A long time ago I left the Air Force (on good terms, mind you) and joined the business world. An exciting job as a technology analyst at Aberdeen Group called me back home to Boston. But after one year in the ivory tower, meeting and in some cases
I soon learned my job was to stress to potential partners and customers that it was time to take stock. To sort out, if they hadn't already, what hardware and software their enterprises depended upon most. The idea being: You can't remediate what you don't even know you have.
Well, what do you get when you do a real inventory (also referred to as the practice of "asset management")? First of all, lots and lots of grunt work if you're being thorough. But beyond that there's plenty to learn about your own operations and efficiencies:
In short, perceived Y2K threats and remediation costs were used to justify the development or purchase of newer apps and the shuttering of older apps and systems. It became a catalyst for modernization and efficiency that continues to confer benefits to the more aggressive organizations today.
How does this apply to Smart Grid security? Much of the work to be done to get ready for AMI and Smart Grid capabilities involves linking and integrating systems that were previously isolated from each other – that wasn't a Y2K survival requirement. Of course there are other big differences between preparing for Y2K and roll-out of the Smart Grid. With few exceptions, the Y2K window opened and closed in a 24-hour period, while new Smart Grid applications and equipment have been rolling out in fits and starts for several years, and will continue to arrive for the foreseeable future. And the threats to Smart Grid systems are infinitely more varied and complex than the year date problem was to computers more than a decade ago.
Jack and I maintain that you can't secure (or demonstrate compliance with) what you don't even know you have. You can't understand the most vulnerable junction points between your IT and SCADA systems if you're not really sure how one or both is secured on its own. It's hard to prepare to roll out needed enterprise access control or single sign-on capabilities when you have no idea how current users are granted or denied access to key systems pre-Smart Grid.
As more utilities turn to asset and portfolio management processes and systems to get ship shape ahead of their Smart Grid rollouts, there's reason to believe a resurgence of taking stock – a la Y2K – is at hand. And beyond being better prepared to operate in the highly interconnected world of the Smart Grid, there are additional benefits to be had for utilities seeking greater self knowledge.
Andy Bochman and Jack Danahy are authors of the Smart Grid Security Blog.
You might also be interested in …
Smart Grid Security: Questions to Ask Before You Invest in a Software Solution
Why Requirements Development is Critical to Making the Smart Grid Smart
Checklist for a Safe and Sane Smart Grid
Smart Grid Security Class Now in Session
Smart Grid Security news and technologies
Stay connected with SGN …
Smart Grid Discussions: Get LinkedIn with Jesse
Got something to say about this article? Be the first to leave a comment!
|
© 2012 SmartGridNews - Privacy Policy |
|||||||||||||||||||||||