IP-011.1 Implement one or more documented information protection program(s) IP-011 IP-011.1

Each Responsible Entity shall implement one or more documented information protection program(s) that collectively includes each of the applicable requirement parts of Information Protection. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning].
Evidence for the information protection program must include the applicable requirement parts of Information Protection and additional evidence to demonstrate implementation as described in the Measures section.

IP-011.2 Implement one or more documented process(es) for BES Cyber Asset Reuse and Disposal IP-011 IP-011.2

Each Responsible Entity shall implement one or more documented process(es) that collectively include the applicable requirement parts of BES Cyber Asset Reuse and Disposal. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning].
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of BES Cyber Asset Reuse and Disposal and additional evidence to demonstrate implementation as described in the Measures section.

PS-014.1 Perform an initial risk assessment and subsequent risk assessments of Transmission stations and Transmission substations PS-014 PS-014.1

Each Transmission Owner shall perform an initial risk assessment and subsequent risk assessments of its Transmission stations and Transmission substations (existing and planned to be in service within 24 months) that meet the criteria specified in Applicability Section 4.1.1. The initial and subsequent risk assessments shall consist of a transmission analysis or transmission analyses designed to identify the Transmission station(s) and Transmission substation(s) that if rendered inoperable or damaged could result in instability, uncontrolled separation, or Cascading within an Interconnection. [VRF: High; Time-Horizon: Long-term Planning]
Examples of acceptable evidence may include, but are not limited to, dated written or electronic documentation of the risk assessment of its Transmission stations and Transmission substations (existing and planned to be in service within 24 months) that meet the criteria in Applicability Section 4.1.1 as specified in Requirement 014.1. Additionally, examples of acceptable evidence may include but are not limited to, dated written or electronic documentation of the identification of the primary control center that operationally controls each Transmission station or Transmission substation identified in the Requirement 014.1 risk assessment as specified in Requirement 014.1, Part 1.2.

PS-014.2 Have an unaffiliated third party verify the risk assessment PS-014 PS-014.2

Each Transmission Owner shall have an unaffiliated third party verify the risk assessment performed under Requirement 014.1. The verification may occur concurrently with or after the risk assessment performed under Requirement 014.1. [VRF: Medium; Time-Horizon: Long-term Planning]
Examples of acceptable evidence may include, but are not limited to, dated written or electronic documentation that the Transmission Owner completed an unaffiliated third-party verification of the Requirement 014.1 risk assessment and satisfied all of the applicable provisions of Requirement 014.2, including, if applicable, documenting the technical basis for not modifying the Requirement 014.1 identification as specified under Part 2.3. Additionally, examples of evidence may include but are not limited to, written or electronic documentation of procedures to protect information under Part 2.4.

PS-014.3 Notify the Transmission Operator regarding the identification and the date of completion of Requirement 014.2 PS-014 PS-014.3

For a primary control center(s) identified by the Transmission Owner according to Requirement 014.1, Part 1.2 that a) operationally controls an identified Transmission station or Transmission substation verified according to Requirement 014.2, and b) is not under the operational control of the Transmission Owner: the Transmission Owner shall, within seven calendar days following completion of Requirement 014.2, notify the Transmission Operator that has operational control of the primary control center of such identification and the date of completion of Requirement 014.2. [VRF: Lower; TimeHorizon: Long-term Planning]
Examples of acceptable evidence may include, but are not limited to, dated written or electronic notifications or communications that the Transmission Owner notified each Transmission Operator, as applicable, according to Requirement 014.3.

PS-014.4 Conduct an evaluation of the potential threats and vulnerabilities of a physical attack on each Transmission station(s), Transmission substation(s), and primary control center(s) PS-014 PS-014.4

Each Transmission Owner that identified a Transmission station, Transmission substation, or a primary control center in Requirement 014.1 and verified according to Requirement 014.2, and each Transmission Operator notified by a Transmission Owner according to Requirement 014.3, shall conduct an evaluation of the potential threats and vulnerabilities of a physical attack to each of their respective Transmission station(s), Transmission substation(s), and primary control center(s) identified in Requirement 014.1 and verified according to Requirement 014.2. The evaluation shall consider the following: [VRF: Medium; Time-Horizon: Operations Planning, Long-term Planning]
Examples of evidence may include, but are not limited to, dated written or electronic documentation that the Transmission Owner or Transmission Operator conducted an evaluation of the potential threats and vulnerabilities of a physical attack to their respective Transmission station(s), Transmission substation(s) and primary control center(s) as specified in Requirement 014.4.

PS-014.5 Develop and implement a documented physical security plan(s) of each Transmission station(s), Transmission substation(s), and primary control center(s) PS-014 PS-014.5

Each Transmission Owner that identified a Transmission station, Transmission substation, or primary control center in Requirement 014.1 and verified according to Requirement 014.2, and each Transmission Operator notified by a Transmission Owner according to Requirement 014.3, shall develop and implement a documented physical security plan(s) that covers their respective Transmission station(s), Transmission substation(s), and primary control center(s). The physical security plan(s) shall be developed within 120 calendar days following the completion of Requirement 014.2 and executed according to the timeline specified in the physical security plan(s). The physical security plan(s) shall include the related parts. [VRF: High; Time Horizon: Long-term Planning]
Examples of evidence may include, but are not limited to, dated written or electronic documentation of its physical security plan(s) that covers their respective identified and verified Transmission station(s), Transmission substation(s), and primary control center(s) as specified in Requirement 014.5, and additional evidence demonstrating execution of the physical security plan according to the timeline specified in the physical security plan.

PS-014.6 Have an unaffiliated third party review the evaluation of Requirement 014.4 and the security plan(s) developed under Requirement 014.5 PS-014 PS-014.6

Each Transmission Owner that identified a Transmission station, Transmission substation, or primary control center in Requirement 014.1 and verified according to Requirement 014.2, and each Transmission Operator notified by a Transmission Owner according to Requirement 014.3, shall have an unaffiliated third party review the evaluation performed under Requirement 014.4 and the security plan(s) developed under Requirement 014.5. The review may occur concurrently with or after completion of the evaluation performed under Requirement 014.4 and the security plan development under Requirement 014.5. [VRF: Medium; Time-Horizon: Long-term Planning]
Examples of evidence may include, but are not limited to, written or electronic documentation that the Transmission Owner or Transmission Operator had an unaffiliated third party review the evaluation performed under Requirement 014.4 and the security plan(s) developed under Requirement 014.5 as specified in Requirement 014.6 including, if applicable, documenting the reasons for not modifying the evaluation or security plan(s) in accordance with a recommendation under Part 6.3. Additionally, examples of evidence may include but are not limited to, written or electronic documentation of procedures to protect information under Part 6.4.

Main Menu