Definitions and Interpretation
In this regulation:
Act means the Energy Resource Activities Act;
contact information means
a telephone number at which a person can be contacted, and
an email address, if any, at which a person can be contacted;
CSA Z246.1 means the standard published by the Canadian Standards Association as CSA Z7246.1, Security management for petroleum and natural gas industry systems, as amended from time to time;
cybersecurity has the same meaning as in CSA Z246.1;
program means a security management program within the meaning of section 3.
This regulation does not apply in relation to the following:
a Class 1 hydrogen facility as defined in section 1 (1) of the Hydrogen Facility Regulation;
a Class 2 hydrogen facility as defined in section 1 (1) of the Hydrogen Facility Regulation.
For the purposes of this regulation, a permit holder must comply with CSA Z246.1.
A reference in a clause of CSA Z246.1 to "operator" or to "owner" is to be read as a reference to "permit holder" as defined in the Act.
A reference to "should" in a clause of CSA Z246.1 is to be read as a reference to "must".
Programs, Procedures and Plans
A permit holder must prepare and maintain a program in accordance with CSA Z246.1.
A permit holder must review, and, if necessary, update the program
at least once every 3 years,
after a significant change occurs in the types of threats, risks and vulnerabilities associated with the permit holder's energy resource activity that is the subject of the program, and
at any time the permit holder becomes aware of a deficiency in the program that risks
the safety of the permit holder's employees or of the public, or
the safe carrying out of the permit holder's energy resource activity.
A permit holder must, on request by the regulator, do both of the following:
have the program reviewed by a third party acceptable to the regulator to verify that the program meets the objectives of CSA Z246.1;
submit to the regulator the results of the review referred to in paragraph (a).
A plan, record or document prepared and maintained for the purposes of a program is prescribed for the purposes of section 38 (1) (a) of the Act.
A program must include an information security management procedure prepared and maintained in accordance with CSA Z246.1.
A program must include cybersecurity measures prepared and maintained in accordance with CSA Z246.1.
A permit holder must implement the cybersecurity measures in accordance with clause 7 of CSA Z246.1.
The cybersecurity measures implemented under subsection (1) must meet the objectives of either of the following:
the Framework for Improving Critical Infrastructure Cybersecurity, as published by the National Institute of Standards and Technology and as amended from time to time;
a national or international standard comparable to the framework referred to in paragraph (a), if approved by the regulator.
A record or document required to be maintained under clause 7 of CSA Z246.1 is prescribed for the purposes of section 38 (1) (a) of the Act.
A program must include a training plan prepared and maintained in accordance with clause 8.3 of CSA Z246.1.
General
Within 14 days after preparing a program under section 3, a permit holder must submit to the regulator the name and contact information of the person responsible for the implementation of the program.
Within 7 days of a change to the name or contact information submitted under subsection (1), a permit holder must submit updated information.
A permit holder must prepare and maintain a written record of participants in training described in section 6.
On completing the provision of training described in section 6, a permit holder must prepare a report that
states whether the objectives of the training were met,
makes recommendations for improvement, including improvement to the training plan, and
includes a strategy to implement the recommendations for improvement referred to in paragraph (b).
A permit holder must prepare a report of the results of an evaluation of a response to a security incident and maintain the report until the permit for the energy resource activity that is the subject of the program is cancelled by the regulator or declared by the regulator to be spent.
A report under subsection (3) must include
a description of the security incident, including the cause or suspected cause,
a description of the permit holder's response to the incident, including measures taken to reduce the risk of similar incidents occurring, and
an assessment of the permit holder's response.
A report or record required under this regulation or CSA Z246.1 is prescribed for the purposes of section 38 (1) (a) of the Act.
Information required under this regulation must be kept in writing and may be submitted to the regulator in electronic or paper form.
A permit holder must make the reports and records prepared and maintained under this regulation available to the regulator at the permit holder's principal place of business in British Columbia.
An official may exempt a permit holder from complying with one or more provisions of this regulation or with one or more requirements of CSA Z246.1 if the official is satisfied that, in the circumstances,
compliance with the provision or requirement is not reasonably practicable, or
the exemption is in the public interest.
In granting an exemption under subsection (1), an official may impose any conditions on the exemption the official considers necessary.