GS

GRIDSHIELD-ONTARIO v4.1

PASSIVE-FIRSTEVIDENCE ENGINEIESO PUBLIC DATA + LABELLED SAMPLES
SUPPORTS ONLY SPECIFICALLY AUTHORIZED ONTARIO ELECTRICITY-SECTOR ENVIRONMENTS — NOT A GRID-CONTROL SYSTEM — HUMAN AUTHORIZED DECISIONS ONLY
UTC
--
DEMAND
--
THREAT
NOT ASSESSED
READ-ONLY - NO CONTROL PATH
PURDUE REFERENCE MODEL - VALIDATE SITE BY SITE SAMPLE POSTURE
Do not assume posture from level alone - Minimize exposed connectivity - Enforce approved conduits
L0 Physical Process - Turbines/BreakersSECURE - AIR-GAP EVALUATED
L1 Basic Control PLC/RTUALLOWLIST + CONDUIT - LEGACY COMPENSATED
L2 Area Supervisory SCADA/DCSESP ENFORCED 27
L3 Site Ops Historian/HMINAMED ACCTS + JUMP
L3.5 IDMZ DMZ - Broker/Proxy/LoggingEXPLICIT ALLOWLIST - NO DIRECT L3↔L4
L4-L5 Enterprise IT/CloudPHISH-RESISTANT MFA WHERE SUPPORTED
UNIDIRECTIONAL: Evaluate hardware-enforced unidirectional gateways at selected high-consequence boundaries when one-way feasible. Do not require where bidirectional necessary or would reduce safety/reliability/recoverability/vendor supportability.
EASY GRID STATUS - PLAIN LANGUAGE
LOADING
Loading the IESO public data snapshot
PUBLIC IESO REPORT DATA — NOT A CONTROL SIGNAL — shows demand and output only, never whether the grid is stable
ONTARIO DEMAND
--
PUB_Demand
GEN OUTPUT
--
Generators 20 MW+
PRICE
--
Not wired
SUPPLY MIX - EASY
ONTARIO BES MAP - SITUATIONAL AWARENESS ONLY
SAMPLE TOPOLOGY — illustrative sites, lines and statuses, not from IESO or any live source
Hover a site to read its sample record
GREEN LINE ACTIVE
AMBER CONSTRAINED - RECOMMEND REVIEW
RED OUTAGE - REQUIRES CONFIRMATION
MOVING DOTS ARE ANIMATION - NOT MEASURED FLOW
THREAT SURFACE - DETERMINISTIC PROTOCOL INSPECTION - 6ch SIMULATED Heuristic anomaly = LIKELY - NOT labeled as confirmed violation - Show evidence + confidence + competing explanations
COMPLIANCE REPRESENTATION RULE - CORRECTED OCSF v1.1 SAMPLE ROWS - NOT AUDIT EVIDENCE
Must not state compliant, certified, audit-ready, NERC CIP applicable, meets OEB requirements unless scope validated, requirement version identified, evidence reviewed, exceptions documented, qualified human authority approved. OCSF = Ontario Cyber Security Framework v1.1 used by transmitters/distributors to assess/report to OEB.
FrameworkReqEvidenceValidation
IESO DATA-SOURCE POLICY - CORRECTED
Public Reports - reports-public.ieso.ca
May be used only for authorized public-data ingestion, analytics, contextual awareness, reporting. Label: PUBLIC IESO REPORT DATA — NOT A CONTROL SIGNAL. Record identifier, source URL, retrieval timestamp, publication timestamp, file hash, schema/version, freshness. Never use to trigger OT commands, automated containment, load-shedding, protection, dispatch, operational claims.
Confidential Participant - reports.ieso.ca/api/v1.4/files?idp_id=ieso
Access only through duly authorized participant account, approved machine identity, documented owner authorization. Credentials/certificates/secrets only in approved secret-management/HSM-backed systems; never in prompts/logs/code/CI logs/screenshots/tickets. Least privilege, mTLS where specified, cert lifecycle, auditing. Public reports valuable for situational awareness, market/system analysis, analytics, but not authorized real-time control interface and must never drive automated production OT decisions.
DATA SOURCES - WHAT THIS PAGE ACTUALLY READS
SECURITY MONITORING - TIER 0/1 ALERTS SAMPLE - NO SENSOR CONNECTED
EVIDENCE INTEGRITY - SESSION PROVENANCE LOG - SHA-256 CHAIN, UNSIGNED
For every record preserve: Source system & owner, Authorized collection method, Collection UTC, Original timestamp clock-confidence, Schema/version, Integrity metadata, Retention, Chain-of-custody ID, Data classification, Sequence # + prior hash. Digitally sign batch manifests using org-managed keys per HSM policy, reliable time sync, periodic independent verification. SHA-256 = integrity component, not proof of authenticity/completeness/correctness/compliance.
GridShield v4.1 $ MONITOR ANALYZE AUDIT SIMULATE RECOMMEND — NO EXECUTE physical
Dry-run containment plans, approval-ready tickets, notify humans via approved channels. All prod changes require: approved tested runbook, named operational owner + cybersecurity change authority, safety/availability impact, validated prerequisites/scope, maintenance window unless emergency, documented rollback, monitoring/recovery/comms viable, human auth recorded. Break-glass = escalation label, not automated auth.
ModePermittedProhibitedApproval
MonitorPassive evidence, health, baseline, alertingActive scans sensitive OT, command tx, config changesAuthorized scope & data-handling
AnalyzeCorrelation, triage, compliance mapping, threat hypothesis, safe impactDeclaring cause/compromise w/o evidenceHuman review SEV-1/SEV-2
SimulateOffline digital-twin, tabletop, dry-run change plansEstimating physical impact from unvalidated assumptionsEngineering model owner
RecommendContainment options, recovery seq, change ticket, rollbackAutomatic change executionOps & cybersecurity authority
ExecuteOnly external approved control system, pre-approved runbook, authorized boundariesPhysical actuation/prod changes by this promptFormal change approval + logged auth
GridShield-Ontario v4.1 PASSIVE-FIRST — Evidence Engine — Supports only specifically authorized Ontario electricity-sector environments — No NSA/DARPA claims — Human authorized decisions only — SHA-256 integrity component not proof MOST CREDIBLE HIGH-ASSURANCE: Records uncertainty, protects safety, requires verified authority, passive evidence, traceable reversible human accountable