ENERGY COMPLIANCE, INC. Rigorous Compliance. Defensible Programs. HomeWhitepapers › EC-WP-206

Cybersecurity / CIP · EC-WP-206

Remote Operations & Control Centers

Remote and virtual control center operations exploded during COVID and never went back. CIP scope didn't change. Audit findings did.

Remote and virtual control center operations exploded during COVID and never went back. CIP scope didn't change. Audit findings did. If your operator can change a setpoint from a kitchen table, that kitchen has CIP scope — and the network connecting it is now part of your reliability architecture. A control center is wherever the operator is sitting. The function defines the obligation, not the address. Network architecture is now reliability architecture. Designed correctly, the firewall replaces the wall. Designed casually, it doesn't. Remote control isn't unreliable. It is differently reliable. The failure modes are different, and the program has to anticipate the new ones. CIP-005 expectations don't relax for remote operators. If anything, they intensify. The IRA requirements were written for this exact use case. Backup capability for remote operations is functional, not physical. The functional question is whether the team can switch in the time the standard expects. Audit findings on remote control centers cluster around three issues: incomplete asset inventory, IRA logging gaps, unclear physical security on remote workstations.

Contents

  1. Foreword
  2. Evolution of Remote Operations and Control Centers
  3. Control Center Functions and Reliability Responsibility
  4. Situational Awareness and Communications Dependency
  5. Authority, Coordination, and Operating Boundaries
  6. Reliability Risks and Failure Modes in Remote Environments
  7. Cybersecurity Context for Remote and Virtual Control Centers
  8. Remote Access, Virtualization, and Cyber Risk Considerations
  9. Oversight, Registration, and Applicability Considerations
  10. Compliance Monitoring and Enforcement in Remote Operations
  11. Disturbance Experience and Reliability Lessons
  12. Common Misconceptions About Remote Control Centers
  13. Remote Operations in Practice and Ongoing Evolution
  14. Glossary
  15. About the Author
  16. About Energy Compliance, Inc.

Read offline

The complete reference is on this page. The PDF is for circulation inside your organization.

Download the PDF

Foreword

Foreword

This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.

I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.

The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.

That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.

These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.

These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.

Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.

If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?

Rob Smith, Founder, Energy Compliance, Inc.

EC-WP-206 Remote Operations and Control Centers

Chapter 1

Evolution of Remote Operations and Control Centers

NERC CIPs and Regulatory Compliance Cybersecurity is addressed within the context of the NERC CIP Reliability Standards and associated regulatory expectations. This discussion relates to the cybersecurity implications of remote access, virtualization and distributed control systems and the associated risks and Regulatory compliance associated with these technologies and noting that regulatory standards are mandatory while guidelines are voluntary.

The FSP/ Branch publication also deals with oversight and compliance aspects of remote control centers. It deals with the aspect of accountability, registration, monitoring and enforcement as it relates to any business centre, whether physical or located remotely/virtually and corrects some misunderstandings regarding remote/virtual operations.

Release No.FERC-2023-6 This document is being provided as an informational tool to help establish context related to remote operations and control centers within the reliability and cybersecurity space. It does not constitute direction for implementation, design recommendations, regulatory compliance, or legal guidance. Rather, it seeks to neutrally describe where existing reliability and cybersecurity frameworks and guidelines may intersect with these evolving operations practices.

Control centers have been central to the real time operation of the bulk electric system. What typically comes to mind when someone hears the term “control center” is a large physical building in which a number of system operators, supervisors and support staff are situated in close proximity to the resources they are controlling. However, operations, technology and organizational advances have made significant changes to the concept of a control center and the methods used for control.

Early control centers reflected the Analog Communications and Local Control constraints and philosophy. Dedicated voice circuits and hardwired telemetry and on site automation connected the operator to remote transmission and generation equipment. The idea of proximity to the equipment and transmission/distribution lines was deeply embedded in the practices and assumptions of those days.

Several decades of digital control systems, supervisory control and data acquisition (SCADA) systems and wide area communications have changed the physical world of a control center. With advanced technologies, operations personnel are able to manage their facilities from greater distances with greater levels of visibility and granularity. With multiple redundant communications paths and systems, personnel are no longer as closely tied to a single physical location.

The trends in operations mentioned earlier also impacted work habits and priorities of Reliability teams. In addition, business and operational considerations became more significant influences: Activities that involved on-site presence and management of farflung assets became centralized into shared service or other efficiencies driven business operations. In parallel, reliability work became more focused on developing capabilities to ensure that any specific event, whether man-made, a natural disaster or an act of mother nature, does not meaningfully impact the performance of the systems under Reliability management.

In this context “remote operations” is not just a terminology describing operations located in geographically remote areas. The use of Backup Control Centres, Hot Standby Centres, or shared control centres were considered in the design to enhance reliability. This was because availability was considered at the functional level, rather than at the geographical location of the control centre.

Recent developments in virtualization technologies, remote access and distributed infrastructure have further expanded the boundaries of the classical control center. Control tasks are not necessarily limited to centralized on-site control rooms and can also be carried out from a distance, even from different

locations such as regional or mobile facilities. Such trends in control centre technology are also creating concerns for the reliability, cybersecurity and monitoring aspects regulated by current rules.

Much of the EPG’s work on the NERC Reliability Standards Framework has focused on understanding its structure, composition, and evolutionary pathways. One of the enduring features of the current framework is its orientation to a more functionally based view of the grid and the roles that various actors play in the reliable operation of the transmission system. The reliability responsibility for actors has been defined by the functions they have within the framework. As control center structures have changed, (for example, from individual generator-based switchyards to system-wide substation monitoring and control centers), there has been no need to rethink the functional definitions of those responsibilities, which remains a core strength of the Framework.

However, the transition to working remotely from home and from virtual control centers introduces a range of new dependencies and sources of risk. A greater reliance on communication systems, increased exposure to cyber risks and changes in the interaction between people and equipment are all factors that need to be taken into account when managing reliability risk. None of these are changes to the accountabilities, but they do represent changes to the way in which these accountabilities are executed and discharged.

Understanding the historical development of remote operations and control centers is crucial to the discussion of reliability and cybersecurity. Advancements in technology that are increasingly moving us away from being confined to the centralized, physical control room are also playing a role in the shift away from traditional, centralized control rooms. At the same time, authority, coordination, and accountability are still important issues whether control is being exercised from the control room, the field, or from a remote location.

End-of-Chapter Summary

Historically, control centers have been large, stationary facilities. Modern technology, together with changes in business practices and emergency preparedness have led to new types of control centres. Modern control centres can also be located remotely, or in distributed or virtual locations. Reliability control and information functions are still described in functional terms, and the new dependencies and exposures associated with remote control centres will have to be accommodated within the reliability and security frameworks.

FROM THE FIELD

Remote control isn't new. What's new is that remote control is now normal, and the standards were written when it wasn't.

The control center moved. Operators moved with it. The reliability obligations didn't move; they followed the function, wherever the function was performed.

Chapter 2

Control Center Functions and Reliability Responsibility

A control center is a location that provides resources to perform reliability tasks. Whether those tasks are being performed from a head office, a field office or from a home office, remote or virtually, the reliability tasks are no different than described in the NERC Reliability Standards Framework. Understanding this key element of the equation, and not letting the location where work is done cloud our judgment, is critical. Operations associated with the control center are related to certain registered entity roles such as Transmission Operator, Balancing Authority, and Reliability Coordinator. Examples of these operations include real-time tracking of current system conditions, implementation of operating orders, coordination with adjacent systems, and response to emergency or contingency conditions. The reliability effect of these actions is a function of the scope of authority and the level of situational awareness, not their physical location. NERC Reliability Standards Function Based Responsibility The current NERC framework for assigning responsibility to specific entities is based on functional criteria and not based on physical resources or facilities. The fact that the control room for a Transmission Operator or Balancing Authority may be remotely located or virtually situated does not affect responsibility for compliance with applicable Reliability Standards. In other words, the entity performing the function retains all corresponding responsibilities. The same approach applies to backup and alternate control schemes for emergency conditions and for continuity of operations. Backup control centers or remote operations locations may be provided and authority to control the plant may be transferred to these locations under certain conditions and for specified time periods with the same reliability requirements as for the main control center. Communication, visual means for providing dynamic information and emergency procedures would still apply. Authority is a key element of control center responsibility. It is essential that Control Center personnel have sufficient authority to operate within the parameters of their Operating Procedure, as well as to fulfill any Reliability Coordinator instructions. The requirement for clear command and control authority is

not diminished in remote control situations. In fact, it may be increased due to the remote nature of the operation and the resultant need for clear authority and escalation procedures. Operational functions within a control center are fundamentally interrelated. A change by a Balancing Authority (BA) to meet its real-time imbalance criterion will cause a change in transmission loading. A change by a Transmission Operator (TO) to manage potential instability in its vicinity will also cause a change in power flow

elsewhere in the system. Similar interrelationship exists among Reliability Coordinator (RC) functions, spanning a broad geographic area. Remote operation does not eliminate this interrelationship and in some cases may even add to the complexity of coordination. Human factors are still important. Operator decision-making, workload management and communication are all critical to successful system operation. The remote environment will affect the way that these activities are performed, but will not remove the need for rigid adherence to proven operating practices and training in line with the principles of reliability. As outlined in the Functional View of the Control Center, the functions that are performed by the control center are directly related to the role that Remote Operations will play in the reliability process. From a functional viewpoint, even though the physical structure of a control center may change, the basic functions that are required for authority, coordination, situation awareness and accountability will remain the same. This perspective on reliability reinforces the underlying principle in the NERC Reliability Standards Framework that reliability is a result of identified functions being performed reliably, rather than being dependent on the design or location of specific resources.

End-of-Chapter Summary

Function definition and therefore location of a Control Centre is defined by function rather than location. Registered Entity performing operational functions still retain responsibility for reliability and this will not change regardless of where control functions are physically located – in a Control Centre, a Remote Control Centre or as part of a Virtual Control Centre. Regardless of Centre location or configuration, Authority, Coordination and Situation Awareness will remain key elements in maintaining reliable operation.

FROM THE FIELD

A control center is wherever the operator is sitting. The function defines the obligation, not the address. CIP scope follows the function. If an operator can change a setpoint from a kitchen table, that kitchen has CIP scope.

The Region treats remote control centers no differently from physical ones. The audit expectations are the same; the operational evidence has to match.

Chapter 3

Situational Awareness and Communications Dependency

Situational awareness is a fundamental component of reliable bulk power system operation. Control room personnel must have an understanding of system conditions that is timely, accurate and complete in order to identify potential problems, respond to system disturbances and coordinate actions throughout the interconnected system. In remote and virtually operated control centers, situational awareness will be heavily dependent on communication and data systems. Historically substation control centers have always relied on a mix of local knowledge, remote telemetry and radio voice communication to manage their assets. Some of these functions remain important but new ones have been introduced in remote control as a result of the reliance on wide area networks, data centers and remote access technology to manage systems that are not in close geographical proximity to the person controlling them. This article discusses these impacts. One of the underlying factors that affect Situational Awareness is Data Availability and Integrity. As discussed previously, operations personnel needs to receive a wide variety of information on time to understand what is going on with the process. Typically this information includes Telemetry, Alarms, State Estimators and other kinds of analyses and predictions derived from the plant data. In the remote case, the length of the signal paths can increase significantly because of the additional network segments and points of access that need to be traversed. If the quality of the data is compromised in terms of its timely arrival, and in terms of missing or distorted values or trends, it can have a negative impact on the operational activities and readiness of the personnel. Communications is a key factor in the coordination process. Voice communication among various units within the utility and among reliability coordinators, line workers, and transmission system operators in neighboring utilities are needed for both routine operations and under emergency conditions. Remote control centers make use of a mix of analog and digital voice circuits including IP connectivity and have multiple backup communication systems available. This added complexity and additional number of system components emphasizes

the need for redundancy and reliability. Loss of situational awareness can manifest in many forms. Operators might not be aware of changes to the operating state of the system, may not understand what alarms mean or receive timely information during an emergency. Each of these scenarios can occur in remote locations for a variety of reasons including network failures, cyber attacks on the SCADA system, data center failures and misconfiguration of remote access. The NERC reliability standards for situational

awareness do not mandate particular technologies or architecture. Instead they focus on the reliability requirements for the communication systems, information flows and coordination activities needed to support the functional requirements of situational awareness as prescribed in each relevant standard. The control environment requirements of the registered entity will need to support the requirements for situational awareness set forth in each applicable reliability standard. Human-Machine-Interaction (HMI) and Situational Awareness (SA) Remote Operation impact on HMI and SA has the potential to change significantly with remote operation. Operator interactions with HMIs, alarms and other supporting tools and systems may differ significantly from the classical local operator mode. Another concern is the potential impact on communication and mutual understanding between personnel in different locations and also with respect to a distance between personnel and systems and equipment. This impact should not introduce any new reliability requirements, but merely represents a different way of fulfilling the current reliability tasks and challenges. Remote Operations – What is Situational Awareness? Situational awareness (SA) in the context of remote operations is a complex interplay between operational reliability and infrastructure. Remote operations often utilize communication and data systems for a wide variety of applications in the control center. These communication and data systems are not secondary or tertiary systems, but are actually part of the reliability ecosystem that makes the production process possible and allows for operational decisions to be made. As operations shift to new locations, situational awareness of the control center remains a fundamental reliability goal. No matter how remote or virtual operations become, communication reliability, data integrity and proper procedural coordination will still have to build on the existing reliability framework.

End-of-Chapter Summary

Situational awareness is a factor that directly affects the reliability of a system, and is strongly influenced by communication and data systems in remote control systems. When a system is remotely controlled, it adds new interdependencies and failure modes that may impact situational awareness. Reliability of communications, data processing and control of operational procedures are necessary in order to maintain situational awareness and ensure an adequate discharge of functional reliability responsibilities.

FROM THE FIELD

Situational awareness is a SCADA picture, an operating display, a phone line, and a shared mental model among the operators. Remote control changes the second through fourth without changing the first.

A remote operator depends on the network to see the system. Network problems become operational problems faster than at a physical control center, where the operator can walk down the hall.

Communications redundancy isn't a luxury for remote operations. It's the operating premise. Lose the link and you lose the control.

Chapter 4

Authority, Coordination, and Operating Boundaries

Reliability will continue to be ensured regardless of where control functions are exercised. The importance of control functions will not diminish, even in situations of remote and virtual control where there may be greater physical separation of people, systems and facilities. This situation may actually enhance the need for clear definitions of authority and operating boundaries within the established reliability framework. Definition: Authority within a control center means the ability to order actions, to issue directives and to obtain response to control center actions from systems or equipment for functions assigned to control center personnel. For registered entities such as Transmission Operators, Balancing Authorities and Reliability Coordinators the authority is derived from their functional registration, operating agreements and reliability standards. The ability to remotely operate equipment does not change the source or extent of this authority. Transfers of control may occur in remote operations of some stations. For example, a master station may give up control to a backup or alternate control station. Uncertainty of control in transition may cause confusion, extended time to recover from a fault, or conflicting instructions to be given to an automaton or system which can all lead to reliability risk. Coordination of functional activities is a fundamental aspect of authority. An operator has to know its own role and the effects it may have on other systems or on other registered entities in the area. In remote locations the conditions for communication, personal interaction and the use of formal communication protocols may be different. Operating boundaries describe the limits within which operators and control center personnel are allowed to operate. These can be technical in nature (e.g. system operational limits) or more to do with the organization (e.g. jurisdictions or contracts). In remote systems this is particularly important as operators may be controlling equipment over large distances. Reliability Coordinators are responsible for ensuring coordination and enforcement of operating boundaries. RC authority to issue orders is not changed in a remote or virtually operated R/E/V (Reliability / Emergency / Voluntary) system. Control centers performing Reliability Coordinator functions must ensure that remote arrangements are not a barrier to clear communication of R/E/V system orders and for obtaining prompt confirmations ofRC compliance from affected host utilities. Emergency conditions cause the greatest challenges to authority and coordination structures. In the event of system disturbances, operations may have to be carried out under time pressure with inadequate knowledge. In such cases, remote operations can easily lead to unclear authority and coordination problems, and highlight the importance of established operating procedures and agreed procedures for escalation.

There are no specific requirements for the implementation of authority and coordination in remote areas. Rather, there are specific requirements that cover the general aspects of coordination, communication and compliance with the orders. The degree of centralized control arrangements is at the discretion of the Registered Entity, as long as it does not affect authority or coordination. Affirmed Aug 19, 2011 One of the underlying principles of the reliability framework is that accountability and coordination are required to ensure reliability – whether or not people are physically close to each other. This principle was confirmed when understanding authority and coordination in remote control was highlighted. As control center configurations continue to evolve, ensuring that people always understand the operational authority and boundaries they are working under will remain an important consideration for ensuring reliable operation of the power system.

End-of-Chapter Summary

Authority and coordination are key elements of control center operations and are equally important for remote and virtual control centers. The physical distance does not change the authority or boundaries of the functions; it only increases the degree of coordination required. A well-defined authority structure, appropriate communication practices and adequate transition procedures must be in place to ensure high reliability of remote operations.

FROM THE FIELD

Control authority doesn't decentralize because the seat moved. The authority is still concentrated; only the seat is distributed.

Coordination across distributed operators requires more discipline, not less. The hallway conversation that resolved a question at the physical control center has to be replicated explicitly at the remote one.

The remote operator has the same legal authority as the physical operator. The framework recognizes that. The program has to operate it consistently.

Chapter 5

Reliability Risks and Failure Modes in Remote Environments

Remote and virtual control environments present unique reliability risk considerations based on different dependencies, interfaces and failure modes. Remote and virtual control are not unreliable in themselves. This warning is intended to ensure that considerations of reliability risk are made on their own terms, rather than by prejudging what these terms must be. In some respects the major reliability risk in remote sites is associated with the increasing degree of dependency on telecommunications. Wherever possible operational control, situation awareness and coordination between personnel is based on the assumption that telecommunication networks, including the ability to make voice calls, will always be available. Failure of the underlying communication infrastructure - whether the consequence of physical damage, mis-wiring or external events - can have a rapid detrimental effect on operational knowledge and the ability to respond, even in the absence of any failure in the electrical apparatus of the protection system. Latency and data quality is another set of risks that we have to consider. When we operate from a distance we are talking about potentially more network hops and data consolidation points as well as interfaces. Poor quality of service can introduce delays, packet loss or varying update rates that can obscure the operator’s picture of the real time system state. This can affect operational decisions and increase the time it takes to respond to developing issues. Loss of redundancy is a potential failure mode for remote sites that are not redundantly designed. Concentration of control functions, communication links or data services in a single point at one location can create a single point of failure. While consolidation of facilities and systems can provide benefits from cost savings and improved efficiency, it can also result in increased risk of consequences in the event of a site failure unless redundancy and separation are properly considered. Human factors risks may change in a remote environment. As personnel are physically separated from colleagues, field personnel and equipment, communication effectiveness, common understanding and workload redistribution may be affected. Operators may have to rely more on formal communication and less on nonverbal communication which can affect the coordination of crew members during abnormal operating conditions. Transition failures are a different class of failures. Transitions from the primary site to the backup site in a distributed site redundancy configuration, or transitions from the central site to the remote sites in a hierarchical redundancy configuration, are not always well defined, and there can be confusion when a transfer of control is not done smoothly, with no ambiguity as to which site is in control and thus can act in a timely fashion in an emergency situation. Cyber events can also act as a reliability risk in remote operations. While

cybersecurity is treated as a separate risk within the reliability risk management framework, a cyber event impacting a remote operation system, communication network or control system can have an operational impact and is therefore a reliability risk; this applies to both cyber attacks and technical failures. In this context, it is essential to separate the concept of risk presence and risk realisation. While the risks associated with remote operations are quite different, it does not automatically mean that there is more risk of reliability events occurring. In many remote environments, there is actually more redundancy and increased ability to maintain continuity of operations even in the event of a failure of the main control facility. In our opinion, many of the risks associated with geographically dispersed workforces are currently addressed within the reliability frameworks in place by NERC to ensure grid reliability. These address outcomes such as: * Situational awareness * Coordination * Communication reliability * Emergency response capabilities and the related physical contingency structures. While NERC standards typically identify specific failure modes and means of mitigation (e.g. via reliability standards and grid modernization guidelines), they do not do so for remote workplaces. Instead they are built on principles of accountable functions and risk-based oversight. Determining reliability risks and failure modes in a remote control environment can assist in exercising more informed oversight and operational awareness. This points to the need for an integrated system view of remote operations that accounts for interdependencies, interfaces and transitions rather than the physical location of a facility.

End-of-Chapter Summary

Remote control environments pose reliability risks related to communications dependency, data integrity, redundancy, human factors, and control transitions. These reliability risks are driven by a change in system dependencies from what is considered reliable to unreliable. Current reliability analysis methods focus on functional expectations to address awareness, coordination and effectiveness in controlled situations.

FROM THE FIELD

Remote control isn't unreliable. It's differently reliable. The failure modes are different from a physical control center, and the program has to anticipate the new ones.

Single-point-of-failure analysis at a remote control center reveals dependencies that were invisible at a physical one. Network paths, video feeds, authentication services — all become potential single points.

The new failure modes don't replace the old ones. They add to them. The program tracks both.

Chapter 6

Cybersecurity Context for Remote and Virtual Control Centers

Cybersecurity is interwoven with reliability in remote and virtual control centers. With the trend toward more digital communication, remote access technologies and distributed computing platforms in control functions, cyber risks to electric infrastructure have the potential to affect the reliability of the bulk electric system. Note that this does not convert cybersecurity actions into reliability activities. A remote or virtual control center expands the cyber attack surface for the control systems that are being used to perform the control operations. New attack surfaces are created and vulnerabilities previously mitigated can be re-introduced. For example, equipment and applications that were previously not exposed from an untrusted network may now be exposed from a less secure remote location, a virtual environment, or an outside vendor’s network. This can create new and unknown types of threats and vulnerabilities to control operations. Cybersecurity is largely addressed within the NERC framework through the Critical Infrastructure Protection (CIP) standards. These deal with system identification, access control, monitoring, incident response, and recovery. The application of these standards is based on the function and criticality of the systems they govern, rather than on whether the control center is a physical, remote, or virtual location. Remote access is a major focus of the cybersecurity discussion. Control paths for operators that allow them to access components from a remote location must be managed in a manner that is consistent with the established cybersecurity expectations. The availability of remote access does not introduce new reliability considerations; it is more a matter of how the existing cybersecurity requirements are operationalized. Virtualization and cloud-based systems present new boundary, asset, and dependency management issues, which are not addressed in the current reliability framework. The current framework does not preclude the use of any technologies, but rather assumes that the operational picture of the systems provided by the registered entity considers all risks that may arise from the adopted architecture. The entity performing the reliability function is always accountable. Black and brownouts can

occur due to cyber-attacks on the control centers and this has a direct impact on grid reliability. Loss of visibility, denial of control commands or reduced communications can prevent control room operators from effectively managing the grid in real time and in response to changing conditions. The initial cause of the black or brownout may be cyber, but the reliability perspective is the operational impact it has on the power system. Guidance and technical publications issued by NERC frequently mention the need to

incorporate “cyber awareness” into operational procedures and emergency response activities. However, these documents do not create regulatory requirements. Rather, they serve to illustrate how considering the potential impact of cyber vulnerabilities on operational reliability, particularly in remote locations with greater interdependence, is generally good practice. There is often a confusion between the terms of cybersecurity compliance and cyber resilience. Cybersecurity compliance refers to the compliance of technical and organisational measures with specific regulations and standards. Cyber resilience, on the other hand, describes the ability to maintain or restore functions in the event of disruptions or failures. This difference in terms is also relevant in remote and virtual control centers. The greater degree of remote and virtual operation increases the dependency on systems which are outside of operational control. Cybersecurity for remote operations is a key component of the overarching reliability framework. The basic principle of the technology choice does not change the responsibility still holds true. It is important to remember that the registered entities are still responsible for the reliability of the assets, as well as the cybersecurity of the systems, no matter where the control functions are physically located.

End-of-Chapter Summary

Remote and Virtual Control Centers (R/VCCs) typically involve greater dependence on digital communication and remote access technologies increasing the extent of the corresponding cybersecurity risks. Current NERC policies address cybersecurity risks in control systems through application of existing Critical Infrastructure Protection (CIP) standards on a functional basis. A cyber incident in a remote area can impact R/ VCCs directly and therefore they are a clear example of the close connection between their cybersecurity context and operational risk.

FROM THE FIELD

Every remote control center is a CIP scope expansion. The standard applies to wherever the function is performed, and remote means wherever.

The home office that doubles as a backup operating position is in scope. The travel laptop used during emergencies is in scope. The standards don't care about convenience; they care about function.

CIP-005 expectations don't relax for remote operators. If anything, they intensify. The Interactive Remote Access requirements were written with this exact use case in mind.

Chapter 7

Remote Access, Virtualization, and Cyber Risk Considerations

Remote access and virtualization are pervasive components of modern control center technology and have become a core of flexible, resilient, and resourceefficient operations. Cyber risk associated with remote access and virtualization is interwoven with existing reliability professional responsibilities and overseen by regulatory authorities. Remote access refers to the ability for personnel to interact from a remote location with elements of a control system, such as through a computer via modem from a building other than the control facility. Remote and virtual control centers often rely on remote access as a normal, rather than contingency, means of controlling process equipment and systems. As the use of remote access becomes more widespread, the availability, reliability, and control of the remote access paths become operationally important. In Control Centers virtualization is implemented to host, manage and monitor systems. New functions that were previously running on individual pieces of hardware have to be implemented on shared or virtualized infrastructure. While virtualization provides the benefits of improved flexibility and redundancy, it can also obfuscate knowledge of system boundaries and interdependencies. Hence potentially affecting their ability to be managed from a cybersecurity and reliability perspective. Reliability wise, remote access and virtualization are not the issue. The issue is the effect of remote access and virtualization on control availability and operator efficiency in a scenario where reliability is compromised and immediate operator action is required to prevent potential damage to people or equipment. In such a scenario, unexpected loss of access, a reduction in operational system performance, or unexpected interactions between virtualized components can erode the operator’s situational awareness and ability to quickly react to the situation. See the original Cyber Risk Notices published by the relevant Asset Operator for the full list of technologies covered by each Notice and for the notes related to each technology listed. The following cyber risk considerations have been identified in relation to some of the technologies mentioned: authentication failures misconfigurations software vulnerabilities

shared infrastructure. Single point of failure in remote environment Cyber or technical issues affecting remote operations can have significant consequences. In some cases, a single cyber or technical incident affecting a common platform or access point could potentially impact more than one operational process if these all make use of the same shared systems. Accountability for risk within the NERC reliability area remains with the registered entity that is performing the reliability function. Use of 3rd party services,

shared resource platforms or virtual environments does not change this fact. It is necessary for a registered entity to understand the implications of the choices made in their system architecture on cyber and operations risk. Remote access and virtualization is addressed under existing cybersecurity and reliability requirements rather than being addressed through technology standards. The existing standards related to access control, monitoring, incident response, and restoration are applied based on the system criticality and function. The reliability requirements for communication, coordination and emergency response readiness remain the same. Recovery and restoration in virtualized environments should not be neglected. Although virtualization technologies provide fast restoration possibilities, complexities in the prioritization of the recovery actions or in the identification of faults may arise. Reliable restoration of control functions should be provided for all technologies. Remote access and virtualization are complex topics and it is very easy to get into a rut of thinking about them in terms of technology rather than in terms of reliability. These systems do have place in increasing the reliability of some part of our systems. But at the same time they are a great source of new dependencies which must be accounted for. Looking at these things through a reliability filter helps make sure we do not lose sight of the real world in which they are operating.

End-of-Chapter Summary

The use of remote access and virtualization in control centers offer many operational advantages. However, they create cyber and operational dependencies that can impact RRCX reliability risk. These dependencies remain associated with the activities they support rather than the technology employed. Focus on the impact of the activities, remote access controls and restoration processes rather than the technology architecture of the systems that implement them.

FROM THE FIELD

The remote operator has the same access to the system as the physical operator. The remoteness doesn't reduce the privilege; it complicates the verification of who's actually using it.

Multi-factor authentication is necessary but not sufficient. The audit looks at how authentication is monitored, not just whether it's required.

Personnel access controls in a remote model have to anticipate scenarios the physical model didn't: shared devices, family members in the room, intermittent connectivity. The program has to have a position on each.

Chapter 8

Oversight, Registration, and Applicability Considerations

Reliability Oversight of Remote and Virtual Control Centers This cannot be a reliability oversight controlled environment. As such, reliability oversight, registration and applicability determinations remain based on the functions being performed and the impact of those functions to the BES. Understanding the original concepts in this context can help eliminate possible misunderstandings when determining how to implement control center activities in remote or virtual environments. Functional registration is still the basis for defining Reliability responsibility. Entities are registered for the reliability functions that they perform, such as Transmission Operator, Balancing Authority, or Reliability Coordinator. The location of personnel or systems (whether in a control center or not) does not change the registration. Entities can still operate remotely without changing their registration functions, and cannot thereby become registered in a new reliability function. Each Reliability Standard defines the functions, and the criteria, for which it is applicable. Some standards are applied to certain roles or circumstances (e.g. the functioning of control systems). Others apply to activities that could be part of the operational procedures of control centres, such as command, communication, situational management and coordination whatever the location from which they are physically performed. Finally, there is no differentiation between traditional physical control rooms and remote (virtual) control rooms for the application of the standards. However changes to the control centre configuration may have implications for the means of demonstrating compliance with certain requirements. For example, when activities are conducted from remote locations, the methods of demonstrating continuity of communication of authoritative instructions or the ability to respond may require consideration. This is a matter of implementation and documentation and does not relate to the underlying requirement. Shared resources, such as remote control and shared or third party services, can also be a challenge. Understanding the role and responsibility of each involved party can be confusing. While the bulk of the work may be performed by the third party, it is important to remember that

the Registered Entity is still responsible for the compliance of their system. This principle is constantly being reinforced by NERC, as the act of delegating tasks does not necessarily mean the responsibility for that task is transferred. Most remote operations systems have a backup control center or alternate control center. Over sight of control authority when transferred to the remote location does not change. The entity must always be in a position to provide the required reliability of operations, including

communication, coordination and command and control, from whichever location it has control of the system. In remote environments, a range of Registration and applicability issues can arise as a result of the often blurred boundaries between onshore, offshore and the wider geological area, particularly where operations are being carried out from a distance, for example to manage assets over vast areas or across multiple countries. These are however dealt with within the current framework of the registration process and the Rules of Procedure, and do not involve the introduction of any new regime specifically related to remote operations. Oversight and Applicability in Remote Areas Having an understanding of the scope of oversight and applicability in remote areas helps ensure that reliability principles are adhered to regardless of location. As we know, one of the main reliability principles is that location of the facility does not in any way determine the obligation. The reliability standards, therefore, are still effective and applicable based on the function and impact of the facility’s operations. Viewpoint: Consistency with Flexibility (White Paper) A recent discussion paper canvassed four differing viewpoints on how the current regulatory approach could be adapted to ensure regulatory consistency yet provide scope for organisations to implement control arrangements which suit their business operations and circumstances. In particular, the paper suggested that remote and virtual operations could be incorporated within the current approach without the need for significant re-engineering of the registration and applicability frameworks.

End-of-Chapter Summary

Reliability determination of Remote Control Centres (RCCs) will be based on their operational functions rather than on their geographical location or the technology employed. Remote operations will not affect the reliability registration of the TSOs, nor create any new obligations, but may affect the way the applicable rules are demonstrated to be complied with. Ultimately the reliability compliance for the registered TSOs will remain unchanged.

FROM THE FIELD

The network architecture is the new control center perimeter. Where the wall used to be, the firewall now is. The functional equivalence is real; the engineering required to achieve it is non-trivial.

A flat network design that worked for the physical control center can become a single compromised endpoint away from full system access in the remote model.

Defense-in-depth at the network layer is what makes remote control reliability-defensible. Single layers of network protection are documented in findings, not in resilience.

Chapter 9

Compliance Monitoring and Enforcement in Remote Operations

Reliability Standard monitoring and enforcement is the same for remote and virtual control centers as it is for traditional central stations. Enforcement is focused on whether the requirements of the Reliability Standards are met, not on the physical or technological structure of the control center environment. Clarifying how monitoring and enforcement is applied in remote operations should help reduce uncertainty. The compliance monitoring activities verify whether licensees are able to carry out control functions reliably in the operational mode chosen. Audits, spot checks, self-reporting and event-based investigations may involve examination of remote control arrangements if these are considered relevant to the licence conditions applicable to the situation. The presence of remote operations in itself is not an enforcement trigger. Our oversight activities generally are based on outcome and capability, not on system design. An example of an activity we have conducted relates to remote control of unmanned robots. We observed that a small number of remote control functions that operators could use to maintain operational knowledge of the location and actions of their robots at a distance were mandated by FDA standards for unmanned robots as remotly controlled weapons systems. In our testing, we found that the various remote control capabilities that allowed for remote operation and control of the robots from a distance were actually focused on the robots’ operational capability in relation to FDA required standards. Remote operations evidence is not different in any way other than form and description. Communication procedures, operational authority, backup and transfer of control documentation may be reviewed. The purpose of this documentation is to confirm the reliability capability and does not relate to the design of the remote operations. Event-based reviews are a key factor in remote operations. Should a disruption or other operational incident occur, regulatory bodies may consider whether the use of remote operations had an impact on the regulator’s assessment of the operator’s awareness of the situation and the speed and effectiveness of its reactions and decisions. As with other regulatory activities, the key focus is whether regulatory requirements are being met, and that reliability risk is being adequately managed. Please be aware that enforcement of remote work activities is conducted in the same manner as other enforcement activities. Any determination of noncompliance is made based on the requirement and any relevant evidence obtained, and not on the mere fact that remote or virtual activities are being performed. In relation to mitigation, the expectations are still centered on addressing the issues that were identified and reducing reliability risk, and not on the means by which those activities are being carried out. Risk-based oversight is a key consideration in assessing the impact of

remote operations. Our oversight will focus where it can have the greatest impact on reliability, as not all remote working arrangements are created equal. Informed and proportionate oversight, not prescriptive, is key. The reliability framework will continue to ensure consistency in regards to compliance monitoring and enforcement with the implementation of remote operations. The Remote and Virtual Control (RVC) Guideline will ensure that operations conducted from remote or virtual control centres are held to the same scrutiny, processes and standards as all other registered entities. Achieving operational consistency across models supports operational flexibility while still enabling Design to Balance accountability and Reliability targets. This reduces complexity in control center operations and enhances compliance oversight such that as models evolve, there are existing mechanisms to ensure adherence to compliance targets, rather than the enforcement of technical model construct.

End-of-Chapter Summary

RCC compliance monitoring and enforcement is based on the operational configuration (functionality) of the facility, not its physical structure. Surveillance activities focus on the controls and arrangements for maintaining situational awareness, enabling appropriate communication, ensuring necessary facility authority and the ability to provide an effective response, using established processes. Remote operations are treated the same as on-site operations within the risk based reliability oversight framework.

FROM THE FIELD

The Region audits remote operations the same way they audit physical operations. The evidence is different; the standards are the same.

Documentation that the remote operator's environment meets CIP scope expectations has to exist before the audit asks. Building it during the audit is too late.

Audit findings on remote control centers cluster around three issues: incomplete asset inventory, gaps in IRA logging, and unclear physical security on remote workstations. Programs that pre-audit themselves on those three rarely get findings on the others.

Chapter 10

Disturbance Experience and Reliability Lessons

Experience with remote and virtual control center operations comes from actual operational practices and is valuable in helping utilities understand how their systems operate under real world conditions. Disturbance analysis and event reports have identified advantages and challenges of remote operations and will help utilities gain insights into reliability risk, without requiring the development of new guidelines or prescriptive recommendations. Disturbance experience in remote control environments confirms the reliability of the system also in case of physical damage to the primary stations in the affected area. Experience has shown that control from remote stations can be maintained, even if the area is affected by strong winds, lightning, floods, fires, landslides, etc., caused by extreme weather or major natural disasters, or if it has been damaged by local damage to the power system. Such experiences give an example of the possibilities to utilize the flexibility of remote control for achieving reliability of supply in case of e.g. severe weather conditions, earthquakes or other major disturbances that can cause local damage to power systems. Some effects of remoteness were also observed through event analysis. In a number of occurrences, it was not entirely clear what contributed to the complexity introduced by remote operation. Loss of command, loss of feed-back, poor resolution of images and difficulties in the control transfer were all identified in connection with events leading to delay in responding to an incident or with a poor situational awareness. In most cases however such problems did not stem directly from remoteness but from the fact that the many dependent relationships and interfaces provided in near-shore operations were heavily stressed during abnormal operating conditions. We’ve also had a fair bit of discussion around human factors as it relates to disturbance experience. Some events highlighted the importance of clear communication, shared situation awareness and the impact of remote workloads. Physical distance from normal work areas can affect the degree of informal interaction between personnel, which in turn can impact the frequency, type and effectiveness of formal communication used to address emerging events

or threats. The effectiveness of these interactions are often not well understood or practised. Recent disturbance reviews have highlighted the need for transition management. Many disturbance scenarios in the power system involve transitions between different operating areas, and recent disturbance reviews have shown that changes to the control area within certain time frames can be critical. These changes involve many aspects, such as definitions of roles and responsibilities, synchronization of

protection and control systems, and crew readiness. Therefore, adequate transition activities must be considered and managed within the current reliability standards. All too often, we experience the aftermath of a cyber attack and are reminded of the operational consequences of our heavily dependent digital world. System failures from legitimate or illegitimate sources and vulnerabilities show us too that incidents involving control systems and IT can still indeed have reliability consequences - especially in our ever increasing number of remote located operations. The NERC event analysis did not determine the cause of reliability event outcomes related to control center functions to be the choice of control center architecture. Rather, it focused on the performance of the individual control center functions, the level of their interaction, and the bulk power system response. The findings from these analyses are being used to evolve guidance, outreach and standards development activities; however, they do not restrict the choice of architecture or operating procedures. The understanding of Disturbance Experience in relation to Remote Operations points strongly towards that reliability needs to be considered in a holistic perspective. In remote control and with the use of virtual Control Centers reliability can both be increased and exposed in new ways, dependent on how the interdependencies between them are handled during transitions and in relation to the impact of Human Factors. Command Report Lessons Learned Command Report Remote Operations: Lessons Learned The purpose of this command report is to provide a balanced perspective of remote operations. It has been written to preclude the development of the false illusion that remote operations are inherently dangerous or inherently better. The reliability of remote operations technology in enhancing our tactical operations effectiveness will depend upon its effectiveness in enhancing our situational awareness, our command and control authority, our ability to coordinate, and our ability to respond in crisis situations.

End-of-Chapter Summary

Disturbance experience has shown that our remote and virtual control centers are valuable tools in helping us to manage our stations response to physical events and can potentially contribute to increased availability through a better ability to manage complex situations on a few lines due to communication and switch changes as well as crew changes. The event analysis has revealed that the reliability of the power system is a function of the actual performance and coordination of the resources provided by the station configuration and layout as opposed to the type of control center used. This experience has enabled us to gain a better understanding of reliability risk and will not result in any changes to our current methods.

FROM THE FIELD

A backup control center used to be a building. Now it's an operating model. The reliability question is whether the operating model has been exercised, not whether the second building exists.

Failover testing at remote control centers has to be more frequent than at physical ones. The system is more dynamic; the test cadence has to match.

Chapter 11

Common Misconceptions About Remote Control Centers

Remote and virtual control centers (VCCs) are sometimes accompanied by misconceptions that may be interpreted to obscure, rather than clarify, the reliability and cybersecurity impact of such systems. This briefing clarifies and addresses certain misunderstandings concerning the application of the NERC Reliability Standards Framework and enforcement practices with respect to control centers that operate remotely. There is a common misconception that remote control center stations will inherently reduce the reliability of the system. Again, it is the performance of the elements in the system that will affect the reliability of the system not their physical location. A remote location does not, by itself, impact the reliability of the system provided that the required level of control, knowledge of operating conditions, communication, and coordination are maintained. Remoteness is not a legitimate factor for imposing new reliability obligations or creating an argument that existing reliability standards must be modified. The reliability standards applicable to an element of the BPS are based on the functions the element performs and the impact of the failure of the element to reliable operation of the BPS, and not on the location from which operations personnel remotely monitor and direct the activities of the element. In this regard, remote and virtual operations are simply different ways of carrying out work in a control center environment rather than a basis for different reliability standards. Cybersecurity issues related to remote operations are sometimes assumed to be managed independently of reliability. However, there are several connections between these two domains. Examples of operational consequences caused by cyber incidents on remote operations, communications, or control systems illustrate this point and can be managed via oversight using existing standards and procedures. Some consider remote access to be inherently insecure or even contrary to reliability. Remote access increases the number of points of potential failure but it also adds the capability for continued control over the system should the primary access points (e.g. the physical panel in a protected facility) be in some fashion compromised. The potential for increased risk exists

only if remote access is implemented in a fashion that creates greater risk. Another misconception is that regulatory bodies, such as oversight auditors, have a preference or require certain control center designs. None of the regulatory bodies, including NERC and FERC, have requirements or preferences related to the control center design architecture. Rather, these bodies are concerned with determining whether organizations have the control in place to meet the reliability and cybersecurity standards

required to protect the high voltage transmission system. There is also a belief that consolidation/ virtualization leads to loss of control. While consolidation does pose concentration risk if not managed properly, it can also bring numerous benefits such as improved coordination and resource utilization. Reliability is still governed by the same rules of supply and demand as before (redundancy, diversity, adequate operating procedures), regardless of consolidation. This fact sheet is intended to clarify and address some common misunderstandings in relation to the work being done to develop a reliability framework in the context of the Northern Gateway project. More information on this project is available here. This work in relation to the reliability framework serves to reinforce its focus on functions and technology neutrality, and to underpin the risk-based and accountability focused nature of discussions around remote operations. Knowing what constitutes a remote control center and not may be important for stakeholders who want to get involved in the monitoring and reliability planning activities for the plant. It’s an outcomes, connectivity and resilience-focused perspective rather than one based on the physical design.

End-of-Chapter Summary

The Remote Control Center myth buster The safety mythologies associated with Remote Control Centres (RCCs) are as much an obstacle to successful safety case development as are the more familiar myths of Automation, Complexity and Computing. It is often supposed that RCCs must reduce reliability, introduce new hazards, or require particular safety approaches. None of these supposed “myths” are true. Reliability expectations remain function-based and technology neutral. The effectiveness of remote operations is assessed in relation to the requirements for situational awareness, for exercise of authority, for coordination of tasks and for timely response, within the context of the arrangements established for oversight of remote operations.

FROM THE FIELD

"We're a remote operation, so the standards don't fully apply" is the misunderstanding that produces findings.

"The third party hosts the operation, so they're accountable" — the registered entity is accountable. Outsourcing the operation does not outsource the obligation.

"We covered this in our IT security program" — IT security and CIP overlap, but they aren't equivalent. CIP has specific evidence requirements that general IT security doesn't.

Chapter 12

Remote Operations in Practice and Ongoing Evolution

The remote and virtual control centers that are currently located in a few remote locations, are no longer considered experimental, but part of the normal bulk power system operations environment, in view of the increasing use of technology, the need for reorganization of the future work force, in preparation for potential future power disruptions as part of readiness planning for emergencies, and because of the need for increased cost efficiency in operations. The reliability of virtual control centers and the surveillance model that will apply to such stations will be based on existing reliability concepts, theories, and standards with little need for new thinking or provisions. Operation of remote control systems as more than a contingency option is important for operational reliability. Routine use of remote control in operational activities provides more predictable and effective response to emergency or unusual conditions, and it tends to help establish more stable authority and coordination relationships and more detailed understanding of the monitoring and control system’s capabilities and limitations. Why Control Centers Keep Evolving. The reason for evolution is forever changing. Sometimes it is driven by opportunity, other times by necessity. Improvements in communication, virtualization and automation technologies have opened up a wide range of new possible design options for control centers. Operational experience, disturbance analysis and feedback from surveillance all remind us that dependencies and interfaces need to be carefully considered and managed. This means that our approach to control center design has to be dynamic and evolving, not static and fixed. Riskbased oversight is a key element of this transition. Rather than specifying in detail how remote operations are to be conducted, oversight focuses on ensuring that the reliability outcomes are maintained. The nature of oversight activities will change and will be determined by the performance of the system, lessons learned from past events and emerging risk issues. Cybersecurity is expected to remain a key factor in remote operations. As control environments become more distributed and technology plays a larger role, reliable and secure access to control functions will

be a key element. Function-based cybersecurity requirements and accountability for personnel continue to address this technology-agnostic issue. Reliability in Remote Operations is further influenced by the work processes of the Organisation involved. Training, communication and role responsibility are all important for the execution of reliability tasks in a Remote Operation environment. Although not addressed in reliability standards, these elements are crucial for the effectiveness of reliability tasks

when performed remotely. The changing face of remote and virtual control centers is a continuing reminder of the overarching principle of a NERC Reliability Standards Framework of standards that embody the principle of adaptable standards with a foundation of functional accountability. The standard’s focus on performance of functions rather than specific locations or methods of performing those functions allows for evolving practices and procedures related to remote and virtual control centers. Remote control in the smart grid practice provides reliability assurance through redundancy in the operations and control of the power system. Proper understanding and consideration of dependencies, authority and coordination in the implementation of remote control provides reliable and efficient system operation. The remoteness or automation aspect of remote control is a matter of proper procedure and implementation following the well known reliability and IT security practices and rules. [FIGURE: Ongoing evolution of remote control operations within the reliability oversight framework]

End-of-Chapter Summary

Remote and virtual control centers (RVCCs) have become a common and evolving element of the bulk electric system (BES) operations. The reliability performance of RVCCs will depend on the extent to which they are considered part of normal operations, their dependencies are managed, and their work processes are carried out in an organized manner. Reliability oversight practices have adapted to these changing operations using risk-based approaches that enhance reliability accountability and performance in an evolving environment.

Glossary

Glossary

Control Center – A facility or environment which is used to perform one or more of the functions of a registered entity Transmission Operator, Balancing Authority, or Reliability Coordinator roles in a centralized, remote, backup or virtual environment.

Remote Operations Operations in which some or all of the activities from a control center are geographically away from the process equipment and facilities being controlled.

Virtual Control Environment - A control center configuration in which the operational systems are run on a virtualized or distributed server rather than on physical hardware.

Situational Awareness: The ability of operations centre personnel to sense, interpret and forecast the state of the system so as to be able to make rapid and effective operational decisions.

Reliability Coordinator - An entity with the most responsibility and authority to ensure reliability of the bulk electric system within a geographic area defined in the NERC Glossary of Terms.

Balancing Authority A Balancing Authority is an entity responsible for several functions in a power system: - Making decisions concerning scheduled interchange among power plants ahead of time based on resource plans and the supply and demand forecast. - Keeping load and generation in balance within a BA area at all times by absorbing or producing any imbalance as Shah coal. - Supporting interconnection frequency on a real time basis to restore balance.

Transmission Operator – Entity that is in charge of operating transmission facilities in real-time and ensuring that system limits are maintained within its control area.

Bulk Electric System According to the NERC Glossary of Terms, the BES consists of the facilities and control systems that constitute an interconnected electric energy transmission network and does not include facilities that are used for distribution of electric energy to consumers.

Critical Infrastructure Protection Standards - The NERC Reliability Standards that deal with managing cybersecurity risk for control systems that provide reliable operations of the bulk electric system.

Remote Access: The ability to connect to and remotely access the control center systems and interact with them from a location other than the primary control center using technology.

Risk-Based Oversight: An oversight approach which focuses NERC or Regional monitoring and enforcement efforts on those aspects requiring timely attention based on their potential to affect reliability, as opposed to uniformly enforcing all requirements.

This glossary is intended to provide a general understanding of terminology as it is used in the NERC Reliability Standards, technical reports and public reliability publications. This glossary shall not be used to interpret or modify any definitions found in the NERC Glossary of Terms.

About the Author

About the Author

Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.

Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.

Rob’s compliance authority extends across both reliability and cybersecurity domains. His work on Critical Infrastructure Protection includes audit and oversight of CIP-002 through CIP-014, scope and impact classification reviews, ESP and PSP boundary analysis, and program assessments for entities with Low, Medium, and High Impact Cyber Systems.

Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.

About Energy Compliance, Inc.

About Energy Compliance, Inc.

Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.

Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.

We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.

Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.

CIP-Focused Services

Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.

Energy Compliance services related to Critical Infrastructure Protection include, but are not limited to:

  • CIP applicability and scope analysis (CIP-002 through CIP-014)
  • Cyber asset and BES Cyber System identification and impact classification
  • Electronic Security Perimeter and Physical Security Perimeter boundary analysis
  • CIP governance and program assessments
  • Integration of cybersecurity oversight with broader reliability programs
  • Audit and enforcement support for CIP findings (non-advocacy)
  • CIP framework reviews, gap analyses, and improvement plans
  • Training focused on CIP framework, requirements, and audit expectations
  • Executive and board-level CIP awareness briefings

Services are tailored to the functional role, system impact, and regulatory posture of each organization.

ENERGY COMPLIANCE PROFESSIONAL REFERENCE

Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.

N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.

I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.

CONNECT WITH US Scan to visit

E N E RGY COMPL IAN CE , IN C. · EC-WP-206 · © 2026 · AL L RIGHTS RES E RV E D

Cybersecurity / CIP