SlideShare a Scribd company logo
Josh Long and Charlie Givens
ENERGYTECH 2015
Minimum Cyber Security
Requirements for a 20 MW
Photo Voltaic Field
Bechtel Group, NS&E
December 1, 2015
Author Biography
Josiah (Josh) Long
 Bechtel Global Corp: Nuclear Security & Environmental
 Senior Technical Engineering Specialist
 30+ Years experience
 Functional Engineering Control System & Electrical Staff
 25 years Power, 15 years Nuclear, 10 years Government
 BSEE Virginia Tech (1981)
 PE (Control System Engineering), GICSP, ISA CFS & SFS
 Voting Member ISA 67.04&06 Nuclear SR Setpoints
 Whitewater, R&R Guitar and Bass, Robotics
Overview
 Introduction
 Description of the 20 MW Standard PV Plant
 General Approach to Risk
 Risk with the 20 MW Standard
 Cyber Security Management System (CSMS)
 Summary
Elements of the
Standard 20MW
Solar Facility
© Bechtel | 4
PART 1 – Project Overview
Description of the 20 MW Standard PV Plant
 Plot Plan – Covers 85 Acres of relatively flat terran
 Plant includes 10 Identical 2 MW Standard Blocks
 Electrical Designs
– Arrays are based on minimizing wire and maximizing density
– Inverters are centrally located to the blocks
– Transformers are daisy chained to Substation/Switchyard
 SCADA Design
– Standard SCADA system is a Cal ISO base configuration
– 2 SCADA Remote Terminal Units (RTUs) are required
– 1 Weather Station is included.
PART 1 – Project Overview
Plot Plan – Covers 85 Acres of relatively flat terrain
PART 1 – Project Overview
Plant includes 10 Identical 2 MW Standard Blocks
PART 1 – Project Overview
Arrays are based on minimizing wire and maximizing density
PART 1 – Project Overview
Transformers are daisy chained to Substation/Switchyard
PART 1 – Project Overview
Description of the 20 MW Standard PV Plant
 SCADA Design
– Standard SCADA system is a Cal ISO base configuration
– 2 SCADA Remote Terminal Units (RTUs) are required
– 1 Weather Station is included.
SCADA
UNIT 1
Weather
Station
SCADA
UNIT 2
Elements of the
Risk Assessment
© Bechtel | 11
Part 2 – Risk Assessment Plan
 RISK MANAGEMENT PLAN
 Asset List
 Goals
 Risks
 Controls
 Program
Part 2 – Risk ASSET LIST
CREATE AN ASSET LIST
 Solar Panels $20M
 Panel Rack $3.8M
 Inverters/Transformer $3.5M
 SCADA $50K
 Metering $50K
 Substation/Switchgear $50k
 Security Features ???
 Cabling and Wires $1M
Part 2 – Risk Assessment
OBJECTIVES OF THE FACILITY
 What are the Goals of the site
– Power Generation
– Resale
– Dispatch
– Automatic Generation
– Backup Power
Each Can Change The Risk Profile
Part 2 – Risk Assessment
OBJECTIVES OF THE FACILITY
 Power Generation
– In the base configuration only generation matters
 Resale
– If resale is required then Metering is important
 Dispatch
– If Dispatch is require then a mean of changing output is required
» Internet, Dedicated Phone, Manned Facility
 Automatic Generation
– Automatic Generation may require automatic control perhaps through SCADA
 Backup Power
– Backup Power may require a higher integrity of supplied components
Part 2 – Major Risks
Key Risk
 Natural Disaster – Earthquake, Hurricane, Flood, Lightening
 Infrastructure Failure – Power Grid, Intranet, Communications
 Internal Issues – Thief, Damage, Infect, Sabotage
 Accidents – Fall or Crushing Incident, Shock, Electrocution
 External Targeted Attacks – Thief, Mass Damage, Cyber
 External Mass Attacks – Planned Systematic Physical Attack
Part 2 – Risk Controls
 What Controls (NIST 800 – 53/82)
 The Principle Elements of a Cyber Security Program
– People
– Procedures
– Configs and Physical Security
 ISA 99 and NIST 800 Series Approaches to Documentation
Part 2 – Risk Program
Program – Recommended Elements
 Policies and Practices (Standards?)
 Resource Inventory
 Security Liaisons
 Normalized Risk Formula
 Risk/Change Management Committee
 Map of Risk to Objectives
 Contributing Security Programs
 Exception Tracking
© Bechtel | 19
20MW PV FIELD
Final Cyber
Requirements
Part 3 – Minimum Requirements
SWGR USER
MW MW
Part 3 – The Reality of Operation
TOP OPERATIONS ISSUES
1. Perimeter Fence Damage
2. Vandalism or Theft
3. Transformer Leakage
4. Various Inverter Damage
5. Broken Conduit or Combiner Box Damage
6. Vegetation Overgrowth
7. Cell Browning/Discoloring or Shorted Cell
8. Shorted Cell
9. Unclean Panels
10.Animal Nuisance
Part 3 – A More Realistic Approach
© 2012 Bechtel | 22
Firewall
Switch
SCADA
Unit 1
Security System
CCTV System
SCADA
Unit 2 HISTORIAN
WS MW
Part 3 - Execution
 EXECUTION to be performed on an annual or quarterly basis
 The Principle Elements of Cyber Security
– People
– Procedures
– Configs and Physical Security
 Monitoring
 Improvement Plan
 Design Delta
 Summary

More Related Content

PDF
Tues.1040 am states role in protecting electric grids from emp and gmd with a...
PDF
Brian Patterson: Reinventing Building Power
PDF
John Ostrich: Space Weather Policy
PPTX
8.2_IEEE 1547 and Microgrids_Key_EPRI/SNL Microgrid Symposium
PPT
DISTRIBUTED GENERATION ENVIRONMENT WITH SMART GRID
PDF
2.3_SPIDERS Lessons and Observations_Sanborn_EPRI/SNL Microgrid
PDF
Webinar - Distributed and Renewable Power Generation
PPTX
7.1_Decentralized Operation and Control_Rojas_EPRI/SNL Microgrid Symposium
Tues.1040 am states role in protecting electric grids from emp and gmd with a...
Brian Patterson: Reinventing Building Power
John Ostrich: Space Weather Policy
8.2_IEEE 1547 and Microgrids_Key_EPRI/SNL Microgrid Symposium
DISTRIBUTED GENERATION ENVIRONMENT WITH SMART GRID
2.3_SPIDERS Lessons and Observations_Sanborn_EPRI/SNL Microgrid
Webinar - Distributed and Renewable Power Generation
7.1_Decentralized Operation and Control_Rojas_EPRI/SNL Microgrid Symposium

What's hot (20)

PDF
Power Adapter Design for 400 V DC Power Distribution in Electronic Systems
DOCX
GRID INTERCONNECTION OF RENEWABLE ENERGY SOURCES AT DISTRIBUTION LEVEL WITH P...
PPTX
4.4_Micro Grid Design_Bello_EPRI/SNL Microgrid
PDF
8.3_TMSC Overview_Bozada_EPRI/SNL Microgrid Symposium
PPTX
8.1.2_PAR 2030.8_Bower_EPRI/SNL Microgrid Symposium
PPTX
1.3. MCAGCC 29 Palms Microgrid_Morrissett_EPRI/SNL Microgrid
PPTX
2.4_Overview of Microgrid Research, Development, and Resiliency Analysis_Hovs...
PPTX
8.1.1_PAR 2030.7_Bower_EPRI/SNL Microgrid Symposium
PDF
Microsoft PowerPoint - Impacts of Distributed Generation (Public Copy)
PPTX
5.3_Helping Customers Make the Most of their Energy_Barton_EPRI/SNL Microgrid
PPTX
2.2_Microgrids PUC Regulatory Issues_Winka_EPRI/SNL Microgrid
PPTX
Session 06 balance of system components
PPTX
Session 10 grid interconnections & commissioning test procedures
PPTX
Integration of Renewable Energy Sources
PDF
PPTX
Renewable energy and grid integration energy transition
PDF
3.3_Cyber Security R&D for Microgrids_Stamp_EPRI/SNL Microgrid
PPTX
Session 08 design & safety overview
PPTX
Distributed generation b 3
PPTX
10.5_Concordville Microgrid_PECO_EPRI/SNL Microgrid Symposium
Power Adapter Design for 400 V DC Power Distribution in Electronic Systems
GRID INTERCONNECTION OF RENEWABLE ENERGY SOURCES AT DISTRIBUTION LEVEL WITH P...
4.4_Micro Grid Design_Bello_EPRI/SNL Microgrid
8.3_TMSC Overview_Bozada_EPRI/SNL Microgrid Symposium
8.1.2_PAR 2030.8_Bower_EPRI/SNL Microgrid Symposium
1.3. MCAGCC 29 Palms Microgrid_Morrissett_EPRI/SNL Microgrid
2.4_Overview of Microgrid Research, Development, and Resiliency Analysis_Hovs...
8.1.1_PAR 2030.7_Bower_EPRI/SNL Microgrid Symposium
Microsoft PowerPoint - Impacts of Distributed Generation (Public Copy)
5.3_Helping Customers Make the Most of their Energy_Barton_EPRI/SNL Microgrid
2.2_Microgrids PUC Regulatory Issues_Winka_EPRI/SNL Microgrid
Session 06 balance of system components
Session 10 grid interconnections & commissioning test procedures
Integration of Renewable Energy Sources
Renewable energy and grid integration energy transition
3.3_Cyber Security R&D for Microgrids_Stamp_EPRI/SNL Microgrid
Session 08 design & safety overview
Distributed generation b 3
10.5_Concordville Microgrid_PECO_EPRI/SNL Microgrid Symposium
Ad

Viewers also liked (17)

PDF
Anurandha Annaswamy: Computation Model of the Nexus Between Natural Gas and E...
PDF
William Good: Extra Small Modular Reactors
PDF
Benjamin Loop: Simulation Environment for Power Management and Distribution D...
PDF
Andrew Ritch: Interruption in the Utility Industry
PDF
Branndon Kelley Keynote on Cybersecurity and the Smart Utility
PDF
Gareth Digby: Systems-Based Approach to Cyber Investigations
PDF
Bradley Glenn: Holomorphic Embedding Load Flow Method (helmtm) Algorithm Deve...
PDF
Tues pm banquet featuring Jenita McGowan
PDF
David Sadey, Operation and Control of a Three-Phase Megawatt Class Variable F...
PDF
George Baker: Nuclear EMP and Solar GMD Effects, National Protection Impasse,...
PDF
Irv Badr: Managing Risk Safety and Security Compliance
PDF
Flora Flygt: Clean Power Plan Impact on Transmisssion Planning, Development a...
PDF
Loyd Baker: MBSE - connecting the dots process with loyd baker
PPT
Halderman ch035 lecture
PDF
Anne McNelis: Intelligent Power Controller Development for Human Deep Space ...
PDF
Mark Walker: Model Based Systems Engineering Initial Stages for Power & E...
PDF
Neil Kirby: VSC HVDC Transmission and Emerging Technologies in DC Grids
Anurandha Annaswamy: Computation Model of the Nexus Between Natural Gas and E...
William Good: Extra Small Modular Reactors
Benjamin Loop: Simulation Environment for Power Management and Distribution D...
Andrew Ritch: Interruption in the Utility Industry
Branndon Kelley Keynote on Cybersecurity and the Smart Utility
Gareth Digby: Systems-Based Approach to Cyber Investigations
Bradley Glenn: Holomorphic Embedding Load Flow Method (helmtm) Algorithm Deve...
Tues pm banquet featuring Jenita McGowan
David Sadey, Operation and Control of a Three-Phase Megawatt Class Variable F...
George Baker: Nuclear EMP and Solar GMD Effects, National Protection Impasse,...
Irv Badr: Managing Risk Safety and Security Compliance
Flora Flygt: Clean Power Plan Impact on Transmisssion Planning, Development a...
Loyd Baker: MBSE - connecting the dots process with loyd baker
Halderman ch035 lecture
Anne McNelis: Intelligent Power Controller Development for Human Deep Space ...
Mark Walker: Model Based Systems Engineering Initial Stages for Power & E...
Neil Kirby: VSC HVDC Transmission and Emerging Technologies in DC Grids
Ad

Similar to Josh Long: Minimum Cyber Security Requirements for a 20 MW Photo Voltaic Field (20)

PPS
02 ibm security for smart grids
PPTX
Cyber security of power grid
PDF
Cybersecurity of powergrid
PPT
SGSB Webcast 4: Smart Grid Security Standards in Mid 2010
PDF
Cyber security white paper final PMD 12_28_16
PDF
Wind Exchange 2015 Report
PPTX
A Cyber Infrastructure SCADA Testbed Environment for Research on the Nation\'...
PPT
T063500000200201 ppte
PDF
1 3 amec
PDF
Introduction to INFOSEC Professional
PDF
Critical Infrastructure Assessment Techniques to Prevent Threats and Vulnerab...
PPT
7. physical sec
PPTX
2012 Reenergize the Americas 3B: Ralph Martinez
PPT
Cybersecurity for Control Systems: Current State and Future Vision pt.1
PPTX
Challenges and Solution to Mitigate the cyber-attack on Critical Infrastruct...
PPTX
The Final Presentation - The Arsenal.pptx
PDF
Securing SCADA
PDF
Securing SCADA
PDF
Guideline for the certification of wind turbine service technicians 2015 july
02 ibm security for smart grids
Cyber security of power grid
Cybersecurity of powergrid
SGSB Webcast 4: Smart Grid Security Standards in Mid 2010
Cyber security white paper final PMD 12_28_16
Wind Exchange 2015 Report
A Cyber Infrastructure SCADA Testbed Environment for Research on the Nation\'...
T063500000200201 ppte
1 3 amec
Introduction to INFOSEC Professional
Critical Infrastructure Assessment Techniques to Prevent Threats and Vulnerab...
7. physical sec
2012 Reenergize the Americas 3B: Ralph Martinez
Cybersecurity for Control Systems: Current State and Future Vision pt.1
Challenges and Solution to Mitigate the cyber-attack on Critical Infrastruct...
The Final Presentation - The Arsenal.pptx
Securing SCADA
Securing SCADA
Guideline for the certification of wind turbine service technicians 2015 july

More from EnergyTech2015 (8)

PDF
Tues PM banquet keynote featuring Virginia A Greiman
PDF
Mark Minnucci: Deployment of MBSE and the Emergence of a Systems-Thinking Cul...
PDF
Matthew Hause: The Smart Grid and MBSE Driven IoT
PDF
Bob Garrett: Network of Networks Analysis
PDF
David Long Keynote on Beyond MBSE Looking Towards the Next Evolution in Syste...
PDF
John Nairus: Hybrid-Electric Propulsion
PDF
Neil Garrigan: Electric Drive Technology Considerations for Aircraft Propulsion
PDF
EnergyTech2015 Program Guide
Tues PM banquet keynote featuring Virginia A Greiman
Mark Minnucci: Deployment of MBSE and the Emergence of a Systems-Thinking Cul...
Matthew Hause: The Smart Grid and MBSE Driven IoT
Bob Garrett: Network of Networks Analysis
David Long Keynote on Beyond MBSE Looking Towards the Next Evolution in Syste...
John Nairus: Hybrid-Electric Propulsion
Neil Garrigan: Electric Drive Technology Considerations for Aircraft Propulsion
EnergyTech2015 Program Guide

Recently uploaded (20)

PDF
A SYSTEMATIC REVIEW OF APPLICATIONS IN FRAUD DETECTION
PDF
Categorization of Factors Affecting Classification Algorithms Selection
PPTX
Geodesy 1.pptx...............................................
PPTX
CARTOGRAPHY AND GEOINFORMATION VISUALIZATION chapter1 NPTE (2).pptx
PDF
Artificial Superintelligence (ASI) Alliance Vision Paper.pdf
PPTX
6ME3A-Unit-II-Sensors and Actuators_Handouts.pptx
PPT
Mechanical Engineering MATERIALS Selection
PDF
PPT on Performance Review to get promotions
PPTX
Foundation to blockchain - A guide to Blockchain Tech
PPT
Total quality management ppt for engineering students
PDF
Embodied AI: Ushering in the Next Era of Intelligent Systems
PDF
Unit I ESSENTIAL OF DIGITAL MARKETING.pdf
PDF
Level 2 – IBM Data and AI Fundamentals (1)_v1.1.PDF
PDF
Enhancing Cyber Defense Against Zero-Day Attacks using Ensemble Neural Networks
PDF
737-MAX_SRG.pdf student reference guides
PDF
PREDICTION OF DIABETES FROM ELECTRONIC HEALTH RECORDS
DOCX
ASol_English-Language-Literature-Set-1-27-02-2023-converted.docx
PPTX
additive manufacturing of ss316l using mig welding
PPTX
MET 305 2019 SCHEME MODULE 2 COMPLETE.pptx
PDF
III.4.1.2_The_Space_Environment.p pdffdf
A SYSTEMATIC REVIEW OF APPLICATIONS IN FRAUD DETECTION
Categorization of Factors Affecting Classification Algorithms Selection
Geodesy 1.pptx...............................................
CARTOGRAPHY AND GEOINFORMATION VISUALIZATION chapter1 NPTE (2).pptx
Artificial Superintelligence (ASI) Alliance Vision Paper.pdf
6ME3A-Unit-II-Sensors and Actuators_Handouts.pptx
Mechanical Engineering MATERIALS Selection
PPT on Performance Review to get promotions
Foundation to blockchain - A guide to Blockchain Tech
Total quality management ppt for engineering students
Embodied AI: Ushering in the Next Era of Intelligent Systems
Unit I ESSENTIAL OF DIGITAL MARKETING.pdf
Level 2 – IBM Data and AI Fundamentals (1)_v1.1.PDF
Enhancing Cyber Defense Against Zero-Day Attacks using Ensemble Neural Networks
737-MAX_SRG.pdf student reference guides
PREDICTION OF DIABETES FROM ELECTRONIC HEALTH RECORDS
ASol_English-Language-Literature-Set-1-27-02-2023-converted.docx
additive manufacturing of ss316l using mig welding
MET 305 2019 SCHEME MODULE 2 COMPLETE.pptx
III.4.1.2_The_Space_Environment.p pdffdf

Josh Long: Minimum Cyber Security Requirements for a 20 MW Photo Voltaic Field

  • 1. Josh Long and Charlie Givens ENERGYTECH 2015 Minimum Cyber Security Requirements for a 20 MW Photo Voltaic Field Bechtel Group, NS&E December 1, 2015
  • 2. Author Biography Josiah (Josh) Long  Bechtel Global Corp: Nuclear Security & Environmental  Senior Technical Engineering Specialist  30+ Years experience  Functional Engineering Control System & Electrical Staff  25 years Power, 15 years Nuclear, 10 years Government  BSEE Virginia Tech (1981)  PE (Control System Engineering), GICSP, ISA CFS & SFS  Voting Member ISA 67.04&06 Nuclear SR Setpoints  Whitewater, R&R Guitar and Bass, Robotics
  • 3. Overview  Introduction  Description of the 20 MW Standard PV Plant  General Approach to Risk  Risk with the 20 MW Standard  Cyber Security Management System (CSMS)  Summary
  • 4. Elements of the Standard 20MW Solar Facility © Bechtel | 4
  • 5. PART 1 – Project Overview Description of the 20 MW Standard PV Plant  Plot Plan – Covers 85 Acres of relatively flat terran  Plant includes 10 Identical 2 MW Standard Blocks  Electrical Designs – Arrays are based on minimizing wire and maximizing density – Inverters are centrally located to the blocks – Transformers are daisy chained to Substation/Switchyard  SCADA Design – Standard SCADA system is a Cal ISO base configuration – 2 SCADA Remote Terminal Units (RTUs) are required – 1 Weather Station is included.
  • 6. PART 1 – Project Overview Plot Plan – Covers 85 Acres of relatively flat terrain
  • 7. PART 1 – Project Overview Plant includes 10 Identical 2 MW Standard Blocks
  • 8. PART 1 – Project Overview Arrays are based on minimizing wire and maximizing density
  • 9. PART 1 – Project Overview Transformers are daisy chained to Substation/Switchyard
  • 10. PART 1 – Project Overview Description of the 20 MW Standard PV Plant  SCADA Design – Standard SCADA system is a Cal ISO base configuration – 2 SCADA Remote Terminal Units (RTUs) are required – 1 Weather Station is included. SCADA UNIT 1 Weather Station SCADA UNIT 2
  • 11. Elements of the Risk Assessment © Bechtel | 11
  • 12. Part 2 – Risk Assessment Plan  RISK MANAGEMENT PLAN  Asset List  Goals  Risks  Controls  Program
  • 13. Part 2 – Risk ASSET LIST CREATE AN ASSET LIST  Solar Panels $20M  Panel Rack $3.8M  Inverters/Transformer $3.5M  SCADA $50K  Metering $50K  Substation/Switchgear $50k  Security Features ???  Cabling and Wires $1M
  • 14. Part 2 – Risk Assessment OBJECTIVES OF THE FACILITY  What are the Goals of the site – Power Generation – Resale – Dispatch – Automatic Generation – Backup Power Each Can Change The Risk Profile
  • 15. Part 2 – Risk Assessment OBJECTIVES OF THE FACILITY  Power Generation – In the base configuration only generation matters  Resale – If resale is required then Metering is important  Dispatch – If Dispatch is require then a mean of changing output is required » Internet, Dedicated Phone, Manned Facility  Automatic Generation – Automatic Generation may require automatic control perhaps through SCADA  Backup Power – Backup Power may require a higher integrity of supplied components
  • 16. Part 2 – Major Risks Key Risk  Natural Disaster – Earthquake, Hurricane, Flood, Lightening  Infrastructure Failure – Power Grid, Intranet, Communications  Internal Issues – Thief, Damage, Infect, Sabotage  Accidents – Fall or Crushing Incident, Shock, Electrocution  External Targeted Attacks – Thief, Mass Damage, Cyber  External Mass Attacks – Planned Systematic Physical Attack
  • 17. Part 2 – Risk Controls  What Controls (NIST 800 – 53/82)  The Principle Elements of a Cyber Security Program – People – Procedures – Configs and Physical Security  ISA 99 and NIST 800 Series Approaches to Documentation
  • 18. Part 2 – Risk Program Program – Recommended Elements  Policies and Practices (Standards?)  Resource Inventory  Security Liaisons  Normalized Risk Formula  Risk/Change Management Committee  Map of Risk to Objectives  Contributing Security Programs  Exception Tracking
  • 19. © Bechtel | 19 20MW PV FIELD Final Cyber Requirements
  • 20. Part 3 – Minimum Requirements SWGR USER MW MW
  • 21. Part 3 – The Reality of Operation TOP OPERATIONS ISSUES 1. Perimeter Fence Damage 2. Vandalism or Theft 3. Transformer Leakage 4. Various Inverter Damage 5. Broken Conduit or Combiner Box Damage 6. Vegetation Overgrowth 7. Cell Browning/Discoloring or Shorted Cell 8. Shorted Cell 9. Unclean Panels 10.Animal Nuisance
  • 22. Part 3 – A More Realistic Approach © 2012 Bechtel | 22 Firewall Switch SCADA Unit 1 Security System CCTV System SCADA Unit 2 HISTORIAN WS MW
  • 23. Part 3 - Execution  EXECUTION to be performed on an annual or quarterly basis  The Principle Elements of Cyber Security – People – Procedures – Configs and Physical Security  Monitoring  Improvement Plan  Design Delta  Summary