Featured no image

Published on August 7th, 2022 📆 | 6109 Views ⚑

0

New Cybersecurity Tool Simplifies Site Evaluations | News


Free Text to Speech


Conceptual illustration

As federal sites invest in distributed energy resources (DERs) like solar panels and
battery backups, investments in cybersecurity must also be considered. More energy
resources create more complexity to manageā€”introducing the potential of new cyber
vulnerabilities and added costs down the road.

DER_RM logo

Luckily, there is a new tool available to help manage this risk: the National Renewable
Energy Laboratoryā€™s (NRELā€™s) DER Risk Manager (DER-RM), a downloadable application that implements and automates a widely trusted framework
for information security from the National Institute of Standards and Technology (NIST).
The DER-RM, developed with support from the U.S. Department of Energy Federal Energy
Management Program (FEMP), offers a user-friendly solution for sites that must comply
with NISTā€™s Risk Management Framework.

ā€œAfter two years of the teamā€™s hard work and extensive research on the NIST 800-37
Risk Management Framework, weā€™re very excited to launch the beta version of this tool,ā€
said Tami Reynolds, NREL cybersecurity project lead. ā€œThe seven-step NIST framework
is a comprehensive process that helps organizations manage information security and
privacy risk, but it wasnā€™t designed specifically for operational technologies like
distributed energy. The DER-RM offers this service for organizations seeking to adopt
more renewable and distributed energy systems.ā€

Compliance often requires time-consuming, cyclical evaluations, which the DER-RM streamlines.
In addition to NIST compliance, the design of the DER-RM was informed by NRELā€™s previously
developed DER Cybersecurity Framework (DER-CF), a cyber evaluation tool that casts a wider net, evaluating multiple domains of a
siteā€™s security such as its cyber governance, cyber-physical technical management,
and physical security. Both applications guide users through tailored questions to
build a profile of their energy system, which is then assessed, scored, and improved
with unique recommendations.

ā€œThe DER-RM provides a streamlined process for completing and generating associated
reports to achieve compliance, whereas the DER-CF is a flexible, hybrid application
that enables implementation of fundamental cybersecurity practices,ā€ said Anuj Sanghvi,
cybersecurity researcher and technical lead for the project. ā€œFor organizations beginning
to assess the cybersecurity posture for their distributed generation assets, the DER-CF
application plays a vital role for onboarding DER systems to federal enterprises.ā€





In addition to the launch of the DER-RM, the NREL team recently released a series
of training modules on the more fundamental evaluation tool, DER-CF, through FEMPā€™s accredited training
portal.

Easy Compliance for Controls and Communication

For risk management, the DER-RM is built around the controls-oriented NIST framework,
which is mandatory for federal agencies and many other organizations. The tool specifically
provides guidance to help organizations attain an Authorization to Operate (ATO),
which allows facilities to document and weigh the risks that the system introduces
to an organizationā€™s personnel, operations, and other organizations. With an ATO approval,
authorizing officials accept the risks involvedā€”and the plan to mitigate themā€”from
integrating the system onto federal networks.Ā 

Users can input their system information, which the DER-RM assesses by applying common
cybersecurity attacks and testing the systemā€™s defense. Users can also upload their
control data files directly, which the DER-RM checks for NIST compliance and reports
where risk management steps are needed. Because the NIST framework requires ongoing
evaluations, the DER-RM is a significant time-saver for maintaining compliance.

ā€œThe DER-RM utilizes as much dynamic components as possible to provide a truly tailored
experience to the user,ā€ said Ryan Cryar, lead developer of the DER-RM and DER-CF.
ā€œUtilizing the NIST Open Security Controls Assessment Language, or OSCAL, we have
a single schema that allows us to develop around a centralized data model for easier
importing and exporting from different tools for a more custom user experience. No
two assessments are the same.ā€

Both the DER-RM and DER-CF are available at no cost, with an accessible user interface
and the option to anonymize users. For organizations that require cybersecurity compliance,
these tools offer a quick, user-friendly approach to align with several cybersecurity
frameworks and best practices. For organizations that are simply interested in improving
the security of their facilities and DERs, the DER-RM and DER-CF offer accessible
solutions with a unique focus on DERs, allowing organizations to continue to evolve
their energy systems and keep ahead of the cyber threat.

To learn more about the DER-RM and how to access it, please contact Ryan Cryar.

Source link

Tagged with: ā€¢ ā€¢ ā€¢ ā€¢ ā€¢



Comments are closed.