Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

FERC Proposes to Direct NERC to Revise Cyber Proposal on Malware Risks

By Meghan Mandel & Daniel Archuleta on October 24, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

On October 19, 2017, FERC issued a Notice of Proposed Rulemaking (“NOPR”) proposing to direct the North American Electric Reliability Corporation (“NERC”) to modify the Critical Infrastructure Protection (“CIP”) Reliability Standard, CIP-003-7 (Cyber Security – Security Management Controls), which is intended to mitigate cyber security risks posed by malware from ‘transient electronic devices’ (such as laptops and thumb drives) used at low-impact cyber systems.  FERC stated in the NOPR that, once those modifications have been made, it plans to make the new reliability standard effective approximately 18 months after FERC approval.

As background, on January 21, 2016, in Order No. 822, FERC approved seven CIP Reliability Standards that addressed the risks presented by transient electronic devices, such as laptops and thumb drives, used at high- and medium-impact cyber systems.  At that time, FERC also directed NERC to modify the CIP Reliability Standards to provide similar protection for similar transient electronic devices used at low-impact cyber systems.  On March 3, 2017, NERC submitted the proposed Reliability Standard CIP-003-7 to address low-impact cyber systems.

In its October 19 NOPR, FERC proposed to approve NERC’s Reliability Standard CIP-003-7 and related proposals pending NERC’s modifications to the standard.  While FERC determined that the proposed standard improved upon the current FERC-approved CIP Reliability Standards, FERC redirected NERC to make additional modifications to CIP-003-7.  Specifically, FERC ordered NERC to (1) develop criteria regarding electronic access controls for low-impact cyber systems and (2) address the mitigation of risks posed by third-party transient electronic devices.

Comments on FERC’s NOPR are due sixty (60) days after publication in the Federal Register.  A copy of the order may be found here.

 

Photo of Daniel Archuleta Daniel Archuleta

Daniel Archuleta helps energy clients handle critical matters, especially those pertaining to the FERC in both the gas pipeline and electric utility industries.

Read more about Daniel ArchuletaEmail
  • Posted in:
    Energy and Utilities, Privacy and Cybersecurity
  • Blog:
    Washington Energy Report
  • Organization:
    Troutman Pepper Locke
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo