Copyright ©2009 by Federal News Service, Inc., Ste. 500, 1000 Vermont Ave, Washington, DC 20005 USA. Federal News Service is a private firm not affiliated with the federal government. No portion of this transcript may be copied, sold or retransmitted without the written authority of Federal News Service, Inc. Copyright is not claimed as to any part of the original work prepared by a United States government officer or employee as a part of that person's official duties. For information on subscribing to the FNS Internet Service at www.fednews.com, please email Carina Nyberg at cnyberg@fednews.com or call 1-202-216-2706.
SEN. BINGAMAN: Okay, why don't we get started here? Thank you all very much for being here. I'm advised Senator Murkowski is on her way, but asked us to go ahead. Recent newspaper headlines and television news coverage have highlighted the serious security threats to the electricity system in the country. A Wall Street Journal article talked about Soviet and Chinese hackers who may have left potentially damaging computer viruses in the control systems of electric utilities. Just the thought that foreign agents are hacking into our control systems is obviously alarming, and the potential for damage they could do in the case of a conflict would create a compelling reason to act to prevent that damage.
We recently sponsored a classified briefing for members and staff on this set of issues, members of security agencies, and the Department of Energy, and the Federal Energy Regulatory Commission told us about these threats and about the inadequacy of our government's authority to respond to and prevent these threats. Some thought that we had taken sufficient action to protect against these types of threats when we put into place the reliability protection structure of Section 215 of the Federal Power Act, which we passed in 2005.
More recently, however, we've come to believe that these provisions do not provide sufficient protection against computer attacks. Both the recent Republican chairman of the Federal Energy Regulatory Commission, Joe Kelleher, and the current Democratic chair, John Wellinghoff, have indicated that they believe they need stronger authority to deal with cyber threats and vulnerabilities.
Almost all the witnesses gathered here today agree that we need some kind of increased federal authority, although there is disagreement as to exactly what that authority should look like and who should exercise it. This hearing is on a bill that we intend to include in a comprehensive energy bill that the committee is working on to address these gaps in federal authority and to protect against these dangers. The proposal is fairly simple. It gives the secretary of Energy authority to order actions to protect against imminent threats when a security agency informs the secretary that an action is about to take place. The secretary is able to order measures to protect against the attack.
It then goes on to allow FERC to issue rules for longer-term circumstances that are not immediate threats, but that are too dangerous to wait for the development of rules through the extremely cumbersome NERC process. This authority does not supersede the NERC process or can issue rules that can then be replaced by rules developed under the NERC process when those rules are finally -- when those rules finally are such that the commission can approve them.
This is obviously an important issue and one that I hope we're able to deal with as part of an energy bill, and I thank the witnesses for being here. Let me go ahead and introduce the witnesses, and then we will hear the testimony.
Patricia Hoffman is principle deputy and acting assistant secretary in the Office of Electricity Delivery and Energy Reliability at the Department of Energy. She's been here before our committee recently on -- in other -- on other issues as well.
Joseph McClelland is the director of the Office of Electric Reliability at FERC, and thank you for being here.
Rick Sergel is President and CEO of the North American Electric Reliability Corporation in Princeton. Thank you for being here.
Allen Mosher is a senior director of policy analysis and reliability with the American Public Power Association.
And David Owens is the executive vice president with Business Operations with Edison Electric Institute. Thank you very much for being here.
If each of you could take five or six minutes and give us your perspective on this set of issues -- and then we'll undoubtedly have questions.
Ms. Hoffman.
MS. HOFFMAN: Thank you.
Mr. Chairman and members of the committee, thank you for this opportunity to testify before you on cyber security issues facing the electric industry, and on emergency authorities to protect critical electric infrastructure. All of us here today share common concerns that vulnerabilities exist within the electric system and that the government and private sector must do everything we can to address it. This is particularly true for Smart Grid systems, which, by their very nature, involves the use of information technologies in areas and applications on the electric system where they not have been used before.
The mission of the Office of Electricity Delivery and Energy Reliability is to lead national efforts to modernize the electric grid, to enhance the security and reliability of the energy infrastructure, and to facilitate recovery from disruptions to the energy supply. To accomplish this mission, the office focuses on long-term system requirements through our research investments and the electric delivery system and near-term energy vulnerability assessments and disaster recovery.
Our efforts to enhance the cyber security of the energy infrastructure have produced results in five areas. We have identified cyber vulnerabilities in energy control systems and worked with vendors to develop hardened systems that mitigate the risk. We have developed more secure communication methods between energy control systems and field devices. We have developed tools and methods to help utilities assess their security posture. And we have developed modeling and simulation capabilities to estimate the effects of cyber attacks on the power grid. And finally, we have provided extensive cyber security training for the energy owners and operators to help them prevent, detect, and mitigate cyber penetration.
In 2005, the Department worked closely with asset owners and operators in the oil, gas, and electric sectors to develop the roadmap to secure control systems in the energy sector, a detailed, prioritized plan for cyber security improvements over the next ten years, including best practices, new technologies, and risk management. The roadmap vision is that control systems for critical applications will be designed, installed, and operated to maintain and survive an intentional cyber assault with no loss of critical function.
Efforts at the national labs are producing results that industry can use today to enhance the security of their control systems. For example, Sandia National Laboratories developed an advanced network toolkit for assessments in remote mapping, which aids utility owners in mapping access points to allow easy visualization of their control system networks; an important, critical step in meeting the North American Electric Reliability Corporation's critical infrastructure protection standard.
Through the Department's National Supervisory Control and Data Acquisition Test Bed Program, we have assessed 90 percent of the current market offerings of SCADA and energy management systems in the electric sector, and 80 percent of the current market offerings in the oil and gas sector. Twenty test bed and offsite field assessments of control systems from vendors have led to the development of 11 hardened control system designs with 31 of these systems now deployed in the marketplace.
The national labs also educate end users on cyber security best practices in implementing methods to better manage control system risk. For example, the Idaho National Laboratory has released a Common Vulnerabilities Report. This report represents the steadily growing understanding of control system security issues and methods for mitigating current and emerging vulnerabilities. And this effort is expanding to new technologies, such as substation automation and the Smart Grid as the program seeks a continuing understanding of the systems being planned for and developed for the energy sector critical infrastructure.
The Department is also working to implement the America Recovery and Reinvestment Act of 2009, the programs authorized under Title 13 of the Energy Independence and Security Act of 2007 for the Smart Grid. We are hoping to implement these in a responsible manner, and the request for proposals for these activities will include requirements that each applicant will thoroughly and systematically address all cyber security risks to their systems.
A key component of the Smart Grid is the Advanced Metering Infrastructure, AMI. AMI requires two-way communications between utilities and the end users. Over the last ten months, DOE has been partnering with the AMI Security Task Force under the International Users Group. This task force is comprised of utilities, security domain experts, standard body representatives, and industry vendors. On March 10, 2009, the task force published the AMI security requirements, which provides critical guidance for vendors and utilities to design and procure secure and reliable AMI systems. Because of the success of this industry-government collaboration, the Department is working with the task force to expand the activity and develop a suite of security requirements for all critical Smart Grid applications.
The National Institute of Standards and Technology is responsible for developing the framework for interoperability standards development for the Smart Grid. These standards will be submitted to the Federal Energy Regulatory Commission for rulemaking. The department views the development of interoperability standards that includes appropriate cyber security protections as one of the key milestones towards realizing the goal of widespread implementation of Smart Grid technologies, tools and techniques.
With regard to protecting the electric grid from newly discovered vulnerabilities, the Department does not have a position on the draft joint cyber security text. The Department does provide the following technical comment: "All vulnerabilities must be thoroughly evaluated on a scientific basis to determine the impact and risk to the nation in the event the vulnerability was to be exploited. Any decision to act or to issue an order by the government must be based on sound risk management principles and judgment considering the characteristics of the vulnerability, the capabilities of the threat, the likelihood of attack, the consequences to the nation should the vulnerability be exploited, and the cost of mitigation."
This concludes my statement, Mr. Chairman, and thank you for the opportunity to speak. I look forward to answering any questions you and your colleagues may have.
SEN. BINGAMAN: Thank you very much.
Mr. McClellan.
MR. MCCLELLAN: Mr. Chairman and members of the committee, thank you for -- better do that first. Thank you for the invitation to appear before you today to discuss the cyber security of the electric grid. My name is Joe McClellan, and I am the director of the Office of Electric Reliability at the Federal Energy Regulatory Commission. I am here today as a Commission staff witness, and my remarks do not necessarily represent the views of the commission or any individual commissioner.
Although new Section 215 of the Federal Power Act has provided an adequate foundation for the development of reliability standards to date, the threat of cyber attacks or other intentional malicious acts against the electric grid is very different. These threats can endanger national security, and they may be posed by foreign nations or others intent on attacking the United States through the electric grid. Widespread disruption of electric service can quickly undermine the United States government, its military, and the economy, as well as endanger the health and safety of millions of our citizens.
Given the national security dimension to this threat, there may be a need to act quickly to protect the grid to act in a manner where action is mandatory rather than voluntary, and to protect certain information from public disclosure. Faced with the cyber or other national security threats to reliability, there may be a need to act decisively in hours or days rather than weeks, months, or years. The commission's legal authority is inadequate for such action, as it is required to depend on an electric reliability organization, or ERO, to develop and propose standards to address cyber security issues. The process employed by the ERO typically takes years to develop a standard, is open to public review, and may not be necessarily responsive to the commission's directives. This is true of both cyber and non-cyber threats that pose national security concerns.
In the case of such threats to the electric system, the commission does not have timely, confidential, or direct authority to protect the reliability of the system. As a result, I believe legislation is needed. Any new legislation should address several key concerns. First, the legislation should allow the commission to take action before a cyber or other national security incident has occurred. Second, any legislation should allow the commission to maintain the appropriate confidentiality of any security sensitive information submitted or developed through the exercise of this authority. Third, it is important that Congress be aware that if additional reliability authority is limited to the quote, "bulk power system," end quote, as defined in the Federal Power Act, it would exclude protection against attacks involving Alaska and Hawaii and possibly the territories, including any federal installations located therein.
In addition, a current interpretation of bulk power system also would exclude some transmission in all local distribution facilities, including virtually all of the grid facilities in large cities, such as New York City, thus precluding commission -- possible commission action in these population centers. Finally, legislation should not only address cyber security threats, but also, other national security threats to reliability.
The Joint Staff bill is one approach that would largely rectify the inadequacies in existing federal authority to address cyber threats to the electric grid. It gives the commission authority to issue rules or orders that are necessary to protect critical electric infrastructure and thus allow the commission to act to protect against damage to the grid.
I will briefly point out a few concerns with the Joint Staff draft. While the draft bill addresses the protection of critical infrastructure information, it could be construed to provide protection only for information voluntarily submitted to the commission or the secretary. It does not address other information, such as that which may be compelled or developed by the commission or the secretary, or information that would be included in orders issued by either agency. Therefore, I recommend that the language be amended to address these issues.
I also recommend that the legislation address not only cyber security threats, but other national security threats to reliability. Intentional physical acts against the grid can cause equal or greater destruction than cyber attacks, and the federal government should have no less ability to act to protect against such damage. Finally, Congress should be aware that if additional reliability authority is limited to the areas within the commission's jurisdiction under Section 215 of the Federal Power Act, it would exclude protection against reliability threats in Alaska, Hawaii, and possibly the territories, again, including any federal installations located therein, as well as major population areas, such as New York City.
Thank you again for the opportunity to testify today, and I would be happy to answer any questions that you may have.
SEN. BINGAMAN: Thank you very much.
Mr. Sergel, go right ahead.
MR. SERGEL: Thank you, chairman, and members of the committee. I appreciate the opportunity to testify today, and I commend you and your staffs for your attention to this important issue. NERC is committed to ensuring the reliability of the bulk power system in North America in the face of cyber security threats and assuring that NERC's efforts will compliment those of the government and industry with regard to cyber security protection and assuring that there are no gaps and that that responsibility is clear for execution of cyber security protection initiatives.
Now, as the international regulatory authority for the reliability of the bulk power system in North America, NERC is responsible for developing reliability standards applicable to all users and owners of the system, ensuring that each of the nearly 2,000 entities that own and operate components of the system understand cyber security and the efforts needed to adequately protect the security of the bulk power system, and this has been a priority for us.
Now, my written testimony details the steps NERC has taken to enhance protection of the system from cyber security vulnerabilities and threats. I'm not going to talk about those here today. We do have eight of the mandatory and enforceable reliability standards in effect today focused on cyber security and fill a specific role in the protection of the system. Now, these standards were developed under the process established in Section 215, a process that worked to put those standards in place for securing the grid, and it's working today to -- and we are working today to improve those standards.
But reliability standards are not enough. NERC needs that new, specific -- agrees that new, specific authority for emergency response to cyber threats is necessary. In the case of an imminent cyber security threat, authority to direct action should be vested in the federal government in the United States, and as appropriate, in Canada. The Joint Staff draft addresses what we see as the principle gap in the current law. The federal government lacks sufficient authority to act to address an imminent and specific cyber security threat to the critical infrastructure of the United States. And NERC believes that authority to act in such emergencies should be assigned to a single federal agency.
The draft would give the secretary of Energy the authority to act in such circumstances. The provisions of the draft to encourage consultation and coordination with officials in Canada and Mexico are, we believe, very important in recognition of the international nature of the interconnected North American power system.
Now, in addition to the new authority in the Department of Energy, the draft would also give new authority to the Federal Energy Regulatory Commission to establish standards to address not only emergencies, by cyber security vulnerability. Moreover, FERC would be authorized to adopt rules or orders without notice or hearing. NERC believes it would be unwise to supplant Section 215 with respect to the establishment of cyber security standards, and we -- whatever occurs, we need to make sure that it's complimentary to what we do today, and hopefully, we'll be able to do that.
The NERC standards setting process brings together industry and security experts to develop standards that must apply to the international, interconnected grid. Developing long-term standards that apply to the more than 1,800 diverse entities that own and operate the grid is a complex undertaking. Standards must apply equally to companies with thousands of employees and to those with only 20. Additionally, the standards must do no harm. They must take into account unique component configurations and operational procedures that differ widely across the grid.
And given the industry's extensive experience in standard development, NERC firmly believes that the level of expertise necessary to create standards that achieve security objectives and ensure reliability can best be found within the industry itself. But I am emphasize again -- that is only if we have emergency authorization in place. Now, we are also concerned that the draft sets up potentially competing emergency authorities between the secretary of Energy and FERC.
Now, in closing, I'd like to reiterate our primary message. In the case of an imminent cyber security threat, the U.S. government should be authorized to act immediately. With emergency responsibility in the hands of government, NERC will be better able to do what it does best; develop and implement cyber security reliability standards that will harden the grid against intrusion and aid in responding effectively to cyber security incidents.
Thank you.
SEN. BINGAMAN: Thank you very much.
Mr. Mosher.
MR. MOSHER: Thank you, and good morning.
Chairman Bingaman, members of the committee, thank you for asking me to testify this morning. I'm Allen Mosher, director of policy analysis and reliability for APPA. I'm here on behalf of APPA staff. There wasn't sufficient time for me to run the staff draft by APPA membership, so I'm giving you a preliminary view.
APPA is the trade association of the nation's 2000 state, municipal, and other publicly owned utility systems. We serve about 45 million people across the country in 49 of the 50 states. I did have an opportunity to speak with a member at the NERC Board of Trustees member meeting the other day about the draft legislation in my testimony, and he very much wanted me to emphasize that if the utility industry is given reliable, credible, actionable information from the federal government, we will act to protect our facilities. We have a vested interest in protecting both the assets and in ensuring reliable service to our customers. It's a responsibility to customers, to our communities, and to the nation as a whole to do that.
APPA does believe that legislation is needed, but it needs to be carefully drawn and to build upon the security -- cyber security and bulk power reliability framework that's already in place. We need to improve upon the NERC standards development process. Yes, it isn't fast enough, but we need to -- we do believe we can improve upon it, make it more effective, and meet many of the needs that are -- have been identified.
We do agree that there should be specific, additional legislative statutory authorities for the federal government, in particular for FERC and DOE. First, we support targeted authority for FERC to issue emergency orders and response to imminent threats to the bulk power system. These directives should, however, remain in effect only until the threat subsides, or we can -- and until we can replace them with permanent NERC reliability standards.
We also support specific authority for the commission to address certain vulnerabilities identified in the June, 2007 NERC advisory called Aurora. In APPA's view, those -- the Aurora-related vulnerabilities can and should be addressed through reliability standards, but until there are standards in place to cover it, then FERC should have some interim authority, but limited to that advisory.
We definitely need to have better mechanisms and statutory protections for communications. There is real problems communicating on the nature of threats, both from the government down to the industry, and back up from the industry to the government. There are particular problems for publicly owned entities, both federal, state, and municipal, because we are entities of local governments. We have public openness laws that sometimes get in the way of keeping information confidential.
And -- let's see, we will -- let me go on to the next point. We do have some concerns with the draft. It's potentially over inclusive of facilities. It covers generation transmission and distribution. We are concerned that if you include distribution facilities within the scope of the legislation, you may actually reduce the effectiveness of the overall program. By trying to cover everything, you may actually weaken the overall program.
In Section 224-B1 FERC is given very, very broad discretion to act in the public interest to protect against a cyber attack. We think there should some limitations on that authority. It could, in fact, in the absence of prior consultation with the industry, lead to requirements that are burdensome, very expensive, and potentially ineffective. Again, the commission can't know all of the details in all the different utility systems. As Rick said earlier, I have -- we have very small electric utilities in the country. I have members -- utilities that have staffs of five people. It would be impossible for them to be read into the programs and to work effectively in this construct. So thus, we need to have a limited scope to make sure we really have an effective program for the bulk power system.
Next, the bill gives both FERC and DOE authority to act on an emergency basis, although one is -- characterizes authority to act on vulnerabilities, and the other is threats. This could lead to conflicts between the actions of two federal agencies. And what we really can't afford to have in a time of crisis is two directives from two agencies that are inconsistent.
And finally, we need to have really far more effective measures on confidentiality. The bill raises the issue, but we need a much more comprehensive structure, and we'd be happy to work with the committee to work out such provisions.
Thank you.
SEN. BINGAMAN: Thank you very much.
Mr. Owens.
MR. OWENS: (Off mike) -- executive vice president for business operations for the Edison Electric Institute. I certainly do appreciate this opportunity to be with you today. I'm accompanied today by Steve Nowman (ph), who is the vice president of wholesale market development for the Exelon Corporation. Steve also serves as the chair of the Member Representatives Committee of the North American Electric Reliability Corporation. So he has extensive technical background and a good understanding of the NERC processes. (Inaudible) -- you asked me some hard questions, so I'll turn around and say Steve helped me out.
But let me get into the -- just the points that I'd like to make. I'd like to really focus on three areas this morning. I'd like to first say that I believe that the success of public/private partnerships in recognizing and addressing cyber threats and vulnerabilities are very critical. I also believe that there's a need to avoid unintended consequences when implementing cyber security remedies. And finally, I'd like to make a couple of comments about the joint draft proposal.
But let me start out and really piggyback something that Allen Mosher said earlier, and that is that we take the issue of cyber security very, very seriously in our industry, not just as utility owners and operators, but all aspects of the industry. We take it very seriously. We also recognize, however, that our cyber adversaries are becoming much more sophisticated, and so that compels that the private sector work more closely with the government in coordinating information from and to the government. So we see that we have a significant commitment to work very closely with the government to get a good understanding of the possibility of cyber threats and vulnerabilities.
We recognize that we have important roles and the government has important roles. And we believe that both the public and private sectors -- we need to have our regimes very clearly defined. We recognize that our roles are complimentary and our responsibilities may be complimentary. But we certainly do believe that there needs to be substantial cooperation between government agencies and utilities.
We also believe very passionately that grid security -- in order to provide grid security -- that the manufacturers of critical components of our systems -- they also need to come under some very high standards, and they need to demonstrate that they're adequately fulfilling their security responsibilities by adopting good security practices as well. Now, if our suppliers are building security into their products and providing mitigation and technical assistance and new vulnerabilities arrive, then it permits us to operate our systems in a much more secure and reliable fashion.
We also recognize, as Pat Hoffman indicated, that there are additional potential cyber vulnerabilities as we begin to digitize our systems. As we begin to go to Smart Grid technologies, we recognize that we open ourselves up for other vulnerabilities. And we believe that it is very imperative that the industry work closely with the vendors and the manufacturers to ensure that they understand that cyber security is essential so that they have cyber security protections, and that they're incorporated in devices as much as possible. To that end, we certainly do support the process currently underway at the National Institute of Standards and Technology to develop a framework of standards that will become the foundation of a secure, interoperable Smart Grid.
Now, we're also encouraging the development of a security certification program. Let me describe that. We call it a -- kind of a good housekeeping seal of approval, if you will, through which Smart Grid components and systems could undergo rigorous independent testing and receive a certification that security tests have been passed. If we're using new devices and we're moving to the Smart Grid, we believe that those devices really need to be able to pass through a very rigorous screen.
I mentioned earlier the need for cooperation between the government and industry. And EI members are working very closely with government partners -- the national labs, the FBI, the DHS, DOE, the Office of Director of National Intelligence, and even FERC -- in many proactive processes to enhance cyber security. We believe that this careful consultation with the utilities helps ensure that government intervention in protecting the grid from a cyber attack does not have unintended consequences. That's because, as you know, the grid is a very complex machine, and certain measures which might prevent a particular type of cyber attack could themselves have adverse consequences on the safety and reliability of the electric grid.
So we believe for this reason any new legislation giving FERC or the Department of Energy additional statutory authority should be limited to emergency situations where there is significant declared national security or public welfare concerns and should provide ongoing consultation with industry experts as much as possible. Now, we applaud the committee and the chair for the Herculean efforts in the adoption of mandatory reliability standards, and as was indicated earlier by Rick Sergel, there's a very deliberative process that we go through within the NERC framework and the adoption of standards. And we recognize that that NERC process really is not suited for developing standards that are designed to address emergencies where we require immediate mandatory action with the confidential handling of information.
But it's also important to recognize, as I believe, that the vast majority of cyber issues do not rise to the level of national security. And as such, we believe very strongly that the legislation should be focused narrowly on addressing a potential set of threats that legitimately merit special federal emergency authority.
I'll go back to a major theme, and that is promoting clearly defined roles and responsibilities, as well as ongoing consultation and sharing of information between the government and the private sector. In our opinion, it's the best approach to improve cyber security. EI and its member (companies ?) -- we remain fully committed to working with the committee, working with the various government agencies. I appreciate this opportunity to appear before you today, and I look forward to your questions.
SEN. BINGAMAN: Well, thank you all for your excellent testimony. Let me just ask a few questions and then defer to Senator Murkowski.
Mr. Mosher, you point out -- and I think several of the other witnesses did as well -- that the draft we have circulated here has both FERC and the Department of Energy -- with new authority to act on an emergency basis. And you say that you think this could be confusing and that APPA suggests that such emergency or expedited authority be assigned to a single agency. Which of the two?
MR. MOSHER: My recommendation is that the emergency authority to issue orders should be assigned to FERC, and that DOE should be given a lead role in the R&D and communications process. It's important, I think, to separate regulatory responsibilities and penalties for enforcement for failure to comply with government regulations, put that in one agency, and then put the R&D -- let's stretch the frontier responsibility in another organization. I think DOE is very well situated. I think we have immense opportunities to improve our communications to get information from the federal government to the industry, make it actionable, and I would hate to have a conflict of interest there -- (inaudible).
SEN. BINGAMAN: Mr. McClelland, do you agree with that way of fixing the problem?
MR. MCCLELLAND: If you'll bear with me just for a moment -- I brought along a statistic, if I can find my statistic. If I can't, I can almost recall it from memory. I'd rather not comment on the capabilities of the Department of Energy, but I would like to comment on the commission's capabilities. The commission is a regulator, and it deals with industry. Last year, for instance, the commission issued almost 9,000 orders to the affected entities, mostly to electric utilities. We had over 400 -- close to 500 -- re-hearings. So we have a process by which we can issue an order, and then we can hold a hearing to hear objections and come to a reasoned decision. We initiated approximately 50 enforcement cases and settled -- or ended 22 enforcement cases.
So the commission is well situated as a regulatory authority to make certain that measures, if you will, emergency measures that may be applied, get implemented. There's a hearing and appeals process, and then there's also an enforcement arm for folks that may not be so inclined to follow the commission's directives.
SEN. BINGAMAN: All right. So you think giving the commission authority to act in the face of immediate threats is a -- is consistent with the authority they currently have. Is that what I'm understanding?
MR. MCCLELLAND: Well, it's authority -- it's consistent with implementation. The commission has maintained all along that the commission is not -- we are not an intelligence or a security organization. We work very closely with the Department of Energy. We work closely with Homeland Security, the Central Intelligence Agency, the Department of Defense, Nuclear Regulatory Commission on intelligence matters, but many of our folks were -- in my particular office were mostly experienced electrical engineers from industry.
So we use that intelligence. We draw upon that intelligence. We have top secret NSCI clearances. We use that intelligence and coordinate very closely with the agencies to subsequently work with industry to try to address the vulnerabilities.
SEN. BINGAMAN: Let me ask you about one other point you made in your testimony. This might be something of interest to Senator Murkowski. You say Congress -- finally, Congress should be aware -- this is on page 16 of your testimony -- should be aware of the fact that if additional reliability authority is limited to the areas within the commission's jurisdiction under Section 215 of the FBA, it would exclude protection against reliability threats in Alaska and Hawaii and possibly the territories, including any federal installations located therein. And you mentioned New York City, as I understood it. Could you elaborate on that?
MR. MCCLELLAND: Yes. Would you like the elaboration just to the cities, or --
SEN. BINGAMAN: Well, elaboration on all of it, please.
MR. MCCLELLAND: The Defense Science Board, the Energy Task Force, issued a report. It was entitled, More Fight, Less Fuel. That's February, 2008. One of the primary findings -- they didn't intend to arrive at this conclusion, but they arrived at two primary conclusions. The second conclusion, which is the one that they had not intended to reach, was that the military's critical missions are overly dependent upon the commercial power grid. And the commercial power grid in many cases -- the military installations do not have sufficient backup other than for a few hours on base for selected facilities. That would speak very heavily -- there was also a classified annex, which we couldn't go in -- into an open forum, but the classified annex names specific facilities that would be at risk.
What we wanted to make certain of was that if Congress chose the definition of -- under the Federal Power Act, it would do so with a completely understanding that Alaska, Hawaii, perhaps the territories, would not be included. And so we couldn't assure that mandatory actions would be taken to protect -- to implement measures to protect the cyber security of those systems.
In addition, the Federal Power Act allows some discretion in the definition of bulk power system. One of the regions in the Northeast has chose to define bulk power system to largely exclude all facilities below 230,000 volts. In that particular case -- and they have that discretion now. It's subject to the commission's review, but the process will take some time to sort through. It could take years to sort through. That discretion essentially opts out all of New York City. If other entities or other regions exercise that same definition, then major population areas would be excluded from cyber security protection that the commission might employ under -- that definition under the Federal Power Act.
SEN. BINGAMAN: So you're suggesting that we clarify the -- what the definition needs to be under the Federal Power Act to deal with that problem, and we also clarify that if there is additional emergency authority given to FERC, that it not be restricted just to the Section 215.
MR. MCCLELLAND: No, I'm sorry. I probably wasn't clear. We're going to keep working out the Section 215 definition of bulk power system. The commission does have an ability to initiate proceedings and to clarify and issue directives on the definition of bulk power system. It's just a time consuming process. However, in a matter that affects national security where timely action and targeted action is critical, for instance, to the success of the military missions of the Department of Defense, that definition is not acceptable. And what we've asked this committee to consider is that it not use that definition of bulk power system and initiate a separate definition that would clearly delineate where the commission's authorities were under these emergency actions.
SEN. BINGAMAN: Okay. Let me defer to Senator Murkowski for our questions.
SEN. LISA MURKOWSKI (R-AK): Mr. Chairman, I appreciate you bringing up both aspects, certainly the clarification on the Alaska, Hawaii, and the territories issue, but also to better understand that inadvertently perhaps through our definition we could be laying vulnerable some of the larger cities, whether it be Washington D.C. or New York.
MR. OWENS: Senator, may I just -- if I might, please --
SEN. MURKOWSKI: Yes. John?
MR. OWENS: I don't necessarily agree with Mr. McClellan's explanation. Let me see if I understand whether there's a gap here in regulation. When he was describing the City of New York, I believe that he's describing local distribution issues, which I believe are fairly handled by the companies and the state agencies. I don't see a gap in their ability to respond to emergency situations. They understand those systems extremely well. They work very closely with the utility systems. They have a process where the government and the industry clearly understand their respective roles. I don't believe there's any evidence to indicate that there has been a failure of those agencies or those utilities to be responsive to a national threat. And I would go back to 9-11 to just suggest that to you, where I believe that we all applauded the efforts of the City of New York.
So I don't necessarily agree with Mr. McClelland that we need to extend FERC's jurisdiction all the way down to the distribution level.
SEN. MURKOWSKI: Well, I want to make sure that I clearly understand this discussion, because I think it's very, very important.
Now, what you're suggesting, Mr. Owens, is that through the local distribution system it can be handled, it has been handled, and we don't need to worry about it.
MR. OWENS: That's correct.
SEN. MURKOWSKI: If I have understood what we're attempting to do through this legislation -- is to allow for that authority to the FERC if it is -- if that threat is -- if that vulnerability is there.
But you're suggesting, Mr. McClellan, that if we limit it to the bulk power system, then we will not have the ability for the FERC to intervene. Is that correct?
MR. MCCLELLAN: Yes. And I guess I would like to clarify. I'm not certain I've made my point clear. Downtown New York City is served by a network of 138,000 volt facilities. If it's Congress's expectation that a population center like downtown New York City would be covered under an emergency provision like this -- in other words, that the commission would be able to implement mitigations, measures that would protect against a cyber security threat, their vulnerability, and New York City would be covered -- and that would not occur under the current definition of bulk power system in the Northeast.
SEN. MURKOWSKI: Under the definition as it is now included in this legislation, or the definition that we are currently operating under?
MR. MCCLELLAN: Well, the definition that we're currently operating under in Section 215 of the Federal Power Act. So my point was to make certain that if the committee chose to exercise or to use the definition of bulk power system as it's used in Section 215, it's subject to the interpretation and application of the regional entities. In this particular base, the regional entity has excluded the network, the 138,000 volt network that serves downtown New York City and other major facilities, such as -- I believe there are some nuclear power plants that are also excluded from regulation, the interconnections with those nuclear power plants. And so I think it's an important distinction to make.
SEN. MURKOWSKI: Mr. Sergel?
MR. SERGEL: Thank you, Senator Murkowski. If we start, I think, from Section 215 that was put in place, perhaps that will make it easier. The Congress did just a fabulous job there -- and I really believe that -- in defining the bulk power system as the users and owners and operators of the bulk power system and left it at that. And it has been the task of NERC, working with the Federal Energy Regulatory Commission, to determine what precisely is meant by the bulk power system. It is not defined per se, nor should it have been.
The law goes on to particularly exclude distribution facilities --
MR. OWENS.: Right.
MR. SERGEL: -- so it's users and owners of the bulk power system --
MR. OWENS: Right.
MR. SERGEL: -- and the law specifically excludes distribution. And what Mr. McClellan is saying is that from time to time we find ourselves where that is problematic. What a surprise that we -- (laughs) -- find that it's problematic with respect to New York City where the number of distribution facilities are so significant and the level -- and sort of the voltage level at which they conduct business at distribution is so high. Have I -- and so as a consequence, it is a particular example of where it is a challenge to determine it. It does not mean that it is per se excluded under that definition. We continue to work on that.
SEN. MURKOWSKI: I'm going to move on --
MR.: Yeah.
MR.: Yeah. (Laughs.)
SEN. MURKOWSKI: -- because my time has expired. I don't know whether we've clarified the issue or we've further muddied it --
SEN.: Or confused it.
SEN. MURKOWSKI: -- but it sounds like we do need to work on this just a little bit more.
Senator Shaheen.
SEN. JEANNE SHAHEEN (D-NH): I actually would like to switch topics, since I'm not any clearer on the answer to -- (laughter) -- the previous question. I want to talk a little bit about standards, because most of you mentioned those in your remarks, and this issue of adequate standards as we're looking to change our energy foundation in this country has come up time and time again.
So I guess my first question to you, Mr. McClelland is -- you stated in your testimony that the Department of Energy views the -- well, actually, I guess maybe I should direct this to Ms. Hoffman. The Department of Energy views the development of interoperability standards for Smart Grid technologies that include cyber security protections as a key milestone. How close are we to achieving that milestone, and what kind of progress has been made, and what more do we need to do in order to get there?
MS. HOFFMAN: Through the National Institute of Standards and Technologies, they've convened a workshop on April 28th and 29th to look at standards, which -- one of the domains that was discussed was cyber security standards. They will hold another meeting May 19th and 20th to continue that discussion of standards. So that standards process is moving as quickly as possible, but in the meantime what the Department of Energy has been doing is working with utilities vendors to look at procurement strategies so that as utilities purchase Smart Grid technology, they will have procurement strategies to define what should be some of those cyber security requirements in the interim until the standards are developed.
SEN. SHAHEEN: Would anybody else like to address where you think we are?
Mr. Owens, you mentioned standards in your testimony as well.
MR. OWENS: We're working very closely with Department of Energy. In fact, I would even suggest that the -- there's going to be an important meeting on May, the 18th where we're going to talk about some of the (new ?) standards and how we can move forward -- interoperability. And we are very much in support of the direction that's been carved out.
SEN. SHAHEEN: Were you suggesting that there be independent testing --
MR. OWENS: Yes.
SEN. SHAHEEN: -- separate form this, and how would -- how do you envision that operating?
MR. OWENS: Well, NIS is really complementary. I mean, when I spoke to the independent testing of the various components that would be -- comprise a Smart Grid, I was really speaking to the fact that in the absence of the NIS interoperability standards right now -- because utility systems are beginning to move aggressively towards Smart Grid -- that we have a way that we can verify that the technologies, the devices that are being installed on our systems are really cyber secure, that they've gone through some independent testing, that we have a set of standards that they have to meet, so that when we integrate them into the grid, we have a comfort level that those facilities will not pose additional cyber vulnerabilities.
SEN. SHAHEEN: So again, how do you envision that kind of independent testing? Would that be done by -- would there be standards that the manufacturer would have to meet?
MR. OWENS: There'd be a set of standards that would be developed, and the manufacturers would be held to those set of standards, and there would be an independent tester that would make sure that those component devices are consistent with the standards. If they're not consistent with the standards, obviously a utility would say we don't want to install that piece of equipment into our overall system because we're creating a potential cyber vulnerability because it hasn't met the test.
So it would be like a good housekeeping seal of approval, and all vendors would have to comply. That's actually what NIS is trying to do, and this is complementary of what NIS does, but recognizing that many of our systems are already beginning to put in Smart meters and other elements of the Smart Grid. We are suggesting that we try to do something right away to make sure that there's consistency and that there -- and that we're not subjecting our system to cyber vulnerabilities.
SEN. SHAHEEN: And do you have a proposal for who should do that independent testing, who should be responsible for it?
MR. OWENS: No, I do not.
SEN. SHAHEEN: Anyone else?
MS. HOFFMAN: I think it's a great opportunity for the market to develop that capability in the testing and the verification.
MR. OWENS: And I would agree with that response.
SEN. SHAHEEN: Thank you.
SEN. MURKOWSKI: Senator Corker.
SEN. BOB CORKER (R-TN): Thank you very much, and thank all of you for your testimony.
Mr. McClelland, you -- I think the chairman asked you about whether you should or should not have the ultimate, singular authority to take actions on an emergency or expedited basis. It was a pretty long answer, and I think you were saying yes, but I'd like a yes, no answer.
MR. MCCLELLAND: The commission has requested that authority, yes.
SEN. CORKER: So the answer is yes.
So I noticed, Ms. Hoffman -- and then in your opening testimony that Department of Energy is taking no position on this legislation, which, by the way, I find to be kind of odd, since this is sort of in your wheelhouse. And I don't know whether it's just due to lack of staffing right now or what, but in the event the legislation was changed so that FERC had solely that responsibility, would Department of Energy wish to weigh in on the legislation at that time, or does it agree with that proposition?
MS. HOFFMAN: You're correct, senator. The Department does not have a position on the legislation at this time. As we've looked at all emergencies within the federal government, coordination and consultation is very critical in making sure that everyone is on the same page with actions and responses.
SEN. CORKER: But consultation is interesting, and we like that too, I'm sure, but at the end of the day are you agreeing with the proposition that FERC should have -- and when you -- in an emergency you can't have two or three folks, I assume, as has been mentioned by others, issuing conflicting direction. You're agreeing, then, by lack of weighing in that FERC should have this responsibility?
MS. HOFFMAN: The Department does not have a position at this time, but I know the secretary is committed to working with the Administration on the (risk ?), roles, and responsibilities in determining who should have that authority.
SEN. CORKER: Well, this legislation is going to determine that authority, so let me just as a follow-up -- could you get the secretary to tell us yes, no, whether FERC should have this responsibility by itself? I do think it's problematic when we're looking at emergency issues to have two organizations involved that could issue conflicting direction. Could you get the secretary to tell us yes, no, whether it ought to be FERC or DOE? I think most of us would probably be uncomfortable with both.
MS. HOFFMAN: Sir, I can take the question for the record. I would like to bring up emergency versus vulnerability. The aspect of the legislation brings up two points, which is an emergency authority with the determination that there is actually a threat out there. The vulnerability part of the language as we read it provides an interim measure that if there is a vulnerability that it's discovered within the electric sector, that there is action that may need to be taken on that vulnerability if that vulnerability is determined to have a significant impact to the electric sector.
So one actually looks at a threat environment. The other one actually looks at a vulnerability that may be discovered, that it may be prudent for someone to take action on a near-term accelerated basis.
SEN. CORKER: So since there is a difference, are you saying that DOE should look at the vulnerability issue and FERC should command in the event of an emergency? Is that what you're saying, or are you not going to weigh in again?
(Laughter.)
MS. HOFFMAN: The Department does not have a position at this time.
SEN. CORKER: That's interesting. I assume it's -- there are some staffing issues that maybe caused this, and I certainly don't want to in any way embarrass you. If you could maybe get the -- whoever it is that would like to weigh in to weigh in on behalf of the Department at the appropriate time before we pass this out of committee -- which I assume is going to be like in a week. Is that correct?
SEN.: (Off mike.)
SEN. CORKER: That would be I think helpful to everybody. We obviously want to work, as you mentioned, in cooperation -- do you want to say something, Mr. McClelland?
MR. MCCLELLAND: Yes. I'd like to say that the draft bill does make an important distinction between the responsibilities of the Department of Energy and the FERC. The bill designates the ability to address vulnerabilities to FERC and threats to the Department of Energy. So in the particular draft the commission staff didn't necessarily see a conflict or an overlap between the Department of Energy's role and FERC's role.
SEN. CORKER: And the industry folks agree with that?
MR. OWENS: We think that there needs to certainly be a clear understanding of who deals with cyber threats, and so if that's the Department of Energy or FERC -- as long as there's a single agency and a clear, defined authority with respect to cyber vulnerabilities, I believe FERC already has that responsibility, and they've been implementing elements of that through their standards under Section 215 of the Federal Power Act.
SEN. CORKER: Mr. Sergel, you were mentioning that you all were working on some of the definitional issues that -- you know, I mean, New York City is a -- a been thrown out multiple times during the course of this testimony -- and that you all were working on definitional language, and that's evolving. However, since this legislation is to focus on cyber security and other kinds of things, would it be relevant for us to work out that definitional language in advance of passing this legislation, or just leaving it somewhat abstract when in essence -- I guess we're trying to figure out a way to actually deal with real threats that exist. Just curious as to what your response might be to that.
MR. SERGEL: Well, we are attempting to work out the precise lines of the definition between distribution, which is excluded from Section 215, and the bulk power system in which we have authority, and there are -- not a long list, but certainly a list of places where it's difficult, New York being the best example.
I think the question on the distribution side goes more to the necessity of the authority that you want to grant in an emergency, as opposed to that. So if, in fact, the authority of the -- to act in an emergency is intended to cover everyone and you wish to do that in this legislation, it would be -- you would want to then specify who that is, and it would extend, for example, to those places that are not interconnected with the United States, excluded from Section 215 -- Alaska and Hawaii, Guam -- not interconnected.
And so you would be extending the definition from 215. If you just think of it -- 215 is covering a portion, the largest facilities, the largest lines. But it doesn't include distribution. So I would think you would want to say what do you want to include? I would go from 215, and then I would decide what you were going to add. It's 215, plus. And if it was all of distribution, I -- my own view is that all of distribution is a reach, that that's not necessary here, but then at the same time I understand where it should be broader than the current definition of 215 -- Alaska, Guam, Hawaii -- potentially very large metropolitan areas, like New York and Washington, right, which -- military facilities. But I would add -- I would start from the definition of 215 and decide how much to add. If you decided to add all of distribution, that would be one way to do it.
SEN. CORKER: Madame Chairman, is it okay if I continue to listen? Mr. Mosher?
MR. MOSHER: Yes, thank you, Senator. I would suggest that the committee look and think seriously about starting in the other direction and figuring out which customers you're trying to protect and you're most concerned about rather than encompassing all of distribution. If you're concerned about New York City or Washington, DC or military facilities, then you need to talk, for example, starting with military with the base commanders there and identify their vulnerabilities. And then assign authority or set up regulations that would ensure that those particular facilities are protected. And that involves a relationship between a particular distributing utility and the customer.
Now, New York City and Washington, DC, I know, are areas of particular concern. Frankly, I think that both power reliability standards and the authority that's commonplace for the commission will, in fact, cause the utilities that serve those areas to adopt standards and policies and to train their personnel so that they will have cyber protection for the entire DV enterprise. That's the underlying part of the NYS spring work is that it's not a facility specific program. There's NYS for cyber security.
It's about protecting your entire enterprise and making sure there's no backdoor way of attacking the system. If you do it for the entire utility, you're indirectly going to protect the distribution facilities for part of it.
SEN. CORKER: I know my time's way beyond over. Thank each of you for your testimony. And I hope that what you may consider is that my sense is we're going to have a mark up on this very soon, is that on the definitional issue we just discussed. But also the definitional issue of critical electric infrastructure and cyber security threat, those two terms, I would encourage each of you to submit to us some clarifications that you think might be helpful to us. And again, Ms. Hoffman, thank you very much for being a good soldier today, and hopefully somebody from the department will respond to the questions. Thank you all very much.
SEN. MURKOWSKI: Thank you, Senator Corker. I think it is important to know we do have this on the schedule for next Wednesday for potential mark-up if all goes as planned. I think you've raised some good issues here today. It is important to try to get that input from the department, and we recognize that there's a lot happening, not the least of which is that people aren't entirely in place and perhaps might not be focused on this. But we are trying to move on it.
I might note, and it may have been already brought up by the chairman, but we are not the only committee looking at the issue of cyber security. There's legislation out there that would have FERC be consulting with the Department of Homeland Security. We've also got legislation coming out of the commerce committee where it would be the Secretary of Commerce that is providing the direction.
You've got another bill that would establish an office of national cyber security advisor within the executive branch. So, it's kind of all over the board right now. I guess I'll throw out this question to all of you. There's been some discussion about whether or not we need a cyber security czar. Is that where you go with it? Mr. Mosher?
MR. MOSHER: My view is that the committee ought to focus here on the particular concerns of the electric power industry and solve those as surgically as you can. Because the issue of cyber security is so much bigger than the electric power industry. The federal government, the executive branch and Congress need to come to a meeting of minds of what that federal government strategy is. And then you can do a comprehensive strategy, whether it entails a cyber czar in the White House, a special office there for the authority assigned to NSA, or whether it's shared with DHS.
Those are sort of mega-level issues that are, frankly, much beyond our pay grade. But we would like to see that our particular vulnerability issues and authority issues are resolved pretty quickly. And we certainly are willing to work with the Congress to resolve that as quickly as we can. And we hope that we can work with you and get something that we can all agree upon and get in place as part of the comprehensive energy bill.
SEN. MURKOWSKI: Mr. Sergel?
MR. SERGEL: Thank you. I agree with Allen, but not just over all, but within the specific confines of this bill as well, that the emergency authority for cyber security is extremely important to us. We need that. It's important to complement our standards. Our standards are incomplete without that authority. And, so, it's taking action on those things that we can do today to protect the bulk power system in that situation. And certainly we will work to get our definitions as precise as we can to make that as effective.
But it's to do that portion of it that's so important. There's always the broader and larger picture. But for this industry, we need the emergency authority granted to us through a single agency.
SEN. MURKOWSKI: That's fair, and I appreciate that. I was reading an article here that is posted in the Wall Street Journal this morning. It attracts my attention because it details a report that the air traffic data systems in Alaska were shut down by hackers. And, you know, when you're in a state like mine where everybody flies, and you've got your air traffic control systems that have been breached, this is a real problem.
Not to suggest that it's greater than the electrical. We recognize that in today's world where we're so connected in so many different ways, there's a level of vulnerability in our day to day lives that we could never even imagine a couple of decades ago. So, whether it's what's happening with air traffic control or electricity, just our security in general.
Let me ask a question. We did not address this in our legislation, but it's the issue of the potential costs. There has been some concern expressed with the cost of compliance, whether it's an emergency order through DELE or for expedited rules. And the concern that merchant suppliers can't pass these costs on that they need to incur in order to address the cyber security threats. Do we just consider these costs as part of doing business in today's world? Or should there be some kind of costs recovery mechanism included in our legislation?
As I said, we have not included it. But what's here, what's your position on that?
MR. SERGEL: Just two things for me, and then I'll turn it over to David Owen. First, the way standards are set under Section 215 with the industry participating assures that the costs of taking an action are incorporated in the decision itself. Because it's part of the process, and it's reflected there. And it's very important.
The second is that the 215 address the bulk power system, because it is the priority. It is the one in which we're most endangered. I point to the length of time ? we had an event in Florida. It was over in an hour. Whereas the August, 2003 blackout, it took days to recover from that same event in many places. So, it's very important that we deal with the bulk power system large scale or whole orders of magnitude greater concern.
So, from the standpoint of what it costs, let the standards process we have today do the job and focus on the bulk power system. It's where the highest priority is. So, from cost, those would be my suggestions.
SEN. MURKOWSKI: Mr. Owen?
MR. OWEN: Soon after 9-11, FERC adopted a policy, because it recognized that companies wanted to secure their systems. And they said in emergency situations, they would focus on giving you cost recovery. So, I think it is very, very appropriate for merchant generators who don't serve retail customers and don't go before state PUC that to the degree that we're responding to emergency standards, standards relating to cyber, bought to reduce cyber vulnerabilities and so forth, it is very, very appropriate that they get cost recovery. I think that's very consistent with how FERC has dealt with issues in the past.
SEN. MURKOWSKI: Mr. McClelland?
MR. McCLELLAND: I'd like to add to that. In fact, David stole my thunder. The commission did issue a policy statement after 9-11 that said it would prioritize costs recovery filings for security reasons, for security aspects. So, the commission's very aware of that. As a staff member, I can say that it seems reasonable. And as a staff member, I would support cost recovery filings in order to comply with measures necessary to protect the bulk power system, be they cyber or be they physical.
And if I could just throw the pot back up again, because it seems like it's settled down a bit too much, back to the issue as far as the definition of bulk power system, Smart Grid actually would enable a new type of attack vector. Rick's talked about priority associated with bulk power system, but if you could imagine many millions and millions of distribution meters being installed on the Smart Grid and have two-way communication capability and would be interacting perhaps back to ISO or an RTO or some central control center. That's another path and a substantial path for compromise. And there are several different attack vectors that can be associated with the installation of those type meters.
So, it's a complex issue, it's ever changing.
SEN. MURKOWSKI: Do we need some kind of additional federal authority as we reckon with the complications, as we look at the Smart Grid and how that plays out?
MR. McCLELLAND: I think the committee needs to consider that aspect. And I think that it needs to be well aware that as Smart Grid is implemented, and as these devices, these formerly dumb appliances that couldn't communicate now can communicate in two directions. Any time there's two-way communication, there's a chance for cyber compromise.
The current draft does go through the distribution level. So, it appears to be a mechanism by which Smart Grid could be addressed. But it would be an expansion, a significant expansion of commission's authority if the commission were selected as the lead agency to implement these mitigation measures for the vulnerabilities.
SEN. MURKOWSKI: Senator Shaheen.
MR. OWEN: Very briefly, the commission has no rate jurisdiction over distribution. So, if the costs are incurred at the distribution level, then this should be something before state public utility commissions. And also the mechanisms for guaranteed rate recovery for independent power producers would give public power systems some heartburn. I will leave it at that.
SEN. MURKOWSKI: Senator Shaheen.
SEN. JEANNE SHAHEEN (D-NH): Thank you. I want to go back to the definition, because I guess I'm a little confused by the previous exchange. Because as I look at the bill, it defines critical electric infrastructure and would amend the Federal Power Act. And it seems to me it's a pretty comprehensive definition, because it defines it as systems and assets, whether physical or virtual, used for the generation, transmission or distribution of electric energy affecting interstate commerce that is determined by the commission or secretary. How ever that gets resolved, are so vital to the United States that the incapacity or destruction of the systems and assets would have a debilitating impact on national security, national economic security or national public health or safety.
I mean, I guess as I read this definition, it would address the concerns that you all are raising. Do you think that definition is not adequate if it were adopted in the bill?
MR. SERGEL: The definition in the draft legislation is the broadest one possible. You are absolutely correct. It does not need to be broader to increase the protection. The current Section 215 covers only the bulk power systems, the largest line and plants and the interconnected system in the United States. Therefore, excluding both distribution and Guam, Alaska, Hawaii as well.
I think the NERC's position on this is that we start from the bulk power system, because it's the highest priority. It needs to be protected. And that addition to that definition to expand it should be carefully done because the authority being granted here is so great. Now, there's two different components of the draft. One component of the draft is to emergency authority. And on that I would say --
SEN. SHAHEEN: Which is the definition I just read.
MR. SERGEL: Yes. And, so, as it relates to giving emergency authority on that expanded definition, we will all work to make sure that we understand how that should be done and how it should be done effectively.
For example, then, when you move to the vulnerabilities language, I would be willing to say I think that definition is too broad for the vulnerabilities language because it would give the authority to order distribution companies to take actions from the federal government, which is not in place today. And, so, I think that definition is broad enough to protect for cyber security but is actually a reach too far with respect to standards setting. An emergency authority, it's logical. On standard setting, it's a reach too far.
SEN. SHAHEEN: So, is everyone on the panel in agreement that in terms of a definition for an emergency situation, that that definition is adequate? Or is there some objection from the rest of you that that's going too far?
MR. OWENS: I think it is my view that the definition goes too far on distribution even for emergency authority to have a regulatory program that's actually going to be effective. I can see it cratering just in the number of entities that the commission would have to pre- establish communication pathways to make it work. If it has an authority to issue an emergency order, then it presumably needs to know who it's going to contact. If it has to contact all of the roughly 1,650 municipal systems in the country that are not under the NERC compliance registry, then the FERC would have to establish who that contact person is, what clearances they have and have the ability to execute it.
SEN. SHAHEEN: If there's a current emergency, how does that work? I mean, right now in the absence of this kind of legislation to address cyber security, if there were an emergency affecting the municipal utilities, how would that be communicated to them?
MR. OWENS: Today, within the scope of NERC's authority, they're communicating primarily with the registered entities. We are working to expand their ability to communicate through the ESI sites, the electricity sector information sharing and analysis center. Excuse me for the acronym. We will be improving it and have voluntary communications that will reach basically all municipals over time. But it's not in place yet. We, again, are trying to prioritize, get the communications down where the risks are the greatest, which are on the larger entities.
My concern is not on the emergency authority. But it's the regulatory hooks that come with it. And the effectiveness of the communication to make sure that, for example, when Joe sends out of a directive, he needs to know if the other person on the other end of the line has the security clearance. I know for a fact that we can't get security clearances to all of these entities. It would just overwhelm the capability of the FBI to get all the clearances done. People change jobs, people are performing multiple functions.
It just isn't going to work.
I'm suggesting a more targeted approach going to defense establishments and to addressing whatever concerns you have with large cities. That would be the way to focus, and that would be my recommendation.
SEN. SHAHEEN: Mr. McClelland?
MR. McCLELLAND: When we meet as federal agencies and we discuss cyber security and cyber security issues that would affect the electric utility industry, when we speak about the electric utility industry, we say they're out in the wild. And the reason why we say they're out in the wild is that they don't have information regarding the current threats and the current activities that are being propagated on the electric grid.
One thing I would like to address that Allen had said was that we needed a security clearance or we need a security clearance to communicate with entities. Our assumption would be that if we broadcast the information out to a large number of entities, forget it. That information will be disclosed. And so, the advisories or the orders that we would issue, the advisories NERC crafts and the orders we would issue will be carefully crafted so as to not compromise national security but would provide clear direction.
The testimony that I gave today, the oral and written testimony, was merely intended to reflect the fact or inform the committee that there's a clear distinction between there's a limitation under 215 as to how far the commission can reach. The staff draft, however, went much further and captures even distribution. That capturing effect, or that effect would, in turn, capture the Smart Grid meters, the meters that would be deployed. We didn't address the complexities associated with an agency and exercising that control. But the definition seems to, and the testimony is reflected to say that that definition's very broad. And if the committee intends to move in that direction, the committee should understand that Alaska, Hawaii, the territories and the large urban areas should be captured from the commission's perspective, and we are advising you in regard to that definition.
In other words, the definition appears to be adequate and separate from the definition of bulk power system under 215.
SEN. SHAHEEN: But that's why I'm still confused. Because if the definition says it would cover any system that would have a debilitating impact on national security, economic security, public health or safety, why would that not then affect the Alaska, Hawaii and the territories?
MR. McCLELLAND: Well, I think the question would be what was intended by the draft and how does the Federal Power Act capture Alaska and Hawaii and the territories.
SEN. SHAHEEN: So, do you also share the concern expressed by others on the panel that this definition is too broad?
MR. McCLELLAND: It depends on what the intent of the committee is. If the direction of the committee is to ensure that the agencies, the Department of Energy and the Federal Energy Regulatory Commission would have sufficient authority to be able to address cyber security threats that could affect the United States, could impact the mission of the Department of Defense, the military facilities. Then we'd say, no, the definition is not too broad if you intend to capture Alaska and Hawaii and the territories.
If, however, you intend to limit it to, say, the continental United States, and just the definition of a bulk power system under 215, then you should be advised that there are limitations with that definition and complexities associated with the interpretation and the administration of that definition. And that in and of itself, if one is speaking about national security, that could render the actions ineffective. If there's disagreement about where it applies and how it applies and whether or not it goes to a downtown urban area and there's some room for interpretation or discussion, you really can't be sure that the directive you've issued will be affected to address the cyber security concern.
MR. OWEN: Senator, can I try to just simplify this? I think we're making it a little bit too complicated. You asked if the definition is too broad. If you're seeking to define a national emergency, and you know the components that make the electric system, the definition covers the broadness of the electric system. But then if you're speaking to how do I define a cyber vulnerability, what is the level or the scope of authority of the Department of Energy at the Federal Energy Regulatory Commission, you're raising a different set of issues.
So, we have to separate cyber threat from cyber vulnerability. In a cyber threat, you certainly do. Even Allen's members want to know that if there's a cyber threat, it needs to be well communicated to them so they can take corrective action, so we don't have widespread disruption. So, I don't think anybody has a problem with that. We need to make sure that there's a single agency that has that responsibility. And we're clear, and there's ongoing communication with the utility and people that have security clearances. So they can huddle together and say, well, here are the solutions to deal with this immediate threat.
SEN. SHAHEEN: Okay, can I stop you right there, because that's not what I heard Mr. Mosher say.
MR. OWEN: Well, no, I just changed it a little and said that if you want to have communication with your folks --
SEN. SHAHEEN: So, do you agree with what he just said?
MR. MOSHER: Yes, I do. If we're talking about communication, then I agree. And what David was saying is we get the experts together talking to the federal government. With experts from the industry, experts from the government, distill the threat down to something that's actionable. Because of need-to-know basis, take out all of the underlying threat information that should be classified, tell the entities what to do. That can be communicated.
Now, the question where we may differ is on whether there's a regulatory structure that's imposed upon this to say that if the entity that receives the information does not comply, then there will be sanctions. And it's when you get to the sanctions that the process breaks down, because there's regulatory burden increases. The entities that receive this information are going to respond to it. But they are very different in their capabilities to respond to this information. And they're different in the vulnerabilities they present to the nation. Small municipals with one stoplight aren't in the same category as PEPCO.
SEN. CORKER: I think this hearing's coming to a close pretty soon. And we've got a four page bill. It's not like it's pretty short. And I think we've found through this Q&A time that it may be doesn't adequately address some of the definitional issues that are important to each of you that you actually have to deal with on a daily basis. And you're asking what the intent of the committee is. Look, I mean ? we're senators. Okay? Let's face it. We do not understand fully as each of you do, and that's why you're here, exactly how this language affects you on a daily basis.
I think our concern is, we're concerned about cyber security. Okay? And we're concerned about making sure Americans, including those in Hawaii and Alaska wake up and have power to do the things they need to do. And that our country has the ability through its military to do the things necessary. So, I would suggest that the four of you, and if DELE determines it wants to weigh in, I think it might, that y'all take these four pages and make it work and give us the input back, even if it's six pages. Okay? To sort of deal with this.
It's evident that you guys have a wealth of knowledge that we don't. That's why you're here. And I would just ask you to help with us because it sounds like that we, in some ways in trying to solve this problem, could raise more questions than answers. So, I'll conclude with this, at least my portion of it.
Mr. McClelland, you mentioned that there are issues in addition to cyber security that we need to be addressing. That there are other national security threats to reliability. And I'm wondering if in this little four-pager that we have, it could be five, six, seven, eight.
Are there other powers as it relates to the reliability side that you feel like we ought to be addressing for FERC right now?
MR. McCLELLAND: Yes. Our point in the oral remarks and my written testimony is that there are physical attacks that can occur on the power grid, and those attacks can be just as devastating as cyber attacks. And, so, if Congress would entrust an agency to be able exercise directives, not ask for voluntary measures but exercise directives over the industry affected industry for cyber, our position is that it should consider or should also grant the agency an ability under extraordinary circumstance to also exercise actions against physical threats.
Now, a good example is a bulk car system transformer. If there were some issue or information that would indicate that these transformers were affected, the affected agency or the agency in charge could then issue a directive to help or to give guidance to the affected industry to protect those transformers. Perhaps relocate the transformers or take other actions in order to secure these transformers for a period of time.
SEN. CORKER: I notice the two guys on the end sort of shrinking ?
MR. MOSHER: There are numerous police agencies in the United States, and the FERC is not among them. And, particularly for municipal utilities where we have a local police department that they're, frankly, very good at maintaining local security, they know who isn't from the community and is lurking around the substation. I agree with Joe that there are physical security concerns, but I do not think that the FERC is the appropriate agency to undertake that.
MR. OWEN: And I would agree. I think if there are other agencies that have the responsibility, I think Joe is right that there are elements of our system that present some vulnerabilities. He mentioned specifically transformers, and we already have an industry effort underway to make sure that we can secure, if we have a disruption in our transformers, we have an inventory of transformers that can be quickly mobilized so that we can make sure that electric service is restored very quickly. FERC has blessed that approach, but FERC is not the agency that deals with all the physical aspects of our systems.
I think that there does need to be coordination. If that's what Joe is indicating, I do agree with him that there needs to be ongoing coordination between the federal government and the state and local agencies.
MR. SERGEL: On physical security, I worry that too many agencies that are qualified will show up to help. On cyber security, I lie awake at night worrying that no one will show up. Cyber security emergency legislation is absolutely essential. There are physical issues, they're real. But, again, I agree with my associates that that FERC is not the priority that I have, but it's also that others would be the ones who would be better suited to do that.
SEN. CORKER: Madame Ranking Chairman, I think we've had some great witnesses. And I do ? Did I say ranking chairman? Acting chairman, acting chairman. I do wonder if we're ready to do this next week. I know it's a short piece of work, four pages. But it seems like a very, very important issue. And it seems like that these witnesses have some clarifications that could be incredibly helpful. Either they have some quick work to do and all of us to sort of sit down and think that that what they do is good, or maybe we ought to think about maybe looking at this some more. Because I know you're very concerned. I've heard you talk several times about cyber security. I know the senator for New Hampshire is, too. I know our whole country is. And I just wonder if we're adequately addressing this right now.
SEN. MURKOWSKI: Thank you, Senator Corker. I think we all share the concerns. And I'm pretty certain that the folks within the White House are very keyed on this as well. Whether it's cyber security within the power grid or, as I mentioned, cyber security issues that crop up in other aspects of our day to day life in commerce.
But the problem is that they perhaps have not moved as quickly in determining how they are going to approach the issue of cyber security. And, again, I threw out this whole discussion about cyber security czar. I'm not convinced that's necessarily what you need. But I think it speaks to the issue that we're faced with today that there is a level of vulnerability that we have that the smarter that we get, and our ability to utilize new technologies. And Smart Grid is a perfect example of, boy, makes our life better and more efficient, but exposes us to a level of vulnerability if we don't build securities into our system. And we've got to be on top of this in a very, very strong way.
So, the issues that have been presented today I think have been very helpful. I think you're right, Senator Corker. We have recognized that as part of the comprehensive energy bill, we'd be foolish not to include some aspect of cyber security into an energy piece. But how we define it and kind of, who is in charge here?, is really very key. And I think it's important that we do our best to try to get it right. So, I appreciate the input from the witnesses here today, and the good exchange from key members this morning.
Thank you.