Mandatory Reliability Standards for Critical Infrastructure Protection
Federal RegisterFeb 7, 2008
Ask Donna
What actually matters in this document.
Text
DEPARTMENT OF ENERGY
Federal Energy Regulatory Commission
18 CFR Part 40
[Docket No. RM06-22-000; Order No. 706]
Mandatory Reliability Standards for Critical Infrastructure Protection
Issued January 18, 2008.
AGENCY:
Federal Energy Regulatory Commission, Department of Energy.
ACTION:
Final Rule.
SUMMARY:
Pursuant to section 215 of the Federal Power Act (FPA), the Commission approves eight Critical Infrastructure Protection (CIP) Reliability Standards submitted to the Commission for approval by the North American Electric Reliability Corporation (NERC). The CIP Reliability Standards require certain users, owners, and operators of the Bulk-Power System to comply with specific requirements to safeguard critical cyber assets. In addition, pursuant to section 215(d)(5) of the FPA, the Commission directs NERC to develop modifications to the CIP Reliability Standards to address specific concerns.
DATES:
Effective Date:
This rule will become effective April 7, 2008.
FOR FURTHER INFORMATION CONTACT:
Gary Cohen (Legal Information), Office of the General Counsel, Federal Energy Regulatory Commission, 888 First Street, NE., Washington, DC 20426, (202) 502-8321.
Christy Walsh (Legal Information), Office of the General Counsel, Federal Energy Regulatory Commission, 888 First Street, NE., Washington, DC 20426, (202) 502-6523.
Regis Binder (Technical Issues), Office of Electric Reliability, Federal Energy Regulatory Commission, 888 First Street, NE., Washington, DC 20426, (202) 502-6460.
Jan Bargen (Technical Issues), Office of Electric Reliability, Federal Energy Regulatory Commission, 888 First Street, NE., Washington, DC 20426, (202) 502-6333.
SUPPLEMENTARY INFORMATION:
TABLE OF CONTENTS
Paragraph
Nos.
I. Background
2
II. Discussion
13
A. Overview
13
B. Approval of NERC's Proposed CIP Reliability Standards
15
1. NOPR Proposal
15
2. Comments
16
3. Commission Determination
24
C. Applicability
31
1. NOPR Proposal
32
2. Comments
35
3. Commission Determination
47
D. Compliance Measured by Outcome
54
1. Performance-Based Standards
54
2. Adequacy of Outcomes
65
E. Implementation Plan
77
1. Commission Approval of Implementation Plan
78
2. Self-Certification
91
3. Adding a Cyber Security Assessment to NERC's Readiness Reviews
100
F. Issues Presented by Terminology
106
1. Reasonable Business Judgment
107
2. Acceptance of Risk
139
3. Technical Feasibility
157
G. Use of National Institute of Standards and Technology (NIST) Standards in Developing Future Revisions to the CIP Reliability Standards
223
1. NOPR Proposal
223
2. Comments
224
3. Commission Determination
232
H. Discussion of Each CIP Reliability Standard
234
1. CIP-002-1—Critical Cyber Asset Identification
234
2. CIP-003-1—Security Management Controls
342
3. CIP-004-1—Personnel and Training
413
4. CIP-005-1—Electronic Security Perimeter(s)
477
5. CIP-006-1—Physical Security of Critical Cyber Assets
548
6. CIP-007-1—Systems Security Management
584
7. CIP-008-1—Incident Reporting & Response Planning
653
8. CIP-009-1—Recovery Plans for Critical Cyber Assets
688
I. Violation Risk Factors
749
1. General Issues
754
2. Specific Modifications to Violation Risk Factors
761
III. Information Collection Statement
770
IV. Environmental Analysis
777
V. Regulatory Flexibility Act
778
A. NOPR Proposal
782
B. Comments
788
C. Commission Determination
799
VI. Document Availability
807
VII. Effective Date and Congressional Notification
810
Before Commissioners: Joseph T. Kelliher, Chairman; Suedeen G. Kelly, Marc Spitzer, Philip D. Moeller, and Jon Wellinghoff.
Final Rule
1. Pursuant to section 215 of the Federal Power Act (FPA),
1
the Commission approves eight Critical Infrastructure Protection (CIP) Reliability Standards submitted to the Commission for approval by the North American Electric Reliability Corporation (NERC). The CIP Reliability Standards require certain users, owners, and operators of the Bulk-Power System to comply with specific requirements to safeguard critical cyber assets.
2
In addition, pursuant to section 215(d)(5) of the FPA, the Commission directs NERC to develop modifications to the CIP Reliability Standards to address specific concerns identified by the Commission.
1
16 U.S.C. 824o (2000 & Supp. V 2005).
2
In the context of the CIP Reliability Standards, cyber assets are programmable electronic devices and communication networks including hardware, software, and data.
See Mandatory Reliability Standards for Critical Infrastructure Protection,
Notice of Proposed Rulemaking, 72 FR 43970 (Aug. 6, 2007), FERC Stats & Regs. ¶ 32,620 at P 1 (Jul. 20, 2007) (CIP NOPR).
I. Background
2. Section 215 of the FPA requires a Commission-certified Electric Reliability Organization (ERO) to develop mandatory and enforceable Reliability Standards, which are subject to Commission review and approval. Once approved, the Reliability Standards may be enforced by the ERO, subject to Commission oversight, or the Commission can independently enforce Reliability Standards.
3
3
16 U.S.C. 824o(e)(3) (2000 & Supp. V 2005).
3. Pursuant to section 215 of the FPA, the Commission established a process to select and certify an ERO
4
and, subsequently, certified NERC as the ERO.
5
On April 4, 2006, as modified on August 28, 2006, NERC submitted to the Commission a petition seeking approval of 107 proposed Reliability Standards. On March 16, 2007, the Commission issued a Final Rule, Order No. 693, approving 83 of these 107 Reliability Standards and directing other related actions.
6
In addition, pursuant to section 215(d)(5) of the FPA, the Commission directed NERC to develop modifications to 56 of the 83 approved Reliability Standards.
7
4
Rules Concerning Certification of the Electric Reliability Organization; and Procedures for the Establishment, Approval, and Enforcement of Electric Reliability Standards,
Order No. 672, FERC Stats. & Regs. ¶ 31,204 (2006),
order on reh'g,
Order No. 672-A, FERC Stats. & Regs. ¶ 31,212 (2006).
5
North American Electric Reliability Corp.,
116 FERC ¶ 61,062 (ERO Certification Order),
order on reh'g & compliance,
117 FERC ¶ 61,126 (ERO Rehearing Order) (2006),
appeal docket sub nom. Alcoa, Inc.
v.
FERC,
No. 06-1426 (D.C. Cir. Dec. 29, 2006).
6
Mandatory Reliability Standards for the Bulk-Power System,
Order No. 693, FERC Stats. & Regs. ¶ 31,242 (2007); Order No. 693-A,
reh'g denied,
120 FERC ¶ 61,053 (2007).
7
Section 215(d)(5) provides “The Commission . . . may order the Electric Reliability Organization to submit to the Commission a proposed reliability standard or a modification to a reliability standard that addresses a specific matter if the Commission considers such a new or modified reliability standard appropriate to carry out this section.”
4. In April 2007, the Commission approved delegation agreements between NERC and each of the eight Regional Entities.
8
Pursuant to the delegation agreements, the ERO has delegated responsibility to the Regional Entities to carry out compliance monitoring and enforcement of the mandatory Reliability Standards.
8
See North American Electric Reliability Corp.,
119 FERC ¶ 61,060,
order on reh'g,
120 FERC ¶ 61,260 (2007).
5. Prior to being certified by the Commission as the ERO, NERC had developed a cyber security standard for the electric industry on a voluntary basis. This voluntary standard, Urgent Action 1200, was adopted in 2003, and remained in effect on a voluntary basis until June 1, 2006, at which time the eight CIP Reliability Standards that are the subject of the current rulemaking replaced the Urgent Action 1200 standard.
6. On August 28, 2006, NERC submitted to the Commission for approval the following eight CIP Reliability Standards:
9
9
The CIP Reliability Standards are not codified in the CFR and are not attached to the Final Rule. They are, however, available on the Commission's eLibrary document retrieval system in Docket No. RM06-22-000 and are available on the ERO's Web site,
http://www.nerc.com.
CIP-002-1—Cyber Security—Critical Cyber Asset Identification:
Requires a responsible entity to identify its critical assets and critical cyber assets using a risk-based assessment methodology.
CIP-003-1—Cyber Security—Security Management Controls:
Requires a responsible entity to develop and implement security management controls to protect critical cyber assets identified pursuant to CIP-002-1.
CIP-004-1—Cyber Security—Personnel & Training:
Requires personnel with access to critical cyber assets to have identity verification and a criminal check. It also requires employee training.
CIP-005-1—Cyber Security—Electronic Security Perimeters:
Requires the identification and protection of an electronic security perimeter and access points. The electronic security perimeter is to encompass the critical cyber assets identified pursuant to the methodology required by CIP-002-1.
CIP-006-1—Cyber Security—Physical Security of Critical Cyber Assets:
Requires a responsible entity to create and maintain a physical security plan that ensures that all cyber assets within an electronic security perimeter are kept in an identified physical security perimeter.
CIP-007-1—Cyber Security—Systems Security Management:
Requires a responsible entity to define methods, processes, and procedures for securing the systems identified as critical cyber assets, as well as the non-critical cyber assets within an electronic security perimeter.
CIP-008-1—Cyber Security—Incident Reporting and Response Planning:
Requires a responsible entity to identify, classify, respond to, and report cyber security incidents related to critical cyber assets.
CIP-009-1—Cyber Security—Recovery Plans for Critical Cyber Assets:
Requires the establishment of recovery plans for critical cyber assets using established business continuity and disaster recovery techniques and practices.
7. NERC states that these CIP Reliability Standards provide a comprehensive set of requirements to protect the Bulk-Power System from malicious cyber attacks. They require Bulk-Power System users, owners, and operators to establish a risk-based vulnerability assessment methodology to identify and prioritize critical assets and critical cyber assets. Once the critical cyber assets are identified, the CIP Reliability Standards require, among other things, that the responsible entities establish plans, protocols, and controls to safeguard physical and electronic access, to train personnel on security matters, to report security incidents, and to be prepared for recovery actions. Further, NERC developed an implementation plan that provides for a three-year phase-in to achieve full compliance with all requirements.
8. Each CIP Reliability Standard uses a common organizational format that includes five sections, as follows: (A) Introduction, which includes “Purpose” and “Applicability” sub-sections; (B) Requirements; (C) Measures; (D) Compliance; and (E) Regional Differences. In this Final Rule, these section titles are capitalized when referencing a designated provision of a Reliability Standard.
9. In a separate filing, NERC submitted 162 Violation Risk Factors that correspond to Requirements of the proposed CIP Reliability Standards.
10
Violation Risk Factors delineate the relative risk to the Bulk-Power System associated with the violation of each Requirement and are used by NERC and the Regional Entities to determine financial penalties for violating a Reliability Standard.
10
See
NERC's March 23, 2007 filing in Docket No. RR07-10-000, Exh. A.
10. On December 11, 2006, the Commission released a “Staff
Preliminary Assessment of the North American Electric Reliability Corporation's Proposed Mandatory Reliability Standards on Critical Infrastructure Protection” prepared by the Commission's staff (CIP Assessment). The CIP Assessment identified staff's preliminary observations and concerns regarding the eight proposed CIP Reliability Standards, describing issues common to a number of the proposed CIP Reliability Standards, and discussing various issues raised by individual CIP Reliability Standards. While discussing the issues, the CIP Assessment did not make specific recommendations on the appropriate action to be taken by the Commission on particular proposals.
11
11
The CIP Assessment is available on the Commission's webpage at
http://www.ferc.fed.us/industries/electric/indus-act/reliability.asp.
11. On July 20, 2007, the Commission issued the CIP NOPR, which proposed to approve the eight CIP Reliability Standards submitted to the Commission for approval by NERC. In addition, the Commission proposed to direct NERC to develop modifications to the CIP Reliability Standards to address specific concerns identified by the Commission.
12. In response to the CIP NOPR, comments were filed by about 70 interested persons. In the discussion below, we will address the issues raised by these comments. Appendix A to this Final Rule lists the entities that filed comments on the CIP NOPR. Five comments were filed after the time prescribed in the CIP NOPR. Nevertheless, the Commission will consider these comments, as they will neither prejudice the other commenters, nor delay the proceeding.
II. Discussion
A. Overview
13. In the Final Rule, the Commission approves the eight CIP Reliability Standards, finding that they are just and reasonable, not unduly discriminatory or preferential and in the public interest. Further, the Commission approves NERC's implementation plan that sets milestones for responsible entities to achieve full compliance with the CIP Reliability Standards. The Commission also directs NERC to develop modifications to the CIP Reliability Standards through its Reliability Standards development process to address specific concerns identified by the Commission. Similar to our approach in Order No. 693, we view such directives as a separate action from approval, consistent with our authority in section 215(d)(5) of the FPA to direct the ERO to develop a modification to a Reliability Standard. As discussed below, such modification should not affect the current implementation plan. Rather, NERC is directed to develop a timetable for development of the modifications to the CIP Reliability Standards and, if warranted, to develop and file with the Commission for approval, a second implementation plan.
14. Other determinations in the Final Rule include:
A directive that the ERO must develop modifications to the CIP Reliability Standards to remove the “reasonable business judgment” language.
The ERO must also develop modifications to remove “acceptance of risk” exceptions from the CIP Reliability Standards.
The ERO is directed to develop specific conditions that a responsible entity must satisfy to invoke the “technical feasibility” exception. This structure for use of the technical feasibility exception allows flexibility and customization of implementation of the CIP Reliability Standards in a controlled manner.
The Commission directs the ERO to provide additional guidance regarding the development of a risk-based assessment methodology for the identification of critical assets pursuant to CIP-002-1. Further, external review of critical asset lists is required.
The Commission directs the ERO to make specific revisions to its Violation Risk Factor designations.
B. Approval of NERC's Proposed CIP Reliability Standards
1. NOPR Proposal
15. In the CIP NOPR, the Commission proposed to approve NERC's eight proposed CIP Reliability Standards as mandatory and enforceable. As a separate action, pursuant to section 215(d)(5) of the FPA, the Commission proposed to direct NERC to modify certain provisions of the CIP Reliability Standards.
2. Comments
16. Most commenters strongly support the Commission's proposal to approve the CIP Reliability Standards as mandatory and enforceable.
12
For example, EEI states that the CIP Reliability Standards are technically sound and well designed to achieve the specified reliability goal, namely cyber security for electric industry critical assets. EEI adds that the CIP Reliability Standards are designed to serve the interest of preserving grid reliability by seeking to prevent unauthorized access to control systems and other critical cyber assets, whether by physical or electronic means. EEI believes that the CIP Reliability Standards strike the appropriate balance in providing reasonable flexibility in an environment where systems vary greatly in architecture, technology, and risk profile.
13
12
E.g.,
Alliant, Arizona Public Service, Bonneville, California Commission, Duke, EEI, Idaho Power, ISO/RTO Council, Juniper, KCPL, Luminant, Manitoba, NERC, New York Commission, Northeast Utilities, Ontario IESO, Ontario Power, PG&E, PSEG Companies, Progress, Puget Sound, ReliabilityFirst, SDG&E, Southern, Tampa Electric, Teltone and Xcel.
13
Alliant, KCPL, PG&E, Puget Sound, PSEG Companies and Southern support EEI's views.
17. By contrast, ABB argues that the Commission should defer action so that equipment vendors and the standard-setting organizations such as the Institute of Electrical and Electronics Engineers can coordinate electric power system cyber security initiatives. Applied Control Solutions argues that the proposals in the CIP NOPR do not go far enough, and that the Commission should go further and immediately adopt the National Institute of Standards and Technology (NIST) Security Risk Management Framework in place of the CIP Reliability Standards.
18. NIST itself argues that the Commission should adopt the NERC proposed CIP Reliability Standards, as appropriately enhanced based on the Commission's proposed directives in the CIP NOPR, as an interim measure. NIST advocates that the Commission prescribe plans for a two to three year transition to cyber security standards that are identical to, consistent with, or based on SP 800-53 and related NIST standards and guidelines.
19. WIRAB supports NERC's CIP Reliability Standards and states that they represent a significant advancement for cyber security and Bulk-Power System reliability. Yet, WIRAB recommends that the Commission remand the CIP Reliability Standards to NERC with guidance as to the types of changes the Commission would like to see, but without direction to make any specific change. WIRAB expresses concern that the CIP NOPR proposes numerous detailed directives to modify the CIP Reliability Standards and goes beyond providing guidance to NERC. WIRAB states that a remand would allow the Reliability Standards development process to work as anticipated and, in doing so, would avoid problems with different Reliability Standards or different levels of enforcement on different sides of the international border.
20. In response to our proposal to modify certain CIP Reliability Standards, some commenters maintain that the Commission's proposals were
overly prescriptive.
14
Others state that any prescriptive elements of the CIP NOPR should be replaced with directions that NERC use its Commission-approved Reliability Standards development process to address any necessary changes identified by the Commission.
15
PG&E adds that the measures agreed on in the NERC stakeholder process and included in the CIP Reliability Standards represent a reasonable balance between aggressive Reliability Standards and measures that are feasible and sustainable. EEI argues that the Commission needs to be careful when it provides guidance that it does not usurp NERC's authority as ERO by dictating a specific or exclusive outcome from this process.
14
E.g.,
CEA, EEI, FirstEnergy, PSEG Companies, SDG&E and Tampa Electric.
15
E.g.,
Georgia Operators, Idaho Power, Muscatine Power, NERC, Northern California, NRECA, TAPS and Xcel.
21. Commenters also express concern that the Commission might intend to sidestep the NERC stakeholder process and have NERC simply revise the CIP Reliability Standards in accordance with the Commission's proposals without providing NERC stakeholders an opportunity to participate in this process.
16
In this regard, EEI urges that the Final Rule make clear that any improvements to the CIP Reliability Standards should be considered in the NERC Reliability Standards development process before being mandated.
16
See,
e.g.
, Allegheny, Alliant, Arizona Public Service, Duke, EEI, Entergy, FirstEnergy, FPL Group, Iowa Municipals, KCPL, Luminant, PG&E, Progress, PSEG Companies, Tampa Electric and TAPS.
22. KCPL supports the Commission's proposal to direct NERC to develop modifications to the CIP Reliability Standards to address potential improvements using the Reliability Standards development process. KCPL believes that the Commission has authority to direct the ERO to modify the CIP Reliability Standards and to provide sufficient guidance to the direction that grid reliability should take so as to fulfill its obligations under the Energy Policy Act of 2005. However, KCPL too is concerned that several of the Commission's proposed requirement directives are overly prescriptive.
23. The New York Commission opposes the Commission placing any conditions on its approval of the CIP Reliability Standards, such as requiring NERC to rewrite them as a condition for their approval.
3. Commission Determination
24. The Commission approves the eight CIP Reliability Standards pursuant to section 215(d) of the FPA, as discussed below. In approving the CIP Reliability Standards, the Commission concludes that they are just, reasonable, not unduly discriminatory or preferential, and in the public interest. These CIP Reliability Standards, together, provide baseline requirements for the protection of critical cyber assets that support the nation's Bulk-Power System. Thus, the CIP Reliability Standards serve an important reliability goal.
17
Further, as discussed below, the CIP Reliability Standards clearly identify the entities to which they apply, apply throughout the interconnected Bulk-Power System, and provide a reasonable timetable for implementation.
18
17
See
Order No. 672 at P 321.
18
Id
. P 322-35.
25. The Commission believes that the NIST standards may provide valuable guidance when NERC develops future iterations of the CIP Reliability Standards. Thus, as discussed below, we direct NERC to address revisions to the CIP Reliability Standards CIP-002-1 through CIP-009-1 considering applicable features of the NIST framework. However, in response to Applied Control Solutions, we will not delay the effectiveness of the CIP Reliability Standards by directing the replacement of the current CIP Reliability Standards with others based on the NIST framework.
26. With regard to WIRAB's recommendation, we share the ongoing concern of promoting coordinated action on Reliability Standards on an international basis. However, in this instance, we do not believe a remand to NERC, which would result in significant delays in having mandatory and enforceable cyber security requirements in effect in the United States, is justified or would further such coordination. The implementation schedule provided by NERC, which applies continent-wide, requires applicable entities to achieve “auditable compliance” no earlier than mid-2009. This should provide adequate time for entities responsible for compliance with the CIP Reliability Standards in the United States, Canada and Mexico to achieve compliance on a common timetable. As discussed later, future modifications to the CIP Reliability Standards developed pursuant to the direction provided in the Final Rule would not overlap with the NERC implementation plan. Accordingly, the Commission concludes that this is not a satisfactory reason for remanding the CIP Reliability Standards.
27. In approving the CIP Reliability Standards and directing the ERO to modify them, the Commission is taking two independent actions and does not condition our approval on the ERO modifying the CIP Reliability Standards. First, we are exercising our authority to approve a proposed Reliability Standard. Second, we are directing the ERO to submit a modification of the Reliability Standards to address specific issues or concerns.
19
Accordingly, New York Commission's concerns about the Commission placing any conditions on its approval of the CIP Reliability Standards are unnecessary.
19
16 U.S.C. 824o(d)(5) (“[t]he Commission . . . may order the Electric Reliability Organization to submit to the Commission a proposed Reliability Standard or modification to a Reliability Standard that addresses a specific matter if the Commission considers such a new or modified Reliability Standard appropriate to carry out this section.”).
28. With regard to the concerns raised by some commenters about the prescriptive nature of the Commission's proposed modifications, the Commission agrees that a direction for modification should not be so overly prescriptive as to preclude the consideration of viable alternatives in the ERO's Reliability Standards development process. However, in identifying a specific matter to be addressed in a modification to a CIP Reliability Standard, it is important that the Commission provide sufficient guidance so that the ERO has an understanding of the Commission's concerns and an appropriate, but not necessarily exclusive, outcome to address those concerns. Without such direction and guidance, a Commission proposal to modify a CIP Reliability Standard might be so vague that the ERO would not know how to adequately respond.
20
20
See
Order No. 693 at P 185-87.
29. Thus, in some instances, while we provide specific details regarding the Commission's expectations, we intend by doing so to provide useful guidance to assist in the Reliability Standards development process, not to impede it. We find that this is consistent with statutory language that authorizes the Commission to order the ERO to submit a modification “that addresses a specific matter” if the Commission considers it appropriate to carry out section 215 of the FPA. In the Final Rule, we have considered commenters' concerns and, where a directive for modification appears to be determinative of the outcome, the Commission provides flexibility by directing the ERO to
address the underlying issue through the Reliability Standards development process without mandating a specific change to the CIP Reliability Standard. Further, the Commission clarifies that, where the Final Rule identifies a concern and offers a specific approach to address that concern, we will consider an equivalent alternative approach provided that the ERO demonstrates that the alternative will adequately address the Commission's underlying concern or goal as efficiently and effectively as the Commission's proposal.
30. Consistent with section 215 of the FPA, our regulations, and Order No. 693, any modification to a Reliability Standard, including a modification that addresses a Commission directive, must be developed and fully vetted through NERC's Reliability Standard development process. Until the Commission approves NERC's proposed modification to a Reliability Standard, the preexisting Reliability Standard will remain in effect.
C. Applicability
31. The Applicability section of each proposed CIP Reliability Standard identifies the following 11 categories of responsible entities that must comply with the CIP Reliability Standard: Reliability coordinators, balancing authorities, interchange authorities,
21
transmission service providers, transmission owners, transmission operators, generator owners, generator operators, load serving entities, NERC, and Regional Reliability Organizations.
21
See
Docket No. RR08-3-000 wherein, on November 11, 2007, NERC filed an amendment to its Statement of Compliance Registry Criteria to add Interchange Authority to the list of functional entities that are required to comply with certain Reliability Standards.
1. NOPR Proposal
32. The CIP NOPR explained that, with regard to the applicability of the CIP Reliability Standards to the ERO, NERC has modified its Rules of Procedure to provide that the ERO will comply with each Reliability Standard that identifies the ERO as an applicable entity.
22
Further, the delegation agreements between NERC and each of the eight Regional Entities expressly state that the Regional Entity is committed to comply with approved Reliability Standards. The Commission stated its belief that, while it is likely that NERC and the Regional Entities are not directly subject to mandatory Reliability Standards as users, owners or operators of the Bulk-Power System, their adherence to the CIP Reliability Standards pursuant to the NERC Rules of Procedure and the delegation agreements suffices.
22
See
CIP NOPR at P 21-31; NERC Rules of Procedure, section 100.
33. The Commission also indicated in the CIP NOPR that it would rely on the NERC registration process to determine applicability with the CIP Reliability Standards.
23
While expressing concern about small entities becoming a gateway for cyber attacks, the Commission indicated that it was prepared to rely on the registration process based in part on the expectation that industry will use the “mutual distrust” posture.
24
The Commission also explained that it would rely on the NERC registration process to include all critical assets and associated critical cyber assets, and listed examples. Further, we noted that because, as an initial compliance step, each entity that is responsible for compliance with the CIP Reliability Standards must first identify critical assets through the application of a risk-based assessment, CIP-002-1 acts as a filter, determining a subset of entities that must comply with the remaining CIP requirements (i.e., CIP-003-1 through CIP-009-1).
23
Id.
P 27. The CIP NOPR also affirmed the statement in Order No. 693 that the Commission intends to further examine applicability issues under section 215 of the FPA in a future proceeding. Order No. 693 at P 77.
24
Id.
P 28. The term “mutual distrust ” is used to denote how “outside world” systems are treated by those inside the control system. A mutual distrust posture requires each responsible entity that has identified critical cyber assets to protect itself and not trust any communication crossing an electronic security perimeter, regardless of where that communication originates. This concept is discussed further in the context of CIP-003-1.
34. The Commission also raised concerns regarding operation of critical cyber assets by out-sourced entities.
25
The CIP NOPR noted that, on occasion, NERC negotiates contracts with third-party vendors, and the products developed by the vendors are then used by responsible entities that, as owners of the critical cyber assets, are ultimately responsible for their cyber security protection under the CIP Reliability Standards. The Commission solicited comment on whether and how out-sourced entities should be contractually obligated to comply with the CIP Reliability Standards while satisfying their other contractual obligations.
25
CIP NOPR at P 31.
2. Comments
35. Most commenters that address the issue support the Commission's approach to assuring NERC and Regional Entity compliance with the CIP Reliability Standards. Commenters also support the Commission's reliance on the NERC registration process to identify appropriate entities. Numerous commenters address the issue of third-party vendors, indicating that such third parties are not subject to mandatory Reliability Standards and that responsible entities need to address the matter through contractual provisions with their vendors.
a. Applicability to NERC and Regional Entities
36. EEI supports the Commission's conclusion that NERC's modifications to its Rules of Procedure and the delegation agreements between NERC and each of the eight Regional Entities with respect to compliance with approved Reliability Standards is sufficient and does not require any additional measures or revisions at this time. EEI expects that the Commission will provide oversight with respect to compliance by NERC and a Regional Entity. However, unlike responsible entities, the ERO and Regional Entities are not subject to penalties under the FPA. Therefore, in considering what level of oversight to provide for these entities, EEI urges the Commission to consider that these entities do not have the same incentive as responsible entities to comply with the CIP Reliability Standards.
37. Progress believes that the CIP Reliability Standards must apply to the ERO and the Regional Entities since they have access to critical data of many electric systems and may be perceived as more strategic targets than other registered entities. California Commission, Northern Indiana and Northeast Utilities also assert that the CIP Reliability Standards should apply to NERC and the Regional Entities. Northern Indiana states that subjecting NERC to the CIP Reliability Standards would obviate Northern Indiana's concern with providing NERC personnel with access to information they may need when reviewing and evaluating Northern Indiana's compliance measures.
38. California Commission comments that the CIP NOPR properly recognized the ERO as an applicable entity. It also states that the delegation agreements between NERC and the Regional Entities mandate that the Regional Entities will be subject to the CIP Reliability Standards. California Commission states that, if the ERO or Regional Entities do not adhere to the CIP Reliability Standards, they could become the weak link whose failure could harm the Bulk-Power System.
b. Reliance on NERC Registration Process
39. NRECA, MEAG Power and other commenters support the Commission's reliance on the NERC registration process to identify appropriate entities and also share the concern that entities not registered could become a weakness in the security of the Bulk-Power System.
26
NRECA states that the Commission's proposed approach is appropriate and consistent with the Commission's prior orders, the statute, and the ERO's Statement of Registry Criteria. EEI suggests that proper registration, combined with a strong ERO audit program, would assure that all critical assets are covered by the CIP Reliability Standards. EEI also asks the Commission to clarify that the NERC registration process would identify responsible entities, but not critical assets.
26
E.g.
, Duke, EEI, Energy Producers, Northeast Utilities and Reliant.
40. EEI and ISO/RTO Council agree with the statement in the CIP NOPR that demand side aggregators might also need to be included in the NERC registration process if their load shedding capacity would affect the reliability or operability of the Bulk-Power System. EEI comments that demand side aggregators do not fit into any of the current registry categories and their inclusion would likely require the development of a definition of “demand response” and “direct load control,” as well as size thresholds, which are best addressed in the NERC Reliability Standards development process.
41. California Commission comments that small entities can become a weak link whose failure could harm Bulk-Power System reliability. It is concerned that an entity that should be registered may slip through the identification process. Accordingly, California Commission suggests that any entity connected to the Bulk-Power System, regardless of size, must comply with the CIP Reliability Standards irrespective of their registration status.
c. Third-Party Vendors
42. The majority of commenters contend that neither the ERO, nor the Commission, have authority to extend the applicability of the CIP Reliability Standards to third-party vendors.
27
NRECA, for example, argues that this conclusion is dictated by statute, as section 215 of the FPA only applies to users, owners and operators of the Bulk-Power System and does not confer jurisdiction over third-party vendors. Accordingly, commenters claim that the relationship between registered entities and their outsourced providers is necessarily one of contract, and the regulatory compliance obligation falls solely on the registered entity.
27
See
,
e.g.
, Alliant, Mr. Brown, Duke, EEI, ISO/RTO Council, NRECA, PG&E, SDG&E and Tampa Electric.
43. EEI agrees with the CIP NOPR statement that responsible entities, as owners of critical assets, are ultimately accountable for their cyber security protection under the Reliability Standards. EEI also comments that it is reasonable that responsible entities may wish to provide their vendors with incentives to comply with CIP Reliability Standards while satisfying their other contractual obligations.
28
According to ReliabilityFirst, out-sourced products developed for the exchange of data integral to reliability must be developed in compliance with the CIP Reliability Standards. It believes the responsible entity should contractually obligate vendors of such products to comply with appropriate requirements of the CIP Reliability Standards.
28
Alliant, Mr. Brown, PG&E, SDG&E and Tampa Electric agree with EEI's position.
44. ISO/RTO Council comments that, when an application is developed and maintained by an outsourced provider, that provider manages access to the environment on which the application runs and therefore must be contractually obligated by the responsible entity to comply with the CIP Reliability Standards. While not in NERC's registry, such third parties must perform the services and operate the applications in a manner consistent with the CIP Reliability Standards. According to ISO/RTO Council, the responsible entity should be charged with incorporating contractual terms and conditions into its agreements with the third-party provider that obligates the provider to comply with the requirements of the CIP Reliability Standards. Responsibility for non-compliance by the third-party vendor should be borne by the responsible entity that made the business decision to outsource the application.
45. Other commenters contend that the CIP Reliability Standards must apply to vendors and contractors as well as responsible entities. For example, California Commission suggests that the CIP Reliability Standards should apply to every entity that has a cyber connection to the Bulk-Power System. However, in California Commission's view, some special rules must be developed on CIP Reliability Standards applicability for entities that are not responsible entities but that have entered contracts obligating them to comply with the CIP Reliability Standards. Consumers claims that vendors and contactors with access (remote and on-site) to the critical cyber assets should be required to comply with the CIP Reliability Standards' personnel risk assessment guidelines. Consumers also advocates that vendor companies should have a personnel risk assessment policy, i.e., background check, for all new personnel and all systems (software applications and hardware devices) should be tested for quality and reliability.
46. Northern Indiana comments that third-party vendors working for NERC must comply with the CIP Reliability Standards, e.g., background checks, just as Northern Indiana's third-party vendors must. Otherwise, NERC's vendors should not be given access to critical cyber assets.
3. Commission Determination
47. The Commission adopts the CIP NOPR approach regarding NERC and Regional Entity compliance with the CIP Reliability Standards. The Commission maintains its belief that NERC's compliance is necessary in light of its interconnectivity with other entities that own and operate critical assets. Further, we conclude that NERC's Rules of Procedure, which state that the ERO will comply with each Reliability Standard that identifies the ERO as an applicable entity, provide an adequate means to assure that NERC is obligated to comply with the CIP Reliability Standards. Likewise, the delegation agreements between NERC and each Regional Entity expressly state that the Regional Entity is committed to comply with approved Reliability Standards.
29
Based on these provisions, we find that the Commission has authority to oversee the compliance of NERC and the Regional Entities with the CIP Reliability Standards.
29
In Order No. 693, at P 157, the Commission directed NERC to remove each reference to the Regional Reliability Organization and replace it with a reference to the Regional Entity. This directive applies to the CIP Reliability Standards as well.
48. With regard to EEI's concerns about NERC's incentives to comply with the CIP Reliability Standards, we believe that NERC's position as overseer of Bulk-Power System reliability provides a level of assurance that it will take compliance seriously. Moreover, section 215(e)(5) of the FPA provides that the Commission may take such action as is necessary or appropriate against the ERO or a Regional Entity to
ensure compliance with a Reliability Standard or Commission order.
30
30
Section 39.9 of the Commission's regulations provides similar language to that of the statute. In Order No. 672, the Commission discussed its authority to take action against the ERO or a Regional Entity and the types of actions that are available.
See
Order No. 672 at P 761-62.
49. The Commission also adopts its CIP NOPR approach and concludes that reliance on the NERC registration process at this time is an appropriate means of identifying the entities that must comply with the CIP Reliability Standards.
31
We are concerned, like the California Commission, that some small entities that are not identified in the NERC registry may become gateways for cyber attacks. However, we are not prepared to adopt California Commission's suggested approach of requiring that any entity connected to the Bulk-Power System, regardless of size, must comply with the CIP Reliability Standards irrespective of the NERC registry. We believe this approach is overly-expansive and may raise jurisdictional issues. Rather, we rely on NERC and the Regional Entities to be vigilant in assuring that all appropriate entities are registered to ensure the security of the Bulk-Power System.
31
CIP NOPR at P 26-30.
50. With regard to EEI's request for clarification, the NERC registry process is designed to identify and register entities for compliance with Reliability Standards, and not identify lists of assets. In the CIP NOPR, the Commission explained that it would expect NERC to register the owner or operator of an important asset, such as a blackstart unit, even though the facility may be relatively small or connected at low voltage.
32
While the facility would not be registered or listed through the registration process, NERC's or a Regional Entity's awareness of the critical asset may reasonably result in the registration of the owner or operator of the facility.
32
Id.
P 29.
51. Likewise, we believe that NERC should register demand side aggregators if the loss of their load shedding capability, for reasons such as a cyber incident, would affect the reliability or operability of the Bulk-Power System. EEI and ISO/RTO Council concur that the need for the registration of demand side aggregators may arise, but state that it is not clear whether aggregators fit any of the current registration categories defined by NERC. We agree with EEI and ISO/RTO Council that NERC should consider whether there is a current need to register demand side aggregators and, if so, to address any related issues and develop criteria for their registration.
52. The Commission agrees with the many commenters that suggest that the responsibility of a third-party vendor for compliance with the CIP Reliability Standards is a matter that should be addressed in contracts between the registered entity that is responsible for mandatory compliance with the Standards and its vendor. To the extent that the responsible entity makes a business decision to hire an outside contractor to perform services for it, the responsible entity remains responsible for compliance with the relevant Reliability Standards. Thus, it is incumbent upon the responsible entity to assure that its third-party vendor acts in compliance with the CIP Reliability Standards. We agree with ISO/RTO Council's characterization of the matter:
. . . when an application is developed and maintained by an outsourced provider, that outsourced provider manages physical and cyber access to the environment on which the application runs and therefore must be contractually obligated to the Responsible Entity to comply with the Reliability Standards.
While such providers are not registered entities subject to the Reliability Standards, they must perform the services and operate the applications in a manner consistent with the Reliability Standards . . . the Responsible Entity should be charged with incorporating contractual terms and conditions into agreements with third-party service providers that obligate the providers to comply with the requirements of the Reliability Standards. In that regard, if a Responsible Entity determines that it is necessary to outsource a service that is essential to the reliable operation of a Critical Asset, Critical Cyber Asset, or the bulk electric system, it is clear that the Responsible Entity must be held responsible and accountable for compliance with the Reliability Standards.[
33
]
33
ISO/RTO Council comments at 21-22.
53. Further, it is incumbent upon a responsible entity to conduct vigorous oversight of the activities and procedures followed by the vendors they employ. Thus, we expect a responsible entity to address in its security policy under CIP-003-1 its policies regarding its oversight of third-party vendors.
D. Compliance Measured by Outcome
1. Performance-Based Standards
a. NOPR Proposal
54. The CIP NOPR expressed concern that the lack of specificity within the proposed CIP Reliability Standards could result in inadequate implementation efforts and inconsistent results.
34
In addressing the appropriate amount of specificity, the Commission stated that “performance-based standards may not always be appropriate, for example, in situations where the `how' may be inextricably linked to the Reliability Standard and may need to be specified to ensure the enforceability of the standard.”
35
Thus, the Commission indicated that it may be appropriate to direct NERC in specific instances to develop modifications to the CIP Reliability Standards to address the “how.”
34
CIP NOPR at P 32, citing CIP Assessment at 3.
35
Id.
at P 33, quoting Order No. 672 at P 260.
55. The CIP NOPR also noted that the CIP Reliability Standards do not provide a mechanism to measure performance. The Commission identified three strategies for monitoring performance: (1) Internal and external oversight of a responsible entity's activities; (2) documenting, monitoring and revisiting a responsible entity's exercise of flexibility in a way that excepts it from a Requirement; and (3) reporting certain wide-area information and analysis to the Commission.
b. Comments
56. NERC and others comment that the CIP Reliability Standards should prescribe what outcome must be accomplished, but should not prescribe how that outcome is accomplished.
36
These commenters contend that discussion on how to implement a Requirement should be provided in a separate reference document such as guidelines or white papers, but not included in the CIP Reliability Standards themselves. This approach would allow responsible entities to retain the flexibility to implement a solution that best meets their needs.
37
According to NERC, including “how” language in the CIP Reliability Standards would dictate the only acceptable manner of implementation and thwart other acceptable, and possibly superior, methods of satisfying the Reliability Standards. In contrast, a guidance document allows more flexibility and is more easily updated as technology advances.
36
E.g.
, EEI, Alliant, Arizona Public Service, Mr. Brown, FirstEnergy, ISO/RTO Council, Luminant, Northeast Utilities, Ontario Power, PSEG Companies, Puget Sound and Southern.
37
E.g.
, NERC, ReliabilityFirst and Mr. Brown.
57. In addition, NERC expresses concern that including acceptable solutions as part of the CIP Reliability Standards could introduce common vulnerabilities based on all industry participants using a nearly identical solution to a given vulnerability.
38
PSEG Companies share this concern, adding that identifying the technology
to be used to combat vulnerabilities creates vulnerabilities and allows hackers to focus their efforts on disrupting those systems. NERC and ReliabilityFirst also argue that guidance to address every contingency would be voluminous and difficult to write.
38
Ontario Power and ReliabilityFirst raise similar concerns.
58. A number of commenters also provide comment regarding performance measurement and the Commission's proposal for internal and external oversight. NERC contends that much of the proposed additional oversight is in place in the existing ERO and regional compliance and audit programs. NERC explains that these programs are being updated based on the Requirements of the CIP Reliability Standards.
59. Other commenters, such as EEI, ISO/RTO Council and Puget Sound, suggest that the determination of whether a responsible entity meets or fails to meet the requirements of a CIP Reliability Standard should be determined in an audit based on the specific facts and circumstances of its use, ownership or operation of the Bulk-Power System. EEI argues that a strong auditing requirement serves to ensure quality control, and will result in consistency in the implementation of the CIP Reliability Standards. KCPL states that the information technology associated with cyber security provides a unique challenge for the audit function and auditors must have a significant amount of experience with both the industry and the cyber security needs to ensure that the obligations to the CIP Reliability Standards are properly evaluated during an audit. SERC-CIPC adds that the distinction between mandatory requirements and non-binding guidance should be made clear to auditors, noting that these differences could be subtle.
60. With regard to external oversight, Northern Indiana believes that certain independent entities' employees “such as [those performing] the internal audit function” can provide a wide-area view. Northern Indiana requests clarification on what the Commission means by the term “external oversight.”
c. Commission Determination
61. The Commission received comments on both sides of the issue of specificity. Some commenters caution against the CIP Reliability Standards being too specific, while others request more guidance to help them comply. In general, the Commission believes it is appropriate to provide sufficient guidance to explain Requirements so that responsible entities have a high degree of certainty that they understand what is necessary to comply with a Requirement. More guidance will allow responsible entities to implement measures adapted to their specific situations more consistently and effectively. Additional guidance need not be included in a specific Requirement, but could be in the form of examples. The Commission is not directing that the ERO establish a specific end result. Our concern is simply that responsible entities have guidance on how to achieve an appropriate result in individual cases, which can vary on a case-by-case basis. Therefore, in several instances throughout this Final Rule, the Commission gives the ERO direction to provide additional guidance. In some cases, we require that the guidance be placed in modifications to the CIP Reliability Standards. In other cases, we note that some or all of the additional guidance could be placed in a reference document separate from the CIP Reliability Standards.
62. Some of the more specific directives in this Final Rule pertain to issues that the Commission considers necessary to carry out its statutory responsibilities. Examples of this include areas of oversight, exceptions to Requirements, and reports to the Commission. In developing these directives, we have tried to strike a balance between our needs to implement the statute and the concerns expressed by commenters.
63. We agree in general with commenters who point out that compliance issues should be determined in audits and that a strong auditing process will help to ensure quality control and consistency in the implementation of the CIP Reliability Standards. However, we point out that audits are only one aspect of the ERO's compliance monitoring and enforcement process. All aspects of that process must function well. In addition, we note compliance audits are conducted after-the-fact and do not diminish the necessity for internal and external reviews of compliance efforts, including the identification of critical assets and critical cyber assets.
64. In response to Northern Indiana, we explain “external oversight” in our discussions and determinations of specific Requirements in the Final Rule.
2. Adequacy of Outcomes
a. NOPR Proposal
65. The CIP NOPR noted that many of the Requirements of the CIP Reliability Standards consist of broad directives, with corresponding Measures and Compliance provisions focusing largely on proper documentation.
39
The Commission asserted that documentation by itself does not satisfy the Requirements of a Reliability Standard and, rather, implementation of the substance of the Requirements is most important in determining compliance.
39
CIP NOPR at P 35-41.
66. The Commission also noted that, while certain Requirements of the CIP Reliability Standards obligate a responsible entity to develop and maintain a plan, policy or procedure, the Requirements do not always explicitly require implementation of the plan, policy or procedure. The Commission proposed to interpret such provisions to include an implicit implementation requirement.
b. Comments
i. Documentation
67. SPP and ReliabilityFirst agree with the Commission that adequate documentation does not substitute for substantive compliance with the responsibilities set forth in the requirements of the CIP Reliability Standards. However, they express concern that not relying on objective documentation requirements to demonstrate compliance could result in subjective variations in the audit process and uneven application of the Requirements of a Reliability Standard. ReliabilityFirst states that, while it is reasonable to apply subjective reasoning as part of a readiness assessment, any audit that could result in financial sanctions for non-compliance must rely solely upon clearly defined objective measures. To remedy the concern that documentation may not assure compliance with a CIP Reliability Standard, SPP suggests that the Requirements and Measures prescribed in a CIP Reliability Standard be enhanced to define the minimum acceptable documentation content.
68. In the context of measuring performance, Northern Indiana states that it generally supports the Commission's desire to clarify the CIP Reliability Standards but cautions the Commission from prescribing modifications that would limit a responsible entity's discretion. Northern Indiana comments that, while in some instances (such as testing vulnerabilities on a real-time, active system basis) documentation should suffice to demonstrate compliance, in other situations documentation does not suffice. In these instances, even though the responsible entity's documentation may comply with the CIP Reliability
Standards, the responsible entity must nevertheless demonstrate actual compliance. In these cases, Northern Indiana suggests that compliance can be verified in a subsequent audit.
69. Xcel notes that, in the CIP NOPR, the Commission indicated that “compliance will in all cases be measured by whether a party met or failed to meet the Requirement given the specific facts and circumstances.”
40
Xcel agrees that the Requirements contain the substantive obligations of a CIP Reliability Standard. Xcel asks the Commission to clarify whether an entity that complies with the substance of the Requirements but violates the documentation provisions of the Measures or Levels of Non-Compliance may be assessed a penalty. Xcel suggests that penalties are not warranted in this circumstance.
40
Xcel comments at 5, quoting CIP NOPR at P 39 (in turn quoting Order No. 693 at P 253).
ii. Obligation to Implement Plans, Policies and Procedures
70. EEI, FirstEnergy, ISO/RTO Council, Northeast Utilities and PG&E agree that certain CIP requirements do not explicitly require implementation of a plan, policy or procedure that the responsible entity is required to develop and maintain. Thus, they support directing NERC, in the course of its scheduled industry Reliability Standards development process, to consider making explicit that a responsible entity must implement a plan, policy or procedure that it is required to develop.
71. Xcel asks the Commission to clarify what it means to implement a plan, policy or procedure. Specifically, Xcel asks the Commission to clarify that “this does not mean that an entity has to follow every aspect of its plans, policies or procedures to the letter or be in violation * * *.”
41
Xcel comments that following every feature of a plan in all cases would hinder the flexibility that an entity needs to respond effectively to a particular situation. Further, according to Xcel, the Commission's proposal would make each plan, policy and procedure tantamount to an enforceable Reliability Standard. Xcel claims that this would give entities an incentive to include fewer details in their plans, policies and procedures.
41
Xcel comments at 7.
c. Commission Determination
i. Documentation
72. While the Commission agrees with commenters that relying on an objective determination such as whether a document exists would facilitate the compliance audit process, we do not believe such a cursory approach is the best way to ensure the protection of the Bulk-Power System. We adopt our proposal in the CIP NOPR that responsible entities must comply with the substance of a Requirement. In this way we affirm the Commission's position established in Order No. 693 that, “while Measures and Levels of Non-Compliance provide useful guidance to the industry, compliance will in all cases be measured by determining whether a party met or failed to meet the Requirement given the specific facts and circumstance of its use, ownership or operation of the Bulk-Power System.”
42
While we agree with Northern Indiana that, depending on the Requirement in question, in some instances (such as active system testing) documentation would suffice to demonstrate compliance, even in these cases auditors should look at the content of the documentation to determine if the substance of the Requirement has been met.
42
Order No. 693 at P 253.
73. Xcel seeks clarification regarding responsible entities that comply with the substance of a Requirement but violate the documentation provisions. In Order No. 693, in response to a similar request by Xcel, the Commission explained that, “[w]hile the Commission generally agrees that it is a violation of the Requirements that is subject to a penalty, we recognize that because Measures are intended to gauge or document compliance, failure to meet a Measure is almost always going to result in a violation of a Requirement.”
43
We add that a responsible entity's failure to maintain documentation (as set forth in a Measure) that obstructs the ability of the ERO, Regional Entity or Commission to determine compliance with the substance of a Requirement may warrant a penalty.
43
Id.
P 256.
ii. Obligation To Implement Plans, Policies and Procedures
74. In the CIP NOPR, the Commission also noted that, while certain Requirements of the CIP Reliability Standards obligate a responsible entity to develop and maintain a plan, policy or procedure, the Requirements do not always explicitly require implementation of the plan, policy or procedure. The Commission proposed to interpret such provisions to include an implicit implementation requirement.
75. Consistent with that proposal, the Commission concludes that, where the CIP Reliability Standards obligate a responsible entity to develop and maintain a plan, policy or procedure, there should be a corresponding obligation to implement the plan, policy or procedure. However, while the CIP NOPR proposed to interpret the CIP Reliability Standards as including an implicit obligation to implement plans, policies and procedures, we are persuaded by the commenters that a better approach is for the ERO to develop modifications to the CIP Reliability Standards that contain appropriate implementation language. Accordingly, we direct the ERO to develop modifications to the CIP Reliability Standards that require a responsible entity to implement plans, policies and procedure that it must develop pursuant to the CIP Reliability Standards.
76. As to Xcel's argument that, at times, the proper course is to deviate from a plan, we agree that the details of such plans are not equivalent to Requirements of a CIP Reliability Standard. However, the responsible entity's plan should be followed unless a deliberate decision is made for good reason not to follow it. Such reason should be documented and available for compliance auditors to review. Merely ignoring plan provisions is equivalent to not having a plan. For clarity, we note that a decision not to follow a particular plan provision due to circumstances will not except a responsible entity from a related Requirement in a CIP Reliability Standard. As discussed below, we find that any exception to a CIP Reliability Standard must comply with the required conditions for a technical feasibility exception.
E. Implementation Plan
77. In the CIP NOPR, the Commission explained that, because the CIP Reliability Standards are new and require applicable entities in many cases to develop new cyber security systems and procedures, NERC developed an implementation plan based on a schedule that provides for implementation of the CIP Reliability Standards over a three-year period.
44
The implementation plan sets out a proposed schedule for accomplishing the various tasks associated with compliance with the CIP Reliability Standards. The schedule gives a timeline by calendar quarters for completing various tasks and prescribes
milestones for when a responsible entity must: (1) “Begin work”; (2) “be substantially compliant” with a Requirement; (3) “be compliant” with a Requirement; and (4) “be auditably compliant” with a Requirement. According to the implementation plan, “auditably compliant” must be achieved in 2009 for certain Requirements by certain responsible entities, and in 2010 for others.
44
CIP NOPR at P 42.
See also
NERC August 28, 2006 Filing, Exhibit B “Implementation Plan for Cyber Security Standards” (implementation plan).
1. Commission Approval of Implementation Plan
a. NOPR Proposal
78. The Commission proposed to approve NERC's implementation plan, including the proposed timelines for achieving compliance.
45
The Commission stated its belief that the timetable proposed by NERC sets reasonable deadlines for industry compliance, recognizing the broad industry input to its development, and the tasks that many responsible entities face to purchase and install new equipment and software to achieve compliance.
45
Id.
P 47.
b. Comments
79. Numerous commenters urge the Commission to accept NERC's proposed implementation plan and the proposed timeline for achieving compliance with the CIP Reliability Standards.
46
For example, Applied Control Solutions comments that, due to real cyber vulnerabilities to the grid, there is an urgent need to move forward with the effective dates without delay and not allow any extension of those dates. KCPL states that the implementation plan has been developed based on input from industry stakeholders and the timetables and processes agreed upon in that process represent prudent steps toward the implementation of the CIP Reliability Standards.
46
E.g.,
NERC, Applied Control Solutions, EEI, FirstEnergy, KCPL, PG&E and Progress.
80. Many of these same commenters express concern about how the Commission's proposal in the CIP NOPR to direct that NERC develop certain modifications to the CIP Reliability Standards would affect the implementation schedule. NERC explains that the implementation plan and time frame are for the existing CIP Reliability Standards as submitted to the Commission. NERC states that any changes to the CIP Reliability Standards resulting from the Final Rule will potentially impact the implementation plan and time frame, and a new schedule will need to be developed during the Reliability Standards development process associated with those changes.
47
47
See also
Allegheny, Alliant, Detroit Edison, Duke, EEI, Entergy, FPL Group, Idaho Power, KCPL, Manitoba Hydro, MidAmerican, National Grid, OGE, Ontario IESO, PG&E, PSEG Companies, Southern, Teltone and Xcel.
81. Similarly, EEI and Entergy advocate that the Final Rule make clear that modifications developed pursuant to the Reliability Standards development process should not be implemented until the conclusion of the NERC implementation plan.
48
PSEG Companies add that responsible entities have already developed budgets and implementation plans in reliance on the existing CIP Reliability Standards. PSEG Companies indicate that, although they may ultimately support some of the changes proposed in the CIP NOPR, they cannot support modifying the current CIP Reliability Standards before the 2009 compliance deadline. EEI and Alliant claim that, if the Commission directs the NERC Reliability Standards development process to consider potential changes to the CIP Reliability Standards before the conclusion of the implementation plan, responsible entities will be significantly discouraged from performing any further work until these changes are finalized. Thus, implementation work may slow or come to a stop because responsible entities will have an incentive to wait for the final outcome of this Commission-imposed revision process.
48
EEI at 6. Elsewhere, EEI states that the Commission should not direct NERC to consider changes to the CIP Reliability Standards before the conclusion of the NERC implementation plan. EEI at 7-8.
82. Manitoba Hydro comments that the Commission should reject NERC's proposed implementation schedule because it is based on the unrealistic expectation that the CIP Reliability Standards would be approved without the need for any revisions. Muscatine Power & Water argues that if the Commission requires utilities to base their risk-based assessments on formal guidelines provided by NERC, then the implementation schedule must be extended to allow additional time for compliance.
83. APPA/LPPC suggest the implementation plan may need adjustment if the Regional Entities or some other region-wide institutions supplement a responsible entity's list of critical assets. In such cases, APPA/LPPC request that the Commission direct NERC to develop a reasonable schedule for determining the timeline for being auditably compliant with respect to the newly designated assets.
84. Entergy characterizes the CIP NOPR as proposing to “remand” CIP-002-1, which according to Energy would leave unresolved the basic issue of which assets are subject to the CIP Reliability Standards. Entergy contends that without knowledge of which assets the CIP Reliability Standards apply, the proposed timeline is unworkable.
85. SPP maintains that there is no table prescribing a schedule in which an existing registered entity can bring a newly identified critical asset and its critical cyber assets into compliance. While not expected to change frequently, the critical asset list can change for any number of valid reasons, and the registered entity needs an appropriate period of time in which to achieve compliance for that asset. In the absence of a compliance schedule, no guidance is available to either the registered entity or the auditor. SPP recommends that a new table be developed defining a compliance schedule for newly identified critical assets and based upon the date of the risk-based assessment. SPP argues that the table should include milestones for tasks already completed and milestones for tasks yet to be done that will require additional resources and time to comply.
c. Commission Determination
86. The Commission adopts its CIP NOPR proposal and approves NERC's implementation plan and time frames for responsible entities to achieve auditable compliance. Responsible entities require a reasonable period of time to purchase and install new cyber software and equipment and develop new programs and procedures to achieve compliance. Commenters indicate that the implementation plan provides that reasonable period of time. Further, we agree with commenters that there is an urgent need to move forward without any delays. Accordingly, we approve NERC's implementation plan.
87. Commenters raise concerns regarding the impact on the implementation plan of the Commission's directives for modifications to the CIP Reliability Standards. As explained above, the Commission is not modifying the CIP Reliability Standards in this Final Rule. Rather, pursuant to section 215(d)(5) of the FPA, the Commission in the Final Rule directs the ERO to develop certain modifications to the CIP Reliability Standards pursuant to the NERC Reliability Standards development process. Even though the development of such modifications will take time, this does not present a reason for delay or revision to the NERC implementation plan for implementing the CIP
Reliability Standards approved in this Final Rule.
88. The Commission believes that the modifications to the CIP Reliability Standards developed by the NERC Reliability Standards development process should not be audited prior to the conclusion of the approved implementation plan. EEI and other commenters claim that commencing the development of such modifications prior to the conclusion of the implementation plan would be discouraging to industry. The Commission, however, finds that it is unacceptable to delay the development of the modifications directed in this Final Rule until after the conclusion of the implementation plan. Since it is uncertain how long it will take to develop revised CIP Reliability Standards, we believe it is not reasonable to wait until the 2009-2010 time period for the process to start. Features such as enhanced conditions on technical feasibility exceptions and oversight of critical asset determinations are too important to the protection of the Bulk-Power System to wait that long.
89. While we are both sympathetic and concerned about straining industry resources, the Commission and the electric industry must do their best to protect the electric infrastructure that is essential to the health and safety of the nation. Therefore, we direct the ERO to submit a work plan for Commission approval for developing and filing for approval the modifications to the CIP Reliability Standards that we are directing in this Final Rule. As suggested by NERC, the Commission will consider a second implementation plan for achieving compliance with the forthcoming revised CIP Reliability Standards.
90. The Commission did not propose to remand CIP-002-1 as argued by Entergy. Nonetheless, Entergy raises a valid concern since the Commission's directive, discussed below, that the ERO develop modifications to CIP-002-1 could affect a responsible entity's identification of critical assets. We share Entergy's concern that there are threshold issues regarding CIP-002-1 that must be addressed before responsible entities can have certainty regarding which assets must be protected according to the CIP Reliability Standards. We also believe that responsible entities need certainty regarding the conditions for a technical feasibility exception to inform their decisions about how to comply with the CIP Reliability Standards, even in their current form. Therefore, we direct the ERO, in its development of a work plan, to consider developing modifications to CIP-002-1 and the provisions regarding technical feasibility exceptions as a first priority, before developing other modifications required by the Final Rule.
2. Self-Certification
a. NOPR Proposal
91. In the CIP NOPR, the Commission expressed concern over whether responsible entities will be fully prepared for compliance upon reaching the implementation deadline and will take reasonable action to protect the Bulk-Power System during the interim period.
49
The Commission stated that NERC's plans to require self-certification during the interim period are helpful and proposed that, to allow adequate monitoring of progress, the ERO develop a self-certification process with certifications more frequent than once per year. The CIP NOPR suggested that self-certification be tied either to target dates in the schedule or perhaps quarterly or semi-annual certifications. The Commission indicated that, while an entity should not be subject to a monetary penalty if it is unable to certify that it is on schedule, such an entity should explain to the ERO the reason it is unable to self-certify. The ERO and the Regional Entities should then work with such an entity either informally or, if appropriate, by requiring a remedial plan, to assist such an entity in achieving full compliance in a timely manner. We also stated that the ERO and the Regional Entities should provide informational guidance, upon request, to assist a responsible entity in assessing its progress in reaching “auditably compliant” status.
49
CIP NOPR at P 48.
b. Comments
92. Many commenters oppose directing NERC to consider a self-certification process with more frequent self-certifications than on an annual basis.
50
In this regard, EEI argues that a more frequent self-certification requirement is likely to impose undue burdens without commensurate benefits. KCPL claims that there are sufficient processes already in place in order to evaluate and monitor CIP Reliability Standards compliance and additional requirements for self-certification provide no significant support or benefit to tracking a Responsible Entity's obligations to the CIP Reliability Standards and are unneeded.
50
E.g.
, Alliant, Bonneville, Entergy, EEI, ISO-NE, KCPL, National Grid, Northeast Utilities, PG&E, Portland General, Progress, Puget Sound and Southern.
93. Other commenters, such as APPA/LPPC, MidAmerican, Northern Indiana and SDG&E either support or do not object to more frequent self-certifications. APPA/LPPC support NERC's proposed self-certification process as a reasonable means of tracking the progress made by responsible entities toward full, auditable compliance. Nor do they object to the Commission's proposal that such certification be rendered quarterly or semi-annually. Northern Indiana supports semi-annual self-certification during the transition until the implementation plan is completed. Northern Indiana contends that more frequent self-certification would be unduly burdensome.
94. METC-ITC also support quarterly or semi-annual self-certifications because the certifications will properly pressure entities to take timely steps to achieve compliance by the deadline for auditable compliance. METC-ITC are concerned, however, that having NERC monitor progress toward compliance with the CIP Reliability Standards via self-certifications, may place a burden on the ERO and the Regional Entities that their current staffs may be unable to properly administer. Thus, METC-ITC propose that the Commission require the ERO to file plans addressing how it will satisfy the new requirements for providing assistance to responsible entities and further assessing CIP implementation as part of its readiness reviews.
95. SDG&E supports semi-annual certifications, but comments that quarterly certifications would be distracting to the main goal, as well as burdensome, time consuming and paper intensive. It agrees with the Commission that an entity should not be penalized if it cannot certify that it is on schedule. SDG&E does not object to the Commission's proposal that the ERO and the Regional Entities should work with such an entity to achieving full compliance, provided that the Commission clarify that this means “getting back” on schedule and not accelerating compliance.
c. Commission Determination
96. While the Commission is sensitive to concerns that more frequent self-certifications may be burdensome, it is important that the ERO and the Commission know whether industry, or segments of industry, are having difficulty implementing the CIP Reliability Standards. Therefore, we direct the ERO to require more frequent, semi-annual, self-certifications prior to
the date by which full compliance is required. Such additional self-certifications may be a “stream-lined” version, but must be useful for the ERO and the Commission to assess industry's progress toward achieving compliance with the CIP Reliability Standards.
97. Further, we adopt our CIP NOPR proposals that, while an entity should not be subject to a monetary penalty if it is unable to certify that it is on schedule, such an entity should explain to the ERO the reason it is unable to self-certify. The ERO and the Regional Entities should then work with such an entity either informally or, if appropriate, by requiring a remedial plan to assist such an entity in achieving full compliance in a timely manner. Further, we expect the ERO and the Regional Entities to provide informational guidance, upon request, to assist a responsible entity in assessing its progress in reaching “auditably compliant” status.
98. With regard to METC-ITC's comment, we will not require NERC and the Regional Entities to submit plans describing how it will undertake these responsibilities. Rather, the ERO and Regional Entities can address any need for additional resources in the ERO's annual budget filing. If necessary to fulfill their statutory obligations, the ERO and Regional Entities may file a request for additional funding to supplement their Commission approved budgets.
99. With regard to SDG&E's comment, we clarify that the goal of a Regional Entity working with a responsible entity that is unable to self-certify is to assist the entity in meeting the NERC time frames for auditable compliance, and not to accelerate compliance ahead of schedule.
3. Adding a Cyber Security Assessment to NERC's Readiness Reviews
a. NOPR Proposal
100. To further address the Commission's concerns about the period prior to when responsible entities achieve full compliance with the CIP Reliability Standards, the CIP NOPR also proposed that the ERO add a cyber security assessment to NERC's existing readiness reviews.
51
The Commission explained that the assessment should identify best practices and deficiencies of the reviewed entities to assist them in preparing for implementation of the CIP Reliability Standards and help the Commission evaluate the potential effectiveness of the Standards before full implementation.
51
CIP NOPR at P 49.
b. Comments
101. NERC and other commenters oppose the addition of a cyber security assessment to NERC's existing readiness reviews.
52
NERC requests that the Commission allow the existing oversight framework to work without adding new or different requirements specific to the CIP Reliability Standards. EEI points out that, because readiness reviews are not conducted on an annual basis, the review would not occur early enough in the implementation process to assist responsible entities' implementation of the CIP Reliability Standards or assist the Commission in assessing the status of compliance efforts. EEI also asserts that the most likely result of adding a cyber security assessment to NERC's readiness reviews would be to unnecessarily distract responsible entities from performing the actual implementation of the CIP Reliability Standards. Southern adds that such assessments would merely duplicate the self-certifications.
52
E.g.,
Alliant, Bonneville, EEI, ISO-NE, Luminant, Northeast Utilities, Southern and Tampa Electric.
102. Northeast Utilities asks the Commission to reconsider its proposal prior to the 2009 deadline for full compliance with the CIP Reliability Standards. According to Northeast Utilities, readiness reviews are performed by industry peer volunteers under Regional Entity guidance to identify best practices and ensure that system operators have the tools, processes and procedures in place to operate reliably. It contends that, given the limited industry experience with cyber security, the readiness review process will not produce the benefits the Commission expects.
103. In contrast, MidAmerican and SDG&E agree with the Commission that adding a cyber component to the readiness audit process would be beneficial, provided an exception is made for publication of any weaknesses found during a typical readiness audit. They submit that any areas of concern uncovered by the audit should be considered sensitive and confidential with appropriate safeguards developed and in place to protect this information. MidAmerican also recommends that the Commission consider including a cyber security assessment within the ERO's existing readiness reviews.
104. Xcel asks the Commission to clarify that the CIP NOPR, in proposing that NERC add cyber security assessments to its existing schedule of reliability readiness reviews, did not intend for NERC to revise its schedule of reviews but, rather, add a new element to the previously-scheduled reviews.
c. Commission Determination
105. The Commission is persuaded by comments regarding the limited reach of readiness reviews and the questionable utility of such reviews prior to the date by which entities are to be compliant; thus, adding the CIP Reliability Standards to the readiness reviews at this time will delay industry's compliance efforts. Therefore, the Commission will not require that the CIP Reliability Standards be added to the readiness reviews at this time.
F. Issues Presented by Terminology
106. The CIP NOPR discussed specific terminology used in the CIP Reliability Standards that, while providing flexibility for a responsible entity in achieving compliance, also raise concerns regarding enforceability of the Standards. Specifically, the Commission raised concerns regarding the terms “reasonable business judgment,” “acceptance of risk,” and “technical feasibility.” As discussed below, the Commission adopts the CIP NOPR proposals and directs NERC to modify the CIP Reliability Standards through the Reliability Standards development process to remove the first two terms, and develop specific conditions that a responsible entity must satisfy to invoke the “technical feasibility” exception. Moreover, in response to concerns raised by commenters, the Commission has changed certain conditions for invoking the technical feasibility exception.
1. Reasonable Business Judgment
a. NOPR Proposal
107. As we stated in the CIP NOPR,
53
each of the proposed CIP Reliability Standards incorporates the concept of “reasonable business judgment” as a guide for determining what constitutes appropriate compliance with those Reliability Standards. The Purpose statement of Reliability Standard CIP-002-1 provides that:
53
CIP NOPR at P 50.
These standards recognize the differing roles of each entity in the operation of the Bulk Electric System, the criticality and vulnerability of the assets needed to manage Bulk Electric System reliability, and the risks to which they are exposed. Responsible entities should interpret and apply Standards CIP-002 through CIP-009 using reasonable business judgment.
108. In addition, each of the subsequent CIP Reliability Standards (
i.e.
, CIP Reliability Standards CIP-003-1 through CIP-009-1) includes a
statement that “Responsible Entities should interpret and apply the Reliability Standard using reasonable business judgment.”
109. The Commission pointed out in the CIP NOPR that NERC's Glossary of Terms Used in Reliability Standards (NERC Glossary) does not define reasonable business judgment, and the CIP Reliability Standards do not otherwise suggest how the term is to be interpreted. NERC's Frequently Asked Questions (FAQ) document that accompanies the CIP Reliability Standards provides the only available guidance on the issue.
54
It states that the phrase is meant “to reflect—and to inform—any regulatory body or ultimate judicial arbiter of disputes regarding interpretation of these Standards—that responsible entities have a significant degree of flexibility in implementing these Standards.” The FAQ document notes that there is a long history of judicial interpretation of the business judgment rule and states that “[c]ourts generally hold that the phrase indicates reviewing tribunals should not substitute their own judgment for that of the entity under review other than in extreme circumstances.”
54
NERC included the FAQ document in its August 28, 2006 filing. The FAQ document is also available at
ftp://www.nerc.com/pub/sys/all_updl/standards/sar/Revised_CIP-002-009_FAQs_06Mar06.pdf
.
110. The Commission proposed, in the CIP NOPR, to direct the ERO to modify the CIP Reliability Standards to remove references to the “reasonable business judgment” language before compliance audits start in 2009.
55
In the CIP NOPR, the Commission discussed the history of the reasonable business judgment concept and the meaning attached to that concept by the courts in the corporate context.
56
The Commission pointed out that, if this term is applied to the CIP Reliability Standards, it could easily be understood to have the same meaning as in the corporate context.
55
CIP NORP at P 58.
56
Id.
P 59, 61.
111. The Commission noted that flexibility and discretion are essential in implementing the CIP Reliability Standards and that implementing those Reliability Standards must be done on the basis of the specific facts and circumstances applicable in the individual case at hand. Cyber security problems do not lend themselves to one-size-fits-all solutions. In addition, the Commission acknowledged that cost can be a valid consideration in implementing the CIP Reliability Standards. However, the Commission concluded that the traditional concept of reasonable business judgment is ill suited to the task of implementing an appropriate program of cyber security pursuant to section 215 of the FPA.
112. That concept was developed specifically to address the issue of how courts should approach business decisions made by a company's officers or directors, and the answer it provides is based on certain assumptions about how our economic system operates and who is most likely to have the knowledge and expertise needed to make appropriate business decisions. However, the concept of reasonable business judgment takes on a very different meaning when removed from its original context and applied to a different factual situation where very different assumptions apply.
113. The Commission noted in the CIP NOPR that cyber security standards are essential to protecting the Bulk-Power System against attacks by terrorists and others seeking to damage the grid. Because of the interconnected nature of the grid, an attack on one system can affect the entire grid. It is therefore unreasonable to allow each user, owner or operator to determine compliance with the CIP Reliability Standards based on its own “business interests.” Business convenience cannot excuse compliance with mandatory Reliability Standards. The Commission also noted that the explanation of reasonable business judgment found in the FAQ document closely tracks the treatment of the concept in the corporate law context.
114. The Commission stated that this test is fundamentally incompatible with Congress' decision to adopt a regime of mandatory Reliability Standards. The Commission explained that the issue under section 215 of the FPA is not whether the management of a business is acting in the interest of its own shareholders, but rather whether an entity is taking appropriate action to avert risks that could threaten the entire grid. Finally, the Commission noted that in the corporate governance context, the business judgment rule is invoked only in extreme circumstances, generally when an officer or director is found to have acted fraudulently, in bad faith, or with gross or culpable negligence. For all these reasons, the Commission proposed in the CIP NOPR that the ERO remove references to the “reasonable business judgment” language from the CIP Reliability Standards.
b. Comments
115. NERC and numerous parties, including California Commission, Texas Commission, ISO-NE and ReliabilityFirst, agree that references to reasonable business judgment should be removed from the CIP Reliability Standards. National Grid concurs to the extent that this language adds confusion by incorporating a business law concept into the CIP Reliability Standards or could be construed to allow responsible entities to avoid liability for violations unilaterally and subjectively. APPA/LPPC state that use of reasonable business judgment overstates the appropriate amount of discretion to the extent that term was intended to incorporate a body of law developed in the corporate governance context. NRECA agrees that the term would give responsible entities too much latitude in essence to exempt themselves from the CIP Reliability Standards. Xcel states that reasonable business judgment has developed an exculpatory meaning in corporate law that is not applicable to compliance with the CIP Reliability Standards. ISO-NE states that the term provides no measurable value to any of the Requirements and appears to be an open-ended caveat that is susceptible to abuse.
116. Texas Commission states that, in reviewing costs associated with upgrades for physical and cyber security for prudence, it applies a more rigorous criterion than reasonable business judgment. It argues that a looser criterion in the CIP Reliability Standards could require a company to purchase more equipment or software than would later be compensated for in their rates. Texas Commission states that reasonable business judgment does not relieve an entity from showing that any expenditures it made were just and reasonable as required in Texas Commission rate cases. Texas Commission concludes that it is in the best interest of regulated entities either to remove the term or to replace it with a more narrowly focused term with a clearly defined statutory basis.
117. Numerous commenters argue that use of the term reasonable business judgment was never intended to import corporate law concepts into the CIP Reliability Standards but rather to ensure that Responsible Entities have sufficient flexibility when implementing them.
57
EEI states that the term was intended to allow flexible but objective decision-making in determining an approach to compliance. It was not intended to provide flexibility on whether to comply, only on how to comply.
57
E.g.
, Alliant, Arizona Public Service, EEI, PSE&G, SoCal Edison and Xcel.
118. Mr. Brown states that neither the CIP Reliability Standards nor the FAQ document state that the use of
reasonable business judgment would have the effects that the Commission suggests and that the Commission's description of the language and its potential effect is an effort to set up a “straw man” rather than address the clear intent of the language. He maintains that the Commission's analysis of the language is speculative and hyper-legalistic.
119. A number of commenters either oppose removal of reasonable business judgment from the CIP Reliability Standards or express serious concern about removing it. Tampa Electric argues that the term should be retained or at the very least replaced with language that ensures flexibility. SDG&E disagrees with wholesale elimination of the business judgment rule and instead urges that parameters or guidelines be adopted that determine when and how to apply the concept. MidAmerican suggests that it can be retained if accompanied by a mitigation plan with a sunset clause. Northern Indiana supports retaining the language, explaining that the CIP Reliability Standards are new, and the development of best practices regarding them continues to evolve. Responsible entities thus must have the flexibility to exercise discretion and make the appropriate strategic decisions when implementing the Reliability Standards.
120. A number of commenters argue that use of reasonable business judgment makes it clear that cost is a relevant factor. EEI states that a responsible entity is expected to weigh cyber security options in light of the risk to reliability in the same manner as similarly situated entities. Reasonable business judgment does not imply that it is acceptable to make purely economic choices to avoid protecting a critical cyber asset and thus to jeopardize grid reliability. Evaluating whether an asset is critical requires considering the asset's role, its cost, and the impact of the asset being compromised, as well as the costs of potential protection strategies, consistent with good business practice in the electric industry. EEI states that even with the inclusion of this language, the other requirements in the CIP Reliability Standards, such as documentation of decision-making and rigorous auditing, will prevent unfettered discretion in identifying and securing critical cyber assets.
121. Ontario Power states that outright removal will render the CIP Reliability Standards too rigid and that removal could be interpreted by some to mean that compliance is required regardless of the cost, the impact on production systems, or the risk to the Bulk-Power System. Tampa Electric argues that without the leeway afforded by reasonable business judgment, responsible entities could be forced into cost-prohibitive controls that do not add value in terms of security simply to satisfy an external requirement that is ill-fitted to the particular circumstances. SDG&E states that because the cost should not exceed the security benefit, certain security investments require business judgment. There must be latitude to develop a reasonable business case for determining the costs and benefits of investing in or implementing a security control based on key risk and investment factors specific to an entity.
122. A number of commenters defend the use of reasonable business judgment in terms that focus more on the issue of liability than simple flexibility or economic considerations. AMP-Ohio states that the plain language of the proposed CIP Reliability Standards could create a strict liability environment if there is no exception for “good faith” or “reasonable judgment.” Mr. Brown states that the proposal to remove the reasonable business judgment language appears to hold utilities, and perhaps individual managers, officers and directors, directly responsible for any adverse impact of decisions based upon their inherently imperfect knowledge and information regardless of whether they acted in good faith and made reasonably well-informed decisions. Entergy states that the industry must have reasonable assurance that the actions they are implementing meet the CIP Reliability Standards and Requirements if they acted in good faith, performed the proper evaluation, and took actions consistent with their evaluation.
123. Mr. Brown maintains that there are 200 years of legal precedent for determining what constitutes prudent behavior, and nothing in the legislative history of section 215 of the FPA suggests that Congress intended to depart from that precedent in this case. He states that the Commission should proceed with great caution when it proposes to depart from this precedent for determining prudent behavior without a clear, express mandate from Congress to do so.
124. EEI and other commenters argue that if the reasonable business judgment language is removed from the CIP Reliability Standards, it should be replaced with alternative language developed in the Reliability Standards development process.
58
They argue that such language is necessary to ensure necessary flexibility. National Grid states that the Commission should allow the ERO to develop suitable replacement language to allow for the reasonable flexibility that the Commission acknowledges that the industry requires in addressing critical infrastructure protection issues.
58
E.g.
, Arizona Public Service, Mr. Brown, Georgia Operators, KCPL, NRECA, Northern California, NIPSCO, Northeast Utilities, OGE, PG&E, SoCal Edison, Tampa Electric and Xcel.
125. APPA/LPPC suggest that phrases such as “reasonable judgment” or “judgment consistent with Good Utility Practice” as substitutes for reasonable business judgment. A number of commenters, including NIPSCO and Georgia Operators, point to the phrase “good utility practice” in the pro forma OATT as a model or starting point for alternative language.
126. A number of commenters, including Manitoba Hydro and NRECA, criticize the proposal to remove references to reasonable business judgment as overly prescriptive. Manitoba Hydro states that the proposal appears to preclude the consideration of alternative wording. These commenters stress the importance of reliance on the Reliability Standards development process.
127. Southwest TDUs state that, while the Commission correctly proposes to eliminate the so-called business judgment rule, the CIP NOPR does not address the dichotomy in application of the CIP Reliability Standards between public and private entities. While the Commission correctly concludes that flexibility and discretion in implementation are necessary, there is no discussion of what that means for a public body, nor is there any recognition that a public body may be governed by state requirements and possibly by local ordinances.
c. Commission Determination
128. Consistent with the CIP NOPR, the Commission concludes that the concept of reasonable business judgment is inappropriate in the context of mandatory CIP Reliability Standards. Accordingly, the Commission directs the ERO to develop modifications to the CIP Reliability Standards that do not include this term. We note that many commenters, including NERC, agree that the reasonable business judgment language should be removed based largely on the rationale articulated by the Commission in the CIP NOPR.
129. While there may have been no intention to import corporate law concepts into the CIP Reliability Standards, it is difficult to draw any other conclusion on the basis of the
documents provided. We note that the only guidance on reasonable business judgment that emerged from the Reliability Standards development process and that was supplied to the Commission is found in the FAQ document, and that document appears to invoke the traditional corporate law business judgment rule. The FAQ document specifically references existing court precedent on the rule, and it sets forth the elements of reasonable business judgment in what is essentially a restatement of classic formulations of the business judgment rule.
59
Moreover, the FAQ document specifically references one of the most objectionable aspects of the business judgment rule in the cyber security context, the requirement that the courts defer to the decisions of company officers and directors in all but the most extreme circumstances.
59
See
,
e.g.
,
Cramer
v.
General Telephone and Electronics Corp.
, 582 F.2d 259 (3d Cir. 1978);
Joy
v.
North
, 692 F.2d 880 (2d Cir. 1982);
In Re Bal Harbour Club, Inc.
, 316 F.3d 1192 (11th Cir. 2003);
Froelich
v.
Senior Campus Living LLC
, 355 F.3d 802 (4th Cir. 2004);
Poth
v.
Rassey
, 281 F. Supp. 2d (E.D. Va. 2003).
130. In short, the only explanation of reasonable business judgment in the documentation responsible entities would rely on focuses on corporate law concepts. We thus reject Mr. Brown's claim what we are being hyper-legalistic and constructing straw men rather than addressing the clear intent of the language. Mr. Brown fails to identify where some intent other than to adopt the traditional business judgment rule is clearly stated, and his references to 200 years of legal precedent only serve to reinforce our conclusion. We are unaware of any such extensive body of precedent on reasonable business judgment other than that developed in the corporate law context.
131. The most common argument raised in favor of reasonable business judgment is that it ensures flexibility. The Commission, however, acknowledged the importance of flexibility and discretion in the CIP NOPR.
60
The CIP Reliability Standards consist for the most part of quite general Requirements that must be implemented in a wide variety of circumstances. As drafted, they do not provide one-size-fits-all solutions and, rather, require responsible entities to assess their individual situations and devise solutions appropriate to their circumstances. We therefore disagree with Ontario Power that outright removal of all references to reasonable business judgment would render the CIP Reliability Standards too rigid. It will still be necessary for responsible entities to choose between available alternatives to arrive at cyber security solutions that best fit their situation. In short, the CIP Reliability Standards do not simply allow flexibility, they require it.
60
See
CIP NOPR at P 17, 59.
132. Many commenters suggest that the issue is not simply flexibility, but rather the flexibility to balance costs against other factors when implementing the CIP Reliability Standards. Many of the arguments about cost have been raised in connection with the problem of technical feasibility as it relates to long-life legacy equipment. We will address that issue below and note here simply that cost is a relevant consideration for those purposes, and recourse to reasonable business judgment is unnecessary to confirm that or to address the problem appropriately. Beyond that we disagree that deleting references to reasonable business judgment will lead to overly burdensome requirements or counterproductive results. For example, we disagree with Tampa Electric that without the leeway afforded by reasonable business judgment responsible entities would be forced into cost-prohibitive controls that do not add value in terms of security. No explanation was provided as to how this might occur. The Commission acknowledged the validity of cost considerations in the CIP NOPR and reaffirms that position here. The funds available for cyber security will not be infinite and, therefore, a responsible entity will need to make careful judgments to ensure that available funds are spent effectively. We do not see how the absence of references to reasonable business judgment will prevent this from happening.
133. Finally, some commenters link the need for flexibility with the problem of liability. We are keenly aware that unlike many other aspects of Bulk-Power System operations, cyber security represents a new and rapidly developing field. In other areas, the substance of appropriate practices is well established and well understood, but there can be considerably more uncertainty in the cyber security realm. Responsible entities therefore quite understandably wish to have, in Entergy's words, assurances that their actions meet the CIP Reliability Standards and Requirements if they act in good faith, perform the proper evaluation, and act consistent with their evaluation. We agree that they should have such assurances, but we disagree that references to reasonable business judgment are an appropriate way to provide such assurances. The real issue is whether responsible entities take reasonable and prudent actions based on an informed understanding of the current state of cyber security practice and how it applies to their situation. The Commission, therefore, disagrees with AMP-Ohio and Mr. Brown that the absence of references to reasonable business judgment will lead to a strict liability enforcement regime.
134. We disagree with Mr. Brown's claim that removal of reasonable business judgment could lead to liability for individual managers under section 215 of the FPA. That section applies to users, owners, and operators of the Bulk-Power System, and any liability arising under section 215 applies to them, not their employees.
135. Although we disagree with National Grid and others that alternative language is necessary to ensure necessary flexibility, we agree that the ERO and the participants in the Reliability Standards development process may choose to develop alternative language to replace reasonable business judgment and propose it for Commission approval. Such language would need to be adapted to the issues involved in forming judgments on proper cyber security measures and embody an objective standard focused on conduct that promotes the interests of Bulk-Power System security and reliability. Such language would also need to take into consideration our finding discussed below that a responsible entity cannot excuse itself from compliance with a requirement of the CIP Reliability Standards.
136. In response to the Southwest TDUs, we note that the CIP Reliability Standards apply in the same way to both public and private users, owners, and operators of the Bulk-Power System. Any specific issues that Southwest TDUs have with the Reliability Standards should be raised in the Reliability Standards development process.
137. Finally, we reject arguments that we are being overly prescriptive in directing the ERO to remove all references to reasonable business judgment from the CIP Reliability Standards. We discuss that general issue elsewhere in this Final Rule and will not repeat that discussion here. It is, however, important to note that such objections are inapposite in this instance for an additional reason that involves the specific nature of the issue raised. The concept of reasonable business judgment speaks to a general legal standard of conduct proposed to apply under a statute that Congress has directed the Commission to administer. It does not involve matters specific to
reliability but rather is bound up with the problem of legal enforceability. The Commission has a particular duty to see that the laws it administers can be enforced effectively. We are not being overly prescriptive when acting to ensure that this will be the case.
138. Based on the above discussion, as well as our lengthy analysis in the CIP NOPR, the Commission directs the ERO to modify the CIP Reliability Standards through its Reliability Standards development process to remove references to reasonable business judgment before compliance audits begin.
2. Acceptance of Risk
a. NOPR Proposal
139. The Commission explained in the CIP NOPR that some Requirements in the CIP Reliability Standards permit an entity not to take the actions specified in the Requirement if they “document compensating measures applied to mitigate risk exposure or an acceptance of risk.”
61
The CIP NOPR explained that the CIP Reliability Standards do not provide explicit guidance on the circumstances in which it is appropriate to accept the risk of non-compliance. The Commission further explained that the phrase “acceptance of risk” essentially allows a Responsible Entity to opt out of certain provisions of a mandatory Reliability Standard at its discretion.
62
The Commission stated its belief that the acceptance of risk language does not serve any justifiable purpose and proposed to direct that the ERO remove this language from the CIP Reliability Standards.
61
Id.
P 70.
See also
CIP-007-1, Requirements R2.3, R3.2, and R4.1.
62
Id.
P 83.
b. Comments
140. Numerous commenters, including NERC, support the removal of acceptance of risk language, provided that this is accomplished using NERC's Reliability Standards development process.
63
Texas Commission believes that removing the term is warranted and states that one entity's acceptance of risk may have an adverse impact on the Bulk-Power System. ISO-NE argues that the term provides no measurable value to any of the Requirements and appears to be an open-ended caveat that is susceptible to abuse.
63
See also
California Commission, CEA, Texas Commission, ISO-NE and ReliabilityFirst.
141. EEI, FirstEnergy, Manitoba Hydro and others contend that the proposal to remove the acceptance of risk language from the CIP Reliability Standards mandates a specific outcome and fails to allow for consideration of alternatives to address the Commission's concerns in the NERC Reliability Standards development process. FPL recommends directing the ERO to consider the issue and either (1) make the appropriate modifications based on the Commission's concerns or (2) provide justification for an acceptance of risk provision. EEI states that the Commission's concerns regarding this language are valid, but should be reasonably tempered by the Commission's expectation that industry will use the mutual distrust posture.
142. Some commenters suggest alternate language to replace the term “acceptance of risk.”
64
SDG&E states it does not disagree with the Commission's rationale but proposes, rather than eliminating the concept entirely, to substitute the term “risk-based.” Similarly, Xcel acknowledges that acceptance of risk may be a poor choice of words, but that alternate language should be considered. Xcel explains that the phrase “acceptance of risk” recognizes that an exception may be appropriate under some circumstances. For example, Requirement R2.3 of CIP-007-1 allows an entity to determine that an unused port does not need to be disabled and accept the risk of not doing so if it determines that the port is insignificant. METC-ITC state that the Commission should consider alternate language that promotes the quantification, documentation and justification of the risk that an entity proposes to accept.
64
E.g.
, METC-ITC, SDG&E and Xcel.
143. A number of other commenters, including Tampa Electric, note that it is not possible to eliminate all risks and state that the goal should be to minimize risks to an acceptable level that still allows business processes to function. Idaho Power states that all businesses carry and accept some level of risk, and it is not appropriate to shift the burden to the company, ratepayer or shareholder to develop systems that may remove all risk. A company can perform an analysis of risk to determine a risk level that delivers an adequate level of security for the company, neighboring utilities and consumers, while remaining manageable to the company from a cost standpoint.
144. APPA/LPPC agree that the CIP Reliability Standards cannot be ignored simply because a company deems a risk acceptable, but believe that the intent of this language was to provide a degree of discretion where compliance is perceived to pose a greater risk to critical asset availability than non-compliance. They envision situations where it is reasonable to conclude that compliance poses a significant risk in the specific instances where acceptance of risk language appears. For example, with respect to Requirement R3.2 of CIP 007-1 (security patch management), inadequately tested patches can pose a risk of system failure, and an entity must weigh the risk of using software with a known flaw against the risk that the vendor's patch will introduce even greater risk.
145. Tampa Electric maintains that the impact of risk to the grid should be weighed before disallowing acceptance of risk. References to acceptance of risk should not be removed because, when a measure is not technically feasible, an effective compensatory control or mitigation, short of replacing the system, is not always possible. In addition, acceptance of risk is not always based on cost reasons. A compensatory step could cause safety issues or some other process problem that makes it highly undesirable.
146. Mr. Brown states that acceptance of risk does not permit an entity simply to decline compliance. The intent was to require explanation, mitigation efforts, evaluation of the potential ramifications of accepting the risk, or other accountability to demonstrate how the CIP Reliability Standards are being complied with in essence. Mr. Brown states that greater transparency is welcome, but removing the language does not mean that such decisions will no longer be made. Rather it will result in such decisions being kept out of sight.
147. FPL Group states that the CIP Reliability Standards provide guidance that allows documentation of measures taken to mitigate risk exposure or an acceptance of risk. This guidance is reasonable and based on control system best practices. It allows responsible entities to evaluate the value of the mitigation with regard to operability and reliability of the Bulk-Power System in comparison to overall feasibility. Responsible entities should not have to bear unreasonable burdens for mitigation that yields only limited benefit. Responsible entities can make the determination to accept the risk-based on reasonable technical judgment insofar as there is no material negative impact to the Bulk-Power System.
148. Entergy opposes eliminating acceptance of risk. It argues that acceptance of risk by senior management is a long-established practice and predates the CIP Reliability Standards. Because of legacy technology, removing this option would require expenditure of significant
additional time and money to secure equipment. Associated countermeasures would in many cases be of limited relevance and effectiveness due to the vintage of these legacy controls.
149. With regard to CIP-007-1, MidAmerican supports the proposal to eliminate acceptance of risk from Requirement R2.3 but believes the term should remain in Requirement R3 if accompanied by a mitigation plan and sunset provision. MidAmerican argues that, by requiring a mitigation plan and a time frame for compliance, the CIP Reliability Standard would provide needed flexibility while maintaining the certainty of a committed end-date.
c. Commission Determination
150. The Commission continues to view the term “acceptance of risk” as representing an uncontrolled exception from compliance that creates unnecessary uncertainty about the existence of potential vulnerabilities. Responsible entities should not be able to opt out of compliance with mandatory Reliability Standards. The Commission, therefore, directs the ERO to remove acceptance of risk language from the CIP Reliability Standards.
151. In response to concerns raised by NERC, EEI and others, we agree that this action should occur through the Reliability Standards development process. In response to the concerns of many commenters who argue that it should be possible to propose alternative language, we note that this is consistent with the Reliability Standards development process. However, any alternative language that provides a similar opportunity for a responsible entity to opt out of compliance would be subject to remand. Rather, the Commission believes that alternative language that deals with such issues in terms of technical feasibility is preferable. To that end, we have adapted the concept of technical exceptions to encompass a broader range of valid justifications. Elsewhere in this Final Rule we address the criticism that our actions are overly prescriptive and those remarks apply equally here.
152. Expanding the use of the technical feasibility conditions would address the desire for flexibility expressed by some commenters while providing the control that the Commission finds to be necessary. It would provide for documentation, reporting and approval of how responsible entities have elected to comply with the CIP Reliability Standards and thus would permit the ERO and Regional Entities to assess the significance of any possible vulnerability. As to the argument by METC-ITC that a technical feasibility exception may not be possible in all cases, we note that we have found that technical feasibility should not be limited simply to whether something is technically possible but also whether it is technically safe and operationally reasonable. Thus, this approach addresses the issue of inadequately tested patches raised by APPA/LPPC, and similar general concerns raised by Tampa Electric.
153. In response to Entergy, we note that a long-established practice of risk acceptance by senior management does not mean that a continuation of this practice is appropriate under a new system of mandatory cyber security Reliability Standards. We have addressed Entergy's concerns about costs-related legacy equipment in connection with technical feasibility.
154. Many commenters defend retention of the acceptance of risk language by pointing out that it is impossible to eliminate all risk. While likely true, it is beside the point. The acceptance of risk language in the CIP Reliability Standards fails to acknowledge that the real issue is whether the nature and level of inevitable risk is acceptable from a system-wide perspective. Within a system of CIP Reliability Standards intended to protect the Bulk-Power System as a whole, that problem can be addressed by a system that documents and reports the risks in question and ultimately subjects them to approval by the ERO or Regional Entities. The Commission's concern in the CIP NOPR was with the lack of appropriate controls, and eliminating references to acceptance of risk does not imply that all risk can be eliminated.
155. We disagree with Mr. Brown that mutual distrust means that risks accepted by one entity do not affect others on an interconnected control system. A mutual distrust approach is a good security posture. However, its value depends on how well it is implemented. There will likely be a variety of levels of sophistication applied to implementing mutual distrust. It is not a basis for allowing other responsible entities to ignore their obligations under mandatory CIP Reliability Standards.
156. Accordingly, the Commission directs the ERO to develop through its Reliability Standards development process revised CIP Reliability Standards that eliminate references to acceptance of risk.
3. Technical Feasibility
a. NOPR Proposal
157. As the Commission explained in the CIP NOPR, two proposed CIP Reliability Standards provide exceptions from compliance with Requirements based on “technical feasibility.”
65
The NERC Glossary does not define the term “technically feasible,” nor do the CIP Reliability Standards themselves specify how an entity is to determine whether an action is technically feasible. NERC's FAQ document provides the following guidance on the meaning of the phrase “where technically feasible: ”
65
CIP NOPR at P 68-69. The “technically feasible” phrase is found in CIP-005-1, Requirements R2.4, R2.6, R3.1, R3.2 and CIP-007-1, Requirements R4, R5.3, R6, R6.3. Additionally, CIP-007, Requirement R2.3 uses “technical limitations” to similar effect.
Technical feasibility refers only to engineering possibility and is expected to be a “can/cannot” determination in every circumstance. It is also intended to be determined in light of the equipment and facilities already owned by the responsible entity. The responsible entity is not required to replace any equipment in order to achieve compliance with the Cyber Security Standards. When existing equipment is replaced, however, the responsible entity is expected to use reasonable business judgment to evaluate the need to upgrade the equipment so that the new equipment can perform a particular specified technical function in order to meet the requirements of these standards.
66
66
FAQ document at 1.
158. Based on these concerns, the Commission proposed in the CIP NOPR to allow, in the near term, exceptions from compliance based on the concept of “technical feasibility” in a limited set of circumstances, but also stated that responsible entities should not be permitted to invoke technical feasibility on the basis of “reasonable business judgment.” In addition, a responsible entity should not be able to except itself unilaterally from a Requirement of a mandatory CIP Reliability Standard with no oversight.
159. Thus, the Commission proposed in the CIP NOPR to direct that the ERO establish a structure to require accountability from those who rely on “technical feasibility” as the basis for an exception. The CIP NOPR described such a structure as requiring a responsible entity to: (1) Develop and implement interim mitigation steps to address the vulnerabilities associated with each exception; (2) develop and implement a remediation plan to eliminate the exception, including interim milestones and a reasonable completion date; and (3) obtain written
approval of these steps by the senior manager assigned with overall responsibility for leading and managing the entity's implementation of, and adherence to, the CIP Reliability Standards as provided in CIP-003-1, Requirement R2.
67
67
CIP NOPR at P 79.
160. The Commission stated in the CIP NOPR that this proposed structure should include a review by senior management of the expediency and effectiveness of the manner in which a responsible entity has addressed each of these three proposed conditions. In addition, the Commission proposed to require a responsible entity to report and justify to the ERO and the Regional Entity for approval each exception and its expected duration. In situations where any of the proposed conditions are not satisfied, the Commission proposed that the ERO or the Regional Entity would inform the responsible entity that its claim to an exception based on technical feasibility is insufficient and therefore not approved. Failure to timely rectify the deficiency would invalidate the exception for compliance purposes.
161. The Commission stated its belief that it is important that the ERO, Regional Entities and the Commission understand the circumstances and manner in which responsible entities invoke the technical feasibility provision as well as other provisions that function as exceptions to the CIP Reliability Standards. The Commission, therefore, proposed to direct the ERO to submit an annual report that would include, at a minimum, the frequency of the use of such provisions, the circumstances or justifications that prompt their use, the interim mitigation measures used to address the vulnerabilities, and the milestone schedule to eliminate them and to bring the entities into compliance to eliminate future reliance on the exception.
162. The Commission sought comment on additional categories of information that should be included in the content of this report that would be useful for the Commission, as well as the ERO and Regional Entities, in evaluating the invocation of technical feasibility and similar provisions, and the impact on protection of critical assets.
163. Finally, the Commission proposed to direct the ERO to consider making “technically feasible,” and derivative forms of that phrase as used in the CIP Reliability Standards, defined terms in the NERC Glossary, pursuant to the prior clarifications, without any reference to reasonable business judgment.
164. Below, we first address issues related to the general rationale underlying technical feasibility exceptions. We then address issues connected with documentation of exceptions and their remediation and mitigation. Finally, we address the approval of these exceptions.
b. Technical Feasibility Generally
i. Comments
165. Numerous commenters focused on the need for technical feasibility exceptions generally and their underlying rationale. Most support technical feasibility exceptions in some form.
166. Texas Commission expresses concern that technical feasibility could be used to justify inaction. It states that flexibility can be achieved by other means, but if reference to technical feasibility is retained, responsible entities should not be allowed to use it to avoid taking necessary action. Texas Commission comments that it is reasonable to develop a process under which entities with known vulnerabilities self-report to NERC and the Regional Entity and provide a timeline for correcting these deficiencies.
167. NERC states that the Commission properly recognized the appropriateness of an exception based on technical feasibility and suggests that it be designated an “exemption for reliability.”
68
NERC supports clarification of the Reliability Standards to ensure that an exemption is documented and justified in terms of its impact on Bulk-Power System reliability. ReliabilityFirst makes similar proposals.
68
NERC comments at 20-22.
168. NERC and others believe that the appropriate way to address the Commission's specific proposed directives is through the Commission-approved Reliability Standards development process.
69
Northern California supports the Commission's recommendation that the ERO re-examine and clarify the meaning of technical feasibility and provide guidance on the appropriate procedures for claiming an exemption based on it. Ontario IESO comments that, if the term reasonable business judgment is removed from the CIP Reliability Standards, industry and the ERO may find other areas where the concept of technical feasibility is applicable when revising the CIP Reliability Standards. NRECA states that technical feasibility is a matter on which the Commission should defer to the ERO's technical expertise and not adhere to a one-size-fits-all approach.
69
E.g.,
Alliant, Manitoba Hydro, Northern California and NRECA.
169. NERC explains that the CIP Reliability Standards include references to technical feasibility to recognize that, in many cases, equipment in place in substation and generating plant environments was implemented with operational functions paramount to all other considerations, including security. This equipment is not at the end of its useful life and historically has not been designed with ready access to software updates and patches. Such software upgrades that could increase functionality without directly contributing to reliability generally have not been made. NERC states that modern replacement equipment is more readily compatible with an environment where updates and patches are more commonplace and security functionality is an understood necessity. Securable equipment will be used when equipment is replaced due to natural end-of-life or failure, but this modern equipment represents a very small percentage of the installed base of all cyber equipment in substations and generating plants.
170. Many commenters, including APPA/LPPC, Duke, Entergy, NRECA and ReliabilityFirst, concur with this explanation of rationale for the references to technical feasibility. Duke agrees that technical feasibility exceptions should be controlled, but it argues that replacing legacy equipment on an accelerated schedule could create industry-wide logistical problems and unwarranted ratepayer impacts. NRECA maintains that rapid replacement of equipment would mean costs for customers, could overwhelm the supply chain, and could lead to premature obsolescence of replacement equipment as security technology continues to improve. Consumers Energy states that technical feasibility exceptions are proposed as a last resort that is forced by the limitations of available technology, support and service limitations of existing technology, and as-built limitations.
171. Entergy maintains that the older equipment in question generally cannot be compromised through typical hacker techniques, and physical access to it is often required. This presents greater challenges for attackers and means that only local impact will result from a successful attack. Entergy recommends allowing industry three to five years to upgrade critical assets with modern cyber controls that will provide the needed operational efficiency
improvements and that would be properly secured as a matter of course.
172. ReliabilityFirst notes that a very small percentage of the installed base of all cyber equipment in substations and power plants incorporates security functionality. Consumers Energy explains that older control systems can still be very reliable, but many assets identified as critical cyber assets do not have malware and virus protection, in some cases due to technology conflicts with virus and malware protection systems. In addition, managing updates on devices that are continuously online is a difficult task. Consumers Energy states that there are adequate alternate measures in such cases such as firewalls with content security functions that restrict any options for infecting systems with viruses and that implement intrusion detection for the perimeter with advanced content security services.
173. NERC states that the drafting team believed that cyber security standards should not unnecessarily impede the primary mission of maintaining reliable Bulk-Power System operations. NERC and ReliabilityFirst argue that changes must be carefully planned and tested to ensure that no unintended consequences occur. Technologies are constantly evolving, and it is impractical to think that equipment always can maintain a leading-edge cyber security posture without introducing operating issues.
174. Manitoba Hydro states that industry attempted to strike a balance for security at the various types of facilities while recognizing the large base of legacy systems at remote locations. The security framework focused on routable protocols and dial up access. The Commission's proposals to limit technical feasibility exceptions and implement a defense in depth measure in front of legacy systems would have a nominal impact on control centers but a significant impact on other facilities, systems and equipment, forcing unjustified early equipment replacement or installation of technology to provide mitigating controls. Manitoba Hydro argues that modifying the Reliability Standards on this point could add considerable work for responsible entities and require modifications to the implementation period.
175. Northern Indiana, Ontario Power and SoCal Edison support retaining the term technical feasibility. Ontario Power maintains that removing references to technical feasibility could be interpreted by some to mean that mandatory compliance is required, regardless of the cost, the impact on production systems, or the risk to the Bulk-Power System. Northern Indiana concurs with the Commission's proposal to treat instances of technical infeasibility as exceptions that require reporting and certain alternative courses of action. However, it disagrees with what it describes as the Commission's restrictive interpretation of the term and urges the Commission to acknowledge that technical infeasibility may apply to future assets as well. Northern Indiana advocates that the Commission instead direct NERC to interpret technical feasibility narrowly with regard to the technical characteristics of both existing and future assets. Northern Indiana states that the Commission should not assume technical infeasibility will exist only during the transition period and not afterwards, nor should it assume only one single means will exist, on a going forward basis, to comply with the Reliability Standards.
176. Mr. Brown states that technical feasibility has less to do with whether to comply than with how to comply. Whether or not something is technically feasible is purely an engineering issue. On the other hand, whether or when to replace equipment that cannot do something due to technical feasibility with equipment that can do so is purely a managerial decision. Mr. Brown states that in light of his interpretation of reasonable business judgment, the Commission should have much less concern about the interplay between technical feasibility and reasonable business judgment.
177. Teltone states that it is now easy to incorporate CIP-related features such as two-factor authentication (with unique user names and passwords) to both dial-up and Internet protocol devices without replacing them, upgrading their software, or taking them offline. Access and usage logging of legacy devices at substations is easily accomplished, something Teltone maintains should quell the problem of technical feasibility.
ii. Commission Determination
178. The Commission adopts the CIP NOPR proposal and directs the ERO to develop a set of conditions or criteria that a responsible entity must follow when relying on the technical feasibility exception contained in specific Requirements of the CIP Reliability Standards. We will modify some of our proposed criteria for that framework of accountability further below. We are persuaded by commenters that the proposed conditions for invoking the technical feasibility exception should allow for operational considerations. In response to Northern Indiana and other commenters, we note that the Commission did not propose to eliminate references to technical feasibility from the CIP Reliability Standards, only that the term be interpreted narrowly and without reference to considerations of business judgment.
179. In response to those commenters who argue that the Commission's concerns and directives should be addressed through the Reliability Standards development process, we agree that to the degree revisions to the Reliability Standards are necessary to address our concerns, they would be made through that process. We disagree, however, with the arguments that claim we are rewriting the CIP Reliability Standards or adhering to a one-size-fits-all approach. With respect to the latter point, we note that technical feasibility issues are by their nature something that must be dealt with on a case-by-case basis, as they only arise in specific circumstances. Our concern here is primarily with the framework within which decisions on technical feasibility are made and ensuring that this framework promotes sound decisions that lead to effective results. The oversight provisions we describe below are essential elements of such a framework.
180. We agree with NERC and other commenters on the underlying rationale for a technical feasibility exception, i.e., that there is long-life equipment in place that is not readily compatible with a modern environment where cyber security issues are an acknowledged concern. While equipment replacement will often be appropriate to comply with the CIP Reliability Standards, such as in instances where equipment is near the end of its useful life or when alternative or supplemental security measures are not possible, we acknowledge that the possibility of being required to replace equipment before the end of its useful life is a valid concern.
181. The Commission, however, disagrees with Northern Indiana that technical feasibility should be interpreted to apply to future assets also. The justification presented for technical feasibility exceptions is rooted in the problem of long-life legacy equipment and the economic considerations involved in the replacement of such equipment before the end of its useful life. We recognize that these considerations can be valid in some cases, but Northern Indiana has not explained why technical feasibility exceptions should apply to replacement equipment. The Commission neither assumes that technical infeasibility issues will be present only during the transition period, nor does it assume
that on a going forward basis there will be only one single means to comply with the CIP Reliability Standards. It does assume, however, that all responsible entities eventually will be able to achieve full compliance with the CIP Reliability Standards when the legacy equipment that creates the need for the exception is supplemented, upgraded or replaced.
182. The Commission agrees with various commenters that the implementation of the CIP Reliability Standards should not be permitted to have an adverse effect on reliability and that proper implementation requires that care be taken to avoid unintended consequences. We thus believe it is important to clarify that the meaning of “technical feasibility” should not be limited simply to whether something is technically possible but also whether it is technically safe and operationally reasonable.
183. We disagree with Mr. Brown's view that whether or when to replace equipment that cannot do something due to technical feasibility with equipment that can do so is purely a managerial decision, especially since he intertwines this proposition with the concept of reasonable business judgment. While we accept NERC's rationale for technical feasibility exceptions, as discussed below, an integral issue in individual cases where legacy equipment presents a technical feasibility issue is whether an alternative course of action protects the reliability of the Bulk-Power System to an equal or greater degree than compliance would. This is not a purely managerial decision involving reasonable business judgment, regardless of what meaning one imparts to that term.
184. While a number of commenters agree that it is important to clarify the meaning of technical feasibility, none appear to support defining the term in the NERC Glossary. Therefore, in light of the comments received generally and the specific guidance that we are providing to the ERO in connection with technical feasibility, we conclude that a definition of this type is unnecessary. A definition cannot substitute for a framework of conditions or criteria to provide accountability, and if those conditions or criteria are implemented, a definition is not needed. We do not agree with NERC that replacing the term technical feasibility with “exemption for reliability” would be helpful. We note, in particular, that an “exemption” normally is understood to be a release from an obligation whereas what is under discussion here is an exception that forms an alternative obligation.
185. While the Commission will not address the merits of any particular technology, we note that Teltone's comments raise an important general consideration when developing policy on technical feasibility. While technical limitations present real issues, and while one should not be overly optimistic that technological developments will resolve them sooner than expected, one should not be overly pessimistic either. Indeed, high standards should, if anything, encourage the development of technical solutions.
186. Based on the above considerations, the Commission adopts its proposal in the CIP NOPR that technical feasibility exceptions may be permitted if appropriate conditions are in place. The term technical feasibility should be interpreted narrowly to not include considerations of business judgment, but we agree with commenters that it should include operational and safety considerations.
c. Technical Feasibility Exception Mitigation and Remediation
187. As mentioned above, in the CIP NOPR, the Commission proposed a three step structure to require accountability when a responsible entity relies on technical feasibility as the basis for an exception. This proposed structure would require a responsible entity to: (1) Develop and implement interim mitigation steps to address the vulnerabilities associated with each exception; (2) develop and implement a remediation plan to eliminate the exception, including interim milestones and a reasonable completion date; and (3) obtain written approval of these steps by the senior manager assigned with overall responsibility for leading and managing the entity's implementation of, and adherence to, the CIP Reliability Standards, along with regional approval through the ERO.
i. Comments
188. NERC supports clarification of the CIP Reliability Standards to ensure that the use of a technical feasibility exemption must be documented and justified in terms of its impact on Bulk-Power System reliability. Duke also agrees with the proposal to require documentation, including appropriate mitigation and a senior management-approved remediation plan.
189. National Grid states that the Commission's mitigation proposal is reasonable and appropriate, but it maintains that the Commission should clarify that acceptable mitigation for older assets entails measures short of replacement, upgrades, or retrofits. A mitigation requirement otherwise would undermine any relief associated with an exception. Mitigation measures for vulnerabilities associated with older assets will need to be in place as long as those assets remain in service. National Grid states that the Commission's references to “interim” mitigation and remediation implementation milestones could suggest that older assets must be replaced before the end of their useful lives or that the mitigation measures would not be as effective as the solutions codified in the Reliability Standards. National Grid argues that mitigation measures should be as or more effective than compliance, and in the case of minor technical or administrative requirements, replacement of certain assets before the end of their useful lives would be wasteful and inefficient.
190. SPP believes it is reasonable to treat technical feasibility as a documented exception. Such exceptions should be reviewed and approved annually, but identifying a reasonable completion date for remediation may not always be possible. SPP states that to require remediation of a technical feasibility exception by a date certain is contrary to the Commission's acknowledgement that cost can be a prohibiting factor. Technical limitations may prohibit compliance with a requirement. The appropriate response in such cases is to mitigate the risk by implementing compensating measures. SPP questions the need for remediation where compensating measures are equally effective in reducing risk. It recommends that responsible entities be required initially to mitigate the risk and then evaluate and document whether further remediation is required and technically feasible as part of the exception approval process.
191. Northern Indiana believes a remediation plan should seek to eliminate the exception to the extent possible, but complete elimination may not be possible in all cases. Northern Indiana states that the Commission should consider the development and implementation of a remediation plan to eliminate the exception to the extent possible. Tampa Electric submits that it is unreasonable to require a remediation plan in every case. Sometimes there is no technology that would permit compliance with the letter of the CIP Reliability Standard.
ii. Commission Determination
192. With some minor refinements discussed below, the Commission adopts the CIP NOPR proposal for a
three step structure to require accountability when a responsible entity relies on technical feasibility as the basis for an exception. We address mitigation and remediation in this section and direct the ERO to develop: (1) A requirement that the responsible entity must develop, document and implement a mitigation plan that achieves a comparable level of security to the Requirement; and (2) a requirement that use of the technical feasibility exception by a responsible entity must be accompanied by a remediation plan and timeline for eliminating the use of the technical feasibility exception. While the CIP NOPR proposed that each remediation plan contain a reasonable completion date, the Commission is persuaded by the comments of National Grid and SPP that a date certain for remediation may not be possible in some instances. While we expect remediation by a date certain to be the norm, we will not require a date certain for remediation in every instance that a responsible entity invokes the technical feasibility exception. An entity must provide an explanation when it believes that it is not possible for a remediation plan to provide a reasonable completion date.
193. We also agree with Northern Indiana that in some instances remediation can be required only to the extent possible. For example, in some cases it may never be possible to enclose certain critical cyber assets within a six-sided physical boundary as required under CIP-006-1. However, such cases need to be sufficiently justified, the mitigation strategies must be ongoing and effective, and the justification must be subject to periodic review. We also are mindful that accelerated replacement of equipment can be economically wasteful where security is not otherwise compromised. We thus agree with National Grid that where mitigation measures are as or more effective than compliance, and in the case of minor technical or administrative requirements, replacement of certain assets before the end of their useful lives can be wasteful and inefficient. We also agree with SPP that remediation might not be necessary where compensating measures are equally effective in reducing risk. However, such cases must be subject to clear criteria and periodic review and, where necessary, updates.
194. However, in adopting this approach, we do not intend to suggest that it would never be necessary to replace equipment before the end of its useful life to achieve cyber security goals. Where equipment is near the end of its useful life or if insufficient mitigation measures are available, the equipment should be replaced. However, such situations must be dealt with on a case-by-case basis. We emphasize that responsible entities must protect assets that are critical to the reliable operation of the Bulk-Power System.
d. Approval and Control of Specific Exceptions
195. This section discusses the Commission's directions with regard to approval of a technical feasibility exception, the third component of our framework for allowing technical feasibility exceptions. As described above, the CIP NOPR proposed that NERC develop a requirement that a responsible entity relying on the technical feasibility exception must obtain written approval of a remediation plan by a senior manager.
70
The Commission also proposed that the responsible entity report and justify to the ERO and the Regional Entity for approval of each exception. In addition, the Commission proposed to direct that the ERO submit an annual report regarding industry use of the technical feasibility exception.
70
CIP NOPR at P 79.
i. Comments
196. California Commission states that approval of technical feasibility exceptions by the ERO and the relevant Regional Entity is critical because it prevents attempts to manipulate the system and induces responsible action.
197. National Grid supports providing Regional Entities with notice of technical feasibility exceptions and audits of exceptions by Regional Entities. It states that a central clearinghouse that catalogs all technical feasibility exceptions would be helpful because of the interdependencies among the Bulk-Power System assets. This clearinghouse could verify whether reliance on exceptions (or the associated mitigation measures) adequately maintains reliability and does not create reliability issues for neighboring systems. ISO-NE states that reporting exceptions to Regional Entities would be useful in identifying CIP Reliability Standards and Requirements with frequent implementation issues that call for modifications.
198. In contrast, ISO/RTO Council, EEI and others do not believe that reporting and approval of technical feasibility exceptions is appropriate.
71
EEI states it does not believe that NERC or the Regional Entities have the technical expertise to make these types of determinations. ISO-NE states it is unlikely that either Regional Entities or the ERO will have the necessary skills to evaluate the broad spectrum of situations that the industry presents. MidAmerican states that requiring ERO and Regional Entity approval would burden those entities, create delays, and divert resources away from more urgent cyber security concerns. Tampa Electric states that the Commission should ensure that delays do not interfere with timely compliance by responsible entities. Idaho Power believes that the Commission's proposals on technical feasibility would place administrative burdens on both company and the Regional Entities that outweigh the benefits. Idaho Power sees little value in policing the use of the technical feasibility exception with such a burdensome administrative process that may, in the end, delay the resolution of legitimate technical feasibility issues.
71
E.g.,
FirstEnergy, ISO-NE, KCPL, SERC-CIPC and SoCal Edison.
199. ReliabilityFirst argues that a responsible entity's senior manager must already approve any exceptions, making reporting and approval unnecessary, and it will be very difficult for the ERO or Regional Entity staff to review a responsible entity's exceptions effectively and assess them realistically. SERC-CIPC recommends that the requirement to authorize and document exceptions remain with the entity's designated senior manager.
200. ISO/RTO Council argues that granting the Regional Entities authority to adjudicate exceptions along with the ability to apply sanctions for non-compliance creates a conflict of interest. Auditors should be independent, and an assessor should not be involved with review and approval of policy exceptions. ISO/RTO Council argues that instead of requiring that exceptions be reported and justified, the Commission should consider directing the ERO to detail the type of justifications and considerations that must be documented when invoking a technical feasibility exemption. Responsible entities would then be required to incorporate them into their analysis of possible exemptions.
201. EEI, OGE and SoCal Edison question how the ERO and Regional Entities would determine what is technically feasible for a particular model of equipment in a specific context. If there is to be external review and approval, there should be an appeals process, and that would delay implementation of future revisions to the CIP Reliability Standards. Alliant, EEI and Tampa Electric believe that NERC should require that decisions on technically feasible be subject to audits
that are ultimately reported to the Commission. Duke, KCPL and SoCal Edison maintain that evaluation of technical feasibility issues should be left to compliance audits.
202. Northern Indiana seeks clarification of the information that will be needed to justify an exception. It suggests that, similar to the Commission's proposed approach regarding self-certification, a responsible entity should have the opportunity to consult with the ERO and Regional Entities. Northern Indiana also advocates the waiver of monetary penalties during this time as well as within the timeframe of any remediation plan.
203. APPA/LPPC state that the Commission should clarify that when a Regional Entity or the ERO rejects a technical feasibility exception request, the responsible entity may rely on the exception until it has been ruled upon. In addition, the organization should be allowed a reasonable time to come into compliance.
204. Entergy states that there is no indication that the benefits of reporting exceptions would outweigh the detriments, but if further reporting is required, it recommends a single annual report from each registered entity that includes a summary description of the exceptions and actions taken or to be taken. The ERO could use this report to satisfy its annual reporting requirement.
205. A number of other commenters emphasize the sensitivity of information about technical feasibility exceptions. SPP states that an annual report must contain information that qualifies as Critical Energy Infrastructure Information (CEII) to be of any value. SERC-CIPC also recommends CEII treatment for this information. SPP is concerned that if the report is not treated as CEII, sensitive data could be inadvertently made public. To protect against disclosure, SPP proposes that the ERO could make exception documentation available for Commission staff inspection in the ERO offices as a possible alternative to a report. National Grid states that information about exceptions should be subject to adequate information protection controls to avoid disclosure and misuse.
206. Duke opposes an annual report by the ERO to the Commission because, even if it does not contain CEII, it will compromise security by publicly identifying problem areas for the industry and the mitigation measures being employed. If a report must be submitted, there must be stringent and enforceable confidentiality measures to prevent inadvertent or unauthorized disclosure. OGE believes reporting and approval for all exceptions is contrary to the purpose of the CIP Reliability Standards because information on exceptions sent to the ERO or Regional Entity could indicate weaknesses in security that could be compromised and exposed. These same concerns lead Xcel to urge that Regional Entities develop confidentiality protocols for such communications.
207. ISO-NE states that detailed technical descriptions of exceptions should not be passed to the Regional Entities or the ERO because the information would be potential vulnerability information that the responsible entity should protect as critical cyber asset information under CIP-003-1, Requirement R4. Tampa Electric states that, if the Commission decides to require ERO or Regional Entity review, it should also prescribe controls to ensure the confidentiality and security of the information under review.
208. Although not commenting specifically on reporting of technical feasibility issues, Bonneville notes that under the Freedom of Information Act (FOIA), release of information to an external party generally waives any privileges against disclosure with respect to subsequent requests to the federal agency for that same information. Bonneville is concerned that submission of critical asset information to the Regional Entity, particularly the vulnerability-related rationales for including and excluding various facilities on the critical asset list, may act as such a waiver.
ii. Commission Determination
209. For the reasons discussed below, the Commission concludes that technical feasibility exceptions should be reported and justified and subject to approval by the ERO or the relevant Regional Entity. The Commission thus adopts its CIP NOPR proposal that use and implementation of technical feasibility exceptions must be governed by a clear set of criteria. However, because we are persuaded by the commenters, we have modified certain elements of our original proposal, as discussed below.
210. Most objections to the CIP NOPR proposal regarding the review and approval of technical feasibility exceptions are not objections in principle but rather focus on practical issues of implementation, such as limited ERO and Regional Entity resources and sensitivity of the information in question. To the extent that objections in principle have been raised, we disagree. Thus, we disagree with ReliabilityFirst's argument that senior manager approval of exceptions is unnecessary because of the responsibilities already assigned to the senior manager by CIP-003-1. These technical feasibility exceptions implicate matters that go beyond the purview of individual responsible entities and must be subject to review and approval by those with a wider-area view and general responsibility for system reliability. We also disagree with the ISO/RTO Council that the Commission should simply direct the ERO to detail the type of justifications and considerations that must be documented when invoking a technical feasibility exemption. While such guidance could be useful, it cannot substitute for reporting, review, and approval, which is necessary to address concerns that extend beyond the reach of an individual responsible entity.
211. With regard to the senior management approval, we continue to believe that internal approval is an important component of an overall framework of accountability with regard to use of the technical feasibility exception. Therefore, we adopt this aspect of our CIP NIPR proposal and direct the ERO to include approval of the mitigation and remediation steps by the senior manager (identified pursuant to CIP-003-1) in the course of developing this framework of accountability.
212. However, the practical considerations pointed out by a number of the comments have convinced us to adopt an approach to the issue of external oversight different from the one originally proposed. We agree, in particular, with those commenters who argue that pre-approval could tax ERO and Regional Entity resources, delay implementation, and possibly create undue risks that sensitive information will be disclosed.
213. The Commission agrees with National Grid that Regional Entities should, in the first instance, receive and catalogue notices of technical feasibility exceptions that are claimed. Such notices must include estimates of the degree to which mitigation measures achieve the goals set by a CIP Reliability Standard and be in sufficient detail to allow verification of whether reliance on exceptions (or the associated mitigation measures) adequately maintains reliability and does not create reliability issues for neighboring
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.