Deriving a Capability Maturity Model for Electric Utility Security Assessment

Barbara E. Endicott-Popovsky, Diane L. Lockwood · Academy of Information and Management Sciences journal · 2005

ABSTRACT The pressures of better, faster, cheaper have driven electric utilities to find new, more efficient, cost-cutting approaches to doing business such as using low cost public networks like Internet for data communications. While many utilities have rushed to take advantage of apparent benefits, new security vulnerabilities these technologies introduce have not been fully appreciated. As a result, many utilities are not aware of potential threats and impacts such vulnerabilities may introduce, nor are they prepared to assess these risks fully. This paper describes a security assessment tool, Critical Infrastructure Capability Maturity Model (CI-CMM), which is designed to assist power industry in determining whether their security processes are adequate, including those that address threats posed by potential electronic intrusion. This proposed new model is based on a derivative of Software Engineering Institute's Capability Maturity Model (CMM), which has become a well-established tool for assessing effectiveness of a firm's software development processes. Use of this proposed new tool should not only identify potential security problems, but also provide needed education and awareness to utilities submitting to assessment process. INTRODUCTION While physical destruction due to natural occurrences is still greatest threat facing North American electric utilities, growing vulnerability to electronic intrusion has been well documented. The White House report by National Security Telecommunications Advisory Committee (NSTAC) states that the security of electric power control networks represents a significant emerging risk to electric power grid (NSTACIA, 1997), (Oman, Schweitzer & Frincke, 2000). These systems are increasingly vulnerable to hackers, disgruntled insiders and terrorists; yet, at same time, traditional security assessment models used by electric utilities have continued to emphasize physical threats (IEEE-PES, 2000). Recent research has shown validity of applying tools and techniques from Infosec community to safeguarding of critical components of electric utility infrastructures (Oman, Risley, Roberts & Schweitzer, 2002). Likewise, by drawing from techniques used by InfoSec community to assess effectiveness of computer security processes, this paper provides an approach for assisting utilities in assessing security risks to their critical infrastructure, including those posed by potential electronic intrusion. Realizing that education and awareness is an important first step to recognizing security risks, this process will also provide valuable learning experiences for those undertaking it (IEEE-PES, 2000). We begin with a description of what is included in definition of a critical infrastructure system, then provide an overview of kinds of assessment models available to InfoSec community. We discuss how to adapt these models to evaluating security at electric utilities and then make recommendations about how to apply and interpret them during an onsite assessment. SCOPE OF CRITICAL INFRASTURE SYSTEMS We have broadened definition of critical infrastructure to include not only technology, but also people and processes necessary to run it and physical boundary that offers first level of protection. [FIGURE 1 OMITTED] People According to IEEE1402, ignorance is a significant vulnerability in face of intrusion threats (IEEE-PES, 2000). If individuals working for a public utility are unaware of security vulnerabilities, they might ignore security practices that they perceive as being of no value other than making work more difficult. The level of security awareness, and skills and training in security of people working with a critical infrastructure system, affect its level of vulnerability. …

Read the paper · More papers on PaperTik