UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION COMMENTS OF THE PENNSYLVANIA PUBLIC UTILITY COMMISSION

Similar documents
151 FERC 61,066 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION ORDER DENYING REHEARING. (Issued April 23, 2015)

Physical Security Reliability Standard Implementation

Project Physical Security Directives Mapping Document

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION ) )

UNITED STATES OF AMERICA BEFORE THE U.S. DEPARTMENT OF COMMERCE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION

Re: North American Electric Reliability Corporation Docket No. RM

October 2, CIP-014 Report Physical Security Protection for High Impact Control Centers Docket No. RM15-14-

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION. Foundation for Resilient Societies ) Docket No.

EEI Fall 2008 Legal Conference Boston, Massachusetts Stephen M. Spina November 1,

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION ) ) )

OPUC Workshop March 13, 2015 Cyber Security Electric Utilities. Portland General Electric Co. Travis Anderson Scott Smith

The North American Electric Reliability Corporation ( NERC ) hereby submits

Critical Cyber Asset Identification Security Management Controls

Project Retirement of Reliability Standard Requirements

Please contact the undersigned if you have any questions concerning this filing.

Grid Security & NERC

Cyber Threats? How to Stop?

136 FERC 61,187 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. 18 CFR Parts and 40. [Docket No. RM ]

162 FERC 61,044 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. 18 CFR Part 40. [Docket No. RM ]

June 4, 2014 VIA ELECTRONIC FILING. Veronique Dubois Régie de l'énergie Tour de la Bourse 800, Place Victoria Bureau 255 Montréal, Québec H4Z 1A2

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION

Reliability Standard Audit Worksheet 1

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

BILLING CODE P DEPARTMENT OF ENERGY Federal Energy Regulatory Commission. [Docket No. RM ] Cyber Systems in Control Centers

BILLING CODE P DEPARTMENT OF ENERGY. Federal Energy Regulatory Commission. 18 CFR Part 40. [Docket No. RM ]

November 9, Revisions to the Violation Risk Factors for Reliability Standards IRO and TOP

Cyber Security Reliability Standards CIP V5 Transition Guidance:

Standard CIP 007 3a Cyber Security Systems Security Management

Standard CIP Cyber Security Systems Security Management

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION. Physical Security ) Docket No. RM Reliability Standard )

Standard CIP 007 4a Cyber Security Systems Security Management

Standard Development Timeline

Implementation Plan for Version 5 CIP Cyber Security Standards

BILLING CODE P DEPARTMENT OF ENERGY FEDERAL ENERGY REGULATORY COMMISSION. 18 CFR Part 40. [Docket No. RM ]

CIP Cyber Security Configuration Change Management and Vulnerability AssessmentsManagement

CIP Standards Development Overview

February 18, The Honorable Kimberly D. Bose Secretary Federal Energy Regulatory Commission 888 First Street, NE Washington, DC 20426

CIP Cyber Security Systems Security Management

Summary of FERC Order No. 791

163 FERC 61,032 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. 18 CFR Part 40. [Docket No. RM ; Order No.

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 June 2, 2014

Cyber Security Supply Chain Risk Management

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

Grid Security & NERC. Council of State Governments. Janet Sena, Senior Vice President, Policy and External Affairs September 22, 2016

Critical Infrastructure Protection Version 5

October 2, 2017 VIA ELECTRONIC FILING

Standard CIP Cyber Security Systems Security Management

Electric Transmission Reliability

Chapter X Security Performance Metrics

Standards Authorization Request Form

Smart Grid Standards and Certification

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

Standard CIP Cyber Security Security Management Controls

Project Cyber Security - Order No. 791 Identify, Assess, and Correct; Low Impact; Transient Devices; and Communication Networks Directives

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 January 23, 2015

Unofficial Comment Form Project Operating Personnel Communications Protocols COM-002-4

Violation Risk Factor and Violation Severity Level Justifications Project Modifications to CIP Standards

January 30, Docket Nos. ER and ER Interconnection Queue Quarterly Progress Report, Q4 2014

March 6, Dear Electric Industry Vendor Community: Re: Supply Chain Cyber Security Practices

Standard Development Timeline

A. Introduction. Page 1 of 22

Standards Authorization Request Form

Scope Cyber Attack Task Force (CATF)

March 15, 2011 VIA ELECTRONIC FILING

154 FERC 61,037 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. 18 CFR Part 40. [Docket No. RM ]

March 4, 2011 VIA ELECTRONIC FILING

This section is maintained by the drafting team during the development of the standard and will be removed when the standard becomes effective.

Standard CIP Cyber Security Incident Reporting and Response Planning

A. Introduction 1. Title: 2. Number: 3. Purpose: 4. Applicability: 4.1. Functional Entities: Balancing Authority Distribution Provider

Violation Risk Factor and Violation Severity Level Justification Project Modifications to CIP-008 Cyber Security Incident Reporting

Regulatory Impacts on Research Topics. Jennifer T. Sterling Director, Exelon NERC Compliance Program

History of NERC December 2012

Cybersecurity for the Electric Grid

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

Standard CIP Cyber Security Critical Cyber As s et Identification

NERC CIP VERSION 6 BACKGROUND COMPLIANCE HIGHLIGHTS

Unofficial Comment Form Project Modifications to CIP Standards Requirements for Transient Cyber Assets CIP-003-7(i)

April 12, 2017 VIA ELECTRONIC FILING

SUMMARY: The Federal Energy Regulatory Commission (Commission) proposes to

BILLING CODE P DEPARTMENT OF ENERGY Federal Energy Regulatory Commission. 18 CFR Part 40. [Docket No. RM ]

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION

Standard CIP-006-4c Cyber Security Physical Security

Standard CIP Cyber Security Critical Cyber Asset Identification

CIP Cyber Security Configuration Management and Vulnerability Assessments

Standard CIP Cyber Security Critical Cyber As s et Identification

CIP Cyber Security Personnel & Training

December 30, 2015 VIA ELECTRONIC FILING

Standard CIP-006-3c Cyber Security Physical Security

Standard CIP Cyber Security Electronic Security Perimeter(s)

1. Post for 45-day comment period and pre-ballot review. 7/26/ Conduct initial ballot. 8/30/2010

161 FERC 61,291 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. 18 CFR Part 40. [Docket Nos. RM and AD ]

UNITED STATES OF AMERICA BEFORE THE FEDERAL ENERGY REGULATORY COMMISSION. REPLY BRIEF OF SOUTHERN CALIFORNIA EDISON COMPANY (March 19, 2009)

Proposed Clean and Redline for Version 2 Implementation Plan

CIP Version 5 Transition. Steven Noess, Director of Compliance Assurance Member Representatives Committee Meeting November 12, 2014

Why you should adopt the NIST Cybersecurity Framework

152 FERC 61,116 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION

Standard TOP Transmission Operations

Standard CIP Cyber Security Critical Cyber Asset Identification

Transcription:

UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION Physical Security Reliability : Standard : Docket No. RD14-15-000 COMMENTS OF THE PENNSYLVANIA PUBLIC UTILITY COMMISSION I. INTRODUCTION On July 17, 2014, the Federal Energy Regulatory Commission (FERC or Commission) issued its Notice of Proposed Rulemaking proposing to approve Reliability Standard CIP-014-1. The North American Electric Reliability Corporation (NERC) 1 submitted the proposed Reliability Standard for Commission approval in response to a Commission order issued on March 7, 2014. 2 The purpose of the proposed Reliability Standard CIP-014-1 is to enhance physical security measures for the most critical Bulk-Power System facilities and, as a result, lessen the overall vulnerability of the Bulk-Power System against physical attacks. As set forth in these Comments, the Pennsylvania Public Utility Commission (Pa. PUC) continues to support the Commission s efforts to identify and protect critical facilities within the Bulk-Power System. Further, the Pa. PUC commends the Commission in seeking input on this very important issue, supports the promulgation of such Reliability Standards, and files these Comments in accordance with the Order. 1 NERC is the Commission-certified Electric Reliability Organization. 2 The Pennsylvania Public Utility Commission filed Comments in response to that Order as well. 1

II. SUMMARY OF THE PROPOSED STANDARD In its March 7, 2014 Order, the FERC determined that physical attacks on the Bulk-Power System could adversely impact the reliable operation of the Bulk-Power System and result in instability, uncontrolled separation, or cascading failures. Therefore, pursuant to section 215 of the Federal Power Act (FPA) and to provide for the reliable operation of the Bulk-Power System, the Commission directed NERC to develop (and file for approval) proposed Reliability Standards that address threats and vulnerabilities to the physical security of critical facilities on the Bulk-Power System. On May 23, 2014, the NERC petitioned the Commission to approve proposed Reliability Standard CIP-014-1 and maintained that the proposed Reliability Standard is just, reasonable, not unduly discriminatory, or preferential, and in the public interest. In addition, NERC asserted that the proposed Reliability Standard complies with the Commission's directives in the March 7, 2014 Order. In the instant Notice of Proposed Rulemaking, the FERC proposes to approve proposed Reliability Standard CIP-014-1. However, the Commission also proposes several modifications. Of critical importance to the Pa. PUC, the Commission proposes to direct NERC to develop a modification to the physical security Reliability Standard to allow applicable governmental authorities to add or subtract facilities from an applicable entity's list of critical facilities. The Commission also proposes to direct NERC to modify the physical security Reliability Standard to remove the term widespread. Further, the Commission proposes to direct NERC to make two informational filings the first to be submitted within six months of the effective date of a final rule in this proceeding addressing the possibility that proposed Reliability Standard CIP-014-1 may not provide physical security for all High Impact control centers (as that term is defined in Reliability Standard CIP-002-5.1) and the second to be 2

submitted within one year of the effective date of a final rule in this proceeding addressing possible resiliency measures that can be taken to maintain the reliable operation of the Bulk- Power System following the loss of critical facilities. As set forth in these Comments, the Pa. PUC supports implementation of proposed Reliability Standard CIP-014-1 and the FERC s proposed modifications. 3

III. COMMENTS The Pa. PUC supports FERC s efforts to establish reliability standards which can protect the Bulk-Power System from physical attacks that can adversely impact its reliable operation resulting in instability, uncontrolled separation, or cascading failures. The Pa. PUC has instituted such protections for its jurisdictional electric distribution companies and requires all jurisdictional utilities to develop and maintain appropriate written physical security, cyber security, emergency response and business continuity plans to protect the Commonwealth s infrastructure and ensure safe, continuous and reliable utility service. The Pa. PUC has a direct interest in the efficacy and structure of any reliability standards related to physical attacks on the Bulk-Power System. As noted above, electric distribution companies in Pennsylvania already have written physical security plans for distribution assets which could be utilized as a baseline for developing plans for their Bulk- Power System assets. While the facilities addressed by the standards will likely be nonjurisdictional to state public utility commissions, the effects of any physical attacks that impact the Bulk-Power System would certainly impact the electric utility distribution facilities subject to Pa. PUC jurisdiction. In Pennsylvania, the Pa. PUC performs a crucial role in the response to issues involving the physical security of electric distribution systems through the State Emergency Operations Plan. The Pa. PUC provides information and subject matter expertise to the State Emergency Operations Center on an as-needed basis for electric sector emergencies impacting the Commonwealth. Therefore, the Pa. PUC s interests are aligned with those of the Commission in the instant proceeding. Consequently, the Pa. PUC agrees with the FERC s approval of Reliability Standard CIP-014-1 and also supports FERC s proposed modifications. 4

Applicable governmental authorities The Pa. PUC fully supports this proposal which would provide applicable governmental authorities with the flexibility to efficiently and effectively add or subtract critical facilities as was the intent in FERC s March 7, 2014 Order. As FERC points out, NERC s proposed methodology for allowing FERC to add or subtract facilities may prove inefficient as it would require the transmission operators to re-perform the risk assessment (which may not necessarily reach the conclusion to add the facilities). Clearly, FERC would have already determined the criticality of a facility through an audit of an applicable entity, or through some other means and re-performing the risk assessment would be an unneeded step and would delay the development of the physical security plan and review. Therefore, the Pa PUC agrees with the Commission that this modification is necessary. Removal of the term widespread The Pa. PUC also fully supports the proposal to remove the term widespread as it appears in the phrase widespread instability. As the FERC highlights, the term widespread is undefined by NERC in its standard and supporting documents and could be interpreted so broadly as to make the standards meaningless. Therefore, the term could be interpreted so broadly that the number of critical facilities would be far less than was intended by the March 7, 2014 Order. Consequently, the Pa. PUC agrees that removal of this term is warranted. 5

Six-month informational filing The PUC also supports FERC s proposal that NERC make an informational filing within six months of the effective date of a final rule in this proceeding indicating whether the development of reliability standards that provide physical security for all High Impact control centers is necessary for the reliable operation of the Bulk-Power system. The FERC correctly notes that a successful attack on primary or back-up control centers of those other than transmission owners and operators that are identified as High Impact could allow attackers to distribute misleading and potentially harmful data and operating instructions that could result in instability, uncontrolled separation, or cascading failures. As the Commission highlights, the standards under CIP-006-5 may not be sufficient to deter, detect, delay, assess, communicate, and respond to potential threats and vulnerabilities. Therefore, further study is needed to determine appropriate response measures as well as measures to deter and delay potential threats, which are not addressed in CIP-006-5. 6

IV. CONCLUSION For all of the foregoing reasons, the Pa. PUC respectfully requests that its Comments be considered in this proceeding. Respectfully submitted, /s/ James A. Mullins James A. Mullins /s/ James P. Melia James P. Melia Counsel for the Pennsylvania Public Utility Commission P.O. Box 3265 Harrisburg, PA 17105-3265 jmelia@pa.gov jamullins@pa.gov Dated: September 8, 2014 7

CERTIFICATE OF SERVICE I hereby certify that the foregoing document has been served in accordance with 18 C.F.R. Sec. 385.2010 upon each person designated on the official service list compiled by the Secretary in this proceeding. Dated at Harrisburg, PA this 8 th of September, 2014. /s/_james P. Melia James P. Melia 8