Search NASASearch

SEARCH · Search NASA

Results for “knowledge sharing”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Federated learning for 2D synchrotron x-ray diffractometry: a cross-institutional approach for phase quantification of Ti–6Al–4V alloy

High-energy Two dimensional (2D) synchrotron x-ray diffractometry provides important insights into the atomistic structure and phase evolution of materials, yet traditional analysis methods remain complex, knowledge-intensive, and computationally demanding. Deep-learning models offer a powerful alternative for automating their analysis. Institutions that hold these datasets may be unwilling to share their data due to privacy and security policies, as well as the challenges associated with large-scale data transfer. As a result, models trained on local datasets often perform well only on their own data but exhibit bias and poor generalization across different instruments or facilities. To overcome these limitations, we explore federated learning (FL) for 2D synchrotron diffractograms, enabling collaborative model training without exchanging raw data. In this study, 2D synchrotron diffractograms of Ti–6Al–4V alloy collected from two independent facilities are used to train convolutional neural networks for predicting the β-phase volume fraction. Experimental results show that federated global models significantly outperform locally trained models in terms of generalization and achieve accuracy comparable to centralized trained models. These findings demonstrate the potential of FL to enable secure, cross-institutional collaboration and enhance the scalability of deep-learning-based materials characterization.

36 MATERIALS SCIENCE

CG-Kit: Code Generation Toolkit for performant and maintainable variants of source code applied to Flash-X hydrodynamics simulations

CG-Kit is a new Code Generation tool-Kit that we have developed as a part of the solution for portability and maintainability for multiphysics computing applications. The development of CG-Kit is rooted in the urgent need created by the shifting landscape of high-performance computing platforms and the algorithmic complexities of a particular large-scale multiphysics application: Flash-X. To efficiently use computing resources on a heterogeneous node, an application must have a map of computation to resources and a mechanism to move the data and computation to the resources according to the map. Most existing performance portability solutions are focussed on abstracting the expression of computations so that a unified source code can be specialized to run on different resources. However, such an approach is insufficient for a code like Flash-X, which has a multitude of code components that can be assembled in various permutations and combinations to form different instances of applications. Similar challenges apply to any code that has composability, where a single specified way of apportioning work among devices may not be optimal. Additionally, use cases arise where the optimal control flow of computation may differ for different devices while the underlying numerics remain identical. This combination leads to unique challenges including handling an existing large code base in Fortran and/or C/C++, subdivision of code into a great variety of units supporting a wide range of physics and numerical methods, different parallelization techniques for distributed and shared memory systems and accelerator devices, and heterogeneity of computing platforms requiring coexisting variants of parallel algorithms. All of these challenges demand that scientific software developers apply existing knowledge about domain applications, algorithms, and computing platforms to determine custom abstractions and granularity for code generation. There is a critical lack of tools to tackle those problems. CG-Kit is designed to fill this gap by providing a user with the ability to express their desired control flow and computation-to-resource map in the form a pseudocode-like recipe. It consists of standalone tools that can be combined into highly specific and, we argue, highly effective portability and maintainability toolchains. Here we present the design of our new tools: parametrized source trees, control flow graphs, and recipes. The tools are implemented in Python. They are agnostic to the programming language of the source code targeted for code generation. In conclusion, we demonstrate the capabilities of the toolkit with two examples, first, multithreaded variants of the basic AXPY operation, and second, variants of parallel algorithms within a hydrodynamics solver, called Spark, from Flash-X that operates on block-structured adaptive meshes.

Algorithmic portability

Hydrogen Education for a Decarbonized Global Economy (H 2 EDGE) (Final Technical Report)

The energy sector is undergoing rapid growth and transformation, creating urgent demand for a skilled workforce to support emerging technologies and resilient systems. Hydrogen is an emerging solution for “hard to abate” sectors, including heavy industry and transportation that also provides optionality for the electric system and enables long‑duration energy storage. As hydrogen scales from traditional industrial uses to new applications, success depends on knowledgeable engineers, technicians, planners, and operators safely deploying hydrogen technologies across the full value chain: production, delivery, storage, and end use. The H 2 EDGE initiative, funded by the U.S. Department of Energy’s Hydrogen and Fuel Cell Technologies Office from 2020 to 2025, was launched to prepare people for careers hydrogen and related technologies. Through its interactive approach, H 2 EDGE equipped stakeholders with knowledge and tools to build a reliable and sustainable energy future together. H 2 EDGE built a national network of academic and industry partners to deliver modular training, share open-access curricula, and engage diverse talent pipelines. The program leveraged EPRI’s extensive industry membership and expanded on the train-the-trainer model of the GridEd program to connect educators, employers, and community organizations across all regions of the U.S. New methods were introduced to more systematically map hydrogen competencies and assess curricula using traditional and AI-assisted approaches. Outcomes included delivery of professional short courses, developing university curriculum, sponsoring faculty and student projects, and engaging stakeholders through workshops, site tours, and webinars.

08 HYDROGEN

Application of Accelerator Technology to Quantum Information Science

The intersection of accelerator and quantum information science (QIS) offers a unique platform to advance both fields through shared technology and infrastructure. This talk will discuss the synergies which exist between these two vastly different but complementary domains. We demonstrate how we leverage pre-existing infrastructure and knowledge to perform research and development which helps to realize dramatic improvements in both 10 km long accelerators and 10 cm large quantum processors. We will explore niobium superconducting radio-frequency (SRF) cavities, a highly advanced technology that excels in efficiently storing electromagnetic energy, enabling ultra-long photon lifetimes critical for quantum processors and facilitating the characterization of quantum materials with parts-per-billion precision. We will also discuss how advancements in superconducting materials, cryogenic systems, and control techniques help to reduce cost and improve performance for both quantum systems and particle accelerators. Moreover, we will discuss cross-disciplinary applications such as dark-matter searches and demonstrate the convergence of these fields in addressing fundamental scientific questions.

Bafia, Daniel [Fermilab]

Improving Marine Energy Production Through Commercialization of a Low Cost, Drag-Reducing Slippery Coating (CRADA 679 Abstract)

Marine energy capture systems offer great promise for providing clean energy, but they operate in a challenging and dynamic environment and must be optimized to the highest extent possible. Computational studies predict that drag reduction on marine energy and blue economy systems will result in meaningful improvements in energy efficiency. Based on extensive coating experience, PNNL is proposing to bring to market a new drag-reducing coating called Superhydrophobic Lubricant-Infused Drag-Efficient Coating – SLIDE-Coat. PNNL has a deep knowledge base regarding this class of slippery coatings, and we have a group of enthusiastic industry partners who have committed to partnering, conducting field testing, and providing well over 50% cost share. In addition to validating the technology, the team will create a commercialization roadmap to ensure the commercial success of the technology after the government-sponsored two-year program is complete. The main technical goal is to design, manufacture, and experimentally validate a new coating that can reduce hydrodynamic skin friction drag by 20%. The main commercialization goal is to develop a roadmap that identifies activities needed to complete SLIDE-Coat’s development after the conclusion of this project. Year 1 will focus on adaptation and modification of the existing SLIC coating system to optimize drag reduction and assessment and quantification of drag reduction on relevant materials in a laboratory setting. Year 2 will focus on optimizing and demonstrating drag reduction with preferred coatings. The manufacturability, ease of application, adhesion to relevant surfaces, and consistency will be assessed. Quantification of drag reduction on prototype materials in a relevant marine field setting will be executed.

16 TIDAL AND WAVE POWER

Integrative Modeling and Analysis of Fungal Central Carbon Metabolism

Over a thousand fungal genomes have been sequenced, yet manually curated genome-scale metabolic models (GEMs) are available for only a limited number of species. Moreover, these models have often been developed independently, leading to inconsistencies in namespaces, compartment definitions, and pathway representations that hinder comparative analysis, the systematic reuse of prior curation efforts, and the integration of consolidated metabolic knowledge. Here, we present the Consolidated Fungal Core Metabolism Model (CFCMM), constructed by integrating thirteen published fungal models spanning Ascomycota, Mucoromycota, and both Crabtree-positive and Crabtree-negative yeasts. We harmonized metabolites and reactions into a non-redundant shared ModelSEED ontological space, standardized compartmentalization, and refined gene–protein–reaction (GPR) rules. Using pathway-level visualization and systematic gap detection, we further improved the integrated network through literature-guided curation to correct stoichiometry, stereospecificity, and pathway architecture. Orthologous protein family reconstruction and functional annotation workflows were used to validate and inform GPR associations, with particular emphasis on ambiguous enzyme superfamilies and membrane-associated components. Using the resulting CFCMM, we built high-quality central carbon core models for each fungus and performed flux balance analysis to quantify ATP-yield variation under aerobic and anaerobic conditions, explicitly evaluating scenarios driven by differences in electron transport chain (ETC) composition. Simulations reproduced the expected fermentative yield of approximately 2 mmol ATP per mmol glucose under anaerobic conditions and separated the thirteen fungi into two bioenergetic groups under aerobic respiration based on Complex I status, with predicted yields of approximately 30 versus 22 mmol ATP per mmol glucose. Forcing flux through the alternative oxidase bypass further reduced ATP yields to approximately 12 and 4 mmol ATP per mmol glucose in Complex I-containing and Complex I-lacking fungi, respectively. Collectively, this work provides a manually curated, ModelSEED-consistent, and extensible fungal core metabolic template, deployed in DOE KBase as a resource for automated reconstruction of central carbon core models from any sequenced fungal genome. In addition, the CFCMM provides modular components for developing GEMs with more accurate energy predictions and enables robust comparative analyses of fungal bioenergetics and core metabolic diversity

59 BASIC BIOLOGICAL SCIENCES

Methods of Securing Chemical and Pharmaceutical Knowledge and Recommendations for International Institutions to Enhance Research Integrity

Here, this paper examines strategies for securing chemical and pharmaceutical expertise in a globalized research environment, focusing on safeguarding intellectual property and preventing the misuse of sensitive and potentially dual-use information. The product of collective efforts between Pacific Northwest National Laboratory, Carol Davila University of Medicine and Pharmacy, and New Bulgarian University, highlights the challenges and opportunities posed by cross-border research collaborations, particularly in the context of differing regulatory frameworks and research cultures. It explores current mechanisms to prevent data loss and unauthorized access to sensitive information while assessing the effectiveness of existing security measures, frameworks, and international export control regimes. The approach examines the differing methodologies for promoting transparency, trust-building, and mutual accountability in joint research projects to cultivate secure data-sharing practices and intellectual property. It provides recommendations for international institutions to implement security guidelines in framing research priorities, encourages continual training and education programs, and the integration of processes for monitoring research compliance. This partnership aims to advance scientific innovation while maintaining global stability, ensuring compliance with international norms, and safeguarding valuable intellectual property as measures in chemical and pharmaceutical research security practices continue to expand due to international collaboration and knowledge exchange.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH

Outcomes of PAX sapiens-Supported Global Wildlife Data Sharing Conferences for Enhanced One Health Security (GWDSC)

Across two consecutive Global Wildlife Data Sharing Conferences supported by PAX sapiens—Year 1 (May 2024) at Pacific Northwest National Laboratory and Year 2 (2025) in Ciudad Real, Spain—the initiative converted wildlife data sharing from aspiration into operational reality, producing measurable impacts in platform development, data mobilization, standards harmonization, and international partnership formation. The conferences addressed a critical gap in global health security: while 75% of emerging infectious diseases affect both humans and animals and over 60% originate in wildlife, wildlife health surveillance has historically lagged behind human and agricultural sectors due to fragmented databases, inconsistent terminology, uneven capacity, and limited cross-border coordination. By convening practitioners, government agencies, international organizations, academic institutions, and NGOs, the GWDSC catalyzed trust-based relationships and practical workflows that enable earlier detection, better risk assessment, and more effective prevention of threats at the wildlife–domestic animal–human–environment interface.

54 ENVIRONMENTAL SCIENCES

Unlocking the benefits of transparent and reusable science for climate-risk management

People around the world seek climate-risk information to guide their decisions. For instance, projections about future flood risk inform where households choose to live, how lenders manage credit risks, and which communities receive federal funding. Yet data limitations and fundamental validation challenges raise important concerns about the reliability of such projections. The principles of transparency and reusability help address these concerns by enabling scrutiny of assumptions and methods, development of foundational data and tools, and consistent application of evaluation standards. While there is ongoing debate about how much transparency commercial climate-risk services should provide, many expect non-commercial actors to lead the way on operationalizing transparency and reusability to fulfill their knowledge-building role in the climate-risk ecosystem. However, despite prominent success stories, we find a substantial gap between principles and practice: only four percent of the most-cited peer-reviewed climate-risk studies in recent years fully share their data and code despite this being a widely accepted minimum standard for transparency. We highlight low-cost measures that non-commercial researchers can take now to improve transparency and reusability. We also emphasize that transformative progress requires substantial investment, cross-sector collaboration, and careful consideration of tradeoffs, data rights, and multiple perspectives on equity. We hope this perspective accelerates both immediate actions and longer-term conversations to improve the ability of science to effectively support timely, evidence-based, and sound climate-risk management.

Open Science

SIMBER: the Simula Berkeley Education and Research Collaboration (CRADA Final Report)

The SIMBER project is centered around advancing the state-of-the-art in the science of modelling of the human heart and leveraging the collaborations between leading research groups at the University of California Berkeley (UC Berkeley), the Lawrence Berkeley National Laboratory (Berkeley Lab), and Simula Research Laboratory (Simula). In particular, the following areas of expertise are shared and expanded through this project: “heart-on-chip” experimental systems from UC Berkeley, mathematical modelling of the heart from Simula, and supercomputing software from Simula and Berkeley Lab. This intersection of expertise is already enabling the development of novel tools and knowledge that produce more accurate models of the human heart in both health and disease, which in turn are leading to drug screening technologies that make cardiac drug development faster, cheaper and more humane.

Li, Xiaoye Sherry [Lawrence Berkeley National Labo

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie

Geospatial Data Platform for All

Spatiotemporal data has evolved in scale due to augmented use in cross-domain applications. Simultaneously, there is substantial growth in the availability of Geographic Information Systems (GIS) data provided by the United States Geological Survey (USGS) along with other federal, state, county, or local agencies through open-data portals and public access APIs. However, data availability does not equate with accessibility. Large-scale analyses and applications require robust, performant data management with co-location of data storage and computing. The insufficiency of data management infrastructure compels researchers to adopt ad hoc project- specific GIS data storage solutions (e.g., copying data to High-Performance computer file systems). As an ad hoc storage strategy does not scale, it hampers cross-domain analyses causing difficulty in data reuse and utilizing existing code bases. Furthermore, GIS data is complex and requires expertise to analyze and manipulate due to its intricate data structures and data-specific projection transformations. Despite the challenges, we recognize that derived GIS data products, e.g., satellite or LIDAR-based images, can be used in downstream applications such as AI by domain, but non-GIS experts. To address the data needs and overcome the challenges, we are working towards a GIS Data Platform focused on efficient data storage, data discovery and access, and an API to enable common workflows. We propose a knowledge-graph (KG) approach for data discovery, whereby datasets are semantically linked to higher- level constructs such as projects and research areas. The semantic data links enable researchers to explore datasets in a top-down approach by specifying relevant and meaningful terms (assists in finding hidden data). An advantage is that the nodes and edges in a knowledge graph create built-in semantic documentation. Deeper spatiotemporal connections between data sources can be encoded via Graph Neural Networks (GNN) (Zhang et al., 2021). The KG approach can be extended to integrate the data itself in a Virtual KG (VKG). Our work will derive inspiration from large-scale VKG efforts that have been undertaken or are currently underway as part of the OpenStreetMap project (Ding et al., 2021). For DOE Data Days, we share the proposed geospatial data platform hybrid (cloud/on-prem) architecture, our work-to-date on storing, retrieving, and transforming LiDAR and raster data relevant to two important NREL use-cases, including the Renewable Energy Potential (reV) Model, and present our proposal for a KG based data discovery engine.

data platform

Unveiling Structural Heterogeneity and Imbalance of Gold Decahedral Nanoparticles using Four-dimensional Scanning Transmission Electron Microscopy

Multi-twinned structures have been observed in technologically important crystal systems, for example diamond cubic and face-centered cubic (FCC) lattices, that include materials such as diamond, silicon, a wide range of noble metals, and their nanoscale counterparts. Beyond atomic building blocks, the special arrangements also occur in the self-assembly of nanoparticles (NP) and μm-sized colloidal particles and occupy parts of their phase diagrams. Spanning a wide range of length scales, the universality of the structures arises when the systems attempt to achieve multitwinned structures by overcoming geometric misfits during minimizing surface energies with entirely {111} or close-packing facets. While it is fundamental to understand how strain is sustained upon twinned structures and symmetry breaking, the knowledge will be paramount in practical aspects such as guiding and controlling the thin film growth, anisotropic NP growth, and self-assembly of NPs. Au decahedral (Dh) NP, as the most prevalent multi-twinned model system, fits five tetrahedral motifs into a circle by sharing an axis resulting in a geometric misfit angle of 7.35°, or a disclination with power of -7.35°. Postulating how Au FCC lattice adopts the misfit, theoretical models have been developed to address the underlying lattice symmetry and inhomogeneous strain distribution separately. Yet, experimental reports regarding the former have been limited due to the relatively large X-ray beam sizes that do not fit the sizes of NPs. On the other hand, though the latter has been widely adapted in the thermodynamics of small (<10 nm) multi-twinned nanoparticles, previous literature has shown that, at edge length of 17 nm, the theory’s is invalidated by shear strain that is observed in a defect-free Au Dh NP by high-resolution transmission electron microscopy (HR-TEM) imaging. Though the advancement of aberrationcorrected scanning transmission electron microscopy (AC-STEM) imaging and ab initio calculation techniques brings new opportunities, along with challenges in complicated image analysis and limitation in particle size (usually below 10 nm), the gap between nanoscale and mesoscale has never been extended to gain insight from atomic system with straightforward interaction potentials.

4D-STEM

LandScan Global 2024

The LandScan program is excited to share LandScan 2024, the latest annual update of a global gridded population dataset at 30 arc-second resolution that serves as foundational GEOINT Human Geography data. Substantial changes were continued from last year in the new ML methodological approach with the goal to retain the knowledge and expertise represented through improvements with each annual release over the past quarter century. Through these annual releases, Oak Ridge National Laboratory (ORNL) has consistently produced the most accurate global gridded population data, reflecting both ambient and unwarned population patterns that meet the United States Department of Defense (U.S. DoD) requirements. Additionally, the dataset is used widely across various U.S. government programs and is released publicly through an NGA and ORNL collaborative open portal (https://LandScan.ornl.gov) to expand its availability to researchers, humanitarian organizations, and the public at large.

Lebakula, Viswadeep [ORNL] (ORCID:0000000152935914

The nucleardatapy toolkit for simple access to experimental nuclear data, astrophysical observations, and theoretical predictions

Systematic comparisons across theoretical predictions for the properties of dense matter, nuclear physics data, and astrophysical observations (also called meta-analyses) are performed. Existing predictions for symmetric nuclear and neutron matter properties are considered, and they are shown in this paper as an illustration of the present knowledge. Asymmetric matter is constructed assuming the isospin asymmetry quadratic approximation. It is employed to predict the pressure at twice saturation energy-density based only on nuclear-physics constraints, and we find it compatible with the one from the gravitational-wave community. To make our meta-analysis transparent, updated in the future, and to publicly share our results, the Python toolkit nucleardatapy is described and released here. Hence, this paper accompanies nucleardatapy, which simplifies access to nuclear-physics data, including theoretical calculations, experimental measurements, and astrophysical observations. This Python toolkit is designed to easily provide data for: (i) predictions for uniform matter (from microscopic or phenomenological approaches); (ii) correlation among nuclear properties induced by experimental and theoretical constraints; (iii) measurements for finite nuclei (nuclear chart, charge radii, neutron skins or nuclear incompressibilities, etc.) and hypernuclei (single particle energies); and (iv) astrophysical observations. This toolkit provides data in a unified format for easy comparison and provides new meta-analysis tools. It will be continuously developed, and we expect contributions from the community in our endeavor.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS

Radio Frequency Spectrum Audit to Inventory Private Cellular Base Station Infrastructure

The ever-changing cellular communication landscape makes it difficult to identify, map, and localize cellular base stations. Localizing cellular base stations provides various advantages, including information security, cybersecurity, spectrum management, and interference detection. For example, the MITRE ATT&CK® (Adversarial Tactics, Techniques, and Common Knowledge architecture) [1] and Common Attack Pattern Enumeration and Classification [2] emphasize the importance of being able to minimize the cyber security threat presented by unregulated private cellular base stations (PCBS). The majority of published research looks at the malicious use of PCBSs and focuses on using data retrieved from user equipment (UE), data obtained from an application on the UE, or data shared between the UE and a mobile network to locate it. This innovative strategy, however, focuses on the passively discovered uniqueness of radio frequency (RF) transmissions from commercial cellular infrastructure received in a designated monitoring position (DMP).

42 ENGINEERING

Building hypotheses to understand the synergistic effects of heat and pollution exposure in a changing climate

The increasing intensity, frequency, and duration of extreme weather events due to climate change poses a broad range of health risks, and the synergistic effects of extreme temperature co-occurring with other hazardous exposures such as air pollution may result in higher risks of all-cause mortality and cardiovascular and respiratory morbidity than exposure to either event alone. There are a number of hypothesized mechanisms for this interaction effect, including increased susceptibility to heat effects on chronic conditions affected by air pollution exposure, exacerbation of pollution effects due to temperature-induced stress, and shared pathophysiological pathways (e.g., systemic inflammation), but specific physiological mechanisms are not well understood. In this editorial, the authors discuss this aspect of a recently published study examining ambient formaldehyde combined with high temperature exposure and respiratory disease admissions among children. Here, the observation that the health effects of pollutants such as formaldehyde are amplified following periods of high temperature can help inform risk warning systems even without knowledge of the underlying physiological mechanisms, but a deeper biological understanding of the interaction effects of heat and ambient air pollution may better inform interventions. This is even more important in view of increases in both extreme temperature and pollution events tied to climate change.

Chambliss, Sarah [University of Texas at Austin, T

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING