FERC-725B, (Proposed Rule in RM21-3) Mandatory Reliability Standards for Critical Infrastructure Protection [CIP] Reliability Standards)
Revision of a currently approved collection
No
Regular
Comment filed on proposed rule and continue
04/16/2021
02/17/2021
In accordance with 5 CFR 1320, OMB is filing comment and withholding approval at this time. The agency shall examine public comment in response to the proposed rulemaking and will include in the supporting statement of the next ICRâwhich is to be submitted to OMB at the final rule stageâa description of how the agency has responded to any public comments on the ICR, including comments on maximizing the practical utility of the collection and minimizing the burden.
table that charts list comparision
Inventory as of this Action
Requested
Previously Approved
12/31/2021
36 Months From Approved
05/31/2022
224,800
0
224,800
2,119,709
0
2,119,709
0
0
0
NOPR 21-3 is set out to ensure that a public utility receiving incentive rate treatment has implemented the requirements for the incentive and to ensure that it continues to adhere to these requirements, we propose to add § 35.48(f) to the Commissionâs regulations to require public utilities to submit annual informational filings with the Commission. We propose specific reporting requirements for each of the NERC CIP Incentives Approach and the NIST Framework Approach The Transmission Incentives NOPR proposes additional reporting requirements for recipients of transmission incentives under FPA section 219. Such additional reporting is likewise appropriate for cybersecurity upgrades receiving incentives. Accordingly, we propose to add § 35.48(f) to require that, within 120 days of the completion of cybersecurity upgrades for which an applicant is granted incentives, an incentives recipient must make an informational filing and subsequent informational filings annually thereafter. The annual informational filings must detail the specific investments that were made pursuant to the Commissionâs approval and the corresponding FERC account(s) used. In addition, the annual informational filings must describe what parts of its network were upgraded or expanded (i.e., which substations, control centers, automated and continuous monitoring equipment) in addition to the nature (i.e., describing hardware purchase) and actual cost of the various capital investments. For incentives where the Commission allows deferral of expenses as regulatory assets, annual informational filings should describe such expenses in sufficient detail to demonstrate that such expenses are specifically related to implementing the cybersecurity incentives described in this NOPR and not for ongoing costs including system maintenance, surveillance, and other labor costs, either in the form of employee salaries or third-party service contracts.We preliminarily find that the proposed reporting requirements are necessary to provide the Commission with an understanding of the costs of various types of cybersecurity investments in order to more precisely target future incentives or other policies. However, based on the qualities of such investments, as well as the likely higher sensitivity of the information, we propose to require different reporting requirements under this proposal than those proposed under the Transmission Incentives NOPR. Several aspects of cybersecurity necessitate reporting different information that the Commission has required for conventional transmission facilities receiving incentives pursuant to FPA section 219. First, cybersecurity investments are not observable. Unlike conventional transmission facilities, such as a new transmission line, it is not readily apparent if, and when, such investments are completed and serving customers. Therefore, it is important to confirm the completion of cybersecurity investments by establishing additional reporting requirements. Second, certain cybersecurity investments may require public utilities to undertake subsequent actions or make expenditures to maintain the status for which they receive incentives. Annual reports enable public utilities to demonstrate that they have undertaken such actions or expenditures.Finally, we propose that both the initial and annual informational filings provide a summary of the costs incurred to achieve the higher level of security, including supporting documentation that provides a narrative explanation of the nature of the expenses proposed for deferred cost recovery, and inclusion in rate base as a regulatory asset, including the specific accounts (under the Commissionâs Uniform System of Accounts) initially charged for the incurred expenses.
Program Changes Due to Agency Discretion:
⢠The Burden was reduced to reflect the removal of one-time burden associated with RM 17-11 and RM17-13 (removal of 925 responses and 76,683 hours). Those one-time filings have been completed.
⢠The NOPR in Docket No. RM21-3 would increase the number of responses by 20 and burden by 1,600 hours.
The net changes are -905 responses and -75,083 hours.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.