Yesterday the Federal Energy Regulatory Commission (FERC) published a notice of proposed rulemaking (NOPR in the FERC jargon) on their website for “Internal Network Security Monitoring for High and Medium Impact Bulk Electric System Cyber Systems”. In this NOPR, FERC proposes to direct the North American Energy Reliability Corporation (NERC) to “to develop and submit for Commission approval new or modified Reliability Standards that require internal network security monitoring within a trusted Critical Infrastructure Protection networked environment for high and medium impact Bulk Electric System Cyber Systems.”
NOTE: Thanks to Patrick C Miller for pointing out this NOPR on TWITTER®.
Background
FERC is a Federal Agency responsible for regulating broad swaths of the energy economy in the United States including the Bulk Electric (distribution) System (BES). It has empowered (under congressional authority to be sure) a private entity (NERC) to act as the oversight agency (Electrical Reliability Organization- ERO) over the BES. NERC works with the public and private sector entities running the various elements of the BES to establish the Critical Infrastructure Protection (CIP) rules for the operation of the BES. FERC ratifies those CIP and can direct (as in this action) that CIP be developed or modified. Both FERC and NERC can undertake enforcement activities under those CIP. That is the broad swath of the regulatory regime and I have overlooked, ignored and misunderstood many of the idiosyncrasies and complexities of the situation that are only fully comprehended by Mr. Miller (grin).
Actually, understanding the FERC – NERC relationship may become more broadly important as there is a move afoot to requires the establishment of a separate Reliability Organization to deal with energy pipeline operations, see HR 6084. But that is another story for another day.
Cybersecurity Monitoring
NERC has adopted (with significant industry input) a wide range of cybersecurity related CIP. According to this NOPR, however, the security monitoring aspects of those rules effectively stop at the Electronic Security Perimeter. That means that if an adversary has found a way over, under or even through the ESP, that there is currently no requirement to maintain the monitoring systems that would be expected to catch the adversary before they wreaked havoc on the system. Thus, NERC will be expected to establish regulations requiring the use of internal network security monitoring (INSM).
The NOPR provides a discussion about why INSM provides a valuable cybersecurity view into the operations of these bulk power systems. In fact, FERC is asking for comment on what would happen if they expanded the INSM requirements to low impact BES cyber systems, systems that are not now required to comply with the CIP perimeter monitoring requirements.
Seeking Public Comments
FERC is soliciting public comments on this NOPR. Comments may be submitted via the eFile option on www.FERC.gov for registered individuals (Docket # RM22-3-000). Others may send comments via snail mail to:
Federal Energy Regulatory Commission
Office of the Secretary
888 First Street NE
Washington, DC 20426
The deadline for submission of comments will be 60-days after the NOPR is published in the Federal Register, probably sometime next week.
Commentary
This proposed expansion of cybersecurity regulations should surprise no one. It does not appear to me to be the least bit unreasonable. I would hope that most organizations under the NERC CIP would have at least some level of view within their networks that would form part of the proposed INSM, so that this proposed requirement should not be too much of a new regulatory burden.
This rulemaking is targeted at the physical operations networks supporting the BES, but other organizations utilizing similar networks to conduct operations in the physical realm should take a hard look at the proposals in the NOPR as similar technology is necessary to protect operations technology in other industries as well.