Search NASA⌕ Search

Engineering topics

Powell, Charisa

Publications and source records attributed to Powell, Charisa.

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Software-defined Networking for Energy Delivery Systems (SDN4EDS): An Architectural Blueprint (Final Report)

This is the initial version of a reference for suppliers and energy companies of all sizes to deploy networks based on software-defined networking technology (SDN) to improve reliability, reduce cyber security attack surface, and facilitate mitigation of adversarial behavior. It is a living document and will progress over the life cycle of the Software-Defined Networking for Energy Delivery Systems (SDN4EDS) project. Version 2 of this report provides information on the Red Team tabletop assessment performed against the initial reference architecture. Version 3 of this report updates the reference architecture with lessons learned from the Red Team tabletop assessment, as well as provides additional details for the use cases. It also provides information on the decision process that could be used by an organization when considering deploying SDN in their environment. The final version of this report consolidates all the interim reports generated by the project into a final report. It also draws from PNNL’s experience in deploying SDN to make recommendations on how SDN could be deployed in a utility environment, and provides rationale for those decisions allowing individual utilities to make risk-based and knowledge-based decisions on how to best deploy SDN in their own environment

97 MATHEMATICS AND COMPUTING↗

Software-defined Networking for Energy Delivery Systems (SDN4EDS): An Architectural Blueprint (Final Summary Report)

This is the initial version of a reference for suppliers and energy companies of all sizes to deploy networks based on software-defined networking technology (SDN) to improve reliability, reduce cyber security attack surface, and facilitate mitigation of adversarial behavior. It is a living document and will progress over the life cycle of the Software-Defined Networking for Energy Delivery Systems (SDN4EDS) project. Version 2 of this report provides information on the Red Team tabletop assessment performed against the initial reference architecture. Version 3 of this report updates the reference architecture with lessons learned from the Red Team tabletop assessment, as well as provides additional details for the use cases. It also provides information on the decision process that could be used by an organization when considering deploying SDN in their environment. The final version of this report consolidates all the interim reports generated by the project into a final report. It also draws from PNNL’s experience in deploying SDN to make recommendations on how SDN could be deployed in a utility environment, and provides rationale for those decisions allowing individual utilities to make risk-based and knowledge-based decisions on how to best deploy SDN in their own environment. This summary report provides a higher-level overview of the project reports. Readers interested in additional detail, including results of the Red Team assessments and the final configuration, are encouraged to read the full final report.

97 MATHEMATICS AND COMPUTING↗

Hydropower Cyber-Physical Configurations

The U.S. Department of Energy’s Water Power Technologies Office funded Pacific Northwest National Laboratory, Argonne National Laboratory, and the National Renewable Energy Laboratory to develop a typology to characterize the variety and pervasiveness of cyber-physical configurations across the nation’s hydropower fleet. Outreach to owners and operators returned configurations for 275 hydropower plants or approximately 12% of the fleet. Components (OT and IT), systems, and connections among systems differed among plants according to function, age, position in the river cascade, and many other factors. Seven cyber-physical configuration types labeled A through I, included from 2 to dozens of plants. They were differentiated by how pervasive data and control connections were among cyber-physical components and how frequently control signals paired with data signals in a feedback loop. The flow of data and control within each type implies what cybersecurity vulnerabilities may exist, and what mitigation actions may be most effective. A self-assessment approach allows plant operators to identify the configuration type similar to their plant and link to the lessons learned and best practices information. The cyber-physical typology reinforces the idea that hydropower facilities vary widely, but it also identifies groups that highlight similarities in how their cyber-physical components interact. This helps address fleetwide cybersecurity needs by identifying a reasonable number of configuration types that share risks, vulnerabilities, and potential mitigations.

13 HYDRO ENERGY↗