I wonder what scale of disaster will have to occur before information security is placed under the same legal and regulatory scrutiny as physical security?
"In 2007, FERC designated NERC the ERO in accordance with Section 215 of the Federal Power Act, enacted by the Energy Policy Act of 2005. Upon FERC’s approval, NERC’s Reliability Standards became mandatory within the United States. These mandatory Reliability Standards include CIP standards 001 through 009, which address the security of cyber assets essential to the reliable operation of the electric grid."
Source: http://www.nerc.com/pa/CI/Comp/Pages/default.aspx
(Edit: clarification)