Central Electricity Authority Notifies Cybersecurity Regulations for Power Sector

|

Central Electricity Authority Notifies Cybersecurity Regulations for Power Sector

Science & Technology
Central Electricity Authority Notifies Cybersecurity Regulations for Power Sector

The Central Electricity Authority (CEA) notifies new cybersecurity regulations to protect the power sector from cyber-attacks, and they become effective from April 1, 2027. The regulations prescribe coverage, reporting timelines, IT-OT security requirements, audits, and institutional measures for entities linked to the interconnected power system.

CEA Cybersecurity Regulations:

Dimension Key Details
Coverage The regulations apply to entities owning, operating, or managing Operational Technology (OT) infrastructure linked to the interconnected power system, and to IT infrastructure physically or logically connected to OT systems.
Coverage threshold For generating companies, captive plants, and energy storage systems, the regulations apply to 50 MW and above.
Key data security measures Sensitive data, including cloud-hosted and historical data, must be encrypted, securely stored, and protected from unauthorised access.
Applicability to service providers The requirements apply to vendors and cloud service providers.
Cyber incident reporting timeline Cybersecurity incidents must be reported to CSIRT-Power and CERT-In within 6 hours.
Cyber sabotage reporting timeline Cyber sabotage involving critical systems must be reported within 24 hours.
IT–OT security Mandatory segregation of IT and OT systems is mandated.
OT procurement OT equipment and services must be procured from trusted sources.
Remote OT operations conditions Remote OT operations, where required, must be conducted within India and use a dedicated communication channel isolated from the internet.
Cybersecurity audits for new critical systems New critical systems must undergo cybersecurity audits, vulnerability assessment, and penetration testing (VAPT) before commissioning.
Vulnerability remediation timeline Critical and High vulnerabilities must be remediated within 1 month, and Medium and Low vulnerabilities must be remediated within 3 months.
Institutional requirements Appointment of a Chief Information Security Officer (CISO) and an Alternate CISO is mandated, along with a 24×7 information security function.
Annual self-audits and documentation Annual self-audits and maintenance of cyber-risk assessments, asset registers, and incident-response plans are mandated.
Capacity building and monitoring Mandatory cybersecurity training for personnel handling critical systems, continuous monitoring of IT and OT systems, and periodic cybersecurity exercises are mandated.
CSIRT-Power status and role CSIRT-Power has been established at CEA in April 2023 as an extended arm of CERT-In, and it helps power utilities detect, respond to, and manage cyber incidents.
Cyberattack reference The power sector faces nearly 2 lakh cyberattacks during Operation Sindoor, and all of these are discontented.
Did you find this informative?

Attempt Possible Qs

Q 1 / 3

With reference to the CEA cybersecurity regulations, consider the following statements:

1. The regulations apply to IT infrastructure that is physically or logically connected to OT systems.
2. The regulations apply only to OT infrastructure and exclude IT infrastructure in all cases.
3. The regulations apply to entities linked to the interconnected power system.

Which of the statements given above are correct?