Breakfast
7:00 a.m. – 8:00 a.m.
Breakfast 7:00 a.m. 8:00 a.m. Opening Announcements NERC 2015 - - PowerPoint PPT Presentation
Breakfast 7:00 a.m. 8:00 a.m. Opening Announcements NERC 2015 Standards and Compliance Spring Workshop April 3, 2015 NERC Antitrust Compliance Guidelines It is NERCs policy and practice to obey the antitrust laws and to avoid all
7:00 a.m. – 8:00 a.m.
NERC 2015 Standards and Compliance Spring Workshop
April 3, 2015
RELI ABI LI TY | ACCOUNTABI LI TY 2
RELI ABI LI TY | ACCOUNTABI LI TY 3
RELI ABI LI TY | ACCOUNTABI LI TY 4
RELI ABI LI TY | ACCOUNTABI LI TY 5
RELI ABI LI TY | ACCOUNTABI LI TY 6
Marisa Hecht, Senior Advisor, Compliance Assurance Ed Kichline, Senior Counsel, Associate Director of Enforcement 2015 Standards & Compliance Spring Workshop April 3, 2015
RELI ABI LI TY | ACCOUNTABI LI TY 2
RELI ABI LI TY | ACCOUNTABI LI TY 3
RELI ABI LI TY | ACCOUNTABI LI TY 4
(IRA) and Internal Controls Evaluation (ICE) processes
registered entities
RELI ABI LI TY | ACCOUNTABI LI TY 5
RELI ABI LI TY | ACCOUNTABI LI TY 6
Risk-based Compliance Oversight Framework (Framework)
RELI ABI LI TY | ACCOUNTABI LI TY 7
RELI ABI LI TY | ACCOUNTABI LI TY 8
RELI ABI LI TY | ACCOUNTABI LI TY 9
Post Implementation Plan in September each year. Consider Requirements and functional entities remaining and determine if any additional guidance should be provided to CEAs Review functional entities to determine their importance to the remaining Requirements Consider additional factors and remove Requirements not appropriate for additional focus Identify the specific Requirements related to their management of risk. Select a sub-set of risks for additional focus based on significance and existence of Reliability Standards for that risk Identify an effective body of Reliability Standards related to the risks. Develop a matrix and prioritize reliability risks. Collect the ERO Enterprise data.
RELI ABI LI TY | ACCOUNTABI LI TY 10
RELI ABI LI TY | ACCOUNTABI LI TY 11
RELI ABI LI TY | ACCOUNTABI LI TY 12
RELI ABI LI TY | ACCOUNTABI LI TY 13
RELI ABI LI TY | ACCOUNTABI LI TY 14
1.Infrastructure maintenance 2.Uncoordinated protection systems 3.Protection systems misoperations 4.Workforce capability 5.Monitoring and situational awareness 6.Long term planning and system analysis 7.Threats to cyber systems 8.Human error 9.Extreme physical events
RELI ABI LI TY | ACCOUNTABI LI TY 15
RELI ABI LI TY | ACCOUNTABI LI TY 16
Subject Date Uncoordinated Protection Systems April 16, 2015 Monitoring and Situational Awareness May 21, 2015 Infrastructure Maintenance June 18, 2015 Protection System Misoperation July 16, 2015 Workforce Capability August 20, 2015 Long Term Planning and System Analysis September 17, 2015 Extreme Physical Events October 15, 2015 Threats to Cyber Systems November 19, 2015
RELI ABI LI TY | ACCOUNTABI LI TY 17
RELI ABI LI TY | ACCOUNTABI LI TY 18
Marisa Hecht, Senior Advisor, Compliance Assurance Ed Kichline, Senior Counsel, Associate Director of Enforcement Spring 2015 Standards & Compliance Workshop April 3, 2015
RELI ABI LI TY | ACCOUNTABI LI TY 20
RELI ABI LI TY | ACCOUNTABI LI TY 21
RELI ABI LI TY | ACCOUNTABI LI TY 22
RELI ABI LI TY | ACCOUNTABI LI TY 23
RELI ABI LI TY | ACCOUNTABI LI TY 24
RELI ABI LI TY | ACCOUNTABI LI TY 25
RELI ABI LI TY | ACCOUNTABI LI TY 26
RELI ABI LI TY | ACCOUNTABI LI TY 27
RELI ABI LI TY | ACCOUNTABI LI TY 28 3 part communication process is clearly established Operators trained regularly on 3 part communication Operators use 3 part communication for all information exchange and not just directives Operator consoles have a visual reminder to use 3 part communication All directives recorded on tapes Shift supervisor regularly listens to the tapes to verify 3 part communication Feedback to operators on improving 3 part communication
RELI ABI LI TY | ACCOUNTABI LI TY 29
personnel)
RELI ABI LI TY | ACCOUNTABI LI TY 30
RELI ABI LI TY | ACCOUNTABI LI TY 31
RELI ABI LI TY | ACCOUNTABI LI TY 32
Andrew Wills, NERC Associate Counsel 2015 Standards and Compliance Spring Workshop April 3, 2015
Scott Mix, CISSP Spring 2015 Standards and Compliance Workshop April 3, 2015
2 RELIABILITY | ACCOUNTABILITY
3 RELIABILITY | ACCOUNTABILITY
* - Changed “Devices” to “Systems” in background section ** - Developed as version 7
4 RELIABILITY | ACCOUNTABILITY
*** - Developed as version 3
5 RELIABILITY | ACCOUNTABILITY
6 RELIABILITY | ACCOUNTABILITY
7 RELIABILITY | ACCOUNTABILITY
8 RELIABILITY | ACCOUNTABILITY
9 RELIABILITY | ACCOUNTABILITY
10 RELIABILITY | ACCOUNTABILITY
11 RELIABILITY | ACCOUNTABILITY
attachment
12 RELIABILITY | ACCOUNTABILITY
13 RELIABILITY | ACCOUNTABILITY
14 RELIABILITY | ACCOUNTABILITY
into the compliance process”
protections for Low impact facilities should be clear, objective and commensurate with their impact on the system, and technically justified.”
15 RELIABILITY | ACCOUNTABILITY
16 RELIABILITY | ACCOUNTABILITY
requirements together; no documentation of deviations or specific record retention – but still need to demonstrate compliance)
17 RELIABILITY | ACCOUNTABILITY
18 RELIABILITY | ACCOUNTABILITY
19 RELIABILITY | ACCOUNTABILITY
20 RELIABILITY | ACCOUNTABILITY
21 RELIABILITY | ACCOUNTABILITY
22 RELIABILITY | ACCOUNTABILITY
23 RELIABILITY | ACCOUNTABILITY
24 RELIABILITY | ACCOUNTABILITY
25 RELIABILITY | ACCOUNTABILITY
26 RELIABILITY | ACCOUNTABILITY
27 RELIABILITY | ACCOUNTABILITY
standard
plan, security awareness, and response
and electronic security
28 RELIABILITY | ACCOUNTABILITY
29 RELIABILITY | ACCOUNTABILITY
Scott Mix, CISSP scott.mix@nerc.net 215-853-8204
10:45 a.m. – 11:00 a.m.
Valerie Agnew, NERC Senior Director of Standards Ryan Stewart, NERC Manager of Standards Development Marisa Hecht, NERC Senior Advisor of Compliance Assurance 2015 Standards and Compliance Spring Workshop April 3, 2015