July 20, 2021
Supply Chain Security Assessment Model Adoption Survey Results Posted
The results of the Industry Organizations Metric Team’s survey to determine adoption of the model, criteria, and questionnaire have been posted to the supply chain industry coordination resources page under the "Resources/Documents" headings.
The posting consists of a spreadsheet containing responses and a PDF containing charts and graphs of the responses. The response was lower than anticipated; however, the respondents provided thoughtful comments that will help guide future activities to help align industry on what information is needed from suppliers to conduct a supply chain risk assessment.
June 09, 2021
NATF Supply Chain Model, Criteria, and Risk Questionnaire Version 2.0 Posted for Industry Use
The “Supply Chain Security Assessment Model,” “NATF Supply Chain Security Criteria,” and “Energy Sector Supply Chain Risk Questionnaire” version 2.0 documents have been posted for industry use on the Supply Chain Cyber Security Industry Coordination page of the NATF public website.
Supported by the Industry Organizations Team, the model and complementary products provide a streamlined, effective, and efficient industry-accepted approach for entities to evaluate supplier supply chain security practices.
The five-step model provides a solid foundation for identifying, assessing, and mitigating supply chain risks; provides for inclusion of suppliers and solution providers depending upon each entity’s needs; and provides for flexibility of each entity’s implementation.
The criteria includes mapping to existing security frameworks and is categorized into two areas: (1) supplier’s organizational information and (2) supplier’s level of adherence to supply chain security practices.A formatted and unformatted version of the questionnaire is provided. The formatted version includes guidance based upon answers to a series of “qualifier” questions that identifies optional questions for utilities to consider in a risk assessment. The unformatted version is text-only for easy incorporation into various toolsets or existing company spreadsheets.
March 05, 2021
NATF Questionnaire and Criteria Revisions Posted for Industry-Wide Comment through April 2
The NATF Questionnaire and Criteria revision team has reviewed suggestions for modifications to the Questionnaire and Criteria, and adopted changes have been posted for industry-wide comments through April 2.
Please review the Questionnaire and Criteria for:
- changes in the Questionnaire (formatted version) and Criteria
- the questions and criteria in general for alignment to the information you collect from suppliers
- the mapping to the security frameworks
Changes are indicated by red text and a summary of changes is available on the “Confidentiality” tab of each document. The redlines for the Questionnaire are provided in the formatted version only. Conforming final changes will be made to the unformatted version.
A webinar will be provided on March 19 from 11:30 am - 12:30 pm eastern. This webinar is open to industry. Register here.
The review team will review comments in April and will provide a summary for their determinations. The final changes will be provided to the NATF board for approval in May, and upon approval the revised Questionnaire and Criteria will be posted.
Main points to note:
- The Questionnaire and Criteria have been reviewed by the E-ISAC and NERC for sufficiency in regards to the Solar Winds hack, and it was determined that no additional changes were needed.
- The Questionnaire and Criteria were both reviewed to determine if they would obtain sufficient information regarding countries of origin.
- In the Questionnaire, mapping was added to the new supplier criteria
- In the Criteria, three questions from the “Organizational Information” section were moved into the “Supplier Criteria” tab
- The changes to the Questionnaire are denoted in the formatted version for comments; final changes will be included in the unformatted after approval.
October 30, 2020
NATF is hosting an Industry Organizations webinar for suppliers!
This webinar will be provided twice, on December 1 and January 12, to help suppliers understand the requests they are receiving from entities and how they can be prepared to provide entities will responses. The webinar will cover the NATF Criteria and Questionnaire, as well as how suppliers can work directly with entities and with solution providers. Just as the IO Team is working to converge industry on what information is necessary to obtain from suppliers, the Team is also working with suppliers so they will have the information you need readily available. The invitation to attend this webinar is provided on the Industry Organizations webpage. Click HERE for the Supplier Communication Webinar Invitation.
Many entities and solution providers involved in the Industry Organizations collaboration effort have agreed to distribute the letter invitation to their suppliers. We are also asking that you, as you are able, distribute the letter invitation to your organization’s suppliers.
You are also welcome to attend these webinars. Registration is required to join this event. If you plan to attend and have not registered, please do so now.
Click HERE to register for the December 1, 2020 webinar
Click HERE to register for the January 12, 2021 webinar
September 23, 2020
NATF Posts Revision Process for Supply Chain Criteria and Questionnaire
The NATF has posted the "Revision Process for the Energy Sector Supply Chain Risk Questionnaire and NATF Cyber Security Criteria for Suppliers" for industry use.
The purpose of this process is to facilitate periodic reviews and modifications of the NATF “Energy Sector Supply Chain Risk Questionnaire” (Questionnaire) and the “NATF Cyber Security Criteria for Suppliers” (Criteria), which were developed for industry-wide use to drive consistency of information obtained from suppliers of bulk power system hardware, software, and services.
Consistent with the NATF’s open, collaborative, and consensus-based approach, modifications via this process will be made with consideration of input from across industry and will include adding, deleting, or modifying individual questions in the Questionnaire or individual criterion in the Criteria as well as adding, deleting, or modifying mappings to security frameworks (e.g., SOC2, ISO27001, etc.).
The process is available on the NATF Supply Chain Cyber Security Industry Coordination page.
May 18, 2020
NATF Posts Energy Sector Supply Chain Risk Questionnaire
The Energy Sector Supply Chain Risk Questionnaire has been completed! We now have a complementary tool for the NATF Criteria to obtain information from suppliers - one that should help drive convergence in the industry regarding the information needed from suppliers.
This new open-source questionnaire to support supply chain cyber security risk assessments, developed by a group of more than 20 U.S. energy companies, is now available for your consideration and potential use. This questionnaire, called the Energy Sector Supply Chain Risk Questionnaire (“ESSCRQ” or “Questionnaire”), was developed to provide utilities with a set of supplier- and equipment-focused questions to obtain better information on a supplier’s security posture. The Questionnaire works in conjunction with the NATF Criteria, and together these complementary tools can help our industry drive convergence on information that is needed from suppliers.
The questions in the ESSCRQ will help you obtain information regarding a supplier’s adherence to the NATF Criteria plus additional valuable information. The ESSCRQ denotes where questions directly align or will provide key supporting information regarding a supplier’s adherence to each of the NATF Criteria, and the information obtained through other questions will provide additional insight. Further, in light of the May 1 Executive Order, both the Questionnaire and the NATF Criteria gather information regarding a supplier’s sourcing, activities and staffing in other countries.
This information will enable you to evaluate a supplier’s cyber security practices and identify potential risks to be mitigated, which will ultimately provide data to consider in your company’s supply chain risk assessments.
Two versions of the Questionnaire are available on the Supply Chain Cyber Security Industry Coordination page of the NATF public website. The first includes a series of macros to provide a self-contained tool that can be used by utilities and suppliers. The second version provides a text-only version for easy incorporation into various toolsets or existing company spreadsheets.
February 03, 2020
NATF Launches Industry Coordination Webpage
Today, the NATF launched the “Supply Chain Cyber Security Industry Coordination” web page under a new “Industry Initiatives” section of the site. The supply chain cyber security industry coordination page provides information on the collaborative work conducted by NATF subject-matter experts, industry organizations (including trade and forums), key suppliers, and third-party assessors on this important topic.