FERC Staff Provides “Lessons Learned” from Critical Infrastructure Protection Reliability Standard Audits

Nov 5, 2021

Reading Time : 2 min

The report is based on nonpublic audits of NERC “registered entities”1 subject to the CIP reliability standards that were conducted by FERC’s Office of Electric Reliability and Office of Enforcement, in collaboration with NERC and its regional reliability entities. In addition, while FERC’s Office of Energy Infrastructure Security (OEIS) was not involved in the audits, its Office of Electric Reliability “consulted with OEIS” in preparing the report. OEIS is responsible for “identification and implementation of best practices to address current and emerging defense and mitigation strategies for advanced cyber and physical threats to not only the Bulk-Power System but all energy infrastructure” under FERC’s jurisdiction.

This year, FERC staff “found that while most of the cybersecurity protection processes and procedures adopted by the registered entities met the mandatory requirements of the CIP Reliability Standards, there were also potential compliance infractions.” Such infractions can create significant risk and result in penalties that vary depending on the severity of the risk they present. FERC staff “also identified practices not required by the CIP Reliability Standards that could improve security.” The report includes those as “voluntary cyber security recommendations.” These recommendations are relevant not only for registered entities, but “may be generally beneficial to the utility-based cybersecurity community” to improve the security of the bulk electric system.

The report’s overview of “lessons learned” lists 14 principal recommendations, including:

  • “Enhanc[ing] policies and procedures to include evaluation of Cyber Asset misuse and degradation during asset categorization.”2
  • “Properly document[ing] and implement[ing] policies, procedures and controls for low-impact transient cyber assets.”
  • “Enhanc[ing] recovery and testing plans to include a sample of any offsite backup images in the representative sample of data used to test the restoration of bulk-electric system cyber systems.”
  • “Improv[ing] vulnerability assessments to include credential-based scans of cyber assets.”
  • “Enhanc[ing] internal compliance and controls programs to include control documentation processes and associated procedures pertaining to compliance with the CIP Reliability Standards.”

For each of its 14 recommendations, the report discusses the related audit findings and ties each recommendation to the specific CIP reliability standard(s) and requirement(s) to which it applies. The report also provides the “lessons learned” from four prior annual reports, illustrating how FERC staff’s audit findings and recommendations have evolved over time. This year’s report highlights FERC’s and NERC’s ongoing focus on registered entities’ compliance with the CIP reliability standards and should be required reading for both registered entities and other owners and operators of assets on the U.S. electric grid in connection with the development and implementation of their cybersecurity programs.


1 As FERC staff explained in the report, “[a]ll Bulk-Power System users, owners and operators are required to register with NERC and, once registered, are commonly referred to as ‘registered entities.’”

2The NERC Glossary defines “Cyber Assets” as “programmable electronic devices, including the hardware, software, and data in those devices.”

 

Share This Insight

Previous Entries

Speaking Energy

June 12, 2025

We are pleased to share the presentation slide deck and a recording of Akin’s recently presented webinar, “Navigating U.S. Policy Shifts in the Critical Minerals Sector.”

...

Read More

Speaking Energy

June 10, 2025

On June 4, 2025, the U.S. Department of Transportation’s (DOT) Pipeline and Hazardous Materials Safety Administration (PHMSA) announced revisions to its procedures for pipeline safety enforcement actions. The changes, outlined in two new policy memoranda from PHMSA’s Office of the Chief Counsel (PHC), aim to enhance due process protections for pipeline operators by clarifying how civil penalties are calculated and expanding the disclosure of agency records in enforcement proceedings.

...

Read More

Speaking Energy

May 22, 2025

On May 19, 2025, the Department of Energy (DOE) finalized its 2024 LNG Export Study: Energy, Economic and Environmental Assessment of U.S. LNG Exports (the 2024 Study) through the release of a Response to Comments on the 2024 Study. The Response to Comments concludes that the 2024 Study, as augmented through public comments submitted on or before March 20, 2025, supporting a finding that liquefied natural gas (LNG) exports serve the public interest. With the comment process complete, DOE will move forward with final orders on pending applications to export LNG to non-free trade agreement (non-FTA) countries.

...

Read More

Speaking Energy

May 20, 2025

On Thursday, May 15, the Senate Commerce, Science & Transportation Subcommittee on Surface Transportation, Freight, Pipelines and Safety held a hearing titled, “Pipeline Safety Reauthorization: Ensuring the Safe and Efficient Movement of American Energy.” The hearing examined legislative priorities for reauthorizing the Pipeline and Hazardous Materials Safety Administration (PHMSA).

...

Read More

Speaking Energy

April 15, 2025

On April 9, 2025, President Trump issued an executive order (EO)1 directing several federal agencies and subagencies that regulate energy, environmental, and conservation matters,2 including the Federal Energy Regulatory Commission (FERC) and the Department of Energy (DOE), to establish conditional sunset dates for “regulations governing energy production.” The stated objective of the EO is to require agencies to periodically reexamine their regulations to ensure that they continue to serve the public good. For FERC, the order covers regulations promulgated under the Federal Power Act (FPA), the Natural Gas Act (NGA) and the Powerplant and Industrial Fuel Use Act (FUA)3, as amended, while DOE must consider regulations promulgated under the Atomic Energy Act (AEA), the National Appliance Energy Conservation Act, the Energy Policy Act of 1992 (EPAct 1992), the Energy Policy Act of 2005 (EPAct 2005) and the Energy Independence and Security Act of 2007 (EISA), as amended (collectively the Covered Regulations).4 To the extent the DOE has been directed to promulgate regulations under various sections of the NGA, FPA and FUA, and FERC has been directed to promulgate regulations specific to the statutes attributed to the DOE in the EO, the EO is silent. The EO expressly does not apply to those “regulatory permitting regimes authorized by statute.”5

...

Read More

Speaking Energy

April 10, 2025

On April 8, 2025, President Trump issued an Executive Order (EO) directing the Department of Energy (DOE) to take steps to expand the use of its emergency authority under Federal Power Act (FPA) Section 202(c) to require the retention of generation resources deemed necessary to maintain resource adequacy within at risk-regions of the bulk power system regulated by the Federal Energy Regulatory Commission (FERC).1 The EO appears to envision a more active role for DOE in overseeing and supporting the resource adequacy of the grid that deviates from the historic use of Section 202(c) and touches on issues at the intersection of state and federal authority over resource planning.

...

Read More

Speaking Energy

March 10, 2025

On March 5, 2025, the United States Department of Energy (DOE) approved Golden Pass LNG Terminal LLC’s (GPLNG) request to extend a deadline to begin exporting liquefied natural gas (LNG) from its terminal facility currently under construction in Sabine Pass, Texas for 18 months, from September 30, 2025, to March 31, 2027 (the Order). The Order amends GPLNG’s two existing long-term orders authorizing the export of domestically produced LNG to countries with which the United States does and does not have free trade agreements (FTA).1  The Order does not amend the authorizations’ end date, which remains December 31, 2050. Under section 3 of the Natural Gas Act (NGA), the DOE may authorize exports to non-FTA countries following completion of a “public interest” review, whereas exports to FTA countries are deemed to be in the public interest and the DOE is directed to issue authorizations without modification or delay.

...

Read More

Speaking Energy

March 4, 2025

Join projects & energy transition partner Shariff Barakat at Infocast’s Solar & Wind, where he will moderate the “Tax Equity Market Dynamics” panel.

...

Read More

© 2025 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.