What is NERC CIP v5?

On November 22, 2013, FERC approved Version 5 of the critical infrastructure protection cybersecurity standards (CIP Version 5), which represent significant progress in mitigating cyber risks to the bulk power system.

What are NERC CIP requirements?

The NERC CIP standards require utility companies in North America to establish and adhere to a baseline set of cybersecurity measures. The goal is to ensure that appropriate security controls are in place to protect BES and its users and customers from all threats that may affect its timely and effective functioning.

How many NERC CIP requirements are there?

The NERC CIP consists of 11 standards that are for protection against cybersecurity attacks.

How often does the identification of BES cyber assets need to be reviewed?

The standard indicates that a discrete list of low impact BES Cyber Systems is not required. Under this standard, the Responsible Entity must review the identifications made under this standard and have its CIP Senior Manager (or delegate) approve those identifications at least once every 15 calendar months.

What CIP 004?

Purpose: Standard CIP-004-4 requires that personnel having authorized cyber or. authorized unescorted physical access to Critical Cyber Assets, including contractors and service vendors, have an appropriate level of personnel risk assessment, training, and security awareness.

What is CIP compliance?

In 2008, (CIP) Critical Infrastructure Protection standards compliance framework was developed to mitigate cybersecurity attacks on the Bulk Electric System. While initially, these standards were not required, they were used to mitigate risk, later becoming an industry norm.

What is a CIP exceptional circumstance?

A CIP Exceptional Circumstance (CEC) is defined in the NERC Glossary of Terms Used in Reliability Standards as: A situation that involves or threatens to involve one or more of the following, or similar, conditions that impact safety or BES reliability: a risk of injury or death; a natural disaster; civil.

What is CIP in cyber security?

What CIP 13?

The CIP-013-1 is an update to the Critical Infrastructure Protection (CIP) standard, which includes a set of regulatory requirements “to mitigate cyber security risks to the reliable operation of the Bulk Electric System (BES)”.

Categories: Blog