-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathprofile.json
More file actions
196 lines (196 loc) · 10.8 KB
/
Copy pathprofile.json
File metadata and controls
196 lines (196 loc) · 10.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
{
"evidence_bundle_profile_version": "0.1",
"profile_id": "nerc-cip-readiness-v0.1",
"title": "NERC CIP + TSA + DOE + FERC Readiness Evidence Bundle",
"purpose": "Profile of the Evidence Bundle spec scoped to electric utilities, grid operators (ISO/RTOs, balancing authorities, transmission operators), pipeline operators, and AI vendors providing tools that touch BES Cyber Systems, pipeline SCADA, or wholesale market operations. Covers NERC Reliability Standards CIP-002 through CIP-014 + NERC operating procedures + TSA Security Directive SD-2021-02C (pipeline cybersecurity post-Colonial) + DOE EO 14028 implementation + FERC Order 2222 (DER aggregation fairness) + state PUC prudency review baseline. NOT a NERC audit attestation. NOT a substitute for the registered entity's regional-entity-led CIP-V5/V6 audit cycle.",
"applies_to": [
"investor-owned-utility",
"publicly-owned-utility",
"cooperative-utility",
"iso-rto-operator",
"regional-transmission-organization",
"balancing-authority",
"transmission-operator",
"transmission-owner",
"generator-operator",
"generator-owner",
"interstate-gas-pipeline-operator",
"intrastate-gas-pipeline-operator",
"ai-vendor-providing-tools-to-bes-environment"
],
"obligation_families": [
{
"code": "cip-002-bes-categorization",
"title": "BES Cyber System Categorization (CIP-002-5.1a)",
"citation": "NERC Reliability Standard CIP-002-5.1a",
"summary": "Identify and categorize BES Cyber Systems as HIGH-IMPACT, MEDIUM-IMPACT, or LOW-IMPACT per the categorization methodology in CIP-002 Attachment 1. AI tools that read or recommend on BES Cyber Systems inherit the categorization tier.",
"required_evidence_kinds": [
"bes-cyber-system-inventory-with-categorization",
"annual-categorization-review-record",
"ai-tool-to-bes-cyber-system-mapping",
"categorization-change-management-log"
]
},
{
"code": "cip-005-electronic-security-perimeter",
"title": "Electronic Security Perimeter (CIP-005)",
"citation": "NERC Reliability Standard CIP-005-7",
"summary": "Identify Electronic Security Perimeters (ESPs) around BES Cyber Systems; control all inbound and outbound communications crossing the ESP. AI tools that cross the ESP boundary require explicit Interactive Remote Access controls.",
"required_evidence_kinds": [
"esp-diagram-current",
"ai-tool-esp-crossing-inventory",
"interactive-remote-access-attestation-for-ai-tools",
"ot-it-data-diode-attestation",
"vendor-remote-access-session-recording-policy"
]
},
{
"code": "cip-007-system-security-management",
"title": "System Security Management (CIP-007)",
"citation": "NERC Reliability Standard CIP-007-6",
"summary": "Ports and services management, security patch management, malicious code prevention, security event monitoring, system access control for BES Cyber Systems. AI tools deployed in BES environment inherit these requirements.",
"required_evidence_kinds": [
"patch-management-policy-for-ai-tools",
"ports-and-services-attestation-for-ai-tool-hosts",
"malicious-code-prevention-on-ai-tool-hosts",
"security-event-monitoring-coverage-for-ai-tools",
"system-access-control-record"
]
},
{
"code": "cip-008-incident-reporting",
"title": "Incident Reporting and Response Planning (CIP-008)",
"citation": "NERC Reliability Standard CIP-008-6",
"summary": "Cyber Security Incident response plan + reporting to E-ISAC. AI-implicated incidents must reach E-ISAC within the 1-hour notification window per CIP-008-6. The audit-stream's CIP-008 wall-clock invariant binds to this.",
"required_evidence_kinds": [
"cyber-security-incident-response-plan-current",
"annual-response-plan-test-record",
"ai-implicated-incident-classification-policy",
"e-isac-reporting-pathway-attestation",
"1-hour-notification-window-drill-record"
]
},
{
"code": "cip-010-configuration-change-mgmt",
"title": "Configuration Change Management + Vulnerability Assessments (CIP-010)",
"citation": "NERC Reliability Standard CIP-010-5",
"summary": "Baseline configurations for BES Cyber Systems, change management for configuration changes, vulnerability assessments. AI tool deployments + updates are configuration changes requiring CIP-010 process.",
"required_evidence_kinds": [
"ai-tool-baseline-configuration",
"ai-tool-update-change-management-record",
"vulnerability-assessment-pre-deployment",
"vulnerability-assessment-annual-recurrence",
"ai-model-version-change-treated-as-configuration-change-attestation"
]
},
{
"code": "cip-011-information-protection",
"title": "Information Protection (CIP-011)",
"citation": "NERC Reliability Standard CIP-011-3",
"summary": "Protect BES Cyber System Information (BCSI) from unauthorized disclosure. AI tools that ingest BCSI for training, fine-tuning, or inference must demonstrate BCSI handling per CIP-011.",
"required_evidence_kinds": [
"bcsi-handling-policy-for-ai-tools",
"no-training-data-use-on-bcsi-contract-clause",
"bcsi-classification-and-labeling-record",
"bcsi-storage-and-transmission-encryption-attestation"
]
},
{
"code": "cip-013-supply-chain-risk-mgmt",
"title": "Supply Chain Risk Management (CIP-013)",
"citation": "NERC Reliability Standard CIP-013-3",
"summary": "Identify and assess supply chain cybersecurity risks for vendors providing products and services to BES Cyber Systems. AI vendors are first-class scope-relevant suppliers when their tools touch BES.",
"required_evidence_kinds": [
"ai-vendor-supply-chain-risk-assessment",
"vendor-incident-notification-contract-clause",
"vendor-cybersecurity-event-coordination-attestation",
"remote-vendor-access-control-policy",
"vendor-product-vulnerability-disclosure-policy"
]
},
{
"code": "cip-014-physical-security",
"title": "Physical Security (CIP-014)",
"citation": "NERC Reliability Standard CIP-014-3",
"summary": "Identify critical transmission stations and substations; develop physical security plans for those identified. AI tools that recommend actions affecting CIP-014 critical assets inherit physical-security awareness obligations.",
"required_evidence_kinds": [
"cip-014-critical-asset-inventory",
"ai-tool-cip-014-asset-awareness-attestation",
"physical-security-incident-coordination-with-ai-output"
]
},
{
"code": "tsa-pipeline-cybersecurity",
"title": "TSA Pipeline Cybersecurity (SD-2021-02C)",
"citation": "TSA Security Directive Pipeline-2021-02C (Revised, July 2022) + subsequent renewals",
"summary": "Critical pipeline owners and operators must implement specific cybersecurity controls including OT/IT segmentation, access controls, continuous monitoring, and 12-hour incident reporting to CISA + TSA. AI tools touching pipeline SCADA fall in scope.",
"required_evidence_kinds": [
"tsa-cybersecurity-implementation-plan",
"ot-it-segmentation-attestation-for-ai-tools",
"12-hour-cisa-tsa-incident-reporting-drill-record",
"ai-tool-continuous-monitoring-coverage-attestation"
]
},
{
"code": "doe-eo-14028-implementation",
"title": "DOE EO 14028 Implementation",
"citation": "DOE implementation of Executive Order 14028 + CISA Binding Operational Directives",
"summary": "Federal cybersecurity baseline for energy-sector AI tools — SBOM, zero-trust architecture, multi-factor authentication, endpoint detection + response.",
"required_evidence_kinds": [
"software-bill-of-materials-for-ai-tools",
"zero-trust-architecture-attestation",
"multi-factor-authentication-coverage-record",
"endpoint-detection-response-coverage-record"
]
},
{
"code": "ferc-order-2222-fairness",
"title": "FERC Order 2222 DER Aggregation Fairness",
"citation": "FERC Order No. 2222 + ISO/RTO compliance filings",
"summary": "AI tools used in DER aggregation programs must demonstrate non-discriminatory access for DER aggregators across customer classes, geographies, and DER types.",
"required_evidence_kinds": [
"der-aggregator-access-fairness-attestation",
"der-fairness-metrics-by-customer-class",
"der-fairness-metrics-by-geography",
"der-fairness-metrics-by-der-type"
]
},
{
"code": "state-puc-prudency-review",
"title": "State PUC Prudency Review Baseline",
"citation": "State PUC orders varying by jurisdiction (CA D.24-06-008, NY 15-E-0751 Supplemental, MA DPU 24-15, etc.)",
"summary": "State PUC review of utility AI-tool procurement + use for cost-recovery and rate-impact prudency. Must demonstrate tariff-filing disclosure and prudency-review readiness.",
"required_evidence_kinds": [
"ai-tool-tariff-filing-disclosure-record",
"prudency-review-supporting-documentation",
"rate-impact-assessment-with-and-without-ai-tool",
"environmental-justice-impact-assessment",
"low-income-customer-impact-assessment"
]
}
],
"non_obligations_explicitly": [
"This bundle does NOT cover physical security planning under EPSA standards or post-CIP-014 evolution.",
"This bundle does NOT cover nuclear plant cybersecurity (10 CFR 73.54) — that's a separate NRC regulatory regime.",
"This bundle does NOT cover renewable energy tax credit + IRA Section 45 cybersecurity requirements — those are IRS+Treasury overlays."
],
"intended_consumers": [
"utility-cio-or-ciso",
"utility-vp-of-grid-operations",
"iso-rto-cybersecurity-officer",
"nerc-regional-entity-auditor-during-cip-audit",
"tsa-pipeline-cybersecurity-coordinator",
"doe-energy-sector-cybersecurity-coordinator",
"state-puc-staff-during-prudency-review",
"ai-vendor-procurement-disclosure-to-utility-buyer"
],
"related": {
"kg_protocol_suite_url": "https://suite.kineticgain.com",
"evidence_bundle_spec": "https://github.com/mizcausevic-dev/evidence-bundle-spec",
"sibling_operator_audit_stream": "https://github.com/mizcausevic-dev/grid-decision-record-audit-stream",
"sibling_state_puc_tracker": "https://github.com/mizcausevic-dev/state-puc-ai-disclosure-tracker",
"sibling_vault_contract": "https://github.com/mizcausevic-dev/grid-asset-data-vault-contract-profile",
"sibling_incident_card": "https://github.com/mizcausevic-dev/grid-operations-incident-card-profile",
"sibling_bias_lab": "https://github.com/mizcausevic-dev/grid-operator-bias-coverage-lab"
}
}