Cybersecurity became part of NERC's reliability mandate because the grid changed. Operations that used to be analog and isolated are now digital and networked. The reliability problem became inseparable from the cybersecurity problem, and the standards followed. CIP isn't an add-on to reliability. It's reliability in the operational technology layer. Cybersecurity compliance doesn't make you cybersecure. NERC has said this explicitly. Don't confuse the audit checkbox with the actual mission. CIP-002 is the gate. Everything else in CIP runs through it. Get classification wrong and the entire program is built on wrong scope. High, Medium, and Low Impact aren't degrees of importance. They are different control architectures with different audit postures. The standards establish the floor. The threat environment is above the floor. Programs built only to the floor operate below the threat baseline. Personnel and access are where most CIP risk lives. Most cyber incidents on the BES start with credentials, not exploits. Detection, response, and recovery aren't post-incident considerations. They're pre-incident obligations.
Contents
- Foreword
- Why Cybersecurity Became a Reliability Imperative
- Statutory Authority and the Evolution of NERC CIP Standards
- Scope and Applicability of the CIP Framework
- Critical Cyber Assets and Impact Categorization
- Security Management Controls and Governance
- Personnel Risk and Access Considerations
- System Security and Technical Protection Concepts
- Monitoring, Detection, Response, and Recovery Concepts
- CIP Compliance Monitoring and Enforcement
- Common Misunderstandings About CIP
- Getting Oriented Within the CIP Framework
- Executive and Engineering Takeaways
- Glossary
- Introduction
- About the Author
- About Energy Compliance, Inc.
Read offline
The complete reference is on this page. The PDF is for circulation inside your organization.
Download the PDFForeword
Foreword
This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.
I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.
The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.
That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.
These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.
These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.
Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.
If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?
Rob Smith, Founder, Energy Compliance, Inc.
EC-WP-200 NERC CIP 101
Chapter 1
Why Cybersecurity Became a Reliability Imperative
This chapter explains why Cybersecurity became a formal and mandatory element of Bulk Electric System (BES) reliability. It covers the historical, operational and regulatory context that led to the development of Critical Infrastructure Protection (CIP) regulations and standards and why Cybersecurity was treated as a reliability issue as opposed to an IT issue.
The Digital Transformation of the Electric Grid The electric power industry has undergone a fundamental change over the last few decades due to the implementation of digital relays, digital communications systems and automation technology. Many of the circuit breaking, protection, monitoring and metering functions originally carried out with electromechanical relays and switchboard and panel components are now being performed with programmable logic circuits, Supervisory Control and Data Acquisition Systems (SCADA) and networked control centers.
The transformation that is underway is providing real-time situational awareness, faster response to events, and greater reliability and efficiency in the operation of the grid. At the same time, it has brought new risks to the grid that are not analogous to those experienced with older technologies. Digital systems bring new vectors of exposure to the risk of failure or cyber attack that did not exist with analog systems.
When combined with the increasing interconnection and dependency of operational technology on cyber assets, reliability engineering considerations naturally transitioned to include cybersecurity as a fundamental one rather than treating it as a technical discipline separate from the others.
Early Cyber Risks and Operational Awareness Early on in the process of Grid digitalization, the focus was often on the operational functionality of the systems involved and security was not at the forefront. Control systems were not implemented with security as a priority; high availability, performance and automation were the main drivers, with focus on authentication, access control and network segregation being neglected. In particular, systems were often implemented with few precautions, assuming that their physical location and the general lack of digital connectivity would suffice to mitigate any possible cyber risks.
All these assumptions, over time, turned out not to be valid. The spread of networks, remote access and the inclusion of the system in the enterprise infrastructure has largely increased the surface exposed to attack. This, together with the growth of system complexity, makes the possibility of unforeseen effects due to failures or attacks difficult to assess.
Our understanding of the operational consequences of cyber risk has developed over time, drawing on lessons learned in the IT industry and from wider developments in information security.
Cybersecurity as a Reliability Concern Cybersecurity in the electric sector is differentiated by its direct and material relationship to reliability outcomes. In other words, a cybersecurity incident could potentially impact the operation of the grid and the delivery of reliable energy. A cyber incident impacting control systems could potentially blind, disrupt communication, or otherwise interfere with protection and control functions, and potentially lead to loss of load, damage to equipment, or cascading failures.
Reliability considers potential cybersecurity risks to data confidentiality and business operations to be relatively low. What is more important to reliability is ensuring that critical systems for planning and real time operation are available and can operate correctly.
These critical systems must be differentiated from other, less sensitive computing systems for which general-purpose information security controls are adequate. This is what differentiates NERC CIP standards from the typical information security regulations and standards used to govern other systems. The differentiator is focus on a function of a system that is critical to reliable operation of the power grid rather than the security of individual data elements such as enterprise applications or commercial data systems.
Historical Events and Policy Drivers The determination of Cybersecurity as a reliability issue was the result of a convergence of events in the industry and the National Electric Reliability Committee’s (NERC) broader national security concerns. Many of the well-publicized cybersecurity breaches in the energy sector have been made in control systems, which are generally considered to be relatively error-free and should not be susceptible to breaches.
While the nature and impact of each incident varied, they generally reinforced the principle that cyber can affect the physical and so potentially the delivery of critical infrastructure and services. This was largely a reflection of the increased interdependencies between the various infrastructure sectors and the potential for significant impacts from single or cascading incidents.
As the threat to personal and critical infrastructure computing systems increased, policymakers and business leaders shifted the focus to thinking of cybersecurity as infrastructure protection versus just an IT risk.
Integration of Cybersecurity into the Reliability Framework Reliability oversight began to develop under federal statute as a regulatory mechanism, and with time, the concept of “cybersecurity” was woven into the fabric of reliability oversight rather than treated as a separate discipline in its own right. This makes sense, given that the cyber risks of concern to the grid are also related to reliability – that is, they are intended to prevent problems or mitigate their impact on such matters as plan and system operation, protection relays, and standards.
Cybersecurity standards for Critical Infrastructure Protection (CIP) were developed to provide regulatory requirements that clearly communicate the level of cybersecurity expected for cyber systems that support the reliability of the bulk electric system. These standards focus on the threat to the reliability of the bulk power system from unauthorized access, system disruption, and loss of critical reliability-related systems and functions.
Critical infrastructure focus on reliability-relevant cyber assets The Electricity Subnetwork Reliability Regulation Guideline was developed with a primary focus on reliability-relevant cyber assets rather than all information systems within an electricity subnetwork.
Distinguishing Operational Technology from Information Technology One of the foundations of CIP standards is the understanding of operational technology and information technology. Operational technology typically refers to equipment or software used for monitoring or controlling the physical aspects of the grid during power system operation. Information technology generally refers to applications or systems used for commercial and enterprise activities, such as accounting and human resources or marketing and websites.
The following domains may share some commonalities in terms of infrastructure or interfaces but have distinct reliability implications: While CIP standards focus on cyber assets whose compromise could affect the reliability of the BES, their identification and mitigation may be different for each domain.
Understanding the relationship between these terms is critical to appreciating why the scope of CIP standards has evolved over time to its current form.
Reliability Oversight and Cybersecurity Establishing Cyber Reliability Required Development of New Reliability Oversight Methods and Technical Tools The implementation of cybersecurity within existing reliability frameworks required expansion and application of established reliability oversight methods and technologies into a new technical domain including defining critical cyber assets, criteria for determining applicability based on functional significance, and alignment to reliability risk considerations.
The resulting Cybersecurity Reliability Framework focuses on consistency, accountability, and system wide risk reduction through the treatment of cybersecurity as just another aspect of reliability management, rather than as a regulatory compliance exercise.
Executive and Governance Perspective The executive had faced a number of traditional challenges in the operations of their business, but the advent of Cybersecurity as a reliability issue has introduced a whole new level of governance. Today, the management of cyber risk has drawn the executive right into the heart of reliability, regulation and corporate accountability.
Many decisions made in the System Architecture Domain, Access Control Domain, Vendor Domain, and Organization Domain can impact the level of cybersecurity risk that impacts system reliability. It is important to understand the relationship between reliability and cybersecurity in order to enable good governance and risk management.
This factor resulted from the growing reliance on digital technologies in the BES, which introduced a new set of cybersecurity-related risks. Thus, the FERC mandated inclusion of cybersecurity as a formal factor in considerations of grid reliability. The agency found that cyberattacks could impact the reliability of the BES by increasing the likelihood of power outages and reducing the reliability of power system automation and control functions.
This section on Risk and Vulnerability Management sets the stage for the discussion of the statutory basis, components, and extent of the NERC (North American Electric Reliability Corporation) CIP standards that are covered in great detail in the following chapter.
FROM THE FIELD
Cybersecurity became part of NERC's reliability mandate because the grid changed, not because cybersecurity changed. The standards followed the operational reality.
Once operations went digital and networked, the cyber attack surface became a reliability attack surface. The standards recognize that. Programs that don't operate as if it's true keep finding out the hard way.
CIP isn't an add-on to reliability. It's reliability in the operational technology layer. Treat it any other way and the program will be misframed.
Chapter 2
Statutory Authority and the Evolution of NERC CIP Standards
This chapter provides background information regarding the federal statute that mandated the development and enforcement of the NERC Critical Infrastructure Protection (CIP) Standards. It traces the history of the development of the CIP Standards in the context of the reliability regulatory framework and describes how cybersecurity was mandated as a regulatory topic under Federal power grid reliability regulations.
Federal Authority Over Reliability and Cybersecurity NERC’s Critical Infrastructure Protection standards are mandated in Section 215 of the Federal Power Act. While Section 215 does not specifically address cybersecurity, it provides the basis for establishing Reliability Standards that are necessary for maintaining reliability of the Bulk Power System.
It’s been long established that digital control systems are part of the operating systems for a wide range of applications including power grid systems, water treatment facilities, etc. As such cybersecurity has been recognized as a reliability risk. Since standards dealing with the operation of the systems are also dealt with under reliability authority – especially as it pertains to statutory authority – standards related to cyber attacks against the operational systems of facilities and processes should fall under reliability authority.
This action effectively enshrined cybersecurity in the statutory requirements for reliability standards, no longer making it an optional or secondary consideration.
Early Reliability Standards and Cyber Considerations In the early years of the energy market reform and mandatory reliability obligations, industry standards predominantly focused on physical risks associated with conventional network planning and operational issues. At that stage, regulation of cyber related aspects was generally restricted to only a few paragraphs of relatively minor consequence, broadly reflecting at that time, the limited extent of ICT within the energy network, and the relative infancy of the organised recognition of threats from the cyber domain.
Historically the reliability discussion concerning early computerized systems began to acknowledge the growing reliance on computer-based systems, but lacked a framework for identification, classification
and reliability assessment of cyber assets which are essential for the reliable operation of a system. There has not been consistent practice for computer security among utility operating companies and other organizations, and which has not really been a recognizable problem in most areas of the world.
The observations uncovered the necessity of addressing this issue in a more structured manner by integrating cybersecurity at the system level into the reliability framework.
Development of the CIP Standards The development of the Critical Infrastructure Protection standards marked a significant expansion of the reliability framework into the cyber domain. The new standards address a broad range of potential cyber-related risks to assets, including but not limited to, unauthorized access, system compromise, and loss of control.
New CIP standards established processes for identifying, classifying and securing vulnerable cyber assets associated with the bulk electric system. As they were revised, the standards started to focus on securing only those digital systems that could pose a reliability risk to the power grid if compromised.
This targeted approach reflected the reliability-based scope of NERC’s statutory authority.
Transition from Asset-Based to Impact-Based Models The CIP release has brought to light a significant shift from the asset-based focus of the initial CIP standard to an impact-based focus on categorizing critical infrastructure assets. Early editions of the standard took a model that focused on identifying particular assets and attempted to apply those models to various types of systems, which proved to be inefficient.
The framework has been evolved so that the focus is on the impact of the equipment on the bulk electric system rather than on the individual piece of equipment. This change in perspective allows for more consistent and reliability risk-based application of the standards.
Reguläre Fortsetzung der Diskussion am 14.12.2016 im Ausschuss für Angelegenheiten der EU im Beisein des Vizeministers für digitale Entwicklung Zied Roubia Le Cidre 7, 1st floor 1000 Brüssel 2 TEL +32 (0)2 284 11 83 E-mail Inception von Risikozentren nach dem Vorbild des #impactbasedregulation: Dieses Prinzip sieht auch vor, dass die Cybersecurity-Vergeltungsmöglichkeiten nach den konsequentierten Systemrisiken ausgerichtet sind.
Regulatory Oversight and FERC Direction FERC was a key participant in shaping the process of developing new CIP standards. This occurred through review and approval of proposed standards and direction on several aspects of CIP standards. This includes, but is not limited to, clarification on scope and boundaries, consistency within the CIP bundle and adherence to FERC’s risk-based policy framework.
This determination was made in order to ensure that CIP Reliability Standard provisions are aligned with statutory authority and reliability objectives. In addition, this determination has the effect of subjecting
cybersecurity provisions of Reliability Standards to the same oversight mechanisms as other Reliability Standards.
The standards development process is inherently iterative as developments in risk and technology are constantly evolving.
Integration with the Broader Reliability Framework These CIP Reliability Standards are not independent and stand alone requirements. Rather, they build upon the existing reliability framework and are governed by the same registration, compliance monitoring and enforcement processes as other Reliability Standards.
cybersecurity as a means to ensure system reliability through risk management. The integration of cybersecurity activities in established structures for risk management of reliability risks validates the adage that cybersecurity is part of reliability.
The purpose of this section is to describe the relationship between process control (CIP) and the administration and enforcement of CIP standards in the context of the established reliability standards.
Jurisdictional Boundaries and Scope The scope of this standard is limited to the defined Bulk Electric System and the statutory jurisdiction of the Federal Energy Regulatory Commission and the Regional Transmission Organizations. The CIP requirements set forth in this standard are not intended to apply to all organizational information systems or business networks.
This boundary maintains focus on reliability relevant cyber assets and prevents its expansion beyond regulatory mandate. It further highlights the difference between enterprise-wide cybersecurity and reliability-centric reliability focused cybersecurity.
Understanding the boundaries of CIP and its limitations is a pre-requisite for this paper.
Executive and Governance Perspective Cybersecurity and reliability in the process industries are entering a new era for executives as advancements in the Computer Interchange Program (CIP) standards are combining the three areas. Choices around cyber-resiliency measures such as system design, access controls and vendor recommendations can have a significant impact on reliability and regulatory compliance.
In order to ensure adequate reliability governance processes address the need for effective cybersecurity risk management. Governance processes should therefore take into account the need to incorporate cybersecurity as part of overall reliability oversight – as opposed to treating it as a purely technical or IT related function.
The NERC Critical Infrastructure Protection (CIP) Standards are a set of rules developed under the statutory authority of Section 215 of the Federal Power Act that designated cyber threats as reliability threats. Through a few iterations under the scrutiny of FERC, the CIP Standards evolved into an impact based risk reduction approach that incorporates elements of the reliability system.
This foundation section prepares the reader for discussion of how standards affect the definitions of scope and applicability as detailed in the next chapter.
FROM THE FIELD
CIP isn't separate from FERC's authority over reliability. It is reliability, governed by the same statute that governs frequency, voltage, and protection.
Each CIP version reflects the threat the standard was last revised to handle. Reading the version history tells you what the framework knows about adversary behavior.
The CIP standards revise faster than other reliability standards because the threats revise faster. Programs built for CIP v5 do not pass v9.
Chapter 3
Scope and Applicability of the CIP Framework
As the previous chapter discussed in some detail, the focus of this chapter is the scope and applicability of NERC’s Critical Infrastructure Protection (CIP) regulations. In particular, the chapter will focus on the scope of the CIP standards, how NERC determines the applicability of the standards, and generally why the scope of CIP has been set where it has. Determining the scope and applicability of the CIP rules and regulations is an important aspect of compliance, because it can be all too easy to become muddled or to misunderstand which elements of the regulations actually apply to your situation. The scope and applicability are intentionally set to include only a certain group of stakeholders and only a certain number of types of critical infrastructure, and it is therefore important to understand clearly how the scope and applicability have been defined by the regulatory body.
Reliability-Driven Scope The scope of the CIP framework is determined by the reliability impact of the potential cybersecurity threats. In other words, the CIP standards focus on those cybersecurity risks which have a reliability impact, and do not address more general cybersecurity risks. In particular, the CIP standards are intended to ensure the security of cyber assets that are relied upon in the provision of reliable Generation, Transmission and Distribution services in the BES.
This reliability-driven scope is based on the statutory authority under which the CIP standards were developed. Section 215 of the Federal Power Act authorizes standards for reliability (as defined by the Commission) and not for comprehensive enterpriselevel cybersecurity governance.
As a consequence, CIP standards generally focus on only those cyber assets whose compromise might affect availability, integrity or interoperability of the Critical Infrastructure.
Applicability Based on Functional Responsibility This Reliability Standard identifies the applicability of the CIP Rules based on functional responsibility rather than the size of the organization, or who owns the assets. As such, Reliability Standard C1 identifies those entities with functional responsibility for activities that impact reliability of the bulk electric system, and identifies those cyber assets owned or operated by such entities.
Holdin system managers accountable for the reliability impact of their cyber actions on the power grid The Electric Power Research Institute, or EPRI, has published a paper that recommends making system managers accountable for the reliability impact of their cyber actions on the power grid. The paper notes that the occurrence of cyber risks is a function of the operation and control of the grid and not of ownership.
Functional applicability ensures consistent treatment across diverse organizational structures and business models.
Cyber Assets and Reliability Impact Cyber-Physical (CIP) elements have a direct relationship with the applicability of CIP regulations. In this context, cyber assets that contribute to reliability have their own definition. In the BES, these are generally referred to as monitoring, control, and protection systems associated with BES facilities.
All digital systems within the framework are not created equal. Business systems, corporate e-mail systems and general information technology systems do not fall within the scope of this framework unless they are utilized in support of some aspect of the reliable operation of the electric system.
This definition reinforces the reliability focus of the CIP standards and precludes expansion into non reliability areas.
Impact-Based Categorization CRDA developed the Cybersecurity and Infrastructure Protection (CIP) Reliability Framework, which defines a risk-based, impact-based approach for categorizing systems and assets using an impact-based methodology. This approach assesses impact by determining the potential effect on the BES that could result from a loss of, compromise to, or use of a system.
This approach to evaluating biological systems supports the principle of proportionality. Systems with higher potential for harm or with greater global impact may be subject to more stringent risk management requirements. In contrast, systems with lower potential for harm or impact may require less stringent risk management activities.
Impact-based categorization is increasingly being recognized as a more nuanced approach to reliability risk management, acknowledging that not all reliability risks are the same and that more resources may be required to address those with higher consequences.
Boundaries of the CIP Framework Just as important as understanding what is covered by the CIP Reliability Standard is an understanding of what is not covered. The CIP Reliability Standard does not address: (1) enterprise-wide cybersecurity programs, (2) protection of personal information, (3) general IT systems at the Bulk Electric System (BES) Entity, unless the general IT systems are used for reliability purposes.
These standards do not address physical security issues except where such issues are the consequence of physical access to cyber assets. This clear boundary between physical and cyber risk reduces confusion.
These limits are intentional and grounded in statutory authority and reliability objectives.
Common Sources of Applicability Confusion It is common for personnel to be confused about which elements of the CIPs are applicable, believing that because standards for cybersecurity exist across the entire electric infrastructure at the grid level they must automatically be applicable to specific assets or processes. This misunderstanding can result in over-scoping and failure to implement necessary reliability efforts due to the misalignment with perceived cybersecurity activities.
Another source of confusion relates to Connectivity vs. Applicability. Simply because a piece of equipment or system is connected, does not necessarily mean it is applicable to CIP. Applicability is more related to the function(s) that the equipment/system performs and the potential impact to system reliability.
Clarifying these misconceptions supports accurate understanding of the framework.
Oversight Perspective A clear scope and applicability is essential for the consistency of oversight activities. The oversight organization uses the functional definitions, and the categories of CIP impact to determine the extent to which CIP applies.
This clarity supports fairness, predictability, and proportionality within the compliance framework.
Recognizing CIP Scope can be helpful to executives in aligning cybersecurity governance activities with reliability obligations in a manageable way. Understanding the boundaries and scope of the control environment can also help executives make informed decisions on CENRS and CAES affected system boundaries and respective controls.
It is important for engineers and operators to have an understanding of what is applicable so they can relate cybersecurity to their work and know how they will be held accountable. It ties back to protecting the cyber assets and making sure the system is reliable.
The scope of the CIP Reliability Standard is limited to cybersecurity risks that could potentially impact the reliability of the bulk electric system. A specific entity’s scope will be based on the functions that the entity performs and the potential reliability impact from failure or compromise of those functions,
regardless of the size of the entity or the entity’s overall Cybersecurity posture. The impact-based categorization approach helps to ensure that regulation is proportionate to the potential reliability impact of a particular function, all while staying within the statutory bounds.
Chapter 1 took a long look at defining the scope and applicability of critical infrastructure cyber systems. Chapter 2 expands on this and considers what this means to the identification and classification of critical cyber assets.
FROM THE FIELD
CIP applies based on what the asset does, not what it's called. A control system that performs a Medium Impact function is Medium Impact, regardless of how the IT department classifies it.
Scope decisions made at registration become program assumptions for years. A scope set wrong at the start is a finding waiting to happen.
Applicability under CIP is determined by the BES Cyber System definition. Anything that meets the definition is in scope. Reading the definition closely is the single most important hour in CIP program design.
Chapter 4
Critical Cyber Assets and Impact Categorization
This chapter describes the underlying theories used when identifying the critical cyber assets and their potential impact within the NERC Critical Infrastructure Protection (CIP) regulations. It focuses on the reasons for the categorization, its relevance to the reliability goal and the overall reliability monitoring function.
The Role of Asset Identification in Reliability The portion of the BES covered by the Cybersecurity Risk Reduction (CRR) Program consists of control systems and cyber infrastructure that are associated with Bulk Power System (BPS) Reliability. This section clarifies that cyber security in the BES relates to assets that are used for reliability-related functions. Identifying critical cyber assets from a reliability perspective is a fundamental principle of the CIP Program.
Asset identification is not about making an inventory of all digital systems used within an organization. Its main purpose is to identify those systems that, if compromised or unavailable, have the potential to impact bulk electric system reliability.
Our methodology is reliability-focused and ensures that cybersecurity governance aligns with regulatory requirements and the relative risk of the system.
From Cyber Assets to Reliability Impact Not all cyber assets on the BES present the same level of risk to reliability. While some systems are integral to the direct monitoring and/or control of or protection for BES facilities, others may be involved with ancillary services or business activities.
The CIP Reliability Standard for Cybersecurity notes that there is a difference between availability, integrity and control of a system component and the determination of reliability impact for each type of component. In other words, the differences between cyber security requirements based on impact would be based on the potential reliability impact of loss of availability, integrity, or control, and not necessarily the type of technology or location of the component in question.
This consequence-driven perspective anchors cybersecurity oversight in reliability outcomes.
Impact Categorization as a Risk Management Tool Impact categorization is a methodology to link cyber security requirements to the potential impact on reliability. Through the impact categorization of critical infrastructure assets, one is able to allocate the appropriate level of resource and scrutiny in a way that is proportional to the assets impact.
Higher-impact systems require more detailed requirements because the impact of the loss of reliability could be more severe on the overall system. Lower-impact systems are handled in proportion to their potential impact on system reliability.
This proportionality reflects a fundamental principle of effective risk management.
Evolution of the Categorization Approach In the early years of CIP, asset-based identification was used in the CIP regulations as a basis for defining vulnerable system components. However, the many possible variations in system design, material and process technology, and operating procedures caused problems with respect to equivalence judgments and resulted in considerable lack of consistency.
Initially the framework assessed various types of electrical system assets that had potential cybervulnerabilities with primary emphasis on characteristics of those assets. The framework has progressed over time toward an impact-based approach with a greater focus on the overall system consequences of a potential threat than on the attributes of the individual components. Moving toward a reliability risk based approach to cybersecurity oversight enhances consistency and reduces ambiguity and is more reflective of potential reliability impacts.
The impact-based model is a development of the CIP (Combined Inspection Plan) framework as the result of the lessons learned and regulatory feedback.
Relationship Between Facilities, Systems, and Cyber Assets The impact categorization does not solely focus on the physical consequence of a type of attack. It incorporates the impact of the facilities themselves, the control or monitoring systems for these facilities, and the cyber-components that enable the functioning of these systems.
This post was updated on 23 January 2020. Understanding the relationship between the physical and cyber components of systems is important for all critical infrastructure partners. The layers of a system and their relationships demonstrate why it is important to understand the role of the cyber components in supporting the physical. A cyber asset’s value is derived from the function it supports.
From this perspective it is understandable that CIP standards are concerned with the functionality and role of the systems within the infrastructure.
Boundaries and Deliberate Limitations Selective definitions of impact are provided and impact categorization is limited. The CIP framework does not attempt to characterize all cyber assets within the Bulk Electric System and does not require reliability standards to be applied to non-critical systems.
The scope is bounded to avoid including enterprise-wide approaches to cybersecurity governance and to align with the intent of relevant statutory authority.
This set of limitations identifies the boundaries and goals of categorization.
Oversight and Consistency Considerations Impact categorization is relevant for CSD overlay purposes from an oversight perspective. Impact categorization serves as a reference point to determine applicable aspects and corresponding expectations. Consistent impact categorization can also provide a basis for equitable and predictable application of the CIP regime to entities and regions.
The purpose of these criteria is to serve as a basis for review and verification by oversight bodies that the parts fall within the appropriate categories, thereby confirming that the parts have the required characteristics to meet the reliability objectives. In no way do these criteria purport to question or change the technical design choices.
This approach reinforces accountability while respecting professional judgment.
Impact Categorization for Executives provides a linkage between System Design Decisions and Regulatory Risk. It identifies potential system design decisions that could impact asset categorization within the reliability framework. These relate to system architecture, integration and control.
For engineers and operators it is important to understand the categorization in order to know how expectations for Cybersecurity relate to their tasks. It is important to realize that the responsibility for Cybersecurity primarily stems from reliability aspects rather than from the technology itself.
The Critical Cyber Asset identification and impact categorization is a core of the CIP (Critical Infrastructure Protection) regulation. The Framework ties cybersecurity regulations to the relative impact to grid reliability, thus enabling utilities to implement only risk-appropriate cybersecurity measures to protect less than critical assets on the BES.
This chapter helps to lay the groundwork for the next chapter, which will explore the specifics of the standards related to security management controls and governance according to CIP.
FROM THE FIELD
The asset list is the foundation of the entire CIP program. If the asset list is wrong, every downstream control is misapplied.
Chapter 5
Security Management Controls and Governance
This chapter examines the role of security management controls and governance in the NERC CIP (Critical Infrastructure Protection) regulation that is used to govern the reliability of the Bulk Electric System (BES). The importance of the governance controls to cybersecurity reliability, the structure of accountability and the role of management oversight in ensuring that consistent protection of reliability critical cyber assets is provided are examined.
Cybersecurity as an Organizational Responsibility The cybersecurity element of reliability cannot be left to technology alone. Rather it is a business responsibility that engages all levels of an organization – from corporatelevel governance to operational-level procedures and individual accountability. The CIP Reliability Standard underscores this approach through its emphasis on management controls that complement technological countermeasures.
Security management controls establish the organizational framework within which security activities take place. They determine the extent of authority and responsibility within the organization and provide a basis for expectations that can ensure that security activities are more closely aligned with business reliability objectives rather than being viewed simply as technical tasks.
Systems reliability is considered from the perspective of the organisational behavior that supports technology. Thus reliability of systems is determined not only by technology but also by the organisational behaviour of the entities which make up a system.
Governance and Reliability Alignment Governance is a component of the CIPs that integrates cybersecurity with reliability of the bulk electric system. Good governance practices ensure that cybersecurity decisions are reliability centered and aligned with regulatory requirements and operational practices.
The Reliability Framework for Operations does not dictate organizational structure. Rather it sets out expectations of accountability and oversight. This allows an organization to design its governance structure to suit its size, complexity and role within the business and still deliver reliable outcomes.
Governance provides the connective tissue between policy intent and operational execution.
Accountability and Assigned Responsibility Security Management Controls (SMC) is a core element of the CIP. The CIP requires identification of who has been assigned the responsibility for making cybersecurity decisions that impact reliability-critical assets.
Clear accountability can be important for helping to ensure that plant operating personnel make consistent decisions in uncertain conditions and to eliminate uncertainty as to who is responsible for what in any given situation. In addition, proper accountabilty for the role of IT in plants can serve to reinforce the notion that IT is not a “wildcard” – that is, a function where there are no rules or where the nature of the work is considered discretionary rather than defined.
This clarity is essential for both day-to-day operations and regulatory oversight.
Policy as a Reliability Instrument In the CIP context, policies are rules or specifications that translate high level reliability goals into actionable goals or expectations for each organization. In relation to cybersecurity, a policy is a set of rules, laws or standards that state what is allowed and what is prohibited, thereby defining the scope of acceptable and prohibited activities and providing a basis for judging whether specific activities are acceptable.
Policies are not outcomes, nor are they standards for behavior. Their worth is in their ability to support reliability outcomes and actions that strengthen reliability culture throughout the organization. Overly broad, complex, or scattered policies can obscure visibility of individual accountability.
Risk-based analysis is based on the principle that the actual form of risk-based policies should closely relate to the reliability risk that they seek to influence.
Management Oversight and Review Management oversight is an important element of cybersecurity governance. In this post we’ll focus on the aspects of oversight and how they can contribute to the overall management of an organization’s cybersecurity. Oversight relates to the mechanisms that provide visibility into an organization’s cybersecurity posture and that help managers to make informed decisions. Oversight can also relate to the means through which managers ensure they hold people accountable for cybersecurity activities and that appropriate action is taken in response to the identification of cybersecurity vulnerabilities or incidents.
Reliability Oversight will ensure that the cybersecurity focus is in alignment with the potential impact and significance of the systems it protects and will help manage awareness of changing threat environments and system conditions.
Our ongoing Oversight efforts remind organizations and employees that Cybersecurity is an on-going responsibility rather than a one time process.
Integration with Reliability Programs Security management controls should not be thought of as being independent of the overall reliability programs of operational, planning and risk management functions.
The integration of electric power delivery cyber systems within Smart Grids creates new possibilities for increased efficiency and productivity, but also raises a range of new Cyber Security challenges. Ensuring the integration of systemic Cyber Security considerations into design choices, access controls and operational interactions, is essential. - The integration of Cyber Security governance with other reliability functions is also important.
Integration reinforces the principle that cybersecurity is an integral part of reliability rather than a separate discipline.
Organizational Change and Continuity The reliability framework considers that organisations are dynamic systems. Personnel may be replaced; structural changes are made and technological advancements occur. These changes can have a negative impact on cybersecurity if managed poorly.
Controls ensure that appropriate security management activities are sustained over time and provide continuity through consistent standards that endure beyond particular personnel or technologies. Controls facilitate the adherence to accepted security practices as systems and organizations evolve.
This continuity is essential for sustaining reliability in a dynamic operating environment.
Oversight Perspective Security management controls provide visibility into activities and processes that help ensure that appropriate controls are in place to ensure that all organization-wide responsibilities for IT security have been addressed and embedded within the organization. Having a defined governance structure enables for more effective, timely, and consistent risk analysis and eliminates ad-hoc decision making.
Reliability Oversight Committee – Regulatory Oversight (ROC) and National Energy Board (NEB) The primary focus of Oversight Bodies is on the governance controls in place to understand how an organization manages cybersecurity risk to reliability in comparison to operational performance rather than the internal structure of the organization.
For executives, the security management controls section is intended to address the governance aspects of cybersecurity. There are many leadership decisions that impact who is accountable for what in terms of risk management, and where availability and reliability considerations are factored into the overall controls of the cybersecurity program.
For engineers and operators, governance provides context for their technical work. It lets them know who has made what decisions and it helps ensure that all technical work and actions are carried out in a way that supports reliability expectations and the decision authority of personnel.
Security management controls and governance are fundamental to the CIP framework. Holding accountables under CIP applicable to the Bulk Electric System (BES) responsible for managing these controls, and tying policy to the reliability goals of the BES, helps ensure that managing cybersecurity is viewed as an enterprise-wide management responsibility critical to BES reliability.
This foundation will be used in the next chapter when we look at personnel and access controls from the perspective of the CIP.
FROM THE FIELD
Governance is the part of CIP that doesn't show up on a network diagram. It's also the part the auditor reads first.
A CIP program without an executive accountable for it is a program waiting for that accountability to be assigned at the next finding.
Policies that haven't been exercised aren't governance. They're documents. The audit looks for evidence that the governance actually governs.
Chapter 6
Personnel Risk and Access Considerations
This chapter addresses the risk and access aspects associated with personnel and their relationships to risks in the context of the NERC-CIP framework with particular respect to the considerations associated with the need for personnel to interact with reliability critical cyber assets, conceptually managing this risk, and how personnel associated with cyber security reliability fit into this Risk Management Framework.
Human Interaction as a Reliability Risk Factor While many are aware that most risks associated with cybersecurity in the Bulk Power System relate to technology, there are many more that relate to a person’s interaction with that technology. Thus, we have a new category of risk that must be carefully managed.
Personnel may interact with a system through operation, maintenance, configuration, or through support functions to the system. These interactions are vital to the operation of the system, and therefore constitute potential vulnerabili- ties. They present the opportunity for errors or misuse to be introduced which may impact on system reliability.
Personnel risks The Chartered Institute of Personnel (CIP) framework states that managing the risks associated with employees is important to maintain reliability.
Reliability Focus of Personnel Controls The CIP personnel requirements relate to achieving the Reliability Goals by addressing specific individuals on a Utilities’ staff rather than dealing with the overall work force. The personnel requirements are focused on personnel that can impact the reliability of cyber systems that support the bulk electric system.
This focus results from the statutory basis of the CIP standards. Not all personnel or human resources activities are covered under the CIP framework. Personnel risk is addressed only where personnel may have access to, or authority for action in, systems that are critical to the availability, integrity, or operation of Information Assets.
This bounded approach preserves clarity and proportionality.
Access as a Reliability Interface Access to reliability-critical cyber assets is one of the most important interfaces between human activity and system behaviour. The access is often physical, logical or remote access, and will generally depend on the nature of the systems involved.
The CIP framework treats access as a conceptual control point rather than a technical feature. The way access is granted, maintained and revoked affects the potential for an individual to impact system behavior.
By looking at access as a means to guarantee availability, its administration shifts from being a managerial activity to a reliability-related one.
Authorized Versus Unauthorized Interaction From a reliability perspective, it is very important to distinguish between authorized and unauthorized interactions. Authorized access is to support on-going operational and engineering activities. Unauthorized access is where reliability is reduced, and risk is introduced.
The CIP Related Intent and Purpose (CIP-RIP) Model, specifically the CIP framework for Asset Management captures four intent and purpose statements of the rules, regulations, standards, and guidelines related to ensuring clarity for who has access to reliability-critical cyber assets and under what conditions. The intent and purpose is for access and use to be clear, in order to hold people accountable and to minimize opportunities for the unauthorized access of critical cyber assets and systems to occur.
The Authorization Control Framework does not address the methodology an organization will use to perform such authorization. Rather, it sets expectations for control and awareness.
Insider Risk and Reliability Personnel-related risk is caused by the unintentional as well as intentional actions of individuals. Errors, misunderstandings or loss of judgement can equally affect the reliability of a system as the activities of a malicious individual.
CIP treats the inherent randomness and unpredictability of human behavior with the controls that support predictable and consistent interaction with reliability-critical system components. The purpose of these controls is to minimize the probability that any single human activity will cause the failure of a reliability-critical system component.
This approach reflects the understanding that insider risk is a reliability issue, not a security issue.
Continuity and Role Changes Personnel changes to roles, responsibilities or employment can significantly impact the organisation’s security if not managed correctly from a reliability perspective the continuity of control and authority should be maintained at all times.
The CIP points out that personnel changes occur and recommends that access be related to current job responsibilities in order to provide high reliability for systems operation.
Continuity considerations reinforce the importance of organizational discipline rather than individual reliance.
Oversight Perspective Personnel and access considerations can provide valuable insight into how people interact with reliability-critical components and systems within an organization. Ensuring that expectations and accountabilities are clearly defined can help facilitate objective evaluation and reduce subjectivity.
Reliability Objectives: Oversight of Personnel-Related Risk Oversight bodies generally focus on ensuring that personnel-related risk is identified and mitigated in a manner consistent with reliability objectives rather than on the specifics of personnel practices.
This distinction preserves organizational flexibility while reinforcing reliability expectations.
Executive summary Personnel risk is a cross cutting topic, related to people and HR management and reliability engineering. Executive actions related to personnel aspects can affect reliability through their impact on overall cybersecurity risk.
For engineers and operators it is often necessary to expand the focus to personnel to recognize how individual actions and access rights impact the overall system performance. This may be done to emphasize the need for discipline and proper role definition in reliability-critical areas.
People’s interaction with reliability-critical cyber assets constitute a significant category of cybersecurity risk under the CIP RC Reliability Conures vulnerability and exposure framework. The framework addresses access and other human factor aspects at a high level of abstraction enabling accountability, continuity and reliability while not mandating any specific workforce behaviors or work flows.
It’s essential to understand this concept before moving into the next chapter. We’ll examine how the CIP Model addresses the system security and technical protection required for the systems at issue.
FROM THE FIELD
Most cyber incidents on the BES involve credentials, not code. CIP recognizes this and the personnel-and-access requirements are designed around it.
A revoked credential that's still active is the most preventable CIP finding. It's also one of the most common.
Access reviews aren't a quarterly checkbox. They're an ongoing reliability obligation. The standard expects the review to detect and correct, not just document.
Chapter 7
System Security and Technical Protection Concepts
Systems, Protection and Technical Countermeasures This Chapter covers the Systems, Protection and Technical Countermeasures control, which is one of the five controls of the NERC Critical Infrastructure Protection (CIP) rule. It discusses the relationship between system security and the concepts of technical protection, and covers the necessity of technical protections from a reliability perspective and how they relate to the overall cybersecurity framework and their application as conceptual controls to reliability-critical cyber assets.
Technical Protection as a Reliability Safeguard The purpose of technical protections is to reduce the likelihood of a successful cyber attack against reliability critical control systems that could compromise the availability, integrity or performance of those systems. They are not ends in themselves, but rather means to an end. Their purpose is to ensure the availability, integrity and reliable operation of systems that perform reliability-critical functions.
Within the CIP reliability framework, technical controls such as technological safeguards are considered to be measures that support the Electric Reliability Commission of Texas (ERCOT) goals of achieving reliability, and are not considered to be Cybersecurity controls in and of themselves. Rather they are one of the measures that integrate with the Governance, administrative controls, and monitoring requirements of the CIP Rule.
Protecting System Availability and Integrity From a reliability standpoint, availability and integrity are critical to ensuring the availability and reliability of the system. Critical cyber assets in the monitoring, control and protection systems must be available when they are required and must perform their intended function.
The intent of technical controls is to reduce the likelihood of cyber incidents affecting the operation of the system. Unintended loss of availability or changes to system operations could impact situational awareness, coordination, and protection system performance.
Availability and Integrity are key reliability metrics that describe when systems or services are operable and performing their required functions. CIP ties technical controls more directly to reliability outcomes by emphasizing availability and integrity.
Boundaries Between Systems and Networks Within the CIP model, one of the key components in identifying a “critical cyber system” is the establishment of boundaries based on reliability relevance and identifying which systems require protection and which connections pose a risk. Not all systems need the same level of protection, nor are all connections to other systems of equal risk.
BSPM - Boundary Separation Point Module - Boundaries serve to control the extent to which disturbances or disruptions can propagate from non-critical systems to reliability-critical systems. They constitute a containment and predicable environment within complex systems.
The framework emphasizes the importance of understanding system relationships rather than prescribing specific network designs.
Communications and Trust Relationships Cyber assets used for reliability operations often interact with other systems, control centers and organizations. This gives rise to reliability trust relationships that must be defined.
The CIP Reliability Standard for Trust Management provides a framework for utilities to understand and begin to plan for the impact of trust on grids, such as the impact of trust relationships on the risks and vulnerabilities of the system. The management of trust is concerned with understanding the flow of information within the system, the entities that can influence the operation of the system, and the impact of interdependencies on reliability.
This focus supports intentional design and awareness rather than technical prescription.
Managing Change and System Stability Many of the system security issues relate to protecting the system from potential malicious activities. However, there are other, less obvious issues related to the management of changes to system components, configurations or software that, if not properly understood and dealt with, can have significant implications on the overall system reliability.
From reliability perspective unintended consequences of change is a form of risk. Technical protections in the context of stability, generally speaking are designed to ensure stability by ensuring predictable system behavior and eliminating unintended effects.
View this as part 1 of our cybersecurity blog post series and in this entry we reiterate that system engineering and cybersecurity are strongly related within a reliability framework.
Detection and Awareness - This knowledge factor of technical protection relates to the component system condition awareness. System condition awareness facilitates early response to unusual system states and can contribute to prevention of primary failures resulting in forced outages.
In the CIP context, monitoring and identifying suspicious events and associated activities is not an end in itself. Rather, the functions of monitoring and notifying for unusual activities ultimately support the planning and response to possible emergencies.
This concept aligns with broader reliability principles related to situational awareness.
Technical Controls in Context According to the CIP standards, technical controls should not be viewed in isolation. Effective technical controls require appropriate governance, administrative controls, and operational procedures.
Controls that add technical layers of protection but are not properly integrated with the processes of the organization or reliability targets do little more than increase complexity without adding value. The Framework therefore emphasizes the principle of alignment rather than accumulation.
To grasp this concept, one must first understand what the surface means in terms of IT security. It is important to keep in mind that a high level of IT security does not necessarily have to do with the amount of technical countermeasures that are implemented.
Oversight Perspective System security concepts relate to our views on the oversight of protection mechanisms provided for reliability-critical systems against potential cyber disruptions. It should be noted that our views relate to concepts as they relate to reliability, as opposed to technology and related implementation details.
This approach preserves flexibility while reinforcing accountability for system-level risk management.
For Executives: System Security Concepts relate to the impact of design choices on reliability, linking technological decisions to reliability exposure. Investments in system architecture, design for integration and for security all affect a systems’ overall level of cybersecurity and their reliability exposure.
For engineers and operators understanding technical protection concepts may seem irrelevant at first but it really does help understand the system behavior, communications and change management in relation to the reliability expectations.
The concepts of system security and technical protection within the CIP Rules are implemented to ensure the reliability of cyber assets providing bulk electric system reliability services by maintaining availability, maintaining integrity and maintaining predictable behavior. These are reliability safeguards
and are not solely focused on cybersecurity. Implementation of these controls must also take into account the governance, workforce and operations considerations.
This foundation will act as a springboard for the discussion in the next chapter, which will be concerned with analyzing how the CIP addresses the monitoring, response and recovery concepts.
FROM THE FIELD
Technical controls are what the firewall does. They're also what the firewall doesn't do, and the gaps are usually the audit findings.
CIP-007 is where most CIP programs spend the most operational effort, and where most audit findings cluster. The two facts are connected.
A baseline configuration that wasn't validated against actual operating need is a baseline that won't survive an audit question. CIP-010 expects validation, not just documentation.
Chapter 8
Monitoring, Detection, Response, and Recovery Concepts
This chapter will discuss how monitoring, detection, response, and recovery relate to bulk electric system reliability in the context of the NERC Critical Infrastructure Protection Reliability Standards. This chapter is different from the rest of the book in that it focuses on the value of monitoring, detection, response, and recovery to reliability as opposed to the broader cybersecurity context. However, it is also important to understand that the regulation of monitoring, detection, response, and recovery as a means of preventing cyberattacks in the bulk electric system is a part of the larger cybersecurity and reliability compliance regime.
Cyber Events as Reliability Events The Cybersecurity Infrastructure Protection (CIP) Reliability Risk Assessment Model treats cyber events differently than traditional information loss scenarios. A cyber event that affects visibility, control or communication functions could be determined to have a material impact on system reliability, even in the absence of physical damage to equipment.
Current CSF perspective has a strong focus on the interdependence of cyber security and operational awareness and control of smart grid assets and systems. Monitoring and response capabilities exist to support reliable grid operation through early detection and resolution of cybersecurity threats to prevent adverse impact on the broader power system.
Monitoring as Situational Awareness Monitoring can be seen as the Situational Awareness (SA) activity for reliability-critical cyber systems. SA is defined as “knowing what is going on with your system in sufficient detail to take appropriate action, at the time the action is required.†Thus, the system status, its behavior and performance are the fundamental indicators that provide the necessary information for decision making at the right time.
From a reliability perspective, monitoring is not only about detecting malicious activity. It’s also about understanding misconfigurations, failures or unusual behavior that can have a negative impact on reliability.
This perspective broadens the scope of monitoring so that it no longer serves merely as a security measure but rather as a general reliability safeguard.
Detection and Reliability Risk The act of determining whether a particular discrepancy from expected system behavior has been identified. In the CIP context, detection enables discrepancies that may potentially affect reliability to be discovered at an early stage.
Early detection helps to reduce uncertainty and gives operators and engineers more time to choose from a range of possible actions. Delayed or inadequate detection allows anomalies to persist and potentially worsen, which can increase the likelihood of system disruption.
Detect defines the role of detection as a Sub-Capability within Capabilities that provides support to activities carried out by other Capabilities rather than serving simply as a technical countermeasure.
Response as Coordinated Action The Response concepts in the CIP Reliability Volume deal with the interaction between control and correction of reliability problems that may arise in reliability-critical systems as a result of abnormal cyber activity. This work recognizes that the actions taken to correct such problems are an extension of normal operational procedures rather than purely technical remedial actions.
Reliability must be considered when activities are conducted in support of response operations. Any actions taken in support of the cyber response must be aligned to the operational priorities and the current state of the system to minimize potential impacts.
The framework therefore emphasizes integration between cybersecurity response and reliability operations.
Recovery and System Resilience Recovery concepts describe the capacity to restore system operations after a cyber incident. From a reliability perspective, recovery is a factor that can influence the overall resilience and capacity to maintain business operations following an incident.
Restoring some system components or subsystems to their original state does not necessarily mean that recovery has been achieved. We have to identify relationships between components, prioritize restoration of reliability-critical functionality and validate the behavior of the restored system with the other system components.
The fact that the focus on recovery is being maintained as one of the three reliability elements within CAP suggests that the role of recovery is being viewed as a reliability capability rather than solely as an engineering activity.
Learning and Continuous Improvement Monitoring, detection, response and recovery also supports learning within a reliability framework. Events and near misses should be analyzed to better understand system performance and risk.
This learning process helps improve operational practices, governance and system design. It reinforces the idea that Cyber Security and Reliability are evolving disciplines.
Continuous improvement strengthens resilience over time.
Boundaries and Scope Similar to other activities defined in the CIP Cybersecurity Incident Protocol (CIP CIP-006-7.2x) framework, the incident monitoring and response concepts described in this subsection are limited by reliability relevance and do not require implementation of enterprise-wide incident response or business continuity plans unless they relate to reliability-critical cyber assets.
Focus Area 5.2 System Reliability Boundaries 5.2.1 Definition This boundary preserves focus on system reliability and excludes the more general cybersecurity governance.
Oversight Perspective Cyber-Reliability Oversight, Monitoring and Response Capabilities This section discusses the information available to an oversight body regarding an organization’s ability to monitor and respond to cyber-related reliability risk, and the focus of that oversight.
This approach supports flexibility while reinforcing accountability.
Executive summary For executives the Monitoring and Response concepts highlight the need for being prepared to respond to an incident and for coordination within the organization. Governance decisions can significantly impact the ability of an organization to detect and respond to cyber-related reliability risks.
Reliability Engineering Note: The following material is intended to benefit control room engineers and operators. The main purpose is to show the relationship between cyber system behavior and operational reliability awareness, coordination of actions and process of reporting an incident in a disciplined manner.
The concepts of monitoring, detection, response, and recovery are all key to maintaining reliability of the bulk electric system (BES) through awareness and coordination of potential cyber threats, and through building system resilience to such events. These
concepts are aligned with several other concepts in the CIP Reliability Standard that comprise the broader categories of governance, technical protections, and operational protocols, and that are essential to reliable generation and transmission of electricity.
This discussion prepares the reader for the topics that will be covered in the next chapter on the application of compliance monitoring and enforcement to CIP standards.
Chapter 9
CIP Compliance Monitoring and Enforcement
This chapter is about how compliance monitoring and enforcement fit within the NERC regime of standards for electric reliability that includes the CIP Rules. It discusses in broad terms the purpose, structure and reliability preserving intent of compliance monitoring and enforcement activities for CIP under NERC’s regime of standards, but omits discussion of less important audit preparation and monitoring matters such as documentation, procedures and techniques for gathering and analyzing evidence as well as general compliance and risk reduction advice to facilities.
Cybersecurity Within the Mandatory Reliability Framework CIP standards are mandated under the same reliability program as planning, operations and protection standards. Therefore, compliance monitoring and enforcement of CIP standards is mandated under the same statutory powers provided under Section 215 of the Federal Power Act.
This rule integrates the principle that cybersecurity is not a separate or optional discipline. The cybersecurity reliability standards associated with reliability functions are subject to the same accountability, consistency and oversight requirements as other Reliability Standards.
Understanding this integration is essential to understanding how CIP oversight functions.
Purpose of CIP Compliance Monitoring Compliance monitoring for CIP standards provides assurance that reliability-critical cyber risks are being addressed in a manner that is compliant with mandatory standards. The purpose of monitoring for compliance with these standards is to confirm that the activities being conducted are in line with reliability expectations rather than to evaluate the overall cybersecurity of control systems.
The focus on cybersecurity reliability mirrors the reliability-based nature of the CIP standards. Activities related to oversight are intended to verify that all required reliability efforts to protect reliability-critical cyber assets have been implemented and are functioning properly.
The Monitoring activity is meant to ensure system reliability, by confirming the accountability for assigned tasks and by pinpointing the criticality level of possible weaknesses.
Risk-Based Oversight Similar to other Reliability Standards, the compliance monitoring activities in relation to CIP are risk-based. The reliability impact of any potential cyber-vulnerabilities that are not addressed (as determined by the Reliability Monitor) is not considered to be the same for all vulnerabilities.
This risk-based approach enables oversight to be both proportionate and efficient. Higher impact systems and functions are given more focus because of their potential system wide impact.
Risk-based oversight reinforces alignment between cybersecurity activities and reliability objectives.
Consistency Across Regions and Entities Consistency is one of the key elements of CIP compliance monitoring with respect to reliability. Consistency in reliability expectations with respect to cybersecurity shall be applied uniformly to all entities performing the same or similar functions, regardless of location or ownership.
All participants work together to ensure that the standards are interpreted and applied uniformly and in a predictable manner. Coordination among NERC and Regional Entities ensures that all focus is on advancing reliability.
Consistency also supports industry confidence in the oversight framework.
Enforcement as an Accountability Mechanism The enforcement of the CIP standards serves as an accountability mechanism within the reliability framework, and is intended to reinforce the gravity of the cybersecurity regulations designed to protect reliability-critical systems.
The FERC order does not specifically punish companies for failing to prevent a cyberattack, but rather for violating reliability standards that are compulsory, FERC Commissioner Kelly said in a statement. “There’s a false narrative that FERC imposed this penalty because Palo Alto Universal Johnson controls center was penetrated by malicious actors. That is not the reason the penalty was issued, although it clearly did occur,” he said.
This clause clarifies that enforcement action will not be taken on variable aspects of supply reliability since the main emphasis of the enforcement procedures is conformity with expected levels of supply reliability, rather than achievement of specific reliability performance standards that may be influenced by factors outside the control of supply entities.
Due Process and Transparency CIP compliance monitoring and enforcement is performed within the guidelines of established procedures and the requirements of Due Process which mandates a thorough and transparent process. Rights of the pertinent regulated entities are defined and an appeals process allowed.
The procedures outlined above are intended to ensure fairness and add to public confidence in the CIP oversight process. They are consistent with principles embodied in the reliability enforcement process for FERC licensed and wholesale rate jurisdictional utilities.
Due process is a foundational element of the statutory reliability framework.
Relationship Between Compliance and Cyber Resilience Adherence to the CIP cyber and physical reliability standards is critical to achieving cyber resilience but is not in and of itself a guarantee of systemic security against cyber attacks. The changing nature of cyber threats, however, means that no level of risk reduction can fully eliminate risk of a cyber attack occurring.
Compliance monitoring is intended to enhance existing controls, accountability measures and to provide an additional layer of protection rather than being a validation of the security of the system. Resilience also depends on a range of other factors at the organizational and technical level.
Understanding this relationship helps set realistic expectations for CIP oversight.
Oversight Perspective CIP compliance monitoring provides visibility into how the risk of cybersecurity to grid reliability is being managed at an operator level. It can be used to identify common problems and inform the development of best practices and standards.
Reliability oversight is more focused on ensuring that the cybersecurity controls implemented by an entity are aligned with its reliability objectives rather than dictating the specific controls or measures that must be put in place.
This alert is for Executives, Governance and Operations. In CIP compliance monitoring, governance of cybersecurity issues is examined from a corporate management perspective. Corporate-level decisions in an organization affect how the cybersecurity functions in relation to reliability.
Understanding CIP Oversight will give Engineers and Operators a better understanding of how utilities’ expectations regarding cyber security are determined. This is a great tie in to the relationship between cyber security and the protection of cyber assets and the overall reliability of a system.
CIP compliance monitoring and enforcement apply cybersecurity standards within the same mandatory reliability framework that is applied to all other NERC Reliability Standards. Oversight activities focus on accountability, consistency and reliability risk, rather than the overall cybersecurity maturity of the BES.
This discussion lays the groundwork for our examination of penalties, mitigation, and risk considerations in relation to CIP standards that we’ll cover in the next chapter.
FROM THE FIELD
CIP audits are denser than non-CIP audits. The evidence requests are deeper, the rolling questions are technical, and the consequence of a finding compounds.
The Region brings cyber-trained auditors to CIP audits. The conversation is technical. Compliance professionals who can't speak the technical language end up taking the auditor's framing.
CIP findings travel further than non-CIP findings. They reach FERC, they reach the public docket, and they reach insurance and procurement. Treat them accordingly.
Chapter 10
Common Misunderstandings About CIP
This chapter identifies some of the sources of misunderstanding related to the NERC Critical Infrastructure Protection (CIP) regulations and the interaction of controls under the CIP regulations with the reliability framework. It is the first step in coming to an understanding of how the CIP regulations are intended to work with the reliability framework and in dispelling misconceptions that interfere with the understanding of the roles that cybersecurity, CIP Rule compliance, and reliability play in ensuring reliable grid operations.
CIP Is Not Enterprise Cybersecurity One of the most frequent misconceptions we run across is that compliance with the CIP standards represents a holistic enterprise-wide cybersecurity program. While risks addressed by the CIP standards certainly include cybersecurity risks, the intent of the standards and their reach are far more narrow and defined to focus on only those cyber assets, whether physical or logical, that impact bulk electric system reliability.
If the enterprise information systems, networks, or applications are not related to reliability-critical activities, they are also outside of CIP. Including all CIP requirements under a single umbrella that is branded as an Enterprise Cybersecurity Framework will almost assuredly result in a false dichotomy that misunderstands priorities and over-explains relatively minor elements in proportion to their actual contribution to overall enterprise performance and security.
Understanding this boundary is essential to interpreting the intent of CIP standards.
Compliance Does Not Equal Cybersecurity Maturity Many interpret or assume compliance with a portion of the CIP cybersecurity regulations (CIP-009 through 011 and CIP-010) as meaning that a utility has achieved a level of cybersecurity maturity commensurate with the risk level of the asset or system involved. This is not correct. The purpose of imposing mandatory baseline requirements via regulation is to reduce reliability risk – not to drive or incentivize implementation of rigorous cybersecurity practices. Thus, compliance with these regulations simply represents a minimum required standard. It does not denote a high level of cybersecurity or even that the regulatory-required controls have been properly implemented to the level needed to address the vulnerability in question.
Some or all of the cybersecurity risks facing an asset operator may not be addressed within the reliability context of CIP. Similarly, an asset operator’s enterprise-level cybersecurity program may be far more sophisticated than that required under CIP.
Recognizing this distinction helps set realistic expectations for what CIP compliance represents.
CIP Is Not an Information Technology Standard CIP standards are sometimes misconstrued as being about information technology. In reality, CIP standards are reliability standards that incorporate provisions that deal with the cybersecurity aspects of operational technology (OT) and system control.
This is a classic misconception that can cause some misguided decisions when it comes to handing over operational responsibilities to IT groups without proper ties to the Ops, Engineering and Reliability organizations.
Identify the disciplines that would need to participate in CIP activities, considering the broad nature of cyber threats on control systems.
Connectivity Alone Does Not Determine Applicability Another common misconception in the process industries is that any connected system is under CIP regulations. A connected system is not automatically subject to CIP requirements.
These components are considered for applicability based on their functional scope and potential impact on reliability. Only those components, which are part of reliability-critical systems and processes, are in scope for CIP. Other components, which are connected but do not provide any critical function to reliability-critical systems or processes, are out of scope.
The risk of overstating connectivity or equating connectivity with applicability is that it may lead to over broadening the scope of compliance or to a misallocation of resources.
CIP Does Not Eliminate Cyber Risk A common misconception in the industry is that following CIP regulations eliminates all cyber risk. In fact, CIP regulations primarily reduce certain, but not all, cyber risks associated with reliability critical cyber assets. It does not eradicate every type of cyber threat or vulnerability.
1.3 Cyber risk The cyber risk faced by an organization is constantly evolving. The reliability framework acknowledges that regulatory standards are subject to change as circumstances develop. Compliance does not equal zero risk.
Understanding this limitation reinforces the importance of professional judgment and continuous awareness.
Enforcement Is Not Based on Cyber Incidents Alone One of the most commonly held misconceptions in cybersecurity is that enforcement actions occur as a direct result of a cyber attack or a cyber breach.
Enforcement occurs because of non-compliance with the required elements of the standards, not as a result of the fact that an incident has occurred.
Although a possible factor to be considered in the oversight of cybersecurity, violations that result from a cyber attack will be managed in relation to the existing reliability standards and thus are not unforeseen consequences.
CIP Is Not Static The CIP standards are often viewed as static or fixed. However, the CIP standards are updated and revised through the formal standards development process to incorporate lessons learned, new technologies, and newly identified threats and risks.
Many of the concerns regarding CIP are based on the assumption that it is a static system and has not changed much in recent years. This is no longer the case and we need to be flexible to meet today’s standards and expectations while still maintaining a level of continuity with existing reliability concepts.
Organizational Responsibility Is Broader Than a Single Team Another common misconception is that the CIP (Critical Infrastructure Protection) responsibility for ensuring cybersecurity falls solely to the IT team or department, whether it be the Information Security department or the Compliance department. In fact, ensuring cybersecurity reliability is a shared responsibility among all groups and stakeholders within an organization.
CIP scope and risk can be impacted by countless operational, engineering, procurement and management level decisions. It is important that all functions are aware of CIP standards to ensure the appropriate involvement in the process.
Clarifying the Role of CIP in Reliability A common source of confusion is the tendency to consider CIP as an isolated standard, rather than as part of the broader reliability risk management system. While the CIP standards deal with specific aspects of reliability risk management, they are a part of a much larger risk management system that also considers planning, operations, protection, and governance aspects.
Understanding CIP’s role within this system helps clarify its purpose and limitations.
There are a number of misconceptions that are prevalent in the industry today regarding CIP. The misunderstandings are generally revolving around the scope, purpose and who is responsible. CIP standards are reliability standards aimed at securing the cyber assets that support the bulk electric system. Achieving compliance to these standards will contribute to reducing some types of risk but in no way should be thought of as replacing good judgement and standard cybersecurity practices.
By clearing up these misconceptions, stakeholders will be better positioned to engage constructively with the CIP framework, which is discussed in detail below. The following chapter then introduces
readers to a high-level overview of how institutions can position themselves within a CIP risk management environment.
FROM THE FIELD
"We outsourced cybersecurity to the IT vendor" is not a CIP defense. The registered entity is accountable, regardless of who the entity contracted with.
"We're CIP-compliant because we passed the audit" is the misunderstanding that produces the next finding. Audits sample. Programs operate.
"CIP is an IT problem" is the framing that under-resources every CIP program that adopts it. CIP is a reliability problem with IT controls, and the staffing has to reflect that.
Chapter 11
Getting Oriented Within the CIP Framework
This chapter provides an overview of how an organization determines how to place itself within the NERC Critical Infrastructure Protection (CIP) regulatory framework. It covers initially how or when a component is determined to be within the CIP requirements, how the organization determines and handles who is responsible in the event of a dispute, and how cyber security reliability oversight fits into a company’s overall reliability program. This chapter does not cover the implementation of CIP requirements.
Entry Points Into the CIP Framework Most organizations run into the CIP (Critical Infrastructure Protection) rules when a system or function they manage is determined by FERC (Federal Energy Regulatory Commission) to be a part of the BES (Bulk Electric System). This typically occurs due to one or more of the following scenarios: - Changes to the physical structure of the network - Increased use of automation and technology - New high voltage interconnections - Changes to the operational role and responsibilities of the entity involved.
Inclusion within the CIP (Critical Infrastructure Protection) Category is based on risk to the reliability of the Bulk Power System. This principle explains why regulation of cyber security can occur where it was not previously considered a regulatory issue.
This reliability-driven entry point distinguishes CIP from enterprise cybersecurity programs.
Understanding Applicability in Context The following identifies how the listed elements function within the CIP relating to the appropriate and applicable relationship between CIP functions, facilities, and cyber assets.
Applicability is not a fixed one-time determination but rather reflects current system roles and configuration for the time period of interest. As a system evolves, or as components change, applicability may differ. Thus, recognising that CIP deals with a reliability issue which may change with time is an important aspect of designing effective controls.
This perspective supports awareness without prescribing evaluation methods.
Organizational Awareness and Alignment Achieving the level of maturity required to fully engage the CIP standards will demand involvement of a number of business functions. Ensuring that appropriate consideration is given to the reliability of the cybersecurity elements is a matter of integrating operational, engineering, planning, IT, and governance practices.
While certain activities outlined below may be assigned to specific individuals within an organization, it is ultimately the organization that has the collective Common Control and Cooperation (C2C) responsibilities for Critical Infrastructure Protection (CIP). Cybersecurity risk reduction decisions can be made and reliability exposures may be introduced or mitigated across a wide range of technical disciplines.
Understanding this alignment supports more effective internal coordination without dictating organizational structure.
Governance and Oversight Context As the CIP is a regulatory measure, it also brings a number of governance implications related to areas such as accountability, delegation of tasks and risk control. The element of cybersecurity reliability obligations brought under statutory management and regulation, is an important one.
EXECUTIVE NOTES ON CYBER RELIABILITY These notes should be reviewed with Executive leadership to understand the import of integrating consideration of cybersecurity impacts on reliability into Executive level discussions. Consider including a discussion of an organizations understanding of how design choices, access decisions, and operational practices may impact their reliability risk profile in these discussions.
Governance does not require technical expertise, but it does require informed oversight.
Interaction With Oversight Bodies Upon working within the CIP framework, organizations are exposed to oversight bodies that operate within the reliability structure and their working processes and expectations.
Inspecting activities should be seen as a part of a reliability regime and therefore conducted in a way that fosters positive relations with Regulatory bodies and other Stakeholders. Overviews are intended to confirm that the facility is following standard practices and therefore are not designed to be intrusive.
This perspective helps reduce uncertainty and supports transparency.
CIP as an Ongoing Responsibility Ensuring the reliability of cybersecurity is an ongoing responsibility that is informed by dynamic technological and system conditions as well as by the unique roles and responsibilities an organization has in its infrastructure. This responsibility is not necessarily bounded by discrete events or activities but may encompass a range of current and prospective circumstances that could affect the validity and effectiveness of measures taken to safeguard a system against cyber threats.
Recent advances in automation, communication, and control technologies affect the role that cyber assets play in ensuring reliability. Awareness of these developments is an important part of recognizing that CIP requirements can change over time as systems evolve.
This reinforces the importance of sustained attention rather than episodic focus.
Avoiding Early Misconceptions We have often seen that companies making their first foray into the CIP (Critical Infrastructure Protection) world believe the CIP BES (Reliability Standard, Grid Cyber) to be more about compliance, or view it as an irritating technical challenge rather than considering its potential for contributing to the overall resilience of the system.
Contrary to this assertion, reliability risk for CIP must be understood more precisely as a means to manage reliability risk of certain types. Compliance is merely a means to that end.
Clarifying this perspective early supports more effective participation in the framework.
As a resource for Executive Leaders, this module will introduce executives to the governance aspects of Cybersecurity Reliability through an orientation to the CIP (Cybersecurity and Critical Infrastructure Protection) framework. Executive Leaders’ Cybersecurity Reliability decisions and actions will be influenced by the organizational structure, their position and level of authority and their comfort level for risk.
For engineers and operations personnel, understanding CIP orientation helps bridge the gap between expectations around reliability of the bulk power system and the behavior of technical systems that support that system. It provides another perspective that links system performance to commissioning and to regulatory activities.
Getting started with the CIP Model starts with understanding the reliability impact, applicability and who is responsible for what within the reliability planning process for electric infrastructure. Who is responsible for reliability-related activities in the Bulk Electric System (BES) varies by system role and may change as new systems are introduced. Understanding that cybersecurity is a reliability concern aids in effective governance, planning and coordination with the FERC reliability review process and other relevant programs.
This chapter provides a prelude to the final synthesis of some of the main ideas about CIP, which will be presented in the last chapter of the book.
Chapter 12
Executive and Engineering Takeaways
This chapter draws together the various themes and ideas mentioned throughout CIP 101 and is directed to executives, engineers, and senior management. The intent of this chapter is to reinforce the Critical Infrastructure Protection (CIP) concepts and show their relevance to general reliability governance, technical decisions, and management practices.
Cybersecurity as a Reliability Discipline This one is very easy. According to the CIP framework, Cybersecurity is treated as a reliability discipline in the same manner as traditional reliability disciplines (e.g. transmission and distribution maintenance, generation and transmission system operations and planning). Therefore, cyber assets that are part of system control, monitoring and/ or protection that are part of the bulk electric system must be treated in the same manner as other reliability resources.
This provides the rationale for including cybersecurity standards within mandatory reliability standards and being held to the same reviews as planning and operational standards.
Understanding cybersecurity through this lens supports more effective engagement across organizational roles.
Governance Shapes Cyber Reliability Outcomes A comprehensive reliability monitoring program cannot be successful nor maintained if poor Governance practices are in place. A large number of the “Choices” that contribute to Cybersecurity reliability risks occur as a result of Governance practices such as organizational design, policies and procedure as well as system architecture and resource design. The following are examples of choices in these areas that need consideration:/Area of choiceDefinition of choiceExample from Governance practices Reliability Centred Security, 4th edition Area of Choice Definitions with examples.
As an Executive this blog post serves as a stark reminder that we can’t abdicate responsibility for Cybersecurity and Reliability to our technical teams. In fact our executive decisions create the conditions in which our Cybersecurity and Reliability goals are played out.
Effective governance aligns cybersecurity efforts with reliability priorities without prescribing technical solutions.
Engineering Judgment Remains Central The CIP standard sets mandatory requirements but does not preclude the use of engineering judgment. The technical person is responsible for understanding how a system operates, its interdependencies and the potential impacts of a cyber attack.
Judgment is required to determine how cyber related issues interact with the operational environment. Standards only set boundaries – it is up to individual engineering judgement, design practices, implementation, and maintenance to ensure systems operate in a reliable manner.
The balance between the Standardised Judgement Framework and judgement is a key element of the framework.
Compliance Supports but Does Not Define Reliability Meeting CIP cyber security requirements does not guarantee reliable cyber security. The requirements are a minimum level of security for certain categories of risks, and other issues within an organization, system, or environment could impact reliability.
Understanding this difference is critical to realising that achieving compliance is not the same as having strong cybersecurity or reliability. Compliance is the minimum and there is always more you can do.
This understanding supports realistic expectations and responsible decision-making.
Integration Across Disciplines Is Essential A persistent theme during our workshop discussions was the intersection of Cybersecurity Reliability with operations, engineering, planning, and governance. Strong engagement with the CIP will be needed from all these areas.
Without considering dependencies or risks of interconnected failures, siloed approaches can lead to blind spots. Integrating controls achieved through the framework ensures that appropriate cybersecurity expectations are aligned with the appropriate functional responsibilities and systems.
Understanding these intersections supports more coherent organizational responses to reliability risk.
Oversight as a Supporting Function Compliance monitoring and enforcement are supporting functions in the reliability framework. Their intent is to promote accountability, consistency and risk awareness, rather than to specify engineering solutions.
Looking at Oversight in this way promotes a more cooperative understanding of the role that oversight plays. Oversight is there to ensure that the systems in place to undertake operational tasks are functioning appropriately, not to replace individual judgement and accountablity.
Adaptation and Evolution CIP-01-10: Version control As the technology bases of the systems, the architecture of the systems and the threat scenarios change over time, the CIP approach will evolve accordingly. Evolution is not considered a weakness.
Understanding this dynamic will help prepare any organization or individual to changes still to come. Awareness of change helps to build resilience and stability.
Shared Responsibility and System Outcomes Improving the cybersecurity reliability of the BES is a shared responsibility among all stakeholders and organizations. The actions and activities of any single entity can potentially impact the overall reliability of the systems they interact with, given the interconnected and distributed nature of the BES.
The CIP framework ensures that adults share the care of children through a set of shared expectations and coordinated monitoring.
Recognizing shared responsibility reinforces the importance of collaboration and communication.
The NERC Critical Infrastructure Protection (CIP) standards for Cybersecurity incorporate some of the reliability oversight requirements into a single regulation to address the risks of dependence on digital control systems. Governance, engineering judgment and organizational changes are important to reliability.
CIPReliability, Executive, Engineer This category is for executives and engineers who have a basic understanding of CIP as a reliability framework and wish to develop skills in exercising direct oversight and participation in the ReliabilityFirst region grid.
Glossary
Glossary
Introduction
Introduction
This glossary includes selected terms that are relevant to the NERC Critical Infrastructure Protection (CIP) voluntary program and are defined in the NERC Glossary of Terms Used in NERC Reliability Standards unless otherwise indicated.
Definitions are included here for informational purposes only and are valid only as of the date hereafter set forth in the Update and Revision Notice, which may be revised periodically. They may be modified by the Commission and/or Regional Transmission Organizations (RTOs) at any time, and are binding only as provided in the rules and regulations of the Commission and/or applicable RTO(s). Users should consult the current NERC Glossary and applicable Commission and/or RTO rules and regulations for the most up to-date definitions.
Defined Terms (Sample – Expand as Needed) Bulk Electric System (BES)- As defined in the NERC Glossary of Terms Used in NERC Reliability Standards.
Cyber Asset- Programmable electronic devices, including the hardware, software, and data in those devices.
Critical Cyber Asset- A Cyber Asset essential to the reliable operation of Critical Assets.
Critical Infrastructure Protection (CIP)- A suite of NERC Reliability Standards designed to protect the confidentiality, integrity, and availability of cyber assets that support reliable operation of the Bulk Electric System.
Electronic Security Perimeter (ESP)- The logical border surrounding a network to which BES Cyber Systems are connected and for which access is controlled.
BES Cyber System- One or more Cyber Assets logically grouped by a responsible entity to perform one or more reliability tasks for a functional entity.
Impact Rating- The categorization of a BES Cyber System based on the potential reliability impact associated with its loss, compromise, or misuse.
About the Author
About the Author
Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.
Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.
Rob’s compliance authority extends across both reliability and cybersecurity domains. His work on Critical Infrastructure Protection includes audit and oversight of CIP-002 through CIP-014, scope and impact classification reviews, ESP and PSP boundary analysis, and program assessments for entities with Low, Medium, and High Impact Cyber Systems.
Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.
About Energy Compliance, Inc.
About Energy Compliance, Inc.
Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.
Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.
We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.
Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.
CIP-Focused Services
Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.
Energy Compliance services related to Critical Infrastructure Protection include, but are not limited to:
- CIP applicability and scope analysis (CIP-002 through CIP-014)
- Cyber asset and BES Cyber System identification and impact classification
- Electronic Security Perimeter and Physical Security Perimeter boundary analysis
- CIP governance and program assessments
- Integration of cybersecurity oversight with broader reliability programs
- Audit and enforcement support for CIP findings (non-advocacy)
- CIP framework reviews, gap analyses, and improvement plans
- Training focused on CIP framework, requirements, and audit expectations
- Executive and board-level CIP awareness briefings
Services are tailored to the functional role, system impact, and regulatory posture of each organization.
ENERGY COMPLIANCE PROFESSIONAL REFERENCE
Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.
N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.
I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.
CONNECT WITH US Scan to visit
E N E RGY COMPL IAN CE , IN C. · EC-WP-200 · © 2026 · AL L RIGHTS RES E RV E D