The Federal Energy Regulatory Commission (“FERC”) recently proposed that the North American Electric Reliability Corporation (“NERC”), which is responsible for promulgating and enforcing FERC-approved mandatory electric reliability standards, revise its Critical Infrastructure Protection (“CIP”) standards to require additional circumstances under which reporting of cybersecurity incidents is mandatory. FERC’s goal is to enhance the awareness of existing or developing threats, including incidents that might enable future harm to the nation’s bulk electric system.
NERC’s current CIP reliability standard, CIP-008-5 (Cyber Security – Incident Reporting and Response Planning), requires incidents to be reported only if they have compromised or disrupted one or more reliability tasks (i.e., core activities of a responsible entity). Both FERC and NERC expressed concerns that the current standard might understate the scope of cyber-related threats facing the bulk electric system.
In light of concerns that the current standard might understate the scope of cyber-related threats facing the bulk electric system, FERC issued a notice of proposed rulemaking (“NOPR”) directing NERC to broaden CIP-008-5 to:
- Include mandatory reporting of cybersecurity incidents that compromise, or attempt to compromise, a responsible entity’s Electronic Security Perimeter or Electronic Access Control and Monitoring System;
- Specify the required information in cybersecurity incident reports to improve the quality of reporting and ease of comparison by standardizing information; and
- Establish a deadline for responsible entities to submit a detailed report following a compromise or disruption, or an attempted compromise or disruption, is identified.
FERC suggests that the detailed report should be provided to the E-ISAC, similar to the current initial incident reporting scheme, and not to FERC. The new rule would also require reports be sent to the Industrial Control Systems Cyber Emergency Response Team (“ICS-CERT”) and require NERC to file an annual, public and anonymized summary of the reports with FERC. Comments to the NOPR are due February 26, 2018.