Geneva, Switzerland, 15-16 September 2014 Smart Grid cyber security within IEC TC57 WG15 Fernando Alvarez, Cyber Security Technical PM ABB Switzerland.

Slides:



Advertisements
Similar presentations
NIST Interoperability Framework for the Smart Grid
Advertisements

Copyright © 2003 Pearson Education, Inc. Slide 1 Computer Systems Organization & Architecture Chapters 8-12 John D. Carpinelli.
Chapter 1 The Study of Body Function Image PowerPoint
1 Copyright © 2013 Elsevier Inc. All rights reserved. Chapter 1 Embedded Computing.
Author: Julia Richards and R. Scott Hawley
1 Copyright © 2013 Elsevier Inc. All rights reserved. Appendix 01.
1 Balloting/Handling Negative Votes September 11, 2006 ASTM Training Session Bob Morgan Brynn Iwanowski.
September 2013 ASTM Officers Training Workshop September 2013 ASTM Officers Training Workshop Symposia, Workshops and Publications September 2013 ASTM.
1 Balloting/Handling Negative Votes September 22 nd and 24 th, 2009 ASTM Virtual Training Session Christine DeJong Joe Koury.
Task Group Chairman and Technical Contact Responsibilities ASTM International Officers Training Workshop September 2012 Scott Orthey and Steve Mawn 1.
RXQ Customer Enrollment Using a Registration Agent (RA) Process Flow Diagram (Move-In) Customer Supplier Customer authorizes Enrollment ( )
Document #07-2I RXQ Customer Enrollment Using a Registration Agent (RA) Process Flow Diagram (Move-In) (mod 7/25 & clean-up 8/20) Customer Supplier.
TIA/ANSI Presentation on New and Novel Topic (NNT) Agenda Item 7 Smart Grid David Su DOCUMENT #:GSC14-PLEN-013 R2 FOR:Presentation SOURCE:TIA/ANSI/NIST.
Geneva, Switzerland, 11 June 2012 Standardization activities on Future Network in JTC 1/SC 6 Shin-Gak Kang Convenor, SC 6/WG 7 Joint.
State of New Jersey Department of Health and Senior Services Patient Safety Reporting System Module 2 – New Event Entry.
Jeopardy Q 1 Q 6 Q 11 Q 16 Q 21 Q 2 Q 7 Q 12 Q 17 Q 22 Q 3 Q 8 Q 13
Jeopardy Q 1 Q 6 Q 11 Q 16 Q 21 Q 2 Q 7 Q 12 Q 17 Q 22 Q 3 Q 8 Q 13
Exit a Customer Chapter 8. Exit a Customer 8-2 Objectives Perform exit summary process consisting of the following steps: Review service records Close.
FACTORING ax2 + bx + c Think “unfoil” Work down, Show all steps.
Year 6 mental test 5 second questions
Year 6 mental test 10 second questions
|epcc| NeSC Workshop Open Issues in Grid Scheduling Ali Anjomshoaa EPCC, University of Edinburgh Tuesday, 21 October 2003 Overview of a Grid Scheduling.
2010 fotografiert von Jürgen Roßberg © Fr 1 Sa 2 So 3 Mo 4 Di 5 Mi 6 Do 7 Fr 8 Sa 9 So 10 Mo 11 Di 12 Mi 13 Do 14 Fr 15 Sa 16 So 17 Mo 18 Di 19.
ZMQS ZMQS
Engineering, Architecture, Construction, Environmental and Consulting Solutions © 2011 Burns & McDonnell Missouri Public Service Commission.
Richmond House, Liverpool (1) 26 th January 2004.
REVIEW: Arthropod ID. 1. Name the subphylum. 2. Name the subphylum. 3. Name the order.
Join Us Now at: Enabling Interoperability for the Utility Enterprise And TESTING.
Page 1 of 30 To the Create Assignment Request Online Training Course An assignment request is created by an assignor to initiate the electronic assignment.
EU Market Situation for Eggs and Poultry Management Committee 21 June 2012.
EIS Bridge Tool and Staging Tables September 1, 2009 Instructor: Way Poteat Slide: 1.
2 |SharePoint Saturday New York City
VOORBLAD.
15. Oktober Oktober Oktober 2012.
BIOLOGY AUGUST 2013 OPENING ASSIGNMENTS. AUGUST 7, 2013  Question goes here!
Factor P 16 8(8-5ab) 4(d² + 4) 3rs(2r – s) 15cd(1 + 2cd) 8(4a² + 3b²)
Basel-ICU-Journal Challenge18/20/ Basel-ICU-Journal Challenge8/20/2014.
CONTROL VISION Set-up. Step 1 Step 2 Step 3 Step 5 Step 4.
© 2012 National Heart Foundation of Australia. Slide 2.
Understanding Generalist Practice, 5e, Kirst-Ashman/Hull
TC 57 IEC TC57 WG15 - Security Status & Roadmap, July 2008 Frances Cleveland Convenor WG15.
25 seconds left…...
H to shape fully developed personality to shape fully developed personality for successful application in life for successful.
Januar MDMDFSSMDMDFSSS
Analyzing Genes and Genomes
We will resume in: 25 Minutes.
©Brooks/Cole, 2001 Chapter 12 Derived Types-- Enumerated, Structure and Union.
Essential Cell Biology
How to Fill out a PAR for a New Standard Revised 8 July 2010.
Intracellular Compartments and Transport
PSSA Preparation.
VPN AND REMOTE ACCESS Mohammad S. Hasan 1 VPN and Remote Access.
Essential Cell Biology
Weekly Attendance by Class w/e 6 th September 2013.
Energy Generation in Mitochondria and Chlorplasts
INTERNATIONAL ELECTROTECHNICAL COMMISSION
Doc.: IEEE /0047r1 Submission SGIP Liaison Report to IEEE Following the SGIP (2.0) Inaugural Conference Nov 5-7, 2013 Date:
IEC TC57: Report on WG21 Interfaces and protocol profiles relevant to systems connected to the electrical grid P. Ferstl August 2012 INTERNATIONAL ELECTROTECHNICAL.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All SMART GRID ICT: SECURITY, INTEROPERABILITY & NEXT STEPS John O’Neill, Senior Project Manager CSA.
IEC TC57 WG15 - Security Status & Roadmap, TC57 Plenary, May 2007
Smart Grid cyber security within IEC TC57 WG15
Frances Cleveland Convenor WG15
Smart Grid cyber security within IEC TC57 WG15
Presentation transcript:

Geneva, Switzerland, September 2014 Smart Grid cyber security within IEC TC57 WG15 Fernando Alvarez, Cyber Security Technical PM ABB Switzerland ITU Workshop on “ICT Security Standardization for Developing Countries” (Geneva, Switzerland, September 2014)

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Cyber Security – Essentials without / before IEC Physical perimeter protection Fences, gates, motion sensors, cameras Electronic perimeter protection Firewalls, VPN Antivirus and IDS Unused ports & services disabled Debug services, USB ports, etc. Robustness tested releases No device crashes due DOS attacks Geneva, Switzerland, September

Cyber Security – Essentials Is all this enough? Geneva, Switzerland, September

IEC – Even more essential 5 Geneva, Switzerland, September 2014

IEC – Even more essential Secure the protocols w/authentication+ Geneva, Switzerland, September

7 Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Geneva, Switzerland, September Mission and Scope of TC57 WG15 on Cyber Security Undertake the development of standards for security of the communication protocols defined by the IEC TC 57 Specifically the IEC series, the IEC series, the IEC series, the IEC series, and the IEC series. Undertake the development of standards and/or technical reports on end-to-end security issues. IEC 62351

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Geneva, Switzerland, September TC57 WG15 Members 76 members Participants from 22 countries Argentina Canada China Croatia Czech Republic Denmark Finland France Germany Great Britain India Japan

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Geneva, Switzerland, September Mapping of TC57 Communication Standards to IEC Security Standards

IEC Parts & Status Geneva, Switzerland, September IEC PartReleasedActivities (by May 2014)Planned Release IEC/TS : Introduction2007- IEC/TS : Glossary of terms2008Review Report pendingPending IEC/TS : Security for profiles including TCP/IP 2007Ed. 2: Responses to Comments on CDV being developed Submitted as CDV by Dec 2012, FDIS Dec 2013, IS Ed. 2 by 2014? IEC/TS : Security for profiles including MMS 2007Starting Edition 2 After amendment process was rejected, the decision was made to start Edition 2 Comments on Q rec’d Dec 2013 Ed. 2: CD 6/2015, CDV 3/2016, FDIS 6/2016, IS Jun 2017 IEC/TS : Security for IEC and derivatives 2009Ed. 2 released April 2013TS Released April 2013 Possible clarifications IEC/TS : Security for IEC profiles: GOOSE & SV 2007Ed. 2 planed: Updates underway, based on security requirements in IEC RR to be issued mid-2014, to be released in parallel with Part 4 IEC/TS : Objects for Network Management 2010Working on Ed. 2: Responded to comments on RR changing TS to IS CD 9/2014, CDV 6/2015, FDIS 3/2016, IS 9/2016 IEC/TS : Role-Based Access Control : RBAC 2011Working on Ed. 2: Discussions on developing categories of roles Planning IS in 2014/15 after TR 90-1 issued IEC/TS : Key Management PendingWorking on Ed. 1: 1 st CD issued August 2013; Responses submitted Feb nd CD planned 2 nd CD August 2014, CDV in (early) 2015 and IS in (late) 2015 IEC/TR : Security Architecture 2012TR published Oct 2012 No further work planed. Done IEC/TS : Security for XML Files PendingWorking on Ed. 1: Developing CD for WG15 review by May 2014 CD 6/2014, CDV 2/2015, FDIS 12/2015, IS 6/2016 PWI: Resiliency and Security for power systems with DER DC PendingNeed broader review by WG17 & 21 before submittal as TR as Review in WG17 and WG21, Circulated in WG19 early 2014 PWI: Conformance Testing for IEC NWIP Pending Pending PWI: IEC : Guidelines for Using Part 8 RBAC TR PendingWork in progressPending

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Geneva, Switzerland, September CompletedUpdates in ProcessPotential New Work Ed. 1 of Parts: 1, 2, 3, 4, 5, 6, 7, 8, and 10 – finalized as TRs or TS Ed. 2 of Part 5 Part 2 Glossary: adding amendments probably update in 2014 Part 3 Security using TLS: Submitted as FDIS Dec 2013 as IS by 2014 Part 4 Security for MMS: Edition 2 started Part 6 on IEC 61850: GOOSE & SVs. Updates to equivalent to IEC Part 7 Network and System Management: update process to Ed 2 started in 2013 Part 8 developing TR as Guidelines for using RBAC Part 9 Key Management: CD issued in August 2013; comments being addressed Part 11 Security for XML Files: in progress Resilience and Security for DER systems and other field devices (collaborate with WG17 and WG21 as appropriate) Conformance Testing TR Profiles for web services including XMPP (once the requirements are determined in the IEC development) Metering (collaborate with TC13) Explore customer premises security issues with WG21 TC57 Security (IEC 62351) Roadmap

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

IEC ~ Standardized Network and System Management Network and system management (NSM) data object models Using Simple Network Management Protocol (SNMP) Coherent status and monitoring data of the power infrastructure/grid Different grid areas, diff. comm. channels, network segments, different protocols, etc. Geneva, Switzerland, September

IEC Network and System Management Geneva, Switzerland, September

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

IEC ~ Standardized Role-Based Access Control Standardized Central User Account Management in the automation, industrial, embedded world Standardized RBAC (Role Based Access Control) User tokens : X.509 certificates User certificates specify user’s roles, roles grouped in AoRs Pull (e.g. LDAP) & Push (e.g. SmartCards) methods supported Geneva, Switzerland, September

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

IEC ~ Standardized Key Management Methods Device/user X.509 digital certificates PKI methods and protocols Full key life cycle : from Creation until the end-of-life GDOI (distribution of symmetrical keys) Geneva, Switzerland, September

Geneva, Switzerland, September Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Geneva, Switzerland, September Liaisons with Other Security Activities Liaison with ISO JTC 1 / SC 27 IT Security: WG15 has provided lists of Smart Grid security standards & documents to SC27. WG15 has reviewed documents of the 270xx series on general cyber security. WG15 welcomes the publication of ISO/IEC TR SC27 liaison : SC27 expects to attend additional WG15 meetings Liaison D with M/490 SGIS: WG15 is exchanging information with SGIS Liaison D with UCAIug: Discussions with SG-Security in UCAIug are underway. Liaison A with IEC TC65C which is standardizing the work of the ISA SP99 Security Standards. Some WG15 members have reviewed and commented on IEC drafts Liaison D with the IEEE PES PSCC Security Subcommittee Working with IEEE Substations on Cybersecurity Standard IEEE 1686

Coordination with Security Groups Coordination mostly through common membership: NIST’s Smart Grid Interoperability Panel (SGIP) Smart Grid Cybersecurity Committee (SGCC) (used to be called CSWG) SGIS NERC CIPs Cigré D2.34 MultiSpeak Security / Security for Web Services (e.g. WS-Security) NESCOR IEC TC13 ITU-T 26 Geneva, Switzerland, September 2014

27 Topics Industrial Cyber Security Essentials Mission and Scope of TC57 WG15 Members IEC Parts & Status IEC Roadmap About IEC Parts 7, 8 and 9 Liaisons and Coordination Standardization Issues

Geneva, Switzerland, September Cyber Security Standardization Issues Although we have cybersecurity experts, they are very busy Cybersecurity is a very dynamic, rapidly changing field which is quite new for the power & automation industries Need to coordinate with other industries and standards groups Need rapid development of new standards and updates to existing standards Need guidelines for end-to-end security, but only for very specific aspects Need both standards and technical reports Need input from power system domain experts on security requirements Need conformance and/or interoperability testing for IEC Abstract conformance test cases should be in each Part, with IEC providing specifics for Interoperability testing?

Geneva, Switzerland, September Questions? Comments?

Geneva, Switzerland, September Thanks

Geneva, Switzerland, September