BES Cyber System Information on AWS
Publication date: May 18, 2022 (Diagram history)
With this architecture, you can build a secure extension of an Operations Technology (OT) data center into AWS. This extension supports ingestion of data from Bulk Electric System (BES) assets. The solution uses an AWS Amazon VPC for inherent security and isolation. Compute, analytics, and AI/ML services operate on a data lake to conduct contingency analysis, incident response, and advanced analytics. The architecture also demonstrates North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) compliance for BES Cyber System Information (BCSI).
BES Cyber System Information diagram
The following steps describe the security, networking, and analytics components for this architecture:
-
Connect your utility OT network (generation facilities, remote substations, data centers, and customer locations) to AWS.
-
Establish secure and highly reliable networking to AWS over VPN. For guaranteed bandwidth, use AWS Direct Connect with IEEE 802.1AE (MACSec) encryption. (Relates to CIP 11.)
-
3A. Manage and govern cloud resources at scale from a centralized location by using services such as AWS Control Tower, AWS Audit Manager, and AWS Systems Manager. Log all account activity with AWS CloudTrail. Use AWS Config to assess all cloud configurations and any changes. (Relates to CIP 11.)
3B. Control access with AWS Identity and Access Management and Directory Service. Monitor network traffic for malicious activity by using Amazon GuardDuty. Encrypt and protect data by using AWS Key Management Service. (Relates to CIP 4 and CIP 11.)
-
Ingest data by using services such as AWS Database Migration Service, AWS Storage Gateway, AWS Transfer Family, or Amazon Kinesis. Route data flows to Amazon VPC through Amazon VPC endpoints. (Relates to CIP 11.)
-
Use Amazon VPC with its inherent security and isolation for hosting compute and database resources. (Relates to CIP 11.)
5A. Run analysis and simulations by using compute options including Amazon Elastic Compute Cloud, AWS Lambda, Amazon Elastic Kubernetes Service, Amazon Elastic Container Service, and AWS Fargate for containerized applications, and Amazon EMR. Encrypt all compute resources with AWS KMS. (Relates to CIP 11.)
5B. Store data securely in highly available relational databases by using Amazon RDS and Amazon Aurora. Encrypt data at rest with AWS KMS. (Relates to CIP 11.)
5C. Use AI/ML services such as Amazon SageMaker AI for analysis and assessment of BCSI.
-
Create the OT data lake on Amazon Simple Storage Service. Perform ETL and build the data catalog with AWS Glue. Archive data in Amazon S3 Glacier. Encrypt data by using AWS KMS. Restrict data access to the Amazon VPC by using Amazon VPC endpoints. (Relates to CIP 11.)
Further reading
For additional information, see the following resources:
Diagram history
To receive updates about this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Initial publication | Reference architecture diagram first published. | May 18, 2022 |
RSS subscription requirement
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.