DER Digital Supply Chain Gap Analysis slide image

DER Digital Supply Chain Gap Analysis

Future Work By leveraging the SunSpec/Sandia cybersecurity working group to create a subgroup on supply chain cybersecurity, further adapt the recommendations. Through this subgroup, to the extent possible, harmonize with other groups, such as SEPA CSWG, CPUC Smart Inverter Working Group, and UL 2941 Technical Committee. With this engagement, industry members see immediate value by actively developing recommendations that can be tailored to their own practices. . SUNSPEC ALLIANCE Funded by: SOLAR ENERGY TECHNOLOGIES OFFICE U.S. Department of Energy SunSpec/Sandia DER Cybersecurity Workgroup Sandia National Laboratories DER Cybersecurity Certification Procedure Defined standardized procedure for DER vulnerability assessments. Leads: Danish Saleem (NREL) and Cedric Carter (MITRE) Publication: "Certification Procedures for Data and Communications Security of Distributed Energy Resources" Future work: Expected development within UL 2900-2-4 STP Data-in-Flight Requirements Complete KEMA Complete Encryption, authentication, and key management requirements. Lead: Ifeoma Onunkwo (Sandia) Publication: "Recommendations for Trust and Encryption in DER Interoperability Standards", another covering Data-in-Transit Requirements document (forthcoming). Future work: IEEE 1547.3 update, IEEE 2030.5 revisions. Secure Network Architecture • Created DER reference architecture best practice. Lead: Candace Suh-Lee (EPRI) Publication: "EPRI Security Architecture for the Distributed Energy Resources Integration Network: Risk-based Approach for Network Design" Future work: Risk-based approach adopted in IEEE 1547.3 Access Control Complete Wrapping Up . DER Role-Based Access Control recommendations. Lead: Jay Johnson (Sandia) Topics: Access control taxonomy and security models Planned Publication: "Recommendations for Distributed Energy Resource Access Controls" Future work: Add recommendations to IEEE 1547.3 Guide Starting! Utility/Aggregator Auditing Procedure Q2 FY21 • Creating recommended auditing practices for DER networks. Planned for March-April 2021. Lead: TBD Topics: Step-by-step auditing procedure for internal or external compliance review. Recommend data for attack forensics. Patching Requirements ⚫ Establishing patching guidelines for DER devices and DER networking equipment. Starting August-Sept 2020. Lead: TBD Topics: Patching update rates, maintenance guidelines, etc.
View entire presentation