ConceptioArchiveNIST
NISTpublic full text

NIST SP 1800-2: Identity and Access Management for Electric Utilities

James McCarthy (NIST); Don Faatz (MITRE); Harry Perper (MITRE); Chris Peloquin (MITRE); John Wiltberger (MITRE) · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
cybersecuritypracticeimplementationguidenccoenist
cybersecurity practice, NCCoE, implementation guide, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 1800-2 Identity and Access Management for Electric Utilities Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: July 2018 Author(s) James McCarthy (NIST) , Don Faatz (MITRE) , Harry Perper (MITRE) , Chris Peloquin (MITRE) , John Wiltberger (MITRE) Editor(s) Leah Kauffman (NIST) Abstract To protect power generation, transmission, and distribution, energy companies need to control physical and logical access to their resources, including buildings, equipment, information technology (IT), and operational technology (OT). They must authenticate authorized individuals to the devices and facilities to which the companies are giving access rights with a high degree of certainty. In addition, they need to enforce access-control policies (e.g., allow, deny, inquire further) consistently, uniformly, and quickly across all of their resources. This project resulted from direct dialog among NCCoE staff and members of the electricity subsector, mainly from electric power companies and those who provide equipment and/or services to them. The goal of this project is to demonstrate a converged, standards-based technical approach that unifies identity and access management (IdAM) functions across OT networks, physical access control systems (PACS), and IT systems. These networks often operate independently, which can result in identity and access information disparity, increased costs, inefficiencies, and a loss of capacity and service delivery capability. Also, these networks support different infrastructures, each with unique security risks. The converged IdAM solution must be constructed to effectively address the highest-risk infrastructure. This guide describes our collaborative efforts with technology providers and electric-company stakeholders to address the security challenges that energy providers face in the core function of IdAM. This guide offers a technical approach to meeting the challenge and also incorporates a business-value mindset by identifying the strategic considerations involved in implementing new technologies. This NIST Cybersecurity Practice Guide provides a modular, open, end-to-end example solution that can be tailored and implemented by energy providers of varying sizes and levels of IT sophistication. It shows energy providers how we met the challenge by using open-source and commercially available tools and technologies that are consistent with cybersecurity standards. The use-case scenario is based on a normal day-to-day business operational scenario that provides the underlying impetus for the functionality presented in this guide. While the reference solution was demonstrated with a certain suite of products, this guide does not endorse these specific products. Instead, this guide presents the characteristics and capabilities that an organization’s security experts can use to identify similar standards-based products that can be integrated quickly and cost-effectively with an energy provider’s existing tools and infrastructure. To protect power generation, transmission, and distribution, energy companies need to control physical and logical access to their resources, including buildings, equipment, information technology (IT), and operational technology (OT). They must authenticate authorized individuals to the devices and... See full abstract To protect power generation, transmission, and distribution, energy companies need to control physical and logical access to their resources, including buildings, equipment, information technology (IT), and operational technology (OT). They must authenticate authorized individuals to the devices and facilities to which the companies are giving access rights with a high degree of certainty. In addition, they need to enforce access-control policies (e.g., allow, deny, inquire further) consistently, uniformly, and quickly across all of their resources. This project resulted from direct dialog among NCCoE staff and members of the electricity subsector, mainly from electric power companies and those who provide equipment and/or services to them. The goal of this project is to demonstrate a converged, standards-based technical approach that unifies identity and access management (IdAM) functions across OT networks, physical access control systems (PACS), and IT systems. These networks often operate independently, which can result in identity and access information disparity, increased costs, inefficiencies, and a loss of capacity and service delivery capability. Also, these networks support different infrastructures, each with unique security risks. The converged IdAM solution must be constructed to effectively address the highest-risk infrastructure. This guide describes our collaborative efforts with technology providers and electric-company stakeholders to address the security challenges that energy providers face in the core function of IdAM. This guide offers a technical approach to meeting the challenge and also incorporates a business-value mindset by identifying the strategic considerations involved in implementing new technologies. This NIST Cybersecurity Practice Guide provides a modular, open, end-to-end example solution that can be tailored and implemented by energy providers of varying sizes and levels of IT sophistication. It shows energy providers how we met the challenge by using open-source and commercially available tools and technologies that are consistent with cybersecurity standards. The use-case scenario is based on a normal day-to-day business operational scenario that provides the underlying impetus for the functionality presented in this guide. While the reference solution was demonstrated with a certain suite of products, this guide does not endorse these specific products. Instead, this guide presents the characteristics and capabilities that an organization’s security experts can use to identify similar standards-based products that can be integrated quickly and cost-effectively with an energy provider’s existing tools and infrastructure. Hide full abstract Keywords cyber security ; physical security ; operational security ; cybersecurity ; electricity subsector ; energy sector ; identity and access management ; information technology Control Families Access Control ; Identification and Authentication ; Physical and Environmental Protection Documentation Publication: https://doi.org/10.6028/NIST.SP.1800-2 Download URL Supplemental Material: SP 1800-2 files Project homepage Related NIST Publications: Project Description Document History: 08/25/15: SP 1800-2 (Draft) 07/13/18: SP 1800-2 (Final) Topics Security and Privacy identity & access management Applications cyber-physical systems Sectors energy HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 2829 · SHA-256 3fcf8b5a234adf7a
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.