Showing posts with label DOE. Show all posts
Showing posts with label DOE. Show all posts

Monday, March 9, 2026

Review – HR 7272 Introduced – DOE Pipeline Security

Back in January Rep Webber (R,TX) introduced HR 7272, the Pipeline Cybersecurity Preparedness Act. The bill would establish Department of Energy responsibilities for physical security and cybersecurity coordination to ensure the security, resiliency, and survivability of natural gas, hazardous liquid pipelines, and liquefied natural gas facilities. No new funding is provided.

Moving Forward

On February 4th, 2026, the House Energy and Commerce Committee held a business meeting that included consideration of HR 7272. The bill passed, without amendments by a voice vote (pages 41-2). Pending publication of the committee report on the bill, the bill is ready for consideration by the full House. I suspect that it will be considered under the suspension of the rules process and would be expected to pass with strong bipartisan support.

Commentary

The inclusion of ‘hazardous liquid pipelines’ in the provisions of this bill is a tad bit odd as they would be a PHMSA area of expertise. While it is clear that general security requirements for energy pipelines would apply to non-energy related chemical pipelines, there are specific safety requirements that would be applicable to toxic chemical pipelines (downwind chemical detection comes to mind) that are probably not necessary for energy pipelines. Having said that, all of the voluntary security measures that would be developed under this bill’s provisions would be beneficial for hazardous liquid pipelines.

 

For more information on the provisions of this bill, including additional commentary on codifying DOE security research requirements, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7272-introduced-doe-pipeline-security - subscription required.

Wednesday, March 4, 2026

OMB Approves DOE Sunset Provision NPRM

(In contravention of yesterday’s post which conflated the wrong OIRA announcement with this rulemaking.)

On Monday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) on “Zero-Based Regulating”. The NPRM was submitted to OIRA on May 21st, 2025.

According to the Spring 2025 Unified Agenda entry for this rulemaking:

“The U.S. Department of Energy is considering initiating a proposed rule to amend the regulations that govern energy production to include a sunset provision in compliance with EO 14270 [link added], "Zero-Based Regulatory Budgeting To Unleash American Energy".”

Depending on which rules the proposed sunsetting provision apply, this rulemaking may or may not receive detailed coverage in this blog. At the very least I will note its publication in the appropriate Short Takes post.

Tuesday, March 3, 2026

DOE Withdraws Sunset Provision NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that the DOE had withdrawn a notice of proposed rulemaking (NPRM) on “Zero-Based Regulating”. Interestingly, the notice reports that the NPRM was also submitted to OIRA yesterday; that probably means that this is just a temporary delay.

According to the Spring 2025 Unified Agenda entry for this rulemaking:

“The U.S. Department of Energy is considering initiating a proposed rule to amend the regulations that govern energy production to include a sunset provision in compliance with EO 14270 [link added], " Zero-Based Regulatory Budgeting To Unleash American Energy".”

 

NOTE: The above post was written and posted in error. 3-4-26 06:00 am EST. See my post here.


Friday, July 11, 2025

OMB Approves DOE Natural Gas Admin Procedures DFR

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule from the DOE’s Office of Fossil Energy on “Administrative Procedures with Respect to the Import and Export of Natural Gas”. The direct final rule (DFR) was submitted to OIRA on July 8th, 2025. The quick turnaround on the rulemaking indicates either high-priority or extreme simplicity, I suspect the former.

I expect that the final rule will be published in the Federal Register sometime next week. Because of my earlier coverage of this rulemaking, I suspect that I might give it more coverage upon publication than I would typically give a rulemaking on this topic.

Thursday, July 10, 2025

Review - DOE Sends Admin Procedures on Natural Gas DFR to OMB – 7-9-25

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a ‘final rule’ from the DOE’s Office of Fossil Energy on “Administrative Procedures with Respect to the Import and Export of Natural Gas”. A direct final rule (DFR) on the same subject (and RIN - 1901-AB67) was published in the Federal Register (90 FR 20758) on May 16th, 2025.

It looks like yesterday’s announcement by OIRA deals with the DOE’s response to the two ‘significant adverse comments’ (here and here) received by DOE in response to the earlier DFR. If DOE acknowledges that either of the two received comments meets the definition of a ‘significant adverse comment’ under DOE’s administrative procedures, the newly announced rulemaking will:

• Withdraw the rulemaking (and perhaps initiate a notice of proposed rulemaking doing the same thing), or

• Reissue the rulemaking with new language that specifically addresses how the rulemaking meets the exception requirements of 5 USC 553(b).

I suspect that the second option will be used with the DOE specifically claiming (with some justification) that the revised requirements do not require the application of the ‘good cause’ exception {§553(b)(B)} since they fall under the “rules of agency organization, procedure, or practice” exception under §553(b)(A). The previously issued rulemaking already outlined how the revised procedures would decrease the burden on the regulated community, but did not specifically claim the subparagraph (A) exception.

I do not plan to cover this rulemaking in any depth when it is published, but I do expect to report its publication in the appropriate ‘Short Takes’ post.

 

For more details about this rulemaking, including a discussion about the DFR exception process, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/doe-sends-admin-procedures-on-natural - subscription required.

Friday, April 19, 2024

OMB Approves DOE’s Foreign Entity Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for the DOE on “U.S. Department of Energy Interpretation of Foreign Entity of Concern”. The rule was submitted to OIRA on March 21st, 2024. This rulemaking was not listed in the Fall 2023 Unified Agenda.

This rulemaking will probably be published next week.

Friday, March 22, 2024

DOE Sends Foreign Entity Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule (direct final rule?) from the Department of Energy on “U.S. Department of Energy Interpretation of Foreign Entity of Concern”. This rulemaking was not listed in the Fall 2023 Unified Agenda.

Friday, October 7, 2022

DOE Publishes RFI for University Aid to Grid Resiliency

Today the DOE’s Grid Deployment Office (GDO) published a request for information in the Federal Register (87 FR 61008-61009) for “Capabilities of Universities and Private-Sector Firms for Providing Technical Assistance to States, U.S. Territories, Indian Tribes, and Other Eligible Entities To Enhance the Resilience of Electricity Delivery Systems”. The GDO is looking for information about “capabilities for providing assistance to States, U.S. Territories, Indian Tribes, and other eligible entities to enhance their ability to plan and implement strategies for improving the resilience of systems that deliver electric power.”

GDO is looking for information on technical assistance capabilities in the following areas:

• Forecasting methods and tools to determine customer electricity demand, the adoption of distributed energy resources, and weather/climate parameters at national, regional, and local levels.

• Risk assessment methods, tools, and processes to examine risks and their impacts on energy infrastructure, essential human services, and vulnerable populations to prioritize resilience investments.

• Modeling and simulation methods and tools to determine the severity and impact of threats on energy and electricity infrastructure at national, regional, and local levels.

• Methods and tools for multi-objective decision analysis to enable the prioritization of electric infrastructure investment options across a range of policy objectives.

• Methods and tools for addressing energy equity in the determination of resilience measures.

• Cost-effectiveness methods and tools to ascertain the appropriateness and benefit of infrastructure investments to aid decision-making.

There is no mention of cybersecurity concerns in this RFI.

GDO requests that interested parties provide responses by email (40101TA@hq.doe.gov) by November 21st, 2022.


Friday, September 10, 2021

Review - HR 4939 Introduced - Grid Security Research and Development

Last month, Rep Bera (D,CA) introduced HR 4939, the Grid Security Research and Development Act. The bill would amend Title VIII, Division Z (the Energy Act of 2020) of the Consolidated Appropriations Act,  2021, inserting 9 new sections in that Title. To support the programs in those new sections the bill would authorize $371 million in FY 2022, increasing to $442 million in FY 2026. The new sections would be:

§8013. Energy sector security research, development, and demonstration program.

§8014. Grid resilience and emergency response.

§8015. Best practices and guidance documents for energy sector cybersecurity research.

§8016. Vulnerability testing and technical assistance to improve cybersecurity.

§8017. Cybersecurity education and workforce training research and standards.

§8018. Interagency coordination and strategic plan for energy sector cybersecurity research.

§8019. Report to Congress.

§8020. Critical infrastructure research and construction.

§8021. Definitions.

Bera and his single cosponsor {Rep Weber (R,TX)} are both members of the House Space, Science, and Technology Committee to which this bill was assigned for consideration. This means that there could be enough influence to see the bill considered in Committee. I suspect that there will be some level of bipartisan support for this bill, but I am not sure that it would be sufficient to allow the bill to move to the floor of the House under the suspension of the rules process. I doubt that there is enough solid support for this bill in the leadership to have the bill move to the floor under regular order.

For more detailed description of the programs outlined in this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4939-introduced - subscription required.

Thursday, July 22, 2021

Review - S 2302 Introduced – DOE Organization

Last month, Sen Barrasso (R,WY) introduced S 2302 (no fancy name). The bill would amend 42 USC 7133(a), which lists the duties of the eight Assistant Secretaries of the Department of Energy. It removes some of the wording of §7133(a) and adds a paragraph (12) listing security and emergency response related duties for Assistant Secretaries.

Barrasso is the Ranking Member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration and his sole cosponsor {Sen Risch (R,ID)} is also a member of the Committee. Normally, this would mean that Barrasso would have enough influence to see the bill considered in Committee. The fact, however, that there is no Democrat cosponsor would seem to indicate that there are conflicts within the Committee about these provisions that may mitigate against the consideration.

For a closer look at the details of the changes proposed in this bill and their potential political ramifications, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2302-introduced - subscription required.

Tuesday, November 24, 2020

S 4795 Introduced – Cyber Sense Program

Last month Sen Rosen (D,NV) introduced S 4795, the Cyber Sense Act of 2020. This bill is very similar to HR 360 that passed in the House days before this bill was introduced. The bill would require DOE to establish “a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system” {§2(b)}.

Differences Between S 4795 and HR 360

The essential components of the ‘Cyber Sense Program’ are the same in the two bills. The differences are structural (S 4795 includes a definitions sub-section {§2(a)} and editorial (HR 360 makes multiple references to the ‘Cyber Sense Program’ where S 4795 makes reference to ‘the program’). These are common stylistic differences frequently seen in House and Senate language.

Moving Forward

Rosen is not a member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration, but her three cosponsors {Sen Hoven (R,ND), Sen King (I,NH), and Sen Risch (R,ID)} are members of that Committee. If this bill had been introduced earlier in the session there would be a good chance that the bill would be considered in Committee and adopted with bipartisan support. There probably is not enough time remaining in the session for this to happen.

Given the fact that HR 360 passed in the House by a voice vote, there remains a good chance that the Senate could directly take up this bill under the unanimous consent process, but I am not sure why they would want to take up this bill rather than HR 360. If S 4795 were passed, it would have to go back to the House for an additional vote (where it would almost certainly pass) but passing HR 360 would avoid having to take that extra step. It is probably a toss up for which would be considered.

Commentary

My two objections to the language of HR 360 also apply to this bill. The information protection language in both bills would allow vendors to continue to sell vulnerable devices without notification and it would probably stop researchers from reporting vulnerabilities to the program instead of CISA NCCIC-ICS. The bigger problem continues to be the lack of specific funding authorization in either bill. This would mean that the DOE would have to fund this program with existing monies, taking money from other programs.

Wednesday, September 30, 2020

House Passes 3 DOE Cybersecurity Bills – 9-29-20

Yesterday the House considered three Department of Energy cybersecurity related bills under the suspension of the rules process. All three bills passed by voice vote.

The three bills were:

• HR 359, the Enhancing Grid Security through Public-Private Partnerships Act,

• HR 360, the Cyber Sense Act of 2019, and

• HR 362, the Energy Emergency Leadership Act

I have not covered HR 362 here in this blog. It would amend 42 USC 7133(a); specifically adding ‘cybersecurity’ as one of the functions which would be assigned to one of more of the eight Assistant Secretaries in the Department.

Moving Forward

These three bills now move to the Senate for possible consideration. None of the bills is important enough in the grand scheme of things to be considered on the floor of the Senate under normal order (debate, amendment and multiple votes), especially this late in a COVID-19, election-year limited session. The only hope that these bills have for action in the Senate would be consideration under the unanimous consent process. The voice votes yesterday would seem to indicate that that could be possible.

Unfortunately, unanimous consent motions can be stopped by the objection of a single Senator. That objection would not necessarily have anything to do with the provisions of the bill but could be used as a lever for one or more Senators to have their way on some other legislative priority. I will be pleasantly surprised if any of these bills are considered in the Senate

Commentary

Of the three bills, only HR 360 has the potential of accomplishing anything in the cybersecurity realm. The other two bills are Congressional ‘we did something’ bills that essentially reaffirm actions already taken by DOE.

But even HR 360 will be of limited effect since it is a voluntary program for vendors and utilities. The only real mandate is the prohibition on information sharing by DOE about vulnerabilities discovered during testing. Since vendors could still continue to sell the vulnerable devices (especially outside of the utility market), this could actually increase the risks for end users, even within the ‘protected’ electric sector.

Of course, the biggest drawback to HR 360 is that the lack of funding for the proposed Cyber Sense program.

Monday, March 16, 2020

DOE Publishes CEII Admin Final Rule


Today the Department of Energy (DOE) published a final rule in the Federal Register (85 FR 14756-14772) concerning “Critical Electric Infrastructure Information; New Administrative Procedures”. The rule establishes procedures for the designation of critical electric infrastructure  information (CEII) under section 215A(d) of the Federal Power Act (16 USC 824o-1). The notice of proposed rulemaking (NPRM) for this action was published in October 2018. OMB approved this final rule on January 28th, 2020.

Changes from NPRM


Changes that were made in the final rule include:

• Added definition of ‘confidential business information’;
• Added definition of ‘CEII Coordinator’;
• Specified that the CEII Coordinator or Coordinator's designee can designate certain information sought by DOE as CEII;
• Expanded the coordination of implementation of DOE's CEII authority to include all CEII Coordinators;
• Updated the marking of CEII as “CEII-CRITICAL ELECTRIC INFRASTRUCTURE INFORMATION—DO NOT RELEASE”;
• Added dual marking requirement for material that is both confidential business information and CEII;
• Clarified that a conference call will be scheduled within five days of when the CEII submitter is notified of the request;
• Added DHS and NRC to the list of federal agencies that the CEII Coordinator will meet with annually to discuss CEII issues;
• Added requirement that the designation decision be communicated “promptly” to the requestor;
• Removed all references to “pre-designation” in the Final Rule;
• Clarified that there are two methods for initiation of the re-designation process;
• Clarified that  reconsideration requests can be made through a secure electronic submission or by mail;
• Clarified that inadvertent disclosure does not affect the disclosed material's CEII status

Effective Date


The effective date on this rule is May 15th, 2020.

Wednesday, October 30, 2019

DOE CEII Final Rule to OMB – 10-29-19


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOE on “Critical Electric Infrastructure” According to the Spring 2019 Unified Agenda, the rule would outline the “administrative procedures [that] are intended to ensure that stakeholders and the public understand how the Department would designate, protect, and share CEII under the Federal Power Act”. The notice of proposed rulemaking for this action was published in October 2018.

Wednesday, August 14, 2019

DOE Calls for Comments on Cybersecurity Maturity Model


Today the DOE published a request for comments in the Federal Register (84 FR 40399-40400) on version 2.0 of its Cybersecurity Capability Maturity Model (C2M2). According to the notice the “C2M2 Version 2.0 leverages and builds upon existing efforts, models, and cybersecurity best practices to advance the model by adjusting to new technologies, practices, and environmental factors.”

The development of version 2.0 includes:

• Establishing a Cybersecurity Architecture domain
• Separating the maturity indicator levels (MILs) from the Information Sharing and Communications domain to include sharing practices in the Threat and Vulnerability Management and Situational Awareness domains
• Movement of Continuity of Operations MILs from the Incident and Event Response to the Cybersecurity Program Management domain to account for continuity activities beyond response events
• Increasing the use of common language throughout the model.

Public comments are being solicited, but there are no instructions within the document on how to submit comments. It does not look like the Federal eRulemaking Portal could be used since there is no docket number provided in the notice. An email address has been provided for Timothy Kocher, who is the DOE officer who signed the notice, but it would be unusual for public comments to be sent directly to him. I have an email in route to Kocher and will update this post as more information becomes available.

Wednesday, July 24, 2019

2 Advisories and 1 Update Published – 07-23-19


Yesterday the DHS NCCIC-ICS published two control system security advisories for products from National Renewable Energy Laboratory (NREL) and Mitsubishi Electric. They also updated a previously published medical device advisory from GE Healthcare.

NREL Advisory


This advisory describes a stack-based buffer overflow vulnerability in the NREL EnergyPlus Energy simulation program. The vulnerability was reported by Karn Ganeshen. NREL has an update available that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute arbitrary code or cause a denial-of-service condition.

NOTE: There is nothing on the DOE’s EnergyPlus web site about this vulnerability, nor do I see any POC for reporting cybersecurity concerns. DOE, really?

Mitsubishi Advisory


This advisory describes two vulnerabilities in the Mitsubishi Electric FR Configurator. The vulnerability was reported by Applied Risk. Mitsubishi has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper restriction of an XML external entity reference - CVE-2019-10976; and
• Uncontrolled resource consumption - CVE-2019-10972

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to enable arbitrary files to be read or cause a denial-of-service condition.

GE Update


This update provides additional information on an advisory that was originally reported on July 9th, 2019. The new information is the addition of more covered products.

NOTE: I briefly reported on GE’s update last Saturday.

Monday, October 29, 2018

CEII Admin Procedures NPRM Published


The Department of Energy published a notice of proposed rulemaking (NPRM) today in the Federal Register (83 FR 54268-54278) describing the DOE’s proposed procedures for the designation and control of Critical Electric Infrastructure Information (CEII) that would parallel the Federal Energy Regulatory Commission’s rules on CEII (18 CFR 388.113). This rule implements the CEII requirements set forth in §61003(d) of the 2015 FAST Act {PL 114-94, 129 STAT. 1773; codified at 16 USC 824o-1(d)}.

The NPRM would add 10 CFR 1004.13, Critical Electric Infrastructure Information. This would include sub-paragraphs for:

• Protection of CEII (Note: This is apparently mismarked at ‘(6)’ not ‘(g)’ in the NPRM);

Readers are reminded that CEII is a listed type of controlled unclassified information (CUI) under the Information Security Oversight Office (ISOO) regulations (32 CFR 2002). Where the requirements of this new DOE rule do not exceed the requirements of the ISOO regulation, the ISOO regulation supersedes these requirements.

DOE is soliciting comments on this NPRM. Comments must be received by December 28th, 2018. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; RIN 1901-AB44).

Wednesday, October 17, 2018

OMB Approves New CEII NPRM


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the Department of Energy on their Critical Electric Infrastructure Information (CEII) program. The NPRM was submitted to OMB in July.

When this NPRM was submitted the rulemaking had not been listed in the latest (Spring 2018) Unified Agenda. Yesterday OIRA published the Fall 2018 Unified Agenda (more on this in another post) and this rulemaking was included; not much information in the listing, unfortunately. The abstract in the listing simply notes:

“The Department of Energy (DOE or Department) is publishing a proposed rule for public comment to implement DOE’s critical electric infrastructure information (CEII) designation authority under section 215A of the Federal Power Act.  The proposed administrative procedures are intended to ensure that stakeholders and the public understand how the Department would designate, protect, and share CEII under the Federal Power Act”

I expect that the NPRM will be published in the Federal Register in the next week or two; even when it initiates regulatory action, the Trump Administration is not quick about these things.


Wednesday, July 11, 2018

DOE Sends CEI Rulemaking to OMB for Approval


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that DOE had submitted a notice of proposed rulemaking (NPRM) on Critical Electric Infrastructure (CIE) for approval. This rulemaking was not published in the Spring 2018 Unified Agenda, so it is not clear what the rule would specifically address.

An article (registration required) in E&E News yesterday, however, states:

“The Department of Energy will soon publish proposed regulations outlining how it plans to ‘receive, hold and share’ critical electricity infrastructure information from utilities, a senior DOE official [Catherine Jereza, DOE's deputy assistant secretary for transmission planning and technical assistance] said yesterday.”

Most of what Jereza describes is covered under 18 CFR 388.113. Interestingly that Critical Electric Infrastructure Information (CEII) regulation only covers information disclosed to the Federal Energy Regulatory Commission (FERC). It does not specifically include similar (or even identical) information disclosed directly to DOE.

Saturday, February 10, 2018

OMB Approves DOE ASHRAE 2016 Determination


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that they had approved the DOE’s final rule on ASHRAE 2016 Determination. DOE should publish this ‘determination’ in the Federal Register this week.

In an earlier blog post I opined that this may be related to the publication of the  American Society of Heating, Refrigerating and Air-Conditioning Engineers (ASHRAE) standard on the Facility Smart Grid Information Model (FSGIM; ASHRAE 201-2016). Since this rulemaking is was not included in the latest version of the Unified Agenda, I was looking for a possible explanation for what DOE was doing. Subsequent investigation has shown that I was probably wrong.

It looks like this ‘determination’ is actually related to the DOE’s responsibility under 42 USC 6833(b)(2)(A) to determine if the latest version of ASHRAE Standard 90.1 (in this case the 2016 version) “will improve energy efficiency in commercial buildings”. Last September DOE published their preliminary determination analysis that the 2016 version would improve energy efficiency and requested public comments on their draft report.

Since this final rule almost certainly pertains to energy efficiency not smart grid implementation, I doubt that this rulemaking will have any further mention in this blog.

 
/* Use this with templates/template-twocol.html */