D-TECH, LLC — Department of Energy SBIR Phase II: 32j
D-TECH, LLC — SBIR Phase II award from Department of Energy.
- Amount
- $1,009,998
- Agency
- Department of Energy
- Program / Phase
- SBIR · Phase II
- Topic
- 32j
- Solicitation
- DE-FOA-0001490
- NAICS
- —
- Place of performance
- VA
- Period
- 2016-08-01 → 2018-07-31
Description
Nuclear power plant (NPP) operators are required by the Nuclear Regulatory Commission (NRC) to perform cybersecurity assessments on their internal networks, control systems and critical data assets on a regular basis to ensure regulatory compliance and safety, security and emergency preparedness of the nation’s most critical infrastructures. However, the current assessment processes in the nuclear industry are highly manual driven, labor intensive and costly. The existing software tools for assessments used today are primarily report generators based on user input to a sequence of static questions. The results generated from such practices are inconsistent, costly, difficult to verify, and inadequate to capture the security posture of an NPP in a timely fashion. In this SBIR, we will develop an innovative solution for the cybersecurity assessment problem via automation. By using a quantitative risk model, we will create a robust and extensible software tool to help streamline the cybersecurity assessment process in the nuclear industry. The software tool, called Automated Cybersecurity Assessment Manager (ACAM™), is designed to support NRC regulatory policies and industry standards, and provide NPP operators with a set of web based functions to manage cybersecurity risks efficiently and cost effectively. At the end of Phase I, we created an initial version of a quantitative risk model and developed a prototype of the ACAM product that demonstrated the solution feasibility and laid out a solid foundation for continuous research and development (R&D) in Phase II. Our Phase II plan is to continue maturing our quantitative model for industrial control systems (ICS), continue developing the ACAM prototype into an enterprise product, and complete the ACAM testing in a lab test environment with realistic digital and process control assets. The end result will be a full-fledged ACAM software product ready to be deployed for beta testing with customers and integrators towards commercialization. ACAM will be the first software framework for conducting quantitative cybersecurity assessment from a risk perspective, providing accurate and consistent assessment results with significant cost savings. The result of this SBIR will fill an important gap in cybersecurity risk management for the nuclear and power industry, creating a viable solution that can be easily customized and adopted by other utility companies as well as other ICS industries. As more enterprises adopt cybersecurity assessment practices, we will be uniquely positioned to capture this growing market by continuing to advance the ACAM technology and help to secure and protect our nation’s critical infrastructures for years to come. Key Words: Cybersecurity Assessment, Assessment Evaluation, Quantitative Risk Analysis, Security Controls, Regulatory Compliance, Nuclear Power Plant Cybersecurity, Critical Infrastructure Protection