Update in NERC CIP Activities June 5, 2014. 2 Update on CIP-014-1 Update on Revisions to CIP Version 5 –BES Cyber Asset Survey –Implementation Plan Questions.

Slides:



Advertisements
Similar presentations
NERC Cyber Security Standards Pre-Ballot Review. Background Presidents Commission on Critical Infrastructure Protection PDD-63 SMD NOPR NERC Urgent Action.
Advertisements

Federal Energy Regulatory Commission July Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
Frequency Responsive Reserve Process Update
W. Shannon Black Manager, Standards Processes Results Based Drafting 2013.
STATUS OF BULK ELECTRIC SYSTEM DEFINITION PROJECT
NERC Operating Committee Activities Update September 16-17, 2014 Meeting.
PER
PER Update & Compliance Lessons Learned
Allan Wick, CFE, CPP, PSP, PCI, CBCP Chief Security Officer WECC Joint Meeting October 8, 2014.
Update in NERC CIP Activities September 4, Update on CIP Update on Revisions to CIP Version 5  -x Posting  v6 Posting Questions Agenda.
Steve Rueckert Director of Standards Standards Update June 5, 2014 Joint Guidance Committee Meeting Salt Lake City, UT.
Recent NERC Standards Activities RSC – Jan. 5, 2011 NSRS Update Date Meeting Title (optional)
NERC ATC STANDARDS Update Aaron Staley, PE Oct 2013.
Brent Castagnetto Manager, Cyber Security Audits & Investigations Team CIP v5 Implementation Guidance CIP v5 Roadshow Salt Lake City, UT May 14-15, 2014.
State of Standards and Standards in Development Sean Cavote, Manager of Standards Development WECC Operating Committee Meeting March 26, 2015.
Project Cyber Security Order 706 January 10, 2012 Most of the material presented has been compiled from NERC webinars and drafting team meetings.
2009 Performance Assessment Member Representatives Committee Meeting October 28, 2008.
Bryan J. Carr, PMP, CISA Compliance Auditor, Cyber Security
1. 11/26/2012: NERC Board of Trustees adopted CIP v5 CIP thru CIP CIP and CIP Version 5 Filing FERC requested filing by 3/31/2013.
CIP Version 5 Update OC Meeting November 7, 2013.
Physical Security CIP NERC Standing Committees December 9-10, 2014.
Cyber Security Standard Workshop Status of Draft Cyber Security Standards Larry Bugh ECAR Standard Drafting Team Chair January 2005.
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
Lisa Wood, CISA, CBRM, CBRA Compliance Auditor, Cyber Security
Federal Energy Regulatory Commission June Cyber Security and Reliability Standards Regis F. Binder Director, Division of Logistics & Security Federal.
Standards Update Project Geomagnetic Disturbance Mitigation Kenneth A. Donohoo, Oncor Electric Delivery Co LLC Chairperson, GMD Task Force Presentation.
Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation - ERO Perspective David R. Nevius and Michael J. Assante 2009 NRC Regulatory.
Implementing the New Reliability Standards Status of Draft Cyber Security Standards CIP through CIP Larry Bugh ECAR Standard Drafting Team.
SPP.org 1. EMS Users Group – CIP Standards The Compliance Audits Are Coming… Are You Ready?
1 Texas Regional Entity 2008 Budget Update May 16, 2007.
1. 2 NERC Bulk Electric System (BES) Definition (NERC Glossary of Terms Used in Reliability Standards) FERC Order 693 FRCC Handbook Review Task Force.
Critical Infrastructure Protection Update Christine Hasha CIP Compliance Lead Advisor, ERCOT TAC March 27, 2014.
Status Report for Critical Infrastructure Protection Advisory Group
Project System Protection Coordination Requirement revisions to PRC (ii) Texas Reliability Entity NERC Standards Reliability Subcommittee.
Board of Directors Meeting February 26, 2013 Standards, Registration and Certification Report.
Project (COM-001-3) Interpersonal Communications Capabilities Michael Cruz-Montes, CenterPoint Energy Senior Consultant, Policy & Compliance, SDT.
Item 5d Texas RE 2011 Budget Assumptions April 19, Texas RE Preliminary Budget Assumptions Board of Directors and Advisory Committee April 19,
Paragraph 81 Project. 2RELIABILITY | ACCOUNTABILITY Background FERC March 15, 2012 Order regarding the Find, Fix, Track and Report (FFT) process  Paragraph.
Date CIP Standards Update Chris Humphreys Texas RE CIP Compliance.
NERC Project S ystem Protection Coordination - PRC-027​ Presentation to the NSRS Conference Call August 17, 2015 Sam Francis Oncor Electric Delivery.
Project – Alignment of Terms WECC Joint Meeting July 15, 2015.
Employee Privacy at Risk? APPA Business & Financial Conference Austin, TX September 25, 2007 Scott Mix, CISSP Manager of Situation Awareness and Infrastructure.
Standards Review Subcommittee Update August 17, 2010.
NERC Project S ystem Protection Coordination - PRC-027​ Presentation to the NSRS Conference Call April 20, 2015 Sam Francis Oncor Electric Delivery.
Page 1 of 13 Texas Regional Entity ROS Presentation April 16, 2009 T EXAS RE ROS P RESENTATION A PRIL 2009.
Compliance Update September Control Performance Highlights  NERC CPS1 Performance ERCOT’s August score was ERCOT’s CPS1 scores show significant.
Project Update TOP/IRO Reliability Standards NERC ORS May 6, 2014.
NERC Project PRC-005 FERC Order No. 803 Directive ​ Presentation to the NSRS Conference Call August 17, 2015 Sam Francis Oncor Electric Delivery.
Reliability Standards Development Plan David Taylor Manager Standards Development Standards Committee Meeting June 12-13, 2008.
RFC Webinar April 24, 2009 and May 1, 2009 Presented By: Mark Kuras Chair, Generator Verification SDT.
Compliance Update July Control Performance Highlights  NERC CPS1 Performance ERCOT’s May score was 146.1; June’s score was May has typically.
Reliability Standard TPL Transmission System Planned Performance for Geomagnetic Disturbance Events September 28, 2016 TPL Standard Status.
WECC – NERC Standards Update
Standards Subject to Future Enforcement 2017
Rachel Coyne Manager, Reliability Standards Program
Planning Geomagnetic Disturbance Task Force (PGDTF) Update to the ROS
ERCOT Technical Advisory Committee June 2, 2005
Merrill Brimhall – Engineer, Staff
NERC Cyber Security Standards Pre-Ballot Review
Larry Bugh ECAR Standard Drafting Team Chair January 2005
Larry Bugh ECAR Standard Drafting Team Chair January 2005
TGs Montreal Closing Report
Reliability Standards Development Plan
NERC Reliability Standards Development Plan
Larry Bugh ECAR Standard Drafting Team Chair June 1, 2005
TGaf San Francisco Closing Report
TGaf San Antonio Closing Report
NERC Reliability Standards Development Plan
Timeline Overview Planned Timescales
Standards Development Process
Presentation transcript:

Update in NERC CIP Activities June 5, 2014

2 Update on CIP Update on Revisions to CIP Version 5 –BES Cyber Asset Survey –Implementation Plan Questions Agenda

FERC Directive March 7 Approved by Industry Final BallotMay 5 Adopted by NERC Board of Trustees May 13 NERC staff is preparing the FERC filing Key Dates: Project Physical Security (CIP-014-1)

Standard Effective  First day of the first calendar quarter that is six months beyond 3 months following govt. approval  Initial Performance of Periodic Requirements CIP Implementation Plan Requirement R1 Must be completed on or before the effective date of the standard. Requirement R2 shall be completed as follows:  Parts 2.1 Shall be completed within 90 calendar days of the effective date of the proposed Reliability Standard.  Parts 2.2 Shall be completed within 90 calendar days of the effective date of the proposed Reliability Standard.  Part 2.3 Shall be completed within 60 calendar days of the completion of performance under Requirement R2 part 2.2.  Parts 2.4Shall be completed within 90 calendar days of the effective date of the proposed Reliability Standard.

CIP Implementation Plan Requirement R3 Shall be completed within 7 calendar days of completion of performance under Requirement R2. Requirement R4 Shall be completed within 120 calendar days of completion of performance under Requirement R2. Requirement R5 Shall be completed within 120 calendar days of completion of performance under Requirement R2. Requirement R6 shall be completed as follows: Part 6.1 Shall be completed within 90 calendar days of completion of performance under Requirement R5. Part 6.2 Shall be completed within 90 calendar days of completion of performance under Requirement R5. Part 6.3 Shall be completed within 60 calendar days of Requirement R6 part 6.2. Part 6.4Shall be completed within 90 calendar days of completion of performance under Requirement R5.

CIP Standards Revisions  Ballot Pool Open June 2 – July 2  45-day comment period June 2 – July 16  Ballot July 7 – July 16  Non-Binding Poll (VRF/VSL) July 7 – July 16  RSAWsJune 17  Industry WebinarJune 19  SDT meeting, St. Paul, MNWeek of July 28  SDT meeting, San Francisco, CA Week of August 19 BES Cyber Asset Survey Comments May 30 – July 14 NERC RAI WebinarJune 19 Key Dates CIP-002 to CIP-011 Revisions

To gain understanding of the term “BES Cyber Asset”  NERC to conduct a survey of responsible entities during the implementation period for CIP Version 5  Determine the types of Cyber Assets that are included in the definition of BES Cyber Asset due to the 15-minute parameter  Determine the types of Cyber Assets that are excluded from the definition of BES Cyber Asset due to the 15-minute parameter BES Cyber Asset Survey

Based on the survey data, NERC is required to explain to FERC: 1)Specific ways in which entities determine which Cyber Assets meet the 15-minute parameter; 2)Types or functions of Cyber Assets that are excluded from being designated as BES Cyber Assets and the rationale as to why; 3)Common problem areas with entities improperly designating BES Cyber Assets; and 4)Feedback from each region participating in the implementation study on lessons learned with the application of the BES Cyber Asset definition. BES Cyber Asset Survey

Builds from April 1, 2016 effective date of V5 While the standard has an effective date, a compliance date may differ for Requirements Do not expect IAC language from V5 to go into effect The following from V5 implementation remains the same:  Initial performance of certain periodic requirements  Previous identity verification  Planned or unplanned changes resulting in a higher categorization CIP-002 to CIP-011 Revision Implementation Plan

For those requirements and parts not listed below, compliance date would be effective date of standard, which is proposed to be later of April 1, 2016 or 3 months following govt. approval. CIP-002 to CIP-011 Implementation Plan StandardRequirement Proposed Implementation Periods CIP-003-6R2 (Low Impact) Later of April 1, 2017 or 9 months following govt. approval CIP-006-6R1 (Comm. Networks) Part 1.10 – Effective date plus 9 months CIP-007-6R1 (Comm. Networks) Part 1.2 – Applicable non- programmable electronic equipment associated with new BES Cyber Systems - Effective date plus 6 months CIP-010-2R4 (transient devices)Effective date plus 9 months

11

Project CIP Standards Version 5 Revisions  Infrastructure-Protection-Version-5-Revisions.aspx Infrastructure-Protection-Version-5-Revisions.aspx BES Cyber Asset Survey  Infrastructure-Protection-Version-5-Revisions.aspx Infrastructure-Protection-Version-5-Revisions.aspx Project Physical Security  Security.aspx Security.aspx References