Title :
A new data classification methodology to enhance utility data security
Author :
Rajagopal, Niranjini ; Prasad, Krishna V. ; Shah, Mubarak ; Rukstales, Chuck
Author_Institution :
Tata Consultancy Services Ltd., Mumbai, India
Abstract :
Classification of data is an important step to strengthen the control of data, define how it is distributed, and who has access to the data. There are established practices among other industries like finance and banking. This paper describes a security framework for classification of data in electric utilities. Presently, data classification is viewed more from Information Security (IS) perspective with limited involvement of business functions. Present approach in utilities does not cover much of the data from Operational Technology (OT) systems. Implementation of Smart Grid increases the complexity of Data Classification with possibilities for dynamic data aggregation through enterprise level system integration. NIST Special Publication 800-60 provides guidelines to arrive at security classification based on broadly classified limited types of utility data. The new approach presented overcomes this limitation by mapping data types to appropriate interface categories based on the guidelines from Smart Grid Interoperability Panel (SGIP) - NISTIR 7628. Case study of a Data Classification exercise carried out for a North American Utility is presented. Some learnings and recommendations for enhancement of the approach are also discussed. A registry tool developed for Data Classification using the new approach is explained.
Keywords :
data handling; electricity supply industry; open systems; pattern classification; power engineering computing; power system protection; power system security; security of data; smart power grids; NIST Special Publication 800-60; North American utility; SGIP; Smart Grid Interoperability Panel-NISTIR 7628; business functions; data classification complexity; data classification methodology; data control; data type mapping; dynamic data aggregation; electric utilities; enterprise level system integration; information security perspective; interface categories; security classification; security framework; smart grid; utility data security enhancement; NIST; Security; Smart grids; Critical Infrastructure Protection; Data Classification; Security; Security framework; Smart Grid;
Conference_Titel :
Innovative Smart Grid Technologies Conference (ISGT), 2014 IEEE PES
Conference_Location :
Washington, DC
DOI :
10.1109/ISGT.2014.6816451