NERC AWARENESS TRAINING

Slides:



Advertisements
Similar presentations
NERC TPL Standard Issues TSS Meeting #146 Seattle, WA August 15-17, 2007 Chifong Thomas.
Advertisements

PER
PER Update & Compliance Lessons Learned
FRCC Fall Compliance Workshop October , 2013
1 PER-005 Update Impact on Operators System Operator Conference April and May 1-3, 2012 Columbia, SC Margaret Stambach Manager, Training Services.
Project Disturbance and Sabotage Reporting (Event Reporting) Project Webinar July 30, 2012.
Key Reliability Standard Spot Check Frank Vick Compliance Team Lead.
Allan Wick, CFE, CPP, PSP, PCI, CBCP Chief Security Officer WECC Joint Meeting October 8, 2014.
Gcpud1 CRITICAL INFRASTRUCTURE PROTECTION NERC 1200 CIP CRITICAL INFRASTRUCTURE PROTECTION NERC 1200 CIP
Cyber Security 2005 ERCOT COMPLIANCE ROLLOUT Lane Robinson Reliability Analyst.
BS Information Systems – University of Redlands BS Information Systems – University of Redlands AS Electronic Technology AS Electronic Technology Project.
System Operator Conference NERC Standards Review for: Simulator Drill Orientation 2014 System Operator Conferences Charlotte NC & Franklin TN SERC/SOS.
Jeffery J. Gust IOWA INDUSTRIAL ENERGY GROUP FALL CONFERENCE Tuesday, October 14, 2014 MidAmerican Energy Company.
Network security policy: best practices
Electric Power Infrastructure: Status and Challenges for the Future Mark Lauby Director, Reliability Assessments and Performance Analysis.
June 6, 2007 TAC Meeting NERC Registration Issues Andrew Gallo, Assistant General Counsel, Litigation and Business Operations ERCOT Legal Dept.
Mandatory Reliability Rules Implementing the Electric Reliability Organization David W. Hilt Vice President & Director of Compliance APPA Reliability Symposium.
1 FRCC Compliance Organization and Entity Registration 2008 FRCC Compliance Workshop.
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
GOP and QSE Relationship Jeff Whitmer Manager, Compliance Assessments Talk with Texas RE June 25, 2012.
ERCOT Compliance Audits Robert Potts Sr. Reliability Analyst March 23, 2005.
Lisa Wood, CISA, CBRM, CBRA Compliance Auditor, Cyber Security
Federal Energy Regulatory Commission June Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
Entity Registration Under EPAct 2005 Public Power Council April 6, 2006 Louise McCarren Chief Executive Officer WECC.
1 Arizona Corporation Commission BTA Workshop Presenter: Steven Cobb May 23, 2008.
Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation - ERO Perspective David R. Nevius and Michael J. Assante 2009 NRC Regulatory.
How To Prepare For A CIP Audit Scott Barker CISSP, CISA CIP Compliance Workshop Baltimore, MD August 19-20, 2009.
Integration of Variable Generation Task Force Preliminary Conclusions and Actions.
Actions Affecting ERCOT Resulting From The Northeast Blackout ERCOT Board Of Directors Meeting April 20, 2004 Sam Jones, COO.
1 CIP Cyber Security – Personnel & Training Steve Garn CIP Compliance Workshop Baltimore, MD August 19-20, 2009 © ReliabilityFirst Corporation.
1 Texas Regional Entity 2008 Budget Update May 16, 2007.
Overview of WECC and Regulatory Structure
Status Report for Critical Infrastructure Protection Advisory Group
1 Information Sharing Environment (ISE) Privacy Guidelines Jane Horvath Chief Privacy and Civil Liberties Officer.
Security Policies and Procedures. cs490ns-cotter2 Objectives Define the security policy cycle Explain risk identification Design a security policy –Define.
Item 5d Texas RE 2011 Budget Assumptions April 19, Texas RE Preliminary Budget Assumptions Board of Directors and Advisory Committee April 19,
Bill Lewis, Compliance Team Lead NERC Reliability Working Group May 16, 2013 Texas RE Update Talk with Texas RE April 25, 2013.
The Electric Reliability Organization: Getting from here to there. Gerry Cauley Director, Standards ERO Project Manager ERO Slippery Slope NERC Today Uphill.
Problem Areas Updates Penalties FRCC Compliance Workshop September / October
Congestion Management in a Market Environment David Nevius Senior Vice President North American Electric Reliability Council.
Chief Compliance Officer
1 Power System Restoration. 2 Not Active 3 4 Compliance Audit Process APPA E&O Technical Conference – Atlanta April 16, 2007.
Impacts and Actions Resulting from the August 14, 2003 Blackout Minnesota Power Systems Conference November 2, 2003.
The Electric Reliability Organization NERC’s Proposal for a Strong and Effective ERO FRCC System Operator Seminar Spring 2006.
Overview of Tampa Electric’s Compliance Program APPA Reliability Standards and Compliance Program January 10, 2007.
NERC Reliability Readiness The Next Steps
FERC Standards of Conduct
Updated ERO Enterprise Guide for Internal Controls
NERC Entity Registration and Certification in the ERCOT Region
ERCOT Technical Advisory Committee June 2, 2005
Pseudo-tie business procedure
NERC Cyber Security Standards Pre-Ballot Review
CEO/Co-founder, SOS Intl
Understanding Existing Standards:
Red Flags Rule An Introduction County College of Morris
CIPC Relationships & Roles
Background (history, process to date) Status of CANs
NERC Critical Infrastructure Protection Advisory Group (CIP AG)
Cybersecurity Special Public Meeting/Commission Workshop for Natural Gas Utilities September 27, 2018.
Impacts and Actions Resulting from the August 14, 2003 Blackout
Project Disturbance and Sabotage Reporting (Event Reporting) Project Webinar July 30, 2012.
County HIPAA Review All Rights Reserved 2002.
The Electric Reliability Organization: Getting from here to there.
Mandatory Reliability Standards
Operationalizing Export Certification and Regionalization Programmes
Larry Bugh ECAR Standard Drafting Team Chair June 1, 2005
NERC AWARENESS TRAINING
Training at the Awareness Level Review
Pseudo-tie business procedure
Presentation transcript:

NERC AWARENESS TRAINING Annual Refresher - 2018 Susan Sosbe, COMPLIANCE SS 1/26/18

NERC EMPLOYEE TRAINING Quick Review – What is NERC? Compliance Commitment, Program, Policy Employee Responsibility Review Event Reporting Operating Plan and Procedure For Reporting a Potential Non-Conformance Critical Infrastructure Protection (CIP)

NERC EMPLOYEE TRAINING WHAT IS NERC? North American Electric Reliability Corp. The mission of NERC is to ensure the reliability of the Bulk Electric System (BES) in North America (U.S. and Canada). Under the authority of FERC, NERC enforces the Reliability Standards with all entities who have registered in one (1) or more of the ten (10) industry segments defined by NERC. NERC is the acronym for the NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION. THE MISSION OF NERC IS TO ENSURE THE RELIABILITY OF THE BULK POWER/ELECTRIC SYSTEM IN NORTH AMERICA, WHICH INCLUDES THE U.S., CANADA, AND SMALL PARTS OF MEXICO. NERC gets its authority from THE FEDERAL ENERGY REGULATORY COMMISSION (FERC). Under that authority, NERC enforces the RELIABILITY STANDARDS with ALL Users, Owners, and Operators of the Bulk Power System.

NERC EMPLOYEE TRAINING How Does NERC Apply To Wabash Valley? Reliability Standards are the planning and operating rules that Registered Entities must follow to ensure the most reliable system possible. Compliance is mandatory & enforceable under the scope of NERC’s Regulatory Authority. We must have Procedures and Documentation for each Standard/Requirement/Measure that is applicable to us. Wabash Valley falls under the jurisdiction of two (2) Regional Reliability Organizations (Reliability First Corporation-RF and SERC Reliability Corporation-SERC). RF is the lead Region. Co-ops in Indiana are in the RF Region. Co-ops in Illinois and Missouri are in the SERC Region. Holland Energy, LLC is in the SERC Region.

NERC EMPLOYEE TRAINING How Does NERC Apply To Wabash Valley? Currently, Wabash Valley’s Registrations are: Distribution Provider (DP) – Provides and operates “wires” between the transmission system and the end-use customer. This registration incorporates our Co-ops. Generator Owner (GO) - The entity that owns and maintains generating units. WVPA is the “GO” for the Wabash River Highland Plant (WRHP). NAES is the Generator Operator (GOP) for this facility. We work together to ensure compliance for the plant. WVPA became the GO effective 9/7/11. WVPA is registered as a GO in the RF Region only.

NERC ANNUAL TRAINING CURRENT JOINT REGISTRATION Reliability First SERC WHAT ARE THE KEY ELEMENTS OF COMPLIANCE OF THE WVPA AND MEMBER SYSTEM NERC COMPLIANCE PROGRAM? - COMMITMENT to fulfill all responsibilities and requirements under NERC. - It is the responsibility of EVERY WVPA and Member Co-op Employee to follow the Policies, Procedures, and Requirements of the NERC Compliance Program.

NERC EMPLOYEE TRAINING How Does NERC Apply To Wabash Valley? We also share compliance responsibility with Hoosier Energy and with NAES Corporation for Holland Energy, LLC. Holland Energy, LLC is registered as a Generator Owner (GO), and NAES Corporation, Holland, is registered as the Generator Operator (GOP). Compliance Contacts: GO: Primary: Susan Sosbe, WVPA Secondary: Greg Vonfeldt, Hoosier GOP: Kent Schmohe, NAES, Plant Manager

NERC EMPLOYEE TRAINING Commitment To Compliance Wabash Valley is committed to fulfilling all of our responsibilities and requirements under NERC. It is the responsibility of every Wabash Valley Employee to follow the Policies, Procedures, and Requirements of our NERC Compliance Program.

NERC EMPLOYEE TRAINING Compliance Program Goals and Objectives: Ensure that WVPA complies with all applicable NERC, RF, and SERC Reliability Standards, which in turn, supports the goal of reliable and secure power production and supply. Ensure that WVPA is prepared to provide required information and data to RF, SERC, and NERC in order to demonstrate compliance with all applicable Reliability Standards. To continue to build a “Culture of Compliance”.

COMPLIANCE POLICY Adopted by the Board of Directors, Rev. 2017 Policy Number B-24

NERC/SERC ANNUAL TRAINING Co-op Responsibilities Complete & Return “Equipment Confirmation Form” (annually) Work with WVPA Compliance Manager regarding Policies, Procedures and Compliance/Documentation Associated with NERC Compliance: NERC Compliance Written Plans Conduct Employee Training Sessions (New Employees/Annual Refresher) Express Concerns & Ask Questions About The Program Report Any Potential Non-Compliance Immediately As outlined in the “Event Reporting Operating Plan” required by EOP-004-3, report Events in a timely manner. What Responsibilities do Co-ops have? - Complete and Return the Equipment Confirmation Form on an annual basis. This is part of our evaluation of Special Protection Systems, Underfrequency and Undervoltage Load Shedding Equipment. - Work with the WVPA Compliance Manager regarding Policies, Procedures and Compliance Documentation. - Conduct NERC Training Sessions on an annual basis. - Express any Concerns regarding the Program, and Report any potential Non-Conformance immediately. What is a “non-conformance”? It’s basically, an “oops”, where we didn’t follow a Procedure, such as timely reporting of a Sabotage Event. We must investigate the potential non-conformance and implement corrective actions in order to ensure Compliance.

PLANS/PROCEDURES WVPA EVENT REPORTING OPERATING PLAN Replaces Disturbance Reporting and Sabotage Reporting, effective 1/1/14. Procedure For Reporting A Potential Non-Conformance, Procedure #5064. We have 3 Procedures to review today. You should recognize these from the NERC Training that was conducted last year. Those Procedures are: Sabotage Reporting, Procedure For Reporting a Potential Non-Conformance And, Disturbance Reporting.

EVENT REPORTING OPERATING PLAN Purpose: To outline the Protocol for reporting Events within timelines, and to the Entities, outlined in EOP-004-3 for BES Facilities. Events will be reported within 24 hours of recognition of meeting a Reportable Event type threshold and within the 1 to 6 hour reporting requirements of DOE, if applicable.

EVENT REPORTING OPERATING PLAN REPORTABLE EVENTS BY EVENT TYPE (Applicable to WVPA) Event Type WVPA Registration Threshold for Reporting Damage or Destruction of a Facility DP, GO Damage or destruction of a Facility that results from actual or suspected intentional human action. Physical Threats to a Facility Physical Threat to a Facility, excluding weather or natural disaster related threats, which has the potential to degrade the NORMAL operation of the Facility. OR suspicious activity or device at a Facility. Loss of Firm Load DP Loss of firm load ≥ 200MW for ≥15 minutes Terrorism Acts Actual or suspected physical or cyber/ communication attacks that could impact electric power system adequacy/reliability as defined by DOE. Vandalism Does not meet definition of terrorism.

WVPA REPORTING GUIDELINES BASED UPON EVENT TYPE Report To Timeline Contact Damage or Destruction of a Facility Local Law Enforcement MISO, RF/SERC, NERC All within 24 hours of recognition See Reporting Procedures by Entity. Physical Threats to a Facility DOE Within 24 hours of recognition 1 hour See Reporting Procedures by Entity. Report to DOE within 1 hour if it meets DOE criteria, such as loss of load. Terrorism Acts Joint Terrorism Task Force (JTTF) – Coordinates resources of federal, state & local law enforcement MISO, RF/SERC, NERC, Within 24 hours of recognition JTTF: 24x7: 1-617-742-5533 Reporting Procedures by Entity Vandalism Local/State Police, Sheriff Loss of Load MISO, RF/SERC, NERC ≥200MW DOE ≥300 MW Within 1 hour

EVENT REPORTING OPERATING PLAN Protocol: Contact Susan, Brent, Kari, or Lee. Work with WVPA to complete appropriate documentation (NERC Event Report Form/DOE OE-417). Co-ops use Event Reporting System. Susan will handle reporting to appropriate Entities. Act of Terrorism: Susan will report to the Joint Terrorism Task Force (JTTF). Contacts must be verified annually and verification must be documented (Susan).

To outline the steps that internal & external PROCEDURE FOR REPORTING A POTENTIAL NON-CONFORMANCE Procedure Purpose: To outline the steps that internal & external personnel must follow in order to properly report a potential non-conformance pursuant to NERC Compliance. PLEASE REPORT IMMEDIATELY UPON DISCOVERY!

PROCEDURE FOR REPORTING A POTENTIAL NON-CONFORMANCE Procedure Steps: WVPA Employee, Co-op, or an external entity becomes aware of a potential non-conformance. They report it to one of the following personnel: - WVPA Compliance Manager - WVPA Exec. VP, Transmission & Reg. Affairs - WVPA President/CEO - WVPA Legal Counsel Communication Flow *Depending upon the severity, the WVPA Board of Directors may also be notified. Depending upon circumstance, Co-op Board of Directors may be notified as well.

PROCEDURE FOR REPORTING A POTENTIAL NON-CONFORMANCE Procedure Steps: The WVPA Compliance Manager investigates & documents the potential non-conformance. If the issue is NOT a non-conformance, the WVPA Compliance Mgr. will communicate the status, implement improvement measures, and will retain all documentation. If the issue IS a non-conformance, the WVPA Compliance Mgr. will: Report to the Appropriate Agency & Develop a Mitigation Plan; Implement Corrective Actions; Communicate Status; Retain All Documentation.

NERC EMPLOYEE TRAINING WVPA Compliance Critical Infrastructure Protection (CIP) Standards CIP-005-2.1 BES Cyber System Evaluation completed - low impact for both WVPA, WRHP, and Holland Energy. CIP-003-6: Cyber Security Management Controls - Low Impact Requirements: Cyber Security Awareness Program 4-1-17 Communications Management support and reinforcement Program shared with Member Cooperatives. Cyber Security Incident Response 4-1-17 Identify, classify, respond, reporting of incident. Test every 36 months. JRO Members and applicable facilities included. First exercise of Plan was also completed prior to 4-1-17!

NERC EMPLOYEE TRAINING WVPA Compliance Critical Infrastructure Protection (CIP) Standards For both Physical Security Controls and Electronic Security Controls, the enforcement date is 9-1-18. Physical Security Controls 9-1-2018 Control physical access based upon need. Controls – card keys, locks, monitored alarms, operational procedures. Have to have something! Electronic Security Controls 9-1-2018 Technical Services

NERC CIP UPDATE NERC FINES 2017 To Date: (SERC) $500,000 - Unidentified Registered Entity Violation of CIP & Non-CIP Standards and Requirements (twelve {12} Standards and thirty-three {33} Requirements). 2016: CIP Fine (RF Region) $1,700,000 Violation of eight (8) CIP Standards and thirty-four (34) Requirements. Highest NON-CIP fine in 2014: $3.2 MILLION Arizona Public Service was fined $3.2 Million for failure to perform next day studies and to coordinate with Transmission Operators under TOP-002-2a, R6. Highest Fine to Date 2010: $25 million – FPL.

NERC EMPLOYEE TRAINING QUESTIONS? Please contact: Susan Sosbe, Compliance Manager x 2848