Summary of Control System Security Standards Activities in the Energy Sector   [open pdf - 921KB]

"In the U.S., systems that control critical energy infrastructure are vulnerable to physical and cyber attack, with potential consequences including significant interruption of economic activity or, even, to catastrophic loss of life. As the nation begins to take the necessary steps to remedy these vulnerabilities, a group is needed to assist in the shared understanding of standards activities in industry and in the standards-producing bodies. Without such shared understanding, results may be piecemeal, conflicting, and incomplete. It is also unlikely that adequate results could be accomplished in the time frame appropriate to the seriousness of the threat. The National SCADA Test Bed (NSTB) Program, directed by the Department of Energy (DOE) - Office of Electricity Delivery and Energy Reliability (OE), is tasked with assisting industry and government in improving the security of energy sector control systems. As part of that mission, the NSTB Program funded the Critical Infrastructure Security Standards Working Group (CISSWG) to identify industry standards applicable to control system security and to perform an initial evaluation of the scope and status of those standards. The CISSWG is DOE-sponsored working group composed of representatives of four national laboratories. It has a charter to consider energy sector cyber security standards. Included in this sector are electrical power and oil and gas. There are many professional bodies that represent interests in the energy sector, but only a few have been identified as dealing with cyber or control system security. There are also other professional bodies that represent interests that complement those in the energy sector."

