New collection (Request for a new OMB Control Number)
No
Regular
07/13/2022
Requested
Previously Approved
36 Months From Approved
686
0
6,860
0
0
0
On September 15, 2021 the North American Electric Reliability Corporation (NERC) filed a petition requesting approval of Reliability Standards CIP-004-7 (Cyber Security, Personnel and Training) and CIP-011-3 (Cyber Security, Information Protection). NERC described the proposed Reliability Standards as âAddressing Bulk Electric System Cyber System Information Access Management.â The petition was noticed on September 22, 2021, with interventions and comments due by October 6, 2021. The Commission did not receive any interventions or comments. On December 7, 2021, the Designated Letter Order in Docket No. RD21-6-000 approved the proposed Reliability Standards, and found that the modified Reliability Standards enhance security as follows: (1) Reliability Standard CIP-004-7 updates CIP-004 by focusing on controls at the file level (e.g., rights, permissions, privileges) of Bulk Electric System Cyber System Information (BCSI), and reduces the need for access to only a physical, designated storage location for BCSI. (2) Reliability Standard CIP-011-3 clarifies the requirements of protecting and handling BCSI with the goal of providing flexibility for Responsible Entities to use third-party data storage and analysis systems. Specifically, Reliability Standard CIP-011-3 requires Responsible Entities to implement specific controls related to BCSI during storage handling use, and disposal of information when implementing services provided by third parties.
This request is for a new control number that at present includes no burdens. All the estimated burdens in this request are thus program changes for the new control number. The total estimated burdens are 686 responses and 6,960 hours.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.