FERC-725B2, (CLO in Docket
RD21-2) Mandatory Reliability Standards for Critical Infrastructure
Protection [CIP] Reliability Standards
New
collection (Request for a new OMB Control Number)
No
Regular
05/07/2021
Requested
Previously Approved
36 Months From Approved
1,029
0
28,926
0
0
0
NOTE: This request related to Docket
No. RD21-2 would normally be submitted under FERC-725B (OMB Control
No. 1902-0248). Another unrelated item is pending at OMB under
FERC-725B, and only one item per OMB Control No. can be submitted
for review at a time. Therefore the requirements of RD21-2 are
being submitted to OMB under FERC-725B2 (temporary interim
information collection number). Additionally, while ROCIS may
indicate that this is a new collection, the existing standards are
included in FERC-725B and the changes to the standards are being
included in FERC-725B2. RD21-2 expands the types of assets to which
the reporting and recordkeeping requirements apply, but does not
change the reporting or recordkeeping requirements. The burden for
the baseline reporting and recordkeeping requirements of the 3
Reliability Standards continues to be covered by FERC-725B.
Pursuant to section 215 of the Federal Power Act (FPA), the
Commission proposes to approve Reliability Standards CIP-013-2
(Cyber Security – Supply Chain Risk Management), CIP-005-7 (Cyber
Security – Electronic Security Perimeter(s)), and CIP-010-4 (Cyber
Security – Configuration Change Management and Vulnerability
Assessments) . The North American Electric Reliability Corporation
(NERC), the Commission-certified Electric Reliability Organization
(ERO), submitted proposed Reliability Standards CIP-013-1,
CIP-005-6, and CIP-010-3 in response to directives in Order No.
829. The proposed reliability standards are intended to augment the
currently effective CIP Reliability Standards in order to mitigate
cybersecurity risks associated with the supply chain for BES Cyber
System. The proposed Reliability Standards CIP-013-1 (Cyber
Security – Supply Chain Risk Management), CIP-005-6 (Cyber Security
--- Electronic Security Perimeters(s)), and CIP-010-3 (Cyber
Security --- Configuration Change Management and Vulnerability
Assessments) are to be used by NERC registered entities to mitigate
cybersecurity risks associated with the supply chain for BES Cyber
System The NERC Compliance Registry, as of December 2017,
identifies approximately 1,250 unique U.S. entities that are
subject to mandatory compliance with Reliability Standards. Of this
total, we estimate that 288 entities will face an increased
paperwork burden under proposed Reliability Standards CIP-013-1,
CIP-005-6, and CIP-010-3.
The proposed standards
(Reliability Standards CIP-013-2 (Cyber Security – Supply Chain
Risk Management), CIP-005-7 (Cyber Security – Electronic Security
Perimeter(s)), and CIP-010-4 (Cyber Security – Configuration Change
Management and Vulnerability Assessments) are not changing the
reporting or recordkeeping requirements, however the proposed
standards are expanding the types of assets to which the reporting
and recordkeeping requirements apply. The previous ICs related to
the NOPR in RM17-13 (480 responses and 67,776 burden hours) were
not approved in FERC-725B2 but were later submitted and approved
under FERC-725B related to the Final Rule in RM17-3. (Those 480
responses and 67,776 hours are being removed as agency adjustments
through the removal of the 2 previous (and now unnecessary) ICs;
that is administrative due to ROCIS and unrelated to Docket No.
RD21-2.)
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.