DA-401-2019: Security test plan for distribution automation RTUs [PUBLIC]

This document provides a plan to test distribution automation (DA) remote terminal units (RTUs) against the security requirements that ENCS has developed.

ENCS has developed a set of security requirement for procuring distribution automation (DA) remote terminal units (RTUs). When the requirements are used, the need arises to evaluate the RTU against the requirements. This document provides a standardized test plan for RTUs.

By standardizing the test plan, the test results can be more easily shared between grid operators. The vendor of the RTU can perform security tests according to the test plan and then use the test report to show compliance in all tenders that use the security requirements. This reduces the cost of testing and can give grid operators assurance in advance that there are RTUs meeting the requirements.

The test plan consists of three phases:

  1. Functional tests and a vulnerability assessment by the vendor, usually performed during development;
  2. A review of development processes and security design by the grid operator, usually performed during selection;
  3. A penetration test by an external lab, usually performed after the RTU has been selected.