Alberta law takes effect on May 31st, 2025
In 2024, Alberta introduced a new regulation, Regulation 84/2024, titled “Security Management for Critical Infrastructure Regulation.” This regulation is part of the Responsible Energy Development Act and is aimed at creating comprehensive security management protocols for critical infrastructure in Alberta’s energy sector. The regulation will come into effect on May 31, 2025, making it vital for facilities in this sector to start preparing now.
The regulation defines critical facilities in Alberta’s energy sector as:
It also mandates a framework for identifying and managing security risks to these vital facilities. This includes protection against threats such as terrorist activities. The Alberta Energy Regulator (AER) plays a key role by maintaining a list of critical infrastructure and ensuring that security protocols are implemented where necessary.
If the AER designates a facility as critical, the licensee or approval holder must be notified and is then required to establish and implement a security management program in line with the CSA Z246.1 standard—“Security Management for Petroleum and Natural Gas Industry Systems,” published by the Canadian Standards Association (CSA).
The consequences of non-compliance are severe: failure to implement CSA Z246.1 could result in a complete shutdown of the facility.
Implementing CSA Z246.1 is a vital but straightforward process involving several key steps:
While CSA Z246.1 does not dictate specific cybersecurity controls, it references several frameworks that can be leveraged to maintain a comprehensive cybersecurity strategy, ensuring your critical infrastructure is resilient against a broad range of threats. These include:
Preparing for a CSA Z246.1 audit can be a complex process, but working with security management consultants can make the journey easier. Consultants with experience in this space can help by:
The complexities of regulatory compliance and risk management have evolved, thanks to the advancement of modern tools and methodologies. Today, compliance and risk assessments do not need to be as cumbersome as they once were, with traditional approaches requiring lengthy consultations and delivery timelines.
Many consulting organizations, such as iON, have adopted efficient and automated tools to simplify the process. With defined deliverables and a focus on reducing business risk, it is easier than ever to enhance your security posture and meet regulatory compliance.
With Alberta’s new regulation taking effect this spring, proactive planning is essential for energy sector operators. If your company needs help implementing or assessing compliance with CSA Z246.1, iON is here to support you. Reach out today to learn how our streamlined, tech-enabled services can assist you in preparing for the upcoming changes, helping to reduce your security risks and making your security management easier to manage.