Newsroom  •  Site Map  •  Contact NERC

  
Advanced Search
 
About NERC Standards Compliance Assessments Events Analysis Programs  


Project 2008-14
Cyber Security Violation Severity Levels


Related Files

Status:

The Violation Severity Levels have been approved by the NERC Board of Trustees and filed with FERC.

Purpose/Industry Need:

The FERC, In Order 706 (Mandatory Reliability Standards for Critical Infrastructure Protection) (Issued January 18, 2008) approved eight Critical Infrastructure Protection (CIP) Reliability Standards directs NERC to develop modifications to the CIP Reliability Standards to address specific concerns. The Order also states that NERC should file Violation Severity Levels before the auditable compliant stage.

Since the CIP Standards have been approved and are enforceable, the “Levels of Non-Compliance” must be replaced with “Violation Severity Levels”. This is in accordance with the Order on Compliance Filing dated June 7, 2007 (Docket #RR06-1-007), which directed NERC to replace the ‘Levels of Non-compliance’ (in the 83 standards it approved) with ‘Violation Severity Levels.’ It also requires development of Violation Severity Levels of new or revised standards.

This project will meet the FERC directives regarding the development of Violation Severity Levels (VSL) for the cyber group of standards: CIP-002-1 – Critical Cyber Asset Identification, CIP-003-1 – Security Management Controls, CIP-004-1 – Personnel and Training, CIP-005-1 – Electronic Security Perimeter(s), CIP-006-1 – Physical Security of Critical Cyber Assets, CIP-007-1 – Systems Security Management, CIP-008-1 – Incident Reporting & Response Planning, CIP-009-1 – Recovery Plans for Critical Cyber Assets.
 

Draft Action Dates Results Consideration of Comments
 Version 1 Violation Severity Levels for CIP-002-1 through CIP-009-1

Version 1 VSLs
Clean  |  Redline to last posting Corrected on 05/27/09*

Final SAR

*Correction: 
Regarding the posting announced on May 26, 2009, errors were discovered in the Violation Severity Levels (VSLs) for CIP-005-1 Requirement R5.3 and CIP-006-1 Requirement R5.  Corrections have been applied to the documents posted below:  

  • The “clean” version shows the above corrections as tracked changes
  • The “redline to last posting” version shows all changes since the last comment period, including the above corrections, as tracked changes
Recirculation Ballot

Info>> | Vote>>
07/07/09 - 07/16/09
(closed)
Summary>>

Full Record>>


Initial Ballot

Info>> | Vote>>
06/15/09 - 06/24/09
(closed)
Summary>>

Full Record>>
Consideration of Comments>>
Pre-ballot Review

Info>> | Join>>
05/26/09 - 06/15/09
(closed)
   
 
Version 1 Violation Severity Levels for CIP-002-1 through CIP-009-1 and Draft SAR Version 2

Version 1 VSLs

Draft SAR Version 2
clean | redline

Supporting Materials:
Complete set of materials for commenting on Project 2008-06 and Project 2008-14 (zip)
Comment Period

Info>>

Submit Comments>>
*Please submit only one comment form.  The form covers Project 2008-06 and Project 2008-14.
03/16/09 - 04/20/09
(closed)



Comments Received>> Consideration of Comments>>
 
Cyber Security VSL SAR

Draft SAR Version 1


Supporting Materials:
Comment Form (Word)
Comment Period

Info>>
Submit Comments>>

01/12/09 - 02/10/09
(closed)
Comments Received>> Consideration of Comments>>
To download a file click on the file using your right mouse button, then save it to your computer in a directory of your choice.

Documents in the PDF format require use of the Adobe Reader® software.  Free Adobe Reader® software allows anyone view and print Adobe Portable Document Format (PDF) files.   For more information download the Adobe Reader User Guide.


All comments should be forwarded to sarcomm@nerc.net.