Showing posts with label FERC. Show all posts
Showing posts with label FERC. Show all posts

Friday, April 24, 2026

OMB Approves FERC 5-year Oil Pipeline Index Review Final Rule

 Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for the Federal Energy Regulatory Commission on “Five-Year Review of the Oil Pipeline Index”. The final rule was submitted to OIRA on April 2nd, 2026. The notice of proposed rulemaking for this action was published in the Federal Register on November 24th, 2025. 

According to the Spring 2025 Unified Agenda for this rulemaking: 

“The Federal Energy Regulatory Commission (Commission) intends to issue a Notice of Proposed Rulemaking initiating its routine review of the oil pipeline index level, a longstanding and recurring rulemaking that the Commission has conducted on regular five-year intervals since establishing the index in 1995 (Docket No. RM25-10-000).” 

That explanation is obviously out-of-date, but that is to be expected since the Administration has not yet published their Fall 2025 Unified Agenda. It will be interesting to see if/when they publishe the Spring 2026 Unified Agenda. 

I do not expect to cover this final rule in any depth. I do, however, expect that I will note its publication in the appropriate Short Takes post. 

Tuesday, October 21, 2025

Review - FERC Publishes Regulation Sunset Rules 10-21-25

Today the Federal Energy Regulatory Commission (FERC) published two rulemakings in the Federal Register, both relating to the sunset date requirements of EO 14270, Zero-Based Regulatory Budgeting to Unleash American Energy. The first rulemaking (90 FR 48397-48408) is a direct final rule (DFR); it would add a sunset date of December 5th, 2026 to each of several sections of 18 CFR Parts 2, 5, 36, 131, 153, 156, 157, 203,  206, 287, 300, 366, 375, and 385. Absent any ‘significant adverse comment’ submitted in response to this DFR, this rule goes into effect on December 5th, 2025.

The second rulemaking (90 FR 48419-48421) is a notice of proposed rulemaking (NPRM) on the same topic. Effectively, it only comes into play if there are any significant adverse comments filed on the DFR above. According to the NPRM preamble:

“This NOPR ensures that the Commission has a proceeding through which it can consider any significant adverse comments that might be filed in response to the direct final rule and determine whether to proceed with finalizing specific sunsetting regulations.”

Public Comments

FERC is soliciting comments on the DFR (which may transfer to the NPRM if FERC declares any of the comments to be significant adverse comments). Comments may be submitted via electronic comments via https://ferconline.ferc.gov/QuickComment.aspx. Comments should be submitted by November 20th, 2025.

 

For more information on the provisions of these two rulemakings, including commentary on missed deregulatory credit, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ferc-publishes-regulation-sunset - subscription required.

Friday, September 19, 2025

Review - FERC Sends Sunset Provisions Direct Final Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a direct final rule from the Federal Energy Regulatory Commission (FERC) on “Implementation of the Executive Order [EO 14270] Entitled ‘Zero-Based Regulatory Budgeting to Unleash American Energy’”. This rule was not listed in the Spring 2025 Unified Agenda. Without the information that would be provided in a UA rulemaking listing, we can only guess that this rule would implement the sunset provisions of section 4 of  EO 14270 for all covered existing FERC regulations.

 

For a discussion about the ‘sunset rule’ provisions of EO 14270, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ferc-sends-sunset-provisions-direct - subscription required.

Tuesday, February 27, 2024

OMB Approves FERC’s CEII Data Request ICR Revision

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a revision request for the Federal Energy Regulatory Commission’s (FERC’s) information collection request (ICR) on “Critical Energy/Electric Infrastructure [CEII] Information Data Request”. The ICR burden was revised downward based upon the recent history of such requests.

The abstract for the announcement notes that:

“In accordance with section 215A(d) of the Federal Power Act and 18 CFR 388.113, this collection of information provides that persons may seek Critical Energy/Electric Infrastructure Information (CEII). To receive CEII, they must show they have a legitimate need for such information, and they must submit a non-disclosure agreement that decreases the likelihood that such information could be used to plan or execute terrorist attacks.”

FERC is one of those agencies that actually periodically updates their ICR requests to reflect recent historical data (which in my opinion all agencies should do for all ICRs). This ICR has been in place since 2002, and the table below is a quick look at the changes in their burden estimates over that time.

 

# of Responses

Burden (hrs)

2002

200

50

2005

182

46

2008

200

60

2020

100

30

2023

50

15

Thursday, August 3, 2023

CSB Urges FERC to Include Hurricanes in Planning Considerations

Yesterday, the Chemical Safety Board disclosed a July 13th, 2023 letter the Board sent to the Federal Energy Regulatory Commission (FERC) that urged “FERC them to address hurricanes and other high-wind extreme weather events in future updates to the Transmission System Planning Performance Requirements for the nation’s bulk-power system.” They note in the letter that June 15th, 2023, Transmission System Planning Performance Requirements for Extreme Weather final rule “, does not address extreme weather events beyond heat and cold, such as high winds and hurricanes, although stakeholders had urged FERC to include such events in the rule.”

The letter goes on to explain CSB’s interest in the matter by explicating two investigations that the Board had conducted about releases caused by hurricanes: the 2017 Arkema organic peroxide incident and the 2022 Bio-Labs TCCA incident.

Interestingly, the Board’s letter does not address flooding events from extended, high-intensity rain storms not associated with hurricanes such as the flooding in Vermont last month, of course that event occurred after the letter was sent and no chemical incident investigations resulted from that flooding. But warning of the potential consequences of such floods should not require a deadly incident to occur before the warning is issued.

Monday, May 1, 2023

Committee Hearings – Week of 4-30-23

This week with just the Senate in session, there will be a relatively light hearing schedule. There is one hearing that may address cybersecurity issues in the management of the electric grid.

FERC Oversight Hearing

On Thursday, the Senate Energy and Natural Resources Committee will hold an oversight hearing for the Federal Energy Regulatory Commission. No witness list is provided, but the sole witness is likely to be the Chair, Willie L. Phillips. This will be a wide ranging discussion, but will almost certainly include questions about cybersecurity and physical security issues.

Thursday, October 6, 2022

Review - FERC Publishes Cybersecurity Incentives NPRM Redux

Today the DOE’s Federal Energy Regulatory Commission (FERC) published a notice of proposed rulemaking (NPRM; yes, FERC uses the DOE ‘NOPR’ but for internal consistency, I will continue to use the more common NPRM) in the Federal Register (87 FR 60567-60580) for “Incentives for Advanced Cybersecurity Investment”. This rulemaking is mandated by §40123 of the Infrastructure and Jobs Act  (PL 117-58, 135 STAT 951). This proposed rulemaking supersedes the NPRM published in January 2021.

In this NPRM FERC proposes to:

Establish a regulatory framwork on how a utility could qualify for incentives for eligible cybersecurity expenditures,

Evaluate cybersecurity investments using a list of pre-qualified expenditures that are eligible for incentives determined by the Commission and publicly maintained on the Commission's website (PQ List),

Establish two options for the type of incentive a utility could receive for an eligible cybersecurity expenditure,

Provide that any approved incentive(s) will remain in effect for five years from the date on which the cybersecurity investment(s) enters service or expenses are incurred, and

Require that a utility that has received a cybersecurity incentive under this section must make an annual informational filing.

Public Comments

FERC is soliciting public comments on this rulemaking. FERC does not use the Federal eRulemaking Portal. Comments may be submitted via the FERC eFiling site (Docket No. RM22-19-000). Comments should be submitted by November 7th, 2022; return comments by November 21st.

Commentary

FERC has come up with an interesting way around a problem that has plagued cybersecurity regulatory efforts, keeping the regulations at least close to current threat and technology trends. Instead of trying to codify the ‘qualified’ expenditures in the regulations (which take long periods of time to update for new technologies and threats), the preamble to the rule lists six federal cybersecurity programs that would be expected to provide more timely information about cybersecurity controls and technology. Two of those programs do use a public comment and response process to update, but the remaining four have a history of responding in months to changes in the threat landscape instead of the years that regulatory changes take. FERC can get away with this since they are not mandating the implementation of these controls, just providing rate incentives to organizations that do implement them.

 

For more details about the proposed rulemaking, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ferc-publishes-cybersecurity-incentives - subscription required.


Monday, January 24, 2022

Reader Comments – Alternatives to FERC INSM NOPR

An interesting discussion this weekend over on LinkedIn about my post on FERCs INSM notice of proposed rulemaking. Lots of good information in that discussion. One point worth mentioning here; Richard Brooks provided a link to an article in which he is quoted as saying:

“The NOPR will “not provide cybersecurity improvements because many entities already implement these cybersecurity best practices, such as anti-malware, but the FERC Order will increase the workload on entities subject to NERC compliance, because they will also have to meet all of the NERC compliance requirements, usually in the form of paperwork, in addition to managing cybersecurity,” Brooks added.”

This is a standard argument against almost any regulatory mandate, and it has a certain level of validity, particularly for the ‘many entities [that] already implement these cybersecurity best practices’. For those organizations, the order resulting from this rulemaking effort will certainly result in some level of increase in compliance paperwork and that increased workload will not result in any better cybersecurity for those organizations. And depending on how the rule is worded and implemented, it may impede future innovation in this security niche. But the latter is supposed to be addressed by the cooperative rulemaking process under NERC.

Unfortunately, ‘many entities’ is not ‘all entities’ and in an interconnected system like the bulk electrical system, the country cannot afford to have too many weak links in that system. Being able to get the BES to a level where most of the high and medium impact systems are effectively using internal network security monitoring systems is only going to be achieved by going this regulatory route.

Friday, January 21, 2022

Review - NERC-CIP and Internal Network Monitoring

Yesterday the Federal Energy Regulatory Commission (FERC) published a notice of proposed rulemaking (NOPR in the FERC jargon) on their website for “Internal Network Security Monitoring for High and Medium Impact Bulk Electric System Cyber Systems”. In this NOPR, FERC proposes to direct the North American Energy Reliability Corporation (NERC) to “to develop and submit for Commission approval new or modified Reliability Standards that require internal network security monitoring within a trusted Critical Infrastructure Protection networked environment for high and medium impact Bulk Electric System Cyber Systems.”

NOTE: Thanks to Patrick C Miller, Ampere Industrial Security [company name and link added, 8-11-22 13:24 EDT] for pointing out this NOPR on TWITTER®.

Seeking Public Comments

FERC is soliciting public comments on this NOPR. Comments may be submitted via the eFile option on www.FERC.gov for registered individuals (Docket # RM22-3-000). Others may send comments via snail mail to:

Federal Energy Regulatory Commission

Office of the Secretary

888 First Street NE

Washington, DC  20426

The deadline for submission of comments will be 60-days after the NOPR is published in the Federal Register, probably sometime next week.

Commentary

This proposed expansion of cybersecurity regulations should surprise no one. It does not appear to me to be the least bit unreasonable. I would hope that most organizations under the NERC CIP would have at least some level of view within their networks that would form part of the proposed INSM, so that this proposed requirement should not be too much of a new regulatory burden.

This rulemaking is targeted at the physical operations networks supporting the BES, but other organizations utilizing similar networks to conduct operations in the physical realm should take a hard look at the proposals in the NOPR as similar technology is necessary to protect operations technology in other industries as well.

For more details about the NOPR, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nerc-cip-and-internal-network-monitoring - subscription required.

Monday, December 20, 2021

Review - HR 6084 Introduced – Energy Product Reliability

Last month, Rep Rush (D,IL) introduced HR 6084, the Energy Product Reliability Act. The bill would require the Federal Energy Regulatory Commission (FERC) to establish an Energy Product Reliability Organization that would to for energy pipelines what NERC has done for the national electric grid. No funding is authorized by this bill.

Rust is a member of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see this bill considered in Committee. I suspect that there would be substantial opposition to this bill from Republicans that generally resist comprehensive regulatory requirements such as those foreseen by this legislation. The bill could pass out of Committee because of Democratic control

I doubt that this bill would make it to the floor of the House because of opposition from two different Committee Chairs, the Homeland Security Committee and the Transportation and Infrastructure Committee. The new authority for EPRO’s would cut into their separate influence over cybersecurity and pipeline security respectively.

Commentary

The requirement for the EPRO to consult with TSA And DOE on cybersecurity standards is more than a little odd. The DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), certainly retains the preeminent government authority (the knowledge based definition of that term) on energy cybersecurity, TSA retains the regulatory authority to oversee security (including, by default, cybersecurity). Thus the ‘consult with’ requirement of §2(e)(4) should probably be changed to a ‘coordinate with’ mandate, unless the legislation were to remove TSA responsibility for security oversight of energy pipelines. Of course, that is not likely to happen (see paragraph immediately above).

TSA has been working with the pipeline industry on voluntary physical security standards for quite some time and CESER also has a background in physical pipeline security processes. Thus, it would certainly be appropriate, at a minimum, to change that paragraph to read:

(4) CONSULTATION.—The Energy Product Reliability Organization shall consult with the Administrator of the Transportation Security Administration and the Secretary of Energy in developing energy product reliability standards relating to cybersecurity for energy pipelines.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6084-introduced - subscription required.

Friday, February 5, 2021

FERC Published Cybersecurity Incentives NPRM

Today the Federal Energy Regulatory Commission published a notice of proposed rulemaking in the Federal Register (86 FR 8309-8325) on ‘Cybersecurity Incentives’. The rulemaking would “establish rules for incentive-based rate treatments for voluntary cybersecurity investments by a public utility for or in connection with the transmission or sale of electric energy subject to the jurisdiction of the Commission, and rates or practices affecting or pertaining to such rates for the purpose of ensuring the reliability of the Bulk-Power System.”

While investments and expenses required to conform to CIP Reliability Standard would not be covered in this proposal, FERC proposes to allow deferred cost recovery for three categories of expenses:

•Expenses associated with third-party provision of hardware, software, and computing networking services,

•Expenses for training to implement new cybersecurity enhancements undertaken pursuant to this rule, and

• Other implementation expenses, such as risk assessments by third parties or internal system reviews and initial responses to findings of such assessments.

CIP Applied to New Facilities

In the new 18 CFR 35.48 that is being proposed in this rulemaking FERC is proposing two separate modalities for facilities to claim the cybersecurity incentives for through voluntary investment in applying the requirements of the CIP Reliability Standards to additional facilities. In the proposed §35.48(b)(1)(i) FERC would allow “a public utility to receive incentive rate treatment for voluntarily applying the requirements for medium or high impact systems to low impact systems, and/or the requirements for high impact systems to medium impact systems”.

The second instance is found in the proposed §35.48(b)(1)(ii) where FERC would allow “a public utility to receive incentive rate treatment for voluntarily ensuring that all external routable connectivity [56] to and from the low impact system connect to a high or medium impact BES Cyber System.”

NIST Framework

In §35.48(b)(2) FERC would authorize a public utility to “receive incentive rate treatment for implementing certain security controls included in the NIST Framework (NIST Framework Approach).” The ‘certain security controls’ are not enumerated in §35.48, but the preamble notes that they include:

• Automated and continuous monitoring,

• Access control,

• Data protection,

• Incident response, and

• Physical security of cyber systems.

Public Comments

FERC is soliciting public comments on the proposed rulemaking. FERC does not use the Federal eRulemaking Portal. Comments may be submitted via the FERC eFiling site (Docket No. RM20-3-000). Comments should be submitted by April 6th, 2021; return comments by May 6th, 2021.

Thursday, August 2, 2018

FERC Publishes Official Cybersecurity Reporting Rule


Earlier this week the Federal Energy Regulatory Commission (FERC) published their final rule on revisions to the cybersecurity reporting requirements in the Federal Register (83 FR 36727-36741). This is the formal publication of their order from two weeks ago. Publication in the Federal Register sets the effective date for the order as October 1st, 2018.

There is nothing new here that was not included in the original order. There are some administrative portions of this order that I did not comment on earlier that deserve some mention in passing. These items all reflect the odd relationship between FERC and the electric grid community and the North American Electric Reliability Corporation (NERC).

Information Collection Request

 

Whenever a federal rule requires the collection of information from a private entity there is a requirement for the OMB’s Office of Information and Regulatory Affairs (OIRA) to approve an Information Collection Request (ICR) before the agency can require the provision of the information. This rulemaking includes the obligatory request for comments on the ICR supporting this rulemaking. In this case it is an ICR revision request not a new ICR because OIRA has already approved a related ICR.

The ‘odd’ thing here is that the approved ICR has nothing to do with cybersecurity reporting requirements (which already do exist, this rule is just expanding the requirements). That is because the rule does not require any cybersecurity reporting. This rule directs NERC to modify existing reporting requirement. The existing ICR that is being revised deals with reporting requirements by NERC to FERC on the establishment of electric reliability standards (OMB Control No. 1902-0225).

When NERC rewrites CIP-008-5 and submits it to FERC for approval there will then be a requirement to submit an ICR revision request to reflect those changed reporting requirements.

Regulatory Flexibility Act


Another federal rule, the Regulatory Flexibility Act (5 USC 601-612), mandates a variety of analysis and reporting requirement for federal agencies to undertake when initiating/finalizing a rulemaking to specifically report on the effect of that rulemaking on small entities. This final rule includes that analysis.

Again, FERC reports that the only affected party under this rulemaking is NERC.  Because of the unusual relationship between FERC, NERC and the bulk power industry, FERC is able to certify that “this Final Rule will not have a significant economic impact on a substantial number of small entities”. When NERC proposes the changes to the Reliability Standards for Cyber Security Incident reporting required by this rulemaking, FERC will “make determinations pertaining to the Regulatory Flexibility Act based on the content of the Reliability Standards proposed by NERC”.

Sunday, July 22, 2018

FERC to Expand Cybersecurity Reporting Requirements


Earlier this week the DOE’s Federal Energy Regulatory Commission published an order (final rule) on their web site (it will become official when published, probably next week, in the Federal Register) directing the North American Electric Reliability Corporation (NERC) “to develop and submit modifications to the NERC Reliability Standards to augment the mandatory reporting of Cyber Security Incidents, including incidents that might facilitate subsequent efforts to harm the reliable operation of the bulk electric system (BES).” The notice of proposed rulemaking for this order was published in December of last year.

I am not going to go into a great deal of detail about this rule here; the complex relationships between FERC, NERC and the electric grid are just a little too byzantine for my simple mind to understand. The interesting take away here for the rest of the control system security community is that the new rules to be written by NERC will expand ‘Cyber Security Incidents’ (capitalized and not hyphenated in FERC SPEAK) to include some sort of measure of near misses and they will include a requirement to notify ICS-CERT of those incidents in addition to the current requirement to notify the Electricity Information Sharing and Analysis Center (E-ISAC).

Expanded Definition


Currently the NERC Reliability Standard CIP-008-05 requires the reporting of Cyber Security Incidents only if they have “compromised or disrupted one or more reliability tasks.” While such incidents are certainly worth reporting they leave a whole slew of potential preparatory ‘attacks’ and compromises outside of the mandatory reporting structure and completely ignore the salutatory effects of sharing information about ‘near misses’ or almost successful attacks.

With this order NERC will be required to recraft CIP-008 to include “Cyber Security Incidents that compromise, or attempt to compromise, a responsible entity’s [Electronic Security Perimeter] ESP or associated [Electronic Access Control or Monitoring Systems] EACMS” in the reporting requirements.

ICS-CERT


In the NPRM it was noted that the DOE noted only two Cybersecurity Incident Reports in 2015/2016 while in the same time frame the DHS ICS-CERT responded to 125 cybersecurity incidents in 2014/2015. Ignoring the whole apples and rocks comparisons here, it becomes apparent that some sort of reporting is already underway to ICS-CERT. The FERC order would formalize that and make it a reporting requirement.

Commentary


The expansion of the reporting requirements for Cyber Security Incidents (and I AM NOT going to do another ‘CSI’ acronym; can’t do it, sorry) cannot help but be a good thing; except….

Okay, we have no idea how many new reports this requirement will generate. IF the industry complies with the intent of the rule (an open question) the number of reports could be quite large. Does NERC (who owns E-ISAC) have the necessary number of analysts necessary to review, catalogue, cross-reference, and then deduce attack information from such submissions and then produce properly anonymized information to share with the remainder of the community in a timely manner. Because of the lack of a reasonable estimate of the potential number of reports, and the apparently expanding interest in probing/compromising the grid, I suspect not.

Then there is the whole issue of the quality of information that will be submitted to E-ISAC. Obviously, the more complete the information, particularly on attempted attacks, the easier it will be for E-ISAC to establish actionable information to share with the other E-ISAC members; poor quality or inaccurate information means the information ultimately shared is less useful and potentially even counter-productive.

That leads to the question of who will train facility control system engineers to recognize, isolate and document cyber-attacks. Oh, sorry, control system engineers will not be doing that, it will be the Security Operations Center with its staff of forensically trained experts. I forgot that those existed at each facility in the Bulk Electric System (SIGH).

Actually, I suspect that this is the reason that the Order includes a requirement to report to ICS-CERT. I do not expect (that is my guess, I certainly do not know) that E-ISAC has fly-way teams of control system experts to investigate these incidents. That is not a complaint, it is just not what one should probably expect from any ISAC.

The problem that arises from this is has anyone looked at the capability of ICS-CERT to expand the operations of its fly-away teams to respond to an increasing number of incidents. Who is going to pay for the additional costs of the investigations of the new reports? FERC has no control of ICS-CERT either directly nor through the DOE, so is there a memorandum of understanding between the two organizations about how ICS-CERT is supposed to respond to these newly required reports?

All sorts of interesting questions being raised by this relatively simple final rule, but I will ask but one more (really); how are the Critical Electrical Infrastructure Information (CEII) regulations going to affect the information submitted by owners to ICS-CERT? Owners can request that sensitive security information submitted to FERC or NERC be protected by CEII disclosure rules, but not information directly submitted to ICS-CERT. Information submitted to ICS-CERT by NERC or FERC could be so protected, but there are no provisions for information submitted directly from the private sector to ICS-CERT. Another important quandary to be considered stumbling down the road to information sharing.

Thursday, December 28, 2017

FERC NPRM to Increase Cybersecurity Incident Reporting

Today the Federal Energy Regulatory Commission (FERC) published a notice of proposed rulemaking (NPRM) in the Federal Register (82 FR 61499-61505) proposing to require the North American Electric Reliability Corporation (NERC) to improve mandatory reporting of Cyber Security Incidents, including incidents that might facilitate subsequent efforts to harm the reliable operation of the bulk electric system.

New Reporting Requirements


Because of the way that FERC utilizes NERC as the actual regulatory agency for the bulk electric system, this NPRM does not include any actual regulatory language. Instead it proposes to require NERC to develop changes to the Critical Infrastructure Protection (CIP) Reliability Standards, specifically CIP-008-5. This NPRM proposed that FERC would direct NERC to modify the CIP Reliability Standards to:

Include the mandatory reporting of Cyber Security Incidents that compromise, or attempt to compromise, a responsible entity's Electronic Security Perimeter (ESP) or associated Electronic Access Control or Monitoring System (EACMS);
Specify the required content in a Cyber Security Incident report;
Establish requirements outlining deadlines for filing a report once a compromise or disruption to reliable bulk electric system operation, or an attempted compromise or disruption, is identified by a responsible entity; and
Require that the reports submitted under the enhanced mandatory reporting requirements would be provided to E-ISAC, similar to the current reporting scheme, as well as ICS-CERT.

Public Comments


FERC is soliciting public comments on this NPRM. Comments may be submitted via the FERC eFiling page (registration required). Comments should be filed by February 26th, 2018.

Commentary


The FERC/NERC relationship is more than a little odd as compared to the rest of the federal government. Readers who work in and/or around the bulk electrical system are probably used to this, but for a relative outsider like myself, the quirks of the rulemaking process are just a tad byzantine.

For example, the notice states that: “the Commission certifies that this Notice of Proposed Rulemaking will not have a significant economic impact on a substantial number of small entities”. They can get away with saying that because, technically, the NPRM only will affect NERC; nobody else will have to take any actions because of this rulemaking. Of course, once NERC modifies CIP-008-05, bunches of other folks (including some number of ‘small entities’) will have to make changes to the way they operate, but that is years down the road.

One of the interesting aspects of this NPRM is that it uses the FY 2016 ICS-CERT Year in Review as part of the justification for the increased reporting requirements. Apparently in 2016 CERC reported that there were no cybersecurity incidents reported to it while ICS-CERT reported investigating 59 incidents in the 'Energy Sector’ (which may or may not have – but probably did - included anyone in the bulk electric systems).

As I pointed out in a blog post about that report (and in numerous other posts over the years) there is a problem with the ICS-CERT incident reporting numbers, it is based upon a non-existent (but apparently very broad) definition of the term incident. This problem is not unique to ICS-CERT and is actually addressed in this NPRM.

After discussing the issue FERC would actually add a new term; ‘a reportable cybersecurity incident’. Unfortunately, the NPRM does not contain a specific definition of the term. Rather it generally describes the issue by stating: “we believe it is reasonable to establish the compromise of, or attempt to compromise, an ESP or its associated EACMS as the minimum reporting threshold”. Because the NERC CIPs are in effect the regulations that this NPRM is attempting to modify, we will have to see what definition that NERC will establish for the ‘reportable cybersecurity incident’ terminology.


One requirement that is not explicitly explained in the NPRM is why FERC wants ICS-CERT to be included as a recipient of any cybersecurity incident report. While I completely agree (and have advocated such reporting requirements for other sectors as well), it would have been helpful to have FERC explicate their reasoning. For me, the inclusion of ICS-CERT would help to ensure that compromises of control system components (including software and firmware) that are also used in other sectors are shared with those sectors. I suspect that the FERC reasoning is similar, but it would have been helpful to have this spelled out.

Wednesday, December 21, 2016

FERC Publishes CEII Revision Final Rule

Today the DOE’s Federal Energy Regulatory Commission (FERC) published a final rule implementing changes to the Critical Energy Infrastructure Information (CEII) program mandated by §61003 (16 USC 824o–1) of the Fixing America's Surface Transportation (FAST) Act (PL 114-94). The notice of proposed rulemaking NPRM (FERC uses a different acronym – NOPR) was published in June of this year. This rule is unlikely to be overturned by the 115th Congress.

Congressional Mandate


The FAST Act required FERC to:

• Establish criteria and procedures to designate information as critical electric infrastructure information;
• Prohibit the unauthorized disclosure of critical electric infrastructure information;
• Ensure there are appropriate sanctions in place for Commissioners, officers, employees, or agents of the Commission or the Department of Energy [DOE] who knowingly and willfully disclose critical electric infrastructure information in a manner that is not authorized by the statute; and
• Facilitate voluntary sharing of critical electric infrastructure information  between, and by Federal, State, political subdivision, and tribal authorities; the Electric Reliability Organization; regional entities; information sharing and analysis centers; owners, operators, and users of critical electric infrastructure in the United States; and other entities determined appropriate by the Commission.

CEII


A number of commenters on the NPRM requested that the Commission provide more details on what constitutes CEII. The preamble to this rule notes that §824o-1(a)(2) provides a definition of CEII. As a result FERC does not see any need to provide additional guidance on what constitutes CEII. FERC reminds commenters that CEII protections only apply to information submitted to FERC and DOE so no other agencies (including the NRC) may designate information CEII. That does not, however, prohibit other agencies from providing protections to electric grid related information submitted to non-DOE agencies.

Protection of CEII and CUI


FERC declined to provide clarification of what constitutes ‘a secure place’ for storing CEII. The preamble to this rule failed to note that by not specifying regulatory requirements for storing CEII that the controlled unclassified information (CUI) regulations of the National Archives and Records Administration provide the controlling authority to define those requirements (including NIST SP 800-171 for electronic storage and transmission) since CEII is a covered CUI listed in the CUI registry.

Effective Date


This rule will become effective on February 21st, 2017. As I noted earlier, this rule is unlikely to be considered for review by the 115th Congress. The rule implements requirements set by the Republican 114th Congress so there will be little impetus for essentially the same Congress to negate this rulemaking even though it fulfills many of the definitional requirements of a ‘midnight rule’.

Commentary


The CEII program only protects information submitted to FERC and the DOE from disclosure by those agencies or personnel with whom those agencies share the information. It does not establish any requirements for protection of that information by submitting organizations. The only drawback that I see is that FERC/DOE are not required to make a determination that the information actually qualifies for CEII protections until the CEII Coordinator at FERC makes that determination in response to a request for the information.


FERC maintains in this rulemaking that the protect submitted information as if it were CEII until such determinations are made. I think that a good lawyer for a whistleblower could maintain that any disclosures of information by FERC/DOE employee prior to a determination being made by the CEII Coordinator. To my mind it would make more sense to declare all submitted material CEII upon receipt and then to remove that declaration when appropriate when the CEII Coordinator is asked to review the information for possible release.
 
/* Use this with templates/template-twocol.html */