Presentation is loading. Please wait.

Presentation is loading. Please wait.

Reliability Assurance Initiative (RAI) 101 Ben Christensen Senior Compliance Risk Analyst, Cyber Security.

Similar presentations


Presentation on theme: "Reliability Assurance Initiative (RAI) 101 Ben Christensen Senior Compliance Risk Analyst, Cyber Security."— Presentation transcript:

1 Reliability Assurance Initiative (RAI) 101 Ben Christensen Senior Compliance Risk Analyst, Cyber Security

2 Agenda Introduction to Reliability Assurance Initiative – Risk Elements – Inherent Risk Assessment (IRA) – Internal Controls Evaluation (ICE) Overview of WECC’s IRA and ICE process and documents W ESTERN E LECTRICITY C OORDINATING C OUNCIL 2

3 Introduction to RAI Implements risk based compliance monitoring and enforcement Initial discussions by NERC in 2012 Regional RAI pilots during 2013 and 2014 2014 NERC and Regions designed the risk based framework W ESTERN E LECTRICITY C OORDINATING C OUNCIL 3

4 Overview of Risk Based Framework 4 W ESTERN E LECTRICITY C OORDINATING C OUNCIL

5 Risk Elements Replaces prior actively monitored lists WECC identified region wide risk elements – 10 O&P risk elements – 6 CIP risks elements WECC identified NERC Standards and Requirements associated with risk elements W ESTERN E LECTRICITY C OORDINATING C OUNCIL 5

6 IRA Overview W ESTERN E LECTRICITY C OORDINATING C OUNCIL 6

7 What is the IRA? Review of inherent risks posed by an entity to the BPS Review of an entity’s characteristics – Such as event history, compliance history, devices owned/operated, types of transmission lines, generation portfolio, etc. IRA process is located on the WECC website IRA process W ESTERN E LECTRICITY C OORDINATING C OUNCIL 7

8 WECC’s IRA Process 8 Identify Major Inputs into IRA Review Entity Background Identify Initial List of Applicable Functions and Standards Identify and Review Applicable Risk Element Determine Monitoring Strategy W ESTERN E LECTRICITY C OORDINATING C OUNCIL

9 IRA Surveys Currently posted on WECC website Completed by Registered Entities Helps identify Entity’s inherent risks 9 W ESTERN E LECTRICITY C OORDINATING C OUNCIL

10 IRA Final Report Documents WECC’s assessments and evaluations Helps develop Registered Entity’s Compliance Oversight Plan Summary of Final Reports provided to Entity 10 W ESTERN E LECTRICITY C OORDINATING C OUNCIL

11 Internal Controls Evaluation (ICE) W ESTERN E LECTRICITY C OORDINATING C OUNCIL 11

12 What is ICE? Voluntary process WECC will evaluate internal controls related to the risks and associated standards WECC will make recommendations to strengthen controls ICE process is located on the WECC website ICE process W ESTERN E LECTRICITY C OORDINATING C OUNCIL 12

13 WECC’s ICE Process 13 Identify key controls related to risks Request controls information Test effectiveness of controls Identify how well controls address risks and provide compliance assurance W ESTERN E LECTRICITY C OORDINATING C OUNCIL

14 ICE Surveys Currently posted on WECC website Completed by Registered Entities Helps identify Entity’s internal controls 14 W ESTERN E LECTRICITY C OORDINATING C OUNCIL

15 ICE Final Report Documents WECC’s assessments and evaluations Helps develop Registered Entity’s Compliance Oversight Plan Summary of Final Report provided to Entity 15 W ESTERN E LECTRICITY C OORDINATING C OUNCIL

16 How will WECC use IRA and ICE? WECC can better tailor compliance monitoring activities using existing CMEP tools (i.e., audits, spot checks, or self-certifications) WECC may use the results to focus the depth and scope of monitoring engagements Not a one size fits all but a risk based approach W ESTERN E LECTRICITY C OORDINATING C OUNCIL 16

17 Additional Resources NERC RAI Page NERC Risk Elements Guide WECC CMEP IP IRA – IRA Process IRA Process – IRA Survey template IRA Survey template – IRA Report template IRA Report template ICE – ICE Process ICE Process – O&P ICE Survey O&P ICE Survey – CIP ICE Survey CIP ICE Survey 17 W ESTERN E LECTRICITY C OORDINATING C OUNCIL


Download ppt "Reliability Assurance Initiative (RAI) 101 Ben Christensen Senior Compliance Risk Analyst, Cyber Security."

Similar presentations


Ads by Google