23. Accelerating Grid Modernization More information available on SGIP.org NEXT STEPS Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 24. Accelerating Grid Modernization More information available on SGIP.org 24 NEXT STEPS NCCoE: ‣ Finalize build architecture Users and other interested parties: ‣ Participate in a use case community of interest Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 25. Accelerating Grid Modernization More information available on SGIP.org SITUATIONAL AWARENESS Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 26. Accelerating Grid Modernization More information available on SGIP.org 26 OVERVIEW Goals ‣ Improve OT availability ‣ Unify visibility across silos ‣ Detect anomalous conditions and remediate them ‣ Investigate events leading to anomalies and share findings Business value ‣ Improves ability to detect security breaches or anomalous behavior ‣ Increases probability that investigations of attacks or anomalous system behavior will reach successful conclusions ‣ Improves accountability and traceability ‣ Simplifies regulatory compliance Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 27. Accelerating Grid Modernization More information available on SGIP.org 27 DESIRED SOLUTION CHARACTERISTICS ‣ Data visualization and analysis capabilities that help dispatchers and security analysts view control system behavior and network and physical security events as a cohesive whole ‣ Analysis and correlation capabilities that help dispatchers and security analysts understand and identify security events and predict how those events might affect control system operation ‣ Scalability sufficient to meet the needs of a large metropolitan utility ‣ Mechanisms that ensure the accuracy and integrity of data collected from remote facilities ‣ Ability to collect logs, traffic and operational data from a variety of sources including servers, ICS equipment, networking equipment, security appliances, issue tracking systems and mobile devices Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 28. Accelerating Grid Modernization More information available on SGIP.org 28 DESIRED SOLUTION CHARACTERISTICS ‣ Ability to allow dispatchers and security analysts to easily automate common and repetitive investigative tasks ‣ Built-in information sharing capabilities that allow dispatchers and security analysts to easily share and acquire new threat indicators, correlation rules, mitigations and investigative techniques ‣ Customizable interfaces that allow users to tailor the system to meet specific business needs ‣ Automated report generation to aid utilities in demonstrating compliance with relevant standards ‣ Intuitive user interfaces that are appropriate for utility dispatchers with limited network security expertise or security analysts with limited expertise in electric power Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 29. Accelerating Grid Modernization More information available on SGIP.org 29 EXAMPLE COMPONENT LIST ‣ ICS equipment, such as RTUs, PLCs and relays, along with associated software and communications equipment (e.g., radios, encryptors) ‣ SIEM or log analysis software ‣ “Bump-in-the-wire” devices for augmenting OT with encrypted communication and logging capabilities ‣ Software for collecting, analyzing, visualizing and storing operational control data (e.g., historians, outage management systems, distribution management systems, human-machine interfaces) ‣ Products that ensure the integrity and accuracy of data collected from remote facilities Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 30. Accelerating Grid Modernization More information available on SGIP.org NEXT STEPS Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 31. Accelerating Grid Modernization More information available on SGIP.org 31 NEXT STEPS NCCoE: ‣ Invite vendors to submit letters of interest that will result in CRADAs Users and other interested parties: ‣ Participate in a use case community of interest Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 32. Accelerating Grid Modernization More information available on SGIP.org Next energy_nccoe@nist.gov240-314-6800 9600 Gudelsky Drive Rockville, MD 20850 http://nccoe.nist.gov
  • 33. Accelerating Grid Modernization More information available on SGIP.org QUESTIONS? Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 34. Accelerating Grid Modernization More information available on SGIP.org Cybersecurity Update • Cloud Computing Considerations in the Smart Grid has now been published for SGIP Members to view and download. – http://members.sgip.org/apps/org/workgroup/sgip- mmc/download.php/5953/latest – Available to public in February 2015. • Other resources at SGIP.org/Publications – Framework for Improving Critical Infrastructure Cybersecurity Core Mapping to National Institute of Standards and Technology (NIST) Interagency Report (IR) 7628 Exclusive to Members – Cybersecurity User's Guide (NISTIR 7628) - Smart Grid Cyber Security Implementation Guidelines 30 pages • Information on the SGIP Smart Grid Cybersecurity Committee may be found at SGIP.org/SGCC Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 35. Accelerating Grid Modernization More information available on SGIP.org SGIP Reminders • Next week on November 20: Another Free Webinar – “What’s New with the Interoperability Process Reference Manual?” and the Smart Grid Testing & Certification Committee • December 8-9: Winter Members Meeting in Portland – Conference on Transactive Energy also in Portland that week. • Webinars & Publications on SGIP.org under “Information Knowledge Base” • Stay in Touch – Twitter: @SGIPNews – Join our LinkedIn Group: https://www.linkedin.com/groups/Smart- Grid-Interoperability-Panel-SGIP-4145498 – Sign up for SGIP Newsletter, The Conductor Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector
  • 36. Accelerating Grid Modernization More information available on SGIP.org THANK YOU FOR YOUR PARTICIPATION A FOLLOW-UP EMAIL WILL BE SENT WITH LINK TO RECORDING AND SUPPORTING MATERIALS Nov. 13, 2014 Securing Networked Infrastructure for the Energy Sector