187 FERC ¶ 61,086
Before Commissioners: Willie L. Phillips, Chairman;
Allison Clements and Mark C. Christie.
North American Electric Reliability Corporation |
Docket No. |
RD24-3-000 |
(Issued May 23, 2024)
On January 31, 2024, the North American Electric Reliability Corporation (NERC), the Commission-certified Electric Reliability Organization (ERO), filed a petition with the Commission seeking approval of proposed Reliability Standard CIP‑012-2 (Cyber Security – Communications between Control Centers). NERC also requested approval of the associated implementation plan, violation risk factors and violation severity levels, and the retirement of the currently-effective Reliability Standard CIP-012-1.
Pursuant to section 215(d)(2) of the Federal Power Act (FPA), we approve proposed Reliability Standard CIP-012-2, its associated implementation plan, violation risk factors and violation severity levels, and the retirement of the currently-effective Reliability Standard CIP-012-1 immediately prior to the effective date of Reliability Standard CIP-012-2.1 For the reasons discussed below, we determine that proposed Reliability Standard CIP-012-2 improves upon and expands the protections required by Reliability Standard CIP-012-1 and addresses the Commission directive issued in Order No. 866.2
Section 215 of the FPA provides that the Commission may certify an ERO, the purpose of which is to develop mandatory and enforceable Reliability Standards, subject to Commission review and approval.3 Pursuant to section 215 of the FPA, the Commission established a process to select and certify an ERO,4 and subsequently certified NERC.5
In Order No. 866, the Commission directed NERC to modify Critical Infrastructure Protection (CIP) Reliability Standards to implement protections regarding the availability of communication links and sensitive bulk electric system (BES) data communicated between BES Control Centers.6 The Commission explained that creating an obligation to protect availability, while affording flexibility in terms of what data is protected and how, was “distinct from relying on currently-effective Reliability Standards whose effect may be to support availability.”7
NERC states that proposed Reliability Standard CIP-012-2 improves upon and expands the protections required by Reliability Standard CIP-012-1 by requiring responsible entities to mitigate the risk posed by loss of availability of communication links and Real-time Assessment9 and Real-time10 monitoring data transmitted between Control Centers. Proposed Reliability Standard CIP-012-2 adds two new provisions to Requirement R1 that address availability by requiring (1) protections for the availability of data in transit and (2) protections to initiate recovery of lost (i.e., unavailable) communication links.11
NERC also requests approval of the associated implementation plan, the associated violation risk factors and violation severity levels, and retirement of Reliability Standard CIP-012-1 immediately prior to the effective date of CIP-012-2. The 24-month implementation period is proposed to afford responsible entities sufficient time to implement the new controls and coordinate with other responsible entities that own or operate Control Centers as required in proposed Reliability Standard CIP-012-2.
Notice of NERC’s filing was published in the Federal Register, 89 Fed. Reg. 8419 (Feb. 7, 2024), with interventions, comments and protests due on or before March 1, 2024. None were filed.
Pursuant to section 215(d)(2) of the FPA, we approve Reliability Standard CIP‑012-2 as just, reasonable, not unduly discriminatory or preferential, and in the public interest. We conclude that Reliability Standard CIP-012-2 addresses the Commission’s directive issued in Order No. 866.
Specifically, we determine that Reliability Standard CIP-012-2 improves upon and expands the protections required by Reliability Standard CIP-012-1 by requiring responsible entities to mitigate the risk posed by loss of availability of communication links and Real-time Assessment and Real-time monitoring data transmitted between Control Centers. We also approve the associated implementation plan. We agree that the proposed implementation plan reflects consideration that responsible entities need sufficient time to implement the new controls and coordinate with other responsible entities that own or operate Control Centers as required in Reliability Standard CIP‑012‑2. In addition, we approve the associated violation risk factors and violation severity level assignments for Reliability Standard CIP-012-2. Finally, we approve the retirement of the currently effective Reliability Standard CIP-012-1 immediately prior to the effective date of Reliability Standard CIP-012-2.12
The Commission orders:
The Commission hereby approves: (1) Reliability Standard CIP-012-2, (2) the associated implementation plan, the associated violation risk factors and violation severity levels, and (3) the retirement of the currently effective Commission-approved Reliability Standard CIP-012-1 immediately prior to the effective date of Reliability Standard CIP-012-2, as discussed in the body of this order.
By the Commission.
Debbie-Anne A. Reese,
Acting Secretary.
