N-1Application
11 passages
C. Description of Proposed Reliability Standards, Second Quarter 2025 As provided in the table below, during the second quarter of 2025, FERC issued an order approving CIP-015-1 (Cyber Security – Internal Network Security Monitoring).[13](...
AI summary In the second quarter of 2025, FERC approved CIP-015-1, a reliability standard related to cyber security and internal network security monitoring. No other reliability standards applicable to Nova Scotia were approved during this period.
1. CIP-015-1, Cyber Security – Internal Network Security Monitoring On June 26, 2025, FERC issued an order approving Reliability Standard CIP-015-1 as well as the associated implementation plan, Violation Risk Factors and Violation Severit...
AI summary FERC approved Reliability Standard CIP-015-1, which mandates internal network security monitoring for high and medium impact bulk electric system cyber systems. The standard aims to improve detection of anomalous activity to enhance response and recovery from cyber attacks.
A. Introduction 1. Title: Cyber Security – Internal Network Security Monitoring 2. Number: CIP-015-1 3. Purpose: To improve the probability of detecting anomalous or unauthorized network activity in order to facilitate improved response an...
AI summary This document outlines the purpose of the CIP-015-1 standard, which aims to enhance the detection of anomalous or unauthorized network activity to improve response and recovery from cyberattacks.
4.1.4. Generator Owner - 4.1.5. Reliability Coordinator - 4.1.6. Transmission Operator - 4.1.7. Transmission Owner - 4.2. Facilities: For the purpose of the requirements contained herein, the following Facilities, systems, and equipment ow...
AI summary This section outlines the responsibilities of Generator Owners and other entities under reliability standards, including exemptions for certain cyber systems and facilities. It defines applicable facilities and systems, such as UFLS, RAS, and protection systems, and specifies exemptions for nuclear-related and low-impact cyber systems.
B. Requirements and Measures - R1. Each Responsible Entity shall implement one or more documented process(es) for internal network security monitoring of networks protected by the Responsible Entity's Electronic Security Perimeter(s) of hi...
AI summary This section outlines requirements for Responsible Entities to implement documented processes for internal network security monitoring of high and medium impact BES Cyber Systems with external routable connectivity. It specifies the need for network data feeds, detection methods, and evaluation processes for anomalous activity. Evidence of implementation is also required.
Part 1.2. - Documentation of anomalous network detection events; - Documentation of configuration settings of internal network security monitoring systems; - Documentation of network communication baseline used to detect anomalous network...
AI summary This section outlines the documentation requirements for detecting and monitoring anomalous network activity, including network security configurations, communication baselines, and alternative detection methods.
Part 1.3. - Documentation of method(s) used to evaluate anomalous activity; - Documentation of actions in response to detected anomalies; or - Documentation of escalation process(es) that could include CIP-008 Cyber Security Incident respo...
AI summary The text outlines requirements for Responsible Entities to document and retain internal network security monitoring data related to anomalous activity, including the implementation of processes to protect this data from unauthorized deletion or modification. These requirements are part of cybersecurity protocols under CIP-008.
Violation Severity Levels ‡ 6 Violation Severity Levels rerity Levels ‡ ¥ Lower VSL Moderate VSL High VSL Severe VSL R1. N/A N/A The Responsible Entity did not implement, using a risk-based rationale, network data feed(s) to monitor networ...
AI summary The document outlines different violation severity levels (Lower, Moderate, High, Severe VSL) related to cybersecurity and network monitoring requirements under CIP-008. It details specific actions that Responsible Entities must take to monitor, detect, evaluate, and protect network security data, with higher severity levels indicating more critical non-compliance.
List of Currently Effective NERC Reliability Standards BAL-001-2 Real Power Balancing Control Performance BAL-001-TRE-2 Primary Frequency Response in the ERCOT Region BAL-002-3 Disturbance Control Standard – Contingency Reserve for Recover...
AI summary This document lists currently effective NERC Reliability Standards, including those related to power balancing, frequency response, cyber security, and system restoration. These standards ensure reliability and security in the bulk-power system.
Any comments regarding this glossary should be reported to the NERC Help Desk . Select "Standards" from the "Service" drop-down menu and "Other" from the Standards Subcategory drop-down menu. Subjec Subject to Enforcement ement £10 is a co...
AI summary The text outlines definitions related to frequency performance and balancing authority areas within the context of electric reliability standards. Key terms include £10, Y, H, Bi, and Bs, which are used to calculate frequency error and frequency bias settings.
3 FERC approved the WECC Tier One Reliability Standards in the Order Approving Regional Reliability Standards for the Western Interconnection and Directing Modifications, 119 FERC ¶ 61,260 (June 8, 2007). In that Order, FERC directed WECC...
AI summary The document outlines updates and changes to WECC Regional Definitions, including modifications to terms like ACE, System Voltage Limit, and Automatic Time Error Correction, as well as the retirement of certain terms such as Reportable Cyber Security Incident. These updates were approved by FERC in 2007 and further developed in 2009.