Welcome!
NERC 2016 Standards and Compliance Workshop Hyatt Regency St. Louis at The Arch
July 12-14, 2016
Welcome! NERC 2016 Standards and Compliance Workshop Hyatt Regency - - PowerPoint PPT Presentation
Welcome! NERC 2016 Standards and Compliance Workshop Hyatt Regency St. Louis at The Arch July 12-14, 2016 Todays Agenda 8:15 8:45 a.m.: Legal and Regulatory Update Lauren Perotti 8:45 10:00 a.m.: Compliance Guidance Update
July 12-14, 2016
RELI ABI LI TY | ACCOUNTABI LI TY 2
RELI ABI LI TY | ACCOUNTABI LI TY 3
RELI ABI LI TY | ACCOUNTABI LI TY 4
Lauren Perotti, NERC Legal Counsel 2016 Standards & Compliance Workshop July 14, 2016
RELI ABI LI TY | ACCOUNTABI LI TY 6
RELI ABI LI TY | ACCOUNTABI LI TY 7
PRC-004-4 implementation plan (RD15-6-000, 11/13/2015)
Remedial Action Scheme (RM15-7-000 et al., 11/19/2015)
11/19/2015)
16-000, 11/19/2015)
12/4/2015)
RELI ABI LI TY | ACCOUNTABI LI TY 8
000, 1/21/2016)
(RM15-14-000, 1/21/2016)*
RELI ABI LI TY | ACCOUNTABI LI TY 9
Performance for Geomagnetic Disturbance Events)
GMD event; and
submit informational filings.
RELI ABI LI TY | ACCOUNTABI LI TY 10
Contingency Reserve for Recovery from a Balancing Contingency Event)
Period and the 90-minute Contingency Reserve Restoration Period; and
RELI ABI LI TY | ACCOUNTABI LI TY 11
as follows:
§ 39.11 Reliability reports. * * * * (c) The Electric Reliability Organization shall make available to the Commission, on a non-public and ongoing basis, access to the Transmission Availability Data System, Generator Availability Data System, and protection system misoperations databases, or any successor databases thereto. Such access will be limited to: (1) data regarding U.S. facilities and (2) data that is required to be provided to the ERO.
regulations to protect “critical electric infrastructure information” (CEII) (See FAST Act NOPR - Docket No. RM16-15-000)
RELI ABI LI TY | ACCOUNTABI LI TY 12
RELI ABI LI TY | ACCOUNTABI LI TY 13
for the revised CIP Reliability Standards approved in Order No. 822.
RELI ABI LI TY | ACCOUNTABI LI TY 14
RELI ABI LI TY | ACCOUNTABI LI TY 15
RELI ABI LI TY | ACCOUNTABI LI TY 16
(Supporting Documents)
(Personnel Certification)
Sharing Group” and “Regulation Reserve Sharing Group” as used in BAL-001-2 and BAL-003-1.1
the procedures for Technical Feasibility Exceptions in the ROP are consistent with the CIP version 5 standards (effective July 1, 2016)
RELI ABI LI TY | ACCOUNTABI LI TY 17
http://www.nerc.com/AboutNERC/Pages/Rules-of-Procedure.aspx
RELI ABI LI TY | ACCOUNTABI LI TY 18
http://www.nerc.com/FilingsOrders
RELI ABI LI TY | ACCOUNTABI LI TY 19
http://www.nerc.com/FilingsOrders/us/Pages/NERCFilings2016.aspx
RELI ABI LI TY | ACCOUNTABI LI TY 20
RELI ABI LI TY | ACCOUNTABI LI TY 21
example: Where approval by an applicable governmental authority is required, the standard shall become effective on the first day of the first calendar quarter that is [number (#)] months after the date that this standard is approved by an applicable governmental authority effective date of the applicable governmental authority’s order approving the standard, or as otherwise provided for in a jurisdiction where approval by an the applicable governmental authority is required for a standard to go into effect.
RELI ABI LI TY | ACCOUNTABI LI TY 22
example: Reliability Standard [xxx-xxx-x] shall be retired at midnight of the day immediately prior to the effective date of [new Reliability Standard] in the particular jurisdiction in which the new standard is becoming effective.
RELI ABI LI TY | ACCOUNTABI LI TY 23
example: Compliance Date for [Standard - Requirement R(x), Part (y)] Entities shall not be required to comply with Requirement [R(x), Part (y)] until [number (#)] of [months/days/years] after the effective date of Reliability Standard [xxx-xxx-x].
RELI ABI LI TY | ACCOUNTABI LI TY 24
Marisa Hecht, NERC Senior Advisor, Compliance Assurance 2016 Standards & Compliance Workshop July 13, 2016
RELI ABI LI TY | ACCOUNTABI LI TY 26
RELI ABI LI TY | ACCOUNTABI LI TY 27
compliance guidance
RELI ABI LI TY | ACCOUNTABI LI TY 28
RELI ABI LI TY | ACCOUNTABI LI TY 29
RELI ABI LI TY | ACCOUNTABI LI TY 30
discussion with industry
RELI ABI LI TY | ACCOUNTABI LI TY 31
RELI ABI LI TY | ACCOUNTABI LI TY 32
RELI ABI LI TY | ACCOUNTABI LI TY 33
Guidance
RELI ABI LI TY | ACCOUNTABI LI TY 34
RELI ABI LI TY | ACCOUNTABI LI TY 35
RELI ABI LI TY | ACCOUNTABI LI TY 36
RELI ABI LI TY | ACCOUNTABI LI TY 37
RELI ABI LI TY | ACCOUNTABI LI TY 38
RELI ABI LI TY | ACCOUNTABI LI TY 39
dance_Policy_FINAL_Board_Accepted_Nov_5_2015.pdf
PP-011_May_BOTCC_updated.pdf
RELI ABI LI TY | ACCOUNTABI LI TY 40
Scott Mix, NERC Senior CIP Technical Manager Ryan Stewart, NERC Manager of Standards Development 2016 Standards and Compliance Workshop July 14, 2016
RELI ABI LI TY | ACCOUNTABI LI TY 43
RELI ABI LI TY | ACCOUNTABI LI TY 44
822)
Operator (TOP) Obligations (V5TAG)
RELI ABI LI TY | ACCOUNTABI LI TY 45
RELI ABI LI TY | ACCOUNTABI LI TY 46
Name Entity
Chair Margaret Powell Exelon Vice Chair Christine Hasha Electric Reliability Council of Texas Vice Chair David Revill Georgia Transmission Corporation Members Steven Brain Dominion Jay Cribb Southern Company Jennifer Flandermeyer Kansas City Power and Light Tom Foster PJM Interconnection Richard Kinas Orlando Utilities Commission Forrest Krigbaum Bonneville Power Administration Philippe Labrosse Hydro-Quebec TransEnergie Mark Riley Associated Electric Cooperative, Inc. Zach Trublood Sacramento Municipal Utility District
RELI ABI LI TY | ACCOUNTABI LI TY 47
1. Revise SAR language on Virtualization so not to limit aspects for consideration to CIP-005 2. Review the requirements to include additional exceptions for CIP Exceptional Circumstances as necessary 3. Address in the implementation plan treatment of historical patches for assets newly in scope 4. Consider revisions to the CIP standards to accommodate third party (cloud) services 5. Address treatment of multi-site “asset classes” in the application of the LERC Definition 6. Account for shared facility ownership in the CIP standards and consider requirements for third party notification
RELI ABI LI TY | ACCOUNTABI LI TY 48
1. Revise SAR language on Virtualization so not to limit aspects for consideration to CIP-005 2. Review the requirements to include additional exceptions for CIP Exceptional Circumstances as necessary
RELI ABI LI TY | ACCOUNTABI LI TY 49
Definitions and Concepts Leads: Jay Cribb, Zach Trublood Support: Maggy Powell, Dave Revill, Stephen Crutchfield Tuesday 12-2 pm (Eastern) Transient Devices at Lows Leads: Steve Brain, Rich Kinas Support: Christine Hasha, Dave Revill, Stephen Crutchfield Thursday 12-2 pm (Eastern) Virtualization Leads: Philippe Labrosse, Forrest Krigbaum Support: Dave Revill, Christine Hasha, Al McMeekin Tuesday 2-4 pm (Eastern) TO Control Centers and Comm Networks Leads: Mark Riley, Jennifer Flandermeyer, Tom Foster Support: Maggy Powell, Christine Hasha, Al McMeekin Thursday 2-4 pm (Eastern) LERC Definition Leads: Jay Cribb, Steve Brain Support: Maggy Powell, Stephen Crutchfield, Al McMeekin Friday 11-1 pm (Eastern) as part of the weekly full team call
RELI ABI LI TY | ACCOUNTABI LI TY 50
RELI ABI LI TY | ACCOUNTABI LI TY 51
RELI ABI LI TY | ACCOUNTABI LI TY 52
RELI ABI LI TY | ACCOUNTABI LI TY 53
RELI ABI LI TY | ACCOUNTABI LI TY 54
RELI ABI LI TY | ACCOUNTABI LI TY 55
RELI ABI LI TY | ACCOUNTABI LI TY 56
impact the adoption of emerging technology that could benefit the reliability and security of the BES?
virtualization
RELI ABI LI TY | ACCOUNTABI LI TY 57
RELI ABI LI TY | ACCOUNTABI LI TY 58
Systems that are shared by multiple units, or groups of BES Cyber Systems that could collectively impact multiple units?
RELI ABI LI TY | ACCOUNTABI LI TY 59
RELI ABI LI TY | ACCOUNTABI LI TY 60
RELI ABI LI TY | ACCOUNTABI LI TY 61
protocol communication that crosses the boundary of an asset containing one or more low impact BES Cyber System(s), excluding communications between intelligent electronic devices used for time-sensitive protection or control functions between non-Control Center BES assets containing low impact BES Cyber Systems including, but not limited to, IEC 61850 GOOSE or vendor proprietary protocols.
initiated interactive access or a direct device-to-device connection to a low impact BES Cyber System(s) from a Cyber Asset outside the asset containing those low impact BES Cyber System(s) via a bi-directional routable protocol connection. Point- to-point communications between intelligent electronic devices that use routable communication protocols for time-sensitive protection or control functions between Transmission station or substation assets containing low impact BES Cyber Systems are excluded from this definition (examples of this communication include, but are not limited to, IEC 61850 GOOSE or vendor proprietary protocols).
RELI ABI LI TY | ACCOUNTABI LI TY 62
(LEAP): A Cyber Asset interface that controls Low Impact External Routable
external to the asset or assets containing low impact BES Cyber Systems.
RELI ABI LI TY | ACCOUNTABI LI TY 63
RELI ABI LI TY | ACCOUNTABI LI TY 64
Section 2. Physical Security Controls: Each Responsible Entity shall control physical access, based on need as determined by the Responsible Entity, to (1) the asset or the locations of the low impact BES Cyber Systems within the asset, and (2) the Cyber Asset(s), as specified by the Responsible Entity, that provide electronic access control(s) implemented for Section 3.1, if any. Section 3. Electronic Access Controls: Each Responsible Entity shall: 3.1 Implement electronic access control(s) for LERC, if any, to permit
3.2 Implement authentication for all Dial-up Connectivity, if any, that provides access to low impact BES Cyber Systems, per Cyber Asset capability.
RELI ABI LI TY | ACCOUNTABI LI TY 65
the Measures consistent with the revised requirement language. Section 2. Physical Security Controls : Examples of evidence for Section 2 may include, but are not limited to:
perimeter controls), monitoring controls (e.g., alarm systems, human
security controls that control physical access to both:
within the asset; and
electronic access controls implemented for Section 3.1, if any.
RELI ABI LI TY | ACCOUNTABI LI TY 66
Section 3. Electronic Access Controls : Examples of evidence for Section 3 may include, but are not limited to: 1. Documentation, such as representative diagrams or lists of implemented electronic access controls (e.g., restricting IP addresses, ports, or services; authenticating users; air-gapping networks; terminating routable protocol sessions on a non-BES Cyber Asset; implementing unidirectional gateways) showing that for LERC at each asset or group of assets containing low impact BES Cyber Systems, is confined only to that access the Responsible Entity deems necessary; and 2. Documentation of authentication for Dial-up Connectivity (e.g., dial
modems, modems that must be remotely controlled by the control center or control room, or access control on the BES Cyber System).
RELI ABI LI TY | ACCOUNTABI LI TY 67
RELI ABI LI TY | ACCOUNTABI LI TY 68
RELI ABI LI TY | ACCOUNTABI LI TY 69
RELI ABI LI TY | ACCOUNTABI LI TY 70
RELI ABI LI TY | ACCOUNTABI LI TY 71
RELI ABI LI TY | ACCOUNTABI LI TY 72
RELI ABI LI TY | ACCOUNTABI LI TY 73
RELI ABI LI TY | ACCOUNTABI LI TY 74