Search NASA⌕ Search

SEARCH · Search NASA

Results for “Posture”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 415 records · Page 23

CARILEC Resilient Energy Community CoP for Cybersecurity Workshop Series: Cybersecurity Assessment Tools [Slides]

For the last several years and in collaboration with CARILEC, USAID and NREL have been working to support cyber resilience at power sector utilities in Latin America and the Caribbean. Direct technical assistance with regional utilities has been a key component of USAID-NREL Partnership activities, and technical assistance has typically included a foundational cybersecurity assessment using NREL's Distributed Energy Resource Cybersecurity Framework (DER-CF) tool. The DER-CF allows organizations to benchmark and evaluate their cybersecurity posture across the areas of Governance, Technical Management, and Physical Security. To complement the activities of the newly created CAREC IT/OT and Cybersecurity Team, this webinar on cybersecurity assessment tools includes an overview of the DER-CF tool and a discussion with regional stakeholders and NREL experts on the DER-CF assessment process and other resources for cybersecurity assessments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Informed Engineering (CIE) Principles Slide Presentation [Slides]

This document describes the concept and application of Cyber-Informed Engineering (CIE), a methodology that integrates cyber threat awareness into all stages of the systems engineering life cycle. It delineates how CIE enhances the security posture of critical infrastructure systems, which are increasingly targeted by sophisticated cyber threats. The exposition proceeds to methodically walk through the twelve foundational principles of CIE, each serving as a strategic guidepost for embedding cybersecurity into the fabric of system design, development, operation, and maintenance. The principles highlight the importance of proactive and comprehensive security measures that span from risk assessment to continuous improvement, ensuring that systems are not only designed with security in mind but are also resilient in the face of evolving cyber threats.

42 ENGINEERING↗

Design of Defensive Cybersecurity Architectures for High Temperature, Gas-Cooled Reactors

This report presents the design of defensive cybersecurity architectures (DCSAs) for High Temperature, Gas-Cooled Reactors (HTGRs). A DCSA is a cybersecurity design feature that places systems into security zones in a graded approach according to the importance of the functions performed by the systems. DCSA design efforts for advanced reactors may commence as early as the system-level design phase. This design approach is consistent with the draft regulatory guide for advanced reactor cybersecurity programs (DG-5075) and enables advanced reactor designers to consider the effects of security-by-design (SeBD) features on their DCSAs. Integration of DCSA design and other cybersecurity activities with the traditional design process as part of a SeBD framework may enable advanced reactor designers to improve the security posture of their plants while reducing implementation and operating costs. This report provides a DCSA template for an exemplar HTGR and describes a DCSA design process using event tree analysis so that the template may be optimized for a given HTGR design.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Small Modular Reactor and Microreactor Security-by-Design Lessons Learned: Integrated PPS Designs

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. The past approach has often included implementing security features after a facility has been designed and without attention to optimization, which can lead to cost overruns. Incorporating security into the design process can provide robust, cost-effective, and sufficient physical protection systems. The purpose of this report is to capture lessons learned by the Advanced Reactor Safeguards and Security (ARSS) program that may be beneficial for other advanced and small modular reactor (SMR) vendors to use when developing security systems and postures. This report will capture relevant information that can be used in the security-by-design (SeBD) process for SMR and microreactor vendors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessment of Physical Security Modeling and Simulation in the Vulnerability Assessment Process

This report provides a comprehensive assessment of physical security modeling and simulation tools available for use in the vulnerability assessment (VA) process for nuclear facilities. It outlines the historical evolution of VA methodologies, emphasizing the transition from traditional layer-based approaches to a more holistic framework that integrates detection probabilities directly into combat simulations. The document details the critical components of the VA process, including the characterization of targets, threats, and protective measures, as well as the development of adversary scenarios that reflect both insider and outsider threats. It highlights the importance of performance assurance programs, emphasizing the need for continuous evaluation and testing of security systems to ensure their effectiveness against evolving threats. Additionally, the report discusses the significance of utilizing accredited modeling and simulation tools in accredited areas to accurately represent adversary actions and the corresponding responses of protective forces. By establishing a systematic approach to VA, this document aims to enhance the overall security posture of nuclear facilities, ensuring compliance with regulatory standards while effectively mitigating risks associated with potential adversarial actions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Enterprise Artificial Intelligence Strategy for Los Alamos National Laboratory

In the 1984 martial arts drama film, The Karate Kid, a young Daniel LaRusso is unexpectedly placed in an adversarial environment unable to eYectively adapt to a series of new threats and limitations. Fortunately for the main character, once placed under the tutelage of a Mr. Miyagi, he finds resiliency not through the adoption of new tools, but a re-focused set of fundamentals. Much in the same way that Daniel learns waxing on and buYing oY car wax by hand has rewards for Karate, LANL is choosing the harder path of self-hosting Large Language Models (LLMs) for enterprise use instead of only relying on buying access to a hosted AI service like Azure’s OpenAI Application Programming Interface (API). We also are not willing to wait for software-as-a-service (SAAS) AI services to meet us where we need to be from a FedRAMP accreditation standpoint. Our operations regularly depend on access at CUI, UCNI, ITAR and other FIPS-199 moderate-impact data levels and hosting our own services gives us the right security and compliance posture to be useful across the broad range of our work at LANL. With the rise in threats to critical infrastructure, cloud service providers (CSPs), and supply chain attacks from both state and non-state actors, we are not placing the bet that SAAS hosted AI services will be available when we need them. Should a major event occur, we do not want our staY and operations left without a pathway for us to fix the problem and resume the use of AI tools.

42 ENGINEERING↗

Zero Trust Strategies for Chemical, Biological, Radiological, and Nuclear Detection Systems: D.1 Cyber Scenarios

The evolving landscape of cybersecurity necessitates a paradigm shift to a Zero Trust (ZT) model, which assumes breaches and continuously verifies trust. This approach reshapes how trust boundaries are established, focusing on identities, devices, networks, applications, and data, rather than solely relying on perimeter defenses such as firewalls. Central to this transformation is the National Institute of Standards and Technology's (NIST) Special Publication 800-207, outlining the Zero Trust Architecture (ZTA), along with Executive Order 14028, which mandates federal agencies to adopt ZT principles. Complementary to these efforts, the Cybersecurity and Infrastructure Security Agency (CISA) developed the Zero Trust Maturity Model (ZTMM), providing a framework with five pillars and three cross-cutting capabilities to guide agencies toward enhanced cybersecurity maturity. In support of these initiatives, the DHS Countering Weapons of Mass Destruction Office (CWMD) is applying ZT principles to secure Chemical, Biological, Radiological, and Nuclear (CBRN) detection systems. Recognizing the diverse deployment models and network connectivity of these systems—from stationary, non-networked units to mobile, cloud-connected devices—the Pacific Northwest National Laboratory (PNNL) is developing cybersecurity scenarios specifically for CBRN environments. These scenarios examine various configurations and technological capabilities, offering insights into the application of ZTMM pillars in enhancing the security postures of CBRN devices. The cybersecurity scenarios presented by PNNL are hypothetical, crafted to explore theoretical situations and stimulate discussion on the potential use or compromise of CBRN detection systems in varied contexts. These narratives are illustrative and do not reference any real events or actual networks. Instead, they employ generalized reference models to highlight concepts and potential issues within CBRN security, focusing on how Zero Trust strategies can be adapted to address these challenges effectively.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

How Quantum Sensing Will Help Solve GPS Denial in Warfare

The U.S. military’s ability to posture, deter, and prevail in future conflicts may rest on the quantum sensing position, navigation, and timing (PNT) capabilities that are currently being developed. Heavy reliance on GPS signals for PNT has become a critical vulnerability for the U.S. military. Meanwhile, the conflict in Ukraine has demonstrated that GPS denial and electronic warfare (EW) is now a key component of modern combat and satellite-guided munitions are reportedly being rendered ineffective. The Department of Defense (DOD) is focusing on upgrading GPS to use stronger, military-specific signals, which will still be vulnerable to EW and anti-satellite capabilities. A more diverse and resilient alternate-PNT strategy is needed to ensure mission success.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Security-by-Design: Light Water Small Modular Reactor

The growing demand for nuclear power is increasing pressure to find solutions to cost prohibitive requirements of both construction and security. Offsite response has been proposed as an option to reduce costs associated with training and maintaining an onsite response force. A previous report explored this option and revealed that security could be provided at the required level, but cost savings was not a result of this methodology. An offsite response strategy required costly active and passive delay barriers to provide sufficient time for responders to muster and deploy to a site in time to interrupt a determined and well-equipped adversary. Also, contrary to the hypothesis, the number of responders required for this strategy exceeded that needed for an onsite response force, as the adversaries could avail themselves of advantageous positions within the facility to repel arriving responders. This report builds upon the previous evaluation by using the same hypothetical light water small modular reactor (LWSMR) facility model, but this time an onsite response strategy was assessed. The goal of this analysis was to show that an onsite response strategy could be implemented effectively at a cost point that removes barriers within the industry at this critical time of growth and development. The assessment of the facility design and response strategy was completed through modeling using Scribe3D© and subsequent scenario analysis over the course of a two-day tabletop exercise. Subject matter experts in nuclear security, nuclear facility design, and response strategy and tactics contributed to the effort to ensure accurate representation of hypothetical scenarios. Several adaptations were made to the layout of the LWSMR based on lessons learned during the first day of scenario analysis. The subsequent design evaluated on the second day proved to provide a robust response posture against a large and well-trained adversary force. This report details the process of the analysis and compares the cost of the final facility design with that of the LWSMR model used for evaluation of offsite response. Ultimately, the results of this effort indicate that, when implemented correctly, an onsite response strategy is the best option from a security and cost perspective.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

From Stewardship to Transformation: Toward a Nuclear Enterprise for the 21st Century

The erosion of the global security environment over the last two decades has been rapid and dramatic. It appears also to be accelerating. There are deep and widening concerns in the United States and among its allies and partners that deterrence too has eroded at both the conventional and nuclear levels. The Strategic Posture Commission captured the essence of the problem in its October 2023 report—the United States seeks to meet the challenges of complex multipolar nuclear rivalry in the 21 st century with a slimmed down version of a nuclear deterrent designed in the middle of the 20 th century. With great urgency, the Commission recommended that something more and/or different is needed than simply the replacement of legacy systems with modern variants. But the U.S. nuclear security enterprise was reshaped after the Cold War to support the stockpile stewardship mission—not renewed designed, engineering, and production at scale. It has long fallen short of the agility, flexibility, and adaptiveness periodically asked of it by national leaders. In recent years, however, the message of urgency has been clearly received in the enterprise. Its culture has begun to shift. It has also been received by those in Washington D.C. responsible for funding and guiding the enterprise. The result is an enterprise in transition. Stockpile stewardship has given way to stockpile transformation. Risk aversion is giving way to risk management. Innovation and adaptation have been embraced. Experience to date has yielded some important lessons about what works and what doesn’t in terms of accelerating and delivering the needed innovation and adaptation. It has revealed the enduring character of some challenges. But it has also revealed that a much more agile and effective enterprise is within the national reach—something that will pay important dividends for deterrence, assurance, strategic stability, and peace.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Securing Solar for the Grid (S2G) (Final Project Report) [Slides]

This is the final technical report for the SETO-funded project Securing Solar for the Grid (S2G) from FY22-24. The project scope included development and dissemination of standards' requirements, best practices, equipment testing procedures, assessment tools, as well as education and training materials for cyber defense, posture and maturity tailored to solar technologies. The outcomes for this work include: co-led the development of cybersecurity certification standard (UL2941), co-led the development of cybersecurity guide (IEEE1547.3), development of recommendations for supply chain cybersecurity, and development of cybersecurity risk profiles and recommendations for DERMS.

14 SOLAR ENERGY↗

Design of Defensive Cybersecurity Architectures for Sodium-Cooled Fast Reactors

This report presents the design of defensive cybersecurity architectures (DCSAs) for Sodium-Cooled Fast Reactors (SFRs). A DCSA is a cybersecurity design feature that places systems into security zones in a graded approach according to the importance of the functions performed by the systems. DCSA design efforts for advanced reactors may commence as early as the system-level design phase. This design approach is consistent with the draft regulatory guide for advanced reactor cybersecurity programs (DG-5075) and enables advanced reactor designers to consider the effects of security-by design (SeBD) features on their DCSAs. Integration of DCSA design and other cybersecurity activities with the traditional design process as part of a SeBD framework may enable advanced reactor designers to improve the security posture of their plants while reducing implementation and operating costs. This report provides a DCSA template for an exemplar SFR and how the template may be optimized for a given SFR design.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Equipment Assessment Guide: A Technical Inspection and Hardening Guide for Devices in Power Grid Operations

This Equipment Assessment Guide, developed by Idaho National Laboratory (INL), provides a comprehensive framework designed to enhance the security of operational technology (OT) devices within power grid operations. The guide outlines essential steps for asset owners to conduct technical inspections and harden vulnerable hardware and firmware components commonly found in embedded systems. It focuses on components frequently targeted by cyber threats, offering valuable identification techniques for locating and recognizing critical components on devices. Additionally, the guide presents recommended secure configurations aimed at minimizing exposure and reinforcing defenses, along with impact analysis that highlights the potential consequences for grid operations if components are compromised. By implementing the recommendations outlined in this guide, asset owners can significantly enhance their cybersecurity posture, reduce the attack surface of field-deployed devices, and improve the resilience of grid services against emerging cyber threats.

42 - ENGINEERING↗

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CyTRICS™ Assessment Report: Whole Home Battery Applications

This report examines the software supply chain security posture of mobile applications developed for consumer whole-house battery and energy-management products. While these applications are not currently integrated with critical infrastructure, their growing role in connected energy domain spaces underscores the importance of understanding the external dependencies, permission structures, and runtime behaviors that could introduce systemic risk; particularly, if adoption expands into more critical environments.

25 ENERGY STORAGE↗

CyberMESA: Evaluation Procedures and Metrics for Charging Infrastructure Cybersecurity

A report detailing the cybersecurity evaluation and assessment procedures for EV charging infrastructure. This report is authored by three national lab contributors. INL, PNNL, NRL. The grid integration of Electric Vehicle Charging Infrastructure (EVCI) is a large and complex system of systems (SoS) made up of components from many manufacturers and integrated by various companies responsible for their operation and maintenance. This complexity makes it challenging to implement security standards like IEC 62443 across the entire infrastructure. This document aims to aid in the vulnerability assessments of individual devices, such as Electric Vehicle Supply Equipment (EVSE), to support vendors in adopting and implementing security standards such as UL 2900, NIST SP 800-53 and Common Criteria (CC) (ISO/IEC 15408). This document serves as a guide to help evaluate the cybersecurity posture of EVCI assets. It aims to provide a consistent method for evaluating EVCI, enabling cybersecurity research teams to systematically test a wide range of electric vehicle (EV) assets. The target audiences include cybersecurity research teams, vendor development teams, automotive OEMs, and third-party evaluators.

24 POWER TRANSMISSION AND DISTRIBUTION↗