The Regulation requires the Regulator to keep a confidential critical infrastructure list and requires licensees or approval holders of listed critical facilities to establish and implement a security management program.
(no amdt) Alberta Regulation 84/2024 Responsible Energy Development Act SECURITY MANAGEMENT FOR CRITICAL INFRASTRUCTURE REGULATION Table of Contents 1 Definitions 2 Critical infrastructure list 3 Security management program 4 Repeal 5 Expiry 6 Coming into force Definitions 1 In this Regulation, (a) “approval holder” means an approval holder under an energy resource enactment; (b) “coal processing plant” means a coal processing plant as defined in the Coal Conservation Act ; (c) “critical facility” means any of the following that is named in the critical infrastructure list as a critical facility, and includes any related facility of a critical facility: (i) a coal processing plant; (ii) an in situ operation; (iii) a mine; (iv) a mining operation; (v) a pipeline; (vi) a processing plant; (vii) a well; (d) “critical infrastructure list” means the critical infrastructure list established under section 2; (e) “CSA Z246.1” means CSA Z246.1: Security Management for Petroleum and Natural Gas Industry Systems published by the Canadian Standards Association, as amended or replaced from time to time; (f) “in situ operation” means (i) an in situ operation as defined in the Oil Sands Conservation Act , or (ii) an in situ coal scheme as defined in the Coal Conservation Act ; (g) “licensee” means a licensee under an energy resource enactment; (h) “mine” means a mine as defined in the Coal Conservation Act or the Mineral Resource Development Act ; (i) “mining operation” means a mining operation as defined in the Oil Sands Conservation Act ; (j) “pipeline” means a pipeline as defined in the Pipeline Act ; (k) “processing plant” means a processing plant as defined in the Mineral Resource Development Act , the Oil and Gas Conservation Act or the Oil Sands Conservation Act ; (l) “Regulator” means the Alberta Energy Regulator; (m) “security management” means a process that addresses security in respect of terrorist activity or the threat of terrorist activity against a critical facility for the purposes of section 80 of the Act; (n) “well” means a well as defined in the Geothermal Resource Development Act , the Mineral Resource Development Act or the Oil and Gas Conservation Act . Critical infrastructure list 2 (1) For the purposes of security management, the Regulator must establish and maintain a critical infrastructure list of critical facilities as identified in accordance with subsection (2). (2) In identifying critical facilities, the Regulator may consider the following: (a) the size and type of the facility; (b) the proximity of the facility to people, property and environmental factors; (c) facility throughput; (d) the interdependency of the facility with other infrastructure; (e) any other relevant factors. (3) The Regulator must notify the licensee or approval holder of a critical facility that the critical facility is on the critical infrastructure list. (4) Subject to subsection (3), the critical infrastructure list is confidential and may not be accessed except as permitted by the Regulator. (5) The Regulator may update the critical infrastructure list from time to time. Security management program 3 (1) A licensee or approval holder of a critical facility must establish and implement a security management program for the critical facility in accordance with CSA Z246.1. (2) If the Regulator is of the opinion that the licensee or approval holder of a critical facility has failed to establish and implement a security management program under subsection (1), the Regulator may (a) order the licensee or approval holder of the critical facility to establish and implement a security management program under subsection (1), or (b) order the licensee or approval holder of the critical facility to shut down or shut in the critical facility, and the Regulator may set out the terms under which the order may cease to have effect. (3) The Regulator may require a licensee or approval holder of a critical facility to file with the Regulator all information or any specified information in relation to the security management of the critical facility. (4) Any information filed under subsection (3) is confidential and may not be accessed except as permitted by the Regulator. (5) The Regulator may audit the security management program of a licensee or approval holder of a critical facility to ensure that (a) the security management program is in compliance with the applicable provisions in CSA Z246.1, and (b) the licensee or approval holder of the critical facility has capacity to implement the security management program. Repeal 4 The Security Management for Critical Upstream Petroleum and Coal Infrastructure Regulation (AR 91/2013) is repealed. Expiry 5 For the purpose of ensuring that this Regulation is reviewed for ongoing relevancy and necessity, with the option that it may be repassed in its present form following a review, this Regulation expires on May 31, 2030. Coming into force 6 This Regulation comes into force on May 31, 2025.