What other groups/associations do utilities report cyber-security incidents to, i.e., other utilities, contractors, etc.?

How many cyber-security attacks does a utility average during a day/week/month/year?

How many cyber-security attacks result in an escalated response, or require additional action to repel?

How many security breaches have resulted in the dissemination of personal/customer information?

How often does a utility engage with an independent third-party to engage in penetration testing of their networks, such as AMI, operations, other mainframes, etc.?

How often does a utility engage with an independent third-party to perform a security audit?

How does a utility define a cyber attack, a security break, etc.?

What criteria does a utility use to determine the competence of an internal and/or third-party penetration tester and/or auditors?

What do utilities do when they have determined that Smart Grid components/systems/equipment are vulnerable to security breaches?

Who is responsible for the costs of fixing security breaches due to vulnerabilities in products?

What known security vulnerabilities in the Smart Grid deployment currently remain in a vulnerable state?

What cryptographic techniques/methods are used by utilities to protect the systems?

What automated testing tools/security software are used by the utilities to protect the systems

Do utilities require security certifications for the purchased systems/components?

Do utilities have permanent job positions for security/cryptography professionals?

Do utilities have mechanisms in place to check against publicly known security vulnerabilities?

Do utilities have mechanisms to automatically apply security patches?

(END OF ATTACHMENT B)

124 Registration is defined as "The process by which a Commissioned HAN device is authorized to communicate on a logical network. This involves the exchange of security credentials... The registration process is required for the exchange of secure information..." Definition per the , Draft v1.95, Open HAN Task Force, and referred to in NISTIR 7628 Guidelines for Smart Grid Cyber Security, Vol. 2, Privacy and the Smart Grid, issued in August 2010.

125 Commissioning is defined as "The process by which a HAN device obtains access to a specific physical network and allows the device to be discovered on that network." Admission to the network allows the HAN device to communicate with peer devices and receive public broadcast information, but the information is not secured.

126 Enrollment is defined as "The process by which a Consumer enrolls a HAN device in a Service Provider's program (e.g. demand response, energy management, pre-pay, PEV programs, distributed generation programs, pricing, messaging, etc.) and gives certain rights to the Service Provider to communicate with their HAN device."

Previous PageTop Of PageGo To First Page