New
collection (Request for a new OMB Control Number)
No
Regular
07/13/2022
Requested
Previously Approved
36 Months From Approved
686
0
6,860
0
0
0
On September 15, 2021 the North
American Electric Reliability Corporation (NERC) filed a petition
requesting approval of Reliability Standards CIP-004-7 (Cyber
Security, Personnel and Training) and CIP-011-3 (Cyber Security,
Information Protection). NERC described the proposed Reliability
Standards as “Addressing Bulk Electric System Cyber System
Information Access Management.” The petition was noticed on
September 22, 2021, with interventions and comments due by October
6, 2021. The Commission did not receive any interventions or
comments. On December 7, 2021, the Designated Letter Order in
Docket No. RD21-6-000 approved the proposed Reliability Standards,
and found that the modified Reliability Standards enhance security
as follows: (1) Reliability Standard CIP-004-7 updates CIP-004 by
focusing on controls at the file level (e.g., rights, permissions,
privileges) of Bulk Electric System Cyber System Information
(BCSI), and reduces the need for access to only a physical,
designated storage location for BCSI. (2) Reliability Standard
CIP-011-3 clarifies the requirements of protecting and handling
BCSI with the goal of providing flexibility for Responsible
Entities to use third-party data storage and analysis systems.
Specifically, Reliability Standard CIP-011-3 requires Responsible
Entities to implement specific controls related to BCSI during
storage handling use, and disposal of information when implementing
services provided by third parties.
This request is for a new
control number that at present includes no burdens. All the
estimated burdens in this request are thus program changes for the
new control number. The total estimated burdens are 686 responses
and 6,960 hours.
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.