Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Friday, March 21, 2014

SPIDERS Secure Microgrid Industry Show & Tell Coming Up

Army energy wizard and acting branch chief Harold Sanborn, who's had his hands on SPIDERS since day one, will be there. So will my fellow Zoomie Stuart McCafferty, CEO of GridIntellect, who's been sharing his vast microgrid expertise recently on SmartGridNews.com. I'd also expect engineers from Burns McDonnell, who've been integral to SPIDERS success, to be in attendance.

Here are the basics for you:

It's called, somewhat verbosely: "The Smart Power Infrastructure Demonstration for Energy Reliability and Security (SPIDERS) Joint Capability Technology Demonstration (JCTD) Industry Day"

Date/Time:
22 April 2014, 0800-1330

Location:

Fort Carson McMahon Theater
1517 McDonald Ave
Fort Carson, CO (south side of Colorado Springs)

Official Description:

Hosted by the U.S. Northern Command, JCTD Industry Day will focus on sharing the lessons learned and results of the Phase 2 Operational Demonstration performed at Fort Carson with the public sector and partner agencies.

This event is open to all stakeholders with an interest in the development of secure microgrids, ranging from policy and regulatory bodies and equipment vendors to those tasked with the development of standards and specifications and utilities that will be interconnecting with these microgrids.

Highlights
  • SPIDERS Technical Report
  • V2G solutions and technical and acquisition evolution from Phase 1
  • Microgid Cyber Security: Critical Elements, Requirements and Controls
  • Transitioning SPIDERS JCTD to Industry and Military
  • Cyber Experimentation Report
  • Phase 3 & Future Plans Post-SPIDERS JCTD
  • Tours of Ft. Carson Microgrid while under Red Team Cyber Attack
Link for More Info and to Register

http://energy.gov/eere/femp/articles/register-attend-spiders-joint-capability-technology-demonstration-industry-day

Hope you can make it. ab

Thursday, October 31, 2013

Happy Halloween DOD: Great Microgrid Primer from the SPIDERS team


DOD's Smart Power Infrastructure Demonstration for Energy Reliability and Security (SPIDERS microgrid program) prime integrator Burns & McDonnell has produced an outstanding white paper for anyone wanting to better understand the why's and how's of microgrids.

Overall it's a great paper, but two parts jumped out at me immediately for their value to decision makers.  Here you go, the first is from a section on mission drivers:
By allowing multiple generation assets to provide power for a common load, microgrids greatly increase both the reliability of power and its efficiency of generation. Typically, the greatest beneficiaries of microgrids are customers with large, mission critical facilities or large power consumers in areas prone to frequent and/or prolonged outages (e.g. hurricane zones). Although facilities like these have utilized on site generation in the past, they are starting to migrate towards microgrids due to the many examples of single generators failing during prolonged outages thereby leaving the entire mission in jeopardy.

Wednesday, July 24, 2013

Major SPIDERS Update, Advancing Energy Security & Barbarians at the Gate

This mega post just in from Mr. Harold Sanborn, Program Manager at Construction Engineering Research Lab (CERL), US Army and technical manager for the SPIDERS Joint Capability Technology Demonstration (JCTD).  It's chock full of good news and you'll want to read it top-to-bottom to get the full picture. ab

Starting from the vantage point (30 years of civil service) that "no good idea goes unpunished" allows me the freedom to work complex problems knowing that the threat of doom comes with the territory. Being twisted and enjoying pain keeps me in the zone.

SPIDERS Phase I has finished the "history tour" as we codify and publish the lessons learned. First lesson, see sentence one... Acquisition of both Military Construction and Research and Development on the same contract at a firm fixed price (not a cost plus AFRL contract) isn't done every day. The Joint Capability Technology Demonstration (JCTD) guidance for a minimum of Technology Readiness Level 6 as a pre-condition, to accelerate the deployment of technologies, while needing to leave behind a functioning, sustainable and useful real property improvement in energy security, stretches one's mind. Arguably we accomplished what we set out to do.

Tuesday, June 4, 2013

DOD Energy must learn from DSB report on cybersecurity strengths (and weaknesses)

DOD Energy Blog readers - I try not to do this too often, but when the content of the Smart Grid Security Blog is particularly relevant, we sometimes to a twofer.  That is publishing the same post on both blogs, albeit with slightly different titles. As you know from recent posts on the great secure smart and microgrid work going on at Naval District Washington (NDW), through the SPIDERS program, and elsewhere, much of a good portion of DOD energy security is rooted in cybersecurity. As such, I think this post and the report it references are particularly relevant to our cause.  Here you go:

Last year the US DoD released a report by one of its Defense Science Board teams and I've seen it referenced a number of times in recent weeks, especially in articles announcing our loss of the most sensitive systems design details on dozens of current and next generation weapons systems.

Tuesday, May 14, 2013

Energy Security Conference Alert: IAGS' Target Energy 2013

What is IAGS you say? I'll answer briskly: the Institute for the Analysis of of Global Security. Teaming with NATO's Energy Security Center of Excellence, IAGS is hosting a conference called Target Energy that includes but goes well beyond cybersecurity and the grid.

For those DOD Energy Blog readers whose professional lives are circumscribed by US military energy matters only, this is a chance to stretch a bit. Here's how the organizers describe the focus:
The cost of securing energy supplies is increasing due to threats from terrorists, hackers, activists and hostile nations. What is the impact of attacks against energy, and how can companies, organizations, and governments work with NATO to increase security?

Wednesday, May 8, 2013

Navy Connects to Achieve Physical, Cyber and Energy Security at Naval District Washington

I posted on this NDW effort earlier this year, but now it appears they have accomplished a rather remarkable trifecta. By leveraging an already accredited (secure) command and control network, it appears the Navy NDW folks have achieved improved physical security capabilities, enhanced energy security through Smart, microgrid, and building management functions, and cybersecurity that has passed the scrutiny of the Common Criteria process for vetting the security robustness of important systems.

This is the first Navy site to complete the certification and accreditation process using a full enterprise approach. Here's how Richard Robishaw, regional operations director, puts it:

Monday, February 25, 2013

The Future of Naval Installation Energy is Upon Us

As projected several years ago in this great 5-minute video, paving the way for demand management, energy efficiency, microgrids, support for renewables and all manner of support-the-mission, energy security goals (with cybersecurity baked in, to boot).



From all accounts, the folks involved with this initiative are right on schedule and are meeting their objectives. Recommend you keep an eye on this.  Andy

Saturday, April 7, 2012

USAF Seeking (More than) a Few Good Cyber Men and Women


[Thanks to my friend and Academy classmate Chris Davis (USAFA '85) for the heads-up on this recent Air Force news, and also to the folks at the SGSB for allowing this cross-post.]

Wonder if anyone in DOD has heard of the excellent NBISE, an organization dedicated to cranking out a better breed of cyber defense professional?  Anyone out there know Space Command's General Shelton, quoted within HERE? Maybe he could send some scouts to watch for talent at NBISE's upcoming US Cyber Challenge. It's open for registration now.

Here are a couple of plugs for the event. First, from the Hon. Mike McConnell former Director of National Security and Vice Chairman of Booz Allen Hamilton:
Our government and U.S. commercial companies are being besieged by attempted cyber attacks every day, and the nation needs as many resources as possible to prevent damage and the theft of intellectual capital. The U.S. Cyber Challenge offers a unique and exciting platform to identify the talent we need to defend our nation.
And here's Michael Assante, President & CEO, National Board of Information Security Examiners (NBISE):
The Cyber Quest competition and Cyber Camps are critical as our nation continually undergoes fast-paced changes in technology. Our growing reliance on digital technology requires concentrated efforts, like these, to identify and best develop the next generation of highly skilled cyber security professionals.
Please get the word out on this event if you can. Andy Bochman

Thursday, July 15, 2010

Navy Vets in Key Energy Security Positions: NERC CISO

This post comes to you via the DOD Energy Blog's sister site, the Smart Grid Security Blog.

--------------------------------------

Just so you know, there was a shift in the force recently as Michael Assante stepped down from the CISO position and NERC sought an able replacement. This post (and this NERC announcement) informs you that, happily, the new CISO has been installed and we're back on track.

Good thing too, cause the electricity generating, transmitting (if not yet, distributing) industry is being pulled in two seemingly opposing directions: on one hand, the desire the demonstrate compliance with CIPS 002-009; while on the other, high anxiety that:
  • CIPS 010 and 011 are much different than 002-009 (see summary from James Holler here) and unless they're phased in VERY gradually, that means trouble
  • The new CIPS are based largely on security control standards like those in NIST SP 800-53 "Recommended Security Controls for Federal Information Systems and Organizations." Again, a whole different enchilada in terms of detail than what's in 002-009
  • This will force huge changes (and likely, commensurate new expenses) for utilities trying make the best of limited human resources, time and funds
Maybe there's a loose connection of sorts here. I recall that the SP 800-53 controls are referenced in DOD 8500.x security policies (see DITSCAP and DIACAP). Michael Assante was a Naval intel officer and seems to me he did a great job during his tenure at NERC. Now Mark Weatherford, recently the CISO for the states of California and Colorado, also comes to the office with a solid Navy pedigree. From the NERC announcement on him:
Weatherford began his career as a Naval Cryptologic Officer, where he led the Navy’s Computer Network Defense operations and the Naval Computer Incident Response Team. Weatherford has a bachelor’s degree from the University of Arizona and a master’s degree from the Naval Postgraduate School.
One thing we've seen in our talks with CISOs and other security professionals in the utilities and ISO/RTOs is the prevalence of prior military (though not always Naval) experience, including folks who did crypto and other cyber security related jobs when they were slightly less "seasoned."

Well, as you'll see from Holler's summary, if not your own hands-on experience in the compliance trenches, it may well be a rough ride moving from the relatively light-weight original CIPS, which really just went fully live on 1 Jan of this year, to the industrial strength 010 and 011. I for one am pulling for Mark to do a great job and wish him every success. We all have a job to do, but his is a key role in this.

Thursday, October 1, 2009

As Pledged: Two Smart Grid Security Posts from GridWeek

Folks working energy strategy and energy security at OSD and in the Services are getting earful these days about how the Smart Grid (and its smaller cousin, the microgrid) are going to make it easier to integrate renewables into their facilities energy portfolios and help solve the brittle grid to boot.

Last week a colleague of mine and I were at the GridWeek conference in DC, one of the more prominent of the many dozens of Smart Grid-related conferences happening every year and I said we'd share some findings here on the DOD Energy Blog. Well, without further excess verbosity, here they are, visiting from a sister blog, with excerpts:
1) GridWeek Smart Grid Startups and Security
... the great Smart Grid project could fail, or fail to thrive, largely based on its ability to get security reasonably right, and because adoption will be partially determined by industry and public perception of its safety. The finding that young Smart Grid companies, as represented here, have not prioritized security action, versus titling and responsibility, is a concern.
2) Smart Grid Startups and Security: Round 2 from GridWeek
Hyperbole aside, we all know that the Smart Grid is an area of growing and inevitable security risk. If I'm a utility, and as such am a prospective new customer for a startup, and I'm held accountable to the highest security standards by those who regulate me, I'm going to be damned sure that I put prospective vendors through the ringer before bringing their technology in house. And if I'm a startup, while having a qualified security person on my staff is no silver bullet, our guess is they'll be more than worth their salary as the regulators press their security cases and the utilities/customers get more and more savvy about risk.
By the way, as far as I was able to discern, I only found one rep each from DLA and DHS in attendance, with a handful from Lockheed, Northrop and Raytheon. Will be interesting to learn just how many in the Department are tasked with monitoring which way (and how hard) the Smart Grid winds are blowing, and how to position the DOD ship for maximum advantage.

Tuesday, September 22, 2009

DIACAP a Good Fit for DOD Smart Grid Security?

... and if so, is it being used in the field as DOD rolls out its first few Smart Grid and micro grid pilots, and if so by whom?

The DOD refers to much of cyber security as Information Assurance (IA). And thes primary policy document that instructs the services on which IA controls to implement and how to get their security program right is called the DOD Information Assurance Certification and Accreditation Program, or DIACAP. Here's a short Wikipedia DIACAP summary for you. While great work is being done at NIST and elsewhere right now on Smart Grid security standards, DIACAP seems like a logical starting point for securing Smart Grid devices and systems at DOD facilities.

So far I've received no answers to this question from folks I thought would know in the Department. I've heard security minded folks in the energy industry reference DOD practices as inspiration for some of their cyber security strategies, but have yet to connect the dots. I like to connect dots, so this is a point of frustration.

Thursday, July 16, 2009

Federal Government Smart Grid Security Wake-Up Call

In case you don't know, I started another blog recently, called the Smart Grid Security Blog. I generally try to keep the DOD Energy world separate from the Smart Grid Security world, but as you can imagine, there are undeniable points of intersection.

Here's a post linking to a very well framed recent article by a colleague of mine. It's a great summary of key cyber security issues and actions for Smart Grid initiates. And the strategies it recommends are as applicable to Fed Gov and DOD as they are to all sectors. Think about the security controls being built in (or left out) of new DOD and DOE garrison-level microgrid deployments such as the one discussed here.

Thursday, July 2, 2009

Cyber Security Wake-up Call on DOD Facilities Control Systems

For some, the title of this post won't make the connection to DOD energy issues immediately obvious. Well, all I can say is: think about the Smart Grid, the growing melange of old world electric grid systems and cutting edge networking and Web 2.0 software systems.

Then consider the DSB-identified brittle grid challenge to DOD bases: "Critical missions at fixed installations are at unacceptable risk from extended power loss" and the various smart and micro grid solutions being considered to help isolate them via "islanding." See this presentation delivered at the June 2009 Air Force Cyber Security Symposium for a solid intro.

Sunday, April 12, 2009

You Sure You Want a Smart Grid?

Just one question for you. If this is how grid operators deal with risk pre-smart grid, how the heck are they going to secure the web enabled, bi-directional communications world coming at us with a gathering head of steam?

The North American Electric Reliability Corporation (NERC):
... is asking operators to take another look at their risk assessment methodologies and conduct a new evaluation of critical assets and associated cyber assets. Too many organizations are starting their evaluations with the assumption that no system is critical until it is proved to be so. [NERC CSO] Assante suggested that they reverse the process and assume that every system is critical until it can be demonstrated otherwise.
You don't have to be a security expert to smell several rotten things in these few pages. More on this to follow ...

Sunday, March 22, 2009

Smart Grid Vulnerabilities Might Make us Nostalgic for the Dumb Grid

Last week CNN raised an important and very timely point about the upcoming version 2.0 electric grid: that it may be too easy for bad guys to hack into, take out big parts of it, or otherwise manipulate its behavior.

Maybe the analogy isn't entirely apt (I'm still learning), but let's give it a shot. The US telecommunications industry transformed its infrastructure over the past several decades by replacing mechanical switches with modern computer networking equipment over fiber optic lines. I don't know about you, but cell coverage notwithstanding, my mobile phone, VOIP office phones and home landlines are reliable as I need them to be. The telcos appear to have secured their systems well, and/or have made them resilient and resistant to attack using redundancy and self-healing methods.

Drawing lessons from that highly succesful conversion, US regulators and the power industry are seeking ways to improve the reliability, efficiency and flexibility of the current electric genatration, transmission and consumption system, which is basically unchanged from what was in place nearly a century ago.

However as they do this, they need to be mindful that to be effective, security cannot be bolted on after system is deployed, but rather has to be a fundamental objective of the initial design. If they neglect security up front or get it wrong:
Experts said that once in the system, a hacker could gain control of thousands, even millions, of meters and shut them off simultaneously. A hacker also might be able to dramatically increase or decrease the demand for power, disrupting the load balance on the local power grid and causing a blackout. These experts said such a localized power outage would cascade to other parts of the grid, expanding the blackout. No one knows how big it could get.
Absent solid security from the get go, as the title of this post suggests, DOD and the rest of the nation may rue the day when we tried to gain advantages over our current brittle but generally available grid by overlaying internet technologies on a massively complex critical infrastructure system that has life and death consequences for many of its users.

Tuesday, March 10, 2009

Energy Security Wars: Grids vs. Hackers

According to this Washington Post article, the grid doesn't always win, especially in some ambiguous foreign countries. Tom Donahue, the CIA's top cyber security analyst, made some news when he disclosed that cyber attackers have breached the electrical systems of multiple countries and have gone as far as powering down entire cities when their demands weren't met.

Of course, it's not business as usual for the CIA to speak out so publicly:
The CIA wouldn't have changed its policy on disclosure if it wasn't important. Donahue wouldn't have said it publicly if he didn't think the threat was very large and that companies needed to fix things right now.
But it's not just that hackers are getting more organized and more powerful. Grid breaches are occurring because new IT and communications technologies are making life easier for operators ... and at the same time, more dangerous for customers.  According to security specialist Ralph Logan:
In the past, if they wanted to go out and read a gauge on a gas well, for example, they would have to send a technician in his vehicle; he would drive 100 miles and physically read the gauge and get back in his truck. Now they can read it from headquarters. But it allows attackers a gateway into the system.
All I can say is get ready for the Smart Grid, DOD. I'd recommend more diesel generators on the base ... and lots of candles in the home.

Photo: Wikipedia Commons

Tuesday, February 3, 2009

Be Concerned About Russia Week: Part II

Actually, I won't likely post on Russia for a bit after this. But a recent article in DefenseTech caught my attention as it relates to my day job in cyber security. When Putin, Medvedev & co. aren't turning off their natural gas pipelines or taking out journalists, they're stealthily unleashing cyber attacks on their former USSR neighbors. This time is was Kyrgzstan, home to one of the most important air strips in the world used by the DOD. Well, that was the case until maybe today. Loss of that base would add tremendous additional burdens on DOD fuel and other logistics requirements related to Afghanistan. There's lots more going on than here than offensive cyberwar, but it's clearly part of the overall package of threats Russia holds over its much weaker neighbors.

Back at home, the DHS classifies the US national grid and the large power generating facilities as critical national infrastructure. Considerations of energy security from a DOD and national perspective have to consider the vulnerability of our power generation and transmission systems to cyber attack. And while we talk about this, Russia sure is getting a lot of hands-on practice. Oh yeah, and China too (see: Titan Rain).