Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “DER-CF”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Cybersecurity Assessment for a Behind-the-Meter Solar PV System: A Use Case for the DER-CF

The world's energy production is shifting toward lower-cost, cleaner, more efficient, and sustainable sources. The increasing numbers of distributed energy resources (DERs) are allowing for the rapid transformation of electric grids toward achieving the goal of energy decarbonization. Along with cleaner and more efficient energy, however, we must also aim for a secure energy future. Solar photovoltaic (PV) systems are an important part of this transition. This paper discusses a cybersecurity risk assessment for behind-the-meter DERs using a solar PV system as a use case of the Distributed Energy Resource Cybersecurity Framework (DER-CF) developed by the National Renewable Energy Laboratory. This poster presents a conference paper on the risk assessment processes and summarizes the DER-CF's use case recommendations to strengthen the cybersecurity posture of the electric grid.

cybersecurity↗

Distributed Energy Resource Visual Emulator: Phase 1

To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions, which are used to generate a site-specific report and recommendations. This paper outlines a technical approach to integrate the DER-CF with another key asset—NREL's Advanced Research on Integrated Energy Systems (ARIES) Cyber Range—to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF. The result is a new tool called the Distributed Energy Resource Visual Emulator (DER-VE). Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners. Phase 0 of the integration project was concluded in 2021. Phase 1, completed in 2022, has two components: The first is developing a working visualization of system compliance using the DER-CF, and the second is planning the design of a server application that takes input data from the DER-CF and creates a personal emulated environment of the user's system or a selected reference architect. Major components that were addressed in this phase are the DER-CF output, compliance visualization, data model, and compliance server design.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Distributed Energy Resource Cybersecurity Framework and Cyber Range Integration

Distributed energy resource (DER) systems feature complex, data-driven communications networks that require careful system coordination and constant vigilance to ensure that grid assets are secure. Because DERs are an important component of the decarbonization strategy, agencies need to secure energy data that could implicate issues of national security if compromised. To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's (NREL's) Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions that are used to generate a site-specific report and recommendations. This paper outlines a plan to integrate the DER-CF with another key asset-NREL's cyber range-to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF for federal facility energy managers and planners. This integration will result in a visualization environment to interpret and interact with compliance data. Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CARILEC Resilient Energy Community CoP for Cybersecurity Workshop Series: Cybersecurity Assessment Tools [Slides]

For the last several years and in collaboration with CARILEC, USAID and NREL have been working to support cyber resilience at power sector utilities in Latin America and the Caribbean. Direct technical assistance with regional utilities has been a key component of USAID-NREL Partnership activities, and technical assistance has typically included a foundational cybersecurity assessment using NREL's Distributed Energy Resource Cybersecurity Framework (DER-CF) tool. The DER-CF allows organizations to benchmark and evaluate their cybersecurity posture across the areas of Governance, Technical Management, and Physical Security. To complement the activities of the newly created CAREC IT/OT and Cybersecurity Team, this webinar on cybersecurity assessment tools includes an overview of the DER-CF tool and a discussion with regional stakeholders and NREL experts on the DER-CF assessment process and other resources for cybersecurity assessments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Distributed Energy Resource Cybersecurity Framework

For facilities with distributed energy resources (DERs), cybersecurity must be considered holistically, across system architectures and down to individual components. It's hard to know where to start. That's why the National Renewable Energy Laboratory (NREL) has developed an assessment tool for organizations with DERs to understand and improve their cybersecurity. With support from the U.S. Department of Energy's Federal Energy Management Program, the Distributed Energy Resource Cybersecurity Framework (DER-CF) provides a holistic evaluation of a facility's DER cybersecurity and makes customized recommendations that follow widely recognized best practices for cybersecurity. The DER-CF is available at no cost as an interactive web tool (dercf.nrel.gov).

cybersecurity↗

DER Cybersecurity R&D

The National Renewable Energy Laboratory (NREL) conducted more than 30 assessments for utilities across the United States with a cybersecurity assessment tool based on the U.S. Department of Energy (DOE) Cybersecurity Capability Maturity Model (C2M2) and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and focused on business process. With funding from the DOE Office of Renewable Energy and Energy Efficiency Federal Energy Management Program, NREL modified the current cyber governance assessment tool to include an assessment process specifically for distributed energy resources (DERs). The Distributed Energy Resources Cybersecurity Framework (DER-CF) was developed to help federal agencies mitigate gaps in their cybersecurity posture for distributed energy systems.

cybersecurity valuation↗

Electric Vehicle Supply Equipment Security Solutions

The EVs@Scale cybersecurity pillar deep dive focuses on the three main tasks that NREL has in the consortium: (1) Analysis of EV charging mobile applications, (2) Cybersecurity risk assessments of EVSE through DER-CF, and (3) PKI for EVSE.

ADVANCED PROPULSION SYSTEMS,MATHEMATICS AND COMPUT↗

Hydropower Cybersecurity Value-at-Risk Framework

Hydropower remains one of the strongest forms of renewable energy generation methods. It is crucial to address the increasing risks associated with the rapid digitization. The push towards decarbonization also factors in the need to ensure security and resilience for grid-connected renewable energy resources. This report summarizes the U.S. Department of Energy's Water Power Technologies Office's effort to develop a cybersecurity valuation methodology that assists hydropower stakeholders in assessing risks associated with plan operations and gathers valuation guidance through a web-based application. The Hydropower Cybersecurity Value-at-Risk Framework delivers a platform for industry members to perform self-assessments and make informed decisions on their cybersecurity investments.

13 HYDRO ENERGY↗

Cybersecurity for Energy Systems: Foundational Concepts for Bangladesh Electric Utilities [Slides]

This slide deck was developed for a training for the Northern Electricity Supply Company (NESCO) in Rajshahi, Bangladesh. The topics include: understanding the cybersecurity landscape in power utilities, fundamentals of cybersecurity for power utilities, regulatory compliance and standards, and best practices and strategies. The concepts in this slide deck are relevant for electric utilities throughout Bangladesh.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Critical Energy Infrastructure Cybersecurity: Enhanced Cyber Resilience for Federal Energy Systems

This presentation is an overview of FEMP Resilient and Secure Infrastructure and Facilities. An educational and interactive workshop centered on resilient and secure federal infrastructure and facilities, with a focus on inverter-based resources at Federal sites, building automation systems, and Federal supply chains. This workshop will illustrate an all-hazards scenario and discuss how Federal agencies can be positioned to resist these real-world scenarios.

97 MATHEMATICS AND COMPUTING↗

Ransomware and Today's Electric Grid

Cyberattacks come in many forms, including one of the newest and most threatening of attacks: ransomware. The rise in ransomware impacts businesses small and large -- and have the potential to significantly disrupt the operations of critical infrastructure. This presentation will explain what utilities can expect from a ransomware attack, sharing examples from specific events, provide guidance on how to prepare for the unknown, and offer possible ways to respond when an attack occurs. The presentation will also discuss cybersecurity governance as an effective method in taking preventative action to ransomware by identifying and addressing vulnerabilities through monitoring and assessment.

assessment↗

Cybersecurity Governance

Cybersecurity governance helps an organization detect, prevent, and respond to cyber incidents by establishing cybersecurity policies and procedures for use across the enterprise. As modern energy systems become increasingly reliant on smaller and decentralized generation sources-equipped with complex, data-driven communications-governance will be of growing importance for the continued protection of the electric grid. This presentation sheds light on the important aspects of cybersecurity governance, best practices to ensure a culture of cybersecurity, and approaches to frequent monitoring and assessment of an organization's cybersecurity posture.

business requirements↗

The Distributed Energy Resource Risk Manager

Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.

compliance↗