15.4. Security Capability Expectations¶
To address the risks identified in this threat model, conformant implementations must realize these capabilities within the COE, which serves as the enforcement layer for application behavior, resource governance, and authorized interaction with connected systems while ensuring that operators retain control of the ability to set and enforce policy, protect system integrity, and maintain trust relationships across defined trust boundaries.
The GEISA specification defines the security outcomes that must be achievable, but does not prescribe specific technologies or implementation approaches.
15.4.1. Identity and Authentication¶
Implementations shall support verifiable identity for:
Devices or platforms (e.g., meters, NICs, or other edge hardware), hereafter referred to as the Device/Platform Provider where such identity is supplied by the hardware or platform manufacturer.
Applications and associated software artifacts produced by an Application Publisher (the entity responsible for creating and signing an application or workload).
External systems interacting across trust boundaries.
These identities establish provenance, accountability, and authorization context for software deployment and operation within the COE.
Such identities may represent organizational provenance used to establish trust in software origin and authorization for deployment within the COE.
Identity mechanisms must protect associated credential material from unauthorized extraction, duplication, or misuse and support secure lifecycle management of those credentials.
15.4.3. Integrity Protection¶
Implementations must protect software, configuration, and operational data from unauthorized modification.
15.4.4. Isolation of Workloads¶
The COE shall provide isolation sufficient to prevent privilege escalation or cross-application interference.
15.4.5. Secure Lifecycle Management¶
Implementations must support secure deployment, update, validation, and removal of software throughout the device lifecycle.
15.4.6. Protection of Data¶
Implementations shall protect sensitive data from unauthorized disclosure or manipulation when stored or transmitted across trust boundaries.
15.4.7. Auditability and Visibility¶
The COE shall enable logging and monitoring sufficient to detect unauthorized activity and support operational accountability.
15.4.8. Resilience and Availability¶
Security mechanisms shall support continued safe operation and policy enforcement under degraded connectivity conditions.
These capabilities are intended to enable interoperable yet independently governed deployments across diverse utility environments.