| name | performing-power-grid-cybersecurity-assessment |
| description | Use when this skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and rel... |
| domain | cybersecurity |
| tags | ["ot-security","ics","scada","industrial-control","iec62443","nerc-cip","power-grid","substation"] |
| subdomain | ot-ics-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","DE.CM-01","ID.AM-05","GV.OC-02"] |
Performing Power Grid Cybersecurity Assessment
Overview
Cybersecurity skill for performing power grid cybersecurity assessment. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing power grid cybersecurity assessment"
-
"This skill covers conducting cybersecurity assessments of electric power grid in"
-
When conducting periodic cybersecurity assessments of power grid facilities per NERC CIP requirements
-
When assessing substation automation systems using IEC 61850 GOOSE and MMS protocols
-
When evaluating the security of an Energy Management System (EMS) or SCADA control center
-
When assessing synchrophasor (PMU) networks and wide-area monitoring systems
-
When preparing for regional entity compliance audits or internal security reviews
Do not use for non-BES systems below NERC registration thresholds, for general OT assessment without power grid specifics (see performing-ot-network-security-assessment), or for physical security assessment of generation facilities without cyber scope.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Understanding of electric power grid architecture (generation, transmission, distribution)
- Familiarity with NERC CIP standards and BES Cyber System categorization
- Knowledge of power grid protocols (IEC 61850, IEC 60870-5-104, DNP3, ICCP/TASE.2)
- Passive monitoring tools for substation network traffic analysis
- Access to EMS/SCADA architecture documentation and network diagrams
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}