Cybersecurity Requirements

NY-ADR

11/6/19 N.Y. St. Reg. PSC-09-19-00013-A
NEW YORK STATE REGISTER
VOLUME XLI, ISSUE 45
November 06, 2019
RULE MAKING ACTIVITIES
PUBLIC SERVICE COMMISSION
NOTICE OF ADOPTION
 
I.D No. PSC-09-19-00013-A
Filing Date. Oct. 17, 2019
Effective Date. Oct. 17, 2019
Cybersecurity Requirements
PURSUANT TO THE PROVISIONS OF THE State Administrative Procedure Act, NOTICE is hereby given of the following action:
Action taken:
On 10/17/19, the PSC adopted an order granting, in part, and denying, in part, Joint Utilities' petition and adopts minimum cybersecurity and privacy protections.
Statutory authority:
Public Service Law, sections 5(1)(b), 65(1), (2), (3), 66(1), (2), (3), (5) and (8)
Subject:
Cybersecurity requirements.
Purpose:
To grant, in part, and deny, in part, Joint Utilities' petition and adopt minimum cybersecurity and privacy protections.
Substance of final rule:
The Commission, on October 17, 2019, adopted an order granting, in part, and denying, in part, Consolidated Edison Company of New York, Inc., Orange and Rockland Utilities, Inc., Central Hudson Gas & Electric Corporation, National Fuel Gas Distribution Corporation, The Brooklyn Union Gas Company d/b/a National Grid NY, KeySpan Gas East Corporation d/b/a National Grid, and Niagara Mohawk Power Corporation d/b/a National Grid, New York State Electric & Gas Corporation, and Rochester Gas and Electric Corporation’s (collectively, Joint Utilities) petition and adopts minimum cybersecurity and data privacy requirements for entities that receive from, or exchange customer data with, the utilities on an electronic basis other than by email. Joint Utilities’ are directed to, within 60 days from the date of the Order, file a revised Data Security Agreement and Self Attestation consistent with the discussion in the body of the Order. Energy Service Entities seeking access to customer data through utility IT systems shall be required to execute a Data Security Agreement and Self Attestation as revised in conformance with Ordering Clause No. 1 as a prerequisite of accessing such customer data, subject to the terms and conditions set forth in the order.
Final rule as compared with last published rule:
No changes.
Text of rule may be obtained from:
John Pitucci, Public Service Commission, 3 Empire State Plaza, Albany, New York 12223-1350, (518) 486-2655, email: [email protected] An IRS employer ID no. or social security no. is required from firms or persons to be billed 25 cents per page. Please use tracking number found on last line of notice in requests.
Assessment of Public Comment
An assessment of public comment is not submitted with this notice because the rule is within the definition contained in section 102(2)(a)(ii) of the State Administrative Procedure Act.
(18-M-0376SA1)
End of Document