N-10Reliability Standards of the North American Electric Reliability Corporation 7/5/2010
69 passages
B. Overview of Reliability Standards NERC Reliability Standards define the requirements for reliably planning and operating the North American bulk power system. These standards are developed by industry stakeholders using a balanced, open...
AI summary NERC Reliability Standards outline requirements for the North American bulk power system's planning and operation, developed through an inclusive process by industry stakeholders. The standards cover real-time balancing, equipment limits, contingency management, vegetation control, critical infrastructure protection, and emergency planning, ensuring system reliability and safety.
C. Detailed Description of Proposed Reliability Standards The Reliability Standards presented in Exhibits C and E are grouped by topical area, as summarized below. Resource and Demand Balancing (BAL) ⎯ balancing resources and demand to mai...
AI summary The document outlines proposed reliability standards grouped into 13 topical areas, including resource balancing, cybersecurity, emergency operations, and transmission planning. It references NERC's glossary and Exhibit B, which details each standard's purpose, approval percentages, and changes. The standards aim to ensure grid reliability through coordinated operations, infrastructure protection, and compliance with NERC and FERC guidelines.
Applicability: • Balancing Authorities On October 29, 2008, BAL-006-1.1 was approved by the NERC Board of Trustees. On May 13, 2009, BAL-006-1.1 was approved by the Federal Energy Regulatory Commission. Version BAL-006-1.1 resulted from er...
AI summary The text outlines the approval history of BAL-006-1.1 by NERC and FERC, noting its derivation from errata changes. It also introduces CIP-001-1, a standard requiring sabotage-related disturbances to be reported to relevant authorities.
Applicability: - Reliability Coordinators - Balancing Authorities - Transmission Operators - Generator Operators - Load Serving Entities On October 29, 2006, CIP-001-1 was approved by the registered ballot body by a 69.48% affirmative vote...
AI summary The document outlines the approval process of CIP-001-1 and CIP-002-2 standards by NERC, FERC, and the registered ballot body, emphasizing their role in cybersecurity for the Bulk Electric System. CIP-002-2 mandates risk-based identification of critical cyber assets to ensure reliability.
1.4. Additional Compliance Information Reportable Disturbances – Reportable Disturbances are contingencies that are greater than or equal to 80% of the most severe single Contingency. A Regional Reliability Organization, sub-Regional Relia...
AI summary The section defines reportable disturbances as contingencies exceeding 80% of the most severe single contingency, outlines handling of simultaneous contingencies, and specifies evaluation procedures for multiple contingencies during recovery periods. Compliance is managed by Balancing Authorities and Reserve Sharing Groups, with potential waiver requests for inadequacies in contingency reserves.
D. Compliance
AI summary The document section titled 'Compliance' outlines regulatory requirements and standards relevant to Nova Scotia's utility sector, referencing various reliability, security, and operational protocols governed by entities like NERC, FERC, and NSUARB.
1. Title: Sabotage Reporting 2. Number: CIP-001-1 3. Purpose: Disturbances or unusual occurrences, suspected or determined to be caused by sabotage, shall be reported to the appropriate systems, governmental agencies, and regulatory bodies.
AI summary This document outlines the requirement to report disturbances or unusual occurrences suspected or determined to be caused by sabotage to appropriate systems, governmental agencies, and regulatory bodies.
C. Measures - M1. Each Reliability Coordinator, Balancing Authority, Transmission Operator, Generator Operator, and Load Serving Entity shall have and provide upon request a procedure (either electronic or hard copy) as defined in Requirem...
AI summary The document outlines three measures requiring Reliability Coordinators, Balancing Authorities, and other entities to establish procedures for compliance with reliability standards, including communication protocols with FBI/RCMP for sabotage events. These measures aim to ensure operational reliability and security in the electricity sector.
4. Applicability: - 4.1. Within the text of Standard CIP-002-2, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tr...
AI summary Section 4 defines 'Responsible Entity' under CIP-002-2, including roles like Reliability Coordinators, Balancing Authorities, and Transmission Owners. Exemptions apply to nuclear-regulated facilities and certain cyber assets. The standard's effective date depends on regulatory approvals or BOT adoption.
B. Requirements - R1. Critical Asset Identification Method The Responsible Entity shall identify and document a risk-based assessment methodology to use to identify its Critical Assets. - R1.1. The Responsible Entity shall maintain documen...
AI summary The document outlines requirements for identifying critical assets and cyber assets, including annual risk-based assessments, documentation of methodologies, and senior management approval. Critical assets include control centers, transmission substations, generation resources, and systems essential for system restoration and load shedding. Critical cyber assets are defined with specific communication and accessibility criteria.
4. Applicability - 4.1. Within the text of Standard CIP-005-2, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tra...
AI summary Section 4 defines 'Responsible Entity' under CIP-005-2, including roles like Reliability Coordinators and Balancing Authorities. Exemptions apply to nuclear-regulated facilities and certain cyber assets. The standard becomes effective after regulatory approvals, typically in the third quarter following approval.
1.4. Data Retention - 1.4.1 The Responsible Entity shall keep logs for a minimum of ninety calendar days, unless: a) longer retention is required pursuant to Standard CIP-008-2, Requirement R2; b) directed by its Compliance Enforcement Aut...
AI summary The Responsible Entity must retain logs for 90 days, except when required by CIP-008-2 R2 or directed by the Compliance Enforcement Authority. Documents under CIP-005-2 from the prior year and audit records must also be retained, with the Compliance Enforcement Authority and Registered Entity jointly managing audit data.
Version History Version Date Action Change Tracking 1 01/16/06 D.2.3.1 — Change "Critical Assets," to "Critical Cyber Assets" as intended. 03/24/06 2 Modifications to clarify the requirements and to bring the compliance elements into confo...
AI summary This document outlines the version history and updates to the CIP–005–2 standard, focusing on changes to terminology, compliance requirements, and responsible entities related to cyber security and electronic security perimeters.
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not make exceptions in its cyber security policy to the creation, documentation, or maintenance of a physical security plan. - 1.5.2 For dial-up accessible Critical...
AI summary The Responsible Entity must adhere to strict cyber security policies without exceptions for physical security plans. However, dial-up accessible Critical Cyber Assets using non-routable protocols are exempt from CIP-006-2 compliance for that specific access point.
Version History Version Date Action Change Tracking 2 Modifications to remove extraneous information from the requirements, improve readability, and to bring the compliance elements into conformance with the latest guidelines for developin...
AI summary This document outlines the version history of a compliance standard, detailing modifications to improve clarity, readability, and alignment with the latest guidelines. Key changes include the replacement of the RRO with RE as the responsible entity, updates to CIP-006-1 and CIP-006-2 requirements, and the reorganization of compliance monitoring roles.
B. Requirements - R1. Test Procedures The Responsible Entity shall ensure that new Cyber Assets and significant changes to existing Cyber Assets within the Electronic Security Perimeter do not adversely affect existing cyber security contr...
AI summary The Responsible Entity must implement test procedures to ensure new or modified cyber assets within the Electronic Security Perimeter do not compromise existing security controls, as mandated by CIP-007-2. Procedures must minimize operational disruptions.
C. Measures - M1. The Responsible Entity shall make available documentation of its security test procedures as specified in Requirement R1. - M2. The Responsible Entity shall make available documentation as specified in Requirement R2. - M...
AI summary The Responsible Entity must provide documentation for various cybersecurity programs, including security testing, patch management, malware prevention, account management, and vulnerability assessments, as outlined in requirements R1 through R9.
Standard CIP–007–2a — Cyber Security — Systems Security Management processes, and procedures for securing Cyber Assets and other (non-Critical) Assets within an Electronic Security Perimeter. Replaced the RRO with the RE as a responsible e...
AI summary The document outlines changes and updates to the CIP-007-2a standard related to cyber security and systems security management, including the replacement of the RRO with the RE as a responsible entity, changes to compliance timelines, and the addition of appendices with interpretations approved by regulatory bodies.
Requirement Number and Text of Requirement R2. The Responsible Entity shall establish and document a process to ensure that only those ports and services required for normal and emergency operations are enabled.
AI summary Requirement R2 mandates the Responsible Entity to create and document a process ensuring only essential ports and services for normal and emergency operations are enabled, aligning with cybersecurity standards for electronic security perimeters.
Response The drafting team interprets the term "ports" used as part of the phrase "ports and services" to refer to logical ports, e.g., Transmission Control Protocol (TCP) ports, where interface with communication services occurs.
AI summary The drafting team interprets 'ports' in 'ports and services' as logical ports (e.g., TCP ports) where communication services interface, clarifying technical terminology in the context of regulatory proceedings.
A. Introduction 1. Title: Cyber Security — Incident Reporting and Response Planning 2. Number: CIP-008-2 3. Purpose: Standard CIP-008-2 ensures the identification, classification, response, and reporting of Cyber Security Incidents related...
AI summary This document introduces CIP-008-2, a standard focused on ensuring the identification, classification, response, and reporting of cyber security incidents related to critical cyber assets. It emphasizes integration with other CIP standards (CIP-002-2 to CIP-009-2) for comprehensive cyber security management.
4. Applicability - 4.1. Within the text of Standard CIP-008-2, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tra...
AI summary Defines 'Responsible Entity' under CIP-008-2, including roles like Reliability Coordinators and Balancing Authorities. Exemptions include nuclear-regulated facilities and certain cyber assets. The standard becomes effective after regulatory approvals or BOT adoption in jurisdictions without such requirements.
B. Requirements - R1. Cyber Security Incident Response Plan The Responsible Entity shall develop and maintain a Cyber Security Incident response plan and implement the plan in response to Cyber Security Incidents. The Cyber Security Incide...
AI summary The Responsible Entity must develop and maintain a Cyber Security Incident response plan, including procedures for incident classification, response actions, ES-ISAC reporting, annual reviews, and testing. Documentation of incidents must be retained for three years.
1.4. Data Retention - 1.4.1 The Responsible Entity shall keep documentation other than that required for reportable Cyber Security Incidents as specified in Standard CIP-008-2 for the previous full calendar year unless directed by its Comp...
AI summary The Responsible Entity must retain cybersecurity incident documentation for the previous calendar year unless extended by the Compliance Enforcement Authority. Audit records, including those from the Registered Entity, must be maintained by the Compliance Enforcement Authority.
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not take exception in its cyber security policies to the creation of a Cyber Security Incident response plan. - 1.5.2 The Responsible Entity may not take exception i...
AI summary The Responsible Entity must comply with mandatory cyber security policies requiring a Cyber Security Incident response plan and reporting incidents to ES ISAC. Violation Severity Levels are noted as pending development.
1.4. Additional Compliance Information Attachment 1-COM-001— NERCnet Security Policy - 2. Levels of Non-Compliance for Transmission Operator, Balancing Authority or Reliability Coordinator - 2.1. Level 1: Not applicable. - 2.2. Level 2: No...
AI summary The document outlines non-compliance levels for Transmission Operators, Balancing Authorities, and Reliability Coordinators under the NERCnet Security Policy. Level 3 violations include using non-English language without agreement and lacking written procedures for telecommunication outages. Level 4 violations involve failing to actively monitor, test, manage, or alarm telecommunication systems.
3. Levels of Non-Compliance — NERCnet User Organization - 3.1. Level 1: Not applicable. - 3.2. Level 2: Not applicable. - 3.3. Level 3: Not applicable. - 3.4. Level 4: Did not adhere to the requirements in Attachment 1-COM-001, NERCnet Sec...
AI summary The document outlines non-compliance levels for NERCnet, with Level 4 indicating failure to adhere to the NERCnet Security Policy in Attachment 1-COM-001.
Attachment 1-COM-001— NERCnet Security Policy
AI summary This document outlines the NERCnet Security Policy, focusing on cybersecurity measures for critical infrastructure. It references CIP standards (e.g., CIP-004-2, CIP-005-2) and regulatory bodies like NERC, FERC, and NSUARB, emphasizing compliance with electronic and physical security protocols.
Policy Statement The purpose of this NERCnet Security Policy is to establish responsibilities and minimum requirements for the protection of information assets, computer systems and facilities of NERC and other users of the NERC frame rela...
AI summary The NERCnet Security Policy establishes requirements to protect NERC's information assets and ensure secure connectivity on the NERC frame relay network. It mandates cost-effective protection measures and proper handling of information by users to enable NERC to fulfill its mission.
NERC's Security Mission Statement NERC recognizes its dependency on data, information, and the computer systems used to facilitate effective operation of its business and fulfillment of its mission. NERC also recognizes the value of the in...
AI summary NERC emphasizes the critical importance of securing data, information, and computer systems to ensure operational effectiveness and mission fulfillment. It highlights the need to protect these assets from threats such as destruction, unauthorized access, and confidentiality breaches.
NERCnet User Organizations Users of NERCnet who have received authorization from NERC to access the NERC network are considered users of NERCnet resources. To be granted access, users shall complete a User Application Form and submit this...
AI summary Users of NERCnet must obtain authorization from NERC to access resources, requiring completion and submission of a User Application Form to the NERC Telecommunications Manager.
Responsibilities It is the responsibility of NERCnet User Organizations to: - Use NERCnet facilities for NERC-authorized business purposes only. - Comply with the NERCnet security policies, standards, and guidelines, as well as any procedu...
AI summary NERCnet User Organizations are responsible for using NERCnet facilities only for authorized purposes, complying with security policies, protecting data confidentiality, managing user access, and conducting self-assessments for compliance with NERC standards.
User Accountability and Compliance All users of NERCnet shall be familiar and ensure compliance with the policies in this document. Violations of the NERCnet Security Policy shall include, but not be limited to any act that: - Exposes NERC...
AI summary The document outlines user accountability and compliance requirements for NERCnet, emphasizing adherence to security policies to prevent data breaches, unauthorized use, and illicit activities. Violations include exposing NERC to financial loss or compromising confidential information. The policy was adopted by the Board of Trustees on October 29, 2008.
Attachment 1-EOP-002-2.1 Energy Emergency Alerts
AI summary This attachment outlines the Energy Emergency Alerts framework under EOP-002-2.1, part of Nova Scotia's regulatory process for ensuring grid reliability during emergencies. It references standards for emergency operations planning and cyber security protocols relevant to critical infrastructure protection.
Attachment 1-EOP-004 NERC Disturbance Report Form
AI summary This document is an attachment to a regulatory proceeding in Nova Scotia, specifically the NERC Disturbance Report Form (EOP-004), which relates to cybersecurity and reliability standards for the electric grid.
curity system. Actual or suspected cyber or communications attacks that could impact electric power system adequacy or vulnerability. Adopted by Board of Trustees: November 1, 2006 Page 10 of 13 - 6. Actual or suspected cyber or communicat...
AI summary The document outlines procedures for reporting emergency incidents and disturbances related to the electric power system, including cyber or communications attacks, fuel supply emergencies, and service outages. It specifies the submission of form OE-417 to the DOE Operations Center within 60 minutes and an updated version within 48 hours.
Adopted by Board of Trustees: November 1, 2006 Page 11 of 13 Table 1-EOP-004-0 Summary of NERC and DOE Reporting Requirements for Major Electric System Emergencies Incident No. Incident Threshold Report Required Time 1 Uncontrolled loss of...
AI summary This document outlines the NERC and DOE reporting requirements for major electric system emergencies, detailing specific incidents, thresholds, required reports, and timeframes for submission. It includes nine types of incidents with varying thresholds and reporting schedules.
Standard PRC-004-1 — Analysis and Mitigation of Transmission and Generation Protection System Misoperations
AI summary This document outlines the requirements for analyzing and mitigating misoperations in transmission and generation protection systems under NERC's PRC-004-1 standard. It emphasizes the importance of reliability coordination, incident response, and compliance with facility ratings and operating limits to prevent grid disruptions.
2. Levels of Non-Compliance - 2.1. Level 1: SPS owners provided SPS data, but was incomplete according to the Regional Reliability Organization SPS database requirements. - 2.2. Level 2: SPS owners provided results of studies that show com...
AI summary The document outlines four levels of non-compliance related to Special Protection System (SPS) data submission. Level 1 involves incomplete data, Level 2 includes incomplete study results, Level 3 is not applicable, and Level 4 denotes no data submission or missing compliance studies. Non-compliance is assessed against NERC standards and Regional Reliability Organization (RRO) procedures for PRC-012-0_R1.
C. Measures - M1. The Transmission Owner, Generator Owner, and Distribution Provider that owns an SPS shall have a system maintenance and testing program(s) in place that includes all items in Reliability Standard PRC-017-0_R1. - M2. The T...
AI summary The measures require SPS owners to implement maintenance and testing programs per PRC-017-0_R1 and document them for NERC and RROs within 30 days.
Attachment 1 — TOP-005-1.1
AI summary Attachment 1 — TOP-005-1.1 relates to operational reliability information standards under the Nova Scotia Utility and Review Board (NSUARB) regulatory proceeding. It involves compliance with NERC and FERC standards, including CIP and TOP-005-1.1 requirements for reporting system operating limits and reliability data.
Glossary of Terms Used in NERC Reliability Standards Updated April 20, 2010
AI summary This document provides a glossary of terms from NERC Reliability Standards, defining key concepts, acronyms, and standards critical to electric system reliability. It includes terms related to cybersecurity, emergency operations, transmission planning, and facility ratings, with updates as of April 20, 2010.
1 See 18 CFR 37.6(b)(1) Continent-wide Term Acronym BOT Approved Date FERC Approved Date Definition Curtailment Threshold [Archive] 2/8/2005 3/16/2007 The minimum Transfer Distribution Factor which, if exceeded, will subject an Interchange...
AI summary The text provides definitions for two terms related to transmission and cybersecurity: 'Curtailment Threshold' and 'Cyber Assets.' These terms are part of a regulatory framework and were approved by the Board of Trustees and the Federal Energy Regulatory Commission on specific dates.
Glossary of Terms Used in NERC Reliability Standards Continent-wide Term Acronym BOT Approved Date FERC Approved Date Definition Cyber Security Incident [Archive] 5/2/2006 1/18/2008 Any malicious act or suspicious event that: • Compromises...
AI summary The text provides a glossary of terms used in NERC Reliability Standards, defining key concepts such as 'Cyber Security Incident' and 'Delayed Fault Clearing' with their approved dates and definitions.
Glossary of Terms Used in NERC Reliability Standards
AI summary A glossary defining terms from NERC Reliability Standards, including organizations (NERC, FERC), regulatory bodies (NSUARB), utilities (NSPI), and technical standards (CIP, FAC, EOP). Focuses on electric system reliability, cybersecurity, and operational protocols.
Exhibit D
AI summary Exhibit D provides a list of acronyms and their expansions relevant to regulatory standards, compliance, and operational protocols in the Nova Scotia utility sector, including cybersecurity, emergency operations, and transmission planning.
Current Critical Infrastructure Protection Implementation Plan for Version 2
AI summary Nova Scotia's Version 2 Critical Infrastructure Protection Implementation Plan outlines measures to secure energy systems against cyber threats, aligning with NERC CIP standards. It emphasizes compliance with CIP-004-2, CIP-005-2, and other cybersecurity protocols, while addressing physical security and incident response planning.
(Revised) Implementation Plan for Cyber Security Standards CIP-002-1 through CIP-009-1
AI summary The document outlines a revised implementation plan for cyber security standards CIP-002-1 through CIP-009-1, focusing on compliance measures for Nova Scotia Power Incorporated (NSPI) under oversight by the Nova Scotia Utility and Review Board (NSUARB). It addresses electronic and physical security, incident response, and recovery planning for critical infrastructure.
Implementation Schedule The following tables identify when Responsible Entities must Begin Work (BW) to become compliant with a requirement, Substantially Compliant (SC) with a requirement, Compliant (C) with a requirement, and Auditably C...
AI summary The document outlines an implementation schedule for Responsible Entities under NERC Functional Model standards, detailing compliance stages such as Begin Work, Substantially Compliant, Compliant, and Auditably Compliant. Different tables apply to various entity types, including Balancing Authorities, Transmission Operators, and Generating Plants.
Table 1 Compliance Schedule for Standards CIP-002-1 through CIP-009-1 Balancing Authorities and Transmission Operators Required to Self-certify to UA Standard 1200, and Reliability Coordinators End of 2nd Qtr 2007 End of 2nd Qtr 2008 End o...
AI summary The document presents a compliance schedule for various cybersecurity and reliability standards (CIP-002-1 through CIP-009-1) applicable to Balancing Authorities and Transmission Operators, including self-certification requirements under UA Standard 1200 and Reliability Coordinators.
Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities This Implementation Plan applies to Cyber Security Standards CIP-002-2 through CIP-009-2 and CIP-002-3 through CIP-009-3. The term "Compliant" in...
AI summary The document outlines an implementation plan for compliance with NERC CIP standards (CIP-002-2 to CIP-009-3) for new entities and critical cyber assets, defining compliance schedules and noting that CIP-002 has no new milestones due to prior compliance.
Implementation Plan for Newly Identified Critical Cyber Assets This Implementation Plan defines the Compliant milestone dates in terms of the number of calendar months after designation of the newly identified Cyber Asset as a Critical Cyb...
AI summary This document outlines compliance milestones for newly identified Critical Cyber Assets under NERC CIP-002 through CIP-009 standards. It defines timelines for Responsible Entities to achieve compliance post-designation, with Table 2 specifying milestone dates based on asset identification scenarios and existing compliance programs.
Implementation Plan for Newly Registered Entities A newly Registered Entity is one that has registered with NERC in April 2008 or thereafter and has not previously undergone the NERC CIP-002 Critical Asset Identification Process. As such,...
AI summary Defines newly registered entities under NERC, requiring compliance with CIP-002 to CIP-009 standards via a schedule in Table 3. Entities registered after April 2008 must follow the compliance milestones outlined for NERC Reliability Standards.
Implementation Milestone Categories The Implementation Plan milestones and schedule to achieve compliance with the NERC Reliability Standards CIP-002 through CIP-009 for newly identified Critical Cyber Assets and newly Registered Entities...
AI summary The document outlines implementation milestones for achieving compliance with NERC CIP-002 through CIP-009 standards for newly identified Critical Cyber Assets and Registered Entities. Milestones are categorized by identification scenarios, with definitions for terms like 'Auditably Compliant' (AC) and 'CIP compliance implementation program.'
Implementation Milestone Categories and Schedules Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios are defined and distinguished below fo...
AI summary The document outlines two implementation milestone categories for Critical Cyber Assets under NERC standards. Category 1 applies to entities newly identifying Critical Cyber Assets without prior CIP programs, while Category 2 involves entities expanding existing CIP programs to include newly identified assets. Compliance milestones are detailed in Table 2 for Category 1.
Disaster Recovery and Restoration Activities A special case of restoration as part of a disaster recovery situation (such as storm restoration) shall follow the emergency provisions of the Responsible Entity's policy required by CIP-003 R1...
AI summary The text outlines that during disaster recovery, restoration activities must follow emergency provisions without delay from CIP compliance. Post-restoration, the Responsible Entity must implement CIP compliance and demonstrate it via audits or self-reports.
Newly Registered Entity Scenarios Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios as they apply to newly Registered Entities are defined...
AI summary The document outlines implementation milestones for newly registered entities under Critical Cyber Asset identification scenarios, emphasizing compliance with NERC CIP-002 standards. Predecessor entities are assumed compliant, and scenarios involving mergers/acquisitions are discussed as examples.
A Merger of Two or More Registered Entities where None of the Predecessor Registered Entities has Identified any Critical Cyber Asset In the case of a business merger or asset acquisition, because there are no identified Critical Cyber Ass...
AI summary When merging entities without Critical Cyber Assets, CIP-002 compliance requires implementing risk-based Critical Asset identification. The merged entity has one year to combine or maintain separate methodologies under a unified governance structure. Annual applications of the methodology must continue even during this period, with compliance required post-analysis. Newly identified Critical Cyber Assets trigger full implementation milestones regardless of merger timelines.
A Merger of Two or More Registered Entities where Only One of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset Since only one of the predecessor Registered Entities has previously identified Critical Cyb...
AI summary In a merger where only one predecessor entity has critical cyber assets, its CIP compliance program is assumed to apply post-merger. Other entities without critical cyber assets are not required to have CIP programs, avoiding conflicts. The CIP-002 risk-based methodology from Scenario 1 also applies here.
A Merger of Two or More Registered Entities where Two or More of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset This scenario is the most complicated of the three, since it applies to a merged Register...
AI summary The merger of entities with critical cyber assets requires harmonizing conflicting risk-based identification methodologies and CIP compliance programs. The merged entity must align these under a common governance structure within one year, with compliance reviewed under NERC CIP-002.
Example Scenarios Note that there are no implementation milestones or schedules specified for a Responsible Entity that has a newly designated Critical Asset, but no newly designated Critical Cyber Assets. This situation exists because no...
AI summary This section outlines scenarios related to the designation of Critical Assets and Critical Cyber Assets, explaining that no action is required for a Responsible Entity when a Critical Asset is designated without associated Critical Cyber Assets. Compliance with NERC Reliability Standards CIP-003 through CIP-009 is only required upon designation of Critical Cyber Assets.
Table 1: Example Scenarios Scenarios CIP Compliance Implementation Program: No Program (note 1) Existing Program Existing Cyber Asset reclassified as Critical Cyber Asset due to change in assessment methodology Category 1 Category 2 Existi...
AI summary This table outlines scenarios related to the implementation of the CIP Compliance Implementation Program, detailing how different changes to cyber assets and their classifications affect compliance status, such as reclassification, modifications, and emergency situations.
Table 2: Implementation milestones for Newly Identified Critical Cyber Assets CIP Standard Requirement Milestone Category 1 Milestone Category 2 Standard CIP-002-2 — Critical Cyber Asset Identification R1 N/A N/A R2 N/A N/A R3 N/A N/A R4 N...
AI summary This table outlines implementation milestones for newly identified critical cyber assets under various CIP standards, detailing timelines for compliance across different categories. It includes requirements for security management, personnel training, electronic and physical security, incident reporting, and recovery planning.
Table 35 Compliance Schedule for Standards CIP-002-2 through CIP-009-2 or CIP-002-3 through CIP-009-3 For Entities Registering in April 2008 and Thereafter Registration + 12 months Registration + 24 months All Facilities All Facilities CIP...
AI summary Table 35 outlines compliance schedules for CIP-002-2 through CIP-009-3 standards, showing most requirements as compliant except for CIP-003-2/3 where R2 is initially non-compliant. The note clarifies that 'Compliant' dates follow Version 1 Implementation Plan conventions, aligning with Table 4. Other compliance states from Version 1 are no longer used.
1.4. Data Retention - 1.4.1 The Responsible Entity shall keep personnel risk assessment documents in accordance with federal, state, provincial, and local laws. - 1.4.2 The Responsible Entity shall keep all other documentation required by...
AI summary The Responsible Entity must retain personnel risk assessment documents per legal requirements and maintain CIP-004-3-related documentation from the previous year unless extended by the Compliance Enforcement Authority. Audit records are to be kept by the Compliance Enforcement Authority and Registered Entity.
Version History Version Date Action Change Tracking 1 01/16/06 D.2.3.1 — Change "Critical Assets," to "Critical Cyber Assets" as intended. 03/24/06 2 Modifications to clarify the requirements and to bring the compliance elements into confo...
AI summary This document outlines the version history and modifications to the CIP–005–3 standard, focusing on updates to terminology, compliance requirements, and responsible entities related to cyber security and electronic security perimeters.
T he Tr iss ion O to an sm p er a r i l ize d Fa i l i t to te ty u on e n c Ra ing ha d i f fe fro t t t w t s er e re n m f ho i ie d by t se s p ec a Tr iss ion Ow an sm ne r o r Ge Ow ion in he ir t t ne ra ne r Tr iss ion de l. ( R )...
AI summary The text discusses the violation severity levels (VSL) related to transmission facilities and their ratings, highlighting issues with transmission owners and generators in meeting reliability standards. It references various compliance and regulatory frameworks.
Matrix of Violation Risk Factors for Approval Standard Number Requirement Text of Requirement Violation CIP-001-1 R3. Each Reliability Coordinator, Balancing Authority, Transmission Operator, Generator Operator, and Load-Serving Entity sha...
AI summary The document presents a matrix outlining violation risk factors for approval, focusing on compliance with various reliability standards. It includes requirements for entities such as Reliability Coordinators and Balancing Authorities, emphasizing sabotage response guidelines and critical asset identification methods.
Matrix of Violation Severity Levels for Approval Standard Number Requirement Number Text of Requirement Lower VSL Moderate VSL High VSL Severe VSL CIP-001-1 R2. Each Reliability Coordinator, Balancing Authority, Transmission Operator, Gene...
AI summary This document outlines a matrix defining different levels of violation severity (VSL) for compliance with CIP-001-1 requirements, focusing on procedures for communicating sabotage events. It specifies criteria for lower, moderate, high, and severe VSL based on the adequacy of identified procedures and parties involved.
06641Notice of Filing of Informational Filing of the North American Electric Reliability Corporation 3/23/2011
17 passages
Index to NERC Responses to Directives and Other Actions from September 16, 2010 FERC Order on Three-Year ERO Performance Assessment P No. Directive Page 152 Encourages NERC to intensify its efforts to provide additional oversight and guide...
AI summary The document provides an index to NERC's responses to directives from a September 16, 2010 FERC order regarding a three-year ERO performance assessment. One directive encourages NERC to intensify efforts in providing oversight and guidelines for identifying critical cyber assets in the Bulk-Power System.
3. Critical Infrastructure Protection In its September 16, 2010 Order, P 151, FERC stated: "NERC also should examine the Department of Homeland Security Catalog of Control System Security, which currently is being examined by the NIST-led...
AI summary FERC ordered NERC to examine the DHS Catalog of Control System Security and collaborate with NIST and DOE to integrate CIP standards with smart grid security guidelines. FERC also emphasized the need for NERC to enhance oversight in identifying critical cyber assets for the Bulk-Power System under CIP-002-1.
NERC Response to FERC's Other Action – P 152 NERC has developed and successfully balloted Reliability Standard CIP-002-4, 29 which requires the identification and documentation of the Critical Cyber Assets associated with the Critical Asse...
AI summary NERC developed CIP-002-4 to standardize identification of critical cyber assets for the Bulk Electric System (BES), aligning with FERC's Order No. 706. FERC's Order P 153 emphasized uniformity in CIP audits and auditor qualifications, supporting NERC's efforts to enhance cybersecurity oversight.
a. Situation Awareness In its September 16, 2010 Order, P 166, FERC stated: "While stakeholders expressed concerns to NERC about the SAFNR project, we have no specific information to support their arguments against the project, and thus fi...
AI summary NERC is finalizing the SAFNR Version 2 system, selected via RFP, to enhance situational awareness as required by FERC. Despite budget overruns, NERC seeks funding solutions with FERC. The project timeline has been adjusted due to contract negotiations and data support from Reliability Coordinators.
Further, in P 175, FERC stated: "While the facts and circumstances in both an event analysis and a CVI often are the same, the focus of each inquiry is different. A CVI addresses whether Reliability Standards have been violated, while an e...
AI summary FERC distinguishes between Compliance and Violation Investigations (CVIs) and event analyses, emphasizing that CVIs assess reliability standard violations, while event analyses focus on preventing recurrence. Industry participants cannot influence CVIs, and ERO/Regional Entities must maintain direct involvement in event analyses to ensure objectivity.
NERC Response to FERC's Directive – P 220 NERC and the Regional Entities will continue to audit reliability coordinators, balancing authorities and transmission operators on three year cycles and all other registered entities on six year c...
AI summary NERC outlines a risk-based audit strategy for reliability coordinators and registered entities, focusing on three-year cycles for critical roles and six-year cycles for others. Audits prioritize entities needing oversight while maintaining visibility across all registered entities, guided by the CMEP Implementation Plan and monitored standards.
APPENDIX A Progress in Implementing Specific NERC Actions from the Three-Year ERO Performance Assessment
AI summary This appendix outlines progress in implementing specific North American Electric Reliability Corporation (NERC) actions as part of a three-year Electric Reliability Organization (ERO) performance assessment, focusing on compliance and regulatory oversight.
ed in the issues database where they will be integrated into the respective work plans of the related standards drafting activities. As stated in the 2011-2013 Reliability Standards Development Plan: "NERC has developed specific initiative...
AI summary The text discusses NERC's initiatives in reliability standards development, emphasizing compliance monitoring, technical committees' roles, and addressing Order No. 706's requirements to enhance bulk power system reliability and cybersecurity. It highlights integration of feedback into standards drafting and alignment with Commission directives.
a. SARs i. For narrowly focused requests, post SARs without a comment period or for a single 15-day comment period without a requirement for the requester to respond to all comments individually. 5 2011‐2013 Reliability Standards Developme...
AI summary The document outlines procedural changes to NERC's Standard Authorization Request (SAR) process, including streamlined comment periods for limited SARs, mandatory technical foundation documents for new standards, and allowing draft standards with SAR submissions. These updates aim to expedite reliability standards development while ensuring technical rigor, as detailed in the NERC Standard Processes Manual.
ditation requirements. The three subsequent actions that may be taken to fully process the expedited standard are intended to demonstrate NERC's commitment to meet the ANSI accreditation requirements. Additionally, NERC submitted revisions...
AI summary NERC revised its Reliability Standards Development Procedure to streamline ANSI accreditation, removing VRFs/VSLs from stakeholder ballot processes and establishing parallel approval via NERC Board. A streamlined process for correcting reliability standards was proposed, with Commission approval in Docket RR10-04-000.
Operating Committees. See response in B.1.a above. c. Request comments on the existing criteria from the Regional Entities through the Registration Working Group (RWG). See response in B.1.a above. d. Review data from registered entities s...
AI summary The text outlines NERC's role in entity registration under FERC Order 743, stakeholder discussions on criteria application, and the ERO's case-by-case review of registration issues. NERC's primary responsibility for registry management, with regional input, is emphasized, along with the impact of the BES definition project on criteria.
f processing steps, including "example" documents, which Regional Entities must follow. See item C.1.e above. b. Establish a more extensive training program for Regional Entity compliance personnel. NERC has planned for two ERO auditor wor...
AI summary The document outlines steps to enhance compliance monitoring, including training programs for auditors, pro forma settlements for low-risk violations, and informal advice for Regional Entities. NERC and Regional Entities have implemented workshops and templates to streamline enforcement processes under Order No. 693 and CIP standards.
11. Improve system for submitting compliance information. a. Complete the development and implementation of the new database entry and query system. See item C.2.g above and the response to P 217 of the Commission's September 16, 2010 Orde...
AI summary The document outlines actions to improve compliance information systems, including developing a new database, implementing common report forms, and revising delegation agreements. It addresses conflicts between data retention requirements in reliability standards and CMEP, and emphasizes secure handling of critical energy infrastructure information. NERC and Regional Entities are tasked with updating procedures and communicating revised compliance guidelines.
G. Critical Infrastructure Protection - 1. Centralize direction for implementation of Critical Infrastructure Protection (CIP) reliability standards at NERC rather than allowing Regional Entities to engage in their own efforts. - a. Develo...
AI summary The text outlines proposals to centralize CIP reliability standards under NERC, enhance auditor training, and improve guidance on critical cyber asset identification using risk-based methods. NERC is expanding training programs and collaborating with technical committees to ensure uniform implementation.
H. Situation Awareness - 1. Real-time situation awareness is outside of NERC's scope. - a. NERC will continue to develop its SA to meet obligations set forth in its ERO certification application and in NERC's ROP, Section 1000. In carrying...
AI summary NERC discusses its plans to enhance real-time situation awareness (SA) through the SAFNR Version 2 system, transition reliability tools to industry stakeholders, and improve communication protocols with government agencies. NERC emphasizes collaboration with ESCC, ES-ISAC, and federal entities like DHS and FBI to strengthen emergency preparedness and system resilience.
. While NERC Reliability Standards are mandatory and enforceable in New Brunswick, such Reliability Standards are only relatively recently subject to formal approval by NBSO for application in New Brunswick. The process of establishing a m...
AI summary New Brunswick implements NERC Reliability Standards through a formal approval process by NBSO, with potential remand authority for EUB. Standards are adopted via Market Procedure 08, requiring 30-day public review unless expedited by EUB. EUB retains power to revoke standards under the Electricity Act.
bility Standards that the RC files with the Régie are NERC Reliability Standards and only apply to the registered entities in the Register of registered entities subject to NERC Reliability Standards. With respect to the adoption of Reliab...
AI summary Québec's regulatory process involves adopting NERC Reliability Standards, with the Régie overseeing compliance and sanctioning non-compliance up to $500,000/day. The CME (now CER) filed 95 standards in 2009, with public hearings in 2010 and pending decisions on registry approvals and sanction guidelines.
07810Quarterly Application for Approval of Reliability Standards of the North American Electric Reliability Corporation - September 2, 2011 9/6/2011
55 passages
& lt;sup>16 Reliability Standards marked with an asterisk are not yet mandatorily effective, but have been approved by FERC and have a future mandatory effective date. Critical Infrastructure Protection (CIP) Standards CIP-001-1a - Sabotag...
AI summary The document lists various reliability standards, including Critical Infrastructure Protection (CIP) and Emergency Preparedness and Operations (EOP) standards, along with their effective dates. Some standards are not yet mandatorily effective but have been approved by FERC and have a future mandatory effective date.
- 3) Updated NERC Glossary of Terms 1.) NERC Reliability Standards Applicable to Nova Scotia Approved by FERC Since June 30, 2010 Filing Reliability Standard Effective Date Resource and Demand Balancing (BAL) Standards BAL-002-1 - Disturba...
AI summary The document outlines updated NERC reliability standards applicable to Nova Scotia, including Resource and Demand Balancing (BAL), Critical Infrastructure Protection (CIP), and Emergency Preparedness and Operations (EOP) standards, along with their effective dates.
1. Title: Sabotage Reporting 2. Number: CIP-001-1a 3. Purpose: Disturbances or unusual occurrences, suspected or determined to be caused by sabotage, shall be reported to the appropriate systems, governmental agencies, and regulatory bodie...
AI summary This document outlines the requirements for reporting disturbances or unusual occurrences suspected or determined to be caused by sabotage to relevant systems, governmental agencies, and regulatory bodies.
CIP-001-1 : R2 . Each Reliability Coordinator, Balancing Authority, Transmission Operator, Generator Operator, and Load Serving Entity shall have procedures for the communication of information concerning sabotage events to appropriate par...
AI summary CIP-001-1 R2 mandates that entities like Reliability Coordinators and Load Serving Entities establish procedures to communicate sabotage event information to relevant Interconnection parties, emphasizing security and coordination protocols.
Response The drafting team interprets the phrase "appropriate parties in the Interconnection" to refer collectively to entities with whom the reporting party has responsibilities and/or obligations for the communication of physical or cybe...
AI summary The drafting team interprets 'appropriate parties in the Interconnection' as entities with reporting obligations under NERC standards (e.g., IRO-001, COM-002-2, TOP-001) and agreements. They assert that identifying appropriate parties for sabotage event communication is determined by the reporting entity via CIP-001-1 R2 procedures, with no known interconnection authority holding this role.
A. Introduction 1. Title: Cyber Security — Critical Cyber Asset Identification 2. Number: CIP-002-3 3. Purpose: NERC Standards CIP-002-3 through CIP-009-3 provide a cyber security framework for the identification and protection of Critical...
AI summary The NERC CIP-002-3 standard outlines a cybersecurity framework for identifying and protecting Critical Cyber Assets (CCAs) essential to the reliable operation of the Bulk Electric System (BES). It emphasizes risk-based assessments to identify CCAs and acknowledges the varying roles and vulnerabilities of entities involved in BES operations.
4. Applicability: - 4.1. Within the text of Standard CIP-002-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tr...
AI summary Section 4 defines 'Responsible Entity' under CIP-002-3 to include roles like Reliability Coordinators, Balancing Authorities, and Transmission Providers, while exempting nuclear-regulated facilities and certain cyber assets. The effective date depends on regulatory approvals or BOT adoption.
B. Requirements - R1. Critical Asset Identification Method The Responsible Entity shall identify and document a risk-based assessment methodology to use to identify its Critical Assets. - R1.1. The Responsible Entity shall maintain documen...
AI summary The document outlines requirements for identifying critical assets and cyber assets in the Bulk Electric System. It mandates risk-based assessment methodologies, annual updates to critical asset lists, and senior management approval. Key assets include control centers, transmission substations, generation resources, and systems critical to system restoration and load shedding.
C. Measures - M1. The Responsible Entity shall make available its current risk-based assessment methodology documentation as specified in Requirement R1. - M2. The Responsible Entity shall make available its list of Critical Assets as spec...
AI summary The Responsible Entity must provide documentation on risk-based assessment methodologies, lists of critical and cyber assets, and annual approval records as specified in Requirements R1 through R4.
4. Applicability: - 4.1. Within the text of Standard CIP-003-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tr...
AI summary Defines 'Responsible Entity' under CIP-003-3, lists exemptions for nuclear facilities and certain cyber assets, and sets the effective date based on regulatory approvals.
B. Requirements - R1. Cyber Security Policy The Responsible Entity shall document and implement a cyber security policy that represents management's commitment and ability to secure its Critical Cyber Assets. The Responsible Entity shall,...
AI summary The Responsible Entity must implement a cyber security policy addressing CIP-002-3 through CIP-009-3 standards, including emergency provisions, to protect Critical Cyber Assets as part of regulatory requirements.
C. Measures - M1. The Responsible Entity shall make available documentation of its cyber security policy as specified in Requirement R1. Additionally, the Responsible Entity shall demonstrate that the cyber security policy is available as...
AI summary The Responsible Entity must document and demonstrate compliance with various cybersecurity and operational requirements, including policies, leadership assignments, exceptions, information protection programs, access control, and change management as specified in multiple requirements.
4. Applicability - 4.1. Within the text of Standard CIP-005-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator. - 4.1.2 Balancing Authority. - 4.1.3 Interchange Authority. - 4.1.4 Transmission Service Provider. - 4.1.5 Tra...
AI summary Section 4 defines 'Responsible Entity' under CIP-005-3, including roles like Reliability Coordinator and Transmission Owner. Exemptions apply to nuclear-regulated facilities and entities without Critical Cyber Assets. The standard becomes effective after regulatory approvals, typically in the third quarter following approval.
B. Requirements - R1. Electronic Security Perimeter The Responsible Entity shall ensure that every Critical Cyber Asset resides within an Electronic Security Perimeter. The Responsible Entity shall identify and document the Electronic Secu...
AI summary The Responsible Entity must establish and document Electronic Security Perimeters for all Critical Cyber Assets, including defining access points for dial-up devices using non-routable protocols.
C. Measures - M1. The Responsible Entity shall make available documentation about the Electronic Security Perimeter as specified in Requirement R1. - M2. The Responsible Entity shall make available documentation of the electronic access co...
AI summary The Responsible Entity must provide documentation related to the Electronic Security Perimeter (ESP), including access controls, monitoring, vulnerability assessments, and log management as specified in Requirements R1 through R5.
Question 1 (Section 4.2.2) What kind of cyber assets are referenced in 4.2.2 as "associated"? What else could be meant except the devices forming the communication link?
AI summary The question seeks clarification on the interpretation of 'associated' cyber assets in Section 4.2.2, beyond communication devices. It asks whether other infrastructure, systems, or components (e.g., servers, databases, or security protocols) might also be intended.
Response to Question 1 In the context of applicability, associated Cyber Assets refer to any communications devices external to the Electronic Security Perimeter, i.e., beyond the point at which access to the Electronic Security Perimeter...
AI summary The response defines 'Cyber Assets' as communications devices outside the Electronic Security Perimeter (ESP), excluding devices that control access to the ESP. This clarifies the scope of assets subject to cybersecurity regulations.
Question 2 (Section 4.2.2) Is the communication link physical or logical? Where does it begin and terminate?
AI summary The question asks whether the communication link is physical or logical and identifies its termination points, seeking clarification on its nature and endpoints.
Response to Question 3 The drafting team interprets the endpoint to mean the device at which a physical or logical communication link terminates. The endpoint is the Electronic Security Perimeter access point if access into the Electronic...
AI summary The drafting team defines an endpoint as the device terminating a communication link, specifying that it refers to the Electronic Security Perimeter (ESP) access point if access control occurs there, regardless of the OSI layer managing the communication.
Question 4 (Requirement R1.3) If "endpoint" is defined as logical and refers to layer 3 and above, please clarify if the termination points of an encrypted tunnel (layer 3) must be treated as an "access point? If two control centers are ow...
AI summary The text asks whether encrypted tunnel termination points (layer 3) must be considered access points under FIPS standards, given that encrypted traffic already passes through existing firewall access points with port/protocol restrictions.
A. Introduction - 1. Title: Cyber Security Physical Security of Critical Cyber Assets - 2. Number: CIP-006-3c - 3. Purpose: Standard CIP-006-3 is intended to ensure the implementation of a physical security program for the protection of Cr...
AI summary The document introduces CIP-006-3c, a standard aimed at implementing physical security programs for Critical Cyber Assets. It emphasizes that this standard should be applied alongside CIP-002-3 through CIP-009-3 to ensure comprehensive protection.
4. Applicability: - 4.1. Within the text of Standard CIP-006-3, "Responsible Entity" shall mean: - 4.1.1 Reliability Coordinator - 4.1.2 Balancing Authority - 4.1.3 Interchange Authority - 4.1.4 Transmission Service Provider - 4.1.5 Transm...
AI summary Section 4 defines 'Responsible Entity' under CIP-006-3, including roles like Reliability Coordinators and Transmission Owners, and lists exemptions such as nuclear-regulated facilities and entities without critical cyber assets. The effective date depends on regulatory approvals or BOT adoption.
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not make exceptions in its cyber security policy to the creation, documentation, or maintenance of a physical security plan. - 1.5.2 For dial-up accessible Critical...
AI summary The Responsible Entity must maintain physical security plans without exceptions in cybersecurity policies. Exceptions apply for dial-up devices using non-routable protocols, exempting them from CIP-006-3 compliance for single access points.
Interpretation: Dial-up assets are Critical Cyber Assets, assuming they meet the criteria in CIP-002-1, and they must reside within an Electronic Security Perimeter. However, physical security control over a critical cyber asset is not req...
AI summary Dial-up assets are classified as Critical Cyber Assets under CIP-002-1, requiring placement within an Electronic Security Perimeter. However, non-routable protocol dial-up devices (e.g., RTUs) are exempt from Physical Security Perimeter requirements per CIP-006-1. The standard drafting team clarified that such assets do not need full 'six-wall' enclosures if they use non-routable protocols.
Request: - 1. For physical access control to cyber assets, does this include monitoring when an individual leaves the controlled access cyber area? - 2. Does the term, "time of access" mean logging when the person entered the facility or d...
AI summary The request seeks clarification on two aspects of physical access control to cyber assets: whether monitoring exit from controlled areas is required, and whether 'time of access' refers to entry/exit timestamps or duration of access to critical assets.
Requirement Number and Text of Requirement - R4. Logging Physical Access — Logging shall record sufficient information to uniquely identify individuals and the time of access twenty-four hours a day, seven days a week. The Responsible Enti...
AI summary The requirement mandates 24/7 logging of physical access to identify individuals and times of entry. The Responsible Entity must implement technical/procedural mechanisms using methods like computerized logs, video recording, or manual logs, ensuring compliance with access control standards.
Question If a completely enclosed border cannot be created, what does the phrase, "to control physical access" require? Must the alternative measure be physical in nature? If so, must the physical barrier literally prevent physical access...
AI summary The question seeks clarification on whether alternative measures to control physical access to Critical Cyber Assets must be physical (e.g., concrete barriers) or if logical controls (e.g., cameras, encryption) suffice when a fully enclosed border is unfeasible. It also inquires if logical controls can mitigate physical access risks.
Response For Electronic Security Perimeter wiring external to a Physical Security Perimeter, the drafting team interprets the Requirement R1.1 as not limited to measures that are "physical in nature." The alternative measures may be physic...
AI summary The drafting team interprets R1.1 to allow both physical and logical measures for Electronic Security Perimeter (ESP) wiring outside the Physical Security Perimeter (PSP), provided they meet or exceed the security standards of a fully enclosed six-wall border. Examples include data encryption and multiple access control layers.
Version History Version Date Action Change Tracking 2 Modifications to clarify the requirements and to bring the compliance elements into conformance with the latest guidelines for developing compliance elements of standards. Removal of re...
AI summary This document outlines the version history and updates to the CIP-007-3 standard, which focuses on cyber security and systems security management. Key changes include clarifications to compliance requirements, removal of certain risk-related language, and updates to responsible entities and compliance monitoring procedures.
1.4. Data Retention 1.4.1 The Responsible Entity shall keep documentation other than that required for reportable Cyber Security Incidents as specified in Standard CIP-008-3 for the previous full calendar year unless directed by its Compli...
AI summary The Responsible Entity must retain documentation (excluding cyber security incident records) as per CIP-008-3 for the prior calendar year, with potential extensions by the Compliance Enforcement Authority. Audit records must be maintained by the Compliance Enforcement Authority and Registered Entity.
1.5. Additional Compliance Information - 1.5.1 The Responsible Entity may not take exception in its cyber security policies to the creation of a Cyber Security Incident response plan. - 1.5.2 The Responsible Entity may not take exception i...
AI summary The Responsible Entity must not object to creating a Cyber Security Incident response plan or reporting incidents to ES ISAC, as per compliance requirements.
2. Violation Severity Levels: Requirement Lower Moderate High Severe R1 The Balancing Authority failed to demonstrate the existence of the necessary operating agreements for less than 25% of the adjacent BAs. Or less than 25% of those agre...
AI summary This section outlines the violation severity levels related to the failure of the Balancing Authority to demonstrate the existence of necessary operating agreements with adjacent BAs and the absence of emergency assistance provisions in those agreements, categorized into lower, moderate, high, and severe levels based on the percentage of affected agreements.
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...
AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...
AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...
AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.
Conclusion The TOP-005-1 standard does not provide, nor does it require, a definition for the term "degraded." The IRO-005-1 (R12) standard implies that degraded is a condition that will result in a failure of an SPS to operate as designed...
AI summary The conclusion discusses the absence of a definition for 'degraded' in TOP-005-1 and the implications under IRO-005-1 (R12) regarding SPS failure reporting. It highlights the need for a formal definition via a Standards Authorization Request.
Request: VAR-002 — Generator Operation for Maintaining Network Voltage Schedules, addresses the generator's provision of voltage and VAR control. Confusion exists in the industry and regions as to which requirements in this standard apply...
AI summary The document discusses confusion regarding the application of VAR-002 standards to generators without automatic voltage regulators (AVRs). Generator owners seek clarification on whether they must comply with these requirements, as they lack the necessary equipment. The response clarifies that all requirements apply regardless of AVR presence, but no requirement mandates AVR installation.
Glossary of Terms Used in NERC Reliability Standards Continent-wide Term Acronym BOT Approved Date FERC Approved Date Definition Economic Dispatch [Archive] 2/8/2005 3/16/2007 The allocation of demand to individual generating units on line...
AI summary This section provides a glossary of terms used in NERC Reliability Standards, defining key concepts such as Economic Dispatch, Electrical Energy, and Electronic Security Perimeter, along with their approval dates by the Board of Trustees and FERC.
Glossary of Terms Used in NERC Reliability Standards
AI summary This glossary defines terms used in NERC Reliability Standards, including organizations like NERC, FERC, and NSUARB, technical standards (CIP, TOP, VAR), and acronyms related to grid operations, cybersecurity, and regulatory frameworks.
Current Critical Infrastructure Protection Implementation Plans for Version 3 1
AI summary The document outlines Version 3 of Critical Infrastructure Protection (CIP) implementation plans, focusing on cybersecurity measures for the Nova Scotia power grid. It is part of regulatory proceedings by the Nova Scotia Utility and Review Board (NSUARB).
Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities This Implementation Plan applies to Cyber Security Standards CIP-002-2 through CIP-009-2 and CIP-002-3 through CIP-009-3. The term "Compliant" in...
AI summary This document outlines an implementation plan for compliance with NERC CIP-002 through CIP-009 standards, defining schedules for newly registered entities and critical cyber assets. It clarifies compliance definitions and notes that CIP-002 has no new milestones due to prior compliance requirements.
Implementation Plan for Newly Identified Critical Cyber Assets This Implementation Plan defines the Compliant milestone dates in terms of the number of calendar months after designation of the newly identified Cyber Asset as a Critical Cyb...
AI summary This Implementation Plan outlines compliance milestones for newly identified Critical Cyber Assets under NERC CIP standards. It defines timelines for Responsible Entities to achieve compliance with CIP-003 through CIP-009, depending on asset designation. Existing requirements remain unaffected, while new assets require audit records one year post-compliance milestones.
Implementation Milestone Categories The Implementation Plan milestones and schedule to achieve compliance with the NERC Reliability Standards CIP-002 through CIP-009 for newly identified Critical Cyber Assets and newly Registered Entities...
AI summary The document outlines milestones for achieving compliance with NERC CIP-002 through CIP-009 standards for Critical Cyber Assets and newly registered entities. It defines 'CIP compliance implementation program' and 'Auditably Compliant' (AC), emphasizing auditable records for compliance. The plan omits 'Auditably Compliant' dates as they follow 'Compliant' dates by one year.
Implementation Milestone Categories and Schedules Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios are defined and distinguished below fo...
AI summary The document outlines two implementation scenarios for Critical Cyber Assets under NERC CIP standards. Category 1 applies to Responsible Entities newly identifying Critical Cyber Assets without prior CIP compliance programs, while Category 2 addresses entities adding new Cyber Assets to existing compliance programs. Milestones for Category 1 are detailed in Table 2.
Newly Registered Entity Scenarios Based on the Critical Cyber Asset identification scenarios identified above, the implementation milestone categories and schedules for those scenarios as they apply to newly Registered Entities are defined...
AI summary The document outlines implementation milestones for Critical Cyber Asset scenarios applicable to newly registered entities, emphasizing compliance with NERC CIP-002 standards. Examples include business mergers and asset acquisitions, assuming predecessor entities already comply with CIP-002 and use risk-based Critical Asset identification methods.
A Merger of Two or More Registered Entities where None of the Predecessor Registered Entities has Identified any Critical Cyber Asset In the case of a business merger or asset acquisition, because there are no identified Critical Cyber Ass...
AI summary In a merger without critical cyber assets, CIP-002 risk-based asset identification must be implemented. The merged entity has one year to combine or maintain separate methodologies under common governance. Annual compliance with CIP-002 R2 is required, with potential expansion to CIP-002 R3 if critical cyber assets are later identified.
A Merger of Two or More Registered Entities where Only One of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset Since only one of the predecessor Registered Entities has previously identified Critical Cyb...
AI summary In a merger scenario where only one predecessor entity has critical cyber assets, the merged entity inherits its CIP compliance program. Other entities lack such programs as they aren't required. Post-merger, the existing CIP program applies to new critical assets. The NERC CIP-002 risk-based methodology from Scenario 1 also applies here.
A Merger of Two or More Registered Entities where Two or More of the Predecessor Registered Entities has Identified at Least One Critical Cyber Asset This scenario is the most complicated of the three, since it applies to a merged Register...
AI summary Merging entities with differing critical cyber asset identification methods and CIP compliance programs requires harmonization within one year of the merger. Disparities may arise from tools like antivirus choices or risk methodologies, necessitating governance under a common senior manager. Compliance with NERC CIP-002 is emphasized.
Example Scenarios Note that there are no implementation milestones or schedules specified for a Responsible Entity that has a newly designated Critical Asset, but no newly designated Critical Cyber Assets. This situation exists because no...
AI summary The text explains that no implementation milestones or schedules are required for a Responsible Entity when a Critical Asset is designated without associated Critical Cyber Assets. Compliance with NERC Reliability Standards CIP-003 through CIP-009 is only required upon designation of Critical Cyber Assets.
Table 1: Example Scenarios Scenarios CIP Compliance Implementation Program: No Program (note 1) Existing Program Existing Cyber Asset reclassified as Critical Cyber Asset due to change in assessment methodology Category 1 Category 2 Existi...
AI summary This table outlines scenarios related to the implementation of the CIP Compliance Implementation Program, detailing how different changes or events affect compliance status, such as reclassification of assets, new asset additions, modifications, and emergency situations.
Table 2: Implementation milestones for Newly Identified Critical Cyber Assets CIP Standard Requirement Milestone Category 1 Milestone Category 2 Standard CIP-002-2 — Critical Cyber Asset Identification R1 N/A N/A R2 N/A N/A R3 N/A N/A R4 N...
AI summary The document outlines implementation milestones for newly identified critical cyber assets under various CIP standards. It includes timelines for compliance with requirements such as security management controls, electronic security perimeters, and incident reporting.
Table 35 Compliance Schedule for Standards CIP-002-2 through CIP-009-2 or CIP-002-3 through CIP-009-3 For Entities Registering in April 2008 and Thereafter Registration + 12 months Registration + 24 months All Facilities All Facilities CIP...
AI summary Table 35 outlines a compliance schedule for CIP-002-2 through CIP-009-3 standards, specifying compliance dates for entities registering in April 2008 and beyond. It notes that all requirements are compliant except for R2 in CIP-003-2/3, and references a 2010 Revised Implementation Plan adopted by the Board of Trustees.
Applicable Standards The following standards are covered by this Implementation Plan: CIP–002–3 — Cyber Security — Critical Cyber Asset Identification CIP–003–3 — Cyber Security — Security Management Controls CIP–004–3 — Cyber Security — P...
AI summary The document outlines CIP–002–3 through CIP–009–3 cybersecurity standards for critical infrastructure protection. These standards, covering topics like cyber asset identification, security management, and incident response, are posted for ballot by NERC. Prior versions of these standards will be retired upon their effectiveness.
Implementation Plan for Newly Identified Critical Cyber Assets and Newly Registered Entities Concurrently submitted with Version 3 of Cyber Security Standards CIP-002-3 through CIP-009-3 is a separate Implementation Plan document that woul...
AI summary The document introduces an Implementation Plan to address compliance gaps for newly identified Critical Cyber Assets under NERC CIP-002-3 to CIP-009-3. It provides a phased schedule for Responsible Entities to achieve compliance, rectifying the unrealistic requirement in Version 1 to immediately attain 'Auditably Compliant' status. The plan also covers compliance for merged entities and new NERC registry registrants.
B A L- 0 0 1- 0. 1a R 1. Ea h Ba la in A ho i ha l l o h ha l l in 1 2- h ba is he t ty te t t, t t c nc g u r s p er a s uc on a ro g m on s , f f Co he lo k- in he Ba la in A ho i 's A l t te t t ty tro av er ag e o c c m u a ve ra g es...
AI summary The text discusses a matrix of violation risk factors related to information, including compliance with standards and regulations such as NERC, CIP, and others. It references various entities, acronyms, and potential violations related to reliability and compliance in the energy sector.