2021-28206. Commission Information Collection Activity (FERC-725B4); Comment Request; Extension  

  • Start Preamble

    AGENCY:

    Federal Energy Regulatory Commission, Department of Energy.

    Start Printed Page 73753

    ACTION:

    Notice of information collection and request for comments.

    SUMMARY:

    In compliance with the requirements of the Paperwork Reduction Act of 1995, the Federal Energy Regulatory Commission (Commission or FERC) is soliciting public comment on the information collection requirements associated with Reliability Standards CIP-004-7 and CIP-011-3 in Docket No. RD21-6-000. The burden for the requirements will be included in FERC-725B4 (Mandatory Reliability Standards for Critical Infrastructure Protection [CIP] Reliability Standards).

    DATES:

    Comments on the collections of information are due February 28, 2022.

    ADDRESSES:

    You may submit your comments (identified by Docket No. RD21-6-000) on FERC-725B4 by one of the following methods:

    Electronic filing through http://www.ferc.gov is preferred.

    Electronic Filing: Documents must be filed in acceptable native applications and print-to-PDF, but not in scanned or picture format.

    • For those unable to file electronically, comments may be filed by USPS mail or by hand (including courier) delivery:

    Mail via U.S. Postal Service Only: Addressed to: Federal Energy Regulatory Commission, Secretary of the Commission, 888 First Street NE, Washington, DC 20426.

    Hand (including courier) delivery: Deliver to: Federal Energy Regulatory Commission, 12225 Wilkins Avenue, Rockville, MD 20852.

    Instructions: All submissions must be formatted and filed in accordance with submission guidelines at: http://www.ferc.gov. For user assistance, contact FERC Online Support by email at ferconlinesupport@ferc.gov, or by phone at (866) 208-3676 (toll-free).

    Docket: Users interested in receiving automatic notification of activity in this docket or in viewing/downloading comments and issuances in this docket may do so at http://www.ferc.gov.

    Start Further Info

    FOR FURTHER INFORMATION CONTACT:

    Ellen Brown may be reached by email at DataClearance@FERC.gov, or by telephone at (202) 502-8663.

    End Further Info End Preamble Start Supplemental Information

    SUPPLEMENTARY INFORMATION:

    Title: FERC-725B4, Mandatory Reliability Standards: Critical Infrastructure Protection Reliability Standards CIP-004-7 and CIP-011-3.[1]

    OMB Control No.: TBD.

    Type of Request: Approval of proposed changes as described in Docket No. RD21-6-000.

    Abstract: On September 15, 2021 the North American Electric Reliability Corporation (NERC) filed a petition requesting approval of two Reliability Standards CIP-004-7 (Cyber Security, Personnel and Training) and CIP-011-3 (Cyber Security, Information Protection). NERC described the proposed Reliability Standards as “Addressing Bulk Electric System Cyber System Information Access Management.” The petition was noticed on September 22, 2021, with interventions and comments due by October 6, 2021.[2] The Commission did not receive any interventions or comments.

    On December 7, 2021, the Designated Letter Order (DLO) in Docket No. RD21-6-000 approved the proposed Reliability Standards, and found that the modified Reliability Standards enhance security as discussed below.

    At present, Reliability Standards CIP-004-6 require Responsible Entities to control access to Bulk Electric System Cyber System Information (BCSI) by managing access to a designated storage location, such as an electronic document or physical file room. Reliability Standard CIP-004-7 removes references to “designated storage locations” of BCSI and requires an access management program to authorize, verify and revoke provisioned access to BCSI. This change updates CIP-004 by focusing on controls at the file level ( e.g., rights, permissions, privileges) of BCSI and reduces the need for access to only a physical, designated storage location for BCSI.

    Reliability Standard CIP-011-3 clarifies the requirements of protecting and handling BCSI with the goal of providing flexibility for Responsible Entities to use third-party data storage and analysis systems. Specifically, Reliability Standard CIP-011-3 requires Responsible Entities to implement specific controls related to BCSI during storage handling use, and disposal of information when implementing services provided by third parties.

    Type of Respondents: Businesses and other for-profit entities.

    Estimate of Annual Burden: The Commission estimates 686 responses annually, and per-response burdens of 10 hours and $850.20. The total estimated burdens per year are 6,860 hours and $583,237.20. These burdens are itemized in the following table:

    A. Number of respondents 3B. Annual number of responses per respondentC. Total number of responsesD. Average burden hours 4 & cost per response 5E. Total annual burden hours & total annual cost 6F. Cost per respondent ($)
    (Column A × Column B)(Column C × Column D)(Column E ÷ Column A)
    CIP-004-7343134310 hours & $850.203,430 hours & $291,619.6010 hours & $850.20.
    CIP-011-3343134310 hours & $850.203,430 hours & $291,619.6010 hours & $850.20.
    Totals6866,860 hours & $583,237.2020 hours & $1,700.40
    Start Printed Page 73754

    Comments are invited on: (1) Whether the collection of information is necessary for the proper performance of the functions of the Commission, including whether the information will have practical utility; (2) the accuracy of the agency's estimate of the burden and cost of the collection of information, including the validity of the methodology and assumptions used; (3) ways to enhance the quality, utility and clarity of the information collection; and (4) ways to minimize the burden of the collection of information on those who are to respond, including the use of automated collection techniques or other forms of information technology.

    Start Signature

    Dated: December 21, 2021.

    Kimberly D. Bose,

    Secretary.

    End Signature End Supplemental Information

    Footnotes

    1.  FERC-725B4 is an interim information collection number to accommodate the need to seek timely approval during the pendency of an unrelated information collection request pertaining to FERC-725B (OMB Control No. 1902-0248). In addition, the implementation plan for CIP-004-7 and CIP-011-3 provides that those Reliability Standards become effective on the first day of the first calendar quarter that is 24 calendar months after the effective date of the Commission's order, so that Responsible Entities have sufficient time to come into compliance with the revised Reliability Standards. Thus, FERC-725B continues to cover the current requirements of the standards, before implementation of the revised requirements of Docket No. RD21-6-000.

    Back to Citation

    3.  The number of respondents is based on the NERC Compliance Registry as of June 22, 2021. Currently there are 1,508 unique NERC Registered Entities, subtracting 16 Canadians Entities yields 1,492 U.S. NERC Registered Entities subject to the CIP Standards. However, only those NERC Registered Entities that own Medium Impact or High Impact BES Cyber System are subject to the CIP Standards in this filing which is estimated to be 343 NERC Registered Entities.

    4.  Of the average estimated twenty (20) hours per response, all twenty (20) hours are for the one-time effort of updating or changing documentation for record-keeping burden that is already accounted for.

    5.  Commission staff estimates that the average industry hourly cost for this information collection is $85.02/hour based on the following occupations from the Bureau of Labor Statistics: (1) Manager (Occupational Code: 11-0000): $97.89/hour; and (2) Electrical Engineer (Occupational Code 17-2071): $72.15/hour. Source: http://bls.gov/​oes/​current/​naics3_​221000.htm,, as of June 2021.

    Back to Citation

    [FR Doc. 2021-28206 Filed 12-27-21; 8:45 am]

    BILLING CODE 6717-01-P

Document Information

Published:
12/28/2021
Department:
Federal Energy Regulatory Commission
Entry Type:
Notice
Action:
Notice of information collection and request for comments.
Document Number:
2021-28206
Dates:
Comments on the collections of information are due February 28, 2022.
Pages:
73752-73754 (3 pages)
Docket Numbers:
Docket No. RD21-6-000
PDF File:
2021-28206.pdf