25.12.2012 Views

Security Profile for Advanced Metering Infrastructure - Open Smart ...

Security Profile for Advanced Metering Infrastructure - Open Smart ...

Security Profile for Advanced Metering Infrastructure - Open Smart ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

and verify that the appropriate versions are retained. Inherent in this is an in<strong>for</strong>mation<br />

classification system that allows in<strong>for</strong>mation assets to receive the appropriate level of<br />

protection.<br />

The following are the controls <strong>for</strong> In<strong>for</strong>mation and Document Management that need to<br />

be supported and implemented by the organization to protect the AMI components.<br />

DHS-2.9.1 In<strong>for</strong>mation and Document Management Policy and<br />

Procedures<br />

DHS-2.9.1.1 Requirement:<br />

The organization shall develop, disseminate, and periodically review/update:<br />

1. A <strong>for</strong>mal, documented, AMI system in<strong>for</strong>mation and document management<br />

policy that addresses purpose, scope, roles, responsibilities, management<br />

commitment, coordination among organizational entities, and compliance.<br />

2. Formal, documented procedures to facilitate the implementation of the AMI<br />

system in<strong>for</strong>mation and document management policy and associated system<br />

maintenance controls.<br />

DHS-2.9.1.2 Supplemental Guidance:<br />

The organization must ensure that the AMI system in<strong>for</strong>mation and document<br />

management policy and procedures are consistent with applicable federal laws,<br />

directives, policies, regulations, standards, and guidance. The AMI system in<strong>for</strong>mation<br />

and document management policy can be included as part of the general in<strong>for</strong>mation<br />

security policy <strong>for</strong> the organization. System in<strong>for</strong>mation and document management<br />

procedures can be developed <strong>for</strong> the security program in general, and <strong>for</strong> a particular<br />

AMI component, when required.<br />

DHS-2.9.1.3 Requirement Enhancements:<br />

None.<br />

DSH-2.9.1.4 Rationale<br />

Uncontrolled access to in<strong>for</strong>mation concerning electrical consumption, billing, and other<br />

aspects of utility operations exposes the utility and its customers to potential fraud, theft,<br />

and other kinds of larceny and may result in violations of laws <strong>for</strong> privacy and other,<br />

similar statutes. Policies <strong>for</strong> document management are necessary to protect from these<br />

kinds of error and misuse.<br />

<strong>Security</strong> <strong>Profile</strong> <strong>for</strong> <strong>Advanced</strong> <strong>Metering</strong> <strong>Infrastructure</strong> Version 1.0<br />

UtiliSec Working Group (UCAIug) December 10, 2009<br />

41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!