Information Collection Request

FERC-725B2, (CLO in Docket RD21-2) Mandatory Reliability Standards for Critical Infrastructure Protection [CIP] Reliability Standards

ICR 202102-1902-002 · OMB 1902-0304 · Received in OIRA

Forms and Documents
DocumentTypeStatusAvailability
RD20-2_725B2_Supporting Statement.docx Supporting Statement A Uploaded 2021-05-06 Repair queued
Pub.L 109-59 1211, Title XII, Subtitle A Energy Policy Act of 2005.pdf Supplementary Document Uploaded 2021-05-05 Repair queued
RM17-13-000 (Issued).docx Supplementary Document Uploaded 2021-05-05 Repair queued
725B2_RD21-2_30-day IC Notice Published.pdf Supplementary Document Uploaded 2021-05-04 Repair queued
RM15-4-000 CLO.docx Supplementary Document Uploaded 2021-05-04 Repair queued
Final Rule (Issued) RM17-13-000.docx Supplementary Document Uploaded 2021-05-04 Repair queued
725B2_RD21-2_30-day IC Notice Issued.docx Supplementary Document Uploaded 2021-05-03 Repair queued
RD21-2_725B2_60day (Published).pdf Supplementary Document Uploaded 2021-05-03 Repair queued
20201214-5246_Petition - Supply Chain Risk Management_final.PDF Supplementary Document Uploaded 2021-02-22 Repair queued
ecfr2-22-2021 Part40.docx Supplementary Document Uploaded 2021-02-22 Repair queued
20210222-3001_725B2_RD21-2_60 day IC notice_20162021_ss.DOCX Supplementary Document Uploaded 2021-02-22 Repair queued
16 USC 824(o).pdf Supplementary Document Uploaded 2018-01-30 Missing upstream
ICR Details
1902-0304 202102-1902-002
Received in OIRA 201801-1902-009
FERC FERC-725B2
FERC-725B2, (CLO in Docket RD21-2) Mandatory Reliability Standards for Critical Infrastructure Protection [CIP] Reliability Standards
New collection (Request for a new OMB Control Number)   No
Regular 05/07/2021
  Requested Previously Approved
36 Months From Approved
1,029 0
28,926 0
0 0

NOTE: This request related to Docket No. RD21-2 would normally be submitted under FERC-725B (OMB Control No. 1902-0248). Another unrelated item is pending at OMB under FERC-725B, and only one item per OMB Control No. can be submitted for review at a time. Therefore the requirements of RD21-2 are being submitted to OMB under FERC-725B2 (temporary interim information collection number). Additionally, while ROCIS may indicate that this is a new collection, the existing standards are included in FERC-725B and the changes to the standards are being included in FERC-725B2. RD21-2 expands the types of assets to which the reporting and recordkeeping requirements apply, but does not change the reporting or recordkeeping requirements. The burden for the baseline reporting and recordkeeping requirements of the 3 Reliability Standards continues to be covered by FERC-725B. Pursuant to section 215 of the Federal Power Act (FPA), the Commission proposes to approve Reliability Standards CIP-013-2 (Cyber Security – Supply Chain Risk Management), CIP-005-7 (Cyber Security – Electronic Security Perimeter(s)), and CIP-010-4 (Cyber Security – Configuration Change Management and Vulnerability Assessments) . The North American Electric Reliability Corporation (NERC), the Commission-certified Electric Reliability Organization (ERO), submitted proposed Reliability Standards CIP-013-1, CIP-005-6, and CIP-010-3 in response to directives in Order No. 829. The proposed reliability standards are intended to augment the currently effective CIP Reliability Standards in order to mitigate cybersecurity risks associated with the supply chain for BES Cyber System. The proposed Reliability Standards CIP-013-1 (Cyber Security – Supply Chain Risk Management), CIP-005-6 (Cyber Security --- Electronic Security Perimeters(s)), and CIP-010-3 (Cyber Security --- Configuration Change Management and Vulnerability Assessments) are to be used by NERC registered entities to mitigate cybersecurity risks associated with the supply chain for BES Cyber System The NERC Compliance Registry, as of December 2017, identifies approximately 1,250 unique U.S. entities that are subject to mandatory compliance with Reliability Standards. Of this total, we estimate that 288 entities will face an increased paperwork burden under proposed Reliability Standards CIP-013-1, CIP-005-6, and CIP-010-3.

US Code: 18 USC 824o Name of Law: Federal Power Act
   PL: Pub.L. 109 - 58 1211, Title XII, Subtitle A Name of Law: Energy Policy Act of 2005
  
None

Not associated with rulemaking

  86 FR 11760 02/26/2021
86 FR 23718 05/04/2021
No

  Total Request Previously Approved Change Due to New Statute Change Due to Agency Discretion Change Due to Adjustment in Estimate Change Due to Potential Violation of the PRA
Annual Number of Responses 1,029 0 0 1,029 0 0
Annual Time Burden (Hours) 28,926 0 0 28,926 0 0
Annual Cost Burden (Dollars) 0 0 0 0 0 0
Yes
Miscellaneous Actions
No
The proposed standards (Reliability Standards CIP-013-2 (Cyber Security – Supply Chain Risk Management), CIP-005-7 (Cyber Security – Electronic Security Perimeter(s)), and CIP-010-4 (Cyber Security – Configuration Change Management and Vulnerability Assessments) are not changing the reporting or recordkeeping requirements, however the proposed standards are expanding the types of assets to which the reporting and recordkeeping requirements apply. The previous ICs related to the NOPR in RM17-13 (480 responses and 67,776 burden hours) were not approved in FERC-725B2 but were later submitted and approved under FERC-725B related to the Final Rule in RM17-3. (Those 480 responses and 67,776 hours are being removed as agency adjustments through the removal of the 2 previous (and now unnecessary) ICs; that is administrative due to ROCIS and unrelated to Docket No. RD21-2.)

$6,475
No
    No
    No
No
No
No
No
Simon Slobodnik 202 502-6707 [email protected]

  No

On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
 
 
 
 
 
 
 
    (i) Why the information is being collected;
    (ii) Use of information;
    (iii) Burden estimate;
    (iv) Nature of response (voluntary, required for a benefit, or mandatory);
    (v) Nature and extent of confidentiality; and
    (vi) Need to display currently valid OMB control number;
 
 
 
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.
05/07/2021