HomeCybersecurityM12436Evidence
Topic/Matter Intersection

Topic:"Cybersecurity" in M12436

Matter: North American Electric Reliability Corporation (NERC) - Second Quarter 2025  - Application for Approval of Reliability Standards
16 passages 4 documents

Cybersecurity across all matters →

N-1Application 11 passages
C. Description of Proposed Reliability Standards, Second Quarter 2025 p. p. 6
C. Description of Proposed Reliability Standards, Second Quarter 2025 As provided in the table below, during the second quarter of 2025, FERC issued an order approving CIP-015-1 (Cyber Security – Internal Network Security Monitoring).[13](...

AI summary In the second quarter of 2025, FERC approved CIP-015-1, a reliability standard related to cyber security and internal network security monitoring. No other reliability standards applicable to Nova Scotia were approved during this period.

1. CIP-015-1, Cyber Security – Internal Network Security Monitoring p. pp. 6-7
1. CIP-015-1, Cyber Security – Internal Network Security Monitoring On June 26, 2025, FERC issued an order approving Reliability Standard CIP-015-1 as well as the associated implementation plan, Violation Risk Factors and Violation Severit...

AI summary FERC approved Reliability Standard CIP-015-1, which mandates internal network security monitoring for high and medium impact bulk electric system cyber systems. The standard aims to improve detection of anomalous activity to enhance response and recovery from cyber attacks.

A. Introduction p. p. 10
A. Introduction 1. Title: Cyber Security – Internal Network Security Monitoring 2. Number: CIP-015-1 3. Purpose: To improve the probability of detecting anomalous or unauthorized network activity in order to facilitate improved response an...

AI summary This document outlines the purpose of the CIP-015-1 standard, which aims to enhance the detection of anomalous or unauthorized network activity to improve response and recovery from cyberattacks.

4.1.4. Generator Owner p. p. 10
4.1.4. Generator Owner - 4.1.5. Reliability Coordinator - 4.1.6. Transmission Operator - 4.1.7. Transmission Owner - 4.2. Facilities: For the purpose of the requirements contained herein, the following Facilities, systems, and equipment ow...

AI summary This section outlines the responsibilities of Generator Owners and other entities under reliability standards, including exemptions for certain cyber systems and facilities. It defines applicable facilities and systems, such as UFLS, RAS, and protection systems, and specifies exemptions for nuclear-related and low-impact cyber systems.

B. Requirements and Measures p. p. 10
B. Requirements and Measures - R1. Each Responsible Entity shall implement one or more documented process(es) for internal network security monitoring of networks protected by the Responsible Entity's Electronic Security Perimeter(s) of hi...

AI summary This section outlines requirements for Responsible Entities to implement documented processes for internal network security monitoring of high and medium impact BES Cyber Systems with external routable connectivity. It specifies the need for network data feeds, detection methods, and evaluation processes for anomalous activity. Evidence of implementation is also required.

Part 1.2. p. p. 10
Part 1.2. - Documentation of anomalous network detection events; - Documentation of configuration settings of internal network security monitoring systems; - Documentation of network communication baseline used to detect anomalous network...

AI summary This section outlines the documentation requirements for detecting and monitoring anomalous network activity, including network security configurations, communication baselines, and alternative detection methods.

Part 1.3. p. p. 10
Part 1.3. - Documentation of method(s) used to evaluate anomalous activity; - Documentation of actions in response to detected anomalies; or - Documentation of escalation process(es) that could include CIP-008 Cyber Security Incident respo...

AI summary The text outlines requirements for Responsible Entities to document and retain internal network security monitoring data related to anomalous activity, including the implementation of processes to protect this data from unauthorized deletion or modification. These requirements are part of cybersecurity protocols under CIP-008.

Violation Severity Levels p. p. 10
Violation Severity Levels ‡ 6 Violation Severity Levels rerity Levels ‡ ¥ Lower VSL Moderate VSL High VSL Severe VSL R1. N/A N/A The Responsible Entity did not implement, using a risk-based rationale, network data feed(s) to monitor networ...

AI summary The document outlines different violation severity levels (Lower, Moderate, High, Severe VSL) related to cybersecurity and network monitoring requirements under CIP-008. It details specific actions that Responsible Entities must take to monitor, detect, evaluate, and protect network security data, with higher severity levels indicating more critical non-compliance.

List of Currently Effective NERC Reliability Standards p. p. 10
List of Currently Effective NERC Reliability Standards BAL-001-2 Real Power Balancing Control Performance BAL-001-TRE-2 Primary Frequency Response in the ERCOT Region BAL-002-3 Disturbance Control Standard – Contingency Reserve for Recover...

AI summary This document lists currently effective NERC Reliability Standards, including those related to power balancing, frequency response, cyber security, and system restoration. These standards ensure reliability and security in the bulk-power system.

Any comments regarding this glossary should be reported to the NERC Help Desk . Select "Standards" from the "Service" drop-down menu and "Other" from the Standards Subcategory drop-down menu. p. p. 10
Any comments regarding this glossary should be reported to the NERC Help Desk . Select "Standards" from the "Service" drop-down menu and "Other" from the Standards Subcategory drop-down menu. Subjec Subject to Enforcement ement £10 is a co...

AI summary The text outlines definitions related to frequency performance and balancing authority areas within the context of electric reliability standards. Key terms include £10, Y, H, Bi, and Bs, which are used to calculate frequency error and frequency bias settings.

WECC Regi WECC Regional Definitions tions p. p. 10
3 FERC approved the WECC Tier One Reliability Standards in the Order Approving Regional Reliability Standards for the Western Interconnection and Directing Modifications, 119 FERC ¶ 61,260 (June 8, 2007). In that Order, FERC directed WECC...

AI summary The document outlines updates and changes to WECC Regional Definitions, including modifications to terms like ACE, System Voltage Limit, and Automatic Time Error Correction, as well as the retirement of certain terms such as Reportable Cyber Security Incident. These updates were approved by FERC in 2007 and further developed in 2009.

100226Board Decision Letter 2 passages
M12436 - North American Electric Reliability Corporation (NERC) - Second Quarter 2025 - Application for Approval of Reliability Standards p. p. 0
M12436 - North American Electric Reliability Corporation (NERC) - Second Quarter 2025 - Application for Approval of Reliability Standards The Board reviewed the following filing from the North American Electric Reliability Corporation (NER...

AI summary The Board reviewed NERC's application for approval of revised Reliability Standards, specifically CIP-015-1, which focuses on cybersecurity. NS Power indicated that compliance will require capital project support and recommended approval of the standards. Section 67(2) of the More Access to Energy Act requires the Board to consider reliability standards before approval.

LIST OF STANDARDS APPROVED p. p. 1
LIST OF STANDARDS APPROVED Reliability Standard Description NERC Effective Date (m/d/y) Nova Scotia Effective Date (m/d//y) Critical Infrastructure Protection (CIP) CIP-015-1 Cyber Security – Internal Network Security Monitoring 10/01/2028...

AI summary The document lists reliability standards approved for Nova Scotia, including the Critical Infrastructure Protection (CIP-015-1) standard related to cyber security and internal network security monitoring. Compliance dates are specified for different types of control centers and systems.

99716Comments - NSPI 1 passage
6 p. p. 5
6 Reliability Standard CIP-015-1 (Cyber Security – Internal Network Security Monitoring) Group Critical Infrastructure Protection (CIP) Current version in Effect in Nova Scotia New Standard, no version in effect in Nova Scotia. Applicabili...

AI summary This document outlines the applicability and implementation plan for the CIP-015-1 reliability standard in Nova Scotia, which NS Power recommends be approved. The standard applies to NS Power due to its roles as a Balancing Authority, Distribution Provider, and Transmission Operator. The effective date is contingent on NSEB approval and will be recalculated if approval is delayed.

100226Board Decision Letter 2 passages
M12436 - North American Electric Reliability Corporation (NERC) - Second Quarter 2025 - Application for Approval of Reliability Standards p. p. 0
M12436 - North American Electric Reliability Corporation (NERC) - Second Quarter 2025 - Application for Approval of Reliability Standards The Board reviewed the following filing from the North American Electric Reliability Corporation (NER...

AI summary The Board reviewed NERC's application to approve revised Reliability Standards, specifically CIP-015-1, which focuses on cybersecurity. NS Power provided comments, noting the need for capital project support to implement the standards. The Board must consider Section 67(2) of the More Access to Energy Act before approving the standards.

LIST OF STANDARDS APPROVED p. p. 1
LIST OF STANDARDS APPROVED Reliability Standard Description NERC Effective Date (m/d/y) Nova Scotia Effective Date (m/d//y) Critical Infrastructure Protection (CIP) CIP-015-1 Cyber Security – Internal Network Security Monitoring 10/01/2028...

AI summary The document lists approved reliability standards, including CIP-015-1, which outlines cybersecurity requirements for internal network security monitoring. Compliance dates are specified for different types of control centers and systems in Nova Scotia, with future effective dates set by NERC and the Nova Scotia Power Incorporated.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →