{"id":194126,"date":"2024-09-05T10:46:15","date_gmt":"2024-09-05T08:46:15","guid":{"rendered":"https:\/\/www.rse-web.it\/pubblicazioni\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/"},"modified":"2024-09-05T10:47:44","modified_gmt":"2024-09-05T08:47:44","slug":"cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines","status":"publish","type":"pubblicazioni","link":"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/","title":{"rendered":"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines"},"content":{"rendered":"","protected":false},"excerpt":{"rendered":"<p>This paper describes the methodology used to determine the security requirements to be applied to the extended IT\/OT architecture of the OSMOSE project; the methodology follows and extends the NISTIR 7628 guidelines for achieving a secure architecture by design.<\/p>\n","protected":false},"author":93,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"tags":[1344,1346,1325,1324,1330],"targets":[],"pubblicazioni_tipologie":[778],"class_list":["post-194126","pubblicazioni","type-pubblicazioni","status-publish","hentry","tag-cybersecurity-en","tag-cybersecurity-assessment-en","tag-electrical-system","tag-electricity-network-en","tag-security-en","pubblicazioni_tipologie-paper-en"],"acf":{"projects":{"ID":189183,"post_author":"464","post_date":"2024-06-25 10:06:02","post_date_gmt":"2024-06-25 08:06:02","post_content":"","post_title":"Optimal System-Mix Of flexibility Solutions for European electricity","post_excerpt":"The project address the identification and development of flexibilities required to enable the Energy Transition to high share of renewables through a holistic approach.","post_status":"publish","comment_status":"open","ping_status":"closed","post_password":"","post_name":"optimal-system-mix-of-flexibility-solutions-for-european-electricity","to_ping":"","pinged":"","post_modified":"2024-07-06 15:43:06","post_modified_gmt":"2024-07-06 13:43:06","post_content_filtered":"","post_parent":0,"guid":"https:\/\/www.rse-web.it\/progetti\/optimal-system-mix-of-flexibility-solutions-for-european-electricity\/","menu_order":0,"post_type":"progetti","post_mime_type":"","comment_count":"0","filter":"raw"},"order_posts":"","dont_show_search":false,"related_posts":false,"dont_show_hompage":false,"show_on_slider":false,"single_post_data":{"titolo_spot":"","post_content":"<p>When an electrical system control architecture needs to be extended with new functionality, it is necessary to manage the <em>cybersecurity<\/em> consequences of design choices. Standards, methodologies and support tools can provide guidance early in the design stages by preventing costly corrective actions; this article describes the approach proposed in the European project OSMOSE <em>(Optimal System-Mix Of flexibility Solutions for European Electricity)<\/em>. Within OSMOSE, a new <em>Zonal Energy Management System<\/em> (Z-EMS) is designed. The Z-EMS has to be integrated into a pre-existing monitoring and control architecture. This paper describes the methodology used to determine the <em>cybersecurity<\/em> requirements to be applied to the extended IT\/OT control architecture resulting from the introduction of Z-EMS; specifically, starting with the high-level architecture of the subsystems interacting with Z-EMS, a set of high-level cybersecurity requirements were determined by applying NISTIR 7628 guidelines. Initially, the high-level architecture was specified and mapped onto the SGAM (<em>Smart Grid Architecture Model<\/em>) <em>plane<\/em> with the support of specific software tools, focusing on identifying the key subsystems involved by the major data exchanges. The subsystems were then associated with the actors identified by the NISTIR 7628 guidelines; in doing so, it was necessary to enrich some of the NISTIR actors with new interfaces because those originally available were not adequate to represent the functionality of the subsystems in the updated architecture; the extensions were made in analogy and in accordance with the NISTIR methodology.<\/p>\n","scarica_file":false,"link_estreno":[{"link_text":"Download Memory","link":"https:\/\/www.osmose-h2020.eu\/wp-content\/uploads\/2021\/06\/CIGRE_D2_2019_NISTIR-7628-security.pdf"}],"button":{"text":"","link":""},"referente_group":false,"data_emissione":"2019-06-14","autori":"M.G. Todeschini, G. Dondossola, (RSE S.P.A.)","destinazione":"Cigr\u00e8 SC D2 Colloquium 2019, Helsinki, June 11-14, 2019","rif_rse":"19005964"},"satellite_post_url":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines - RSE<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines - RSE\" \/>\n<meta property=\"og:description\" content=\"This paper describes the methodology used to determine the security requirements to be applied to the extended IT\/OT architecture of the OSMOSE project; the methodology follows and extends the NISTIR 7628 guidelines for achieving a secure architecture by design.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/\" \/>\n<meta property=\"og:site_name\" content=\"RSE\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-05T08:47:44+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/\",\"url\":\"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/\",\"name\":\"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines - RSE\",\"isPartOf\":{\"@id\":\"https:\/\/www.rse-web.it\/#website\"},\"datePublished\":\"2024-09-05T08:46:15+00:00\",\"dateModified\":\"2024-09-05T08:47:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.rse-web.it\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.rse-web.it\/#website\",\"url\":\"https:\/\/www.rse-web.it\/\",\"name\":\"RSE\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.rse-web.it\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.rse-web.it\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.rse-web.it\/#organization\",\"name\":\"RSE\",\"url\":\"https:\/\/www.rse-web.it\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png\",\"contentUrl\":\"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png\",\"width\":734,\"height\":164,\"caption\":\"RSE\"},\"image\":{\"@id\":\"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines - RSE","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/","og_locale":"en_US","og_type":"article","og_title":"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines - RSE","og_description":"This paper describes the methodology used to determine the security requirements to be applied to the extended IT\/OT architecture of the OSMOSE project; the methodology follows and extends the NISTIR 7628 guidelines for achieving a secure architecture by design.","og_url":"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/","og_site_name":"RSE","article_modified_time":"2024-09-05T08:47:44+00:00","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/","url":"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/","name":"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines - RSE","isPartOf":{"@id":"https:\/\/www.rse-web.it\/#website"},"datePublished":"2024-09-05T08:46:15+00:00","dateModified":"2024-09-05T08:47:44+00:00","breadcrumb":{"@id":"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.rse-web.it\/en\/publications\/cyber-security-requirements-of-multi-operator-it-ot-architectures-based-on-nistir-7628-guidelines\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.rse-web.it\/en\/"},{"@type":"ListItem","position":2,"name":"Cyber security requirements of multi-operator IT\/OT architectures based on NISTIR 7628 guidelines"}]},{"@type":"WebSite","@id":"https:\/\/www.rse-web.it\/#website","url":"https:\/\/www.rse-web.it\/","name":"RSE","description":"","publisher":{"@id":"https:\/\/www.rse-web.it\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rse-web.it\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.rse-web.it\/#organization","name":"RSE","url":"https:\/\/www.rse-web.it\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/","url":"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png","contentUrl":"https:\/\/www.rse-web.it\/wp-content\/uploads\/2024\/01\/cropped-logo_rse_2022.png","width":734,"height":164,"caption":"RSE"},"image":{"@id":"https:\/\/www.rse-web.it\/#\/schema\/logo\/image\/"}}]}},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni\/194126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni"}],"about":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/types\/pubblicazioni"}],"author":[{"embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/users\/93"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/comments?post=194126"}],"version-history":[{"count":1,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni\/194126\/revisions"}],"predecessor-version":[{"id":194127,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni\/194126\/revisions\/194127"}],"wp:attachment":[{"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/media?parent=194126"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/tags?post=194126"},{"taxonomy":"targets","embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/targets?post=194126"},{"taxonomy":"pubblicazioni_tipologie","embeddable":true,"href":"https:\/\/www.rse-web.it\/en\/wp-json\/wp\/v2\/pubblicazioni_tipologie?post=194126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}