From: Lexology
At today’s open meeting, the Federal Energy Regulatory Commission (FERC) proposed to approve new Critical Infrastructure Protection (CIP) Reliability Standards developed by the North American Electric Reliability Corporation (NERC) to protect the cybersecurity of the supply chains for critical utility systems. While recognizing the benefits of using a global supply chain to produce the assets used to operate the bulk electric system, FERC staff’s accompanying presentation recognized that relying on a global supply chain “also enables opportunities for adversaries to directly or indirectly affect the management or operations of generation and transmission companies in a manner that may result in risks to end users, such as through the insertion of counterfeits, unauthorized production, tampering, theft, or insertion of malicious software.”
NERC’s proposed standards were developed in response to a commission directive and would require registered entities to develop a plan to mitigate supply chain cybersecurity risks posed by vendor products and services, particularly during the vendor procurement process. Morgan Lewis’s overview of the new standards is available here. If ultimately adopted by FERC, these standards could significantly alter the procurement process for utilities purchasing new assets and services for their critical IT infrastructure. . . .
Leave a Reply