The operative NEPRA obligations run from Regulation 4 to Regulation 11: security policy and governance, security controls implementation, risk and vulnerability assessment, data integrity and confidentiality, authority-mandated audit support, monitoring and incident response, awareness and training, and regulatory reporting. Regulations 1 to 3 cover title, commencement and definitions.
Regulation 4
Security policy & governance
Policies, SOPs, cyber organisation, CISO/lead appointment, asset inventory and classification, change and patch procedures, BCP, NEPRA/PowerCERT channel
Regulation 5
Security controls implementation
IAM and least privilege, MFA, IT-OT segregation, firewalls and allow-listing, secure vendor VPN, endpoint and removable-media control, IDS/IPS at OT boundaries, log retention, control-room access, GPS time sync
Regulation 6
Security risk & vulnerability assessment
Annual IT and OT risk assessment, vulnerability assessment across SCADA and IT, critical-system identification, remediation programme, reassessment after incidents or major change
Regulation 7
Data integrity & confidentiality
Controls over IT/OT data authenticity, secure exchange with grid operators and ISMO, restricted access to critical telemetry
Regulation 8
Authority-mandated audit support
Readiness for a NEPRA-directed technical audit, and an evidence pack organised for submission
Regulation 9
Monitoring & incident response
Control monitoring across IT and OT, incident response plan for plant and SCADA, response-team procedures, recovery and restoration, reporting to National CERT and PowerCERT
Regulation 10
Awareness & training
Awareness programmes for IT and OT personnel, SCADA operator and engineer training, roles and reporting lines
Regulation 11
Regulatory reporting
Quarterly incident reporting to NEPRA, 72-hour reporting of significant incidents, documentation and correspondence with the Authority