Skip to main content

PNNL

  • About
  • News & Media
  • Careers
  • Events
  • Research
    • Scientific Discovery
      • Biology
        • Chemical Biology
        • Computational Biology
        • Ecosystem Science
        • Human Health
          • Cancer Biology
          • Exposure Science & Pathogen Biology
        • Integrative Omics
          • Advanced Metabolomics
          • Chemical Biology
          • Mass Spectrometry-Based Measurement Technologies
          • Spatial and Single-Cell Proteomics
          • Structural Biology
        • Microbiome Science
          • Biofuels & Bioproducts
          • Human Microbiome
          • Soil Microbiome
          • Synthetic Biology
        • Predictive Phenomics
      • Chemistry
        • Computational Chemistry
        • Chemical Separations
        • Chemical Physics
        • Catalysis
      • Earth & Coastal Sciences
        • Global Change
        • Atmospheric Science
          • Atmospheric Aerosols
          • Human-Earth System Interactions
          • Modeling Earth Systems
        • Coastal Science
        • Ecosystem Science
        • Subsurface Science
        • Terrestrial Aquatics
      • Materials Sciences
        • Materials in Extreme Environments
        • Nondestructive Examination
        • Precision Materials by Design
        • Science of Interfaces
        • Smart Advanced Manufacturing
          • Cold Spray
          • Friction Stir Welding & Processing
          • ShAPE
      • Nuclear & Particle Physics
        • Dark Matter
        • Fusion Energy Science
        • Neutrino Physics
      • Quantum Information Sciences
    • Energy Resiliency
      • Electric Grid Modernization
        • Emergency Response
        • Grid Analytics
          • AGM Program
          • Tools and Capabilities
        • Grid Architecture
        • Grid Cybersecurity
        • Grid Energy Storage
        • Transmission
        • Distribution
      • Energy Efficiency
        • Appliance and Equipment Standards
        • Building Energy Codes
        • Building Technologies
          • Advanced Building Controls
          • Advanced Lighting
          • Building-Grid Integration
        • Commercial Buildings
        • Federal Buildings
          • Federal Performance Optimization
          • Resilience and Security
        • Residential Buildings
          • Building America Solution Center
          • Energy Efficient Technology Integration
          • Home Energy Score
        • Energy Efficient Technology Integration
      • Energy Storage
        • Electrochemical Energy Storage
        • Flexible Loads and Generation
        • Grid Integration, Controls, and Architecture
        • Regulation, Policy, and Valuation
        • Science Supporting Energy Storage
        • Chemical Energy Storage
      • Environmental Management
        • Waste Processing
        • Radiation Measurement
        • Environmental Remediation
      • Fossil Energy
        • Subsurface Energy Systems
        • Advanced Hydrocarbon Conversion
      • Nuclear Energy
        • Fuel Cycle Research
        • Advanced Reactors
        • Reactor Operations
        • Reactor Licensing
        • Nondestructive Examination
      • Renewable Energy
        • Solar Energy
        • Wind Energy
          • Wind Resource Characterization
          • Wildlife and Wind
          • Wind Systems Integration
          • Wind Data Management
          • Distributed Wind
        • Marine Energy
          • Environmental Monitoring for Marine Energy
          • Marine Biofouling and Corrosion
          • Marine Energy Resource Characterization
          • Testing for Marine Energy
          • The Blue Economy
        • Hydropower
          • Environmental Performance of Hydropower
          • Hydropower Cybersecurity and Digitalization
          • Hydropower and the Electric Grid
          • Materials Science for Hydropower
          • Pumped Storage Hydropower
          • Water + Hydropower Planning
        • Grid Integration of Renewable Energy
        • Geothermal Energy
      • Transportation
        • Bioenergy Technologies
          • Algal Biofuels
          • Aviation Biofuels
          • Waste-to-Energy and Products
        • Hydrogen & Fuel Cells
        • Vehicle Technologies
          • Emission Control
          • Energy-Efficient Mobility Systems
          • Lightweight Materials
          • Vehicle Electrification
          • Vehicle Grid Integration
    • National Security
      • Chemical & Biothreat Signatures
        • Contraband Detection
        • Pathogen Science & Detection
        • Explosives Detection
        • Threat-Agnostic Biodefense
      • Cybersecurity
        • Discovery and Insight
        • Proactive Defense
        • Trusted Systems
      • Nuclear Material Science
      • Nuclear Nonproliferation
        • Radiological & Nuclear Detection
        • Nuclear Forensics
        • Ultra-Sensitive Nuclear Measurements
        • Nuclear Explosion Monitoring
        • Global Nuclear & Radiological Security
      • Stakeholder Engagement
        • Disaster Recovery
        • Global Collaborations
        • Legislative and Regulatory Analysis
        • Technical Training
      • Systems Integration & Deployment
        • Additive Manufacturing
        • Deployed Technologies
        • Rapid Prototyping
        • Systems Engineering
      • Threat Analysis
        • Advanced Wireless Security
          • 5G Security
          • RF Signal Detection & Exploitation
        • Border Security
        • Internet of Things
        • Maritime Security
        • Millimeter Wave
        • Mission Risk and Resilience
    • Data Science & Computing
      • Artificial Intelligence
      • Graph and Data Analytics
      • Software Engineering
      • Computational Mathematics & Statistics
      • Future Computing Technologies
        • Adaptive Autonomous Systems
    • Lab Objectives
    • Publications & Reports
    • Featured Research
  • People
    • Inventors
    • Lab Leadership
    • Lab Fellows
    • Staff Accomplishments
  • Partner with PNNL
    • Education
      • Undergraduate Students
      • Graduate Students
      • Post-graduate Students
      • University Faculty
      • University Partnerships
      • K-12 Educators and Students
      • STEM Education
        • STEM Workforce Development
        • STEM Outreach
      • Internships
    • Community
      • Regional Impact
      • Philanthropy
      • Volunteering
    • Industry
      • Why Partner with PNNL
      • Explore Types of Engagement
      • How to Partner with Us
      • Available Technologies
      • Procurement
      • Technology Ombuds
  • Facilities & Centers
    • All Facilities
      • Atmospheric Radiation Measurement User Facility
      • Electricity Infrastructure Operations Center
      • Energy Sciences Center
      • Environmental Molecular Sciences Laboratory
      • Grid Storage Launchpad
      • Institute for Integrated Catalysis
      • Interdiction Technology and Integration Laboratory
      • PNNL Portland Research Center
      • PNNL-Seattle
      • PNNL-Sequim (Marine and Coastal Research)
      • Radiochemical Processing Laboratory
      • Shallow Underground Laboratory

Cybersecurity for Buildings and Operational Technology

  • Tool Suite

Breadcrumb

  1. Home
  2. Projects
  3. Cybersecurity for Buildings and Operational Technology

Facility Cybersecurity Framework Tool Suite

The Facility Cybersecurity Framework (FCF) Tool Suite is designed to help organizations, specifically federal agencies, evaluate and strengthen the cybersecurity of their industrial control systems. The tool seeks to address the growing challenge of operational technology (OT) cybersecurity by focusing on facility-related control systems.

Developed by Pacific Northwest National Laboratory (PNNL) in partnership with the Federal Energy Management Program (FEMP), this suite of tools provides a structured and practical approach for facility teams to identify vulnerabilities or gaps in a building’s OT environment, prioritize improvements, and build stronger cybersecurity practices. The tool suite also includes on-demand, interactive training based on real-world examples aimed at helping users better understand how to apply security controls and policies across a variety of scenarios.

Laws and policies require federal agencies to enhance their cybersecurity posture. This collaboration with FEMP ensures that federal agencies make informed decisions that strengthen mission readiness, reduce operational costs, and enhance the overall performance of federal infrastructure.

Since the introduction of these tools, dozens of federal agencies, organizations, and educational institutions, including the U.S. Department of War, U.S. Department of Veterans Affairs, and U.S. Department of Homeland Security, have leveraged them, establishing their value as a proven resource for enhancing cyber readiness across federal operations.

The suite helps users do the following:

  • Conduct self-assessments of facility-related control systems to find cybersecurity gaps
  • Develop actionable improvement plans for their facilities
  • Train personnel to recognize and mitigate cybersecurity risks in day-to-day operations
  • Support compliance with federal cybersecurity requirements

Explore the FCF Tool Suite to find resources for improving facility-related control system cybersecurity.

Identify Needs

Users start by identifying requirements necessary to protect and manage the facility’s OT effectively.

Management Priorities

The Management Priorities tool helps users identify key OT cybersecurity priorities from facility and site management. This tool guides users in assessing, mitigating, and tracking their facility’s cybersecurity posture over time. This streamlined tool helps users understand where cybersecurity actions and investments can best align with management priorities.

After completing a Management Priorities assessment and FCF Core Assessment, users can leverage an in-built feature to see the difference in maturity indicator level between the two and make management decisions on the basis of the discrepancies as appropriate via the Comparison of Management Priorities and Facility Cybersecurity Framework (FCF) Results tool.

Find Gaps

Users next work to identify cybersecurity gaps and risks within facility operations by assessing existing policies and applying established frameworks to strengthen protection. The tool suite offers several different assessments applicable to specific cybersecurity frameworks or technology types of concern.

  • The Facility Cybersecurity Framework Core Assessment helps users assess their cybersecurity policies and relative maturity against the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) to comply with executive orders.
  • The Risk Management Framework Pre-assessment helps users who need to assess their cybersecurity posture against NIST’s Risk Management Framework (RMF) and maps the results against the CSF to enable the user to leverage other site functionalities.
  • Users can leverage the Comparative Evaluation tool to help evaluate the return on investment from cybersecurity actions and the overall cybersecurity posture improvement.
  • The Facility Cybersecurity Capability Maturity Model (F-C2M2) leverages the Department of Energy’s Cybersecurity Capability Maturity model to help users understand the relative maturity of a user’s organizational cybersecurity policies and posture.
  • The FCF Internet of Things (IoT) is an assessment tool specifically targeting users who want to evaluate their security posture in facilities with IoT devices.
  • Finally, the Facility Cybersecurity Framework Grid-interactive Efficient Buildings (FCF GEB) tool helps users who have grid-interactive, efficient buildings (or smart buildings) evaluate specific controls and policies that may affect their cybersecurity posture.

Understand and Mitigate Gaps

Once gaps have been identified, they are analyzed to determine potential exploitation risks.

  • The Best Practices tool leverages back-end mapping so that after a Core Assessment or RMF Pre-Assessment, users are provided with assessment-specific information about the vulnerabilities, best practices, and threat vectors they should be vigilant about.
  • The Qualitative Risk Assessment (QRA) tool is a risk-informed inventory management tool that can be used by the facility owners and operators to qualitatively annotate and track the vulnerability, impact, and risk pertaining to their OT systems.
  • Architecture Generation (ArcGen) is a visualization tool for users to better understand their OT network and identify secure deployment of new systems in their network. Users can map assets from the QRA into ArcGen to help ensure that assets aren’t stranded or overlooked in network maps.
  • The Mitigation of Externally Exposed Energy Delivery Systems (MEEDS) tool, currently in beta, is a downloadable tool that helps users discover vulnerabilities from OT assets that are inadvertently exposed to the public internet. The tool has over 700 scripted queries that can be used to discover cybersecurity vulnerabilities.

Cybersecurity Training

Cybersecurity is a constantly evolving field. The FCF Tool Suite provides users with the opportunity to enhance their cybersecurity skills and knowledge through interactive, accredited training games that apply real-world scenarios to reinforce policies, best practices, and OT system concepts.

  • The scenario Training Game is based on real-world scenarios, allowing users to explore the process of balancing a variety of investment decisions regarding the implementation of new cybersecurity policies and controls to contain a breach.
  • The Network Defense Training Game responds to user actions to help mimic how an adversary evolves to match user decisions and responses. Users seek to defend the OT network from adaptive cyberattacks by directly configuring the physical network environment and implementing security policies in a turn-based simulated cyberattack.
  • The Network Defense Training Game 3D (Network Defense 3D) is an immersive training game where users are tasked with defending their network against consecutive cyberattacks. Users must survey their network to determine which devices are vulnerable and determine the best countermeasures.

Contact 

Julie Rotondo 
Project Manager 
julia.rotondo@pnnl.gov 
509-372-6577

Chris Bonebrake
Principal Investigator 
christopher.bonebrake@pnnl.gov

PNNL

  • Get in Touch
    • Contact
    • Careers
    • Doing Business
    • Environmental Reports
    • Security & Privacy
    • Vulnerability Disclosure Policy
    • Notice to Applicants
  • Research
    • Scientific Discovery
    • Energy Resiliency
    • National Security
Subscribe to PNNL News
Department of Energy Logo Battelle Logo
Pacific Northwest National Laboratory (PNNL) is managed and operated by Battelle for the Department of Energy
  • YouTube
  • Facebook
  • X (formerly Twitter)
  • Instagram
  • LinkedIn