Glossary
103 terms
A
Air gap
A security measure that physically isolates a network, typically OT, from other networks so there is no direct electronic connection between them.
All-hazards approach
Planning for any threat or incident that could endanger life, property, the environment, or public safety, rather than only a narrow set of anticipated scenarios.
Attack surface
The complete set of points where an attacker could try to enter a system, affect it, or extract data from it.
Automatic Generation Control (AGC)
The automated process that continuously adjusts generation to keep supply and demand balanced and frequency within required limits.
B
Balancing authority
The entity responsible for continuously matching electricity supply and demand within its area in real time, and supporting the interconnection's frequency.
Baseload vs. peaker plant
A base load plant runs continuously at essentially constant output; a peaker plant is reserved for hours of highest demand and built to start quickly.
Battery Energy Storage System (BESS)
A grid-connected battery installation that stores electricity and discharges it back to the grid to balance supply and demand.
Blackstart
Restoring a plant or section of the grid after a total shutdown without relying on external power from the wider grid.
Bulk Electric System (BES)
NERC’s formal definition of the high-voltage backbone of the grid that its mandatory reliability and security standards apply to.
C
Capacity factor
The ratio of the energy a generating unit actually produced to what it could have produced running at full capacity the whole period.
Capacity vs. generation
Capacity is the maximum output equipment can produce; generation is the electric energy it actually produced over a period of time.
Cascading failure
A failure in one system that triggers failures in the systems depending on it, amplifying a disruption well beyond its original scope.
CIRCIA reporting rule
The regulation CISA must finalize to put CIRCIA’s reporting requirements into force, defining which entities and incidents are covered.
Circuit breaker
A switching device that automatically interrupts current flow on a fault or overload, keeping a local problem from spreading.
CVE (Common Vulnerabilities and Exposures)
A unique identifier assigned to a specific, publicly known software or hardware vulnerability so everyone can refer to the same flaw consistently.
Control area (superseded term)
The earlier term for what NERC now formally defines as a balancing authority; superseded in 2019 but still used casually.
Critical infrastructure
Systems and assets, physical or virtual, so vital that their incapacity or destruction would debilitate national security, the economy, public health, or public safety.
Critical infrastructure protection
The general discipline of identifying, prioritizing, and safeguarding critical infrastructure assets against the full range of threats they face.
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
A 2022 U.S. law that will require covered entities to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.
D
DDoS (Distributed Denial of Service)
An attack that prevents authorized use of a system by overwhelming it with traffic from many coordinated sources at once.
Defense in depth
Layering multiple different protections across people, process, and technology rather than relying on any single control.
DCS (Distributed Control System)
A control system whose intelligence is distributed physically around the process, typically within a single compact facility rather than across a wide area.
Distributed Energy Resources (DER)
Generation or storage connected to the local distribution system rather than the high-voltage bulk power system, including resources behind a customer’s meter.
E
Electrification
Converting a device, system, or sector that runs on a non-electric energy source to run on electricity instead.
Encryption
Transforming data into an unreadable form so it can only be read by someone holding the correct key.
Energy conversion efficiency
The proportion of input energy a system successfully converts into useful output energy, with the rest typically lost as waste heat.
Energy Management System (EMS)
The control-room software platform grid operators use to monitor and optimize generation and delivery in real time, layered above SCADA.
Energy mix / generation mix
The proportion of different sources that make up a country, region, or utility’s total energy supply or electricity generation.
Energy security
The ability to reliably access needed energy at affordable prices, without disruption from supply shocks, instability, or infrastructure failure.
Energy sources: fossil fuels, nuclear, and renewables
The primary energy sources used to generate electricity fall into three broad categories: fossil fuels, nuclear, and renewables.
Energy transition
The ongoing, large-scale shift in how energy is produced and consumed, most often describing the move away from fossil fuels toward lower-carbon sources.
Energy vs. power
Energy is the capacity to do work (an amount); power is the rate at which energy is produced, transferred, or used.
Engineering workstation (EWS)
The computer engineers use to program and configure ICS devices, and a high-value target because it can push logic directly to field devices.
EU AI Act (Annex III, high-risk classification)
The EU’s AI regulation, whose Annex III explicitly classifies AI used as a safety component in critical infrastructure as high-risk.
F
FERC (Federal Energy Regulatory Commission)
The independent U.S. federal agency that regulates interstate transmission of electricity, natural gas, and oil, and that certified NERC as the Electric Reliability Organization.
Feeder (distribution feeder)
An electrical line running from a distribution substation out to the homes and businesses it serves.
Firewall
A device or program that allows or blocks network traffic between networks with different levels of trust, based on defined rules.
G
Generation, transmission, distribution
The three stages electricity moves through: produced at plants, carried in bulk at high voltage, then delivered locally at lower voltage.
Grid frequency (60 Hz in North America) / frequency regulation
The alternating-current frequency every generator must stay synchronized to, held steady by continuously balancing generation against demand.
I
IEC 62443
An international standard series for securing industrial automation and control systems across their entire lifecycle.
Incident response
The process of detecting, containing, remediating, and recovering from violations of security policy.
Incident response (OT/ICS context)
Detecting, containing, and recovering from a security incident where the usual IT instinct to isolate or shut down a system can itself be dangerous.
Independent System Operator (ISO) / Regional Transmission Organization (RTO)
Independent, federally regulated entities that coordinate regional transmission and run day-to-day wholesale electricity markets and grid operations.
ICS (Industrial Control System)
The umbrella term for the systems that control industrial processes and physical equipment, including SCADA, PLCs, and RTUs.
IT (Information Technology)
The computing, networking, and software systems used to store, process, and move an organization's data.
Insider threat
The risk that someone with authorized access uses it to cause harm, intentionally or through negligence.
Interconnection (Eastern, Western, ERCOT, Quebec)
North America's power grid is divided into separate synchronous interconnections that operate largely independently, linked only by limited DC ties.
Interdependency / cross-sector dependency
A dependency runs one way between two infrastructures; an interdependency runs both ways, and both are what make cascading failure possible.
Inverter-based resource (IBR)
A resource such as solar, some wind, or battery storage that connects to the grid through power electronics rather than a spinning generator.
Investor-owned utility (IOU) vs. municipal utility vs. rural electric cooperative
The three ownership categories U.S. electric utilities generally fall into: private for-profit, city-owned, and member-owned.
Islanding
When a section of the grid disconnects from the main grid and keeps operating on its own local generation and storage.
IT/OT convergence
The trend of connecting operational technology systems that control physical processes with information technology systems that handle data.
L
Least privilege / privilege escalation
Granting only the minimum access necessary to do a job; privilege escalation is an attacker gaining access beyond what was granted.
Lifeline sectors (energy, water, transportation, communications)
The four sectors — energy, water, transportation, and communications — that the other 12 most directly depend on to function at all.
M
Malware
Software or firmware intended to carry out an unauthorized action that harms the confidentiality, integrity, or availability of a system.
Microgrid
A group of interconnected loads and local energy sources within defined boundaries that can act as a single controllable unit, connected to the grid or independent of it.
MITRE ATT&CK for ICS
A public knowledge base cataloging the tactics and techniques attackers have actually used against industrial control systems.
Multi-factor authentication (MFA)
Verifying identity with two or more different types of evidence rather than relying on a password alone.
N
NERC CIP (Critical Infrastructure Protection standards)
A family of mandatory, federally enforceable cybersecurity and physical security standards for the Bulk Electric System in North America.
NERC Reliability Standards (general concept)
The broader family of mandatory requirements defining how the North American bulk power system must be planned and operated to stay reliable, of which NERC CIP is one security-focused category.
Network segmentation
Dividing a network into separate, controlled sections so a compromise in one does not automatically give an attacker access to everything else.
NIST Cybersecurity Framework (CSF)
A voluntary framework organizing cybersecurity risk management around six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
NIST SP 800-82 (Guide to ICS/OT Security)
The dedicated federal guide to securing industrial control systems and operational technology, retitled in Revision 3 from "ICS Security" to "OT Security."
NERC (North American Electric Reliability Corporation)
The not-for-profit regulatory authority, certified by FERC as the Electric Reliability Organization, responsible for mandatory reliability standards across the North American bulk power system.
P
Patch
A piece of code released to fix an identified problem, security flaw, or bug in existing software.
Peak load / load forecasting
Peak load is the maximum demand recorded in a given period; load forecasting is predicting future demand so operators can plan for it.
Phasor Measurement Unit (PMU) / synchrophasor
A device taking highly precise, time-synchronized voltage and current measurements many times per second, revealing the grid’s dynamic behavior in near real time.
Phishing / social engineering
Social engineering tricks someone into compromising security; phishing is its most common technique, an impersonating email or website.
Presidential Policy Directive 21 (PPD-21)
The 2013 presidential directive that established the U.S. critical infrastructure policy framework and designated the 16 sectors.
Primary energy vs. secondary energy
Primary energy is energy in the form it is first accounted for; electricity is a secondary energy carrier produced by converting something else.
PLC (Programmable Logic Controller)
A ruggedized, purpose-built industrial computer that runs the logic controlling a specific piece of physical equipment.
Protective relay / relay protection
A device that monitors electrical conditions and automatically trips a circuit breaker when it detects a dangerous condition such as a short circuit.
Public-private partnership
Because private companies own and operate most U.S. critical infrastructure, protecting it depends on government-industry partnership rather than direct government control.
Purdue Model (Purdue Enterprise Reference Architecture)
A reference architecture that organizes an industrial network into layered zones, from field devices at the bottom to enterprise IT at the top.
R
Ransomware
Malicious software that encrypts data or systems and demands payment, often forcing OT operators to halt physical operations as a precaution.
RTU (Remote Terminal Unit)
A field device that collects data from sensors at a remote site and communicates it back to a central SCADA system.
Renewable / variable generation integration
Keeping supply and demand balanced as weather-dependent sources like solar and wind make up a growing share of generation.
Renewable vs. non-renewable energy
A distinction about whether a resource naturally replenishes on a human timescale, not directly about emissions.
Resilience vs. reliability vs. security
Three commonly conflated properties: reliability is withstanding instability, resilience is recovering from disruption, and security is withstanding deliberate attack.
S
Safety Instrumented System (SIS)
An independent control system designed to detect hazardous conditions and automatically bring a process to a safe state.
Sector Risk Management Agency (SRMA)
The federal agency designated as the day-to-day point of contact for one of the 16 critical infrastructure sectors.
SIEM (Security Information and Event Management)
A platform that centralizes logging and analysis across an organization’s systems so analysts can detect activity no single log would reveal.
SOC (Security Operations Center)
The team and facility responsible for continuously monitoring, detecting, and responding to security incidents across an organization.
Single point of failure
A component whose failure alone is enough to take down an entire system, because no redundant path exists to route around it.
Substation
A facility where equipment switches, changes, or regulates electric voltage, connecting the generation, transmission, and distribution stages.
SCADA (Supervisory Control and Data Acquisition)
A category of control system software that monitors and manages industrial processes across a wide geographic area.
Supply chain attack
Compromising a target indirectly, through a vendor, manufacturer, or contractor in its supply network, rather than attacking it head-on.
Synchronous generator
A traditional spinning power plant generator locked in step with grid frequency, providing rotational inertia that helps stabilize the grid.
T
The 16 CISA critical infrastructure sectors
The 16 sectors designated under PPD-21, each with a federal agency responsible for coordinating with that sector’s owners and operators.
Threat actor / Advanced Persistent Threat (APT)
A threat actor is anyone responsible for a security incident; an APT is a well-resourced actor that pursues objectives persistently and adapts around defenses.
Transformer
An electrical device that changes the voltage of alternating current, stepping it up for transmission or down for local use.
Transmission owner / generation owner
The formally defined NERC roles for the entities that own and maintain transmission and generating facilities, distinct from the operators that coordinate the system.
V
Voltage regulation
Keeping voltage within an acceptable range as it moves through the grid, since equipment can fail or be damaged if voltage drifts too far.
Vulnerability management
The ongoing process of identifying, assessing, and addressing known weaknesses before an attacker can exploit them — substantially harder in OT than in IT.
Vulnerability vs. exploit
The vulnerability is the open door; the exploit is what an attacker uses to walk through it.
W
Z
Zero trust architecture
A security approach where no user, device, or system is trusted by default and every request is verified individually, regardless of network location.
Zero-day vulnerability
A flaw unknown to the vendor with no available fix at the time it is discovered or exploited — the vendor has had zero days to prepare a patch.
Zone and conduit model
An IEC 62443 concept that groups OT assets into zones with shared security requirements, connected by conduits with a consistent security policy.