2021 Fall Reliability and Security Seminar

Discussions will focus on reliability and security of the bulk power system, lessons learned and Change and Configuration management topics.

October 5, 12:30 p.m. – 4:30 p.m. EST October 6, 8:00 a.m. – 12:00 p.m. EST WebEx

2021 Fall Reliability and Security Seminar 2021 Fall Reliability and S c rity Seminar

October 5-6 WebEx

Fall Reliability & Security Seminar

Agenda

SERC is committed to providing training and non-binding guidance to industry stakeholders regarding emerging and revised Reliability Standards. However, compliance depends on a number of factors including the precise language of the Standard, the specific facts and circumstances, and the quality of evidence. Purpose: Discussions will focus on reliability and security of the bulk power system, lessons learned and Change and Configuration management topics. . The agenda allows time for Q&A after each presentation. Therefore, times listed may vary. Those who attend the entire seminar will receive a participation certificate. The certificate does not satisfy educational requirements such as NERC continuing education hours.

WebEx Logon Useful Links Questions for SERC Speaker Bios

Click on speaker’s name on agenda

Tuesday, October 5, 2021

12:30 p.m.

Welcome

Todd Curl – SERC Senior Manager, Risk Awareness and Oversight

Brian Thumm – SERC Vice President of Performance Improvement and Risk Mitigation

12:40 p.m.

SERC Update

Rick Dodd – SERC Senior CIP Compliance Specialist

Align Update

1:00 p.m.

1:15 p.m.

New and Revised Standards Update

Dave Kruger – SERC Program Manager Operations

Entity PNC and MP checklist

1:35 p.m.

Janice Carney – SERC Senior Compliance Engineer

1:45 p.m.

CMEP Implementation Plan Update for 2022

Todd Curl – SERC Senior Manager, Risk Awareness and Oversight

Agenda

Tuesday, October 5, 2021

WebEx Logon Useful Links Questions for SERC Speaker Bios

Registration and Certification Revisions to the Certification areas of the ROP and SERC Processes

2:00 p.m.

Marie Kozub – SERC Sr. Coordinator Certification & Registration Peter Heidrich – SERC Sr. Coordinator Certification & Registration

2:30 p.m.

Break

Click on speaker’s name on agenda

2:50 p.m.

REF Election Update

Greg Davis – Georgia Transmission Corporation Regulatory Compliance Manager

O&P Focus

Facility Ratings Expectations and Lessons Learned

3:00 p.m .

Joel Rogers – SERC Senior Auditor O&P

Regional Entity and Stakeholder Collaboration Computer Based Training for PRC - 019

3:30 p.m.

Marcus Beasley – SERC O&P Auditor

3:50 p.m .

Steve Rose –SERC Auditor O&P Greg Tenley – SERC Senior Auditor O&P

Real Time Assessments

Agenda

Tuesday, October 5, 2021 O&P Focus

WebEx Logon Useful Links Questions for SERC Speaker Bios

4:10 p.m.

Mike Kuhl - SERC Manager of O&P Monitoring

Renewables Penetration Grid Considerations

4:25 p.m .

Wrap-up

Todd Curl – SERC Senior Manager, Risk Awareness and Oversight

Click on speaker’s name on agenda

4:30 p.m.

Adjourn

Agenda

Wednesday, October 6, 2021 CIP Focus

WebEx Logon Useful Links Questions for SERC Speaker Bios

8:00 a.m.

Welcome: Day 2

Todd Curl – SERC Senior Manager, Risk Awareness and Oversight

Leslie Beam - Cisco Global Transformation Operations Change Management Leader

8:05 a.m.

Organizational Change Management

Click on speaker’s name on agenda

Bill Peterson - SERC Manager Outreach and Training

8:35 a.m.

Change and Configuration Management of Critical Infrastructure

Justin Kelly – SERC Senior Compliance Engineer Chris Holmquest – SERC Reliability & Security Advisor

9:00 a.m.

Supply Chain and Vendor Interactive Remote Access

Erik Johnson - R eliability F irst Director Reliability Analysis

9:30 a.m.

The Real Risks of Patching

10:00 a.m.

Break

Kenath Carver - Texas RE Manager of CIP Compliance Monitoring

10:20 a.m.

New Change on the Horizon - CIP-012

Lonnie Ratliff - NERC Senior Manager, Cyber and Physical Security Assurance

Network Change - Third Party Sensors

10:50 a.m.

Agenda

CIP Focus Wednesday, October 6, 2021

WebEx Logon Useful Links Questions for SERC Speaker Bios

11:30 a.m. Entity Engagement Questions Workbook

Stephen Brown – SERC Director of Cyber and Physical Security

11:50 a .m. Wrap-up

Todd Curl – SERC Senior Manager, Risk Awareness and Oversight

Click on speaker’s name on agenda

12:00 p.m. Adjourn

WebEx Logon

WebEx Logon

The WebEx session will be recorded. The recording will be posted to the SERC website and will, therefore, become public.

WebEx login information will be sent to registered attendees by Monday, October 4, 2021 Join by phone1-408-792-6300 Call-in toll number (US/Canada)

Participants will be muted upon entry to eliminate background noise. Please send questions through the Chat feature.

Can't join the meeting? IMPORTANT NOTICE: Please note that this WebEx service allows audio and other information sent during the session to be recorded, which may be discoverable in a legal matter. By joining this session, you automatically consent to such recordings. If you do not consent to being recorded, discuss your concerns with the host or do not join the session.

Useful Links

Topic

Purpose

RegisteredEntityForum REF Steering Committee O&P CIP

If you have a question you would like to submit anonymously, you may do so by contacting one of the Registered Entity Forum Steering Committee members. eLearning Modules, COVID-19, Hurricane and Cold Weather Preparedness, Supply Chain Resources. Past and present newsletters.

Resource Library Newsroom Events Calendar

Register for SERC’s upcoming outreach events

Acronym List

Industry Acronym Reference Index

HOME

Questions for SERC Questions for SERC

Link to Form Link to Form

• Q&A Process • Entity Assistance

WebEx Logon Useful Links Questions for SERC Speaker Bios

Email

Topic

• General inquiries / FAQ • Seminar & Webinar Topic Suggestions • Media inquiries

Support@serc1.org

• SERC Membership • SERC Committees • SERC Compliance & Committee Portal/Committee related issues • Registration and Certification Issues • Compliance monitoringmethods: o Self-Certification o Self-Report submittals o Compliance data submittals • Enforcement and Mitigation o Mitigation Plan submittals • SERC Compliance & Committee Portal-Compliance related issues

SERCComply@serc1.org

• Reliability Assessment data reporting • Reliability Assessment forms • Annual Voting Rights • Reliability Data Reporting Portal

RAStaff@serc1.org

• Industry Subject Matter Expert (ISME) Program • Submitting an ISME application

ISME@serc1.org

• Event Reporting

Reporting Line Sit@list-serc1.org

• Situational Awareness • Events Analysis

SAEA@serc1.org

HOME

Speaker Biographies

Todd Curl Todd is currently responsible for managing the area of Risk Awareness & Oversight which contain the CMEP functions of Inherent Risk Assessments and Compliance Oversight Plans. Previously Todd managed the area of Compliance Monitoring (in both Operations & Planning and Critical Infrastructure Protection areas). Also he was Manager of Compliance Programs which included Registration & Certification, Compliance Investigations, and Compliance Outreach. Todd joined SERC as an O&P Compliance Auditor in 2010, with about 29 years in the electric utility industry. Before joining SERC, Todd was a Senior System Operator at Southern Company’s Power Coordination Center. Primary responsibilities included providing real-time monitoring and control decisions and direction for the 24/7 operation of the Southern Company bulk power system balancing area. He also was responsible for various aspects of reliably operating the bulk power system in a coordinated manner with the four Operating Company transmission control centers, generation operations, and neighboring utilities. He worked with a team of NERC certified operators balancing generation with load, keeping the transmission system reliable, and ensuring correct interchange power flows with neighbors. Todd also spent 10 years on Southern Company’s energy trading floor as an Energy Coordinator, providing economic evaluation and negotiation of next-hour power sales and purchases, and arranged for scheduling of transactions in a real time 24/7 operation. Todd also spent 17 years with Georgia Power Company as a Transmission Operator, and a Substation Maintenance electrician. Todd has a Bachelor of Science degree in Business Administration, and an Executive Certificate in Organizational Leadership from the University of Notre Dame. Todd is also a NERC Certified System Operator with the Reliability Coordinator certification since 1999. Todd has also completed NERC Audit/Certification Team Leader training, and Compliance Investigations training. Brian Thumm Brian is the Vice President of Performance Improvement and Risk Mitigation. In this role, Brian leads SERC’s Risk Assessment & Mitigation, Training & Outreach, and Strategic Initiatives & Continuous Improvement departments. From an external perspective, this includes the oversight of SERC’s Entity Assistance function, which provides entities with Regional perspectives and best practices for myriad reliability and security risks; and oversight of the Risk Assessment and Mitigation function, which performs Inherent Risk Assessments for entities and risk/harm determinations for potential noncompliances. The combination of these roles provides a unique platform from which to communicate emerging and persistent risks to a broad stakeholder base, and to work with registered entities to resolve those risks in a collaborative manner. From an internal perspective, he oversees the strategic planning for the organization, which includes development of the strategic plan as well as development and monitoring of the corporate strategic initiatives. He is also responsible for several internal oversight functions, including quality assurance, internal controls, program readiness, operational excellence, continuous improvement, and the Project Management Office (PMO). Brian has previously provided oversight for SERC’s Compliance Monitoring functions, including audits, self-certifications, and compliance investigations, as well as the Reliability Assessment and Performance Analysis (RAPA) program, which uses data collection and analysis to identify reliability risks within the SERC footprint. Prior to joining SERC, Brian served as Director of Regional Planning for ITC Holdings Corp. There, he led a group of engineers engaged in economic planning analysis, load forecasting, stability analysis, technical studies, and NERC compliance, as well as ITC’s post-Order 1000 planning-related efforts across the country. Brian has over 25 years of electric industry experience, including holding positions in transmission planning, transmission operations, regulatory strategy, external affairs, project development, nuclear licensing, and computer services. H e received a Master’s in Business Administration from Michigan State University; a Master of Science in Electrical Engineering from Tulane University; and a Bachelor of Science in Electrical Engineering from Rensselaer Polytechnic Institute. He is a registered Professional Engineer in Michigan and Louisiana and a certified Project Management Professional.

HOME

Speaker Biographies

Rick Dodd joined SERC on July 1, 2019 as a Senior CIP Compliance Specialist. Rick works in the Risk Assessment and Mitigation team specializing in Critical Infrastructure Protection responsible for implementation of the SERC Compliance Program that assesses overall entity risk within the SERC Region. In addition, he works as a single point of contact with entities to perform specific inherit risk assessments (IRAs) and internal controls evaluations, as well as to review, accept, track, and verify the entity’s Mitigation Plans pertaining to issues or violations of NERC Reliability Standards. Rick has over 38 years of management and technical experience in all aspects of IT and Information Security. Prior to joining SERC, Rick worked with FRCC as a Sr. Risk Assessment and Mitigation Specialist for more than six years as a team member performing similar functions. Prior to joining FRCC, he was a senior member of an Energy Practice consulting team for five years, participating on NERC working groups and numerous client engagements relevant to the CIP Reliability Standards and NEI 08-09, Revision 6 including engagements at numerous registered entities across most of the Regions. While his expertise is broad in all aspects of the CIP Reliability Standards, he has written many highly regarded compliant incident response and recovery plan documents commensurate with the culture and needs of utility clients. His training capabilities are enhanced from his role as an instructor, as he brings more than 10 years of experience as an instructor for diverse curriculum in both classroom and online settings for IT and business subjects. He started his career in the telecommunications industry with Verizon Data Services (formerly GTEDS) gaining extensive knowledge and experience in developing, implementing, and administering scalable multi-tiered, information security, state-of-the-art data warehouse, decision support, document management, Internet website, access administration, and billing systems using the full SDLC. He has demonstrated expertise in gathering business requirements, business process analysis, setting policies and standards, trouble shooting, tuning, and system evaluation. During his tenure with Verizon Data Services, he also managed an Information Security team of more than 30 employees. The wide versatility in multiple computing environments, with a strong understanding of object- oriented technologies, web services and workflow technologies along with BPMN, UML, and Use Case Methods, complements the needs of the team. He has directed and participated in the selection of hardware and software, building proof-of-concept/pilot projects aiding in deployment of enterprise-wide systems. Rick is a Certified Information Systems Security Professional, and holds a Master of Science in Computer Information Systems, a Master of Business Administration, and a Bachelor of Science in Professional Management from Nova Southeastern University, Ft. Lauderdale, FL. Rick Dodd Dave Krueger has been with SERC for three years and is currently the Program Manager, Operations. Prior to that, Dave spent nearly 14 years at ISO New England. He worked in IT, Real-Time and Day Ahead Markets, and spent his last 10 years working in the EMS Modeling and Real-Time Support group and the final 5 as supervisor of the group. Dave has a Bachelors Degree in Electrical Engineering from Rensselaer Polytechnic Institute and a Masters Degree in Power Systems Management from Worcester Polytechnic Institute. Dave Krueger

HOME

Speaker Biographies

Janice Carney

Janice Carney joined SERC in January 2009 as a Compliance Engineer, and currently serves as a Senior Complaince Engineer. Ms. Carney is responsible for administering the Compliance Monitoring and Enforcement Program. This responsibility includes the determination of Alleged Violations and the Enforcement staff’s review and acceptance of Mitigation Plans. Ms. Carney also has the lead role in SERC’s Inherent Risk Assessment processes. Prior to joining SERC, Ms. Carney was the Manager, Regulatory Issues for ElectriCities of North Carolina, Inc., a membership organization including public power communities in North Carolina, South Carolina, and Virginia. Before joining ElectriCities in May 2003, Ms. Carney held various positions in her 16-year career with Progress Energy – Carolinas including power marketer, Manager of Retail Sales, and Major Accounts Manager. Ms. Carney holds a degree in computer engineering from Clemson University

Marie Kozub

Marie joined SERC Reliability Corporation in March 2020 as the Senior Coordinator of Certification and Registration. Marie is responsible for the administration of the SERC functional Entity Registration and Certification processes. Prior to joining SERC, Marie had been a Senior Compliance Analyst with Northeast Power Coordinating Council, Inc. (NPCC) since 2008. There her responsibilities included entity Registration and Certification, CIP Audit Team Lead and auditor, directing the TFE program and training and tracking auditor competency. Previously, Marie had 15 years’ experience as a paralegal including 5 years as a Corporate Officer in the reinsurance industry. Prior work experience also includes seven years in the chemical industry as a Purchasing Manager and responsibilities were expanded to include training, development and implementation of a plant safety program and a team leader for obtaining ISO 2000 certification. Additional audit experience includes conducting managerial audits that encompassed analysis of business processes, operating procedures and corporate culture to identify operating inefficiencies and provide recommendations to improve processes and productivity. Marie has achieved a Bachelor of Science from Montclair State University, Paralegal Certification from Uppsala College and a Master of Business Administration (MBA) from Fairleigh Dickinson University. Marie also maintains a Certified Government Auditing Professional (CGAP) certification .

HOME

Speaker Biographies

Peter Heidrich Peter joined the SERC Reliability Corporation in July 2019 as the Senior Coordinator of Certification and Registration. Peter is responsible for the administration of the SERC Functional Entity Registration and Certification processes, and is also responsible for the implementation and continued maintenance associated with the NERC Glossary of Terms definition of Bulk Electric System (BES) and administration of the Rules of Procedure (ROP) BES Exception Process. Previously Peter was with the Florida Reliability Coordinating Council, Inc. (FRCC) from August, 2008 to June 2019. As the FRCC Director of Reliability Performance & Registration, Peter was responsible for leading the Programs within the FRCC Region to enable the assessment and improvement in reliability performance of the FRCC BES. Responsibilities included Registration and Certification, Events Analysis and Situation Awareness, Reliability Standards Development, and System Operator Training. Within this capacity, Peter was responsible for the administration of the FRCC Functional Entity Registration and Certification processes, and was also responsible for the implementation and continued maintenance associated with the NERC Glossary of Terms definition of BES and administration of the ROP BES Exception Process. Peter served over eight years in the United States Navy in the Nuclear Power Program. Following his military service, he joined DTE Energy (Detroit Edison) in 1992 as a Nuclear Power Plant Operator at the Enrico Fermi II Power Plant (Newport, MI). In 1995, Peter transferred to the System Operations Department where he qualified as a System Operator, and obtained his NERC System Operator Certification. Peter also served in the position of Control Room Supervisor. From 2004 to 2008, Peter served as Manager-Protection Authority with the responsibilities of managing the Hazardous Energy Controls (Red Tag Protection) programs for the corporation. Peter holds a Bachelor of Science Degree in Business Administration, graduating with Honors, from the University of Phoenix. Peter has been a NERC Certified Reliability Coordinator since 2000 Greg Davis As the Regulatory Compliance Manager of Georgia Transmission Corporation (GTC), Greg Davis guides GTC in maintaining compliance with the Electric Reliability Organization Standards. He identifies and evaluates all new or modified reliability standards proposed by NERC and SERC, and assists in the evaluation and understanding of each requirement to ensure compliance readiness. Greg also maintains GTC’s program to monitor processes, procedures, guidelines and documentation to ensure compliance. During his time as a Compliance Manager, Greg has represented GTC in NERC and SERC conferences and has been a member of the SERC Protection and Control Sub Committee along with serving on the SERC Standard drafting team for SERC Standard PRC-006-1 Automatic Underfrequency Load Shedding Requirements. Over Greg’s 20 year career, he has worked in various Electric Utility disciplines from relay maintenance, system protection, bulk planning, and ERO compliance. Greg is known for his ability to work cooperatively, and has the knowledge and experience to be a valuable member of the Registered Entity Forum.

HOME

Speaker Biographies

Joel Rogers

Joel Rogers joined SERC Reliability Corporation as a Compliance Auditor in June 2014. Previously, Mr. Rogers was the Compliance Administrator for Cooperative Energy formerly known as South Mississippi Electric Power Association (SMEPA) in Hattiesburg, MS. In this role, Joel provided counsel to management and directed operations, planning, and critical infrastructure protection staff regarding NERC Reliability Standards compliance. Before taking on the Compliance Administrator role, Joel worked in operations planning for 3 years and Transmission Planning for 1 year. During this time, Joel performed engineering studies, prepared publications, and trained System Operators on peak loading, blackstart restoration, and abnormal transmission system conditions. Joel maintained power system models for both operations and transmission planning and he participated in the development of long-range transmission plans. Joel represented Cooperative Energy on SERC’s Long Term Study Group, Operations Planning Subcommittee, and Near Term Study Group. Prior to joining Cooperative Energy, Mr. Rogers worked for Southern Company Services in Transmission Planning and Mississippi Power Company in Distribution Engineering and Operations. Mr. Rogers graduated from Mississippi State University with a B.S. degree in Electrical Engineering, with an emphasis in power, in December 2005. Joel is a registered Professional Engineer in the state of Mississippi, a NERC Certified System Operator at the Reliability Coordinator level, and a Certified Government Auditing Professional. Mr. Rogers served in the U.S. Navy from 1995 to 2000 as an aviation electrician on the F/A – 18 Hornet.

Marcus Beasley

Marcus is currently an O&P Auditor at SERC performing compliance monitoring functions in accordance with NERC Rules of Procedure. He plays an integral role performing compliance audit of registered entities. He also participates in the assessment of risk to appropriately develop a compliance oversight plan and scope compliance monitoring activities. Before joining SERC, Marcus worked with Tennessee Valley Authority (TVA) as a Transmission Operator (TOP). He was responsible for the operation of a quarter of the TVA electrical grid. Additional responsibilities included writing and issuing switching, navigating complex secondary electrical circuits, responding to system disturbance, and assisting with planned outage logistics. Prior to TVA Transmission Operations, he worked with Hydro Dispatch Control Cell. In this role he managed 29 TVA hydro facilities remoted to System Operations Center. He also worked in real-time with a multi-organizational management team to assure TVA hydro power generation and power systems are operated in a reliable and economic manner. Additional experience includes making economic and operational decisions regarding generation and reactive power generation in coordination with the BA and TOP. As a coordinator, he determined the amount of energy and reactive power needs of a given unit. As a member of the Asset Availability Team, he managed hydro outages and outage requests. He also coordinated load balancing and performed switching at various hydro facilities under the direction of the TOP to safely perform maintenance and other operations.

HOME

Speaker Biographies

Steve Rose

Steve joined the SERC in July 2019. Before joining SERC, Steve worked at City Water Light & Power (CWLP) in Springfield, Illinois, where he spent over 17 year in various roles. He participated in all aspects of O&P and CIP Audits for assessment of Reliability Standards. Steve began his career at CWLP as a Planning Engineer in the CWLP Planning Department. He was responsible for the daily, near term, and long term planning models, MISO Generator Interconnection LGIA, and assessments. Steve also participated in an engineering orientation rotation which included training in each of the following departments in one year increments: Distribution, Substation, and Relay Departments. Later, Steve supervised the CWLP Planning Department. Most recently, Steve was the Superintendent of Compliance where he developed, implemented, and monitored the CWLP Internal Compliance Program. Steve was also the CIP Senior Manager from 2013-2017 and participated in the transition from NERC Cyber Security Standards Version 3 to Version 5. Prior to CWLP, he held the position of General Engineer at the NERC Region Mid America Interconnected Network (MAIN) now Reliability First. For two years Steve was responsible for performing daily ATC, CBM, and TRM studies for the member control areas for real-time situational awareness and ATC. He also served as lead engineer for the MAIN Multi-Regional Modeling Working Group. Prior to beginning his career in the electric industry, Steve was in the United States Marine Corps for five years where he was an I- Level avionics technician on the F/A 18 Hornet. Steve has a B.S. in Electrical Engineering from Southern Illinois University. Steve is a NERC Certified Reliability Coordinator since 2012. Recently he completed the COSO Internal Control Certificate –IIA 2019 and COSO Enterprise Risk Management Certificate –IIA 2020. Steve is also a member of the Institute of Electrical and Electronic Engineers since 1997. Greg Tenley joined SERC in September 2015. Prior to joining SERC Greg worked for PPL Electric Utilities from 2010 until 2015 as a Transmission System Operator. There Greg provided real time monitoring and control decisions and direction for the 24/7 operation of the PPL Electric bulk power system. Also, Greg was responsible for the execution of Emergency Load Control Procedures to maintain system integrity under emergency systems. He executed Permits and Switch Orders in the operation and maintenance of the Bulk Electric System. Greg spent 2 years in the Transmission Control Center Short Term Planning and Outage Coordination office running week ahead load forecast and work planning studies as well as coordinating capital and maintenance projects with Engineers, Project Managers and Contractors. Prior to working for PPL Electric Utilities, Greg worked for First Energy Corporation as a Power System Dispatcher from 2000 until 2010. While there, Greg directed day to day Operation of the Regions Electrical Transmission and Distribution Systems to assure reliable and economic supply of electricity to 1.2 million customers. Greg coordinated and directed activities of personnel in Line, Relay, Test and other departments in the operation, installation and maintenance of electrical facilities and concurrent activities under emergency situations by organizing and directing personnel in five different districts. Greg worked for Nebraska Public Power District as a Regional System Operator from 1995 until 2000. While there, Greg provided for safe, reliable and efficient operation of the regions electrical system to include switching and dispatch functions associated with working clearances, load transfers, system status and operation of power equipment. He was responsible for subtransmission and distribution systems to include substation loading, outage reports, voltage optimization schedules, line patrol reports and environmental reports. Greg supervised the application of the Protective Permit and Tag System to facilities within area of jurisdiction and directed switching and operation of remote control equipment to control substation facilities in the Western Region of NPPD. Greg is also a retired Chief Master Sergeant (E-9) USAF with 28 years of service and completed his career at HQ Air Combat Command, Langley VA as the Commands Chief of Prime Base Engineer Emergency Forces. Greg Tenley

HOME

Speaker Biographies

Mike Kuhl

Mike is Supervisor, Operations and Planning Compliance Audits for SERC Reliability Corporation and reports to the Senior Manager of Compliance Monitoring. Prior to joining SERC in January 2013, Mike worked at the Cincinnati Gas & Electric Company/Cinergy/Duke Energy for nearly 24 years. His responsibilities were primarily in the areas of electric generation and transmission electric system operations. Mike began his career during the construction and start-up phases of W.H. Zimmer Station, a 1,300 MW supercritical unit and the world's first nuclear-to-coal conversion project. Mike transitioned to control area operations in the mid-1990s, subsequently became a NERC-certified transmission system operator, and worked as a Control Area Coordinator. Mike then served as Project Manager of Cinergy's energy markets integration with the Midwest ISO. Several years before reliability standards became mandatory and enforceable, his job focus transitioned to NERC reliability standards compliance where he developed, implemented, and managed Cinergy’s and Duke's initial Reliability Standards Internal Compliance Programs. Mike earned a B.S. in Chemistry from the University of Cincinnati. He is a NERC Certified System Operator at the Reliability Coordinator level, and holds an Internal Auditor Practitioner certification.

Leslie Beam

Leslie is an influential leader with over 20 years of progressive corporate experience, including pivotal roles in business transformations, executive engagements and strategic communications across multiple industries. As a Prosci certified organizational change management professional, she has a passion for connecting the dots between an organization's intentions and results by developing strategies that focus on the human experience. She has created and implemented end-to-end change operation models for large transformational change initiatives (mergers & acquisitions, process standardization, enterprise system implementations, etc.) impacting global Fortune 500 companies such as Duke Energy, Siemens, Dell and Cisco.

HOME

Speaker Biographies

Bill Peterson

Bill Peterson is the Manager Outreach and Training with SERC Reliability Corporation. Bill has contributed over 20 years to the computer security profession with 15 years dedicated to securing the bulk power system. He started working with CIP security in 2007 and has helped numerous organization strengthen their security posture over the years. Previously, Mr. Peterson was the Program Manager, Cyber Security in the Technical Resources department and a Senior CIP Engineer in the Compliance group. Prior to joining SERC, he worked in security roles for Duke Energy and the New York Power Authority. Mr. Peterson has a Master’s in Business Administration with a concentration on Information Technology Management from the State University of New York at Utica/Rome. Mr. Peterson has a Bachelor’s of Science degree with a dual major in Computer Engineering and Electrical Engineering Technology from the State University of New York at Utica/Rome. Bill holds a certification in Certified Information Security Manager (CISM), a Certified Information Systems Security Professional (CISSP), and a Leadership Certificate from Cornell University

Justin Kelly

Justin joined the CIP Compliance audit team at SERC Reliability Corporation in September 2019. Previously, Justin Kelly was an Electrical Engineer with the Federal Energy Regulatory Commission in Washington, DC. He was a sub- team lead for both CIP Version 5 and CIP-014 FERC-led audits. Justin has also been involved in monitoring Standard Drafting Teams, drafting FERC Orders, reviewing CIP related sanctions filed or posted by NERC, and observing regional entity audits. He primarily focused on CIP Reliability Standards during his time at FERC, but also was a technical team lead for Geomagnetic Disturbance and Electromagnetic Pulse research and standards projects. Justin received a Master of Science in Electrical Engineering degree from Virginia Polytechnic and State University in 2009. He is a licensed Professional Engineer (PE) in the state of Maryland and is a Certified Information System Security Professional (CISSP).

HOME

Speaker Biographies

Chris Holmquest

Chris Holmquest joined SERC in July 2019 as a Reliability and Security Advisor. Prior to joining SERC, Chris was with the Florida Reliability Coordinating Council (FRCC) Regional Entity. He joined FRCC RE as a CIP Compliance Auditor in 2013, and was promoted to Manager, Risk Assessment and Mitigation in 2014, as part of the new NERC initiative for Risk-Based Compliance Monitoring and Enforcement. Chris was the FRCC RE representative on the CIP V5 Transition Study, where he worked with the SERC representative and the two SERC utilities selected for the study. Chris has 37 years of electric utility experience, serving over 30 years with a medium-sized electric utility before joining FRCC RE. Chris spent eight years in fossil generation and 23 years at the transmission and generation control center. During his time in the control center. Chris spent several years as an Energy Management Systems (EMS) Engineer and later joined the newly formed NERC Compliance and Training group as a System Operator training engineer. During that time Chris became NERC certified as a Reliability Coordinator (RC) as he built and delivered training programs for operations personnel. Chris was instrumental in starting and building his company’s CIP compliance program and became the manager of CIP Compliance in its new NERC Compliance and Operations Technology group. Chris was also the manager of his company’s NERC Training Department through the PER-005 compliance implementation effort, as well as the manager of both the EMS and Applications teams and the CIP Compliance group. Chris is a Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information System Control (CRISC), and a GIAC Certified Incident Handler (GCIH). Chris is also NERC certified as a Reliability Coordinator.

Erik Johnson

Mr. Johnson currently focuses on Internal and External analytics to drive improved Reliability and reduce Risk. In recent roles he focused on outreach and assistance to the entities. Mr. Johnson comes to ReliabilityFirst with over 20 years of work experience in the Cyber Security field. Prior to ReliabilityFirst, Mr. Johnson was most recently with the Federal Reserve System, where he coordinated cross functional teams in the assessment of Federal Reserve compliance with NIST standards. Mr. Johnson obtained a Bachelors of Science in Business Administration from John Carroll University and a Master’s of Science in Information Security from DePaul University. He holds numerous certifications including his CAP, CISA, CISSP, CRISC and PMP.

HOME

Speaker Biographies

Kenath Carver

Kenath Carver is the Manager of CIP Compliance Monitoring at Texas RE and has been with the company since 2012. He has over 15 years of Information Technology experience and prior to joining Texas RE, Kenath worked as an IT Business Solutions Analyst and Senior IT Security Administrator. Kenath has the following degrees: Associate of Applied Science in Information Technology, Bachelor of Science in Computer Information Systems Software Engineering, and is currently working on a Master of Science in Information Systems. Mr. Carver holds numerous industry-leading certifications, including: CompTIA Network+, Security +, CySA+; GIAC CIP, and ISC 2 SSCP.

Lonnie is a Senior Manager, Cyber and Physical Security Assurance in the NERC Compliance Assurance group. In this position, Lonnie is responsible for providing oversight, guidance, and coordination in managing programs and processes to monitor, review, and evaluate program effectiveness of Electric Reliability Organization (ERO) Enterprise implementation of risk-based compliance monitoring and adherence to the NERC Rules of Procedure, Compliance Monitoring and Enforcement Program, and approved delegation agreements. In July 2017, Lonnie joined NERC’s Grid Assurance group. Prior to joining NERC, Lonnie was the Manager, Entity Assessment and Mitigation (EAM) at SERC Reliability Corporation. Lonnie led a team that was responsible for assessing non-compliance scope and risk posed to the Bulk Power System. In addition, his team was responsible for conducting registered entity Inherent Risk Assessments and ensuring appropriate mitigation activities were applied for each non-compliance Lonnie Ratliff

HOME

Speaker Biographies

Stephen Brown

Stephen joined the CIP Compliance audit team at SERC Reliability Corporation in September 2018. Previously, Stephen joined the NERC ERO at Georgia System Operations (GSOC) in 2006. While at GSOC, he managed and coordinated all Critical Infrastructure Protection (CIP) changes to ensure that stakeholders were aware of the change(s) and risks. He also ensured security controls were identified prior to changes and confirmed all documentation was complete. Stephen has over 15 years of information and operation technology experience with detailed knowledge in asset management, business continuity, disaster recover planning, incident response, policy administration, process improvement, and risk assessment. He has led a security and network operations center and managed multiple security and compliance projects. Stephen is a Certified Information Security Manager (CISM) and has been a Subject Matter Expert on standards CIP-006, CIP-007, and CIP-010 for multiple Critical Infrastructure Protection (CIP) audits. He is a new resident to North Carolina and holds a Masters of Business Administration (MBA) in Information Systems from Argosy University.

HOME

Thank You

ADDITIONAL INFORMATION Questions concerning registration and meeting content - Lynn Black

Follow for updates

Page 1 Page 2 Page 3 Page 4 Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 13 Page 14 Page 15 Page 16 Page 17 Page 18 Page 19 Page 20

www.serc1.org

Made with FlippingBook - Online magazine maker