ARTICLE
27 October 2017

FERC Proposes New Cybersecurity Controls For Bulk Electric System

HL
Hogan Lovells Cadwalader

Contributor

Hogan Lovells Cadwalader is a global law firm trusted by clients to deliver on complex, high-stakes matters.

Operating at the intersection of business, finance, and government, we bring an unwavering commitment to client service and the decisive counsel that helps clients achieve exceptional results.

Consistently recognized for innovation across legal services, we combine sharp judgment with deep commercial perspective and intellectual rigor to address critical, cutting-edge challenges.

With 3,100 lawyers worldwide, we offer global scale with strong local insight in the markets that matter most. Our commitment extends beyond client work through pro bono activities, community investment, and responsible business practices.

The Federal Energy Regulatory Commission ("FERC") proposed to approve new cybersecurity management standards submitted by North American Electric Reliability Corporation ("NERC").
United States Technology
Hogan Lovells Cadwalader are most popular:
  • within Intellectual Property, Food, Drugs, Healthcare, Life Sciences and Transport topic(s)

The Federal Energy Regulatory Commission ("FERC") proposed to approve new cybersecurity management standards submitted by North American Electric Reliability Corporation ("NERC"). The new standards are intended to improve the reliability and resiliency of the U.S. bulk electric system.

FERC determined that the NERC-proposed reliability standards represents an "improvement" over the current reliability standard. Specifically, the proposal would (i) clarify the obligations pertaining to electronic access control for low-impact cyber systems, (ii) require mandatory security controls for transient electronic devices used at low-impact cyber systems (such as thumb drives and laptops), and (iii) require responsible entities to have policies for declaring and responding to CIP Exceptional Circumstances related to low-impact cyber systems.

In addition, FERC proposed that NERC develop certain modifications to the reliability standard. Specifically, FERC proposed that NERC (i) provide clear, objective criteria for electronic access controls for low-impact cyber systems and (ii) address the need to mitigate the risk of malicious code from third-party transient electronic devices. Further, FERC proposed to accept two violation risk factors and two violation severity levels associated with the new reliability standard.

FERC also accepted NERC's proposed effective date of the "first day of the first calendar quarter that is eighteen months after the effective date of [FERC's] order approving the proposed reliability standard."

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More