NERC to improve protection response to critical infrastructure

subscribe

Rick Sergel, president and CEO of the North American Electric Reliability Corporation (NERC), recently announced the organizationÂ’s plans to improve its response to cyber security and critical infrastructure protection concerns for the bulk power system in North America.

Revealed to NERCÂ’s board of trustees and stakeholders in a letter, the plan outlines six specific actions that will lay the foundation for improving grid reliability by enabling faster and more effective action to protect critical assets from cyber or physical threats.

These actions arise from NERCÂ’s recent interaction with various organizations, notably including the House Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology of the House Homeland Security Committee, whose efforts have been instrumental in emphasizing the urgency and priority of this critical issue.

“Cyber security is a critical component of grid reliability, but is, by its nature, fundamentally different from any other reliability concern we currently address through our standards, analysis, or enforcement programs,” commented Rick Sergel, president and CEO of NERC. “It therefore requires a different approach; one that allows for more expedient treatment of critical information, urgent action on standards, and more thorough threat analysis and risk assessment.”

“As the Electric Reliability Organization in the U.S. and home to the Electric Sector Information Sharing and Analysis Center (ES-ISAC), we are seeking to enhance and focus our existing efforts by putting the organizational structure in place to better support a more comprehensive treatment of these critical issues,” he continued. “One of our key initiatives in this area is the recent formation of the Electric Sector Steering Group (ESSG), comprised of five industry chief executives, a NERC board member, and of which I am the Chairman. The group will be instrumental in guiding NERC as we execute the plans announced today.”

Commenting on today’s announcement, Barry Lawson, Chair of NERC’s Critical Infrastructure Protection Committee (CIPC), stated “NERC’s ongoing efforts to improve its ability to respond quickly and efficiently to cyber and physical security threats are critically important to reliability of the bulk power system and the CIPC continues to be supportive of their successful execution.”

Specific actions, as detailed in the letter, include:

Increasing NERC Expertise on Critical Infrastructure Protection and Cyber Security — NERC will formally establish the Critical Infrastructure Protection program as one of NERC’s program functions, alongside existing standards development, compliance and enforcement, and reliability assessment program areas. The establishment of this program will include the staffing of a Chief Security Officer position, who will serve as the single point of contact for the industry, the ESSG, and government regulators and stakeholders seeking to communicate with NERC on cyber and infrastructure security matters.

Consider Alternative Standard Setting Process for Cyber Security Standards —NERC will establish a task force to review, and where appropriate recommend, a standard setting process for cyber security that will include an emergency/crisis standards setting process. This process must provide a level of due process and technical review, but also provide the speed necessary to establish standards quickly and respond seamlessly to government agencies in the U.S. and Canada.

Expedited Review of Existing Cyber Standards —Working through the Standards Committee, NERC also seeks to accelerate the comprehensive review of its eight existing critical infrastructure protection standards to fully incorporate the directives from FERC, including the consideration of the extent to which elements of the National Institute of Standards and Technology (NIST) standards should be incorporated therein or within new standards.

Facilitate Joint Collaboration on Cyber Security — NERC, working with the Federal Energy Regulatory Commission in the U.S. and relevant governmental authorities in Canada, will organize a briefing for the ESSG, the NERC CEO, and senior level utility executives across all stakeholder groups on cyber security threats.

Related News

Was there another reason for electricity shutdowns in California?

SAN FRANCISCO - According to the official, widely reported story, Pacific Gas & Electric (PG&E) shut down substantial portions of its electric transmission system in northern California as a precautionary measure.

Citing high wind speeds they described as “historic,” the utility claims that if it didn’t turn off the grid, wind-caused damage to its infrastructure could start more wildfires.

Perhaps that’s true. Perhaps. This tale presumes that the folks who designed and maintain PG&E’s transmission system are unaware of or ignored the need to design it to withstand severe weather events, and that the Federal Energy Regulatory Commission (FERC) and North American…

READ MORE
montreal ev race

The City of Vancouver is hosting an ABB FIA Formula E World Championship race next year, organizers have announced

READ MORE

electricity revenue meter

Opinion: With deregulated electricity, no need to subsidize nuclear power

READ MORE

wind power

France and Germany arm wrestle over EU electricity reform

READ MORE

bc hydro logo

B.C. residents and businesses get break on electricity bills for three months

READ MORE