performing-power-grid-cybersecurity-assessment

Featured

This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and related attacks.

AI & Automation 16,326 stars 1981 forks Updated 2 weeks ago Apache-2.0

Install

View on GitHub

Quality Score: 97/100

Stars 20%
100
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Performing Power Grid Cybersecurity Assessment ## When to Use - When conducting periodic cybersecurity assessments of power grid facilities per NERC CIP requirements - When assessing substation automation systems using IEC 61850 GOOSE and MMS protocols - When evaluating the security of an Energy Management System (EMS) or SCADA control center - When assessing synchrophasor (PMU) networks and wide-area monitoring systems - When preparing for regional entity compliance audits or internal security reviews **Do not use** for non-BES systems below NERC registration thresholds, for general OT assessment without power grid specifics (see performing-ot-network-security-assessment), or for physical security assessment of generation facilities without cyber scope. ## Prerequisites - Understanding of electric power grid architecture (generation, transmission, distribution) - Familiarity with NERC CIP standards and BES Cyber System categorization - Knowledge of power grid protocols (IEC 61850, IEC 60870-5-104, DNP3, ICCP/TASE.2) - Passive monitoring tools for substation network traffic analysis - Access to EMS/SCADA architecture documentation and network diagrams ## Workflow ### Step 1: Map Power Grid Cyber Architecture Identify and document all cyber systems supporting grid operations including EMS, SCADA, substation automation, and communication infrastructure. ```yaml # Power Grid Cyber Architecture Assessment facility_type: "Regional Transmission Organization Control Cente...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
2 weeks ago
Language
Python
License
Apache-2.0

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

performing-ot-network-security-assessment

This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infrastructure.

16,326 Updated 2 weeks ago
mukul975
AI & Automation Featured

performing-oil-gas-cybersecurity-assessment

This skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream (exploration/production), midstream (pipeline/transport), and downstream (refining/distribution) operations. It addresses SCADA systems controlling pipeline operations, DCS for refinery process control, safety instrumented systems for hazardous processes, remote terminal units at unmanned wellhead sites, and compliance with API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST Cybersecurity Framework for critical infrastructure.

16,326 Updated 2 weeks ago
mukul975
AI & Automation Featured

implementing-nerc-cip-compliance-controls

This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), supply chain risk management (CIP-013), and the 2025 updates including mandatory MFA for remote access and expanded low-impact asset requirements.

16,326 Updated 2 weeks ago
mukul975