1 By Andy Bochman
For those who argue that one cannot secure a system without knowing how it works or the consequences of implementing the wrong security, this book is for you. Our goal is to make the Smart Grid and all its warts accessible to not only cyber security practitioners, but also to media, policymakers, regulators, engineers, utility executives, and even to consumers to understand the interplay between the automation of the electric grid and security.
Titled Smart Grid Security: an End-to-End View of Security in the New Electrical Grid,
the book is very current, having just become available for purchase at Amazon and elsewhere in December.
There's much I could point out to you that's worthwhile, but the job of the blog is to alert you to the availability of a resource, and give you an opinion on whether it might be worth your time, not to do a full book review.
But to give you a feel for the types of topics Sorebo and Echols reach, consider this piece pulled from a chapter on operations and outsourcing:
Monitoring for cyber-threats through an incident identification and response strategy should extend beyond the traditional boundaries of the utility itself ... Vendors are typically connected to multiple utilities that are connected to multiple vendors ... the question becomes: if Vendor A is compromised, how many utilities does it affect? And how would those utilities know if they were affected or not?
To mitigate [risks like these], utilities and vendors must begin to insert cyber security into their maintenance and support contracts ... If a vendor loses information deemed to be private, then they are generally required to report the fact that there was a breach ... However, there appears to be no legal requirements for a vendor that is compromised and that has direct access to a utilities' control system ... As part of a good incident response security posture, [increased] collaboration may be necessary in the highly interconnected organizations that support the bulk electric system including utilities, vendors and service providers.
So there you go. And there's more helpful details on this and many other topics for folks charged with bringing security capabilities to fruition. I highly recommend this book for anyone for who cares that their grid is as reliable, efficient and secure as possible, even as it goes through the many changes involved in becoming a smart grid.
Andy Bochman is author of the Smart Grid Security Blog and an Energy Security Lead for IBM's Rational division, where the focus is on securing the software that runs the smart grid. Andy is a contributor to industry and national security working groups on energy security and cyber security. He lives in Boston, is an active member of the MIT Energy Club, and is the founder of the Smart Grid Security and DOD Energy Blogs.
You might also be interested in ...
PJM CEO speaks out on cyber security and resilience
Security scare - a tempest in a water pump
Got something to say about this article? Be the first to leave a comment!
|
© 2012 SmartGridNews - Privacy Policy |
||||||||||||||||||||||||