DER Digital Supply Chain Gap Analysis
Future Work
By leveraging the SunSpec/Sandia
cybersecurity working group to
create a subgroup on supply chain
cybersecurity, further adapt the
recommendations.
Through this subgroup, to the extent
possible, harmonize with other
groups, such as SEPA CSWG, CPUC
Smart Inverter Working Group, and
UL 2941 Technical Committee.
With this engagement, industry
members see immediate value by
actively developing
recommendations that can be
tailored to their own practices.
.
SUNSPEC
ALLIANCE
Funded by:
SOLAR ENERGY
TECHNOLOGIES OFFICE
U.S. Department of Energy
SunSpec/Sandia DER Cybersecurity Workgroup
Sandia
National
Laboratories
DER Cybersecurity Certification Procedure
Defined standardized procedure for DER vulnerability
assessments.
Leads: Danish Saleem (NREL) and Cedric Carter (MITRE)
Publication: "Certification Procedures for Data and
Communications Security of Distributed Energy Resources"
Future work: Expected development within UL 2900-2-4 STP
Data-in-Flight Requirements
Complete
KEMA
Complete
Encryption, authentication, and key management requirements.
Lead: Ifeoma Onunkwo (Sandia)
Publication: "Recommendations for Trust and Encryption in DER
Interoperability Standards", another covering Data-in-Transit
Requirements document (forthcoming).
Future work: IEEE 1547.3 update, IEEE 2030.5 revisions.
Secure Network Architecture
•
Created DER reference architecture best practice.
Lead: Candace Suh-Lee (EPRI)
Publication: "EPRI Security Architecture for the Distributed
Energy Resources Integration Network: Risk-based
Approach for Network Design"
Future work: Risk-based approach adopted in IEEE 1547.3
Access Control
Complete
Wrapping Up
.
DER Role-Based Access Control recommendations.
Lead: Jay Johnson (Sandia)
Topics: Access control taxonomy and security models
Planned Publication: "Recommendations for Distributed
Energy Resource Access Controls"
Future work: Add recommendations to IEEE 1547.3 Guide
Starting!
Utility/Aggregator Auditing Procedure
Q2 FY21
• Creating recommended auditing practices for DER networks.
Planned for March-April 2021. Lead: TBD
Topics: Step-by-step auditing procedure for internal or external
compliance review. Recommend data for attack forensics.
Patching Requirements
⚫ Establishing patching guidelines for DER devices and DER networking
equipment.
Starting August-Sept 2020. Lead: TBD
Topics: Patching update rates, maintenance guidelines, etc.View entire presentation