Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Confidentiality Levels #35

Open
ERelAlg opened this issue May 3, 2023 · 0 comments
Open

Confidentiality Levels #35

ERelAlg opened this issue May 3, 2023 · 0 comments

Comments

@ERelAlg
Copy link

ERelAlg commented May 3, 2023

After a meeting with Rado (from OPDE) and Semir (OPC/STA).

Context:

  • OPDE

    • "OPDE Confidential" and "OPDE Secrets" are the current confidentiality levels.
    • These levels are defined after the security controls used to share the data. It is a non-trivial definition and they cannot provide it.
    • Four new levels will be used next year: "Normal", "High", "Very High" and "OPDE Confidential". The first three ones are taken from the GSP and the fourth is an edit of the "Very High" level.
  • OPC/STA

    • "OPC/STA Confidential" is the only level that is used.
    • In principle, once the new definitions for OPDE are put in place and if it is ok for the OPDE team, we should be able to assimilate "OPC/STA Confidential" as "OPDE Very High".

Tasks for Eduardo:

  • Speak with Daiga from ICT Solutions and obtain the new definitions of the confidentiality levels
  • For now, we could include in the reference data the definition provided by Semir for "OPDE Confidential".
  • Once I have the four levels, I will make OPC/STA Confidential == OPDE Very High

"OPDE Confidential" (by Semir): "Information/data which if disclosed to or modified by unauthorized persons, or subject to unplanned unavailability would cause either: substantial financial loss or substantial damage to the reputation or embarrassment to ENTSO-E; inability to deliver a critical service to the TSO community resulting in a loss of confidence; the breaking of any legal, regulatory or statutory laws or rules which could result in penalties or fines"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant