NERC News - September 2009

advertisement
Standards
Headlines
Executive Brief: Electromagnetic Pulse and
Geomagnetic Storm Events
Electromagnetic Pulse and Geomagnetic Storm Events
have the potential to significantly disrupt the normal
operation of the bulk power system.
To read more click here >>
NERC and Energy Central Team on CIP
Education
New webinar series to provide key insights on
compliance with CIP standards.
To read more click here >>
NERC Requests Candidates for Board of
Trustees
Cyber Security Standards Drafting Team
Continues to Make Progress
Version 3 revisions are underway, key concept paper
drives key discussions with industry.
To read more click here >>
Drafting Team Openings
Opportunities to participate in NERC’s Standards
Development Process.
To read more click here >>
Compliance
July 2009 Compliance Violation Statistics
To read more click here >>
The Nominating Committee for the Board of Trustees
seeks input.
To read more click here >>
Certification and Training
2008 GADS Data Now Available
NERC Certification Exam Development
The new data set features compiled data from 20042008.
To read more click here >>
NERC recently completed a job analysis survey of
Certified System Operators as a first step in the
development of a new set of exams.
To read more click here >>
Filings
Feature Article
NERC Filings/FERC Orders
Manitoba Hydro Place: A Green Experience
Documents filed with FERC and Canadian authorities
over the last month.
To read more click here >>
The new Manitoba Hydro head office sets new
standards for a healthy work environment and sets
new standards for energy conservation.
To read more click here >
Situational Awareness
New Secure Alerting System Gearing up for
Launch
With a formal launch scheduled in the upcoming
weeks, NERC’s secure alert system is getting ready for
prime time.
To read more click here >>
Reference:
NERC Glossary
This Edition of NERC News
At the suggestion of our stakeholders, NERC has changed the
scheme by which we date our newsletters. NERC News will now
be dated for the month it is issued, not the month of news
covered, as had been the case in the past. This month will
reflect a “skip” of the month of August in name only as we1 move
to the new convention.
HEADLINE NEWS
Executive Brief: Electromagnetic Pulse and
Geomagnetic Storm Events
NERC and Energy Central Team to Provide
Education on Critical Infrastructure Protection
and Cyber Security Standards
August 24, 2009
September 9, 2009
Electromagnetic Pulse (EMP) and severe Geomagnetic
Storm events cause bursts of magnetically-induced
currents that can disrupt or damage electrical
components. These events can be caused by a variety
of possible scenarios, with those of highest impact
involving the detonation of a nuclear weapon and
natural phenomena such as severe solar weather.
EMP and Geomagnetic Storm events fall into a
category of High Impact, Low Frequency (HILF)
events. The probability of these events’ occurrence is
uncertain relative to other threats, but they could
significantly impact the system were they to occur.
EMP and Geomagnetic Storm events have the potential
to physically damage electrical and electronic
equipment throughout North America’s critical
infrastructure, notably including Extra High Voltage
transformers and industrial control systems like
Supervisory Control and Data Acquisition (SCADA)
systems. The most significant electric reliability
concern is the potential for simultaneous impact to
large portions of the bulk power system, from which
restoration and recovery may be challenging and
prolonged. Similar to other critical infrastructures, the
bulk power system’s vulnerability to EMP and
Geomagnetic Storm events (in some geographic areas)
is high due to the nature of the system. Essentially all
of the system’s critical conductive elements are
exposed to this threat, as are many of its critical control
elements. As a result, deploying controls and
equipment that could prevent damage from EMP may
require considerable expertise, time, and financial
resources.
NERC and Energy Central are working together to
offer a series of six educational webcasts on
compliance with NERC’s Critical Infrastructure
Protection (CIP) standards. The sessions will follow
the schedule below:
Next Steps
NERC established a partnership with the U.S.
Department of Energy to review the impacts of HILF
events on the bulk power system. This effort will be
closely coordinated with Canadian governmental
authorities. Under the direction of the HILF event
Steering Committee, efforts to convene a November
2009 workshop are well underway. Tentative dates are
targeted at November 10-11th in Washington, DC.
View the full brief at:
http://www.nerc.com/fileUploads/File/CIP/EMPGeomagnetic-Exec-Brief(1).pdf ■■■
Reference:
NERC Glossary
9/23/09
10/6/09
10/21/09
11/11/09
12/2/09
12/16/09
Identifying Critical Assets
Program Governance Issues
Change Management Systems
Personnel Issues & Training
Physical & Electronic Access Controls
Testing Procedures & Recovery Plans
The sessions will be markedly different from those
currently available to industry:
NERC will guide content development for the
sessions, providing direction and vetting information to
ensure accurate information is presented. Presentations
will be made by experts from across the industry.
NERC will not present.
Low attendance costs ($147 per session, per access
point) represent a significant value to NERC
stakeholders, especially when compared to alternatives
currently on the market. Costs can be further reduced
by registering in advance for all six sessions.
As a media company, Energy Central presents
information from an objective viewpoint. No sponsors,
consultants, or vendors will be involved in the
development of the sessions.
Sessions will be recorded and will be made available
on Energy Central’s website for those who are unable
to attend the live webcast. The same low attendance
fee applies to these sessions.
View the press release at:
http://www.nerc.com/news_pr.php?npr=398
Register for the sessions today at:
http://www.energycentral.com/events/20734/
■■■
2
HEADLINE NEWS
NERC Requests Candidates for Board of
Trustees
August 27, 2009
The Nominating Committee for the Board of Trustees
is providing an opportunity for stakeholders to suggest
candidates to serve as independent members of
NERC’s Board of Trustees.
Independent trustees serve staggered three-year terms.
The independent trustees whose terms expire at the
2010 annual meeting are John Q. Anderson, Tom
Berry, and Sharon Nelson.
Ms. Nelson has informed the Chairman of the Board
and the Chairman of the Nominating Committee that
she will not stand for re-election. The committee has
determined that Messrs. Anderson and Berry are
willing and interested to serve an additional term. One
additional trustee will also be nominated to fill an
expected additional position, as discussed in
modifications to NERC’s bylaws approved by NERC’s
board on August 4-5.
The Nominating Committee for this year comprises the
following: Independent Trustees Ken Peterson
(Chairman), Paul Barber, Janice Case, James
Goodrich, Fred Gorbet, Bruce Scherr, and Jan Schori,
and Member Representatives Committee members
Steve Naumann (MRC Chairman), Ed Tymofichuk
(MRC Vice Chairman), John A. Anderson (ELCON),
Bill Gallagher (TAPS), and Jim Keller (Wisconsin
Electric Power Co.).
The Committee has retained SpencerStuart to assist in
the search and screening of candidates. Candidates
must be prepared to demonstrate they would be able to
meet the independence requirement and be free from
conflicts of interest. Please submit all suggestions for
candidates to Robert Shields of SpencerStuart,
RShields@SpencerStuart.com. All suggestions for
candidates must be received by September 18, 2009.
View the letter at:
http://www.nerc.com/docs/bot/botnc/Request-forCandidates-20090827.pdf ■■■
Reference:
NERC Glossary
2008 GADS Data Now Available
August 25, 2009
NERC has set a new record for gathering, correcting,
and publishing unit outage data for the Generating
Availability Data System (GADS). In 2008, GADS
collected data on 5,805 electric generating units: a
7.0% increase over the data collected in 2007. All
units are from traditional generating facilities;
renewable statistics are next on the agenda.
The 2004-2008 Generating Availability Report (GAR)
along with the Generating Unit Statistical Brochure
will be available for download from the NERC website
at: http://www.nerc.com/page.php?cid=4|43|47.
For more information about GADS, please contact
Mike Curley, Manager of GADS Services at
mike.curley@nerc.net.
STANDARDS NEWS
Cyber Security Standards Drafting Team
Continues to Make Progress
NERC’s Standards Drafting Team for Project 2008-06
– Cyber Security Order 706 continues to make
significant strides in the revisions to NERC’s critical
infrastructure protection standards.
Version 2
The initial phase revisions include the necessary
modifications to the cyber security standards (CIP-0021 through CIP-009-1) to comply with the near term
specific directives included in FERC Order 706 and
706A. In particular, the SDT addressed the directive in
FERC Order 706 that the “… ERO modify the CIP
Reliability Standards through its Reliability Standards
development process to remove references to
‘reasonable business judgement’ before the compliance
audits begin in 2009.” In addition, a number of other
directives included in FERC Order 706 that apply to
specific standards are also addressed in this initial
phase. The more contentious issues were deferred to
subsequent phases of Project 2008-06 – Cyber Security
Order 706.
The Standard Drafting Team (SDT) prepared and
posted the Version 2 of the CIP Reliability Standards
on Cyber Security for industry balloting in April 2009.
The Version 2 CIP Reliability Standards received a
weighted segment affirmative vote from the industry of
3
STANDARDS NEWS (continued)
88.32%, and the Version 2 Standards were reviewed
and approved by the NERC Board of Trustees on May
6, 2009. Accordingly, NERC submitted the Version 2
CIP Reliability Standards to the Federal Energy
Regulatory Commission (FERC) on May 22, 2009, and
respectfully requested the Commission to approve the
Version 2 CIP Reliability Standards and make them
effective in accordance with the effective date
provisions set forth in the proposed Reliability
Standards, and the accompanying implementation
plans. Also, upon the effective date of the Version 2
Reliability Standards, the correlating Version 1 Cyber
Security Reliability Standards will be retired.
Version 3
As an integral part of the preparations to draft Version
3 of the CIP Reliability Standards, a strategic
assessment regarding the applicability of the NIST risk
management framework, which was developed for use
by governmental agencies required to comply with the
Federal Information Security Management Act
(FISMA), was necessary. In Order 706, FERC
directed NERC to consider the applicable features of
the NIST framework in the development of the revised
critical infrastructure protection standards. In response
to this directive, the SDT studied and evaluated various
possible approaches to accomplish this objective.
As a corollary to the NIST framework discussion,
another important point that will be addressed in
Version 3 of the CIP Standards is the scope of the
requirements for the CIP-002 Reliability Standard on
Cyber Security, that is what electrical and cyber
equipment should be covered and therefore addressed
by the Reliability Standards on Cyber Security CIP003 through CIP-009.
A draft Working Concept Paper, Categorizing Cyber
Systems: An Approach Based on BES Reliability
Functions, was developed by the SDT to propose a
broader and more comprehensive approach for
providing appropriate and effective cyber security to
protect the systems which support a reliable bulk
power system. In this paper, the system is viewed
holistically in terms of reliability functions supporting
an Adequate Level of Reliability. Its supporting
subsystems and cyber systems are categorized based
on impact to the ability of the bulk system to support
that Adequate Level of Reliability. This process results
in a more uniform selection of appropriate security
Reference:
NERC Glossary
requirements and controls, which reduces risk to the
bulk system caused by a Cyber Security Incident. The
draft Working Concept Paper was posted for industry
comment and feedback on July 21, 2009 for a 45-day
comment period ending on September 4, 2009. A
Webinar presentation of the draft Working Concept
Paper was prepared and presented to the industry on
August 25, 2009. The 30-minute presentation was
followed by 60 minutes of questions and feedback
from the industry.
Approximately 600 industry
participants registered for the webinar and participated
in the discussions. Nearly 50 sets of comments have
been received from a broad cross-section of the
electricity industry, including asset owners, consultants
and vendors.
Current Plans and Schedule
The SDT will be reviewing and considering the
industry comments and feedback at its September 2009
meeting. The SDT has formed five subgroups to focus
on specific requirement areas and develop a standardsrequirements draft, which when combined with the
other subgroup inputs will serve as the basis for the
Version 3 CIP-002 standard. The SDT has also reached
out to the Operating Committee, Planning Committee
and other operating and planning groups within NERC
to solicit additional non-cyber focused assistance in the
development of the BPS impact portions of the
categorization and assessment components of the
Version 3 CIP-002 effort.
The schedule the SDT is working towards calls for
posting of the revised Version 3 CIP-002 Reliability
Standard on Cyber Security for industry comment by
the end of 2009. Subsequently, the SDT is targeting to
prepare the Implementation Plan and the New Asset
Implementation Plan, while strategizing on various
approaches to replacing the CIP-003 to CIP-009
reliability standards with the new Version 3 standards.
Overall, the SDT plans to post a complete set of CIP
reliability standards on cyber security for initial
balloting by the end of 2010. ■■■
NERC Trivia
What does SVC stand for?
See page 8 for the answer.
4
STANDARDS NEWS (continued)
Standards Drafting Team Vacancies
NERC currently has a number of standards drafting
teams seeking expertise. Any industry stakeholder
meeting the indicated qualifications for the vacant
appointments may submit a self nomination form to
sarcomm@nerc.com. Please contact Lauren Koller at
lauren.koller@nerc.net or with questions regarding the
drafting team vacancies.
For a list of vacancies please visit the following site:
http://www.nerc.com/filez/standards/drafting_team_va
cancies.htm ■■■
COMPLIANCE NEWS
July 2009 Compliance Violation Statistics
The July 2009 statistics continue to highlight progress
of NERC and the Regional Entities in processing
violations and mitigation plans.
View
the
complete
July
report
at:
http://www.nerc.com/files/2009_July_Statistics.pdf
SITUATIONAL AWARENESS
Secure NERC Alerting System Gearing Up for
Launch
The highly anticipated secure alerting system is
gearing up for launch in the coming weeks. The system
is designed to expedite and facilitate NERC’s alerts
process, whereby the organization is able to notify
users, owners, and operators of the bulk power system
of
vulnerabilities,
threats,
and/or
abnormal
events/conditions on the BPS. The system enables
rapid alert creation and dissemination to the electric
industry, and provides for quick and secure
acknowledgement and response from the industry via a
secure web browser portal.
The system supports up to 10,000 users.
Approximately 1,800 NERC registered entities
currently exist and each may assign approximately four
users. Additionally, there are approximately 5,000
electric industry participants that are not registered
with NERC.
All companies appointed access to the system are
assigned an administrator of user accounts for that
company and its associated registered entities. The
Administrator is responsible for maintaining accurate
contact information for all users within the company
and to assign Respondents and Functional Group
Members for their company/entities. Respondents can
acknowledge and respond to alerts. Functional Group
Members are able to receive alerts, but do not have
permission to acknowledge or respond to an alert.
Alerts can be distributed to a targeted cross-section of
the industry by registered function.
An alert
notification will be sent via email and optionally via
short message service (SMS) to inform users that an
alert has been posted to the system. Users are
informed to log in to the system in order to read the
posted alert and to acknowledge and respond as
necessary.
■■■
Reference:
NERC Glossary
In addition to distributing alerts to the electric industry,
the system provides a secure portal for subject matter
experts (SMEs) to collaborate, discuss and share
information on potential vulnerabilities, threats, and/or
abnormal events/conditions on the BPS. The secure
site contains discussion groups, document libraries,
chat, search, and action item assignment and tracking
5
SITUATIONAL AWARENESS
CERTIFICATION AND TRAINING
NERC Certification Exam Development
in a single web based location to engage industry
expertise in the alert process.
Performance and Data Security
Users have 24/7/365 access to the system, ES-ISAC
and SME sites and there is no browser specific
dependency. The system is designed with
authentication level access with Secure Socket Layer
(SSL) encryption. Sites are hosted on the vendor’s
production servers at a secure multiple layer access
controlled facility. The system and secure portals will
not directly interface with any external systems.
System Launch Schedule
Issue Training Materials & Help Desk
Thursday 9/24
Webinars: System Overview & Demo
The content for these sessions will be the same
Tuesday, 9/22 – 11:00 AM – 12:00 PM Eastern
Register >>
Tuesday, 9/29 – 1:00 – 2:00 PM Eastern
Register >>
System Available for Log In & Exploration
Monday, 9/28
Initial System Exercise – Test Alert to be
Issued
Tuesday, 10/6
Follow-up Webinar: Using the System
Thursday, 10/15
■■■
NERC recently completed a job analysis survey of
Certified System Operators as a first step in the
development of a new set of exams. Almost 18% of
the 7,800 invitations sent to operators resulted in a
response, which is a typical response based on past
NERC operator surveys and well above the 3-5%
response from most other certified professions.
Developing and maintaining a professionally sound
and legally defensible examination program begins
with how each exam is developed. The job analysis
survey results will become an exam content outline or
exam blueprint for each of the four exams based on the
tasks that system operators rated highest in the survey.
The ‘exam blueprint’ then provides the framework
needed to accurately link individual exam questions to
the tasks being performed by certified system
operators.
The job analysis also dictates the cognitive level of the
exam questions and how many of each type of question
will be on each exam. Cognitive levels on NERC
exams categorize a question as recall, application, or
analysis. Recent surveys have shown an increase in
the cognitive levels with the tasks performed. The
result is that today’s exams contain fewer recall
questions and more application and analysis items than
earlier exams.
Finally, the percentage of questions required to be
answered correctly is determined by a scientific
method, which helps produce a cut score. NERC
contracts with a psychometric consultant (Applied
Measurement Professionals) to assist in the job
analyses, development of the exam content outlines,
and development and maintenance of each of our four
exams.
The processes used throughout the NERC System
Operator Certification Program continue to meet the
National Commission for Certifying Agencies (NCCA)
accreditation standards. This commitment to quality
gives us confidence that our certification program will
always meet or exceed professional testing standards
and legal guidelines used throughout many profession
certification programs.
NERC expects that a new set of exams based on this
survey will be ready for use by the summer of 2010.
with a full launch of the system expected by October
15. ■■■
Reference:
NERC Glossary
6
FEATURE ARTICLE
Manitoba Hydro Place: A Green Experience
FILINGS (Month of August, 2009)
NERC Filings to FERC
(click on the filing to view)
Recently, the NERC Board of Trustees Meeting was
held in Winnipeg, Canada home of Manitoba Hydro
and their award winning new Headquarters Building.
Manitoba Hydro extended to Trustees and Members an
exclusive tour of the one-of-a-kind building and to say
it was impressive does not do justice.
The new Manitoba Hydro head office sets new
standards for a healthy work environment. The
building uses 60 percent less energy than standard
office buildings and is the most energy efficient office
tower in North America. Fresh air flows through the
building 24 hours a day, 7 days a week, year-round.
Solar energy is maximized and energy efficient
windows maximize natural sunlight.
The Manitoba Hydro head office tower in Winnipeg
sets new standards for energy conservation. There are
280 geothermal loops deep beneath the building's
foundations that provide 100 per cent of the air
conditioning and 60 per cent of the heating
requirements. Additional heating comes from eight
small high efficiency boilers. This building is the most
energy efficient office tower in North America and
among the most energy efficient in the world.
August 6, 2009
Petition for Approval of Amendments to the NERC
Bylaws Amendments to Article III, sections 1 and 2 of
NERC’s Bylaws. Docket No. RR09-8-000
August 6, 2009
Request for Approval of Supplemental 2009 Budget and
Funding for MRO Docket No. RR08-6-000
August 10, 2009
Informational Filing Regarding the Assignment of
Violation Risk Factors and Violation Security Levels
Docket Nos. RM08-11-000, RR08-4-000, RR07-9-000
and RR07-10-000
August 12, 2009
Petition for Approval of Errata Changes to Three
Reliability Standards IRO-006-4.1, MOD-021-0.1, PER001-0.1. Docket No. RD09-9-000
August 14, 2009
Compliance Filing in Response to Order No. 716 and
Petiton for Approval of NUC Reliability Standard
NUC-001-2 — Nuclear Plant Interface Coordination.
Docket No. RM08-3-000
August 17, 2009
Comments of NERC in Response to Notice of Proposed
Rulemaking Transmission Relay Loadability. Docket No.
RM08-13-000
August 24, 2009
Request for Acceptance of 2010 Business Plans and
Budgets of NERC and for Approval of Proposed
Assessments to Fund Budgets Docket Nos. RR08-6-004,
RR07-14-004, RR09-9-000
August 28, 2009
Compliance Filing in Response to Order No. 723
Modifications to the WECC VRFs for the BAL-004WECC-01 Regional Reliability Standard as specified by
FERC. Docket No. RM08-12-000
■■■
August 31, 2009
Second Quarter 2009 Compliance Filing in Response to
Orde No. 693 Docket No. RM06-16-000
Reference:
NERC Glossary
7
FILINGS (Month of August, 2009)
FERC Orders to Note
(click on the filing to view)
CAREERS AT NERC
Engineer of Reliability Performance and
Events Analysis
Princeton, NJ
August 7, 2009
Notice on Notices of Penalty
Docket Nos. NP09-28-000, NP09-29-000, NP09-30-000,
NP09-31-000, NP09-32-000
August 20, 2009
Order Approving VRFs for CIP Reliability Standards
CIP-003-1, R4.1; CIP-005-1, R1.5; CIP-007-1, R5.1; and
CIP-007-1, R5.3.3/ The Commission has approved the
modification of all of these VRFs from “Lower” to
“Medium.” Docket No. RM06-22-009
August 26, 2009
Letter Order on Three Notices of Penalty
FERC issues a letter order stating that it will not further
review Notices of Penalty for the MidAmerican Energy
Company, Ashburnham Municipal Light Plant, and
Pacific Gas and Electric Company. Docket Nos. NP0933-000, NP09-34-000, NP09-35-000
July 27, 2009
Letter Order Regarding Reporting Requirements of
WECC Deviations
FERC issues an order regarding continuation and
reporting requirements of the WECC deviations from the
NERC pro forma hearing procedures. Docket Nos.
RR06-1-022, RR07-7-008
Details:
http://www.nerc.com/files/EngineerofReliabilityPerfor
manceandEventsAnalysis.pdf
Standards Development Coordinator
Princeton, NJ
Details:
http://www.nerc.com/files/Engineer%20of%20organiz
ation%20registration.pdf
Engineer of Organization Registration,
Certification, and Compliance Monitoring
Princeton, NJ
Details:
http://www.nerc.com/files/EngineerOfOrganizationRe
gistration.pdf
Answer to NERC Trivia
What does SVC stand for?
Static Var Compensator
Subscribe to NERC News:
Send an e-mail message addressed to: subscribenercnews@listserv.nerc.com. Leave the subject
and body of the message blank.
Unsubscribe from NERC News:
Send an e-mail message addressed to:
unsubscribe-nercnews@listserv.nerc.com.
Leave the subject and body of the message blank.
Reference:
NERC Glossary
8
Download