Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cybersecurity risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Integrating Cybersecurity with System Operations and Restoration

This presentation covers the interaction of the discipline of system operations with the discipline of cybersecurity. First, a common mental model for risk - both cybersecurity and all-hazards - is presented, followed by a discussion of high-level management strategies for different kinds of cyber harm facing system operators, based on the consequences and frequencies of the harm. The next section covers the importance of cybersecurity for a system operator organization and explains some general concepts to understand the relationships. Finally the role of system operators in the security of the grid as a larger system of systems is discussed over the framework of a resilience event.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Progress on the MARVEL Cybersecurity by Design Model-Based Systems Engineering Project

Formal model-based systems engineering (MBSE) combines a model, systems thinking, and systems engineering to visually depict the boundaries, context, and behavior of interconnected systems, facilitating effective design, development, and utilization of engineered systems throughout the systems engineering lifecycle. Although nuclear reactor vendors employ these tools to integrate functionality, performance, and safety, they are not yet addressing digital risk concerns introduced by use of operational technology, such as digital instrumentation and control systems. To accomplish this objective, the Microreactor Applications Research Validation and EvaLuation (MARVEL) microreactor was used as an MBSE case study. This real-world application provides a first-of-a-kind opportunity to demonstrate the benefits of integrating digital risk and cybersecurity into the MBSE design process of a nuclear reactor. This paper provides an update of the ongoing MARVEL Cyber MBSE project as it specifically relates to the integration of digital risk management and cybersecurity by design.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Distributed Energy Resource Cybersecurity Standards Development [Final Report]

Currently, the solar industry is operating with little application-specific guidance on how to protect and defend their systems from cyberattacks. This 3-year Department of Energy (DOE) Solar Energy Technologies Office-funded project helped advance the distributed energy resource (DER) cybersecurity state-of-the-art by (a) bolstering industry awareness of cybersecurity concepts, risks, and solutions through a webinar series and (b) developing recommendations for DER cybersecurity standards to improve the security performance of DER products and networks. Drafting DER standards is a lengthy, consensus-based process requiring effective leadership and stakeholder participation. This project was designed to reduce standard and guide writing times by creating well-researched recommendations that could act as a starting place for national and international standards development organizations. Working within the SunSpec/Sandia DER Cybersecurity Workgroup, the team produced guidance for DER cybersecurity certification, communication protocol standards, network architecture s, access control, and patching. The team also led subgroups within the IEEE P 1547.3 Guide for Cybersecurity of Distributed Energy Resources Interconnected with Electric Power Systems committee and pushed a draft to ballot in October 2021.

14 SOLAR ENERGY↗

Smart manufacturing maturity models and their applicability: a review

The purpose of this paper is to review existing smart manufacturing (SM) maturity models' dimensions and maturity levels to assess their applicability and drawbacks. There are many maturity models available but many of them have not been validated or do not provide a useful guide or tool for applications. This gap creates the need for a review of the existing maturity model's applicability. Nineteen peer-reviewed maturity models related to “Digital Transformation,” “Industry 4.0” or “Smart Manufacturing” were selected based on a systematic literature review and five consulting firm models were selected based on the author's industry knowledge. The chosen models were analyzed to determine 10 categories of dimensions. Then they are assessed on a 1–5 scale for how applicable they are in the 10 categories of dimensions. The five “consulting firm” models have a first-mover advantage, are more widely used in industry and are more applicable, but some require payment, and they lack published details and validation. The 19 “peer reviewed” models are not as widely used, lack awareness in the industry and are not as easy to apply because of no web tool for self-assessment, but they are improving. The categories defined to characterize the models and facilitate comparisons for users include “Information Technology (IT) and Cyber-Physical System (CPS) and Data,” “Strategy and Organization,” “Supply Chain and Logistics,” “Products and Services,” “Culture and Employees,” “Technology and Capabilities,” “Customer and Market,” “Cybersecurity and Risk,” “Leadership and Management” and “Governance and Compliance.” The analyzed maturity models were particularly weak in the areas of cybersecurity, leadership and governance. Researchers and practitioners can use this review with consideration of their specific needs to determine if a maturity model is applicable or if a new model needs to be developed. The review can also aid in the development of maturity models through the discussion of each of the dimension categories. Finally, compared to existing reviews of SM maturity models, this research determines comprehensive dimension categories and focuses on applicability and drawbacks.

42 ENGINEERING↗

Development of Integrated Safety and Security Models for Comprehensive Reliability and Resiliency Evaluation

The security of the electric grid and supporting energy systems is crucial to national security. One of the complexities in analyzing the security of energy systems is the safety consequences that may result from accidents. For energy systems, the goal is to ensure that they operate as intended and that any consequences are mitigated or prevented. The integration of safety and security is paramount to protecting these systems from attacks and ensuring that large consequences are prevented. This report describes an integrated safety and security methodology to evaluate cybersecurity events that can lead to large consequences. This novel approach first describes how Systems-Theoretic Process Analysis (STPA) provides a digital causal analysis for Bayesian Networks (BNs). The use of STPA causal analysis provides a systematic approach to constructing BNs that adequately model cyber scenarios that result in consequences. When combined with the technical principles described in Risk-Informed Management of Enterprise Systems (RIMES), a comprehensive risk-informed cybersecurity analysis results that allows decision-makers to prioritize systems that most impact risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Distributed Energy Resource Risk Manager

Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.

compliance↗

FEMP Cybersecurity Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools. The tools are meant to help federal owners and operators to evaluate their overall cybersecurity posture. These tools are developed based on the NIST Cybersecurity framework, risk management framework, and DOE C2M2 architectures. Version 3 provides significant updates and features in ten areas

Ashley, Travis [Pacific Northwest National Laborat↗

Resilience Framework for Electric Energy Delivery Systems (R.1)

The intent of this document is to provide a Resilience Framework for electrical energy delivery systems which can be applied to Distributed Wind. However, the framework is not limited by application to any resource or system. This framework represents the defined steps to a cyclical process similar in mechanism to both cybersecurity and risk frameworks, while providing a common set of language and process for all stakeholders involved. The need for this Resilience Framework was established in a previous document, “Distributed Wind Resilience Metrics for Electric Energy Delivery Systems.” One important characteristic we see in resilience is the unique needs and perspectives of different systems, geographies, resources, stakeholders, perceived risks, and consequences, which we term the distinctiveness property. This distinctiveness property drives the requirement to have a resilience framework or methodology that can be implemented by different types of organizations and systems. The process or methodology should be cyclic. Recognizing that a system’s resilience is based on finite resources and time, it must continually evolve through this framework’s risk management and capital investment steps at an appropriate pace for its distinctiveness property.

17 WIND ENERGY↗

Resilience for Advanced Distributed Wind Systems: Identifying the resilience benefits of advanced controls and hybrid systems for distributed wind

Under the Department of Energy (DOE) Wind Energy Technologies Office (WETO), Idaho National Laboratory (INL) has been tasked with defining the resilience benefits of distributed wind systems for the Microgrids, Infrastructure Resilience, and Advanced Controls Launchpad (MIRACL) project. This project is a collaboration between the National Renewable Energy Laboratory (NREL), Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL). In the final year of this project, INL is collaborating with the other labs to bring together key results from our previous work on resilience, cybersecurity and risk, distributed wind hybrid systems, and valuation of distributed wind.

17 WIND ENERGY↗

Attack Surface of Wind Energy Technologies in the United States [Slides]

This slide deck presents an overview of the threat landscape for wind energy technologies. It highlights unique cybersecurity considerations for wind, the growing penetration and potential impact of an attack. Standard architectures are shared to highlight where vulnerabilities may exist and attack paths to reach critical infrastructure. We discuss threat actors and attack paths. Several recent events impacting wind assets or wind companies are explained.

17 WIND ENERGY↗

Informing Cybersecurity Decisions With the Value-at-Risk Framework

Security at every site is critical to making hydropower a strong contributor to the country's grid, but with ongoing development and expanding capabilities, the diversity of the existing hydropower fleet makes across-the-board investment decisions difficult. The threat of cyberattacks naturally increases as the interconnection of Information Technology and Operational Technology networks broadens. Hydropower plants require custom analyses that are specific to the unique challenges and characteristics of any given facility. Facilities, however, often do not have the necessary resources for managers to make informed decisions on investments based on assessed capabilities and risks.

50 EE - Wind and Water Power Program - Water (EE-4↗

Survey of Space Professionals’ Perception of Satellite Cybersecurity from 2012 to 2022: Decision-Makers’ Thoughts on Satellite Cybersecurity Evolving

Cyberattacks on space assets are often portrayed in vague terms of doubt and mystery. Several claims depict satellites being compromised or attacked, but little corroboration has been published or made publicly available. As the commercial space industry is growing, commercial satellite decision makers will need to analyze the unacknowledged risk of cyberattacks against satellites. This paper identifies and characterizes what a cybersecurity risk to a space asset could look like and why space professionals might not prioritize cybersecurity. Additional information was captured from a decadal survey of space professionals in 2012 and 2022. Comparing the decadal results shows a rise in the perceived risk of satellites to cybersecurity threats from a sample of space professionals. This growing notable shift of perspective is not fully defined or agreed upon.

97 MATHEMATICS AND COMPUTING↗

Digital risk analysis in nuclear engineering projects: Designing for safety, performance, reliability, and security

Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cybersecurity Framework Profile for Electric Vehicle Extreme Fast Charging Infrastructure

This document is the Cybersecurity Framework Profile (Profile) developed for the Electric Vehicle Extreme Fast Charging (EV/XFC) ecosystem, including the four domains that relies on the ecosystem (i) Electric Vehicles (EV); (ii) Extreme Fast Charging (XFC); (iii) XFC Cloud or Third-Party Operations; and (iv) Utility and Building Networks. This Profile utilizes the NIST Cybersecurity Framework Version 1.1 and provides voluntary guidance to help relevant parties develop Profiles specific to their organization to understand, assess, and communicate their cybersecurity posture as a part of their risk management process. The Profile is intended to supplement, not replace, an existing risk management program or cybersecurity standards, regulations, and industry guidelines that are in current use by the EV/XFC industry.

33 ADVANCED PROPULSION SYSTEMS↗

US Department of Energy, Office of Science High Performance Computing Facility Operational Assessment 2021: Oak Ridge Leadership Computing Facility

Oak Ridge National Laboratory’s (ORNL’s) Leadership Computing Facility (OLCF) continues to surpass its operational target goals of supporting users; delivering fast, reliable computational ecosystems; creating innovative solutions for high-performance computing (HPC) needs; contributing to the community to build the next generation HPC workforce, and managing risks, safety, and security associated with operating some of the most powerful computers in the world. The results can be seen in the cutting-edge science conducted by users and the praise from the research community. Calendar year (CY) 2021 saw continued excellence in research supported by the OLCF’s leadership-class computing resources, including Summit (the nation’s most powerful supercomputer), the global scratch file system Alpine, the Scalable Protected Infrastructure (SPI), the Exploratory Visualization Environment for Research in Science and Technology (EVEREST), and the archival mass-storage resource High-Performance Storage System (HPSS). While maintaining access and exceptional user support for Summit, the OLCF continued to make progress on the installation and deployment of Frontier, which will be the nation’s first exascale system when it comes online at the start of CY 2023. Users have already begun running and optimizing scientific codes on Crusher, the OLCF test and development system equipped with Frontier’s architecture. Throughout the year, the OLCF maintained a strong culture of operational excellence, including risk management, workplace safety, and cybersecurity. The OLCF’s rigorous risk management strategy anticipated and mitigated risks, and at this time there are no high-priority operational risks. Similarly, ORNL and the OLCF were committed to operating under the US Department of Energy’s (DOE’s) safety regulations that ensure a safe workplace. Technical staff tracked and monitored existing threats and vulnerabilities within the OLCF while continually developing tools and practices to enhance operations without increasing the facility’s risk. CY 2021 was filled with outstanding results and accomplishments, including a very high rating from users on overall satisfaction for the eighth consecutive year; a tremendous number of node hours delivered to 1,671 researchers on Summit; and the successful delivery of the allocation split of roughly 60%, 20%, and 20% of core-hours offered for the Innovative and Novel Computational Impact on Theory and Experiment (INCITE), Advanced Scientific Computing Research Leadership Computing Challenge (ALCC), and Director’s Discretionary (DD) programs, respectively (Section 2). COVID-19 research remained a focus in 2021, and the ALCC and DD programs allocated over 1 million Summit hours to the COVID-19 High Performance Computing Consortium. These accomplishments, coupled with the high utilization rates (i.e., overall and capability usage), represent the fulfillment of the promise of leadership class machines: efficient facilitation of leadership-class computational applications.

97 MATHEMATICS AND COMPUTING↗

Case Study: Applying the INL Resilience Framework to Iowa Lakes Electric Cooperative Distributed Wind Systems

Traditional metrics and evaluation methods for resiliency are not sufficient to evaluate the effect that distributed wind systems will have, particularly in light of the challenges described above. While the concept of resiliency is not new, its application to the electric grid is neither standardized nor well-defined, and there is little to no guidance on how to evaluate resilience specifically for distributed wind systems. To fill this gap, the Idaho National Laboratory (INL), as part of the multi-laboratory Microgrids, Infrastructure Resilience, and Advanced Controls Launchpad (MIRACL) project, has developed a resilience framework for electric energy delivery systems (EEDS). The framework provides detailed steps for evaluating resiliency in the planning, operational, and future stages, and encompasses five core functions of resilience. It allows users to evaluate the resilience of distributed wind, taking into consideration the resilience of the wind systems themselves, as well as the effect they have on the resiliency of any systems they are connected to. In this study, we evaluate the resilience of the distributed wind systems at Iowa Lakes Electric Cooperative to cybersecurity hazards. We show that the wind resource can benefit the overall system resilience during some hazards. We show that the practices in place make the wind subsystems resilient against some cybersecurity hazards but that there are still significant risks associated with other cybersecurity hazards

17 WIND ENERGY↗

Overview and Recommendations for Cyber Risk Assessment in Nuclear Power Plants

Digital instrumentation and control (I&C) systems are being deployed in nuclear power plants (NPPs) for both existing and advanced reactor designs. As I&C systems become more digitized to allow features like near autonomous control and remote operation, they introduce greater cyber risk to NPPs. Cyberattacks targeting industrial control systems (ICSs) are growing in both qualities and capabilities, which indicates that cybersecurity needs to be an integral part of risk assessment in the industry. Although there are some risk assessment methods in traditional information technology (IT) cybersecurity, the differences between IT and ICS cybersecurity make it infeasible to apply these risk assessment methods directly to ICSs. Some research has focused on risk assessment methods for ICSs, but few studies focus on applications to NPPs. Ideal risk frameworks for the nuclear industry are dynamic and account for system dependencies; this survey review focuses on such risk assessment methods both in and outside the nuclear field. In this article, the major challenges in cybersecurity risk assessment research are pointed out, and further research suggestions and considerations for cyber risk assessment in I&C systems are identified.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗