Cybersecurity reliability at the transmission and distribution interface is where regulated cybersecurity meets unregulated cybersecurity. CIP applies on one side. The other side is utility-managed but not federally audited. The seam is where adversaries hunt and where most utilities have shared risk surfaces that compliance frameworks weren't designed to eliminate. Cyber risk doesn't respect the BES/non-BES line. Adversaries don't read the NERC scope document. The seam between regulated and unregulated is where the most unmonitored risk lives. Knowing what crosses the seam matters more than knowing what's on each side. A breach that originates outside scope but causes a reliability event inside scope is a finding inside scope. Smart grid integration brought T&D operations closer than the historical scope language anticipated. The standards are catching up. Two utilities can share a risk surface and have no shared regulatory obligation to manage it. Operationally that gap has to be closed even when the standards don't require it. Defense-in-depth at the interface is a program decision, not a regulatory one. The standard tells you the floor; the threat environment tells you the ceiling.
Contents
- Foreword
- Defining Cybersecurity Reliability at the Transmission and Distribution Interface
- BES and Non-BES System Boundaries and Classification Concepts
- Operational and Cyber Interdependencies Across the Interface
- Data Exchange, Visibility, and Control Pathways
- Shared Risk Without Shared Obligation
- Cybersecurity Threat Propagation Across System Boundaries
- Critical Infrastructure Protection Context at the Interface
- Functional Responsibility and Accountability at BES and Non-BES Boundaries
- Oversight, Compliance Monitoring, and Enforcement Considerations
- Disturbance Experience and Reliability Lessons Involving Interfaces
- Common Misconceptions About Transmission and Distribution Cybersecurity Risk
- Evolving Interfaces, Emerging Technologies, and Future Considerations
- Glossary
- About the Author
- About Energy Compliance, Inc.
Read offline
The complete reference is on this page. The PDF is for circulation inside your organization.
Download the PDFForeword
Foreword
This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.
I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.
The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.
That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.
These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.
These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.
Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.
If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?
Rob Smith, Founder, Energy Compliance, Inc.
EC-WP-205 Cybersecurity Reliability for T&D Interfaces
Chapter 1
Defining Cybersecurity Reliability at the Transmission and Distribution Interface
CyPRoc 2017 discusses the impact of the NERC Reliability Standards, including the Critical Infrastructure Protection (CIP) Reliability Standards, on addressing cybersecurity risk within the approved scope of applicable Reliability Standards. The guide covers topics such as the impact of functional responsibility, system classification and applicability determinations on Grid Entities’ oversight responsibilities at
interconnection points and clarifies some of the misconceptions that have arisen from these arrangements as a result of the transfer of responsibility from transmission to distribution entities.
The Commission examines oversight and governance through the shared risk rather than the shared obligation framework in this ebook. The ebook addresses compliance monitoring, enforcement and risk based oversight approaches for managing new classes of cyber risks that originate in non-BES environments but have the potential to impact the reliability of the bulk electric system.
This report provides a comprehensive background of cybersecurity reliability at transmission and distribution (T&D) system interfaces. It does not attempt to provide procedures for implementing the findings, recommend appropriate security controls, or outline procedures to comply with recommendations made in the report. Rather, it serves to provide a definitive treatise describing boundaries, shared risk and oversight that presently exist within current reliability and cybersecurity standards and guidelines that underpin the North American bulk electric system reliability framework.
The topic of cybersecurity reliability at the transmission and distribution interface is a unique and increasingly important topic in the North American bulk electric system. The interface is a point where technology, organizational boundaries, and regulatory rules meet at a different place than they historically have. As the transmission and distribution systems move toward greater use of communication technologies and automation to better integrate their operations, a clear understanding of cybersecurity reliability at the interface must consider the formal definitions of the systems involved and the reliability risk as it is practically realized.
The reliability of the cybersecurity of smart grid systems refers to the ability of cyber and physical systems that are interconnected to provide reliable power delivery in the presence of cyber threats, vulnerabilities and disruptions. It is not the same as saying that the system is compliant with cybersecurity requirements for the protection of particular assets. Rather, it refers to the impact of the cyber environment on system performance, operational decisions, and reliability effects on a wide area of the grid.
The transmission and distribution interface is a system interface characterized by both physical and functional characteristics. A physical characterization might include substations, protection, and control associated with points of interconnection between transmission and distribution systems. A functional characterization includes data and control transactions and system functions which define the interrelationship between bulk system functions performed by utilities operating in the BES and non-BES environments.
The relationship between the Bulk Electric System (BES) and non-BES systems is defined by the Commission’s BES definitions and applicable thresholds in the NERC Reliability Standards. Cybersecurity reliability considerations however are not limited to BES defined boundaries. Non-BES cyber incidents
could impact the BES through shared infrastructure, trusted communications or operational dependencies.
One of the difficulties in defining the concept of Cybersecurity Reliability at this boundary is to differentiate between the responsibility, and the risk. Although risks are shared, compliance with regulatory obligations is not necessarily so; and irrespective of this, organizations may still retain responsibility for defined aspects of a system. The Reliability framework currently defines two main elements – one describing the scope to which regulations and standards apply; and another describing where risks may occur or be transferred.
In prior years the transmission and distribution systems were considered to be built based on different assumptions for operations and regulation. The distribution systems have been designed as an autonomous system close to the customers with only minimal points of connection to the grid while the transmission systems required coordinated operation across the grid with a centralized monitoring point. In the age of smart grid the differences in between these systems start to fade and all relevant data requires a new evaluation in relation to potential cyber security threats particularly at common points of the grid such as Sub-Station Interfaces.
A broad number of factors influence the reliability of Cybersecurity at the WCG (Working Circuit Gas) interface including data exchange arrangements, remote access protocols, protection system relaying, and operational visibility and their impact on the speed and accuracy with which operational staff can make timely and informed operating decisions and recover their system from any disruptions that may arise following a cyber attack.
Key to this is that cybersecurity reliability does not necessarily imply a combined transmission and distribution security domain. Our work does not mean that all the boundaries between domains go away – rather that understanding the coupling that exists across these boundaries so that the impact of that coupling can be understood and adequately considered by regulators and other stakeholders.
The discussion of cybersecurity reliability at the transmission and distribution interface is the starting point for analyzing boundaries, shared risks and who is responsible for what. It does not translate to an endless discussion on system behavior and reliability impact and cannot be equated to mere administrative compliance or become a principle of design.
End-of-Chapter Summary
Reliability at the transmission and distribution interface is an indicator of cybersecurity reliability in the face of cyber conditions impacting the Bulk Electric System (BES) and the non-BES across formal BES/ non-BES boundaries. Compliance with regulatory definitions that establish scope is one factor, but the risk of reliability problems can extend to other parts of the grid through shared resources and operating
relationships. Understanding the difference between compliance and risk is an important step in considering reliability of cybersecurity at the system interfaces.
FROM THE FIELD
Cyber risk doesn't respect the BES/non-BES line. Adversaries don't read the NERC scope document. The reliability framework has to think about what happens when an attack crosses the boundary the regulation drew.
The transmission and distribution interface is the seam where regulated cybersecurity meets unregulated cybersecurity. Most utilities operate both sides; few coordinate them as a single risk surface.
A finding on a CIP-regulated asset can trace back to an unregulated distribution system that wasn't audited. Scope doesn't equal risk, and the program has to manage both.
Chapter 2
BES and Non-BES System Boundaries and Classification Concepts
The Bulk Electric System (BES) versus non-BES distinction is a core of the North American reliability program. It determines which activities and facilities are subject to the Reliability Standards, and it focuses where cybersecurity and operational Reliability Standards are enforced. Understanding the criteria for making this distinction is a first step in analyzing cybersecurity reliability issues at the transmission and distribution interface. The definition of the BES is based on voltage criteria, functional criteria, and the inclusion and exclusion principles. The BES definitions are used to determine which facilities and systems are necessary for providing reliable transmission of bulk electricity over an interconnected transmission grid and for maintaining reliability of the transmission grid on a regional or interconnection-wide basis. Facilities that do not meet these definitions are generally considered to be non-BES. Non-BES means those portions of the distribution facilities, equipment, systems and infrastructure that are not regulated by the FERC through the development and enforcement of Reliability Standards. NonBES includes distribution facilities, systems and infrastructure for control and other functions as well as all other distribution-level systems and equipment that are used for local service delivery and distribution operations. Although an element of the Transmission and/or Distribution Grid may be critical to local operations, FERC policy is to assume that such components are not material to normal reliability of the Bulk Power System. The classification of a cyber system also follows boundary logic. In the context of Critical Infrastructure Protection (CIP), the applicability of regulations is dependent on whether the cyber assets are involved in supporting BES functions and whether they meet certain impact criteria. In general, cyber systems that reside in non-BES facilities are not subject to CIP regulations (regardless of whether they have interface connections with BES systems). These classification constructs are considered to be binary. A facility or cyber system is either within scope or outside scope for a particular requirement. This facilitates enforceability and consistency of the standard, while at the same time does not imply that
outside scope systems are not reliable systems. It is a policy determination of where mandatory requirements are to be applied. The transmission and distribution interface is where the IEC 62451 classification boundaries are the most likely to encounter shared infrastructure. Substations supporting both transmission and distribution assets, control systems that cover all voltage levels supported at a substation, as well as shared data communication networks that carry BES and nonBES signals are all
scenarios where an understanding of the IEC 62451 classification criteria will be needed to determine the appropriate classification for IEC 62421 evaluations at this interface. NERC processes address boundary determination and classification issues. An Inclusion and Exclusion Request, Applicability Determination, and Registration Determination addresses inclusion and exclusion requests, applicability determinations, and registration determinations to determine whether a particular facility or system is considered part of the BES or CIP. These processes are for determining classification of a system, facility, or other asset and do not imply that additional requirements need to be developed. In IEC 60300-1, an item has to be classified prior to risk evaluation and handling. This classification is different from the risk associated with a product or item in terms of cyber/information security or reliability. The fact that an item is not included in the scope of BES or CIP does not mean that the item does not represent some level of risk. It simply means that the BES/CIP regulations are not applicable for the item. The risk and risk handling activities would then carry on at the level of operational procedures, voluntary recommendations or management decisions at the level of the organization. The distinction between BES and non-BES boundaries is not always clear-cut and is sometimes misconstrued. Misconceptions can lead to incorrect assumptions regarding authority and control. Equating all interface systems with an equal set of requirements can cloud accountability and create unrealistic expectations. Conversely, ignoring interface risks because the system is out of scope can greatly diminish the reliability impact of the interface. This subtopic focuses on the BES and non-BES classification of concepts that underpin the consideration of cybersecurity reliability at system interfaces. Boundaries define the parameters of oversight and can inform considerations of shared risk while avoiding conflation of regulatory boundaries.
End-of-Chapter Summary
The BES and non-BES classifications are used to define the scope of mandatory reliability and cybersecurity standards by clearly and systematically defining the applicable boundaries. Although these classifications determine the level of mandatory obligation for reliability and cybersecurity standards, they do not eliminate the inherent risk to cybersecurity and reliability that will continue to exist for systems that interface with BES systems. It is important to understand the criteria that define and apply these boundaries in order to fully evaluate the nature and extent of shared risk associated with interconnections between the transmission and distribution grids.
FROM THE FIELD
The BES definition draws the line between regulated and unregulated. The line was drawn for reliability purposes, not cybersecurity ones.
A cyber path that crosses from non-BES into BES is a CIP-relevant path, even if its origin is outside the framework. Programs that treat the boundary as a firewall miss the connections the boundary actually has.
Chapter 3
Operational and Cyber Interdependencies Across the Interface
Operational and cyber interdependencies between transmission and distribution (T&D) systems have increased as the grid has become increasingly smart and datadriven. While interdependencies don’t change the physical boundaries of the high voltage transmission or low voltage distribution systems, they do potentially affect the detection, response and management of a cyber incident and operational condition that may affect reliability at the transmission and distribution interface. The chapter emphasizes that operational interdependence arises from the need to manage synchronization, voltage support, and situational awareness across multiple systems in real time. It also emphasizes the potential for mutual impact and influence among distribution systems – i.e., how load dynamics, DER output and protection activities influence the performance of a transmission system and conversely, how disturbances on a transmission system might impact distribution system reliability and restoration. Cyber interdependence is an additional layer of operational relationship for those systems identified as part of the BES. Common control systems, communication links and data exchanges can all serve to interconnect the operational relationship of BES systems. Information such as breaker states, voltage readings and power flow orders can be transmitted across the BES interface to support operational planning and management decisions. Since the integrity and availability of this information may affect reliability performance, consideration should also be given to systems outside of the BES. Remote access and centralized monitoring can also add to interdependencies. Many systems today rely on real-time operational data from other systems; e.g., transmission operators who use distribution-level data to make real-time determination of system conditions, or distribution operators who use transmission-level data to make feeder operation and restoration decisions. All of these bidirectional dependencies can provide additional attack paths for the potential cyber-vulnerabilities. The protection and control systems are highly interdependent. While protection functions have traditionally been designed to operate independently, the coordination of protection on
transmission and distribution systems is required to prevent unnecessary power outages and to prevent cascading effects. In addition, if the protection functions are enabled using cyber systems for protection settings, monitoring and coordination, there will be increased exposure to potential cyber effects on system behavior. Shared communication resources can increase interdependencies. Fiber optic networks, leased circuits and data centers may be used for both transmission and distribution functions
and an outage of these shared resources can impact visibility and control across multiple layers of a system. While concentration of dependency is an important reliability factor, the classification of the systems impacted is less important. Organizational interdependencies also come into play. For example, T&D utilities may share support functions, such as human resources, real estate, finance, security, environmental or health and safety, as well as cybersecurity resources, or vendor-managed applications. Although the reliability system is designed to specify who is responsible for specific functions, it does not preclude operational interdependencies or account for their implications. The impact of shared functional resources, applications or services on the speed, efficacy and accuracy with which problems are uncovered, reported or corrected can be significant. Key terms in the Reliability Framework Explained Interdependence does not mean the loss of the High Voltage transmission line boundary. Each utility is still responsible for its own High Voltage transmission line. Rather interdependence describes how relationships between High Voltage transmission line systems behave. The Reliability Framework sets out to codify these behaviors. Oversight has more to do with whether or not registered utilities can actually demonstrate on-going performance of the behaviours that comprise their interdependence. Cybersecurity can be a key area of risk in complex, interconnected systems where vulnerabilities may arise due to lack of consideration of potential interdependencies, or where the full nature and extent of interdependencies are not fully understood, and therefore possibly underestimated. It may be that there are unconsidered dependencies, unrecorded information flows, or shared systems infrastructure that are not accounted for in design or everyday operations, and which can therefore be overlooked during analysis or planning, and that become apparent only in the event of a cyberattack or system failure. Understanding operational and cyber interdependencies between the Bulk Electric System (BES) and non-BES systems across the transmission and distribution interface is critical for understanding shared risk. The Reliability Advisory Working Group (RAWG) Technical Team is looking into reliability impacts of interdependencies in a manner that does not expand regulatory authority or compliance.
End-of-Chapter Summary
Coordination and interaction between transmission and distribution systems are increasingly realized through operational synchronization, information sharing, common infrastructure, and organizational collaboration. Understanding these interdependencies is key to recognizing how potential cyber vulnerabilities that affect one part of the Bulk Electric System (BES) or non-BES side of the BES could impact the reliability of other parts. Interdependence provides a basis for understanding shared risk, while at the same time preserving necessary distinctions regarding responsibility and regulatory jurisdiction.
Chapter 4
Data Exchange, Visibility, and Control Pathways
The integration of transmission and distribution systems is critical to modern grid operations. Knowledge sharing across the transmission and distribution systems via the transmission and distribution interface enables situational awareness, coordination, and operational decision-making for both the transmission and distribution domains. From a Cybersecurity reliability perspective, interdependencies at these points can introduce shared risk, even if regulatory requirements differ. Much of the information required by transmission system operators for managing real time grid operation comes from BES facilities. However, there can be occasions when data from distribution grids is also material to managing the transmission system. In particular, those distribution systems that have non-routine patterns of peak load demand or high penetration of DR resources. Hence, the accuracy and reliability of distribution grid data is material to reliability performance. Distribution utilities use transmission system information to manage and analyze feeder performance, voltage levels and restoration priorities. Coordinated communication during disturbances enhances the utility’s response to the disturbance and facilitates more effective restoration. Loss of cyber communications may continue even after the core operational controls have been restored. Control actions across the interface are usually limited and strictly defined. Distribution systems usually have no direct control over transmission lines and transmission has no direct control over distribution equipment. However, indirect control influence can exist through automated schemes, protection coordination or supervisory control signals which may affect the control actions in the other system. Cybersecurity reliability engineering is concerned with dealing with the reliability aspects of the unknown or un-documented communication and control paths between systems that are potentially enabled by electronic means, such as through data exchange or remote control. The cause may be that the communication and control paths are not well understood or documented, which could include hidden or un-documented interactions and legacy communications that are no longer required or documented. In any case, these may not violate any prescribed rule or regulation but they can cause significant increases in system risk to unusual operating scenarios. Visibility
is another factor. In addition to what data is being received and how it is being received, centers that use an interface-based control model need to know what is included in the data (its source, accuracy and time to receipt). An interface with a large number of variables and integrated, summarised or processed information can obscure relationships between the different elements. A cyber attack in the control
systems in the upstream equipment can affect visibility in unpredictable ways. This Reliability Framework does not address data exchange structures or visibility tools. It focuses on general expectations for situational awareness, communication and coordination, given the specific roles carried out by entities at the time an incident occurs. How entities choose to implement data exchange in their design and operation is a matter of discretion. The focus in operational oversight is generally on whether the communication paths for the exchange of data and for commanding and controlling processes ensure that the processes can be operated safely and reliably, not on how the individual paths are implemented. When carrying out audits, reviewing incidents and analyzing disturbances, operational oversight bodies focus on the consequences of the individual processes and do not cover the underlying process structures. Examining data exchange, visibility and control paths at the transmission and distribution interface (T&D interface) highlights the need to look at Cybersecurity Reliability through a system wide perspective, and also confirms that even a limited or non-direct connection to the grid can have a significant impact on reliability performance when a cyber threat materializes. A systems-based approach may underpin risk sharing evaluations, possibly as part of a framework to support informed discussion, however this does not have to be a regulatory-based approach and does not mean design of interfaces will change. Rather than having an additional compliance focus on dependency, the recognition of these as the basis of high reliability is a preferable and simpler approach.
End-of-Chapter Summary
Data exchange and limited control pathways across the transmission and distribution interface exist to enable coordination and situational awareness, and the resulting shared cybersecurity reliability risk is a consideration. An understanding of these pathways can help utility leaders be more aware of the shared risk, while also maintaining
regulatory boundaries to protect core reliability functions. Vulnerabilities in these systems can impact how the grid as a whole responds, even if the core control functions remain operational.
FROM THE FIELD
Every data exchange across the T&D interface is a potential control pathway. Programs that secure the data without securing the pathway have done half the work.
The control center sees what the data feeds give it. If a data feed is compromised, the control picture is compromised, and the operator is acting on adversary-shaped information.
Read-only data paths are not low-risk by virtue of being read-only. Read-only data shapes operational decisions, and shaped decisions can be exploited.
Chapter 6
Cybersecurity Threat Propagation Across System Boundaries
Cybersecurity threats to the electric system are not bounded by Commission regulations or FERC-defined functional areas. While Mandatory Reliability Standards govern the scope of regulated activity under the NERC Reliability Standards Framework, the ability of a cyber-attack to affect one part of the grid and have unintended reliability effects elsewhere means the reach of those threats must be understood if we are to assess the role of cybersecurity reliability at the transmission and distribution interface. The means by which a compromise of one system can impact other systems through networks, or through other trust, or operational dependency relationships. Propagation pathways can exist between the transmission and distribution systems, whether or not they are physically or logically segregated or are subject to different management or regulatory regimes. Shared infrastructure is one such possible means of propagation. Data communication links that support BES and non-BES systems may carry operational, monitoring, or supervisory control information. Cross-organizational transmission on these systems can affect visibility and control in more than one system layer, thereby increasing the reliability impact. Censuses of trusted data exchange relationships can also reveal new attack vectors. For example, a transmission operator might make use of data supplied from a distribution system for situational awareness, and a distribution utility might utilize information from a transmission system to coordinate operational procedures, facilitate restoration efforts, etc. In such cases if an attack is made that compromised the integrity or reliability of the data, the operators might rely on a normal operating procedure of reacting and making operational decisions with the data available to them (possibly unreliable or insufficient due to the attack’s success), even though they may not notice any problems in their operational control system communications. The ability of an incident to spread within a network via remote access technologies is a second criterion. If a means exists whereby an incident can traverse BES and non-BES environments for the purposes of operations support, maintenance, or monitoring, it could potentially affect critical infrastructure. Even if the controls in place to mitigate such accesses are compliant to existing standards, they can still impact the reliability risk due to the nature of cross boundary access relationships that they enable. Propagation may also occur through shared service models and third party dependencies. For example, multiple components on the interface may leverage a common data center, identity management services, or a Security Information and Event Management (SIEM) system. If any of these are compromised in a cyber-attack, it may propagate across the interface, potentially affecting individual components that otherwise seem properly segmented. The propagation
potential of a cyber event is not always the same as its actual effect. The fact that a means exists for a potential cyber event to propagate does not mean that the resulting cyber event will actually propagate and cause reliability harm. Many countermeasures, protections and operating procedures may be in place to limit the impact of any such event. However, the potential for propagation of such events is a factor in assessing the risk posed by such events and in planning for such events. The Threat Propagation activity is used to look back over what occurred and analyze the impacts or outcomes of the cyber activity rather than expanding the scope of compliance. Activities such as Disturbance analysis, Event reviews, and Reliability analyses focus on the operational impacts on connected or dependent systems beyond those directly addressed in controls and procedures. NERC technical reports and guidance documents have identified the need to understand interdependencies and paths of propagation as part of Reliability Risk Awareness. The reports and guides do not include requirements, but serve a purpose of raising awareness in the industry of where cyber vulnerabilities can affect the operations at the Interfaces. The fact that the spread of cyber threats across system boundaries must be taken into account when defining the scope of responsibility, areas of awareness and the necessary measures of resistance within an accountability domain is a further argument for the non-bounded nature of the reliability of IT security within the compliance area. It also underlines that the cyber threat reliability of IT systems cannot be confined to the compliance scope, that shared risks cannot be brought into consideration without jeopardizing the regulatory framework, and that the limits of liability must be clearly defined.
End-of-Chapter Summary
Cyber threats can propagate across transmission and distribution boundaries through shared resources, trusted information sharing, remote access relationships and third party dependencies. While the regulatory boundaries are clearly defined, propagation potential affects reliability risk and oversight addresses this through risk analysis of outcomes rather than expansion of regulations.
FROM THE FIELD
Threats propagate by the network's logic, not the regulator's. If the network connects BES to non-BES, a threat at one end can reach the other.
The framework regulates effects, not causes. A breach that originates outside scope but causes a reliability event inside scope is a finding inside scope.
Defense-in-depth at the interface is a program decision, not a regulatory one. The standard tells you the floor; the threat environment tells you the ceiling.
Chapter 7
Critical Infrastructure Protection Context at the Interface
Cybersecurity oversight at the transmission and distribution interface is primarily driven by Critical Infrastructure Protection (CIP) Reliability Standards. These standards impose mandatory cybersecurity controls on certain ICT that supports reliable grid performance (defined as part of the Bulk Electric System) and excludes systems outside their scope criteria. Knowing what CIP applies to at the transmission/distribution interface is critical to understanding Cybersecurity Reliability without imposing arbitrary rules on T&D systems beyond their defined scope. Identifies which CIP cyber systems are subject to the CIP cyber security standards based on whether they provide service to BES functions and meet the impact-based thresholds in CIP-R v5.1: – Identifies processes and criteria for determining whether a cyber system has a role in BES operations. – Identifies processes and criteria for determining whether a cyber system has connections to BES operations that are likely to have a negative impact on reliable BES operation. – Identifies processes and criteria for determining that a cyber system in a non BES facility is not subject to part 929 even if the cyber system exchanges information with BES systems or with other cyber systems that have roles, connections, or negative impacts in BES operations. Cyber systems in non-BES facilities are generally not subject to part 929, even where the cyber system communicates with BES or other cyber systems identified in part 929. This apparent difference between the transmission and distribution interfaces to BES becomes less unclear when looking at the function of a distribution system. Data from a distribution system may be provided to a transmission operator to assist in system planning, protection coordination may be provided from a distribution system to the transmission system and transmission operator actions and decisions may be influenced by data and other information provided from a distribution system; however, the resulting determination is that the system is not part of the Bulk Electric System and associated CIP definition and criteria based on criticality, connectivity, and impact. The CIP Vol. I Reliability Standard for the Bulk Electric System (BES) Cybersecurity
provides a functional description of a cybersecurity framework (CIP framework) that is technology neutral. The CIP framework does not prohibit communication between BES and non-BES cyber systems, nor does it impose identical cybersecurity measures in corresponding environments. Rather, the BES Cybersecurity Reliability Standard establishes basic, mandatory cybersecurity measures that are applicable to in-scope BES cyber systems, while allowing the C&E to consider vulnerability and manage
additional cyber risk through the discretionary use of the nonmandatory cyber risk management requirements contained in Vol. II. This section covers the Cybersecurity and Infrastructure Protection (CIP) cyber risk controls to which reliable operation of the BES Cyber Systems is addressed, specifically identifying assets, managing access, implementing monitoring, preparing for incidents, and recovering. These controls mitigate the chances of compromise to BES Cyber Systems that could affect reliable operation. They do not attempt to eliminate threats from other networks or systems outside the scope of BES Cyber Systems. CIP reliability will be compromised at the interface and the interaction between BES Cyber Systems and non-BES systems will play a role. Understanding trusted connections, data feeds and paths will be important to consider in relation to regulatory requirements. However, the fact that these interactions occur will not expand the CIP scope to non-BES systems. The interface CIP oversight is to determine whether the registered fiduciary or other entity has appropriately identified the systems it has determined to be in scope and is following the appropriate riskbased controls. Interface CIP oversight does not focus on the overall security of systems identified by the entity as being out of scope, except to the extent that interactions with in-scope systems may impact the entity’s compliance with the CIP requirements. NERC guidance and technical publications dealing with cybersecurity risk have long acknowledged the complexity of risk at interfaces while reaffirming the principles of clearly defined boundaries of applicability to recognize interdependencies and potential indirect effects while avoiding any binding or CIP regulatory effect. Recognizing the CIP context at the transmission and distribution interface reinforces the underlying principles of the reliability framework that 1) cybersecurity compliance is scoped and enforceable, while cybersecurity reliability awareness is broader and risk informed; and 2) that the framework requires defined boundaries and informed oversight, rather than universal control. Cyber risk governance from a risk-reduction perspective considers that Mandatory Controls need to be enforced only where their effect is most certain and predictable
and therefore contributes most to overall risk reduction; and that not all types of cyber risk can be addressed through compliance measures. [FIGURE: CIP applicability boundaries at the transmission and distribution cybersecurity interface]
End-of-Chapter Summary
Standards for Critical Infrastructure Protection establish scoped, impact-based cybersecurity requirements for Information Technology (IT) and Industrial Control Systems (ICS) that support BES functions. Criteria defined in the standards as opposed to connectivity at the transmission and distribution interface is used to determine what systems are considered cyber trustworthy for the purposes of CIP Reliability. The Standards preserve well-defined boundaries between various sets of regulation and policy, while fostering mutual awareness of common cyber risks – without increasing regulatory requirements.
Chapter 8
Functional Responsibility and Accountability at BES and Non-BES Boundaries
In the NERC Reliability Standards Framework, functional responsibility is what organizes the requirements of the Reliability Standards. It still applies to cybersecurity reliability at the transmission and distribution interface. It is based on the functions that are performed by entities, as opposed to the ownership of the assets; the design of the systems; or their level of interconnection. This principle applies because the technical boundaries defining clear responsibility have become increasingly complex. While numerous stakeholders may be connected to T&D equipment to exchange operational data and coordinate restoration activities, each party is accountable only for the reliability contributions of the functions they have registered for the portion of the system under their control. This holds true for cybersecurity as well. Parties are held accountable for the cybersecurity of systems inscope to the functions they have registered and the data they collect from other systems. They are not responsible for managing or controlling all the systems that may be connected or influenced by the systems they have responsibility for. Bulk system functions performed by transmission entities responsible for such functions must be carried out in a manner that ensures proper operation of control systems, associated communications, and data networks. The entities must understand the potential impact of any dependence on non-BES systems or shared services to carrying out those functions, including any dependence that may not be regulated under this part. Distribution entities are not typically registered for bulk system functions and are not subject to the same cybersecurity requirements as other entities. Any cybersecurity obligations for distribution entities are governed by their own policies, state regulations or industry standards on a voluntary basis rather than by the NERC Reliability Standards. The lack of federal reliability oversight does not diminish the role of distribution entities. Functional accountability shall also apply to cases where a third party or shared service provider is involved. In the case of use of external vendors, data centers or managed services, it does not transfer the responsibility for reliability. The Registered Entity that performs the reliability
function shall be held responsible in the same manner as before, and for compliance with the same requirements. At the interface, accountability questions often arise when a single cyber-attack affects multiple systems. In these scenarios, accountability focuses on whether each organization within the
scope acted appropriately and the focus remains on each individual’s defined scope of management rather than attempting to attribute accountability across organizational boundaries. Responsibility must be clearly allocated for effective coordination during an incident. Coordination of response actions can then take place based on the formally assigned responsibilities, with mutual information provided via established communication channels. Uncertainty in this regard may cause considerable delays and can have significant reliability consequences. Understanding functional responsibility at the boundaries of BES and non-BES systems is key to disciplined automation. In order to have reliable Cybersecurity, no one needs to be in complete control, as long as all systems and components function in their assigned roles and work together as a common operating environment. This perspective is in accordance with the reliability concept within the general framework of reliability. This perspective utilizes defined roles, well defined boundaries of authority and accountability, and well defined co-ordination in the management of cross-cutting functions arising from dynamic interactions among systems, equipment and components, while ensuring that regulatory boundaries are not eroded.
End-of-Chapter Summary
The functional responsibility will define the cybersecurity accountability at the transmission and distribution interface. The accountability for cybersecurity of systems that support the functions for which an entity has registered and which are within scope will remain unchanged in a shared risk scenario across boundaries. This functionbased approach maintains the clarity, facilitates the coordination of operation, and does not increase the regulatory burden.
FROM THE FIELD
NERC standards are reliability standards with cybersecurity components. They aren't cybersecurity standards. The distinction matters when an entity tries to use compliance as a security baseline. The standards establish a floor. The threat environment is above the floor. A program built only to the floor is a program operating below the threat baseline.
The regulatory framework is necessary. It is not sufficient. Mature programs operate above the floor and document the gap.
Chapter 9
Oversight, Compliance Monitoring, and Enforcement Considerations
The transmission and distribution interface Cybersecurity Reliability Standard oversight is conducted within the compliance monitoring and enforcement framework established for approved Reliability Standards under a risk-based approach with due process considerations. Understanding the applicability of oversight at interfaces will depend on defining compliance scope versus reliability impact. The purpose of compliance monitoring is to ensure that entities with registered critical infrastructure have the required level of cybersecurity and operational resilience to meet regulatory requirements. For transmission and distribution (T&D) assets, this monitoring is focused on the BES Cyber Systems, communications and control activities that occur at the T&D interface. The regulation does not mandate a full evaluation of non-in-scope systems, including those non-BES systems that may be considered to be within the operational environment. Audits, spot checks and event-driven audits may include an examination of interface-related conditions where this is relevant to applicable requirements. For example, an oversight audit may determine whether a transmission entity understands and manages dependencies on distribution-generated data or a shared communication infrastructure where the dependency is associated with meeting situational awareness or cybersecurity requirements. Risk-based oversight is a key factor in interface evaluation activities. Regulatory bodies are focusing more on reliability risk assessment when determining what aspects of grid operations require closer monitoring. This approach may result in compliance activities for higher complexity and dependence interfaces without altering the application thresholds. Interconnection Enforcement determinations are based on requirements language and criteria/evidence in NERC Reliability Standards. Enforcement determinations for noncompliance are made only with respect to BES functions for which the Registered Entity has jurisdiction and is within scope. Factors external to the BES including issues in nonBES systems will not by themselves be the basis for an enforcement determination unless there is a corresponding requirement that was violated. Mitigation expectations similarly remain scoped. Our expectation for Registered Entities is that they mitigate identified noncompliance to the extent it is within their control. Oversight does not require entities to perform mitigation on non-BES systems, but instead to determine, to the extent feasible, whether steps to mitigate reliability risk have been taken within their operational
systems. Many event-based reviews center on interfaces because these provide unique insights into the interactions among complex systems. Possible disruption or operational issues may be scrutinized by oversight entities in order to assess how dependencies at interfaces have played a role in mitigating the occurrence of potentially severe consequences. Without expanding regulatory enforcement, these review activities are part of an educational effort that can teach lessons that can be adopted as best practices. Transparency and consistency are two important oversight issues at interfaces. NERC and the Regional Entities have addressed consistent application of Reliability Standards across regions, while recognizing the wide variation in interface configurations. Oversight must not be technology biased and functional responsibility must be clearly defined. This bulletin is part 2 of a 2-part series focusing on oversight and enforcement of electric utility activities. Our previous bulletin discussed the oversight and enforcement of generation activities; this bulletin addresses transmission and distribution activities. As we previously noted, compliance monitoring can serve as a governance mechanism for certain elements of electric utility operations. Understanding the oversight and enforcement considerations at the transmission and distribution interface, however, provides context for the scope of compliance monitoring and highlights its limited scope as a cybersecurity reliability risk management tool. Compliance oversight is critical to ensuring that utilities comply with required regulations. However, ensuring that electric grid cybersecurity reliability is maintained in general requires more than just awareness of compliance. It also requires coordination and utilities’ operational discipline, which are not necessarily defined by compliance regulations.
End-of-Chapter Summary
The Commission directed staff to oversee the cybersecurity reliability at the transmission and distribution interface within existing monitoring, enforcement, and compliance frameworks. Staff will conduct compliance analyses of utilities’ compliance with in-scope regulations based on risk and with appropriate due process. Although shared
risk may be a factor in deciding where to focus surveillance activities, enforcement coverage will continue to be based on applicable regulatory requirements and functional responsibilities.
FROM THE FIELD
Audit findings at the T&D interface tend to be subtle. The auditor looks for the connections the program didn't document, not the controls the program did install.
A finding that traces to an unregulated system feeding a regulated system is still a finding against the regulated entity. The auditor follows the data, not the org chart.
Programs that map data flows across the interface, in writing, cleared regulator scrutiny faster than programs that mapped only their CIP-scoped assets.
Chapter 10
Disturbance Experience and Reliability Lessons Involving Interfaces
Disturbance experience is valuable in understanding the impact of potential Cybersecurity and Operations conditions at the transmission/distribution interfaces on the Bulk Electric System reliability. Numerous Event reports that have been reviewed by NERC and industry stakeholders confirm that the reliability outcomes of interacting systems are heavily dependent on more than just adherence to individual Reliability Standards, but also to how the overall grid system, and its stakeholders, function during disturbed conditions. Cyber/Communications disturbances at interfaces have demonstrated the important role of indirect relationships and the fact that reliability impact can result from interface conditions rather than asset failures. In general, loss of visibility, degradation of data quality, or degradation of coordination at the transmission/distribution interface can complicate system response, even though the primary BES control systems for the affected resources have not been directly compromised. Cyber events affecting non-BES systems have on occasion impacted BES through the use of trusted data sharing or the use of shared infrastructure. The analysis of several events has demonstrated where disturbances on the distribution system have compromised visibility for grid operations or otherwise otherwise impacted the coordination of grid operating activities during times of unusual operating conditions, illustrating the concept of shared risk without shared obligation. As has already been mentioned, protection system performance has also played a role in interface-related incidents. Misoperation of or lack of coordination between protection relays located at the transmission distribution interface, often due to combined cyber and non-cyber causes, has been involved in a number of such incidents. The impact of cyber components such as protection relay setting management systems, monitoring systems and communication channels on protection system operation under fault conditions has been established. Recurring in the disturbance experience at interfaces is the impact of human factors. Several events have identified issues with clear communication of information, understanding of roles and processes, and movement of information
between transmission and distribution. Cyber disruptions to communication and data systems can make these issues worse, potentially impacting the timing and quality of the response to a disturbance. The Reliability Lessons Learned – Event Analysis activity identifies lessons learned about reliability from regulatory reports of disturbances and power failures to emphasize that reliability lessons are not technology or system design specific. Many components of the NERC Disturbance Report focus on the
functional performance, coordination of different components of the power system, and overall system response rather than who or what was classified as BES or non-BES. This helps to reinforce the concepts of interactions and dependencies rather than focusing solely on compliance related criteria. While disturbance experience has not resulted in the determination that the FERC has broader regulatory authority to address interface risk, it has instead influenced the development of guidance, outreach efforts and industry awareness regarding interdependencies and shared risk in a non-regulatory fashion and therefore outside of the Commission’s regulatory boundaries. An incident was noted which caused some disruption to power supplies. The Grid Code disturbance review highlighted the importance of openness and communication within the network. Operators are encouraged to share knowledge of interface disturbances which can aid the understanding of cyber and operational risk interactions. No new operating requirements have been introduced as a result of this activity. Modeling disturbance experience at the transmission and distribution interfaces helps advance the system view of cyber security reliability. Understanding the impact of disturbances to the interfaces will help us understand how reliability is a result of the interplay among various elements in the power system rather than individual technical standards compliance.
End-of-Chapter Summary
The experience of a disturbance highlights the potentially significant indirect impact of cybersecurity and operational issues at the transmission-distribution interfaces (T/D) on the reliability of the bulk electric system. Again, as with many lessons learned related to events, the experience focuses on the functional aspects of the power system and the shared risk, and not necessarily on regulatory compliance. Recognizing and addressing these lessons as a reliability matter will help to advance reliability awareness and initiatives, without the need for regulatory action.
FROM THE FIELD
"It's distribution, so CIP doesn't apply" is correct on scope and wrong on risk. Scope and risk are not the same thing.
"We segmented the network" is necessary but doesn't end the conversation. Segmentation is a control, not a guarantee. The audit asks how the segmentation was validated.
"The transmission and distribution sides have different security teams" is common, and is exactly the program structure adversaries plan around.
Chapter 11
Common Misconceptions About Transmission and Distribution Cybersecurity Risk
Cybersecurity reliability at the transmission and distribution (T&D) interface is a frequently misunderstood concept due to a complex interplay of technological, regulatory and operational factors. Understanding and addressing the misconceptions regarding the T&D interface helps to harmonize perception, risk, responsibility and the overall reliability model. Misconception #1: Cybersecurity risk at the interface is a compliance issue Managing cybersecurity risk at the interface between BES and non BES systems does not necessarily mean that someone is out of compliance. The fact that there is cyber risk associated with non-BES systems does not reflect a failure of the Reliability Standards Framework to provide adequate protection. The Framework provides the maximum extent of mandatory requirements within defined scopes, and it recognizes that not all risks can be addressed through compliance with regulation. Common misconceptions and their corresponding clarifications: Non-BES systems that are located in BES systems are automatically covered under CIP. It is not necessarily about being “connected to the BES,” but about the defined impact criteria and function of the systems and what they control. Making all non-BES systems that connect to a BES system in-scope can cloud the clear definitions and intent of the regulations. Another misconception is that certain entities need to protect a distribution system because it may be shared and the operational impacts of protection may be shared. However, with function-based responsibility, the distribution system owner and operator remains responsible for the systems they manage. This means that a transmission owner and operator only needs to manage their own systems and their dependencies to function properly – they do not have to manage the cybersecurity activities of others. One related misunderstanding is that achieving reliability through cybersecurity means removing all dependencies between objects across boundaries. This cannot be done and is not necessary, as grids rely heavily on information sharing and coordination, using many common resources and shared infrastructure. Reliability and resilience require full understanding and management of the dependencies which cannot be eliminated – since a grid with zero interconnection is unrealistic and undesirable. There are a number of organizations that have expressed the belief that audit authorities consider the security of non-BES systems as part of the audit of a utility’s Critical Cyber Systems (CCS) and compliance with regulations, such as ACRP and NERC CIP. The oversight of critical
infrastructure systems is based on a set of defined scope criteria. In-scope requirements define the set of regulations that must be followed by critical infrastructure organizations, with the audit authority checking adherence for defined sets of required controls. Interfaces to BES systems may be mentioned in the audit reports for context, but because the non-BES systems in question are out of scope, there is no formal compliance audit of the non-BES systems unless the system or aspects of it fall under the definitions for audit criteria. Compliance is sometimes equated to “security” or “reliability” in the context of cyberspace. Compliance is the aspect of having conformed to the required, standardized, or legislated levels of performance or restrictions. In the case of cybersecurity reliability, non-performance or reduced performance may result from cyber-attacks and failures affecting the overall ability of the system or product to perform its required functions. A system may be fully compliant with standard regulations, yet may be faced with reliability challenges due to cyber-issues at the interface points where dependent systems are not fully trusted, and their interactions are not fully understood. Misconceptions can arise, in part, from over-reliance on guidance documents and technical reports related to emerging risks and infrastructures interdependencies. These documents are valuable sources of information about risks and possible mitigation measures but are inherently advisory and do not represent regulatory requirements. Their intent is to assist and warn, not to enforce mandatory compliance. Correcting these misunderstandings underscores the necessity of maintaining clear regulatory boundaries and prudent public awareness of shared risk. It serves to foster reasonable discussions among transmission and distribution utilities based on sound expectations, as opposed to regulatory overreach. Knowing what cybersecurity reliability at the interface is, and isn’t, is important for any number of stakeholders trying to get involved with efforts to oversee reliability in this area. As we’ve said before, achieving reliable cybersecurity at the interface between IT and operational technology involves much more than just being coordinated and following procedures based
on defined roles – than attempting to deal with unexpected circumstances using assumptions about what might happen, or trying to manage risk by predicting or mitigating unlikely outcomes.
End-of-Chapter Summary
Misconceptions regarding Cybersecurity Risk at Transmission and Distribution Interfaces often revolve around issues such as connectivity resulting in compliance obligations; that all interfacing systems require compliance coverage; and that compliance equals resilience. Clarifying these misconceptions for transmission and distribution interfaces: - Ensures that function-based responsibility is enforced and that the appropriate oversight for each function is provided and that utility awareness of shared risk is grounded in existing reliability understandings.
Chapter 12
Evolving Interfaces, Emerging Technologies, and Future Considerations
The electric power system’s transmission and distribution interface is a dynamic element that is shaped by changing technologies, operating practices, and system configurations. Cybersecurity reliability risk is a reflection of the broader set of changes occurring in the electric power system. Although these changes affect the transmission and distribution interface and the risks associated with it, the underlying reliability principles are not changing. This discussion of possible considerations of the future of the transmission and distribution interface focuses on trends and does not take into account proposed future requirements or regulatory actions. New interface issues are arising from evolving technologies associated with interfaces between electric power delivery systems. For example, widespread adoption of distributed resources, advanced distribution management systems, and automatic control technologies are expanding the scope of communication among devices within the distribution network and between transmission and distribution systems. Such developments potentially increase power system reliability while at the same time creating new sources of cyber risk for consideration in power delivery system risk management. Understanding the nature of interface risk from a reliability perspective is, therefore, a concern that should be addressed. Digital systems have introduced a new dimension of speed and quantity of transactions across system boundaries. While increased visibility may enhance situational awareness, it can also have the effect of making a system’s vulnerability to disruption in data integrity or availability more pronounced. Therefore, cybersecurity reliability of systems has to account for the consequences of interconnected information flows. With the increasing digitalisation of infrastructure and services, Organisational Models are undergoing significant changes. Shared services, centralised security operations centres and the use of cloud services, are changing the scope of work of IT departments, the rules that govern their behaviour and the limits they are authorised to cross, without necessarily changing the underlying liabilities. In this context, the governance, clarification of roles and the concept of interfaces are
more important than ever, as the physical boundaries that separate these entities are increasingly blurred by digital connections. Our approach to evolution is riskbased and not prescriptive. We have stated on numerous occasions to NERC and FERC that there is no need to expand standards or regulatory documentation to address “evolving technologies”. Rather, they prompt us to examine whether current regulatory guidance and risk reduction activities adequately address identified reliability risks. The
complexity of cybersecurity risks at the interfaces of the future will probably not be fundamentally different from the present-day complexity; it will just be more complex. The interfaces will be part of more complex systems, the attack surfaces will grow, and the need for efficient recovery coordination will increase. The reliability framework deals with this complexity by basing the responsibility on the function and the outcome of the function rather than on the technology itself. While the principle of evolution argues in favour of evolution, this does not necessarily mean convergence of regulatory scope at the level of transmission and distribution systems. There will always be the need to enforce boundaries. The distinguishing between shared risk and shared obligation that has been established at the interfaces between the networks should also be sustained in the face of rising interface complexity. Industry learning and transparency remain an important element. Analysis of potential disturbances, technical studies as well as voluntary information exchange by market players contribute to better understanding of potential risks arising at the interfaces, without a premature and inflexible regulatory adjustment. Stability can be preserved in this respect by adapting to developing regulatory affairs. This chapter on Dynamic Systems is the culmination of the cybersecurity reliability discussion that began with the importance of understanding the context of risk reduction. Dynamic systems are about evolving interfaces that highlight the need for reliability and cybersecurity to deal with complexities that are becoming increasingly dynamic. To recall, reliability, as discussed in previous chapters, is about resilience achieved through knowledge, coordination and compliance with specific roles. The principles of risk reduction discussed earlier in the context of reliability are therefore unchanged, albeit applied to increasingly dynamic systems. Reliability of Cybersecurity at the Transmission and Distribution Interface will remain a dynamic activity. Governance will be based on clear boundaries, functional responsibility and informed direction, rather than on equal treatment of interconnected systems.
End-of-Chapter Summary
Transmission and distribution interfaces are undergoing changes due to emerging technologies, increased digitalization of the grid, and changes in work practices. The changes impact cybersecurity reliability risk without altering the underlying reliability theory and its underlying assumptions. As interfaces become more complex, so too does the need for clear boundaries, functional accountability and risk-based management.
Glossary
Glossary
Bulk Electric System (BES) – A term defined in the NERC Glossary of Terms that means all the facilities and control systems that constitute an interconnected electric energy transmission network, except for facilities and control systems that are used for the local delivery of electric energy.
Cybersecurity Reliability: The ability of cyber systems and supporting processes to sustain or restore reliable operation of the electric system in the presence of cyber threats, vulnerabilities, or disruptions.
CIPS: Critical Infrastructure Protection Standards - The NERC Reliability Standards that provide cybersecurity requirements for control systems that are relied upon to maintain reliable operation of the Bulk Electric System.
Distribution System - Those facilities and systems that provide energy delivery from transmission lines or distribution substations to the point of ultimate use, and which are not included in the definition of the BES.
Functional Responsibility Reliability accountability is assigned to items based on the functions they perform in the entity, regardless of who owns them or what the structure of the systems is.
Interface - The point in a transmission and/or distribution system that physically, logically or operationally allows power, data or control to be transferred from one system to another.
Non-BES System - Any facility or cyber system that does not meet the definition or applicability criteria of the Bulk Electric System for purposes of the NERC Reliability Standards.
Operational Interdependence: The condition of two or more systems in which the operation or behavior of one affects the operation of the others through coordinated activity, information exchange, or shared resources.
Oversight refers to the processes by which a Reliability Organization such as NERC, Regional Entities, or the FERC monitor, audit and enforce Reliability Standard compliance and assesses reliability risk.
Risk-Based Oversight - An approach to compliance monitoring and enforcement where activities are prioritized based on the potential reliability impact of noncompliance with standards, rather than applying equal weight to all requirements.
Shared Risk Reliability outcomes may be affected by components of a system or entities outside the control of, or within the compliance scope of, an entity.
Transmission System - The high-voltage facilities and systems that carry high volumes of bulk electric energy over long distances and are part of the grid’s transmission infrastructure.
This glossary is intended for general information only and should not be used as the basis for any determination relating to compliance with the NERC Reliability Standards, technical reports or public reliability documents. Instead, for every term listed herein, the definition found in the NERC Glossary of Terms is to be applied.
About the Author
About the Author
Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.
Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.
Rob’s compliance authority extends across both reliability and cybersecurity domains. His work on Critical Infrastructure Protection includes audit and oversight of CIP-002 through CIP-014, scope and impact classification reviews, ESP and PSP boundary analysis, and program assessments for entities with Low, Medium, and High Impact Cyber Systems.
Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.
About Energy Compliance, Inc.
About Energy Compliance, Inc.
Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.
Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.
We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.
Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.
CIP-Focused Services
Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.
Energy Compliance services related to Critical Infrastructure Protection include, but are not limited to:
- CIP applicability and scope analysis (CIP-002 through CIP-014)
- Cyber asset and BES Cyber System identification and impact classification
- Electronic Security Perimeter and Physical Security Perimeter boundary analysis
- CIP governance and program assessments
- Integration of cybersecurity oversight with broader reliability programs
- Audit and enforcement support for CIP findings (non-advocacy)
- CIP framework reviews, gap analyses, and improvement plans
- Training focused on CIP framework, requirements, and audit expectations
- Executive and board-level CIP awareness briefings
Services are tailored to the functional role, system impact, and regulatory posture of each organization.
ENERGY COMPLIANCE PROFESSIONAL REFERENCE
Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.
N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.
I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.
CONNECT WITH US Scan to visit
E N E RGY COMPL IAN CE , IN C. · EC-WP-205 · © 2026 · AL L RIGHTS RES E RV E D