HomeCybersecurityM03324Evidence
Topic/Matter Intersection

Topic:"Cybersecurity" in M03324

Matter: E-NERC-R-10 - North American Electric Reliability Corporation - Reliability Standards; and Northeast Power Coordinating Council, Inc. - Regional Reliability Criteria
171 passages 11 documents

Cybersecurity across all matters →

N-1Notice of Filing of Amendments to the Bylaws 6/29/2010 1 passage
ARTICLE I Definitions
ntrolled separation, or cascading failures of the bulk power system will not occur as a result of a sudden disturbance, including a cybersecurity incident, or unanticipated failure of system elements. "Sector" means a group of members of t...

AI summary The text defines key terms related to the bulk power system, including 'Sector' and reliability standards. It emphasizes cybersecurity and system reliability, referencing the Federal Power Act and technical definitions from regulatory frameworks.

N-2Informational Filing of 2010 Development Plan Pursuant to Section 310 of the NERC Rules of Procedure 6/29/2010 1 passage
iii. Project Timeline Changes
schedule. These combined activities have resulted in an approximate nine month extension to the project. The anticipated completion date of the project is now scheduled for the third quarter of 2012. 2008-02 Undervoltage Load Shedding. No...

AI summary The project timeline has been extended by nine months, with completion now in Q3 2012. The 2008-02 project timeline remains unchanged. The 2008-06 Cyber Security project, initiated under FERC Order 706, involves multiple phases of revising CIP Reliability Standards, with FERC approving Version 2 in September 2009 and directing further modifications.

N-3Notice of Filing of Revised Pro Forma Delegation Agreement, Relevant Revised Delegation Agreement, and Amendments to the NERC Rules of Procedure 6/29/2010 1 passage
5. Amendments to Section 1000 – Situation Awareness and Infrastructure Security
5. Amendments to Section 1000 – Situation Awareness and Infrastructure Security The only amendment to §1000 is in §1003.2.5, to change the reference to "Cyber Security Standard" to "Cyber Security Standards." This revision is appropriate t...

AI summary The amendment to Section 1000 involves updating §1003.2.5 to refer to 'Cyber Security Standards' instead of 'Cyber Security Standard,' acknowledging the nine active Critical Infrastructure Protection standards.

N-7Notice of Filing of NERC's 2010 Business Plan and Budget and the 2010 Business Plans and Budgets of Regional Entities and the Proposed Assessments to Fund Budgets 6/29/2010 5 passages
B. Regional Entity Proposed 2010 Budgets p. p. 0
to adequately carry out the functions delegated to the Regional Entity under the delegation agreement, (2) verifying that the Regional Entity was using the common budgeting assumptions, common budget 34 However, as discussed below, followi...

AI summary The text discusses the submission of 2010 Business Plans and Budgets by Regional Entities to NERC, emphasizing common budgeting assumptions and revised plans to address resources for processing CIP standard exceptions. NERC reviewed and approved these plans, confirming adequacy for delegated functions.

5. Situation Awareness and Infrastructure Security p. p. 0
5. Situation Awareness and Infrastructure Security NERC's Situation Awareness and Infrastructure Security Program coordinates all of NERC's efforts to improve physical and cyber security for the North American bulk power system as it relat...

AI summary NERC's Situation Awareness and Infrastructure Security Program enhances physical and cyber security for the North American bulk power system through standards, compliance, risk assessments, and real-time monitoring. It oversees the ES-ISAC, established in 1999, and the ESSG created in 2008 to guide infrastructure security efforts.

6. Administrative Services p. p. 0
e General Counsel, four other attorneys, one paralegal and one administrative assistant). The Legal and Regulatory budget also includes the expense for NERC's retained Canadian affairs representative. IT – NERC's IT program supports employ...

AI summary The text outlines NERC's 2010 IT program budget, including a $2.5 million allocation with a 7.75 FTE workforce. Key initiatives involve deploying secure file systems for compliance and CIP programs, and implementing a SharePoint-based knowledge management system. The budget reflects increased capital expenditures for IT infrastructure and software.

3. NPCC p. p. 0
3. NPCC NPCC's statutory budget for 2010 is $11,354,085, an increase of $1,345,200 over its 2009 Budget. NPCC plans total staffing for statutory and administrative programs of 27.41 FTEs, an increase of 4.01 FTEs over its 2009 Budget. 78 N...

AI summary NPCC's 2010 statutory budget increased by $1.35M (12.8%) to $11.35M, reflecting a 14.7% rise in FTEs (from 23.4 to 27.41) to support expanded compliance activities, including CIP standard audits, compliance violation investigations, and registry maintenance. Consultant/contract resources for compliance programs also increased significantly.

IX. UPDATE ON RELIABILITY ENHANCEMENT PROGRAMS p. p. 0
IX. UPDATE ON RELIABILITY ENHANCEMENT PROGRAMS In the 2009 Budget Order , FERC stated: The Commission understands that many aspects of the implementation of the Energy Policy Act of 2005 are still in a state of evolution and that, because...

AI summary FERC acknowledged NERC's 2008 reliability enhancement filing but emphasized the need for more developed programs and funding in NERC's 2010 Business Plan. The 2009 Budget Order highlighted ongoing obligations to address cybersecurity standards and resource adequacy, requiring staged development with measurable goals.

N-8NERC's Three-Year Electric Reliability Organization Performance Assessment Report 6/29/2010 6 passages
Preamble p. p. 0
1 Under 18 C.F.R. §39.3, after receipt of this assessment report, the Commission is to establish a proceeding, with opportunity for public comment, in which it will review the ERO's performance. Is reliability as good as it needs to be? No...

AI summary The Commission is required to establish a proceeding to review the ERO's performance under 18 C.F.R. §39.3. Reliability is deemed insufficient, requiring legislative action on cybersecurity emergency authority, improved standards development, and enhanced delegation agreements with Regional Entities. NERC and stakeholders have fulfilled Congressional objectives under the Federal Power Act §215.

E. NERC Has Developed an Effective Program for Disseminating Alerts on Potential Reliability Issues to Owners, Operators and Users of the Bulk Power System p. p. 30
em (NSANS) that will enable rapid alert creation and dissemination to the electric industry as well as provide for quick acknowledgement and response from the industry via a secure Web browser portal. As of May 31, 2009, NERC has issued a...

AI summary NERC's NSANS system enables rapid alert creation and dissemination for reliability issues, with 21 advisories and 4 recommendations issued by May 2009. Key topics included cybersecurity vulnerabilities and equipment malfunctions. No essential actions were issued, focusing instead on advisory measures.

Issues Identified by Stakeholders Concerning the Industry Alerts Program p. p. 30
Issues Identified by Stakeholders Concerning the Industry Alerts Program Commenters' concerns focused on the inordinately large number of cyber-related alerts, which commenters noted may cause a diminished perception of the importance of t...

AI summary Stakeholders raised concerns about the Industry Alerts Program, citing an excessive number of cyber-related alerts leading to decreased alert importance perception, insufficient detail and timeliness, a 24-hour acknowledgment requirement, and unclear contact points. NERC's responses are detailed in Attachment 2.

I. NERC is Taking an Industry Leadership Role in Critical Infrastructure Protection p. p. 30
I. NERC is Taking an Industry Leadership Role in Critical Infrastructure Protection Prior to certification as the ERO, NERC played an important role in critical infrastructure protection (CIP) activities for the electric industry, includin...

AI summary NERC, as the ERO, leads CIP efforts for North America's bulk power system. It coordinates the ES-ISAC, established under Presidential Decision Directive 63, and centralized CIP activities under a CSO in 2008. NERC also created a dedicated CIP manager role to enhance infrastructure security and mitigation strategies.

Improvement to the Reliability of the Bulk Power System p. p. 30
Improvement to the Reliability of the Bulk Power System NERC's CIP activities are improving, and will continue to improve, the reliability of the bulk power system. As the CIP standards implementation schedule is completed, the industry's...

AI summary NERC's CIP activities enhance the reliability of the bulk power system by improving compliance with standards, monitoring, and cybersecurity through ES-ISAC. Continued implementation of CIP standards and information sharing reduces risks from cyber attacks and system failures.

Issues Identified by Stakeholders Concerning Critical Infrastructure Protection p. p. 30
Issues Identified by Stakeholders Concerning Critical Infrastructure Protection Stakeholders identified a number of issues and recommendations concerning NERC's CIP activities, including the following: - Direction for implementation of CIP...

AI summary Stakeholders highlighted issues with NERC's CIP activities, including the need for centralized direction, timely guidance, a fast-track process for interpretation requests, and more targeted cybersecurity advisories. NERC's role in infrastructure security via ES-ISAC is noted, with detailed discussion in Attachment 2.

N-9Northeast Power Coordinating Council, Inc. Criteria Filing 6/30/2010 12 passages
Revision History p. p. 110
Revision History Version Date Action Change Tracking (New, Errata or Revisions) Table of Content Title Page 1 Revision History 2 Table of Content 3 1.0 Introduction 4 2.0 Terms Defined in This Directory 5 3.0 NERC ERO Reliability Standard...

AI summary The document outlines the NPCC Directory D3 Maintenance Criteria for Bulk Power System Protection, detailing reliability standards, regional requirements, and testing procedures for power system components and protection systems.

Section 175 p. p. 110
- (1) Non-Self Monitored protection assemblies include electromechanical relays and solid state relays . - (2) Microprocessor-based protection assemblies where the principal fault-sensing and logic components include self monitoring or sel...

AI summary The document outlines testing requirements for protection assemblies and systems, including non-self monitored relays, microprocessor-based relays with self-monitoring, and DC circuit testing for protection groups. It emphasizes verifying the operation of protection equipment and ensuring system reliability.

Preamble p. p. 110
5.5 Breaker Test Tripping Requirements Refer to Figure 1, equipment marked as [4] The ability of the breaker(s) to trip via each trip coil shall be verified every two years. Nuclear plants can complete these tests at an interval not to exc...

AI summary The document outlines requirements for breaker test tripping and telecommunication testing. Breaker tripping via each trip coil must be verified every two years, with nuclear plants allowed up to three years. Telecommunications terminal equipment testing intervals align with protection assemblies as specified in Table 1.

3.1 Definitions for Use in this Guideline Only p. p. 125
3.1 Definitions for Use in this Guideline Only The flowing defined terms are used for illustration of the guideline presented in this Section only. These terms are not defined in Appendix A of this Directory, or any other NPCC documents. I...

AI summary The section defines terms used in the guideline, including IED, PLC, and cybersecurity-related concepts like intrusion and cryptography, emphasizing their role in device functionality and security.

3.2 Governing Principles p. p. 125
3.2 Governing Principles The industry has become more reliant on computer technology for power system protection , control, communications, and automation of its power system. Electromechanical and solid-state technologies are being replac...

AI summary The text discusses the increasing reliance on computer technology in power system protection and control, highlighting vulnerabilities in Intelligent Electronic Devices (IEDs). It emphasizes the need for cybersecurity principles to prevent unauthorized access, monitor assets, and limit exposure to threats that could disrupt service or damage equipment.

3.3.1 Authentication p. p. 125
3.3.1 Authentication One of the foundations of the cyber security program is controlled, or secure, access. This dictates that some form of user authentication be used. Three common means of authenticating a user's identity are: - 3.3.1.1...

AI summary The text outlines authentication methods in cybersecurity, emphasizing multi-factor approaches (knowledge, possession, biometrics) and notes that existing equipment lacks advanced security features like encryption, relying instead on multi-level passwords.

3.3.2 Substation IED Access Point p. p. 125
3.3.2 Substation IED Access Point A list of all substation IEDs that have remote electronic access configured should be compiled and maintained. This list should also include the access method(s) (e.g., dial-in, WAN, etc), the associated p...

AI summary The document mandates compiling and maintaining a list of substation IEDs with remote access configurations, including access methods (e.g., dial-in, WAN), contact details, IP addresses, passwords, and other relevant data to ensure secure and organized management of electronic access points.

3.3.3 Approved Remote Access Authorization List p. p. 125
3.3.3 Approved Remote Access Authorization List A list of approved users, and the station IEDs they are authorized to access, should be established and maintained. It is vital that all such access information be classified as confidential,...

AI summary The document mandates the establishment and maintenance of an approved remote access authorization list for users and station IEDs, emphasizing the classification of access information as confidential.

3.3.4 Remote Access Configuration p. p. 125
3.3.4 Remote Access Configuration Protection system IEDs should be configured to afford remote access only where needed and approved, and then, only when proper authentication is provided.

AI summary The configuration of protection system IEDs (Intelligent Electronic Devices) must restrict remote access to cases where it is necessary and approved, requiring proper authentication to ensure security and control.

3.3.5 Password p. p. 125
3.3.5 Password Most protection system IEDs offer multiple access levels, each with separate passwords. Normally, a "view" only level is provided which allows a user to extract and or view information only. An alternate access level is prov...

AI summary The section discusses password security for protection system IEDs, emphasizing multi-tiered access levels, changing default passwords, and using strong, complex passwords to prevent unauthorized access and potential damage to the power system.

3.3.6 Logging/Alarming p. p. 125
3.3.6 Logging/Alarming When remote connections are used to access the relay beyond "view-only" mode, this should be alarmed and/or logged where possible.

AI summary The text mandates that remote access to relays beyond 'view-only' mode must be logged and/or alarmed to ensure security and monitoring. This requirement emphasizes the importance of tracking unauthorized or elevated access attempts to maintain system integrity.

3.3.7 Controlling Authority Approval p. p. 125
3.3.7 Controlling Authority Approval For both local and remote communications, excluding viewing, notification and approval of the Controlling Authority should be required to access in-service protection system IEDs. Only authorized users,...

AI summary The document mandates Controlling Authority approval for accessing in-service protection system IEDs, restricts remote access to authorized users, and emphasizes disabling unused IED functions to mitigate vulnerabilities. Additional security measures include implementing VPNs, limiting public network use, callback systems, and hardware dongles for dial-up access.

N-10Reliability Standards of the North American Electric Reliability Corporation 7/5/2010 69 passages
B. Overview of Reliability Standards p. p. 5
B. Overview of Reliability Standards NERC Reliability Standards define the requirements for reliably planning and operating the North American bulk power system. These standards are developed by industry stakeholders using a balanced, open...

AI summary NERC Reliability Standards outline requirements for the North American bulk power system's planning and operation, developed through an inclusive process by industry stakeholders. The standards cover real-time balancing, equipment limits, contingency management, vegetation control, critical infrastructure protection, and emergency planning, ensuring system reliability and safety.

C. Detailed Description of Proposed Reliability Standards p. p. 5
C. Detailed Description of Proposed Reliability Standards The Reliability Standards presented in Exhibits C and E are grouped by topical area, as summarized below. Resource and Demand Balancing (BAL) ⎯ balancing resources and demand to mai...

AI summary The document outlines proposed reliability standards grouped into 13 topical areas, including resource balancing, cybersecurity, emergency operations, and transmission planning. It references NERC's glossary and Exhibit B, which details each standard's purpose, approval percentages, and changes. The standards aim to ensure grid reliability through coordinated operations, infrastructure protection, and compliance with NERC and FERC guidelines.

Applicability: p. p. 24
Applicability: • Balancing Authorities On October 29, 2008, BAL-006-1.1 was approved by the NERC Board of Trustees. On May 13, 2009, BAL-006-1.1 was approved by the Federal Energy Regulatory Commission. Version BAL-006-1.1 resulted from er...

AI summary The text outlines the approval history of BAL-006-1.1 by NERC and FERC, noting its derivation from errata changes. It also introduces CIP-001-1, a standard requiring sabotage-related disturbances to be reported to relevant authorities.

Applicability: p. p. 24
Applicability: - Reliability Coordinators - Balancing Authorities - Transmission Operators - Generator Operators - Load Serving Entities On October 29, 2006, CIP-001-1 was approved by the registered ballot body by a 69.48% affirmative vote...

AI summary The document outlines the approval process of CIP-001-1 and CIP-002-2 standards by NERC, FERC, and the registered ballot body, emphasizing their role in cybersecurity for the Bulk Electric System. CIP-002-2 mandates risk-based identification of critical cyber assets to ensure reliability.

1.4. Additional Compliance Information p. p. 131
1.4. Additional Compliance Information Reportable Disturbances – Reportable Disturbances are contingencies that are greater than or equal to 80% of the most severe single Contingency. A Regional Reliability Organization, sub-Regional Relia...

AI summary The section defines reportable disturbances as contingencies exceeding 80% of the most severe single contingency, outlines handling of simultaneous contingencies, and specifies evaluation procedures for multiple contingencies during recovery periods. Compliance is managed by Balancing Authorities and Reserve Sharing Groups, with potential waiver requests for inadequacies in contingency reserves.

D. Compliance p. pp. 136-198
D. Compliance

AI summary The document section titled 'Compliance' outlines regulatory requirements and standards relevant to Nova Scotia's utility sector, referencing various reliability, security, and operational protocols governed by entities like NERC, FERC, and NSUARB.

Preamble p. pp. 136-198
1. Title: Sabotage Reporting 2. Number: CIP-001-1 3. Purpose: Disturbances or unusual occurrences, suspected or determined to be caused by sabotage, shall be reported to the appropriate systems, governmental agencies, and regulatory bodies.

AI summary This document outlines the requirement to report disturbances or unusual occurrences suspected or determined to be caused by sabotage to appropriate systems, governmental agencies, and regulatory bodies.

C. Measures p. pp. 136-198
C. Measures - M1. Each Reliability Coordinator, Balancing Authority, Transmission Operator, Generator Operator, and Load Serving Entity shall have and provide upon request a procedure (either electronic or hard copy) as defined in Requirem...

AI summary The document outlines three measures requiring Reliability Coordinators, Balancing Authorities, and other entities to establish procedures for compliance with reliability standards, including communication protocols with FBI/RCMP for sabotage events. These measures aim to ensure operational reliability and security in the electricity sector.

4. Applicability: p. pp. 136-198
4. Applicability: - 4.1. Within the text of Standard CIP-002-2, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tr...

AI summary Section 4 defines 'Responsible Entity' under CIP-002-2, including roles like Reliability Coordinators, Balancing Authorities, and Transmission Owners. Exemptions apply to nuclear-regulated facilities and certain cyber assets. The standard's effective date depends on regulatory approvals or BOT adoption.

B. Requirements p. pp. 136-198
B. Requirements - R1. Critical Asset Identification Method The Responsible Entity shall identify and document a risk-based assessment methodology to use to identify its Critical Assets. - R1.1. The Responsible Entity shall maintain documen...

AI summary The document outlines requirements for identifying critical assets and cyber assets, including annual risk-based assessments, documentation of methodologies, and senior management approval. Critical assets include control centers, transmission substations, generation resources, and systems essential for system restoration and load shedding. Critical cyber assets are defined with specific communication and accessibility criteria.

4. Applicability p. pp. 136-198
4. Applicability - 4.1. Within the text of Standard CIP-005-2, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tra...

AI summary Section 4 defines 'Responsible Entity' under CIP-005-2, including roles like Reliability Coordinators and Balancing Authorities. Exemptions apply to nuclear-regulated facilities and certain cyber assets. The standard becomes effective after regulatory approvals, typically in the third quarter following approval.

1.4. Data Retention p. p. 136
1.4. Data Retention - 1.4.1 The Responsible Entity shall keep logs for a minimum of ninety calendar days, unless: a) longer retention is required pursuant to Standard CIP-008-2, Requirement R2; b) directed by its Compliance Enforcement Aut...

AI summary The Responsible Entity must retain logs for 90 days, except when required by CIP-008-2 R2 or directed by the Compliance Enforcement Authority. Documents under CIP-005-2 from the prior year and audit records must also be retained, with the Compliance Enforcement Authority and Registered Entity jointly managing audit data.

Version History p. p. 136
Version History Version Date Action Change Tracking 1 01/16/06 D.2.3.1 — Change "Critical Assets," to "Critical Cyber Assets" as intended. 03/24/06 2 Modifications to clarify the requirements and to bring the compliance elements into confo...

AI summary This document outlines the version history and updates to the CIP–005–2 standard, focusing on changes to terminology, compliance requirements, and responsible entities related to cyber security and electronic security perimeters.

1.5. Additional Compliance Information p. pp. 136-198
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not make exceptions in its cyber security policy to the creation, documentation, or maintenance of a physical security plan. - 1.5.2 For dial-up accessible Critical...

AI summary The Responsible Entity must adhere to strict cyber security policies without exceptions for physical security plans. However, dial-up accessible Critical Cyber Assets using non-routable protocols are exempt from CIP-006-2 compliance for that specific access point.

Version History p. p. 136
Version History Version Date Action Change Tracking 2 Modifications to remove extraneous information from the requirements, improve readability, and to bring the compliance elements into conformance with the latest guidelines for developin...

AI summary This document outlines the version history of a compliance standard, detailing modifications to improve clarity, readability, and alignment with the latest guidelines. Key changes include the replacement of the RRO with RE as the responsible entity, updates to CIP-006-1 and CIP-006-2 requirements, and the reorganization of compliance monitoring roles.

B. Requirements p. p. 136
B. Requirements - R1. Test Procedures The Responsible Entity shall ensure that new Cyber Assets and significant changes to existing Cyber Assets within the Electronic Security Perimeter do not adversely affect existing cyber security contr...

AI summary The Responsible Entity must implement test procedures to ensure new or modified cyber assets within the Electronic Security Perimeter do not compromise existing security controls, as mandated by CIP-007-2. Procedures must minimize operational disruptions.

C. Measures p. p. 136
C. Measures - M1. The Responsible Entity shall make available documentation of its security test procedures as specified in Requirement R1. - M2. The Responsible Entity shall make available documentation as specified in Requirement R2. - M...

AI summary The Responsible Entity must provide documentation for various cybersecurity programs, including security testing, patch management, malware prevention, account management, and vulnerability assessments, as outlined in requirements R1 through R9.

Standard CIP–007–2a — Cyber Security — Systems Security Management p. p. 136
Standard CIP–007–2a — Cyber Security — Systems Security Management processes, and procedures for securing Cyber Assets and other (non-Critical) Assets within an Electronic Security Perimeter. Replaced the RRO with the RE as a responsible e...

AI summary The document outlines changes and updates to the CIP-007-2a standard related to cyber security and systems security management, including the replacement of the RRO with the RE as a responsible entity, changes to compliance timelines, and the addition of appendices with interpretations approved by regulatory bodies.

Requirement Number and Text of Requirement p. p. 136
Requirement Number and Text of Requirement R2. The Responsible Entity shall establish and document a process to ensure that only those ports and services required for normal and emergency operations are enabled.

AI summary Requirement R2 mandates the Responsible Entity to create and document a process ensuring only essential ports and services for normal and emergency operations are enabled, aligning with cybersecurity standards for electronic security perimeters.

Response p. p. 136
Response The drafting team interprets the term "ports" used as part of the phrase "ports and services" to refer to logical ports, e.g., Transmission Control Protocol (TCP) ports, where interface with communication services occurs.

AI summary The drafting team interprets 'ports' in 'ports and services' as logical ports (e.g., TCP ports) where communication services interface, clarifying technical terminology in the context of regulatory proceedings.

A. Introduction p. p. 136
A. Introduction 1. Title: Cyber Security — Incident Reporting and Response Planning 2. Number: CIP-008-2 3. Purpose: Standard CIP-008-2 ensures the identification, classification, response, and reporting of Cyber Security Incidents related...

AI summary This document introduces CIP-008-2, a standard focused on ensuring the identification, classification, response, and reporting of cyber security incidents related to critical cyber assets. It emphasizes integration with other CIP standards (CIP-002-2 to CIP-009-2) for comprehensive cyber security management.

4. Applicability p. p. 136
4. Applicability - 4.1. Within the text of Standard CIP-008-2, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tra...

AI summary Defines 'Responsible Entity' under CIP-008-2, including roles like Reliability Coordinators and Balancing Authorities. Exemptions include nuclear-regulated facilities and certain cyber assets. The standard becomes effective after regulatory approvals or BOT adoption in jurisdictions without such requirements.

B. Requirements p. p. 136
B. Requirements - R1. Cyber Security Incident Response Plan The Responsible Entity shall develop and maintain a Cyber Security Incident response plan and implement the plan in response to Cyber Security Incidents. The Cyber Security Incide...

AI summary The Responsible Entity must develop and maintain a Cyber Security Incident response plan, including procedures for incident classification, response actions, ES-ISAC reporting, annual reviews, and testing. Documentation of incidents must be retained for three years.

1.4. Data Retention p. p. 136
1.4. Data Retention - 1.4.1 The Responsible Entity shall keep documentation other than that required for reportable Cyber Security Incidents as specified in Standard CIP-008-2 for the previous full calendar year unless directed by its Comp...

AI summary The Responsible Entity must retain cybersecurity incident documentation for the previous calendar year unless extended by the Compliance Enforcement Authority. Audit records, including those from the Registered Entity, must be maintained by the Compliance Enforcement Authority.

1.5. Additional Compliance Information p. pp. 136-198
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not take exception in its cyber security policies to the creation of a Cyber Security Incident response plan. - 1.5.2 The Responsible Entity may not take exception i...

AI summary The Responsible Entity must comply with mandatory cyber security policies requiring a Cyber Security Incident response plan and reporting incidents to ES ISAC. Violation Severity Levels are noted as pending development.

1.4. Additional Compliance Information p. p. 136
1.4. Additional Compliance Information Attachment 1-COM-001— NERCnet Security Policy - 2. Levels of Non-Compliance for Transmission Operator, Balancing Authority or Reliability Coordinator - 2.1. Level 1: Not applicable. - 2.2. Level 2: No...

AI summary The document outlines non-compliance levels for Transmission Operators, Balancing Authorities, and Reliability Coordinators under the NERCnet Security Policy. Level 3 violations include using non-English language without agreement and lacking written procedures for telecommunication outages. Level 4 violations involve failing to actively monitor, test, manage, or alarm telecommunication systems.

3. Levels of Non-Compliance — NERCnet User Organization p. p. 136
3. Levels of Non-Compliance — NERCnet User Organization - 3.1. Level 1: Not applicable. - 3.2. Level 2: Not applicable. - 3.3. Level 3: Not applicable. - 3.4. Level 4: Did not adhere to the requirements in Attachment 1-COM-001, NERCnet Sec...

AI summary The document outlines non-compliance levels for NERCnet, with Level 4 indicating failure to adhere to the NERCnet Security Policy in Attachment 1-COM-001.

Attachment 1-COM-001— NERCnet Security Policy p. p. 136
Attachment 1-COM-001— NERCnet Security Policy

AI summary This document outlines the NERCnet Security Policy, focusing on cybersecurity measures for critical infrastructure. It references CIP standards (e.g., CIP-004-2, CIP-005-2) and regulatory bodies like NERC, FERC, and NSUARB, emphasizing compliance with electronic and physical security protocols.

Policy Statement p. p. 136
Policy Statement The purpose of this NERCnet Security Policy is to establish responsibilities and minimum requirements for the protection of information assets, computer systems and facilities of NERC and other users of the NERC frame rela...

AI summary The NERCnet Security Policy establishes requirements to protect NERC's information assets and ensure secure connectivity on the NERC frame relay network. It mandates cost-effective protection measures and proper handling of information by users to enable NERC to fulfill its mission.

NERC's Security Mission Statement p. p. 136
NERC's Security Mission Statement NERC recognizes its dependency on data, information, and the computer systems used to facilitate effective operation of its business and fulfillment of its mission. NERC also recognizes the value of the in...

AI summary NERC emphasizes the critical importance of securing data, information, and computer systems to ensure operational effectiveness and mission fulfillment. It highlights the need to protect these assets from threats such as destruction, unauthorized access, and confidentiality breaches.

NERCnet User Organizations p. p. 136
NERCnet User Organizations Users of NERCnet who have received authorization from NERC to access the NERC network are considered users of NERCnet resources. To be granted access, users shall complete a User Application Form and submit this...

AI summary Users of NERCnet must obtain authorization from NERC to access resources, requiring completion and submission of a User Application Form to the NERC Telecommunications Manager.

Responsibilities p. p. 136
Responsibilities It is the responsibility of NERCnet User Organizations to: - Use NERCnet facilities for NERC-authorized business purposes only. - Comply with the NERCnet security policies, standards, and guidelines, as well as any procedu...

AI summary NERCnet User Organizations are responsible for using NERCnet facilities only for authorized purposes, complying with security policies, protecting data confidentiality, managing user access, and conducting self-assessments for compliance with NERC standards.

User Accountability and Compliance p. p. 136
User Accountability and Compliance All users of NERCnet shall be familiar and ensure compliance with the policies in this document. Violations of the NERCnet Security Policy shall include, but not be limited to any act that: - Exposes NERC...

AI summary The document outlines user accountability and compliance requirements for NERCnet, emphasizing adherence to security policies to prevent data breaches, unauthorized use, and illicit activities. Violations include exposing NERC to financial loss or compromising confidential information. The policy was adopted by the Board of Trustees on October 29, 2008.

Attachment 1-EOP-002-2.1 Energy Emergency Alerts p. p. 136
Attachment 1-EOP-002-2.1 Energy Emergency Alerts

AI summary This attachment outlines the Energy Emergency Alerts framework under EOP-002-2.1, part of Nova Scotia's regulatory process for ensuring grid reliability during emergencies. It references standards for emergency operations planning and cyber security protocols relevant to critical infrastructure protection.

Attachment 1-EOP-004 NERC Disturbance Report Form p. p. 136
Attachment 1-EOP-004 NERC Disturbance Report Form

AI summary This document is an attachment to a regulatory proceeding in Nova Scotia, specifically the NERC Disturbance Report Form (EOP-004), which relates to cybersecurity and reliability standards for the electric grid.

Introduction p. p. 136
curity system. Actual or suspected cyber or communications attacks that could impact electric power system adequacy or vulnerability. Adopted by Board of Trustees: November 1, 2006 Page 10 of 13 - 6. Actual or suspected cyber or communicat...

AI summary The document outlines procedures for reporting emergency incidents and disturbances related to the electric power system, including cyber or communications attacks, fuel supply emergencies, and service outages. It specifies the submission of form OE-417 to the DOE Operations Center within 60 minutes and an updated version within 48 hours.

Adopted by Board of Trustees: November 1, 2006 Page 11 of 13 p. p. 136
Adopted by Board of Trustees: November 1, 2006 Page 11 of 13 Table 1-EOP-004-0 Summary of NERC and DOE Reporting Requirements for Major Electric System Emergencies Incident No. Incident Threshold Report Required Time 1 Uncontrolled loss of...

AI summary This document outlines the NERC and DOE reporting requirements for major electric system emergencies, detailing specific incidents, thresholds, required reports, and timeframes for submission. It includes nine types of incidents with varying thresholds and reporting schedules.

Standard PRC-004-1 — Analysis and Mitigation of Transmission and Generation Protection System Misoperations p. p. 171
Standard PRC-004-1 — Analysis and Mitigation of Transmission and Generation Protection System Misoperations

AI summary This document outlines the requirements for analyzing and mitigating misoperations in transmission and generation protection systems under NERC's PRC-004-1 standard. It emphasizes the importance of reliability coordination, incident response, and compliance with facility ratings and operating limits to prevent grid disruptions.

2. Levels of Non-Compliance p. p. 171
2. Levels of Non-Compliance - 2.1. Level 1: SPS owners provided SPS data, but was incomplete according to the Regional Reliability Organization SPS database requirements. - 2.2. Level 2: SPS owners provided results of studies that show com...

AI summary The document outlines four levels of non-compliance related to Special Protection System (SPS) data submission. Level 1 involves incomplete data, Level 2 includes incomplete study results, Level 3 is not applicable, and Level 4 denotes no data submission or missing compliance studies. Non-compliance is assessed against NERC standards and Regional Reliability Organization (RRO) procedures for PRC-012-0_R1.

C. Measures p. p. 171
C. Measures - M1. The Transmission Owner, Generator Owner, and Distribution Provider that owns an SPS shall have a system maintenance and testing program(s) in place that includes all items in Reliability Standard PRC-017-0_R1. - M2. The T...

AI summary The measures require SPS owners to implement maintenance and testing programs per PRC-017-0_R1 and document them for NERC and RROs within 30 days.

Attachment 1 — TOP-005-1.1 p. p. 171
Attachment 1 — TOP-005-1.1

AI summary Attachment 1 — TOP-005-1.1 relates to operational reliability information standards under the Nova Scotia Utility and Review Board (NSUARB) regulatory proceeding. It involves compliance with NERC and FERC standards, including CIP and TOP-005-1.1 requirements for reporting system operating limits and reliability data.

Glossary of Terms Used in NERC Reliability Standards Updated April 20, 2010 p. p. 120
Glossary of Terms Used in NERC Reliability Standards Updated April 20, 2010

AI summary This document provides a glossary of terms from NERC Reliability Standards, defining key concepts, acronyms, and standards critical to electric system reliability. It includes terms related to cybersecurity, emergency operations, transmission planning, and facility ratings, with updates as of April 20, 2010.

1 See 18 CFR 37.6(b)(1) p. p. 128
1 See 18 CFR 37.6(b)(1) Continent-wide Term Acronym BOT Approved Date FERC Approved Date Definition Curtailment Threshold [Archive] 2/8/2005 3/16/2007 The minimum Transfer Distribution Factor which, if exceeded, will subject an Interchange...

AI summary The text provides definitions for two terms related to transmission and cybersecurity: 'Curtailment Threshold' and 'Cyber Assets.' These terms are part of a regulatory framework and were approved by the Board of Trustees and the Federal Energy Regulatory Commission on specific dates.

Glossary of Terms Used in NERC Reliability Standards p. pp. 128-135
Glossary of Terms Used in NERC Reliability Standards Continent-wide Term Acronym BOT Approved Date FERC Approved Date Definition Cyber Security Incident [Archive] 5/2/2006 1/18/2008 Any malicious act or suspicious event that: • Compromises...

AI summary The text provides a glossary of terms used in NERC Reliability Standards, defining key concepts such as 'Cyber Security Incident' and 'Delayed Fault Clearing' with their approved dates and definitions.

Glossary of Terms Used in NERC Reliability Standards p. pp. 165-170
Glossary of Terms Used in NERC Reliability Standards

AI summary A glossary defining terms from NERC Reliability Standards, including organizations (NERC, FERC), regulatory bodies (NSUARB), utilities (NSPI), and technical standards (CIP, FAC, EOP). Focuses on electric system reliability, cybersecurity, and operational protocols.

Exhibit D p. p. 170
Exhibit D

AI summary Exhibit D provides a list of acronyms and their expansions relevant to regulatory standards, compliance, and operational protocols in the Nova Scotia utility sector, including cybersecurity, emergency operations, and transmission planning.

Current Critical Infrastructure Protection Implementation Plan for Version 2 p. p. 170
Current Critical Infrastructure Protection Implementation Plan for Version 2

AI summary Nova Scotia's Version 2 Critical Infrastructure Protection Implementation Plan outlines measures to secure energy systems against cyber threats, aligning with NERC CIP standards. It emphasizes compliance with CIP-004-2, CIP-005-2, and other cybersecurity protocols, while addressing physical security and incident response planning.

(Revised) Implementation Plan for Cyber Security Standards CIP-002-1 through CIP-009-1 p. pp. 170-173
(Revised) Implementation Plan for Cyber Security Standards CIP-002-1 through CIP-009-1

AI summary The document outlines a revised implementation plan for cyber security standards CIP-002-1 through CIP-009-1, focusing on compliance measures for Nova Scotia Power Incorporated (NSPI) under oversight by the Nova Scotia Utility and Review Board (NSUARB). It addresses electronic and physical security, incident response, and recovery planning for critical infrastructure.

Implementation Schedule p. p. 173
Implementation Schedule The following tables identify when Responsible Entities must Begin Work (BW) to become compliant with a requirement, Substantially Compliant (SC) with a requirement, Compliant (C) with a requirement, and Auditably C...

AI summary The document outlines an implementation schedule for Responsible Entities under NERC Functional Model standards, detailing compliance stages such as Begin Work, Substantially Compliant, Compliant, and Auditably Compliant. Different tables apply to various entity types, including Balancing Authorities, Transmission Operators, and Generating Plants.

Table 1 Compliance Schedule for Standards CIP-002-1 through CIP-009-1 Balancing Authorities and Transmission Operators Required to Self-certify to UA Standard 1200, and Reliability Coordinators p. p. 173
Table 1 Compliance Schedule for Standards CIP-002-1 through CIP-009-1 Balancing Authorities and Transmission Operators Required to Self-certify to UA Standard 1200, and Reliability Coordinators End of 2nd Qtr 2007 End of 2nd Qtr 2008 End o...

AI summary The document presents a compliance schedule for various cybersecurity and reliability standards (CIP-002-1 through CIP-009-1) applicable to Balancing Authorities and Transmission Operators, including self-certification requirements under UA Standard 1200 and Reliability Coordinators.

Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities p. p. 185
Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities This Implementation Plan applies to Cyber Security Standards CIP-002-2 through CIP-009-2 and CIP-002-3 through CIP-009-3. The term "Compliant" in...

AI summary The document outlines an implementation plan for compliance with NERC CIP standards (CIP-002-2 to CIP-009-3) for new entities and critical cyber assets, defining compliance schedules and noting that CIP-002 has no new milestones due to prior compliance.

Implementation Plan for Newly Identified Critical Cyber Assets p. pp. 185-186
Implementation Plan for Newly Identified Critical Cyber Assets This Implementation Plan defines the Compliant milestone dates in terms of the number of calendar months after designation of the newly identified Cyber Asset as a Critical Cyb...

AI summary This document outlines compliance milestones for newly identified Critical Cyber Assets under NERC CIP-002 through CIP-009 standards. It defines timelines for Responsible Entities to achieve compliance post-designation, with Table 2 specifying milestone dates based on asset identification scenarios and existing compliance programs.

Implementation Plan for Newly Registered Entities p. p. 186
Implementation Plan for Newly Registered Entities A newly Registered Entity is one that has registered with NERC in April 2008 or thereafter and has not previously undergone the NERC CIP-002 Critical Asset Identification Process. As such,...

AI summary Defines newly registered entities under NERC, requiring compliance with CIP-002 to CIP-009 standards via a schedule in Table 3. Entities registered after April 2008 must follow the compliance milestones outlined for NERC Reliability Standards.

Implementation Milestone Categories p. pp. 186-190
Implementation Milestone Categories The Implementation Plan milestones and schedule to achieve compliance with the NERC Reliability Standards CIP-002 through CIP-009 for newly identified Critical Cyber Assets and newly Registered Entities...

AI summary The document outlines implementation milestones for achieving compliance with NERC CIP-002 through CIP-009 standards for newly identified Critical Cyber Assets and Registered Entities. Milestones are categorized by identification scenarios, with definitions for terms like 'Auditably Compliant' (AC) and 'CIP compliance implementation program.'

Implementation Milestone Categories and Schedules p. pp. 190-191
Implementation Milestone Categories and Schedules Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios are defined and distinguished below fo...

AI summary The document outlines two implementation milestone categories for Critical Cyber Assets under NERC standards. Category 1 applies to entities newly identifying Critical Cyber Assets without prior CIP programs, while Category 2 involves entities expanding existing CIP programs to include newly identified assets. Compliance milestones are detailed in Table 2 for Category 1.

Disaster Recovery and Restoration Activities p. pp. 191-192
Disaster Recovery and Restoration Activities A special case of restoration as part of a disaster recovery situation (such as storm restoration) shall follow the emergency provisions of the Responsible Entity's policy required by CIP-003 R1...

AI summary The text outlines that during disaster recovery, restoration activities must follow emergency provisions without delay from CIP compliance. Post-restoration, the Responsible Entity must implement CIP compliance and demonstrate it via audits or self-reports.

Newly Registered Entity Scenarios p. p. 192
Newly Registered Entity Scenarios Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios as they apply to newly Registered Entities are defined...

AI summary The document outlines implementation milestones for newly registered entities under Critical Cyber Asset identification scenarios, emphasizing compliance with NERC CIP-002 standards. Predecessor entities are assumed compliant, and scenarios involving mergers/acquisitions are discussed as examples.

A Merger of Two or More Registered Entities where None of the Predecessor Registered Entities has Identified any Critical Cyber Asset p. pp. 192-193
A Merger of Two or More Registered Entities where None of the Predecessor Registered Entities has Identified any Critical Cyber Asset In the case of a business merger or asset acquisition, because there are no identified Critical Cyber Ass...

AI summary When merging entities without Critical Cyber Assets, CIP-002 compliance requires implementing risk-based Critical Asset identification. The merged entity has one year to combine or maintain separate methodologies under a unified governance structure. Annual applications of the methodology must continue even during this period, with compliance required post-analysis. Newly identified Critical Cyber Assets trigger full implementation milestones regardless of merger timelines.

A Merger of Two or More Registered Entities where Only One of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset p. p. 193
A Merger of Two or More Registered Entities where Only One of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset Since only one of the predecessor Registered Entities has previously identified Critical Cyb...

AI summary In a merger where only one predecessor entity has critical cyber assets, its CIP compliance program is assumed to apply post-merger. Other entities without critical cyber assets are not required to have CIP programs, avoiding conflicts. The CIP-002 risk-based methodology from Scenario 1 also applies here.

A Merger of Two or More Registered Entities where Two or More of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset p. pp. 193-195
A Merger of Two or More Registered Entities where Two or More of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset This scenario is the most complicated of the three, since it applies to a merged Register...

AI summary The merger of entities with critical cyber assets requires harmonizing conflicting risk-based identification methodologies and CIP compliance programs. The merged entity must align these under a common governance structure within one year, with compliance reviewed under NERC CIP-002.

Example Scenarios p. p. 195
Example Scenarios Note that there are no implementation milestones or schedules specified for a Responsible Entity that has a newly designated Critical Asset, but no newly designated Critical Cyber Assets. This situation exists because no...

AI summary This section outlines scenarios related to the designation of Critical Assets and Critical Cyber Assets, explaining that no action is required for a Responsible Entity when a Critical Asset is designated without associated Critical Cyber Assets. Compliance with NERC Reliability Standards CIP-003 through CIP-009 is only required upon designation of Critical Cyber Assets.

Table 1: Example Scenarios p. p. 195
Table 1: Example Scenarios Scenarios CIP Compliance Implementation Program: No Program (note 1) Existing Program Existing Cyber Asset reclassified as Critical Cyber Asset due to change in assessment methodology Category 1 Category 2 Existi...

AI summary This table outlines scenarios related to the implementation of the CIP Compliance Implementation Program, detailing how different changes to cyber assets and their classifications affect compliance status, such as reclassification, modifications, and emergency situations.

Table 2: Implementation milestones for Newly Identified Critical Cyber Assets p. pp. 196-198
Table 2: Implementation milestones for Newly Identified Critical Cyber Assets CIP Standard Requirement Milestone Category 1 Milestone Category 2 Standard CIP-002-2 — Critical Cyber Asset Identification R1 N/A N/A R2 N/A N/A R3 N/A N/A R4 N...

AI summary This table outlines implementation milestones for newly identified critical cyber assets under various CIP standards, detailing timelines for compliance across different categories. It includes requirements for security management, personnel training, electronic and physical security, incident reporting, and recovery planning.

Table 35 Compliance Schedule for Standards CIP-002-2 through CIP-009-2 or CIP-002-3 through CIP-009-3 For Entities Registering in April 2008 and Thereafter Registration + 12 months Registration + 24 months All Facilities All Facilities CIP-002-2 or CIP-002-3 — Critical Cyber Assets All Requirements Compliant Standard CIP-003-2 or CIP-003-3 — Security Management Controls All Requirements Except R2 Compliant R2 Compliant Standard CIP-004-2 or CIP-004-3 — Personnel & Training All Requirements Compliant Standard CIP-005-2 or CIP-005-3 — Electronic Security All Requirements Compliant Standard CIP-006-2 or CIP-006-3 — Physical Security All Requirements Compliant Standard CIP-007-2 or CIP-007-3 — Systems Security Management All Requirements Compliant Standard CIP-008-2 or CIP-008-3 — Incident Reporting and Response Planning All Requirements Compliant Standard CIP-009-2 or CIP-009-3 — Recovery Plans All Requirements Compliant p. p. 198
Table 35 Compliance Schedule for Standards CIP-002-2 through CIP-009-2 or CIP-002-3 through CIP-009-3 For Entities Registering in April 2008 and Thereafter Registration + 12 months Registration + 24 months All Facilities All Facilities CIP...

AI summary Table 35 outlines compliance schedules for CIP-002-2 through CIP-009-3 standards, showing most requirements as compliant except for CIP-003-2/3 where R2 is initially non-compliant. The note clarifies that 'Compliant' dates follow Version 1 Implementation Plan conventions, aligning with Table 4. Other compliance states from Version 1 are no longer used.

1.4. Data Retention p. p. 198
1.4. Data Retention - 1.4.1 The Responsible Entity shall keep personnel risk assessment documents in accordance with federal, state, provincial, and local laws. - 1.4.2 The Responsible Entity shall keep all other documentation required by...

AI summary The Responsible Entity must retain personnel risk assessment documents per legal requirements and maintain CIP-004-3-related documentation from the previous year unless extended by the Compliance Enforcement Authority. Audit records are to be kept by the Compliance Enforcement Authority and Registered Entity.

Version History p. p. 198
Version History Version Date Action Change Tracking 1 01/16/06 D.2.3.1 — Change "Critical Assets," to "Critical Cyber Assets" as intended. 03/24/06 2 Modifications to clarify the requirements and to bring the compliance elements into confo...

AI summary This document outlines the version history and modifications to the CIP–005–3 standard, focusing on updates to terminology, compliance requirements, and responsible entities related to cyber security and electronic security perimeters.

2.Violation Severity Levels p. p. 87
T he Tr iss ion O to an sm p er a r i l ize d Fa i l i t to te ty u on e n c Ra ing ha d i f fe fro t t t w t s er e re n m f ho i ie d by t se s p ec a Tr iss ion Ow an sm ne r o r Ge Ow ion in he ir t t ne ra ne r Tr iss ion de l. ( R )...

AI summary The text discusses the violation severity levels (VSL) related to transmission facilities and their ratings, highlighting issues with transmission owners and generators in meeting reliability standards. It references various compliance and regulatory frameworks.

Matrix of Violation Risk Factors for Approval p. p. 131
Matrix of Violation Risk Factors for Approval Standard Number Requirement Text of Requirement Violation CIP-001-1 R3. Each Reliability Coordinator, Balancing Authority, Transmission Operator, Generator Operator, and Load-Serving Entity sha...

AI summary The document presents a matrix outlining violation risk factors for approval, focusing on compliance with various reliability standards. It includes requirements for entities such as Reliability Coordinators and Balancing Authorities, emphasizing sabotage response guidelines and critical asset identification methods.

Matrix of Violation Severity Levels for Approval p. p. 131
Matrix of Violation Severity Levels for Approval Standard Number Requirement Number Text of Requirement Lower VSL Moderate VSL High VSL Severe VSL CIP-001-1 R2. Each Reliability Coordinator, Balancing Authority, Transmission Operator, Gene...

AI summary This document outlines a matrix defining different levels of violation severity (VSL) for compliance with CIP-001-1 requirements, focusing on procedures for communicating sabotage events. It specifies criteria for lower, moderate, high, and severe VSL based on the adequacy of identified procedures and parties involved.

N-13NSPI's recommendations with respect to NERC's and NPCC's filings 1 passage
Emerging Issues p. p. 0
Emerging Issues There are two issues which are currently under consideration in North America which could have a material effect on reliability regulation in Nova Scotia; 1) the Bulk-Electric System definition and the 2) the ongoing expans...

AI summary The document highlights two emerging issues in North America—Bulk-Electric System definition and CIP standards expansion—that may impact Nova Scotia's reliability regulation. NSPI submits comments for DARB's consideration without requesting action.

N-17NPCC Response to Information Requests (IR-1-IR-2) issued by the Board 2/10/2011 3 passages
Preamble p. p. 2
A CIP compliance audit ofthe Nova Scotia Power Inc. (NSP), NERC ID #NCR07178 was conducted from October 5 to October 8, 2010. At the time ofthe audit, NSP was registered for the BA, TOP, TO, TP, TSP, PA, GOP, GO, RP, DP and IA functions. T...

AI summary A CIP compliance audit of Nova Scotia Power Inc. (NSP) was conducted from October 5 to October 8, 2010. The audit found NSP compliant with eight CIP standards, except for a possible violation under CIP-004 R4 related to an employee's access not being revoked after their death. The audit team confirmed adherence to NERC and NPCC procedures.

Scope p. p. 2
Scope The scope ofthe compliance audit included the NERC CIP Standards from the NPCC 2010 Implementation Plan. In addition, this audit included a review ofmitigation plans or remedial action directives which have been completed or pending...

AI summary The compliance audit reviewed NERC CIP Standards under the NPCC 2010 Implementation Plan, assessing NSP's adherence during 2009-2010. It evaluated completed/pending mitigation plans and NSP's registered functions, including BA, TOP, TO, and others.

The following table details the findings for compliance for the scope identified for this audit. p. p. 2
The following table details the findings for compliance for the scope identified for this audit. Reliability Req. Finding Standard CIP-002-2 Rl Compliant CIP-002-J R2 Compliant CIP-002-2 R3 Compliant CIP-002·2 R4 Compliant CIP-003;. RI Com...

AI summary The audit findings detail compliance status for various reliability standards, with most requirements marked as compliant, except for one possible violation under CIP-004-2 R4. The document highlights the audit's scope and identifies areas of non-compliance.

06641Notice of Filing of Informational Filing of the North American Electric Reliability Corporation 3/23/2011 17 passages
Index to NERC Responses to Directives and Other Actions from September 16, 2010 FERC Order on Three-Year ERO Performance Assessment p. p. 63
Index to NERC Responses to Directives and Other Actions from September 16, 2010 FERC Order on Three-Year ERO Performance Assessment P No. Directive Page 152 Encourages NERC to intensify its efforts to provide additional oversight and guide...

AI summary The document provides an index to NERC's responses to directives from a September 16, 2010 FERC order regarding a three-year ERO performance assessment. One directive encourages NERC to intensify efforts in providing oversight and guidelines for identifying critical cyber assets in the Bulk-Power System.

3. Critical Infrastructure Protection p. p. 63
3. Critical Infrastructure Protection In its September 16, 2010 Order, P 151, FERC stated: "NERC also should examine the Department of Homeland Security Catalog of Control System Security, which currently is being examined by the NIST-led...

AI summary FERC ordered NERC to examine the DHS Catalog of Control System Security and collaborate with NIST and DOE to integrate CIP standards with smart grid security guidelines. FERC also emphasized the need for NERC to enhance oversight in identifying critical cyber assets for the Bulk-Power System under CIP-002-1.

NERC Response to FERC's Other Action – P 152 p. p. 63
NERC Response to FERC's Other Action – P 152 NERC has developed and successfully balloted Reliability Standard CIP-002-4, 29 which requires the identification and documentation of the Critical Cyber Assets associated with the Critical Asse...

AI summary NERC developed CIP-002-4 to standardize identification of critical cyber assets for the Bulk Electric System (BES), aligning with FERC's Order No. 706. FERC's Order P 153 emphasized uniformity in CIP audits and auditor qualifications, supporting NERC's efforts to enhance cybersecurity oversight.

a. Situation Awareness p. p. 63
a. Situation Awareness In its September 16, 2010 Order, P 166, FERC stated: "While stakeholders expressed concerns to NERC about the SAFNR project, we have no specific information to support their arguments against the project, and thus fi...

AI summary NERC is finalizing the SAFNR Version 2 system, selected via RFP, to enhance situational awareness as required by FERC. Despite budget overruns, NERC seeks funding solutions with FERC. The project timeline has been adjusted due to contract negotiations and data support from Reliability Coordinators.

Further, in P 175, FERC stated: p. p. 63
Further, in P 175, FERC stated: "While the facts and circumstances in both an event analysis and a CVI often are the same, the focus of each inquiry is different. A CVI addresses whether Reliability Standards have been violated, while an e...

AI summary FERC distinguishes between Compliance and Violation Investigations (CVIs) and event analyses, emphasizing that CVIs assess reliability standard violations, while event analyses focus on preventing recurrence. Industry participants cannot influence CVIs, and ERO/Regional Entities must maintain direct involvement in event analyses to ensure objectivity.

NERC Response to FERC's Directive – P 220 p. p. 63
NERC Response to FERC's Directive – P 220 NERC and the Regional Entities will continue to audit reliability coordinators, balancing authorities and transmission operators on three year cycles and all other registered entities on six year c...

AI summary NERC outlines a risk-based audit strategy for reliability coordinators and registered entities, focusing on three-year cycles for critical roles and six-year cycles for others. Audits prioritize entities needing oversight while maintaining visibility across all registered entities, guided by the CMEP Implementation Plan and monitored standards.

APPENDIX A p. p. 63
APPENDIX A Progress in Implementing Specific NERC Actions from the Three-Year ERO Performance Assessment

AI summary This appendix outlines progress in implementing specific North American Electric Reliability Corporation (NERC) actions as part of a three-year Electric Reliability Organization (ERO) performance assessment, focusing on compliance and regulatory oversight.

A. Reliability Standards Development p. p. 63
ed in the issues database where they will be integrated into the respective work plans of the related standards drafting activities. As stated in the 2011-2013 Reliability Standards Development Plan: "NERC has developed specific initiative...

AI summary The text discusses NERC's initiatives in reliability standards development, emphasizing compliance monitoring, technical committees' roles, and addressing Order No. 706's requirements to enhance bulk power system reliability and cybersecurity. It highlights integration of feedback into standards drafting and alignment with Commission directives.

a. SARs p. p. 63
a. SARs i. For narrowly focused requests, post SARs without a comment period or for a single 15-day comment period without a requirement for the requester to respond to all comments individually. 5 2011‐2013 Reliability Standards Developme...

AI summary The document outlines procedural changes to NERC's Standard Authorization Request (SAR) process, including streamlined comment periods for limited SARs, mandatory technical foundation documents for new standards, and allowing draft standards with SAR submissions. These updates aim to expedite reliability standards development while ensuring technical rigor, as detailed in the NERC Standard Processes Manual.

e. Process Administration p. p. 63
ditation requirements. The three subsequent actions that may be taken to fully process the expedited standard are intended to demonstrate NERC's commitment to meet the ANSI accreditation requirements. Additionally, NERC submitted revisions...

AI summary NERC revised its Reliability Standards Development Procedure to streamline ANSI accreditation, removing VRFs/VSLs from stakeholder ballot processes and establishing parallel approval via NERC Board. A streamlined process for correcting reliability standards was proposed, with Commission approval in Docket RR10-04-000.

B. Organization Registration and Certification p. p. 63
Operating Committees. See response in B.1.a above. c. Request comments on the existing criteria from the Regional Entities through the Registration Working Group (RWG). See response in B.1.a above. d. Review data from registered entities s...

AI summary The text outlines NERC's role in entity registration under FERC Order 743, stakeholder discussions on criteria application, and the ERO's case-by-case review of registration issues. NERC's primary responsibility for registry management, with regional input, is emphasized, along with the impact of the BES definition project on criteria.

C. Compliance Monitoring and Enforcement p. p. 63
f processing steps, including "example" documents, which Regional Entities must follow. See item C.1.e above. b. Establish a more extensive training program for Regional Entity compliance personnel. NERC has planned for two ERO auditor wor...

AI summary The document outlines steps to enhance compliance monitoring, including training programs for auditors, pro forma settlements for low-risk violations, and informal advice for Regional Entities. NERC and Regional Entities have implemented workshops and templates to streamline enforcement processes under Order No. 693 and CIP standards.

11. Improve system for submitting compliance information. p. p. 63
11. Improve system for submitting compliance information. a. Complete the development and implementation of the new database entry and query system. See item C.2.g above and the response to P 217 of the Commission's September 16, 2010 Orde...

AI summary The document outlines actions to improve compliance information systems, including developing a new database, implementing common report forms, and revising delegation agreements. It addresses conflicts between data retention requirements in reliability standards and CMEP, and emphasizes secure handling of critical energy infrastructure information. NERC and Regional Entities are tasked with updating procedures and communicating revised compliance guidelines.

G. Critical Infrastructure Protection p. p. 63
G. Critical Infrastructure Protection - 1. Centralize direction for implementation of Critical Infrastructure Protection (CIP) reliability standards at NERC rather than allowing Regional Entities to engage in their own efforts. - a. Develo...

AI summary The text outlines proposals to centralize CIP reliability standards under NERC, enhance auditor training, and improve guidance on critical cyber asset identification using risk-based methods. NERC is expanding training programs and collaborating with technical committees to ensure uniform implementation.

H. Situation Awareness p. p. 63
H. Situation Awareness - 1. Real-time situation awareness is outside of NERC's scope. - a. NERC will continue to develop its SA to meet obligations set forth in its ERO certification application and in NERC's ROP, Section 1000. In carrying...

AI summary NERC discusses its plans to enhance real-time situation awareness (SA) through the SAFNR Version 2 system, transition reliability tools to industry stakeholders, and improve communication protocols with government agencies. NERC emphasizes collaboration with ESCC, ES-ISAC, and federal entities like DHS and FBI to strengthen emergency preparedness and system resilience.

New Brunswick: p. pp. 120-121
. While NERC Reliability Standards are mandatory and enforceable in New Brunswick, such Reliability Standards are only relatively recently subject to formal approval by NBSO for application in New Brunswick. The process of establishing a m...

AI summary New Brunswick implements NERC Reliability Standards through a formal approval process by NBSO, with potential remand authority for EUB. Standards are adopted via Market Procedure 08, requiring 30-day public review unless expedited by EUB. EUB retains power to revoke standards under the Electricity Act.

Québec: p. pp. 125-126
bility Standards that the RC files with the Régie are NERC Reliability Standards and only apply to the registered entities in the Register of registered entities subject to NERC Reliability Standards. With respect to the adoption of Reliab...

AI summary Québec's regulatory process involves adopting NERC Reliability Standards, with the Régie overseeing compliance and sanctioning non-compliance up to $500,000/day. The CME (now CER) filed 95 standards in 2009, with public hearings in 2010 and pending decisions on registry approvals and sanction guidelines.

07810Quarterly Application for Approval of Reliability Standards of the North American Electric Reliability Corporation - September 2, 2011 9/6/2011 55 passages
& lt;sup>16 Reliability Standards marked with an asterisk are not yet mandatorily effective, but have been approved by FERC and have a future mandatory effective date. p. p. 20
& lt;sup>16 Reliability Standards marked with an asterisk are not yet mandatorily effective, but have been approved by FERC and have a future mandatory effective date. Critical Infrastructure Protection (CIP) Standards CIP-001-1a - Sabotag...

AI summary The document lists various reliability standards, including Critical Infrastructure Protection (CIP) and Emergency Preparedness and Operations (EOP) standards, along with their effective dates. Some standards are not yet mandatorily effective but have been approved by FERC and have a future mandatory effective date.

- 3) Updated NERC Glossary of Terms p. p. 20
- 3) Updated NERC Glossary of Terms 1.) NERC Reliability Standards Applicable to Nova Scotia Approved by FERC Since June 30, 2010 Filing Reliability Standard Effective Date Resource and Demand Balancing (BAL) Standards BAL-002-1 - Disturba...

AI summary The document outlines updated NERC reliability standards applicable to Nova Scotia, including Resource and Demand Balancing (BAL), Critical Infrastructure Protection (CIP), and Emergency Preparedness and Operations (EOP) standards, along with their effective dates.

Preamble p. p. 21
1. Title: Sabotage Reporting 2. Number: CIP-001-1a 3. Purpose: Disturbances or unusual occurrences, suspected or determined to be caused by sabotage, shall be reported to the appropriate systems, governmental agencies, and regulatory bodie...

AI summary This document outlines the requirements for reporting disturbances or unusual occurrences suspected or determined to be caused by sabotage to relevant systems, governmental agencies, and regulatory bodies.

CIP-001-1 : p. p. 21
CIP-001-1 : R2 . Each Reliability Coordinator, Balancing Authority, Transmission Operator, Generator Operator, and Load Serving Entity shall have procedures for the communication of information concerning sabotage events to appropriate par...

AI summary CIP-001-1 R2 mandates that entities like Reliability Coordinators and Load Serving Entities establish procedures to communicate sabotage event information to relevant Interconnection parties, emphasizing security and coordination protocols.

Response p. p. 21
Response The drafting team interprets the phrase "appropriate parties in the Interconnection" to refer collectively to entities with whom the reporting party has responsibilities and/or obligations for the communication of physical or cybe...

AI summary The drafting team interprets 'appropriate parties in the Interconnection' as entities with reporting obligations under NERC standards (e.g., IRO-001, COM-002-2, TOP-001) and agreements. They assert that identifying appropriate parties for sabotage event communication is determined by the reporting entity via CIP-001-1 R2 procedures, with no known interconnection authority holding this role.

A. Introduction p. p. 21
A. Introduction 1. Title: Cyber Security — Critical Cyber Asset Identification 2. Number: CIP-002-3 3. Purpose: NERC Standards CIP-002-3 through CIP-009-3 provide a cyber security framework for the identification and protection of Critical...

AI summary The NERC CIP-002-3 standard outlines a cybersecurity framework for identifying and protecting Critical Cyber Assets (CCAs) essential to the reliable operation of the Bulk Electric System (BES). It emphasizes risk-based assessments to identify CCAs and acknowledges the varying roles and vulnerabilities of entities involved in BES operations.

4. Applicability: p. p. 21
4. Applicability: - 4.1. Within the text of Standard CIP-002-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tr...

AI summary Section 4 defines 'Responsible Entity' under CIP-002-3 to include roles like Reliability Coordinators, Balancing Authorities, and Transmission Providers, while exempting nuclear-regulated facilities and certain cyber assets. The effective date depends on regulatory approvals or BOT adoption.

B. Requirements p. p. 21
B. Requirements - R1. Critical Asset Identification Method The Responsible Entity shall identify and document a risk-based assessment methodology to use to identify its Critical Assets. - R1.1. The Responsible Entity shall maintain documen...

AI summary The document outlines requirements for identifying critical assets and cyber assets in the Bulk Electric System. It mandates risk-based assessment methodologies, annual updates to critical asset lists, and senior management approval. Key assets include control centers, transmission substations, generation resources, and systems critical to system restoration and load shedding.

C. Measures p. p. 21
C. Measures - M1. The Responsible Entity shall make available its current risk-based assessment methodology documentation as specified in Requirement R1. - M2. The Responsible Entity shall make available its list of Critical Assets as spec...

AI summary The Responsible Entity must provide documentation on risk-based assessment methodologies, lists of critical and cyber assets, and annual approval records as specified in Requirements R1 through R4.

4. Applicability: p. pp. 21-192
4. Applicability: - 4.1. Within the text of Standard CIP-003-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tr...

AI summary Defines 'Responsible Entity' under CIP-003-3, lists exemptions for nuclear facilities and certain cyber assets, and sets the effective date based on regulatory approvals.

B. Requirements p. p. 21
B. Requirements - R1. Cyber Security Policy The Responsible Entity shall document and implement a cyber security policy that represents management's commitment and ability to secure its Critical Cyber Assets. The Responsible Entity shall,...

AI summary The Responsible Entity must implement a cyber security policy addressing CIP-002-3 through CIP-009-3 standards, including emergency provisions, to protect Critical Cyber Assets as part of regulatory requirements.

C. Measures p. p. 21
C. Measures - M1. The Responsible Entity shall make available documentation of its cyber security policy as specified in Requirement R1. Additionally, the Responsible Entity shall demonstrate that the cyber security policy is available as...

AI summary The Responsible Entity must document and demonstrate compliance with various cybersecurity and operational requirements, including policies, leadership assignments, exceptions, information protection programs, access control, and change management as specified in multiple requirements.

4. Applicability p. p. 21
4. Applicability - 4.1. Within the text of Standard CIP-005-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tra...

AI summary Section 4 defines 'Responsible Entity' under CIP-005-3, including roles like Reliability Coordinator and Transmission Owner. Exemptions apply to nuclear-regulated facilities and entities without Critical Cyber Assets. The standard becomes effective after regulatory approvals, typically in the third quarter following approval.

B. Requirements p. pp. 21-86
B. Requirements - R1. Electronic Security Perimeter The Responsible Entity shall ensure that every Critical Cyber Asset resides within an Electronic Security Perimeter. The Responsible Entity shall identify and document the Electronic Secu...

AI summary The Responsible Entity must establish and document Electronic Security Perimeters for all Critical Cyber Assets, including defining access points for dial-up devices using non-routable protocols.

C. Measures p. p. 21
C. Measures - M1. The Responsible Entity shall make available documentation about the Electronic Security Perimeter as specified in Requirement R1. - M2. The Responsible Entity shall make available documentation of the electronic access co...

AI summary The Responsible Entity must provide documentation related to the Electronic Security Perimeter (ESP), including access controls, monitoring, vulnerability assessments, and log management as specified in Requirements R1 through R5.

Question 1 (Section 4.2.2) p. p. 21
Question 1 (Section 4.2.2) What kind of cyber assets are referenced in 4.2.2 as "associated"? What else could be meant except the devices forming the communication link?

AI summary The question seeks clarification on the interpretation of 'associated' cyber assets in Section 4.2.2, beyond communication devices. It asks whether other infrastructure, systems, or components (e.g., servers, databases, or security protocols) might also be intended.

Response to Question 1 p. p. 21
Response to Question 1 In the context of applicability, associated Cyber Assets refer to any communications devices external to the Electronic Security Perimeter, i.e., beyond the point at which access to the Electronic Security Perimeter...

AI summary The response defines 'Cyber Assets' as communications devices outside the Electronic Security Perimeter (ESP), excluding devices that control access to the ESP. This clarifies the scope of assets subject to cybersecurity regulations.

Question 2 (Section 4.2.2) p. p. 21
Question 2 (Section 4.2.2) Is the communication link physical or logical? Where does it begin and terminate?

AI summary The question asks whether the communication link is physical or logical and identifies its termination points, seeking clarification on its nature and endpoints.

Response to Question 3 p. p. 21
Response to Question 3 The drafting team interprets the endpoint to mean the device at which a physical or logical communication link terminates. The endpoint is the Electronic Security Perimeter access point if access into the Electronic...

AI summary The drafting team defines an endpoint as the device terminating a communication link, specifying that it refers to the Electronic Security Perimeter (ESP) access point if access control occurs there, regardless of the OSI layer managing the communication.

Question 4 (Requirement R1.3) p. p. 21
Question 4 (Requirement R1.3) If "endpoint" is defined as logical and refers to layer 3 and above, please clarify if the termination points of an encrypted tunnel (layer 3) must be treated as an "access point? If two control centers are ow...

AI summary The text asks whether encrypted tunnel termination points (layer 3) must be considered access points under FIPS standards, given that encrypted traffic already passes through existing firewall access points with port/protocol restrictions.

A. Introduction p. p. 21
A. Introduction - 1. Title: Cyber Security Physical Security of Critical Cyber Assets - 2. Number: CIP-006-3c - 3. Purpose: Standard CIP-006-3 is intended to ensure the implementation of a physical security program for the protection of Cr...

AI summary The document introduces CIP-006-3c, a standard aimed at implementing physical security programs for Critical Cyber Assets. It emphasizes that this standard should be applied alongside CIP-002-3 through CIP-009-3 to ensure comprehensive protection.

4. Applicability: p. p. 21
4. Applicability: - 4.1. Within the text of Standard CIP-006-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator - 4.1.2 Balancing Authority - 4.1.3 Interchange Authority - 4.1.4 Transmission Service Provider - 4.1.5 Transm...

AI summary Section 4 defines 'Responsible Entity' under CIP-006-3, including roles like Reliability Coordinators and Transmission Owners, and lists exemptions such as nuclear-regulated facilities and entities without critical cyber assets. The effective date depends on regulatory approvals or BOT adoption.

1.5. Additional Compliance Information p. p. 21
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not make exceptions in its cyber security policy to the creation, documentation, or maintenance of a physical security plan. - 1.5.2 For dial-up accessible Critical...

AI summary The Responsible Entity must maintain physical security plans without exceptions in cybersecurity policies. Exceptions apply for dial-up devices using non-routable protocols, exempting them from CIP-006-3 compliance for single access points.

Interpretation: p. p. 21
Interpretation: Dial-up assets are Critical Cyber Assets, assuming they meet the criteria in CIP-002-1, and they must reside within an Electronic Security Perimeter. However, physical security control over a critical cyber asset is not req...

AI summary Dial-up assets are classified as Critical Cyber Assets under CIP-002-1, requiring placement within an Electronic Security Perimeter. However, non-routable protocol dial-up devices (e.g., RTUs) are exempt from Physical Security Perimeter requirements per CIP-006-1. The standard drafting team clarified that such assets do not need full 'six-wall' enclosures if they use non-routable protocols.

Request: p. p. 21
Request: - 1. For physical access control to cyber assets, does this include monitoring when an individual leaves the controlled access cyber area? - 2. Does the term, "time of access" mean logging when the person entered the facility or d...

AI summary The request seeks clarification on two aspects of physical access control to cyber assets: whether monitoring exit from controlled areas is required, and whether 'time of access' refers to entry/exit timestamps or duration of access to critical assets.

Requirement Number and Text of Requirement p. p. 21
Requirement Number and Text of Requirement - R4. Logging Physical Access — Logging shall record sufficient information to uniquely identify individuals and the time of access twenty-four hours a day, seven days a week. The Responsible Enti...

AI summary The requirement mandates 24/7 logging of physical access to identify individuals and times of entry. The Responsible Entity must implement technical/procedural mechanisms using methods like computerized logs, video recording, or manual logs, ensuring compliance with access control standards.

Question p. p. 21
Question If a completely enclosed border cannot be created, what does the phrase, "to control physical access" require? Must the alternative measure be physical in nature? If so, must the physical barrier literally prevent physical access...

AI summary The question seeks clarification on whether alternative measures to control physical access to Critical Cyber Assets must be physical (e.g., concrete barriers) or if logical controls (e.g., cameras, encryption) suffice when a fully enclosed border is unfeasible. It also inquires if logical controls can mitigate physical access risks.

Response p. p. 21
Response For Electronic Security Perimeter wiring external to a Physical Security Perimeter, the drafting team interprets the Requirement R1.1 as not limited to measures that are "physical in nature." The alternative measures may be physic...

AI summary The drafting team interprets R1.1 to allow both physical and logical measures for Electronic Security Perimeter (ESP) wiring outside the Physical Security Perimeter (PSP), provided they meet or exceed the security standards of a fully enclosed six-wall border. Examples include data encryption and multiple access control layers.

Version History p. p. 21
Version History Version Date Action Change Tracking 2 Modifications to clarify the requirements and to bring the compliance elements into conformance with the latest guidelines for developing compliance elements of standards. Removal of re...

AI summary This document outlines the version history and updates to the CIP-007-3 standard, which focuses on cyber security and systems security management. Key changes include clarifications to compliance requirements, removal of certain risk-related language, and updates to responsible entities and compliance monitoring procedures.

1.4. Data Retention p. p. 21
1.4. Data Retention 1.4.1 The Responsible Entity shall keep documentation other than that required for reportable Cyber Security Incidents as specified in Standard CIP-008-3 for the previous full calendar year unless directed by its Compli...

AI summary The Responsible Entity must retain documentation (excluding cyber security incident records) as per CIP-008-3 for the prior calendar year, with potential extensions by the Compliance Enforcement Authority. Audit records must be maintained by the Compliance Enforcement Authority and Registered Entity.

1.5. Additional Compliance Information p. p. 21
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not take exception in its cyber security policies to the creation of a Cyber Security Incident response plan. - 1.5.2 The Responsible Entity may not take exception i...

AI summary The Responsible Entity must not object to creating a Cyber Security Incident response plan or reporting incidents to ES ISAC, as per compliance requirements.

2. Violation Severity Levels: p. p. 21
2. Violation Severity Levels: Requirement Lower Moderate High Severe R1 The Balancing Authority failed to demonstrate the existence of the necessary operating agreements for less than 25% of the adjacent BAs. Or less than 25% of those agre...

AI summary This section outlines the violation severity levels related to the failure of the Balancing Authority to demonstrate the existence of necessary operating agreements with adjacent BAs and the absence of emergency assistance provisions in those agreements, categorized into lower, moderate, high, and severe levels based on the percentage of affected agreements.

Conclusion p. p. 150
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...

AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.

Conclusion p. p. 185
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...

AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.

Conclusion p. p. 89
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...

AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.

Conclusion p. p. 137
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...

AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.

Request: p. p. 145
Request: VAR-002 — Generator Operation for Maintaining Network Voltage Schedules, addresses the generator's provision of voltage and VAR control. Confusion exists in the industry and regions as to which requirements in this standard apply...

AI summary The document discusses confusion regarding the application of VAR-002 standards to generators without automatic voltage regulators (AVRs). Generator owners seek clarification on whether they must comply with these requirements, as they lack the necessary equipment. The response clarifies that all requirements apply regardless of AVR presence, but no requirement mandates AVR installation.

Glossary of Terms Used in NERC Reliability Standards p. p. 172
Glossary of Terms Used in NERC Reliability Standards Continent-wide Term Acronym BOT Approved Date FERC Approved Date Definition Economic Dispatch [Archive] 2/8/2005 3/16/2007 The allocation of demand to individual generating units on line...

AI summary This section provides a glossary of terms used in NERC Reliability Standards, defining key concepts such as Economic Dispatch, Electrical Energy, and Electronic Security Perimeter, along with their approval dates by the Board of Trustees and FERC.

Glossary of Terms Used in NERC Reliability Standards p. pp. 198-10
Glossary of Terms Used in NERC Reliability Standards

AI summary This glossary defines terms used in NERC Reliability Standards, including organizations like NERC, FERC, and NSUARB, technical standards (CIP, TOP, VAR), and acronyms related to grid operations, cybersecurity, and regulatory frameworks.

Current Critical Infrastructure Protection Implementation Plans for Version 3 p. pp. 10-12
Current Critical Infrastructure Protection Implementation Plans for Version 3 1

AI summary The document outlines Version 3 of Critical Infrastructure Protection (CIP) implementation plans, focusing on cybersecurity measures for the Nova Scotia power grid. It is part of regulatory proceedings by the Nova Scotia Utility and Review Board (NSUARB).

Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities p. p. 12
Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities This Implementation Plan applies to Cyber Security Standards CIP-002-2 through CIP-009-2 and CIP-002-3 through CIP-009-3. The term "Compliant" in...

AI summary This document outlines an implementation plan for compliance with NERC CIP-002 through CIP-009 standards, defining schedules for newly registered entities and critical cyber assets. It clarifies compliance definitions and notes that CIP-002 has no new milestones due to prior compliance requirements.

Implementation Plan for Newly Identified Critical Cyber Assets p. pp. 12-13
Implementation Plan for Newly Identified Critical Cyber Assets This Implementation Plan defines the Compliant milestone dates in terms of the number of calendar months after designation of the newly identified Cyber Asset as a Critical Cyb...

AI summary This Implementation Plan outlines compliance milestones for newly identified Critical Cyber Assets under NERC CIP standards. It defines timelines for Responsible Entities to achieve compliance with CIP-003 through CIP-009, depending on asset designation. Existing requirements remain unaffected, while new assets require audit records one year post-compliance milestones.

Implementation Milestone Categories p. pp. 13-17
Implementation Milestone Categories The Implementation Plan milestones and schedule to achieve compliance with the NERC Reliability Standards CIP-002 through CIP-009 for newly identified Critical Cyber Assets and newly Registered Entities...

AI summary The document outlines milestones for achieving compliance with NERC CIP-002 through CIP-009 standards for Critical Cyber Assets and newly registered entities. It defines 'CIP compliance implementation program' and 'Auditably Compliant' (AC), emphasizing auditable records for compliance. The plan omits 'Auditably Compliant' dates as they follow 'Compliant' dates by one year.

Implementation Milestone Categories and Schedules p. pp. 17-18
Implementation Milestone Categories and Schedules Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios are defined and distinguished below fo...

AI summary The document outlines two implementation scenarios for Critical Cyber Assets under NERC CIP standards. Category 1 applies to Responsible Entities newly identifying Critical Cyber Assets without prior CIP compliance programs, while Category 2 addresses entities adding new Cyber Assets to existing compliance programs. Milestones for Category 1 are detailed in Table 2.

Newly Registered Entity Scenarios p. p. 19
Newly Registered Entity Scenarios Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios as they apply to newly Registered Entities are defined...

AI summary The document outlines implementation milestones for Critical Cyber Asset scenarios applicable to newly registered entities, emphasizing compliance with NERC CIP-002 standards. Examples include business mergers and asset acquisitions, assuming predecessor entities already comply with CIP-002 and use risk-based Critical Asset identification methods.

A Merger of Two or More Registered Entities where None of the Predecessor Registered Entities has Identified any Critical Cyber Asset p. pp. 19-20
A Merger of Two or More Registered Entities where None of the Predecessor Registered Entities has Identified any Critical Cyber Asset In the case of a business merger or asset acquisition, because there are no identified Critical Cyber Ass...

AI summary In a merger without critical cyber assets, CIP-002 risk-based asset identification must be implemented. The merged entity has one year to combine or maintain separate methodologies under common governance. Annual compliance with CIP-002 R2 is required, with potential expansion to CIP-002 R3 if critical cyber assets are later identified.

A Merger of Two or More Registered Entities where Only One of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset p. p. 20
A Merger of Two or More Registered Entities where Only One of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset Since only one of the predecessor Registered Entities has previously identified Critical Cyb...

AI summary In a merger scenario where only one predecessor entity has critical cyber assets, the merged entity inherits its CIP compliance program. Other entities lack such programs as they aren't required. Post-merger, the existing CIP program applies to new critical assets. The NERC CIP-002 risk-based methodology from Scenario 1 also applies here.

A Merger of Two or More Registered Entities where Two or More of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset p. pp. 20-22
A Merger of Two or More Registered Entities where Two or More of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset This scenario is the most complicated of the three, since it applies to a merged Register...

AI summary Merging entities with differing critical cyber asset identification methods and CIP compliance programs requires harmonization within one year of the merger. Disparities may arise from tools like antivirus choices or risk methodologies, necessitating governance under a common senior manager. Compliance with NERC CIP-002 is emphasized.

Example Scenarios p. p. 22
Example Scenarios Note that there are no implementation milestones or schedules specified for a Responsible Entity that has a newly designated Critical Asset, but no newly designated Critical Cyber Assets. This situation exists because no...

AI summary The text explains that no implementation milestones or schedules are required for a Responsible Entity when a Critical Asset is designated without associated Critical Cyber Assets. Compliance with NERC Reliability Standards CIP-003 through CIP-009 is only required upon designation of Critical Cyber Assets.

Table 1: Example Scenarios p. p. 22
Table 1: Example Scenarios Scenarios CIP Compliance Implementation Program: No Program (note 1) Existing Program Existing Cyber Asset reclassified as Critical Cyber Asset due to change in assessment methodology Category 1 Category 2 Existi...

AI summary This table outlines scenarios related to the implementation of the CIP Compliance Implementation Program, detailing how different changes or events affect compliance status, such as reclassification of assets, new asset additions, modifications, and emergency situations.

Table 2: Implementation milestones for Newly Identified Critical Cyber Assets p. pp. 23-25
Table 2: Implementation milestones for Newly Identified Critical Cyber Assets CIP Standard Requirement Milestone Category 1 Milestone Category 2 Standard CIP-002-2 — Critical Cyber Asset Identification R1 N/A N/A R2 N/A N/A R3 N/A N/A R4 N...

AI summary The document outlines implementation milestones for newly identified critical cyber assets under various CIP standards. It includes timelines for compliance with requirements such as security management controls, electronic security perimeters, and incident reporting.

Table 35 Compliance Schedule for Standards CIP-002-2 through CIP-009-2 or CIP-002-3 through CIP-009-3 For Entities Registering in April 2008 and Thereafter Registration + 12 months Registration + 24 months All Facilities All Facilities CIP-002-2 or CIP-002-3 — Critical Cyber Assets All Requirements Compliant Standard CIP-003-2 or CIP-003-3 — Security Management Controls All Requirements Except R2 Compliant R2 Compliant Standard CIP-004-2 or CIP-004-3 — Personnel & Training All Requirements Compliant Standard CIP-005-2 or CIP-005-3 — Electronic Security All Requirements Compliant Standard CIP-006-2 or CIP-006-3 — Physical Security All Requirements Compliant Standard CIP-007-2 or CIP-007-3 — Systems Security Management All Requirements Compliant Standard CIP-008-2 or CIP-008-3 — Incident Reporting and Response Planning All Requirements Compliant Standard CIP-009-2 or CIP-009-3 — Recovery Plans All Requirements Compliant p. pp. 25-26
Table 35 Compliance Schedule for Standards CIP-002-2 through CIP-009-2 or CIP-002-3 through CIP-009-3 For Entities Registering in April 2008 and Thereafter Registration + 12 months Registration + 24 months All Facilities All Facilities CIP...

AI summary Table 35 outlines a compliance schedule for CIP-002-2 through CIP-009-3 standards, specifying compliance dates for entities registering in April 2008 and beyond. It notes that all requirements are compliant except for R2 in CIP-003-2/3, and references a 2010 Revised Implementation Plan adopted by the Board of Trustees.

Applicable Standards p. p. 26
Applicable Standards The following standards are covered by this Implementation Plan: CIP–002–3 — Cyber Security — Critical Cyber Asset Identification CIP–003–3 — Cyber Security — Security Management Controls CIP–004–3 — Cyber Security — P...

AI summary The document outlines CIP–002–3 through CIP–009–3 cybersecurity standards for critical infrastructure protection. These standards, covering topics like cyber asset identification, security management, and incident response, are posted for ballot by NERC. Prior versions of these standards will be retired upon their effectiveness.

Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities p. p. 26
Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities Concurrently submitted with Version 3 of Cyber Security Standards CIP-002-3 through CIP-009-3 is a separate Implementation Plan document that woul...

AI summary The document introduces an Implementation Plan to address compliance gaps for newly identified Critical Cyber Assets under NERC CIP-002-3 to CIP-009-3. It provides a phased schedule for Responsible Entities to achieve compliance, rectifying the unrealistic requirement in Version 1 to immediately attain 'Auditably Compliant' status. The plan also covers compliance for merged entities and new NERC registry registrants.

Matrix of Violation Risk Factors for Information p. p. 28
B A L- 0 0 1- 0. 1a R 1. Ea h Ba la in A ho i ha l l o h ha l l in 1 2- h ba is he t ty te t t, t t c nc g u r s p er a s uc on a ro g m on s , f f Co he lo k- in he Ba la in A ho i 's A l t te t t ty tro av er ag e o c c m u a ve ra g es...

AI summary The text discusses a matrix of violation risk factors related to information, including compliance with standards and regulations such as NERC, CIP, and others. It references various entities, acronyms, and potential violations related to reliability and compliance in the energy sector.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →