On December 20, 2024, NERC submitted proposed Reliability Standard CIP-003-11 for Commission approval. NERC explains that, in response to the SolarWinds Orion platform attack, and at the direction of the NERC Board of Trustees, NERC staff assembled a team of cybersecurity experts and compliance experts called the Low Impact Criteria Review Team (LICRT) that developed a report that discussed the potential threats and risks posed by a coordinated attack on low impact BES Cyber Systems. NERCâs modifications made in Reliability Standard CIP-003-11 reflect many of the recommendations from the LICRT.
NERC states that the Reliability Standard would enhance reliability by mitigating the risk posed by a coordinated attack utilizing distributed low impact BES Cyber Systems. NERC explains that, to address the threat of a coordinated attack on dispersed low impact BES Cyber Systems, the proposed Standard adds controls to: (1) authenticate remote users, (2) protect the authentication information in transit, and (3) detect malicious communications to or between assets containing low impact BES Cyber Systems with external routable connectivity.
Program Change due to Agency discretion includes one-time burden from RM24-8 NOPR already comment and filed on and RM25-8 NOPR 1,673 Responses and 257,642 Annual Burden hrs of new one-time burden
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.