Current through Supplement No. 394, October, 2024
Section 69-09-12-05 - security1. An electric public utility shall meet with the commission annually to report on security preparedness.2. The report must provide: a. Information on the policies, procedure, and process used to inform the management of security risk;b. Information on any critical technology, constraints related to procurement, supply chain risk, impact of compromise to the supply chain, and controls to manage risk associated with dependency on external entities;c. An assessment of emerging threats and efforts taken by the electric public utility to implement security measures;d. A description of the process used to support compliance with applicable standards, laws, regulations, and best practices;e. A description of the policies and protections used to ensure the security of information and operational systems and safeguard against loss of confidential information;f. Information on activities to monitor, detect, and analyze information related to security threats;g. Information on the systems used for collaboration and communication of information and intelligence sharing;h. Information on activities used to address a detected security incident, contain impacts, limit potential damage, and manage consequences of a security incident;i. Information on any plans to maintain resilience and business continuity, timely recovery to normal operations, and corrective actions after occurrence of an incident;j. Information or plans for asset sharing with other electric public utilities and electrical cooperatives to maintain services in the event of a security incident; andk. Information on tabletop and field training exercises regarding security.3. The commission may close the meeting to discuss the security report, unless the commission orders otherwise.N.D. Admin Code 69-09-12-05
Adopted by Administrative Rules Supplement 2022-387, January 2023, effective 1/1/2023.Amended by Administrative Rules Supplement 2024-392, April 2024, effective 4/1/2024.General Authority: NDCC 49-02-04
Law Implemented: NDCC 49-05-17