Item 1C. Cybersecurity
9K characters. Original on sec.gov · Markdown
Item 1C. Cybersecurity
Risk Management and Strategy
Entergy and the Registrant Subsidiaries maintain a security-risk-management system with defined roles, duties, governance, and accountability. Under this physical- and cyber-risk model, Entergy and the Registrant Subsidiaries streamline security into a centralized program. The Chief Security Officer (CSO) is responsible for establishing the security and reliability risk strategy, setting policies, monitoring controls and compliance, providing support activities, and reporting on the security program. The Chief Information Security Officer (CISO) is responsible for establishing the cybersecurity strategy and implementing physical and cyber security systems for the security program. The Chief Information Officer (CIO) is responsible for ensuring that Entergy’s information technology infrastructure is secure and reliable. The Chief Ethics & Compliance Officer works with the CSO to address requirements of external security-related regulations, and where applicable, incorporate them into business policies. Management is responsible for identifying and managing risk directly through execution of the security program and compliance with security policies. Entergy and the Registrant Subsidiaries’ risk management model addresses compliance with certain regulatory constructs, such as the NERC Reliability Standards, the NRC Code of Federal Regulations, the Payment Card Industry Data Security Standard, and the Health Insurance Portability and Accountability Act, among other regulations. Entergy and the Registrant Subsidiaries’ risk management model continuously evolves to improve and implement protections, controls, and monitoring to mitigate risks to their part of North America’s electric grid, to protect sensitive information, and to maintain secure business operations. Entergy and the Registrant Subsidiaries manage cybersecurity threats as an enterprise risk with close coordination and information sharing with its federal, state, and local partners. Entergy and the Registrant Subsidiaries also engage with local, state, and federal law enforcement agencies on initiatives to share threat information and participate in a wide range of industry collaborations and classified briefings on cybersecurity developments and evolving risks.
Entergy and the Registrant Subsidiaries maintain access-management controls, including a layered multi-factor authentication process for network and system access, and a defense-in-depth security ecosystem that includes advanced threat detection from independent third parties and federal agencies, security logging and monitoring, and independent third-party penetration and vulnerability assessments. Relevant employees and contractors must complete cybersecurity trainings periodically to heighten security and threat awareness, promote best practices, and meet regulatory requirements. Additional multi-layered prevention and detection processes and technologies to mitigate and minimize the effects of cybersecurity risks include email security, continuous monitoring, vulnerability scanning, anti-virus and anti-malware software, backups and recovery strategy, network segregation, third-party security, and information protection.
Entergy and the Registrant Subsidiaries have incorporated certain cyber-specific response protocols and procedures into their Entergy Incident Management System framework for responding to emergency incidents. This includes the Entergy Incident Response Team Plan, which outlines Entergy’s procedures, steps, and responsibilities for preparing for, detecting, containing, and recovering from an incident. The plan details the roles and responsibilities of Entergy’s officers who would be engaged in such a response to an emergency incident,
Part I Item 1A, 1B, and 1C
Entergy Corporation, Utility operating companies, and System Energy
including key questions to be addressed, critical decision points, and sources of key information to support decision-making. Senior management and the Emergency Incident Response Team periodically review and drill on the plan.
As cybersecurity risks continue to evolve with multiple threat vectors, Entergy and the Registrant Subsidiaries maintain a comprehensive security strategy to keep current with the changing threats. To inform this effort, Entergy and the Registrant Subsidiaries utilize the National Institute of Standards and Technology Cybersecurity Framework, which consists of standards, guidelines, and best practices to manage cybersecurity risk across the enterprise. A risk-based approach is used to direct security initiatives to the most significant risks and provide the most value in terms of risk reduction and protection. Entergy and the Registrant Subsidiaries use a vendor risk management program to assess and monitor security risks that arise from certain third-party vendors. In addition, Entergy and the Registrant Subsidiaries utilize technology and threat-intelligence services to assess and continuously monitor the cybersecurity risk of key vendors, as identified through the vendor risk management program.
While Entergy and the Registrant Subsidiaries have experienced cybersecurity incidents, except as otherwise summarized above or discussed elsewhere in this report, the risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected them including their business strategy, results of operations, or financial condition. See “Item 1A. Risk Factors” in Part I, Item 1A for a detailed description of the risks related to cybersecurity.
Corporate Governance
The Board of Directors is responsible for oversight of the identification, management, and mitigation of enterprise-wide risk, including cybersecurity risk. The Audit Committee has the primary responsibility for overseeing risk management, including oversight of cybersecurity risk management practices and performance. The Audit Committee generally receives reports at each regular quarterly meeting provided by the CSO, the CISO, the CIO, and the General Auditor on the cybersecurity management program. The reports focus on the programs and protocols in place to mitigate cybersecurity risks, led by the CSO. Among other things, the reports may include: recent cyber risk and cybersecurity developments; industry engagement activities; legislative and regulatory developments; cyber-risk governance and oversight; selected cyber risk metrics and activities; cyber risk incident response plans and strategies; cybersecurity drills and exercises; assessments by third party experts and Internal Audit; and major projects and initiatives.
While the Board of Directors and Audit Committee oversee cybersecurity risk management, Entergy’s management is responsible for managing cybersecurity risk. Entergy and the Registrant Subsidiaries’ security-risk-management system, as discussed above, is comprised of a three lines of defense model to enhance risk management efforts and define roles in the security program. The first line of defense, comprised of business units performing operational functions, including the CISO and CIO, is responsible for identification and management of security and reliability risks directly through design, implementation, and execution of control activities. The second line of defense, comprised of the CSO and Chief Security Office, performs and supports security and reliability risk management and governs and oversees the execution of security and reliability controls by the first line of defense. Ownership of specific security operations may migrate from a business unit in the first line of defense to the second line of defense, as determined to be appropriate by the Chief Security Office. The third line of defense, which includes Internal Audit, independent third parties, and certain regulatory constructs, such as the NERC Reliability Standards and the NRC Cyber Rule, provides assurance of selective actions taken by the first and second lines of defense to senior management and the Board of Directors.
Entergy’s CSO is responsible for overseeing physical, cyber, and reliability risk, including governance, compliance, and threat intelligence. The CSO’s background includes serving as the Global Lead Business Information Security Officer for a multinational pharmaceutical and biotechnology company, Vice President of Cybersecurity Solutions for an international consulting firm, and an operations manager for a multinational technology company. The CSO is also a former intelligence officer in the U.S. Marine Corps, with experience in
Previous: Item 1B. Unresolved Staff Comments · Next: Item 1A. , 1B, and 1C