{"id":188865,"date":"2024-06-21T14:15:58","date_gmt":"2024-06-21T12:15:58","guid":{"rendered":"https:\/\/www.rse-web.it\/pubblicazioni\/how-to-assess-the-cybersecurity-posture-of-utility-infrastructuresa-case-study-from-the-osmose-project\/"},"modified":"2024-11-21T10:31:52","modified_gmt":"2024-11-21T09:31:52","slug":"how-to-assess-the-cybersecurity-posture-of-utility-infrastructuresa-case-study-from-the-osmose-project","status":"publish","type":"pubblicazioni","link":"https:\/\/www.rse-web.it\/en\/publications\/how-to-assess-the-cybersecurity-posture-of-utility-infrastructuresa-case-study-from-the-osmose-project\/","title":{"rendered":"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project"},"content":{"rendered":"<p class=\"last-updated-date\">Recently updated on November 21st, 2024 at 10:31 am<\/p>","protected":false},"excerpt":{"rendered":"<p>This work presents the application of a methodology to assess the cybersecurity posture of a demonstrator within the H2020 OSMOSE project (Optimal System-Mix of Flexibility Solutions for European Electricity) related to congestion management in the Italian transmission network. The inclusion of these new functionalities requires several extensions to the ICT architecture of the hosting organization: new interactions with external factors and the installation of additional components must be analyzed from a cybersecurity perspective. For this purpose, a multi-phase evaluation methodology was applied to the pilot project to consider various organizational and infrastructural aspects.<\/p>\n","protected":false},"author":93,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"tags":[1378,1435,1303,1341,1434,1315],"targets":[1317],"pubblicazioni_tipologie":[778],"class_list":["post-188865","pubblicazioni","type-pubblicazioni","status-publish","hentry","tag-communication-systems-en","tag-control","tag-energy-transition","tag-infrastructure","tag-network-security","tag-smart-grids-en","targets-research","pubblicazioni_tipologie-paper-en"],"acf":{"dont_show_hompage":true,"projects":{"ID":188406,"post_author":"93","post_date":"2024-06-13 15:10:14","post_date_gmt":"2024-06-13 13:10:14","post_content":"","post_title":"Integrated Project for Energy System Cybersecurity","post_excerpt":"The project has the threefold goal of developing studies, tools and methodologies aimed at: \n- ensuring the security of communication technologies in energy systems; \n- preserving the resilience of the electricity system in case of cyber attacks; \n- leveraging artificial intelligence for the detection of cyber anomalies in energy infrastructure.\n","post_status":"publish","comment_status":"open","ping_status":"closed","post_password":"","post_name":"integrated-project-for-energy-system-cybersecurity","to_ping":"","pinged":"","post_modified":"2024-07-02 10:30:09","post_modified_gmt":"2024-07-02 08:30:09","post_content_filtered":"","post_parent":0,"guid":"https:\/\/www.rse-web.it\/progetti\/integrated-project-for-energy-system-cybersecurity\/","menu_order":0,"post_type":"progetti","post_mime_type":"","comment_count":"0","filter":"raw"},"order_posts":"","dont_show_search":false,"related_posts":false,"show_on_slider":false,"single_post_data":{"titolo_spot":"","post_content":"<p>Today, Electric Power Utilities must continuously evaluate the cybersecurity posture of their critical infrastructures. This paper presents the application of a methodology to assess the cybersecurity posture of a demonstrator within the H2020 OSMOSE project (Optimal System-Mix of Flexibility Solutions for European Electricity) related to congestion management in the Italian transmission network.<\/p>\n<p>&nbsp;<\/p>\n<p>The inclusion of these new functionalities requires several extensions to the ICT architecture of the hosting organization: new interactions with external factors and the installation of additional components must be analyzed from a cybersecurity perspective. For this purpose, a multi-phase evaluation methodology was applied to the pilot project to consider various organizational and infrastructural aspects.<\/p>\n<p>&nbsp;<\/p>\n<p>Starting from the ICT technical specification of the OSMOSE pilot, the CSET tool was used to perform a compliance assessment against the NIST 800-53 standard. The first phase of the analysis identifies a list of priority requirements for each category of the standard, deemed suitable for a specific Security Assurance Level. This analysis phase assigns a ranking value to each category of requirements, enabling the identification of critical areas on which to focus the cybersecurity assessment.<\/p>\n<p>&nbsp;<\/p>\n<p>The second step analyzes the ICT architecture in terms of components and networks and derives cybersecurity controls in line with the criticality levels of system assets. The security controls are then used as a guide to structure a cybersecurity test plan of functional, technical, and audit actions involving various processes and organizational areas.<\/p>\n<p>&nbsp;<\/p>\n<p>The final goal of this evaluation is to check whether the integration of new ICT systems for congestion management into the pre-existing architecture requires new cybersecurity controls to meet the assigned Security Level of the entire system. The methodological approach and results presented in the paper may be of interest to many operators who must address the cybersecurity of their evolving digital infrastructures to keep abreast of the new challenges introduced by the energy transition.<\/p>\n","scarica_file":false,"link_estreno":[{"link_text":"Download Publication","link":"https:\/\/www.e-cigre.org\/publications\/detail\/d2-10794-2022-how-to-assess-the-cybersecurity-posture-of-utility-infrastructures-a-case-study-from-the-osmose-project.html"}],"button":{"text":"","link":""},"referente_group":false,"data_emissione":"2022-09-02","autori":"G. Dondossola, R. Terruggia (RSE S.p.A.), A. Foschini, G. Lisciandrello, L. Orru, F. Silletti Terna (S.p.A.)","destinazione":"CIGRE Session 2022, Paris August 28 - September 2, 2022","rif_rse":"22009877"},"satellite_post_url":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project - RSE<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rse-web.it\/publications\/186881\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project - RSE\" \/>\n<meta property=\"og:description\" content=\"This work presents the application of a methodology to assess the cybersecurity posture of a demonstrator within the H2020 OSMOSE project (Optimal System-Mix of Flexibility Solutions for European Electricity) related to congestion management in the Italian transmission network. The inclusion of these new functionalities requires several extensions to the ICT architecture of the hosting organization: new interactions with external factors and the installation of additional components must be analyzed from a cybersecurity perspective. For this purpose, a multi-phase evaluation methodology was applied to the pilot project to consider various organizational and infrastructural aspects.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rse-web.it\/publications\/186881\/\" \/>\n<meta property=\"og:site_name\" content=\"RSE\" \/>\n<meta property=\"article:modified_time\" content=\"2024-11-21T09:31:52+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.rse-web.it\/publications\/186881\/\",\"url\":\"https:\/\/www.rse-web.it\/publications\/186881\/\",\"name\":\"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project - RSE\",\"isPartOf\":{\"@id\":\"https:\/\/www.rse-web.it\/#website\"},\"datePublished\":\"2024-06-21T12:15:58+00:00\",\"dateModified\":\"2024-11-21T09:31:52+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.rse-web.it\/publications\/186881\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.rse-web.it\/publications\/186881\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.rse-web.it\/publications\/186881\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.rse-web.it\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.rse-web.it\/#website\",\"url\":\"https:\/\/www.rse-web.it\/\",\"name\":\"RSE\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.rse-web.it\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.rse-web.it\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.rse-web.it\/#organization\",\"name\":\"RSE\",\"url\":\"https:\/\/www.rse-web.it\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png\",\"contentUrl\":\"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png\",\"width\":734,\"height\":164,\"caption\":\"RSE\"},\"image\":{\"@id\":\"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project - RSE","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rse-web.it\/publications\/186881\/","og_locale":"en_US","og_type":"article","og_title":"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project - RSE","og_description":"This work presents the application of a methodology to assess the cybersecurity posture of a demonstrator within the H2020 OSMOSE project (Optimal System-Mix of Flexibility Solutions for European Electricity) related to congestion management in the Italian transmission network. The inclusion of these new functionalities requires several extensions to the ICT architecture of the hosting organization: new interactions with external factors and the installation of additional components must be analyzed from a cybersecurity perspective. For this purpose, a multi-phase evaluation methodology was applied to the pilot project to consider various organizational and infrastructural aspects.","og_url":"https:\/\/www.rse-web.it\/publications\/186881\/","og_site_name":"RSE","article_modified_time":"2024-11-21T09:31:52+00:00","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.rse-web.it\/publications\/186881\/","url":"https:\/\/www.rse-web.it\/publications\/186881\/","name":"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project - RSE","isPartOf":{"@id":"https:\/\/www.rse-web.it\/#website"},"datePublished":"2024-06-21T12:15:58+00:00","dateModified":"2024-11-21T09:31:52+00:00","breadcrumb":{"@id":"https:\/\/www.rse-web.it\/publications\/186881\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rse-web.it\/publications\/186881\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.rse-web.it\/publications\/186881\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.rse-web.it\/en\/"},{"@type":"ListItem","position":2,"name":"How to assess the cybersecurity posture of utility infrastructures?A case study from the OSMOSE project"}]},{"@type":"WebSite","@id":"https:\/\/www.rse-web.it\/#website","url":"https:\/\/www.rse-web.it\/","name":"RSE","description":"","publisher":{"@id":"https:\/\/www.rse-web.it\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rse-web.it\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.rse-web.it\/#organization","name":"RSE","url":"https:\/\/www.rse-web.it\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/","url":"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png","contentUrl":"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png","width":734,"height":164,"caption":"RSE"},"image":{"@id":"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/"}}]}},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni\/188865","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni"}],"about":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/types\/pubblicazioni"}],"author":[{"embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/users\/93"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/comments?post=188865"}],"version-history":[{"count":3,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni\/188865\/revisions"}],"predecessor-version":[{"id":199201,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni\/188865\/revisions\/199201"}],"wp:attachment":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/media?parent=188865"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/tags?post=188865"},{"taxonomy":"targets","embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/targets?post=188865"},{"taxonomy":"pubblicazioni_tipologie","embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni_tipologie?post=188865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}