Hiển thị các bài đăng có nhãn DOE. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn DOE. Hiển thị tất cả bài đăng

DOE's C2M2 is Growing Up Fast

There's been a ton of work accomplished since DOE handed the C2M2 flame to former FERCer Jason Christopher.  This program has now been leveraged at hundreds of enterprises and now gives you three flavors of Cybersecurity Capability Maturity Model (C2M2) to choose from now.

You can download any/all of the models right this minute if you are so inclined:


In addition, there are a number of new supporting resources for organizations at some stage of the C2M2 consideration or implementation process:

  • C2M2 FAQ - helps answer whether or not a C2M2 self-assessment is right for your organization (ab: sounds a little too much like a Cialis commercial to me)
  • C2M2 Facilitator Guide - provides step-by-step guidance for organizations that want to perform their own internal self-assessments (with or without a 3rd party)
  • C2M2 toolkit for all three models (electricity, oil & natural gas, and sector-neutral) based on MS Excel and Word, so it can be used by any organization. (Toolkits are provided by request only—email C2M2@doe.gov for more information.)

Lastly, this just-released bulletin tells you how DOE, NIST and DHS see the C2M2 and the Critical Infrastructure Security Framework (CSF) playing complementary roles.

So much good stuff.  Between all of the above and the Olympics, this should keep you off the streets and out of trouble until Spring finally shows up.

DHS' CSET: a Remedy for Electric Sector Security Measurement and Reporting Complexity Pains?

Sorry about that ridiculously long title, but felt it couldn't be helped this time. Thanks to Dr. Les Cardwell of Central Lincoln PUD, a publicly owned utility serving communities on the coast of Oregon.

Les wrote in and shared some of what he recommended to NIST and DOE regarding the recent RFI on the "Framework for Reducing Cyber Risks to Critical Infrastructure."

I'm not going to reprint the entirety of his submission, but will share with you two things here. First, Les' articulation of the need for a way to keep complexity in check as we go about this search for a new/better security framework for our community:

I would like to address ... "the "elephant in the room" ... [that could hinder our achievement of] a Digital Systems Security (DSS) Cybersecurity standard across the US Utility spectrum. That issue is the "expanding redundant complexity" of the current approach to the problem domain. While one can appreciate the efforts [involved] in gathering more information from the industry ... for establishing and improving frameworks to raise the overall level of cybersecurity ..., the problem is that it does not address the inherent complexity of the problem. It only exacerbates it by creating yet more administrative requirements for decomposing and resolving the problem domain for each utility.
I think he's on to something. There's more text clarifying the challenge and then some words on what Les proposes could play a major role in the final solution: DHS' own Cyber Security Evaluation Tool (CSET). The department has put together a nice succinct info sheet on CSET, so rather than telling you more about it, I suggest you read it for yourself, which you can do HERE.

I've got some learning to do myself on this, but in the meantime, please let me know if you think CSET has a role to play in this grand challenge.

DOE Seeks Your Ideas for Better Grid and Smart Grid Security

Thanks for to my colleagues JSK and SG for initially sending this my way and given the news lately, how timely it is!

A new Department of Energy (DOE) funded project seeks:
... applications to conduct research, development and demonstrations leading to next generation tools and technologies that will become widely adopted to enhance and accelerate deployment of cybersecurity capabilities for the U.S energy infrastructure, including cyber secure integration of smart grid technologies.

The six capabilities DOE's National Energy Technology Laboratory (NETL) would like to see advanced are:
  1. Verify the integrity and facilitate deployment of energy delivery control system software and firmware updates
  2. Sustain critical energy delivery functions while responding to a cyber-intrusion
  3. Detect compromise of supply chain integrity
  4. Secure remote access for the energy sector
  5. Detect adversarial manipulation of power grid components
  6. Innovative technologies that enhance cybersecurity in the energy sector
It would be nice to think all six of these were already fully mature and deployed, but that's not the case. In particular, I like the resiliency aspect of #2, and note that #6 is open ended, to allow for something outside the box of the way we think about these things that could help.

Approximately $20 million is expected to be available for awards. Once you're registered, the full text of this solicitation (DE-FOA-0000797) is available for download at FedConnect.gov.

Responses are due by April 5, 2013 so better get cracking if you've got an idea that could help secure the grid.

2 Control Systems Metrics Movers/Shakers: Jim Brenton and Joe Weiss

The more metrics the merrier, I say. After yesterday's post on IDC's take on energy sector cybersecurity metrics, let's pivot to control systems, where the three most important things are:
  1. reliability
  2. reliability, and
  3. reliability
... and where what passes for cybersecurity in IT realms just doesn't cut the mustard.

First see this NEW POST from Joe Weiss on how to begin wrapping your head around what control systems metrics could look like.

Then I'd recommend Jim Brenton's PRESENTATION at GridSec earlier this year on a new group that's formed to look at developing security (or should I say reliability and resiliency) metrics for the Bulk Electric System (BES).

OK, that's it, this is a short one. You can go back to what you should have been doing all along.

DOE's Prescription for Electric Sector Cybersecurity Uncertainties


I've had a link to this document in the blog's "Relevant Docs" section since it appeared, but with today's press release, I think it's time to shine a spotlight DOE's latest and greatest electric sector cybersecurity resource.

The campaign for measurement has just been given a big shot in the arm. By definition, in a weird permutation of Newton's Third Law, the minute a metric or measurement is proposed it creates its own opposition. Often vocal opposition, I might add.

Nevertheless, neither Newton nor opposition should cause us to accept stasis and the uncertainties that attend the status quo. "What uncertainties?" you might well ask.

And my answer is that the majority of C-Suiters and BoDs at medium-to-large electric utilities likely do not have a decent understanding of the cyber-related reliability and safety risks confronting their IT and OT operations. Nor do they understand well how sound (or unsound) are the defensive measures (people, policy, processes) their cybersecurity folks have deployed.

If I were to now transition to a tirade about the crying need for business-oriented security metrics and measurement, while linking to previous tirades, few would be surprised. But in a moment uncommon self restraint, I won't do that.

Instead, I invite you to consume a few tapas-sized sound bites from DOE's press release earlier today announcing its new, unpronounceable acronymed tool, the ES-C2M2.

Dig in:
  • Energy Department Develops Tool with Industry to Help Utilities Strengthen Their Cybersecurity Capabilities
  • New Tool Available to Enable Electric Utilities to Better Assess their Cybersecurity Needs and Assets 
  • Maturity models, which rely on best practices to identify an organization’s strengths and weaknesses, are widely used by other sectors to improve performance, efficiency and quality. 
  • More than a dozen utilities nationwide participated in pilot evaluations to help refine the model
  • The Cybersecurity Self-Evaluation Tool itself helps electric utilities and grid operators identify opportunities to further develop their own cybersecurity capabilities by posing a series of questions that focus on areas including situational awareness and threat and vulnerability management
  • Utilities that choose to provide their anonymous self-assessment results to the Energy Department will receive reports with anonymous benchmarking results of all utilities participating in the “opt-in” program.
Here's a LINK to the model. Utilities can request the Cybersecurity Self Evaluation Survey Tool by contacting the Energy Department at ES-C2M2@hq.doe.govNote: The Energy Department is also offering facilitated self-evaluations on request.

Please keep in mind that this is a 1.0 version developed at break-neck speed. The more feedback DOE gets from its earliest users, the more we can expect from future versions. And they do seek your feedback.

I think what's been started here is good, very good in fact. Now let's seek to use it, make it great, and substantially improve the industry's understanding of itself along the way.

Image credit: DiaVoLo Group on Flickr.com