Risks and Controls for VAR and EOP Richard Shiflett Ruchi Ankleshwaria

Size: px
Start display at page:

Download "Risks and Controls for VAR-001-4 and EOP-004-2. Richard Shiflett Ruchi Ankleshwaria"

Transcription

1 Risks and Controls for VAR and EOP Richard Shiflett Ruchi Ankleshwaria

2 2 Introductions Richard Shiflett Compliance Risk Engineer Joined WECC in February years experience with Bureau of Reclamation, Grand Coulee Dam (GO, GOP, TO) as a senior electrical engineer and compliance manager Retired Navy Chief Intelligence Specialist and six years experience as a nuclear mechanical operator Ruchi Ankleshwaria Compliance Risk Engineer Joined WECC in March years of industry experience prior to joining WECC 4 years at a BA/TO/TOP/GO/GOP in WECC as an EMS engineer and project controls engineer 2 years as a project manager Certified Project Management Specialist (PMP)

3 3 Agenda Introduction Risks and Controls VAR Risks and Controls EOP Risks and Controls Key Takeaways

4 4 Risk and Controls Risk Controls Residual Risk

5 5 Types of Internal Controls Internal Controls Management Practices People Tools Processes Systems

6 6 Importance of Risk and Controls Reduces the likelihood of causing a violation Provides efficiency through a proactive approach rather than reactive Helps in identifying details that are not obvious Helps in implementing good organizational processes Help with continuity of operations and other processes

7 7 How Did WECC Identify Risks and Controls? Analyze VAR and EOP requirements highlight key takeaways Research potential causes based on violation history Research best practices implemented by entities WECC Subject Matter Experts industry experience

8 8 List of Standards VAR and VAR Version 3-1/1/2014 Version 4-10/1/2014 EOP /1/2014

9 9 VAR Requirement Mapping VAR R1 R2 R3 R4 and R5 R6 E.A.13 E.A.14 E.A.15 E.A.16 E.A.17 E.A.18

10 10 VAR R1 Each Transmission Operator shall specify a system voltage schedule as part of its plan to operate within System Operating Limits and Interconnection Reliability Operating Limits Each Transmission Operator shall provide a copy of the voltage schedules to its Reliability Coordinator and adjacent Transmission Operators within 30 calendar days of a request.

11 11 VAR R1 Risks and Controls RISKS - Failure to include system voltage schedule or change in voltage schedule as part of TOP s plan - Failure to retain evidence of providing a copy of voltage schedule within 30 Calendar days - Peer review the voltage control plan - Implement change management process for voltage schedule changes - Have a process to maintain logs of all the requests received and sent - Proactively send voltage schedule to appropriate entities CONTROLS

12 12 VAR R2 Each Transmission Operator shall schedule sufficient reactive resources to regulate voltage levels under normal and contingency conditions.

13 13 VAR R2 Risks and Controls RISKS - Failure to schedule reactive resources in contingency conditions - Failure to schedule sufficient reactive resources - Failure to retain evidence that reactive resources were scheduled as per the studies or assessments - Develop a process for scheduling reactive resources - Perform periodic review to confirm system operators knowledge of the available reactive resources - Perform after-the-fact studies to validate the model when there is voltage excursion CONTROLS

14 14 VAR R3 Each Transmission Operator shall operate or direct the Real-time operation of devices to regulate transmission voltage and reactive flow as necessary.

15 15 VAR R3 Risks and Controls RISKS - Failure to utilize available reactive resources to regulate voltage and reactive flows - Failure to direct reactive resource utilization - Failure to retain evidence of actions taken to maintain voltage - Maintain a list of reactive resources that are available to provide voltage support - Maintain logs of reactive resource allocations for voltage support - Maintain high visibility of the voltages at critical areas CONTROLS

16 16 VAR R4 and R5 R4 & R5 are superseded by WECC Regional Variance E.A.13 E.A.18 R4 and R5 are superseded by the WECC Regional Variances E.A.13 E.A.18

17 17 VAR E.A.13 and E.A.14 E.A.13 and E.A.14 Highlights Each TOP shall issue one of the types of voltage schedules to the GOP as listed in the requirement for a specific period of time. Each TOP shall provide one of the types of voltage reference point to the GOP as listed in the requirement.

18 VAR E.A.13 and E.A.14 Risks and Controls 18 RISKS - The TOP fails to issue one of the three types of voltage schedule - The TOP fails to specify the applicable period for the voltage schedule -The TOP fails to provide reference points for the voltage schedule - Develop a template for issuing voltage schedule - Maintain and periodically verify the list of GOPs in the TOPs area - Specify the voltage schedules in the Generation Interconnection Agreement CONTROLS

19 19 VAR E.A.15 and E.A.16 E.A.15 Each Generator Operator shall convert each voltage schedule specified in Requirement E.A.13 into the voltage set point for the generator excitation system. E.A.16 Each Generator Operator shall provide its voltage set point conversion methodology from the point in Requirement E.A.14 to the generator terminals within 30 calendar days of request by its Transmission Operator.

20 VAR E.A.15 and E.A.16 Risks and Controls 20 RISKS - Converted voltage schedules are not applied to all the excitation systems - GOP fails to convert voltage schedules for certain time periods to voltage set points as provided by TOP - GOP fails to document all the converted voltage schedules specific to each excitation system type - GOP fails to submit required set point conversion methodology to the TOP within 30 days - Peer review of the voltage set point conversion methodology - Develop a process to submit the methodology to the TOP once updated - As part of commissioning activities, include a task to develop the voltage set point conversion methodology CONTROLS

21 21 VAR E.A.17 Each Transmission Operator shall provide to the Generator Operator, within 30 calendar days of a request for data by the Generator Operator, its transmission equipment data and operating data that supports development of the voltage set point conversion methodology

22 22 VAR E.A.17 Risks and Controls - The TOP fails to retain evidence of the GOP request for the information. - The TOP fails to provide data within 30 days - Log and track all the requests. - Develop a process for timely review and submission of required data to the GOP CONTROLS RISKS

23 23 VAR E.A.18 Each Generator Operator shall meet the following control loop specifications if the Generator Operator uses control loops external to the Automatic Voltage Regulators (AVR) to manage MVar loading: E.A Each control loop s design incorporates the AVR s automatic voltage controlled response to voltage deviations during System Disturbances. E.A Each control loop is only used by mutual agreement between the Generator Operator and the Transmission Operator affected by the control loop.

24 24 VAR E.A.18 Risks and Controls RISKS - The GOP fails to recognize its external control loop as applicable - The GOP fails to include AVR s response to voltage deviation in its control loop s design - The GOP fails to retain evidence of mutual agreement between the TOP and GOP - Develop a process to review AVR and control loop designs for new and replacement excitation systems - For new generators, add the external control loop design as part of the interconnection agreement CONTROLS

25 25 VAR R6 After consultation with the Generator Owner regarding necessary step-up transformer tap changes and the implementation schedule, the Transmission Operator shall provide documentation to the Generator Owner specifying the required tap changes, a timeframe for making the changes, and technical justification for these changes.

26 26 VAR R6 Risks and Controls RISKS - TOP fails to provide documentation to GO - TOPs documentation to the GOs fails to include all the details as specified in the requirement - TOP fails to maintain evidence of consultation with the GO - Develop a tap change request template that outlines all the required information - Develop a process for tap change request - Develop a process to monitor outage coordination which ensures GO tap changes occur within the implementation period CONTROLS

27 27 EOP Event Reporting

28 28

29 29 EOP R1 Each Responsible Entity shall have an event reporting Operating Plan in accordance with EOP Attachment 1 that includes the protocol(s) for reporting to the Electric Reliability Organization and other organizations.

30 30 EOP R1 Risks and Controls Risks Failure to have an event reporting operating plan Failure to include protocol for reporting Failure to include all requirements of Attachment 1 Controls Periodic review of new standards being effective. Peer Review of the operating plan. Exercise the operating plans

31 31 EOP R2 Each Responsible Entity shall report events per their Operating Plan within 24 hours of recognition of meeting an event type threshold for reporting or by the end of the next business day if the event occurs on a weekend.

32 32 EOP R2 Risks Failure to fully implement the Operating Plan Failure to identify an event as reportable event Failure to submit the report as per Attachment 2 of the standard or the DOE form Failure to follow the protocol as per the Operating Plan Failure to report within required timeframe Failure to retain evidence after event was reported

33 33 EOP R2 Controls Train operators on the reporting timelines, reporting protocols, and Attachment 1 thresholds Create a quick reference of the reportable event types for operators Keep blank copies of Attachment 2 or the DOE form readily available Review event logs from the previous shift Ensure collected data is sufficient to identify an event based on its threshold

34 34 EOP R3 Each Responsible Entity shall validate all contact information contained in the Operating Plan pursuant to Requirement R1 each calendar year.

35 35 EOP R3 Risks and Controls Risks Failure to validate all the contacts within a calendar year Not all of the contacts listed in the operating plan are validated Evidence of the validated contacts is insufficient or missing Controls Identify the personnel responsible for validating contacts and documenting evidence Set up reminders for at least 2 personnel to annually validate the contacts Document validation process

36 36 Examples of Common Controls Roadmap for Identifying Risks and Controls Resources to Build the Processes

37 37 Examples of Common Controls Integrate training into documentation changes and change management activities Implement a document management system or process If possible, identify primary and backup person while assigning responsibilities. Perform periodic review of compliance activities to confirm that the processes are followed. Perform periodic risk assessment to evaluate effectiveness of the controls.

38 38 Road Map for Identifying Risk and Controls Utilize Reliability and Audit recommendations provided by WECC Review past violation root causes Get input from standard owners and SMEs How to identify risk and implement controls? Highlight Key indicators in the Standard

39 39 Resources NIST Guide for Conducting Risk Assessments CMMi - Risk Management CERT Resilience Management Model COSO Internal Control Integrated Framework Internal Controls Working Guide: NERC Internal Controls: NERC Presentation

40 40 Key Takeaways Use the key indicators and failure points to identify risks Establish a combination of controls to address these risks Periodically monitor risks and update internal controls as necessary WECC Subject Matter Experts are available to help

41 41 Contact Information Richard Shiflett Compliance Risk Engineer (801) Ruchi Ankleshwaria Compliance Risk Engineer (801)

3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities.

3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities. A. Introduction 1. Title: Event Reporting 2. Number: EOP-004-2 3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities. 4. Applicability:

More information

Internal Controls And Good Utility Practices. Ruchi Ankleshwaria Manager, Compliance Risk Analysis

Internal Controls And Good Utility Practices. Ruchi Ankleshwaria Manager, Compliance Risk Analysis Internal Controls And Good Utility Practices Ruchi Ankleshwaria Manager, Compliance Risk Analysis 2 Introduction Joined WECC in March 2013 6 years of industry experience prior to joining WECC 4 years at

More information

4.1.1 Generator Owner 4.1.2 Transmission Owner that owns synchronous condenser(s)

4.1.1 Generator Owner 4.1.2 Transmission Owner that owns synchronous condenser(s) A. Introduction 1. Title: Verification and Data Reporting of Generator Real and Reactive Power Capability and Synchronous Condenser Reactive Power Capability 2. Number: MOD-025-2 3. Purpose: To ensure

More information

Summary of CIP Version 5 Standards

Summary of CIP Version 5 Standards Summary of CIP Version 5 Standards In Version 5 of the Critical Infrastructure Protection ( CIP ) Reliability Standards ( CIP Version 5 Standards ), the existing versions of CIP-002 through CIP-009 have

More information

Transmission Function Employees Job Titles and Descriptions 18 C.F.R 358.7(f)(1)

Transmission Function Employees Job Titles and Descriptions 18 C.F.R 358.7(f)(1) Date of Last Change to the Provided Information August 27 th, 2015 Director, Transmission Operations The employee in this position is responsible for effectively managing the operation of FirstEnergy Utilities

More information

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions August 10, 2015. Electric Grid Operations

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions August 10, 2015. Electric Grid Operations San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions August 10, 2015 Electric Grid Operations Director Electric Grid Operations: Responsible for overall transmission

More information

Reclamation Manual Directives and Standards

Reclamation Manual Directives and Standards Subject: Purpose: Ancillary Generation Services Establishes standards for ancillary generation services. Authority: The Reclamation Act of 1902 (Act of June 17, 1902, 32 Stat. 388), the Town Sites and

More information

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions June 4, 2015. Electric Grid Operations

San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions June 4, 2015. Electric Grid Operations San Diego Gas & Electric Company FERC Order 717 Transmission Function Employee Job Descriptions June 4, 2015 Electric Grid Operations Director Electric Grid Operations: Responsible for overall transmission

More information

When this standard has received ballot approval, the text boxes will be moved to the Guidelines and Technical Basis section of the Standard.

When this standard has received ballot approval, the text boxes will be moved to the Guidelines and Technical Basis section of the Standard. CIP-002-5 Cyber Security BES Cyber System Categorization When this standard has received ballot approval, the text boxes will be moved to the Guidelines and Technical Basis section of the Standard. A.

More information

System Operator Certification Program Administrative Guidelines

System Operator Certification Program Administrative Guidelines System Operator Certification Program Send your comments to [email protected] by September 24, 2004 Maintaining NERC System Operator Credential Through the Use of Continuing Education Credit Hours North

More information

Master/Local Control Center Procedure No. 13 (M/LCC 13) Communications Between the ISO and Local Control Centers

Master/Local Control Center Procedure No. 13 (M/LCC 13) Communications Between the ISO and Local Control Centers Master/LCC Procedure No. 13 - Communications Master/Local Control Center Procedure No. 13 (M/LCC 13) Communications 1. References... 2 2. Background... 3 3. Responsibilities... 3 4. Procedure... 4 4.1

More information

Load Dispatcher (Class Code 5223) Task List

Load Dispatcher (Class Code 5223) Task List A. Load Dispatching, General Load Dispatcher (Class Code 5223) Task List 1. Prior to work shift speaks to Load Dispatcher(s), reviews hardcopy and computer logs, and looks at the dispatcher's diagram board

More information

Generation Interconnection Feasibility Study Report-Web Version. PJM Generation Interconnection Request Queue Position Z1-055

Generation Interconnection Feasibility Study Report-Web Version. PJM Generation Interconnection Request Queue Position Z1-055 Generation Interconnection Feasibility Study Report-Web Version For PJM Generation Interconnection Request Queue Position Z1-055 South Bend Generation Project March 2014 PJM Interconnection 2014. All rights

More information

DISCUSSION PAPER: Peak Reliability Performance Metrics

DISCUSSION PAPER: Peak Reliability Performance Metrics DISCUSSION PAPER: Peak Reliability Performance Metrics Executive Summary Performance metrics are critical for any organization in order to encourage improvement, effectiveness and efficiency; to assess

More information

NERC Cyber Security Standards

NERC Cyber Security Standards SANS January, 2008 Stan Johnson Manager of Situation Awareness and Infrastructure Security [email protected] 609-452-8060 Agenda History and Status of Applicable Entities Definitions High Level of

More information

Table of Contents. Real-Time Reliability Must Run Unit Commitment and Dispatch (Formerly G-203) Operating Procedure

Table of Contents. Real-Time Reliability Must Run Unit Commitment and Dispatch (Formerly G-203) Operating Procedure No. 2310 Table of Contents Purpose... 2 1. Responsibilities... 2 2. Scope/Applicability... 2 2.1 Background... 2 2.2 Scope / Applicability... 2 3. Detail... 3 3.1 Energy Dispatching... 3 3.1.2 Real-Time

More information

Standard CIP 007 3a Cyber Security Systems Security Management

Standard CIP 007 3a Cyber Security Systems Security Management A. Introduction 1. Title: Cyber Security Systems Security Management 2. Number: CIP-007-3a 3. Purpose: Standard CIP-007-3 requires Responsible Entities to define methods, processes, and procedures for

More information

CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments

CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:

More information

CIP-003-5 Cyber Security Security Management Controls

CIP-003-5 Cyber Security Security Management Controls A. Introduction 1. Title: Cyber Security Security Management Controls 2. Number: CIP-003-5 3. Purpose: To specify consistent and sustainable security management controls that establish responsibility and

More information

ATTACHMENT G. Network Operating Agreement

ATTACHMENT G. Network Operating Agreement ATTACHMENT G Network Operating Agreement 1. PURPOSE OF NETWORK OPERATING AGREEMENT The purpose of this Agreement is to identify contractual requirements related to Network Integration Transmission Service

More information

Cyber Security Standards Update: Version 5

Cyber Security Standards Update: Version 5 Cyber Security Standards Update: Version 5 January 17, 2013 Scott Mix, CISSP CIP Technical Manager Agenda Version 5 Impact Levels Format Features 2 RELIABILITY ACCOUNTABILITY CIP Standards Version 5 CIP

More information

Advanced Inverter Overview

Advanced Inverter Overview Advanced Inverter Overview Renewables on the Distribution Grid Minnesota Public Utilities Commission April 11, 2014 Lise Trudeau Senior Engineering Specialist Minnesota Department of Commerce Division

More information

Duke Energy Progress Standards of Conduct Transmission Function Employee Job Titles and Job Descriptions 9/1/13

Duke Energy Progress Standards of Conduct Transmission Function Employee Job Titles and Job Descriptions 9/1/13 Duke Energy Progress Standards of Conduct Transmission Function Employee Job Titles and Job Descriptions 9/1/13 Transmission Operations & Planning Carolinas Power System Operations Director Power System

More information

CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments

CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:

More information

Document Management Solution (EDMS)

Document Management Solution (EDMS) Implementing TrackWise with an Electronic Document Management Solution (EDMS) Alex Kotikovsky Product Manager Sparta Systems Gilad Kigel Manager, Solutions Consulting Sparta Systems Agenda Document Management

More information

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION Treasury Inspector General for Tax Administration Federal Information Security Management Act Report October 27, 2009 Reference Number: 2010-20-004 This

More information

Benefits of Big Data Analytics in Security Helping Proactivity and Value Creation. June 2015

Benefits of Big Data Analytics in Security Helping Proactivity and Value Creation. June 2015 Benefits of Big Data Analytics in Security Helping Proactivity and Value Creation June 2015 The Security Landscape Held the door to let 5 people into the data center Who, Where, Why, For How Long & Who

More information

PHASE 9: OPERATIONS AND MAINTENANCE PHASE

PHASE 9: OPERATIONS AND MAINTENANCE PHASE PHASE 9: OPERATIONS AND MAINTENANCE PHASE During the Operations and Maintenance Phase, the information system s availability and performance in executing the work for which it was designed is maintained.

More information

CIP-014-1 Physical Security. Nate Roberts CIP Security Auditor I

CIP-014-1 Physical Security. Nate Roberts CIP Security Auditor I CIP-014-1 Physical Security Nate Roberts CIP Security Auditor I Notes Critical Infrastructure Protection (CIP) Standard CIP-014-1 is currently pending approval by the Federal Energy Regulatory Commission

More information

Standard CIP 003 1 Cyber Security Security Management Controls

Standard CIP 003 1 Cyber Security Security Management Controls A. Introduction 1. Title: Cyber Security Security Management Controls 2. Number: CIP-003-1 3. Purpose: Standard CIP-003 requires that Responsible Entities have minimum security management controls in place

More information

Standard CIP 007 3 Cyber Security Systems Security Management

Standard CIP 007 3 Cyber Security Systems Security Management A. Introduction 1. Title: Cyber Security Systems Security Management 2. Number: CIP-007-3 3. Purpose: Standard CIP-007-3 requires Responsible Entities to define methods, processes, and procedures for securing

More information

Entity Name ( Acronym) NCRnnnnn Risk Assessment Questionnaire

Entity Name ( Acronym) NCRnnnnn Risk Assessment Questionnaire Entity Name ( Acronym) NCRnnnnn Risk Assessment Questionnaire Upcoming Audit Date: March 16, 2015 Upcoming Audit Type: O&P Audit Start of Audit Period: March 16, 2012 Date Submitted: Table of Contents

More information

TRIPWIRE NERC SOLUTION SUITE

TRIPWIRE NERC SOLUTION SUITE CONFIDENCE: SECURED SOLUTION BRIEF TRIPWIRE NERC SOLUTION SUITE TAILORED SUITE OF PRODUCTS AND SERVICES TO AUTOMATE NERC CIP COMPLIANCE u u We ve been able to stay focused on our mission of delivering

More information

Project Risk Management

Project Risk Management Project Risk Management Study Notes PMI, PMP, CAPM, PMBOK, PM Network and the PMI Registered Education Provider logo are registered marks of the Project Management Institute, Inc. Points to Note Risk Management

More information

Asset Management Business Update

Asset Management Business Update Asset Management Business Update Improvements through Asset Management Mark Davis, Director, Asset Management & AW October 29, 2008 1 From Maintenance to Asset Management Maintain the System -Initial Focus

More information

Project Type Guide. Project Planning and Management (PPM) V2.0. Custom Development Version 1.1 January 2014. PPM Project Type Custom Development

Project Type Guide. Project Planning and Management (PPM) V2.0. Custom Development Version 1.1 January 2014. PPM Project Type Custom Development Project Planning and Management (PPM) V2.0 Project Type Guide Custom Development Version 1.1 January 2014 Last Revision: 1/22/2014 Page 1 Project Type Guide Summary: Custom Development Custom software

More information

IEEE-Northwest Energy Systems Symposium (NWESS)

IEEE-Northwest Energy Systems Symposium (NWESS) IEEE-Northwest Energy Systems Symposium (NWESS) Paul Skare Energy & Environment Directorate Cybersecurity Program Manager Philip Craig Jr National Security Directorate Sr. Cyber Research Engineer The Pacific

More information

NERC CIP Compliance Gaining Oversight with ConsoleWorks

NERC CIP Compliance Gaining Oversight with ConsoleWorks NERC CIP Compliance Gaining Oversight with ConsoleWorks The current challenge for many Utility companies is finding efficient ways to gain oversight and control over NERC CIP regulation compliance. NERC

More information

Scope of Restoration Plan

Scope of Restoration Plan RWG Area Restoration Review Worksheet (10/28/09) EOP-006-02 Directory 8 EOP-005 NYSRG Rule G Text Restoration Plan Requirement R1.Each Reliability Coordinator shall have a Reliability Coordinator Area

More information

Job Descriptions. Job Title Reports To Job Description TRANSMISSION SERVICES Manager, Transmission Services. VP Compliance & Standards

Job Descriptions. Job Title Reports To Job Description TRANSMISSION SERVICES Manager, Transmission Services. VP Compliance & Standards Updated July 11, 2013 Job Descriptions Job Title Reports To Job Description TRANSMISSION SERVICES VP Compliance & Standards Develops strategy and business plans for efficient, safe, reliable, regulatorycompliant

More information

RSA ARCHER OPERATIONAL RISK MANAGEMENT

RSA ARCHER OPERATIONAL RISK MANAGEMENT RSA ARCHER OPERATIONAL RISK MANAGEMENT 87% of organizations surveyed have seen the volume and complexity of risks increase over the past five years. Another 20% of these organizations have seen the volume

More information

Last revised: September 1, 2014 TRANSMISSION FUNCTION TITLES AND JOB DESCRIPTIONS

Last revised: September 1, 2014 TRANSMISSION FUNCTION TITLES AND JOB DESCRIPTIONS Last revised: September 1, 2014 TRANSMISSION FUNCTION TITLES AND JOB DESCRIPTIONS EVP, Chief Operations Officer, has primary responsibility for the overall planning, operations and control of the transmission

More information

GxP Process Management Software. White Paper: Ten Most Common Reasons for FDA 483 Observations and Warning Letter Citations

GxP Process Management Software. White Paper: Ten Most Common Reasons for FDA 483 Observations and Warning Letter Citations GxP Process Management Software : Ten Most Common Reasons for FDA 483 Observations and Warning Letter Citations Most FDA violations involve one of the following: Not having procedures in a regulated area

More information

PI/PSLF Based Model Validation Application. Eric Bakie and Milorad Papic WECC JSIS Meeting Tempe, AZ January 21-23, 2014

PI/PSLF Based Model Validation Application. Eric Bakie and Milorad Papic WECC JSIS Meeting Tempe, AZ January 21-23, 2014 PI/PSLF Based Model Validation Application Eric Bakie and Milorad Papic WECC JSIS Meeting Tempe, AZ January 21-23, 2014 1 OUTLINE 1. Background Information 2. What is PI/PSLF Based PPMV Application? 3.

More information

Energy Management System (EMS) Model Updates and Quality Assurance (QA)

Energy Management System (EMS) Model Updates and Quality Assurance (QA) PJM Manual 3A: Energy Management System (EMS) Model Updates and Quality Assurance (QA) Revision: 10 Effective Date: June 25, 2015 Prepared by: Operation Support Division PJM 2015 PJM 2007 Revision 0, Effective

More information

UNITED STATES NUCLEAR REGULATORY COMMISSION OFFICE OF NUCLEAR REACTOR REGULATION WASHINGTON, D.C. 20555-0001. February 1, 2006

UNITED STATES NUCLEAR REGULATORY COMMISSION OFFICE OF NUCLEAR REACTOR REGULATION WASHINGTON, D.C. 20555-0001. February 1, 2006 UNITED STATES NUCLEAR REGULATORY COMMISSION OFFICE OF NUCLEAR REACTOR REGULATION WASHINGTON, D.C. 20555-0001 February 1, 2006 OMB Control No.: 3150-0011 NRC GENERIC LETTER 2006-02: GRID RELIABILITY AND

More information

GENe Software Suite. GENe-at-a-glance. GE Energy Digital Energy

GENe Software Suite. GENe-at-a-glance. GE Energy Digital Energy GE Energy Digital Energy GENe Software Suite Today s utilities have complex requirements that need sophisticated solutions. GE Energy s GENe provides these solutions. Using the latest advances in technology,

More information

Systems Operation Department

Systems Operation Department August 8, 2012 TRANSMISSION FUNCTION EMPLOYEES: Systems Operation Department General Manager Directs the activities of the of the System Operation Department including formulation of personnel issues,

More information

Cyber Security Standards Update: Version 5 with Revisions

Cyber Security Standards Update: Version 5 with Revisions Cyber Security Standards Update: Version 5 with Revisions Security Reliability Program 2015 Agenda CIP Standards History Version 5 Format Impact Levels NOPR Final Rule References 2 RELIABILITY ACCOUNTABILITY

More information

Following up recommendations/management actions

Following up recommendations/management actions 09 May 2016 Following up recommendations/management actions Chartered Institute of Internal Auditors At the conclusion of an audit, findings and proposed recommendations are discussed with management and

More information

Internal Audit Report. Toll Operations Contract Management TxDOT Office of Internal Audit

Internal Audit Report. Toll Operations Contract Management TxDOT Office of Internal Audit Internal Audit Report Toll Operations Contract Management TxDOT Office of Internal Audit Objective To determine whether the Toll Operations Division (TOD) contract management structure is designed and

More information

Arizona Medicaid School Based Claiming

Arizona Medicaid School Based Claiming Arizona Medicaid School Based Claiming Regional Information Session September 2013 www.pcgeducation.com Agenda Direct Service Claiming Annual Cost Settlement.. 3-45 Random Moment Time Study... 46-50 Direct

More information

IA Metrics Why And How To Measure Goodness Of Information Assurance

IA Metrics Why And How To Measure Goodness Of Information Assurance IA Metrics Why And How To Measure Goodness Of Information Assurance Nadya I. Bartol PSM Users Group Conference July 2005 Agenda! IA Metrics Overview! ISO/IEC 21827 (SSE-CMM) Overview! Applying IA metrics

More information

SOP-RTMKTS.0060.0005 - Test and Approve Operations Software Applications. Contents

SOP-RTMKTS.0060.0005 - Test and Approve Operations Software Applications. Contents SOP-RTMKTS.0060.0005 - Test and Approve Operations Software Applications Contents 1. Objective... 2 2. Background... 2 3. Responsibilities... 3 4. Controls... 4 5. Instructions... 5 5.1 Document Operations

More information

Five Ways to Use Security Intelligence to Pass Your HIPAA Audit

Five Ways to Use Security Intelligence to Pass Your HIPAA Audit e-book Five Ways to Use Security Intelligence to Pass Your HIPAA Audit HIPAA audits on the way 2012 is shaping up to be a busy year for auditors. Reports indicate that the Department of Health and Human

More information

SCADA. The Heart of an Energy Management System. Presented by: Doug Van Slyke SCADA Specialist

SCADA. The Heart of an Energy Management System. Presented by: Doug Van Slyke SCADA Specialist SCADA The Heart of an Energy Management System Presented by: Doug Van Slyke SCADA Specialist What is SCADA/EMS? SCADA: Supervisory Control and Data Acquisition Retrieves data and alarms from remote sites

More information

EPA Classification No.: CIO-2150.3-P-09.1 CIO Approval Date: 08/06/2012 CIO Transmittal No.: 12-003 Review Date: 08/06/2015

EPA Classification No.: CIO-2150.3-P-09.1 CIO Approval Date: 08/06/2012 CIO Transmittal No.: 12-003 Review Date: 08/06/2015 Issued by the EPA Chief Information Officer, Pursuant to Delegation 1-19, dated 07/07/2005 INFORMATION SECURITY INTERIM MAINTENANCE PROCEDURES V1.8 JULY 18, 2012 1. PURPOSE The purpose of this procedure

More information

Wilhelmenia Ravenell IT Manager Eli Lilly and Company

Wilhelmenia Ravenell IT Manager Eli Lilly and Company Wilhelmenia Ravenell IT Manager Eli Lilly and Company Agenda Introductions The Service Management Framework Keys of a successful Service management transformation Why transform? ROI and the customer experience

More information

Developing Your Strategic Plan

Developing Your Strategic Plan Training Module: Developing Your Strategic Plan This training contains general information only and Deloitte is not, by means of this training session, rendering accounting, business, financial, investment,

More information

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0 Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0 Unless otherwise stated, these Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies

More information

Reclamation Manual Directives and Standards

Reclamation Manual Directives and Standards Subject: Purpose: Fee-for-Service Business Practices for Technical Services Work This Directive and Standard (D&S) identifies steps to be taken for executing technical services work using standardized

More information

Operational Security Network Code

Operational Security Network Code Amstelveenseweg 998 1081 JS Amsterdam Phone: + 31 20 520 7970 Fax: + 31 346 283 258 Email: [email protected] Website: www.efet.org Operational Security Network Code Public consultation 3 November 2012

More information

Title 20 PUBLIC SERVICE COMMISSION. Subtitle 50 SERVICE SUPPLIED BY ELECTRIC COMPANIES. Chapter 02 Engineering

Title 20 PUBLIC SERVICE COMMISSION. Subtitle 50 SERVICE SUPPLIED BY ELECTRIC COMPANIES. Chapter 02 Engineering Title 20 PUBLIC SERVICE COMMISSION Subtitle 50 SERVICE SUPPLIED BY ELECTRIC COMPANIES Chapter 02 Engineering Authority: Public Utility Companies Article, 2-121, 5-101 and 5-303, Annotated Code of Maryland.

More information

Market Data Transparency Service Level Agreement

Market Data Transparency Service Level Agreement Electric Reliability Council of Texas Market Data Transparency Service Level Agreement Summary: This document describes Market Data Transparency services provided by ERCOT to Market Participants. EFFECTIVE:

More information

PHASE 5: DESIGN PHASE

PHASE 5: DESIGN PHASE PHASE 5: DESIGN PHASE During the Design Phase, the system is designed to satisfy the requirements identified in the previous phases. The requirements identified in the Requirements Analysis Phase are transformed

More information

Manage IT Service Continuity and Availability

Manage IT Service Continuity and Availability Manage IT Service Continuity and Availability Description School jurisdictions are increasingly dependent upon IT services to support day-to-day activities. The process of managing IT ensures that IT services

More information

A MULTIFACETED CYBERSECURITY APPROACH TO SAFEGUARD YOUR OPERATIONS

A MULTIFACETED CYBERSECURITY APPROACH TO SAFEGUARD YOUR OPERATIONS A MULTIFACETED CYBERSECURITY APPROACH TO SAFEGUARD YOUR OPERATIONS CYBER ATTACKS INFILTRATE CRITICAL INFRASTRUCTURE SECTORS Government and enterprise critical infrastructure sectors such as energy, communications

More information

Good Internal Controls for Small Businesses

Good Internal Controls for Small Businesses Good for Small Businesses SOX and the Importance of Good for Small Businesses MENDELSON CONSULTING Mario Nowogrodzki, CPA.CITP America s QuickBooks Specialists www.qbspecialists.com MARIO NOWOGRODZKI,

More information

ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI

ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI Matt Mereness, ERCOT Compliance Director August 2015 Anfield Summit Outline of discussion ERCOT Background Business Case

More information

Olav Mo, Cyber Security Manager Oil, Gas & Chemicals, 28.09.2015 CASE: Implementation of Cyber Security for Yara Glomfjord

Olav Mo, Cyber Security Manager Oil, Gas & Chemicals, 28.09.2015 CASE: Implementation of Cyber Security for Yara Glomfjord Olav Mo, Cyber Security Manager Oil, Gas & Chemicals, 28.09.2015 CASE: Implementation of Cyber Security for Yara Glomfjord Implementation of Cyber Security for Yara Glomfjord Speaker profile Olav Mo ABB

More information

Change Management Policy

Change Management Policy Change Management Policy Change management refers to a formal process for making changes to IT services. The goal of change management is to increase awareness and understanding of proposed changes across

More information

References... 4. Appendices... 5. I. INTRODUCTION... 6 A. Background... 6 B. Standards... 6

References... 4. Appendices... 5. I. INTRODUCTION... 6 A. Background... 6 B. Standards... 6 ISO New England Operating Procedure No. 14 - Technical Requirements for Generators, Demand Resources, Asset Related Demands and Alternative Technology Regulation Resources Effective Date: January 29, 2015

More information

Appendix 2 to Chapter 7 GUIDANCE ON THE DEVELOPMENT OF AN SMS GAP ANALYSIS FOR SERVICE PROVIDERS

Appendix 2 to Chapter 7 GUIDANCE ON THE DEVELOPMENT OF AN SMS GAP ANALYSIS FOR SERVICE PROVIDERS Appendix 2 to Chapter 7 GUIDANCE ON THE DEVELOPMENT OF AN SMS GAP ANALYSIS FOR SERVICE PROVIDERS Gap analysis The implementation of an SMS requires a service provider to conduct an analysis of its system

More information

ARRA HITECH Stimulus HIPAA Security Compliance Reporter. White Paper

ARRA HITECH Stimulus HIPAA Security Compliance Reporter. White Paper ARRA HITECH Stimulus HIPAA Security Compliance Reporter White Paper ARRA HITECH AND ACR2 HIPAA SECURITY The healthcare industry is in a time of great transition, with a government mandate for EHR/EMR systems,

More information

Energy Management Systems (EMS)

Energy Management Systems (EMS) Energy Management Systems (EMS) Introduction Abstract This talk deals with the role of an Energy Management System (EMS) in the overall Smart Grid. Why an EMS is needed will be discussed and its importance

More information