FERC-725B2, (CLO in Docket RD21-2) Mandatory Reliability Standards for Critical Infrastructure Protection [CIP] Reliability Standards

ICR 202102-1902-002

OMB: 1902-0304

Federal Form Document

Forms and Documents
Document
Name
Status
Supporting Statement A
2021-05-06
Supplementary Document
2021-05-05
Supplementary Document
2021-05-05
Supplementary Document
2021-05-04
Supplementary Document
2021-05-04
Supplementary Document
2021-05-04
Supplementary Document
2021-05-03
Supplementary Document
2021-05-03
Supplementary Document
2021-02-22
Supplementary Document
2021-02-22
Supplementary Document
2021-02-22
Supplementary Document
2018-01-30
ICR Details
1902-0304 202102-1902-002
Received in OIRA 201801-1902-009
FERC FERC-725B2
FERC-725B2, (CLO in Docket RD21-2) Mandatory Reliability Standards for Critical Infrastructure Protection [CIP] Reliability Standards
New collection (Request for a new OMB Control Number)   No
Regular 05/07/2021
  Requested Previously Approved
36 Months From Approved
1,029 0
28,926 0
0 0

NOTE: This request related to Docket No. RD21-2 would normally be submitted under FERC-725B (OMB Control No. 1902-0248). Another unrelated item is pending at OMB under FERC-725B, and only one item per OMB Control No. can be submitted for review at a time. Therefore the requirements of RD21-2 are being submitted to OMB under FERC-725B2 (temporary interim information collection number). Additionally, while ROCIS may indicate that this is a new collection, the existing standards are included in FERC-725B and the changes to the standards are being included in FERC-725B2. RD21-2 expands the types of assets to which the reporting and recordkeeping requirements apply, but does not change the reporting or recordkeeping requirements. The burden for the baseline reporting and recordkeeping requirements of the 3 Reliability Standards continues to be covered by FERC-725B. Pursuant to section 215 of the Federal Power Act (FPA), the Commission proposes to approve Reliability Standards CIP-013-2 (Cyber Security – Supply Chain Risk Management), CIP-005-7 (Cyber Security – Electronic Security Perimeter(s)), and CIP-010-4 (Cyber Security – Configuration Change Management and Vulnerability Assessments) . The North American Electric Reliability Corporation (NERC), the Commission-certified Electric Reliability Organization (ERO), submitted proposed Reliability Standards CIP-013-1, CIP-005-6, and CIP-010-3 in response to directives in Order No. 829. The proposed reliability standards are intended to augment the currently effective CIP Reliability Standards in order to mitigate cybersecurity risks associated with the supply chain for BES Cyber System. The proposed Reliability Standards CIP-013-1 (Cyber Security – Supply Chain Risk Management), CIP-005-6 (Cyber Security --- Electronic Security Perimeters(s)), and CIP-010-3 (Cyber Security --- Configuration Change Management and Vulnerability Assessments) are to be used by NERC registered entities to mitigate cybersecurity risks associated with the supply chain for BES Cyber System The NERC Compliance Registry, as of December 2017, identifies approximately 1,250 unique U.S. entities that are subject to mandatory compliance with Reliability Standards. Of this total, we estimate that 288 entities will face an increased paperwork burden under proposed Reliability Standards CIP-013-1, CIP-005-6, and CIP-010-3.

US Code: 18 USC 824o Name of Law: Federal Power Act
   PL: Pub.L. 109 - 58 1211, Title XII, Subtitle A Name of Law: Energy Policy Act of 2005
  
None

Not associated with rulemaking

  86 FR 11760 02/26/2021
86 FR 23718 05/04/2021
No

  Total Request Previously Approved Change Due to New Statute Change Due to Agency Discretion Change Due to Adjustment in Estimate Change Due to Potential Violation of the PRA
Annual Number of Responses 1,029 0 0 1,029 0 0
Annual Time Burden (Hours) 28,926 0 0 28,926 0 0
Annual Cost Burden (Dollars) 0 0 0 0 0 0
Yes
Miscellaneous Actions
No
The proposed standards (Reliability Standards CIP-013-2 (Cyber Security – Supply Chain Risk Management), CIP-005-7 (Cyber Security – Electronic Security Perimeter(s)), and CIP-010-4 (Cyber Security – Configuration Change Management and Vulnerability Assessments) are not changing the reporting or recordkeeping requirements, however the proposed standards are expanding the types of assets to which the reporting and recordkeeping requirements apply. The previous ICs related to the NOPR in RM17-13 (480 responses and 67,776 burden hours) were not approved in FERC-725B2 but were later submitted and approved under FERC-725B related to the Final Rule in RM17-3. (Those 480 responses and 67,776 hours are being removed as agency adjustments through the removal of the 2 previous (and now unnecessary) ICs; that is administrative due to ROCIS and unrelated to Docket No. RD21-2.)

$6,475
No
    No
    No
No
No
No
No
Simon Slobodnik 202 502-6707 [email protected]

  No

On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
 
 
 
 
 
 
 
    (i) Why the information is being collected;
    (ii) Use of information;
    (iii) Burden estimate;
    (iv) Nature of response (voluntary, required for a benefit, or mandatory);
    (v) Nature and extent of confidentiality; and
    (vi) Need to display currently valid OMB control number;
 
 
 
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.
05/07/2021


© 2024 OMB.report | Privacy Policy