Metric Challenges Bheshaj Krishnappa Risk Analysis & Mitigation - - PowerPoint PPT Presentation

metric challenges
SMART_READER_LITE
LIVE PREVIEW

Metric Challenges Bheshaj Krishnappa Risk Analysis & Mitigation - - PowerPoint PPT Presentation

Metric Challenges Bheshaj Krishnappa Risk Analysis & Mitigation About RF ReliabilityFirst preserves and enhances bulk power system reliability and security across 13 states and the District of Columbia. The Boundaries of


slide-1
SLIDE 1

Metric Challenges

Bheshaj Krishnappa Risk Analysis & Mitigation

slide-2
SLIDE 2

Forward Together • ReliabilityFirst

About RF

2

ReliabilityFirst preserves and enhances bulk power system reliability and security across 13 states and the District of Columbia. The Boundaries of ReliabilityFirst include all of New Jersey, Delaware, Pennsylvania, Maryland, District of Columbia, West Virginia, Ohio, Indiana, Lower Michigan and portions of Upper Michigan, Wisconsin, Illinois, Kentucky, Tennessee and Virginia.

slide-3
SLIDE 3

Forward Together • ReliabilityFirst

Data sets and Metrics approach -1

3

  • NERC CIP and O&P standards
  • NERC Standards CIP-002 through CIP-014 covering areas of BES Cyber System Categorization, Security

Management Controls, Personnel & Training, Electronic Security Perimeter(s), Physical Security of BES Cyber Systems, Systems Security Management, Incident Reporting and Response Planning, Recovery Plans for BES Cyber Systems, Configuration Change Management and Vulnerability Assessments, Information Protection and Physical Security

1 2 9 4 6 12 1 5 2 4 6 8 10 12 14 CIP-002 - Critical Cyber Asset Identification CIP-003 - Security Management Controls CIP-004 - Personnel and Training CIP-005 - Electronic Security Perimeter(s) CIP-006 - Physical Security CIP-007 - Systems Security Management CIP-008 - Incident Reporting and Response Planning CIP-009 - Recovery Plans for Critical Cyber Assets

CIP standard violations (representative chart)

slide-4
SLIDE 4

Forward Together • ReliabilityFirst

Data sets and Metrics approach -2

4

  • DOE Electricity Subsector Cybersecurity Capability Maturity Model (ES-C2M2)
  • A maturity model to evaluate, prioritize, and improve cybersecurity capabilities. The areas assessed are Cybersecurity

Program Management (CYBER), Asset, Change, and Configuration Management (ASSET), Information Sharing and Communications (SHARING), Identity and Access Management (ACCESS), Threat and Vulnerability Management (THREAT), Event and Incident Response, Continuity of Operations (RESPONSE), Risk Management (RISK), Situational Awareness (SITUATION), Workforce Management (WORKFORCE)

333 591 550 550 275 515 344 162 657 1685 2611 2465 2465 1085 2378 1309 686 2692

500 1000 1500 2000 2500 3000 Risk Management (RISK) Identity and Access Management (ACCESS) Situational Awareness (SITUATION) Event and Incident Response, Continuity

  • f Operations

(RESPONSE) Cybersecurity Program Management (CYBER) CIP VIolations

Comparison chart of ES C2M2 domains in RFC region against all of NERC (representative chart)

RFC NERC

slide-5
SLIDE 5

Forward Together • ReliabilityFirst

Challenges to Resilience metrics

  • Point in time data
  • Compliance statistics

‒ Violation history based on audits ‒ Cyber assets and vulnerabilities

  • Lack of Incident Response metrics
  • Dwell time, Containment time, Remediation time
  • Lack of benchmark data for "Mean Time To Repair"
  • r "Mean Time To Restore“ to measure resilience
  • Lack of adoption of NIST CSF and availability of

real-time data to assess Prevent, Detect, Respond, and Recover capabilities

5

slide-6
SLIDE 6

Forward Together • ReliabilityFirst

Resilience metrics - Opportunities

  • Research on measurement of resilience indicators
  • Share existing methods of cyber resilience measurement/

approaches

  • Engage larger or targeted stakeholders to pilot projects and

build upon

  • Explore centralized data store and access
  • ICS CERT, Assets database, threats and vulnerability database,

etc.,

  • Explore NIST Cybersecurity Framework / CERT Resilience

Management Model to derive resilience metrics

6

slide-7
SLIDE 7

Forward Together • ReliabilityFirst

Questions & Answers

Forward Together ReliabilityFirst

7