Efficiency and Effectiveness of Stakeholder Engagement

Size: px
Start display at page:

Download "Efficiency and Effectiveness of Stakeholder Engagement"

Transcription

1 Efficiency and Effectiveness of Stakeholder Engagement Michael Walker, Senior Vice President and Chief Enterprise Risk and Strategic Development Officer Member Representatives Committee Meeting February 7, 2018

2 Background ERO Enterprise Long-Term Strategy and Operating Plan recognize the importance of effective industry expertise Emerging issues are increasing resource demands on both industry and the ERO Enterprise There are opportunities to improve efficiency and effectiveness for the benefit of stakeholders, the ERO Enterprise, and reliability Requested policy input on ways to improve efficiency and effectiveness of stakeholder engagement 2

3 Themes of Policy Input Responses Include wider stakeholder involvement in effectiveness and efficiency reviews Review stakeholder committee organization and charters Track and share stakeholder time devoted to ERO groups Leverage technology to reduce travel time and costs Enhance ERO staff training and tools to engage stakeholders Increase communications with and among segments and sectors Increase executive-level stakeholder involvement Avoid duplicate work within the ERO Enterprise and between the ERO Enterprise and industry 3

4 Next Steps Open discussion of input during MRC meeting Obtain feedback from Board of Trustees Follow-up discussion at the May meeting 4

5 5

6 ERO Reliability Risk Priorities Report Peter Brandien, Reliability Issues Steering Committee Chair Member Representatives Committee Meeting February 7, 2018

7 Purpose and Process Strategically defines and prioritizes risks to the reliable operation of the bulk power system (BPS) Supports ERO Enterprise strategic and operational planning Key inputs Reliability Issues Steering Committee s (RISC s) subject matter expertise Reliability Leadership Summit FERC Technical Conference Pulse point interviews Review of a number of NERC technical studies Department of Energy grid study 2

8 Risk Profiles and Recommendations Nine inherent risk profiles for continued level of attention No new profiles; shift in Profile 4 from asset management and maintenance to increasing complexity in protection and control systems Includes recommended actions to mitigate the risks Effort to narrow recommendations since last draft Reduced 99 recommendations to 53 Removed overlapping recommendations and those captured in ongoing activities 3

9 Risk Groupings Risk profiles categorized by mapping of likelihood and impact RISC recommends higher likelihood, higher impact profiles be given highest priority All risk profiles warrant attention regardless of categorization Higher Likelihood, Higher Impact Cybersecurity Vulnerabilities Changing Resource Mix BPS Planning Resource Adequacy 4

10 Risk Groupings Higher Likelihood, Lower Impact Increasing Complexity in Protection and Control Systems Human Performance and Skilled Workforce Lower Likelihood, Higher Impact Loss of Situational Awareness Lower Likelihood, Lower Impact Physical Security Vulnerabilities Extreme Natural Events 5

11 Risk Mapping 6

12 Next Steps Present report to Board of Trustees (Board) for acceptance on February 8, 2018 Next Reliability Leadership Summit Q1/Q Next report to Board August

13 8

14 Resilience Framework Peter Brandien, Reliability Issues Steering Committee Chair Member Representatives Committee Meeting February 7, 2018

15 Recommended Framework Develop common understanding and definition of the key elements of bulk power system (BPS) resilience Understand how key elements of BPS resilience fit in the existing ERO framework Evaluate whether additional steps are needed to address key elements of BPS resilience within the ERO framework 2

16 Understanding and Defining Resilience National Infrastructure Advisory Council s (NIAC s) resilience framework includes four outcome-focused abilities: Robustness absorb shocks and continue operating Resourcefulness skillfully manage a crisis as it unfolds Rapid Recovery get services back as quickly as possible Adaptability incorporate lessons learned from past events to improve resilience 3

17 ERO Enterprise Activities Supporting NIAC Framework Robustness Risk, event, and performance monitoring Reliability and emerging risk assessments Technical committee work Operator training and certification Reliability Standards and Reliability Guidelines E-ISAC information-sharing programs Resourcefulness Situational awareness and industry coordination Government coordination Cross-sector information sharing Reliability Standards and Functional Model 4

18 ERO Enterprise Activities Supporting NIAC Framework Rapid Recovery Situational awareness and industry coordination Government coordination Cross-sector information sharing Adaptability Reliability assessments Event analysis and forensics Reliability Guidelines Technical committee work 5

19 Recommended Next Steps Request standing committee input to the RISC Provide recommendations at the May 2018 Member Representatives Committee meeting Monitor FERC proceedings 6

20 7

21 2017 Reliability Assessments Standard and Guideline Recommendations Mark Lauby, Senior Vice President and Chief Reliability Officer Member Representatives Committee February 7, 2018

22 Evaluating Emerging Risks Through Assessments Key assessments from 2017 Special Reliability Assessment: Potential Bulk Power System Impacts Due to Severe Disruptions on the Natural Gas System 2017 Long-Term Reliability Assessment Recommendations aligned with RISC priorities 2

23 Special Reliability Assessment Objective of report: Evaluate disruptions of key natural gas facilities and their impact to BPS reliability Recommendation: NERC, with industry s support, should enhance its Reliability Guidelines and/or Standards as necessary to include additional planning and operating requirements for analyzing disruptions to the natural gas infrastructure and their impacts on the reliable operation of the BPS 3

24 Special Reliability Assessment Current Plan of Action: Planning Committee advisory group forming Review current requirements (e.g., TPL-001-4) Identify the need and scope for a Reliability Guideline Determine if existing controls are in place to assure extreme conditions due to natural gas disruptions are considered in planning Next Step: Plan of action will be presented for policy input in April 2018 An update of progress will be provided on a quarterly basis 4

25 2017 Long-Term Reliability Assessment Objective of Report: Review, assess, and report on the overall electric generation and transmission reliability of the BPS Recommendation: NERC should conduct a comprehensive evaluation of its Reliability Standards to ensure compatibility with nonsynchronous and distributed energy resources as well as for completeness related to essential reliability services, generator performance, system protection and control, and balancing functions. 5

26 2017 Long-Term Reliability Assessment Significant activity in progress: Revisions planned for MOD-032 to address data sharing Inverter-Based Resources Task Force (Reliability Guideline and Alert) Standard Authorization Request in place to address frequency control and balancing PC assessment of BES-connected dynamic reactive devices Next Steps: Standing Committee Coordinating Group to monitor progress across technical committees An update of progress will be provided on a quarterly basis 6

27 7

28 CIPC Workplan Update Critical Infrastructure Protection Committee Marc A. Child, Great River Energy, CIPC Chair Member Representatives Committee Meeting February 7, 2018

29 CIPC Organizational Chart Executive Committee Ross Johnson, Phys SME, Capital Power Marc Child, Chair, Great River Energy Melanie Seader, EEI Brenda Davis, Cyber SME, CPS Energy David Grubbs, Vice Chair, City of Garland (vacant) APPA Lisa Carrington, Ops SME, Ariz Public Svc David Revill, Vice Chair, NRECA (vacant) EPSA Jeff Fuller, Policy SME, AES Tobias Whitney, Secretary, NERC (vacant) IPC Physical Security Subcommittee (Ross Johnson) Cybersecurity Subcommittee (Brenda Davis) Operating Security Subcommittee (Lisa Carrington) Policy Subcommittee (Jeff Fuller) Physical Security WG (PSAG) (Ross Johnson) Control Systems Security WG (Mike Mertz) (Carter Manucy) Grid Exercise WG (Tim Conway) Security Metrics WG (Larry Bugh) Physical Security Guidelines TF (Darrell Klimitchek) Security Training WG (David Godfrey) (Amelia Sawyer) Planning Committee Joint Project Criticality Reduction (Vacant) Compliance and Enforcement Input WG (Paul Crist) Supply Chain Working Group (Vacant) 2

30 CIPC Charter Key updates to CIPC Charter: Minor verbiage update to acknowledge security guidelines and standards implementation guidance are key deliverables of CIPC Added IEEE to the list of key collaborative organizations Added new non-voting member class: Partner Members Federal Energy Regulatory Commission US Department of Homeland Security US Department of Energy US Department of Energy Laboratories Public Safety Canada Natural Resources Canada Oil & Natural Gas subsector Telecomm sector Financial Services sector Critical Manufacturing sector Water sector 3

31 CIPC Strategic Plan and Work Plan Strategic Plan & Work Plan Change in format to better align with the Electric Reliability Organization (ERO) strategic goals ERO Enterprise Long-Term Strategy ERO Reliability Risk Priorities ( RISC Report ) E-ISAC Long Term Strategic Plan Appendix removed to reduce redundancy and enhance readability Organized into six major activities Advisory panel to the NERC Board of Trustees (Board) Cyber security risk management Physical security risk management NERC standards implementation input BES security metrics Training, outreach, and industry communications 4

32 Advisory Panel to the Board Reports to the Board will become more strategic to address emerging risks and issues pertinent to the security of BES Solicit input from the Board regarding priorities and new challenges Identify opportunities for collaboration with other subcommittees Less focus on status reporting and more focus on the proactive resolution of issues 5

33 Cyber Security Risk Management Cyber security program efforts address the RISC, E-ISAC Long Term Strategic Plan, and the ERO Enterprise Long Term Strategy Identification and reduction of cyber risks Cyber security risk of Fuel Handling SCADA systems for Generation Updated guidance in relation to NERC s Remote Access Study GridEx planning and preparation Supply Chain (vendor security controls and legacy systems testing) 6

34 Physical Security Risk Management Physical security program efforts address the RISC, E-ISAC Long Term Strategic Plan, and the ERO Enterprise Long Term Strategy Identification and reduction of physical risks Security practices for High Impact Control Centers Security implications of drones on electric power Key management security for physical access 7

35 NERC Standards Implementation Input The Compliance and Enforcement Input Working Group (CEIWG) is established to solicit industry stakeholders for input to assist NERC staff with clarification on compliance monitoring or enforcement with the following documents: Implications of Cloud Services for CIP Assets (Pilot/Study) Implementation Guidance for Voice-over-IP services Implementation Guidance for Shared Transmission Facilities 8

36 BES Security Metrics CIPC will utilize the expertise of its members, NERC staff, and others to provide direction, technical oversight, feedback on the collection of industry metrics, and reporting of BES security performance metrics Security Metrics derived from E-ISAC, compliance data, or other sources of periodic reporting Annual security assessment of the BES 9

37 Training, Outreach, and Communications CIPC will provide training, coordination, and communication with those responsible for both physical and cyber security to various industry segments Re-organize information on NERC.com Industry facing collaboration site to maximize joint project activities Publish annual training plan 10

38 Timeline of Activities # CIPC Deliverable (non-ongoing projects) Estimated Completion Date 1 Implications of Voice-over-IP and the CIP Standards Q Develop CIPC Collaboration Site on NERC.com Q CIP Implications of Shared Transmission Facilities Q Key management security guideline Q Vendor Essential Security Practices Model Q Security implications of UAVs Q Update CIPC Website on NERC.com Q Implications of Cloud Services for CIP Assets Q Assess the cyber security risk of Fuel Handling SCADA systems for Generation Q Address Remote Access Security Findings #1-#18 Q Identification and Reduction of Cyber and Physical Security Risks Q Legacy system testing coordination with National Labs Q Annual Security Assessment of the BES Q

39 12

40 Michael Bardee, Director FERC Office of Electric Reliability February 7, 2018

41 Final Rule, RM , 1/18/18 Approves revised reliability standards: Event Reporting (EOP-004-4) System Restoration from Blackstart Resources (EOP-005-3) System Restoration Coordination (EOP-006-3) Loss of Control Center Functionality (EOP-008-2) Revised standards will: Provide accurate reporting to NERC s event analysis group Specify roles of entities to restore system from blackstart resources Clarify procedures & coordination for RC staff to restore system Refine requirements to continue reliable operation if primary control functionality is lost Effective 60 days after publication in the Federal Register

42 Proposed Rule, RM17-13, 1/18/18 Proposes to approve supply chain risk management CIP reliability standards: Supply Chain Risk Management (CIP-013-1) Electronic Security Perimeter(s) (CIP-005-6) Configuration Change Management (CIP-010-3) Proposes to direct NERC to expand these standards to include EACMS for medium- and high-impact; and expand study of low-impact to include PACs and PCAs Comments due 60 days after publication in Fed. Reg.

43 Proposed Rule, RM18-2 & AD17-9, 12/21/17 Proposes to direct NERC to broaden CIP-008 to include mandatory reporting of cyber security incidents that compromise, or attempt to compromise, an entity s Electronic Security Perimeter or associated EACMS Proposes that incident reports be sent to ICS-CERT (in addition to E-ISAC) and that NERC file an annual, public and anonymized summary with FERC Comments due 2/26/18

44 Order Accepting Filing, RR , 11/16/17 Accepts NERC s 2016 Compliance Monitoring and Enforcement Program (CMEP) Annual Report Denies two changes proposed by NERC: Eliminate public posting of CEs identified through self-logging Allow CEs to include certain moderate risk non-compliance Terminates the annual informational filing requirement so long as NERC continues to include: Compliance exceptions in the annual FFT filing Information on RAI program in CMEP report to BOTCC

45 Proposed Rule, RM16-22, 11/16/17 Proposes to approve: PRC (Coordination of Protection Systems for Performance During Faults) PER (Specific Training for Personnel) Proposes to direct NERC to expand PRC to require an initial protection system coordination study as baseline for proper coordination of their systems Comments due 1/28/18

46 Order issued in AD18-7 & RM18-1, 1/8/18 Terminates DOE NOPR on grid resilience Opens new proceeding to examine grid resilience Directs RTOs/ISOs to provide information. Goal: Develop common understanding among Commission, industry and others of what resilience of bulk power system means and requires Understand how each RTO/ISO assesses resilience in its footprint Use this info to evaluate whether additional Commission action on resilience is appropriate RTO/ISO submissions due 60 days after 1/8/18; reply comments 30 days later

47 Thank you! Questions?

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2018-2019 CIPC Executive Committee Updated:xxxxxxxx NERC Report Title Report Date I Table of Contents Preface... iii CIPC Organizational Structure...

More information

ERO Reliability Risk Priorities Report. Peter Brandien, Reliability Issues Steering Committee Chair WECC Reliability Workshop March 21, 2018

ERO Reliability Risk Priorities Report. Peter Brandien, Reliability Issues Steering Committee Chair WECC Reliability Workshop March 21, 2018 ERO Reliability Risk Priorities Report Peter Brandien, Reliability Issues Steering Committee Chair WECC Reliability Workshop March 21, 2018 Reliability Issues Steering Committee (RISC) Background 2 RISC

More information

Critical Infrastructure Protection Version 5

Critical Infrastructure Protection Version 5 Critical Infrastructure Protection Version 5 Tobias Whitney, Senior CIP Manager, Grid Assurance, NERC Compliance Committee Open Meeting August 9, 2017 Agenda Critical Infrastructure Protection (CIP) Standards

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2015-2018 CIPC Executive Committee Updated: December 13, 2016 NERC Report Title Report Date I Table of Contents Preface... iv Executive Summary...

More information

NERC Critical Infrastructure Protection Committee (CIPC) Highlights

NERC Critical Infrastructure Protection Committee (CIPC) Highlights NERC Critical Infrastructure Protection Committee (CIPC) Highlights Mike Kraft, Basin Electric Power Cooperative MRO Board of Directors Meeting March 17, 2016 Midwest Reliability Organization Standards

More information

CIP Version 5 Transition. Steven Noess, Director of Compliance Assurance Member Representatives Committee Meeting November 12, 2014

CIP Version 5 Transition. Steven Noess, Director of Compliance Assurance Member Representatives Committee Meeting November 12, 2014 CIP Version 5 Transition Steven Noess, Director of Compliance Assurance Member Representatives Committee Meeting November 12, 2014 Purpose of the Transition Program Transitioning entities confident in

More information

Power System Resilience & Reliability. Robert W. Cummings Senior Director of Engineering and Reliability Initiatives i-pcgrid March 28, 2017

Power System Resilience & Reliability. Robert W. Cummings Senior Director of Engineering and Reliability Initiatives i-pcgrid March 28, 2017 Power System Resilience & Reliability Robert W. Cummings Senior Director of Engineering and Reliability Initiatives i-pcgrid March 28, 2017 NERC, Reliability, & Resilience NERC has addressed reliability

More information

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION ) )

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION ) ) UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION Cyber Security Incident Reporting Reliability Standards ) ) Docket Nos. RM18-2-000 AD17-9-000 COMMENTS OF THE NORTH AMERICAN ELECTRIC

More information

ERO Enterprise Strategic Planning Redesign

ERO Enterprise Strategic Planning Redesign ERO Enterprise Strategic Planning Redesign Mark Lauby, Senior Vice President and Chief Reliability Officer Member Representatives Committee Meeting February 10, 2016 Strategic Planning Redesign Current

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2013-2016 CIPC Executive Committee 5/14/2013 3353 Peachtree Road NE Suite 600, North Tower Atlanta, Georgia 30326 404-446-2560 www.nerc.com Table

More information

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 I. Vision A highly reliable and secure bulk power system in the Electric Reliability Council of Texas

More information

ERO Reliability Risk Priorities Report. Peter Brandien, RISC Chair Member Representatives Committee Meeting November 1, 2016

ERO Reliability Risk Priorities Report. Peter Brandien, RISC Chair Member Representatives Committee Meeting November 1, 2016 ERO Reliability Risk Priorities Report Peter Brandien, RISC Chair Member Representatives Committee Meeting November 1, 2016 RISC s Proposed 2016 Risk Profiles Changing Resource Mix Bulk Power System Planning

More information

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013 Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013 Purpose and Scope The purpose of the Electricity Sub-Sector Coordinating Council (ESCC) is to facilitate and support

More information

Grid Security & NERC

Grid Security & NERC Grid Security & NERC Janet Sena, Senior Vice President, Policy and External Affairs Southern States Energy Board 2017 Associate Members Winter Meeting February 27, 2017 Recent NERC History Energy Policy

More information

Reliability Standards Development Plan

Reliability Standards Development Plan Reliability Standards Development Plan Steven Noess, Director of Standards Development Standards Oversight and Technology Committee Meeting November 1, 2016 2017-2019 Reliability Standards Development

More information

Chapter X Security Performance Metrics

Chapter X Security Performance Metrics Chapter X Security Performance Metrics Page 1 of 9 Chapter X Security Performance Metrics Background For the past two years, the State of Reliability report has included a chapter for security performance

More information

Cyber Security Incident Report

Cyber Security Incident Report Cyber Security Incident Report Technical Rationale and Justification for Reliability Standard CIP-008-6 January 2019 NERC Report Title Report Date I Table of Contents Preface... iii Introduction... 1 New

More information

Reliability Issues Steering Committee

Reliability Issues Steering Committee Reliability Issues Steering Committee Report on Resilience November 8, 2018 NERC Report Title Report Date I Table of Contents Preface... iii Executive Summary... iv Introduction... vi Chapter 1: The RISC

More information

Chapter X Security Performance Metrics

Chapter X Security Performance Metrics Chapter X Security Performance Metrics Page 1 of 10 Chapter X Security Performance Metrics Background For many years now, NERC and the electricity industry have taken actions to address cyber and physical

More information

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016 Grid Security & NERC Council of State Governments The Future of American Electricity Policy Academy Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016 1965 Northeast blackout

More information

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION. Foundation for Resilient Societies ) Docket No.

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION. Foundation for Resilient Societies ) Docket No. UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION Foundation for Resilient Societies ) Docket No. AD17-9-000 COMMENTS OF THE NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION IN OPPOSITION

More information

Cyber Security Reliability Standards CIP V5 Transition Guidance:

Cyber Security Reliability Standards CIP V5 Transition Guidance: Cyber Security Reliability Standards CIP V5 Transition Guidance: ERO Compliance and Enforcement Activities during the Transition to the CIP Version 5 Reliability Standards To: Regional Entities and Responsible

More information

New Brunswick 2018 Annual Implementation Plan Version 1

New Brunswick 2018 Annual Implementation Plan Version 1 New Brunswick Energy and Utilities Board Reliability Standards, Compliance and Enforcement Program New Brunswick 2018 Annual Implementation Plan Version 1 December 28, 2017 Table of Contents Version History...

More information

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2019 NERC Staff Organization Chart Budget 2019 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Officer Senior Vice President, General Counsel and Corporate

More information

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2019 NERC Staff Organization Chart Budget 2019 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel and Corporate

More information

Agenda Critical Infrastructure Protection Committee March 6, :00 p.m. 5:00 p.m. Eastern March 7, :00 a.m. Noon Eastern

Agenda Critical Infrastructure Protection Committee March 6, :00 p.m. 5:00 p.m. Eastern March 7, :00 a.m. Noon Eastern Agenda Critical Infrastructure Protection Committee March 6, 2018 1:00 p.m. 5:00 p.m. Eastern March 7, 2018 8:00 a.m. Noon Eastern Hyatt Regency Jacksonville Riverfront 225East Coastline Drive Jacksonville,

More information

ERO Enterprise IT Projects Update

ERO Enterprise IT Projects Update ERO Enterprise IT Projects Update Stan Hoptroff, Vice President, Chief Technology Officer and Director of Information Technology Technology and Security Committee Meeting November 6, 2018 Agenda ERO IT

More information

Electric Reliability Organization Enterprise Operating Plan

Electric Reliability Organization Enterprise Operating Plan Electric Reliability Organization Enterprise Operating Plan Approved by the NERC Board of Trustees: November 2017 NERC Report Title Report Date I Table of Contents Preface... iii Introduction... 1 Vision,

More information

FERC Reliability Technical Conference Panel III: ERO Performance and Initiatives ESCC and the ES-ISAC

FERC Reliability Technical Conference Panel III: ERO Performance and Initiatives ESCC and the ES-ISAC : ERO Performance and Initiatives June 4, 2015 Chairman Bay, Commissioners, and fellow panelists, I appreciate the opportunity to address the topics identified for the third panel of today s important

More information

Standard Development Timeline

Standard Development Timeline Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard is adopted by the NERC Board of Trustees (Board).

More information

NERC Staff Organization Chart Budget 2018

NERC Staff Organization Chart Budget 2018 NERC Staff Organization Chart Budget 2018 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel and Corporate

More information

Québec Reliability Standards Compliance Monitoring and Enforcement Program Implementation Plan Annual Implementation Plan

Québec Reliability Standards Compliance Monitoring and Enforcement Program Implementation Plan Annual Implementation Plan Québec Reliability Standards Compliance Monitoring and Enforcement Program Implementation Plan 2017 Annual Implementation Plan Effective Date: January 1, 2017 Approved by the Régie: December 1, 2016 Table

More information

NERC Staff Organization Chart Budget 2017

NERC Staff Organization Chart Budget 2017 NERC Staff Organization Chart Budget 2017 President and CEO Administrative Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel

More information

2018 MRO Regional Risk Assessment

2018 MRO Regional Risk Assessment MIDWEST RELIABILITY ORGANIZATION 2018 MRO Regional Risk Assessment Ben Lewiski, Risk Assessment and Mitigation Engineer November 28, 2017 Improving RELIABILITY and mitigating RISKS to the Bulk Power System

More information

Cyber Security Standards Drafting Team Update

Cyber Security Standards Drafting Team Update Cyber Security Standards Drafting Team Update Michael Assante, VP & Chief Security Officer North American Electric Reliability Corp. February 3, 2008 Overview About NERC Project Background Proposed Modifications

More information

Compliance Monitoring and Enforcement Program Technology Project Update

Compliance Monitoring and Enforcement Program Technology Project Update Compliance Monitoring and Enforcement Program Technology Project Update Stan Hoptroff, Vice President, Chief Technology Officer and Director of Information Technology Technology and Security Committee

More information

Physical Security Reliability Standard Implementation

Physical Security Reliability Standard Implementation Physical Security Reliability Standard Implementation Attachment 4b Action Information Background On March 7, 2014, the Commission issued an order directing NERC to submit for approval, within 90 days,

More information

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016

Standards. Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016 Standards Howard Gugel, Director of Standards Board of Trustees Meeting February 11, 2016 Balancing Authority Reliability-based Controls Reliability Benefits Data requirements for Balancing Authority (BA)

More information

Agenda Critical Infrastructure Protection Committee March 8, :00 5:00 p.m. Eastern March 9, :00 a.m. Noon Eastern

Agenda Critical Infrastructure Protection Committee March 8, :00 5:00 p.m. Eastern March 9, :00 a.m. Noon Eastern Agenda Critical Infrastructure Protection Committee March 8, 2017 1:00 5:00 p.m. Eastern March 9, 2017 8:00 a.m. Noon Eastern Ritz-Carlton Buckhead 3434 Peachtree Road Atlanta, GA 30326 Room: Salon 2678

More information

HPH SCC CYBERSECURITY WORKING GROUP

HPH SCC CYBERSECURITY WORKING GROUP HPH SCC A PRIMER 1 What Is It? The cross sector coordinating body representing one of 16 critical infrastructure sectors identified in Presidential Executive Order (PPD 21) A trust community partnership

More information

NERC Staff Organization Chart Budget 2017

NERC Staff Organization Chart Budget 2017 NERC Staff Organization Chart Budget 2017 President and CEO Administrative Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel

More information

Industry role moving forward

Industry role moving forward Industry role moving forward Discussion with National Research Council, Workshop on the Resiliency of the Electric Power Delivery System in Response to Terrorism and Natural Disasters February 27-28, 2013

More information

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1,

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1, EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1, 2008 www.morganlewis.com Overview Reliability Standards Enforcement Framework Critical Infrastructure Protection (CIP)

More information

Standards Development Update

Standards Development Update Standards Development Update Steven Noess, Director of Standards Development FRCC Reliability Performance Industry Outreach Workshop September 20, 2017 Supply Chain Risk Management 1 Cyber Security Supply

More information

Member Representatives Committee. Pre-Meeting and Informational Webinar January 16, 2013

Member Representatives Committee. Pre-Meeting and Informational Webinar January 16, 2013 Member Representatives Committee Pre-Meeting and Informational Webinar January 16, 2013 Objectives Review preliminary agenda topics for February 6 Member Representatives Committee (MRC) meeting. Review

More information

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management Remarks of Marcus Sachs, Senior Vice President and the Chief Security Officer North American Electric Reliability

More information

Critical Infrastructure Protection Committee Draft Minutes September 16-17, 2014

Critical Infrastructure Protection Committee Draft Minutes September 16-17, 2014 Critical Infrastructure Protection Committee Draft Minutes September 16-17, 2014 Hyatt Regency Vancouver 655 Burrard Street Vancouver, BC, Canada V6C2R7 The Critical Infrastructure Protection Committee

More information

Agenda Critical Infrastructure Protection Committee September 12, :00 5:00 p.m. Eastern September 13, :00 a.m.

Agenda Critical Infrastructure Protection Committee September 12, :00 5:00 p.m. Eastern September 13, :00 a.m. Agenda Critical Infrastructure Protection Committee September 12, 2017 1:00 5:00 p.m. Eastern September 13, 2017 8:00 a.m. Noon Eastern The Hilton Quebec 1100, boul. René-Lévesque Est Quebec, QC, G1R 4P3

More information

Standard Development Timeline

Standard Development Timeline Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard is adopted by the NERC Board of Trustees (Board).

More information

WECC Internal Controls Evaluation Process WECC Compliance Oversight Effective date: October 15, 2017

WECC Internal Controls Evaluation Process WECC Compliance Oversight Effective date: October 15, 2017 WECC Internal Controls Evaluation Process WECC Compliance Oversight Effective date: October 15, 2017 155 North 400 West, Suite 200 Salt Lake City, Utah 84103-1114 WECC Internal Controls Evaluation Process

More information

The NIST Cybersecurity Framework

The NIST Cybersecurity Framework The NIST Cybersecurity Framework U.S. German Standards Panel 2018 April 10, 2018 Adam.Sedgewick@nist.gov National Institute of Standards and Technology About NIST Agency of U.S. Department of Commerce

More information

NERC Staff Organization Chart 2015 Budget

NERC Staff Organization Chart 2015 Budget NERC Staff Organization Chart President and CEO (Dept. 2100) Executive Assistant (Dept. 2100) Associate Director, Member Relations and MRC Secretary (Dept. 2100) Senior Vice President and Chief Reliability

More information

July 5, Mr. John Twitty, Chair NERC Member Representatives Committee. Dear John:

July 5, Mr. John Twitty, Chair NERC Member Representatives Committee. Dear John: July 5, 2017 Mr. John Twitty, Chair NERC Member Representatives Committee Dear John: I invite the Member Representatives Committee (MRC) to provide policy input on one issue of particular interest to the

More information

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure Executive Order 13800 Update July 2017 In Brief On May 11, 2017, President Trump issued Executive Order 13800, Strengthening

More information

Scope Cyber Attack Task Force (CATF)

Scope Cyber Attack Task Force (CATF) Scope Cyber Attack Task Force (CATF) PART A: Required for Committee Approval Purpose This document defines the scope, objectives, organization, deliverables, and overall approach for the Cyber Attack Task

More information

Multi-Region Registered Entity Coordinated Oversight Program

Multi-Region Registered Entity Coordinated Oversight Program Multi-Region Registered Entity Coordinated Oversight Program Ken McIntyre, Vice President and Director of Standards and Compliance Compliance Committee Open Meeting February 7, 2018 Coordinated Oversight

More information

NERC Staff Organization Chart Budget

NERC Staff Organization Chart Budget NERC Staff Organization Chart 2013 2014 President and CEO (Dept. 2100) Executive Assistant (Dept. 2100) Senior Vice President and Chief Operating Officer (Dept. 2100) Senior Vice President General Counsel

More information

Statement for the Record

Statement for the Record Statement for the Record of Seán P. McGurk Director, Control Systems Security Program National Cyber Security Division National Protection and Programs Directorate Department of Homeland Security Before

More information

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

CIP Cyber Security Configuration Change Management and Vulnerability Assessments Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective. Development Steps Completed

More information

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith OPUC Workshop March 13, 2015 Cyber Security Electric Utilities Portland General Electric Co. Travis Anderson Scott Smith 1 CIP Version 5 PGE Implementation Understanding the Regulations PGE Attended WECC

More information

NERC Staff Organization Chart

NERC Staff Organization Chart NERC Staff Organization Chart President and CEO Administrative Associate Director to the Office of the CEO Associate Director, Member Relations and MRC Secretary Senior Vice President and Chief Reliability

More information

Cybersecurity Overview

Cybersecurity Overview Cybersecurity Overview DLA Energy Worldwide Energy Conference April 12, 2017 1 Enterprise Risk Management Risk Based: o Use of a risk-based approach for cyber threats with a focus on critical systems where

More information

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

CIP Cyber Security Configuration Change Management and Vulnerability Assessments CIP-010-2 3 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:

More information

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION Cyber Security Incident Reporting Reliability Standards Docket Nos. RM18-2-000 AD17-9-000 COMMENTS OF THE AMERICAN PUBLIC POWER

More information

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 PPD-21: CI Security and Resilience On February 12, 2013, President Obama signed Presidential Policy Directive

More information

Standards. Mark Lauby, Vice President and Director of Standards Board of Trustees Meeting November 7, 2013

Standards. Mark Lauby, Vice President and Director of Standards Board of Trustees Meeting November 7, 2013 Standards Mark Lauby, Vice President and Director of Standards Board of Trustees Meeting November 7, 2013 Geomagnetic Disturbance Operations EOP-010-1 Reliability benefits Enhance operating response to

More information

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

CIP Cyber Security Configuration Change Management and Vulnerability Assessments CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:

More information

PIPELINE SECURITY An Overview of TSA Programs

PIPELINE SECURITY An Overview of TSA Programs PIPELINE SECURITY An Overview of TSA Programs Jack Fox Pipeline Industry Engagement Manager Surface Division Office of Security Policy & Industry Engagement May 5, 2014 TSA and Pipeline Security As the

More information

History of NERC December 2012

History of NERC December 2012 History of NERC December 2012 Timeline Date 1962-1963 November 9, 1965 1967 1967-1968 June 1, 1968 July 13-14, 1977 1979 1980 Description Industry creates an informal, voluntary organization of operating

More information

Critical Cyber Asset Identification Security Management Controls

Critical Cyber Asset Identification Security Management Controls Implementation Plan Purpose On January 18, 2008, FERC (or Commission ) issued Order. 706 that approved Version 1 of the Critical Infrastructure Protection Reliability Standards, CIP-002-1 through CIP-009-1.

More information

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium Securing Cyber Space & America s Cyber Assets: Threats, Strategies & Opportunities September 10, 2009, Crystal Gateway Marriott, Arlington,

More information

Standard CIP Cyber Security Critical Cyber Asset Identification

Standard CIP Cyber Security Critical Cyber Asset Identification Standard CIP 002 1 Cyber Security Critical Cyber Asset Identification Standard Development Roadmap This section is maintained by the drafting team during the development of the standard and will be removed

More information

Updates to the NIST Cybersecurity Framework

Updates to the NIST Cybersecurity Framework Updates to the NIST Cybersecurity Framework NIST Cybersecurity Framework Overview and Other Documentation October 2016 Agenda: Overview of NIST Cybersecurity Framework Updates to the NIST Cybersecurity

More information

NERC-Led Technical Conferences

NERC-Led Technical Conferences NERC-Led Technical Conferences NERC s Headquarters Atlanta, GA Tuesday, January 21, 2014 Sheraton Phoenix Downtown Phoenix, AZ Thursday, January 23, 2014 Administrative Items NERC Antitrust Guidelines

More information

Cyber Threats? How to Stop?

Cyber Threats? How to Stop? Cyber Threats? How to Stop? North American Grid Security Standards Jessica Bian, Director of Performance Analysis North American Electric Reliability Corporation AORC CIGRE Technical Meeting, September

More information

Department of Defense. Installation Energy Resilience

Department of Defense. Installation Energy Resilience Department of Defense Installation Energy Resilience Lisa A. Jung DASD (Installation Energy) OASD(Energy, Installations and Environment) 19 June 2018 Installation Energy is Energy that Powers Our Military

More information

Welcome. Jim Jones, VP & CIO September 11, 2018

Welcome. Jim Jones, VP & CIO September 11, 2018 Welcome Jim Jones, VP & CIO September 11, 2018 CIPC Workplan Update Critical Infrastructure Protection Committee Marc A. Child, Great River Energy, CIPC Chair Critical Infrastructure Protection Committee

More information

Project Cyber Security - Order No. 791 Identify, Assess, and Correct; Low Impact; Transient Devices; and Communication Networks Directives

Project Cyber Security - Order No. 791 Identify, Assess, and Correct; Low Impact; Transient Devices; and Communication Networks Directives Project 2014-02 - Cyber Security - Order No. 791 Identify, Assess, and Correct; Low Impact; Transient Devices; and Communication Networks Directives Violation Risk Factor and Justifications The tables

More information

June 4, 2014 VIA ELECTRONIC FILING. Veronique Dubois Régie de l'énergie Tour de la Bourse 800, Place Victoria Bureau 255 Montréal, Québec H4Z 1A2

June 4, 2014 VIA ELECTRONIC FILING. Veronique Dubois Régie de l'énergie Tour de la Bourse 800, Place Victoria Bureau 255 Montréal, Québec H4Z 1A2 June 4, 2014 VIA ELECTRONIC FILING Veronique Dubois Régie de l'énergie Tour de la Bourse 800, Place Victoria Bureau 255 Montréal, Québec H4Z 1A2 Re: North American Electric Reliability Corporation Dear

More information

Compliance Exception and Self-Logging Report Q4 2014

Compliance Exception and Self-Logging Report Q4 2014 Agenda Item 5 Board of Trustees Compliance Committee Open Session February 11, 2015 Compliance Exception and Self-Logging Report Q4 2014 Action Information Introduction Beginning in November 2013, NERC

More information

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors Page 1 of 6 Applies to: faculty staff students student employees visitors contractors Effective Date of This Revision: June 1, 2018 Contact for More Information: HIPAA Privacy Officer Board Policy Administrative

More information

1. Post for 45-day comment period and pre-ballot review. 7/26/ Conduct initial ballot. 8/30/2010

1. Post for 45-day comment period and pre-ballot review. 7/26/ Conduct initial ballot. 8/30/2010 Standard CIP 011 1 Cyber Security Protection Standard Development Roadmap This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes

More information

Board of Trustees Compliance Committee

Board of Trustees Compliance Committee Board of Trustees Compliance Committee August 13, 2014 10:00 a.m. 11:00 a.m. Pacific The Westin Bayshore 1601 Bayshore Drive Vancouver, BC V6G 2V4 Reliability Assurance Initiative (RAI) Progress Report

More information

Standard CIP Cyber Security Critical Cyber Asset Identification

Standard CIP Cyber Security Critical Cyber Asset Identification Standard CIP 002 1 Cyber Security Critical Cyber Asset Identification Standard Development Roadmap This section is maintained by the drafting team during the development of the standard and will be removed

More information

CIP Cyber Security Personnel & Training

CIP Cyber Security Personnel & Training A. Introduction 1. Title: Cyber Security Personnel & Training 2. Number: CIP-004-6 3. Purpose: To minimize the risk against compromise that could lead to misoperation or instability in the Bulk Electric

More information

ERO Reliability Risk Priorities

ERO Reliability Risk Priorities ERO Reliability Risk Priorities RISC Recommendations to the NERC Board of Trustees February 2018 NERC Report Title Report Date I Table of Contents Preface... iii Preamble...1 Chapter 1: Background and

More information

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services Enhancing infrastructure cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services European Union Agency for Network and Information Security Securing Europe s Information society 2

More information

History of NERC January 2018

History of NERC January 2018 History of NERC January 2018 Date 1962 1963 The electricity industry created an informal, voluntary organization of operating personnel to facilitate coordination of the bulk power system in the United

More information

Cybersecurity and Data Protection Developments

Cybersecurity and Data Protection Developments Cybersecurity and Data Protection Developments Nathan Taylor March 8, 2017 NY2 786488 MORRISON & FOERSTER LLP 2017 mofo.com Regulatory Themes 2 A Developing Regulatory Environment 2016 2017 March CFPB

More information

GridEx IV Initial Lessons Learned and Resilience Initiatives

GridEx IV Initial Lessons Learned and Resilience Initiatives GridEx IV Initial Lessons Learned and Resilience Initiatives LeRoy T. Bunyon, MBA, CBCP Sr. Lead Analyst, Business Continuity 2017 GridEx IV GridEx is a NERC-sponsored, North American grid resilience exercise

More information

Implementing Cyber-Security Standards

Implementing Cyber-Security Standards Implementing Cyber-Security Standards Greg Goodrich TFIST Chair, CISSP New York Independent System Operator Northeast Power Coordinating Council General Meeting Montreal, QC November 28, 2012 Topics Critical

More information

Why you should adopt the NIST Cybersecurity Framework

Why you should adopt the NIST Cybersecurity Framework Why you should adopt the NIST Cybersecurity Framework It s important to note that the Framework casts the discussion of cybersecurity in the vocabulary of risk management Stating it in terms Executive

More information

CIP Version 5 Evidence Request User Guide

CIP Version 5 Evidence Request User Guide CIP Version 5 Evidence Request User Guide Version 1.0 December 15, 2015 NERC Report Title Report Date I Table of Contents Preface... iv Introduction... v Purpose... v Evidence Request Flow... v Sampling...

More information

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 January 23, 2015

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 January 23, 2015 Federal Energy Regulatory Commission Order No. 791 January 23, 2015 67 and 76 67. For the reasons discussed below, the Commission concludes that the identify, assess, and correct language, as currently

More information

Security and Privacy Governance Program Guidelines

Security and Privacy Governance Program Guidelines Security and Privacy Governance Program Guidelines Effective Security and Privacy Programs start with attention to Governance. Governance refers to the roles and responsibilities that are established by

More information

Compliance Enforcement Initiative

Compliance Enforcement Initiative Compliance Enforcement Initiative Filing and Status Update November 2, 2011 Rebecca Michael Status of the Filings NERC filed several components of the Compliance Enforcement Initiative on September 30,

More information

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas

Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Jim Brenton Regional Security Coordinator ERCOT Electric Reliability Council of Texas Facts expressed in this presentation are Facts Opinions express in this presentation are solely my own The voices I

More information

This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective.

This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective. Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective. Description of Current Draft

More information

BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW

BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW EXECUTIVE SUMMARY CenturyLink is committed to ensuring business resiliency and survivability during an incident or business disruption. Our Corporate Business

More information

Implementation Plan for Version 5 CIP Cyber Security Standards

Implementation Plan for Version 5 CIP Cyber Security Standards Implementation Plan for Version 5 CIP Cyber Security Standards April 10September 17, 2012 Note: On September 17, 2012, NERC was alerted that some references in the Initial Performance of Certain Periodic

More information