NERC Releases Draft Standard for Cybersecurity Supply Chain Risk Management
Time 1 Minute Read

On January 19, 2017, the North American Electric Reliability Corporation (“NERC”) released a draft Reliability Standard CIP-013-1 – Cyber Security – Supply Chain Risk Management (the “Proposed Standard”). The Proposed Standard addresses directives of the Federal Energy Regulatory Commission (“FERC”) in Order No. 829 to develop a new or modified reliability standard to address “supply chain risk management for industrial control system hardware, software, and computing and networking services associated with bulk electric system operations.” 

The Proposed Standard requires each affected entity to develop and implement a cybersecurity risk management plan that addresses the following security objectives: (1) software integrity and authenticity, (2) vendor remote access, (3) information system planning and (4) vendor risk management and procurement controls.

NERC will host a webinar on February 2, 2017 to discuss the Proposed Standard and respond to questions from webinar participants. A formal comment period for the Proposed Standard is now open and will remain open through 8 p.m. ET on Monday, March 6, 2017. NERC must file the final version of the Proposed Standard with FERC by September 27, 2017.

You May Also Be Interested In

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Time 1 Minute Read

On January 26, 2026, the Brazilian data protection authority (“ANPD”) announced that Brazil and the European Union agreed to mutually recognize the adequacy of each other’s data protection networks.

Time 2 Minute Read

On January 8, 2026, the California Privacy Protection Agency announced enforcement activity against Rickenbacher Data LLC d/b/a Datamasters and S&P Global Inc. for failing to register as data brokers in California.

Time 2 Minute Read

On December 17, 2025, the California Privacy Protection Agency announced the release of its Enforcement Advisory No. 2025-01, reminding data brokers of their obligations under California’s Delete Act.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page