ENERGY COMPLIANCE, INC. Rigorous Compliance. Defensible Programs. HomeWhitepapers › EC-WP-201

Cybersecurity / CIP · EC-WP-201

CIP Low & Medium Impact

Low Impact and Medium Impact CIP scope covers most of the registered entities subject to NERC cybersecurity requirements. High Impact is reserved for the largest control centers and substations.

Low Impact and Medium Impact CIP scope covers most of the registered entities subject to NERC cybersecurity requirements. High Impact is reserved for the largest control centers and substations. Most of the operational reality of CIP compliance, and most of the audit findings, live in the Low and Medium Impact tiers. Treating either as a lesser obligation is one of the most common errors in CIP compliance practice. "Low Impact" doesn't mean low importance. It doesn't mean unregulated. It doesn't mean unaudited. Misclassification is the most common Self-Reported violation under CIP-002. The cost rarely shows at registration. It shows at the next audit. Medium Impact requirements run deeper than Low because the consequence of compromise is higher. Same standard. Different control architecture. ESP and PSP boundaries get drawn once and rarely re-checked. Audit findings cluster around the gap between the drawn boundary and the actual one. A Low Impact program scaled up doesn't become a Medium Impact program. Different obligations, different evidence expectations. Governance scales with consequence. Light governance on Medium Impact is a finding waiting for a trigger.

Contents

  1. Foreword
  2. Why Low and Medium Impact Matter in the CIP Framework
  3. Defining Low Impact and Medium Impact Systems
  4. Low Impact CIP: Reliability Context and Oversight Intent
  5. Medium Impact CIP: Reliability Significance and Oversight Focus
  6. Comparing Low and Medium Impact Requirements
  7. Governance and Accountability Across Low and Medium Impact Systems
  8. Personnel and Access Considerations for Low and Medium Impact Systems
  9. System Security Concepts for Low and Medium Impact Systems
  10. Monitoring, Detection, Response, and Recovery Across Impact Levels
  11. Compliance Monitoring and Enforcement for Low and Medium Impact CIP
  12. Common Misunderstandings About Low and Medium Impact CIP
  13. Executive and Engineering Takeaways
  14. Glossary of Low & Medium Impact CIP Terms Introduction
  15. About the Author
  16. About Energy Compliance, Inc.

Read offline

The complete reference is on this page. The PDF is for circulation inside your organization.

Download the PDF

Foreword

Foreword

This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.

I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.

The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.

That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.

These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.

These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.

Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.

If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?

Rob Smith, Founder, Energy Compliance, Inc.

EC-WP-201 CIP 101: Low and Medium Impact

Chapter 1

Why Low and Medium Impact Matter in the CIP Framework

Low Impact and Medium Impact Why these two categories exist and Why they matter to Bulk Electric System Reliability This book describes the CIP standards that are designed to shape the behavior of the parties responsible for Bulk Electric Systems in ways that will help ensure the reliability of those systems. It is essential to understand how the categorization of Low Impact and Medium Impact within the risk management framework of NERC defines the scope of applicable requirements and their importance to reliability. The purpose of this chapter is to describe the motivations for the creation of these two categories and their relevance to BES reliability. It provides background on the reasons for differentiation among levels of impact and how the CIP Rules balance risk, consequence and oversight.

Impact Classification as a Reliability Concept Impact classification refers to the principle that not all cyber assets are created equal and pose different risks to bulk power system reliability. This principle takes into account the varying potential consequences of a cyber compromise that may result from a system failure or attack on a power system based on system role, operational dependency and degree of interconnection.

Low and Medium Impact refer to a structured assessment of the potential impact to reliability in the unlikely event that a cyber system is breached, abused or unavailable. They are not related to the level of importance or the quality of a component.

This approach supports proportional oversight and aligns cybersecurity expectations with reliability risk.

The Prevalence of Low and Medium Impact Systems The majority of entities within the bulk electric system have Low Impact or Medium Impact cyber systems. Many low impact systems are used to support reliability functions, but they do not present the same systemic risk as High Impact systems.

While not typically considered “vital” systems, Low or Medium Impact systems are still necessary for reliable, day-to-day grid operation at the local and regional level. A cyber attack on one of these systems can impact the operations of the grid, potentially resulting in decreased visibility into grid conditions and even localized power outages.

First you have to understand the role of carbon stores before you can understand why they are included in the CIP framework.

Avoiding Misinterpretation of “Low” and “Medium”

One of the most common misconceptions in environmental science is that low or medium impact means that the compound is not important or that it does not affect the environment. It only means that the impact is relatively lower compared to highly toxic compounds.

Low Impact systems generally affect availability in a more localized or contained manner, whereas Medium Impact systems affect operational coordination over a larger area and are below the thresholds for system-wide consequences.

The classification system does not have a category for “non-critical” systems, reinforcing the principle that all classified systems require appropriate attention.

Reliability Risk Versus Cyber Threat Likelihood Impact classifications identify the potential consequence to reliability of a compromise, rather than the likelihood. An equal likelihood of compromise could exist for both High and Low impact systems, yet the consequences to the reliability of the power system for a breach would be different.

This is the first key element in the CIP standards describing the CIP Cybersecurity and Infrastructure Security Act Risk Management Framework – Category 1 (CIP-CAT 1) definition of an original term and definition within CIP Risk Management Framework. Categories do not measure the likelihood of a cyber attack. Instead, Categories measure the potential impact to critical infrastructure should a cyber-attack occur.

Our approach focuses risk management on proven critical consequences, rather than on hypothetical threats. This leads to a focus on compliance to Cybersecurity standards and regulations, which in turn aligns the risk management of cyber threats with power grid reliability objectives.

Regulatory Intent Behind Impact Differentiation This change is related to the recent addition of Low and Medium Impact categories to identify scenarios where regulatory protections may be adjusted in consideration of a little risk. The regulations are not suggesting identical cybersecurity controls be applied to all systems without regard to consequences. Doing so would impose significant regulatory costs and burdens on low risk systems with little or no corresponding safety benefit.

The Impact Differentiation feature in Framework 2.0 allows resource and management focus to be directly proportional to impact, while still achieving reliable results across diverse use cases, system configurations and implementations.

Balancing competing interests is central to the CIP’s credibility and sustainability.

Oversight and Consistency Considerations Classification of impact is an overview perspective tool that determines eligibility and scope of protection based on the potential impact of various activities on a World Heritage site. It is a methodology for uniform interpretation of protection zones and for flexiblity in applying protections.

Consistency does not require uniformity. It requires alignment with reliability risk. Impact classification provides the reference point for that alignment.

Understanding Low and Medium Impact is important for Executive to ensure that risk related to cybersecurity reliability risk is neither over nor under-stated. It enables strong governance and appropriate allocation of resources.

For engineers and operators, impact classification provides insight to how a system is viewed in a reliability context. It reinforces the link between system function and reliability consequence, irrespective of system complexity.

The Low and Medium Impact classifications were introduced to fit certain cyber security expectations to the corresponding reliability consequences and it is more about risk management being proportionate than it being less important. Understanding why they were put into place is key to understanding how Low and Medium Impact CIP requirements are structured and enforced.

This foundation will enable you to analyze the way Low Impact systems are characterized and dealt with in a CIP approach, a topic that will be developed in the next chapter.

FROM THE FIELD

Low Impact does not mean low importance. It means a different proportionality of controls. Treating Low as unregulated is the most common entry point to a finding.

Misclassification under CIP-002 is the single most common Self-Reported violation. The cost of getting it wrong rarely shows up at registration. It shows up at the next audit, after the program was built around the wrong scope.

The CIP framework rates impact by reliability consequence, not by asset size. Two facilities of similar nameplate can carry different impact ratings, and the rating drives every requirement that follows.

Chapter 2

Defining Low Impact and Medium Impact Systems

This chapter covers Low Impact and Medium Impact systems as defined in the NERC Critical Infrastructure Protection (CIP) policy and sets the stage for discussing reliability consequence and the general importance of clear definitions to effective CIO supervision and understanding.

Impact Classification Within the CIP Framework This building block was introduced in the CIP Cybersecurity Risk Management Process Version 5.0 document and discussed further in Version 5.1. Impact classification is a method for distinguishing among varying levels of expected reliability effects resulting from a compromise to a cyber system.

The Low Impact and Medium Impact designations are based on criteria established in the CIP standards. These criteria are generally based on considerations of system role, functional responsibility, and the relative impact on the bulk electric system reliability.

Classification is not a matter of interpretation It is based on defined criteria and threshold values, and on functionality in order to ensure that as much uniformity as possible is achieved within the industry.

Low Impact Systems: Conceptual Definition Systems and/or components which, in the event of a compromise, could affect the functionality of some of the components or processes involved in local reliability restoration, but whose impact is not expected to affect, either directly or through cascading effects, the overall reliability of the power system. These are systems associated with individual components or with limited operational activities.

The impact of a Low Impact failure is generally confined to a limited area. Although not significant to plant or local operations, they are necessary to the successful operation of the plant or facility. Failures at this level could at a minimum present operational difficulties, reduce visibility or necessitate the use of manned intervention.

The Low Impact classification reflects relative consequence, not insignificance.

Medium Impact Systems: Conceptual Definition At Medium Impact, the systems provide support functions that, when compromised, may affect some operational coordination and regional reliability

functions, but not to the extent that they have a system-wide impact. These functions may be located at control centers, utilized in coordination activities, or applied to a broader regional-wide view of system conditions.

A disruption to any of these system components would not necessarily cause widespread power outages but could potentially impact operators’ ability to manage normal system conditions. The IEEE has designated such system components as having a “Medium Impact” upon the power delivery system.

These systems are sometimes called ‘Medium Impact’ due to their position within the CIP regulatory system, where there is some balance of risk and level of oversight or consequence.

Functional Role as the Primary Driver All systems sharing a common functional role are classified as having an equivalent level of impact. In this model the key factor is the functional role of the system; the technology used to support the system, the organizational unit that has responsibility for the system, and other factors are not used as criteria. This categorization is primarily based on the function of the system elements and the potential effects of their failure on reliability.

This approach is based on the function of the elements of a system and is used for consistent classification of equivalent elements in different systems, at different levels of decomposition and in different organizations. Items that perform the same reliability function should be treated in the same manner, regardless of other differences.

Functional alignment reinforces fairness and predictability in oversight.

Relationship to Registered Functions The Impact classification is relevant to the set of registered functions which include, but are not limited to, Transmission Operator, Balancing Authority, Generator Operator. These registered functions generally dictate how controls in the cyber system that supports the respective function will be evaluated.

This relationship is intended to support the relationship of CIP standards with reliability. Cybersecurity expectations should relate to functional responsibility rather than to business type or to the value of assets.

A related knowledge and understanding of this concept is essential in order to understand why systems may be classified in different ways, given the particular operating context.

Avoiding Misclassification Through Overgeneralization One of the common mistakes people make when talking about impact classification is that they consider it to be a general assessment. That is, they assume that the impact classification they assign to one particular function of a system is the same for all other functions of that system. And they assume that the impact classification of one system in a facility or organization is the same for all the other systems in that facility or organization.

The CIP methodology is based on the assumption that classification is carried out in a precise manner and that it relates to specific reliability functions rather than being an overall classification.

Recognizing this precision supports accurate interpretation without prescribing evaluation methods.

Regulatory Intent and Consistency Regulatory requirements increasingly call for uniform application of impact definitions to all entities and locations. Criteria should be specified in detail to provide clarity and prevent ambiguity.

Consistency in more than just a matter of having the same system design or architecture. It is about having the same characteristics in order to satisfy the intent and requirements of the standards.

This emphasis supports confidence in the reliability oversight process.

This page is for Executives Only Definition of Low and Medium Impact systems Understanding what constitutes Low and Medium Impact systems is important for executives so that they have a general appreciation of what is involved in the discharge of some of their cybersecurity governance responsibilities particularly with respect to the consequence of the systems they oversee.

These notes are for the benefit of engineers and operators: knowing the definitions will help them understand how they view reliability of the systems. Also it ties the functional system to the classification regulations.

Low Impact and Medium Impact systems are classified based on their function and potential impact on reliability. These classifications form the basis for exercising reasonable cybersecurity control over Low Impact and other systems and for uniform application of the CIP reliability standard. The classification of Low Impact systems under CIP and the associated requirements are further discussed in the next chapter.

FROM THE FIELD

The definitions in CIP-002 are not abstract. They are the line that determines which controls apply. Reading them once is not enough.

The Cyber Asset versus Cyber System distinction matters. Asset is the thing. System is the function the asset performs. Audit findings most often hinge on which one was scoped.

A Cyber System is what the standard regulates. The asset inventory is what proves the scope. The two have to reconcile, in writing, before audit.

Chapter 3

Low Impact CIP: Reliability Context and Oversight Intent

Low Impact Reliability & Compliance This chapter provides insight on how Low Impact systems are treated within the NERC Critical Infrastructure Protection (CIP) Reliability Standards from a reliability and compliance perspective. A full understanding of the Low Impact Reliability & Compliance requirements in the CIP Version 5 Rule changes, and their direct relation to Grid Reliability and Compliance principles, is central to this chapter. The need for Low Impact requirements and how they support grid reliability efforts are also fully explored, as well as the role these requirements play in compliance with the principles of Proportional Cybersecurity Controls.

The Role of Low Impact Systems in Reliability Low Impact refers to systems that are utilized to support localized or facility-specific reliability functions. These systems may be used to control, monitor, or protect aspects of the power system within an individual facility or a defined operational zone, and are considered safe and reliable within these boundaries.

The potential system-wide impact of a compromise on high-impact systems is limited; compromises to low-impact systems can potentially affect the performance of high-impact systems in some circumstances. This could result in detectable impacts on operations, situational awareness, or the ability to respond. Although these effects are not considered significant for high-impact systems from a reliability perspective, FERC, WAPA, and industry stakeholders agree that they are not negligible and warrant protection.

Low Impact included in CIP means we agree that reliability at the local level counts.

Proportionality and Risk Awareness Note: CIP treats Low Impact systems in a different way to Medium and High Impact systems (see paragraph 8.2(3)). It is inefficient to have numerous requirements that are not more than trivial to fulfill for Low Impact systems, since this would not be proportional to the low potential consequences of a failure or breach in such systems. Conversely, having few requirements could provide insufficient protection for medium and high impact systems.

Proportional is the most efficient way to manage risks. It takes into account the basic cybersecurity risks, without requiring overly constraining controls in relation to the criticality of the availability impact.

Proportionality reinforces the credibility and sustainability of the CIP framework.

Baseline Expectations for Cybersecurity Reliability Low Impact means those requirements that are intended to reduce common sources of cybersecurity risk to reliability-critical systems to a baseline level of awareness, intent, and basic controls beyond the exclusivity of specific technical countermeasures.

Reliability perspective: Baseline assumptions about cyber elements have to be made to ensure that systems that support operational elements are not left unmanaged or undiscovered. This also recognizes that even those with little impact are still worthy of consideration.

The emphasis is on awareness and accountability rather than complexity.

Avoiding Overextension of Low Impact Scope One of the common issues with Low Impact systems is over-scoping the system. Treating Low Impact requirements as enterprise-wide cybersecurity controls does not add value, complexity without benefit to system reliability.

It is important to remember that one of the restrictions of the CIP framework is that Low Impact excludes reliability functions supported by systems. Keeping this in mind helps to avoid a mismatch between the work being done for cybersecurity and the actual value it provides to the grid.

Maintaining appropriate scope supports clarity and efficiency.

Reliability Oversight Perspective Low Impact Requirements provide assurance that the entity has considered and addressed the cybersecurity risks of Low Impact activities, which are defined as the local reliability functions that are enabled by Low Impact technologies deployed within the grid. Oversight is focused on whether all parties understand and apply the baseline expectations.

This is not really a test of advanced level of cybersecurity maturity. We are looking to confirm that there is an understanding for basic reliability-related cyber risks, and that they are properly managed.

This approach supports consistency without imposing undue burden.

Relationship to Operational Practice Low Impact refers to those system impacts which frequently occur within the normal operating envelope and may be directly associated with routine operations. Such impacts could be related to: - actuation of logic switches to command any aspect of process machine control; - monitoring or sensing devices which measure the status or condition of a variable; - circuits used for protective relaying purposes and relied upon by the operating personnel.

Reliability of large infrastructure systems relies heavily on expected standards of cybersecurity behavior to ensure that operational practices remain disciplined. Awareness of cyber risks, as well as the expected consequences of actions and inactions, are critical to providing high levels of operational reliability and preventing unforeseen blackouts.

This relationship underscores the operational relevance of Low Impact requirements.

Low Impact CIP provides visibility into the amount of Cybersecurity Reliability Risk (CSR) associated with Low Impact Moderate Risk (LIMR) sites in a way that does not overstate the potential impact of a cyber attack on critical infrastructure. Additionally, Low Impact CIP enables executives to make more informed and effective governance decisions by making clear where traditional baseline cybersecurity controls are in place.

Low Impact Affords Reminder of Consequence-Driven Cybersecurity for Operations Engineers and Operators Understanding Low Impact treatment affords engineers and operators a reminder that the expectations of cybersecurity activities scale with the consequence of a breach. Such an understanding brings the requirements for protecting critical infrastructure into clearer perspective and informs the operational context in which the requirements must be met.

Low Impact systems are an important part of the overall reliability of a system at the local level, and are considered within the CIP rules to be governed by proportional, baseline cybersecurity standards in a manner that provides reasonable awareness, accountability and basic security measures without overburdening the operations of such systems.

Understanding High Consequence and Medium Impact as defined by the NRC serves as a foundation for exploring how Medium Impact systems are treated under the CIP regime, a topic examined in further detail in the next chapter.

FROM THE FIELD

Low Impact controls exist because Low Impact systems still touch reliability. The proportionality of the controls reflects consequence, not absence.

A Low Impact program built around the minimum is a program that hasn't read CIP-003 closely. The minimum changes faster than entities track.

The Region audits Low Impact differently than Medium. The evidence expectations are lighter, but the program rigor expectations are not.

Chapter 4

Medium Impact CIP: Reliability Significance and Oversight Focus

Medium Impact Systems Within the NERC CIP Reliability Framework - This chapter explores the CIP Reliability Framework treatment of Medium Impact systems from both a reliability and oversight perspective. This chapter examines in depth why Medium Impact requirements are more detailed than Low Impact and how the requirements for medium impact align with the reliability consequence of the systems to which they are applied, and the distinguishing characteristics of medium impact systems as compared with low impact systems and critical cyber systems subject to more rigorous proportional cybersecurity requirements.

The Reliability Role of Medium Impact Systems Reliability services supported by a Medium Impact system may not cause undue concern in the event of a disruption, but they can impact coordination between systems, visibility into certain types of system activity, and control over portions of the transmission grid. These types of systems may provide functional elements within control centers, aggregated displays or real-time monitoring systems, and other coordination activities that encompass more than a single physical location.

While Medium Impact Cyber attacks may not likely cause cascading outages, they will greatly impede controls to manage system operations, respond to abnormalities and may hinder the restoration process. Of high reliability concern.

The Medium Impact classification reflects the increased operational significance of these systems.

Differentiating Medium Impact From Low Impact The Low Impact / Medium Impact distinction is based on consequences rather than technology. A Medium Impact system will have a larger operational footprint, or will be part of a support function with greater coordination implications.

Low Impact systems tend to impact the reliability of a small area, while medium impact systems can potentially affect several facilities, operating areas or even operational decisions. As a result, there is a greater reliability consequence of a cyber compromise.

Understanding this distinction reinforces the rationale for differentiated oversight.

Proportional Increase in Cybersecurity Expectations As things progress we’ll be looking to introduce new security controls in the form of Medium Impact controls, which are a set of controls that are more substantial in terms of requirements than Low Impact. This is not an escalation in itself, but rather to be in line with more substantial systems.

All Reliability Consequence Criteria in the Proposed Standard retain language that notes that a more reliable system with potentially higher reliability consequence would need to have controls in place, monitoring in place and be accountable in the event that cyber events impact normal operating procedures to minimize impacts to coordinated real time operating functions of the grid.

Proportional escalation supports risk-informed reliability management.

Operational Dependence and Coordination The primary function of a Medium Impact system is to support real-time operational activities. Operators, engineers, and reliability personnel will typically interact with a Medium Impact system to understand the status of the system, perform control actions, and monitor trends and behaviors.

Cyber threats to these systems have the potential to introduce uncertainty, cause delays in response, or disrupt coordination during off-normal conditions. These effects create new sources of reliability risk, even if no physical component failures occur.

The reason that the Medium Impact systems are given more focus in the CIP is because they are operationally dependent.

Oversight and Consistency Considerations A ‘Medium Impact’ classification was introduced in order to help determine whether cybersecurity countermeasures respond to potential effects that may undermine the reliability of electrical systems. In the context of oversight, this classification is not a means of requiring specific countermeasures, but rather a benchmark to which EESB operators and grid reliability stakeholders must refer when ensuring consistency of implementation of cybersecurity measures that may impact the reliability of their networks.

Consistency implies that entities performing similar functions will be held to the same standards. Achieving consistent expectations can promote fairness and certainty in one place or across an entire organization.

Oversight emphasizes alignment with reliability objectives rather than uniformity of implementation.

Relationship to Control Centers and Aggregated Functions Many Medium Impact systems have some level of control center or aggregated operational functions. They may be centralized locations or teams for operational control to enhance effectiveness and increase productivity. In addition, the centralization of many Medium Impact systems provides a bird’s eye view in the event of a disruption, which can increase potential consequences.

As outlined in the CIP Reliability Risk and Medium Impact (RRMI) Rule change proposal, the Centralized Information Platform (CIP) Reliability framework considers that the reliability impact is increased in the case of centralization, and with the Medium Impact classification, ensures that appropriate monitoring is in place without increasing the thresholds for system-wide consequences.

This relationship is important to consider when understanding the connection between environments and Medium Impact systems.

Within Medium Impact CIP, the Executive Review highlights those items that have a cybersecurity reliability risk that transcends the individual site. This document serves a governance purpose, noting those systems that require more than local attention.

For engineers and operators it is important to have a basic understanding of Medium Impact treatment in order to understand why some systems and sub-systems have a number of specific requirements. This knowledge will help to enhance the understanding of the relationships between the coordination of operations and the reliability of cyber security.

The objective of the Medium Impact category is to provide some level of support for reliability activities where the consequences of failure are greater than those of Low Impact systems. In CIP, these systems are addressed through the imposition of increased cybersecurity controls consistent with the increased potential for consequences associated with any loss of reliability. Understanding the treatment of Medium Impact systems will help in describing the structural differences between Low and Medium Impact requirements, a topic taken up in more detail in the next chapter.

FROM THE FIELD

Medium Impact is where most CIP audit findings live. Not because Medium is harder to comply with, but because Medium covers most of the registered population.

The Medium Impact stack is a cumulative obligation. CIP-005, 006, 007 layer on top of 003. A program that built 003 well still has to build out the rest, and gaps between layers are common audit targets.

Medium Impact controls were designed for a particular operating profile. If your facility's operations have changed since the impact classification was set, your controls may no longer match your actual risk.

Chapter 5

Comparing Low and Medium Impact Requirements

This chapter will describe the differences in Cybersecurity Expectations between Low Impact and Medium Impact systems as defined by NERC CIP. It will describe at a high level the reasoning behind these differences and focus on the concepts rather than the details of the regulation or the actions necessary to comply with the regulation.

Proportional Structure Within the CIP Framework The CIP framework uses a Proportional Response approach to applying cybersecurity expectations based on reliability consequence. Low and Medium Impact are two of the four levels in this approach.

This delineation of domains is not arbitrary. It is the result of a careful calibration of the intensity of scrutiny to the impact that the system could have in the event of a failure. Such calibration is an efficient way of dealing with risks while avoiding overregulation of systems that are not critical.

Analyzing the damage contours may provide some insight into why expectations at the different impact levels do not quite match up.

Scope and Depth of Expectations Systems identified as Low Impact are subject to a minimum set of expectations intended to raise awareness and require consideration of risk. These considerations include risk awareness and fundamental cybersecurity controls.

Medium Impact (MI) systems have more specifics around what is expected of them based on their higher reliability value to power. This section goes into greater detail on the governance, access, security and monitoring of the systems and technologies involved.

Their basic aim is identical. The difference is one of scope and rigor rather than of fundamental intent.

Reliability Consequence as the Differentiator The Low and Medium Impact Expectations are differentiated by reliability consequence. Medium Impact expectations cover systems that support operational functions where loss of coordination between systems or loss of regional situational awareness could impact reliability.

As consequence increases the framework requires additional controls to mitigate those increased consequences. This is a proportional response to the potential consequences from a cyber breach.

The framework does not take into account the assumption that there is a greater likelihood of threat against Medium Impact systems. The framework takes into account the assumption that the consequences in the event of a successful attack will be greater against these systems.

Consistency Without Uniformity The CIP framework is intended to ensure that expectations are consistently applied, but not that systems are implemented uniformly or operate in the same manner. The Low and Medium Impact requirements of this Volume are intended to demonstrate this principle.

Human activity is designed for particular functions and its reliability for these functions can vary. What is relevant in determining applicable expectations is whether the activities are: – performing a similar function; – of a similar level of reliability for that function. The framework enables some latitude as to how and to what degree these expectations are fulfilled.

This balance supports fairness while respecting operational diversity.

Avoiding Over- or Under-Application It’s common to misunderstand what does and does not fall under the categories of Low and Medium Impact expectations in terms of cybersecurity. Over-explaining or over-explaining the types of threats that fall into these expectations can lead to either over-applying controls or under-applying controls. Over-applying controls increases the complexity of a system while under-applying controls means that reliability risk is still present.

Key Concepts The framework’s tiered structure provides a guide for appropriate alignment, but does not require the same treatment of all systems.

Recognizing this intent supports more accurate interpretation of expectations.

Oversight Perspective An area for potential confusion between Low and Medium Impact activities is who focuses on what when differentiating between the two. The answer to this question is actually around what is being evaluated by the oversight body rather than controls on the activities being the same.

This perspective reinforces proportionality and supports efficient oversight of reliability risk.

This page is specifically for Executives. Low vs. Medium Impact expectations clarify the governance and resource planning responsibilities of an Executive role and helps to put cybersecurity spending into the context of reliability consequence.

It is important for engineers and operators to understand the differences between these types of systems, and what this means in terms of extra scrutiny and procedures. It helps tie the concept of system role to system reliability for the overall goal of cybersecurity.

As currently defined, Low and Medium Impact systems are differentiated in the CIP Rules by different cybersecurity expectations. In this context, any structural or proportional differentiation that supports consistency in reliability of service is appropriate and does not require uniformity in Cybersecurity standards for different reliability consequence levels.

This section will set the stage for considering the differences that arise in Low and Medium Impact systems, which will be examined further in the next chapter.

FROM THE FIELD

The two requirement sets aren't a difference of degree. They're a difference of kind. The control architectures reflect different risk models.

A Low Impact program scaled up doesn't become a Medium Impact program. Different obligations, different evidence expectations, different audit posture.

The most effective programs treat Low and Medium as a single risk-based architecture with proportional controls. The least effective treat them as two separate compliance projects.

Chapter 6

Governance and Accountability Across Low and Medium Impact Systems

This chapter will discuss governance and accountability considerations for Low Impact and Medium Impact systems defined under the NERC Critical Infrastructure Protection (CIP) regulations and how the responsibility of an organization for a particular asset increases as the reliability consequence increases and the importance of having appropriate governance in place in order to ensure adequate Cybersecurity Reliability Oversight (CSRO).

Governance as a Reliability Enabler Within Control Systems the Center for Internet Security (CIS) Controls framework identifies governance as a method to make risk to cyber dependability reliability manageable vs. a compliance activity. In this context governance describes the processes that define roles and responsibilities, how decisions are made, and how reliability risk related to cybersecurity is managed.

For Low and Medium Impact systems, the governance of cybersecurity risk is intended to be a deliberate process rather than a reactive or uncontrolled process. The main distinction between these two categories lies in the level of rigor required to provide the appropriate level of reliability controls and associated visibility to match the level of system consequences.

Governance connects cybersecurity expectations to organizational authority and accountability.

Scaling Accountability With Impact As depicted in the CIP matrix, accountability for reliability impact increases with increasing criticality of the system. Local or facility level awareness of who is accountable for a system or asset is usually adequate for Low Impact assets. For Medium Impact systems, which may be part of large geographically dispersed systems or networks, coordinating and ensuring accountability at a higher level of the organization may be necessary.

This does not mean that Low Impact systems are “ungoverned” because the scalability factor takes into account the potential severity of failure consequences in different systems, and thus calls for corresponding level of formality in the governance framework.

Aligning accountability with impact supports proportional and effective oversight.

Organizational Awareness and Role Clarity In order to effectively govern their systems, it is first necessary to have a solid understanding of how their cyber systems support reliability functions. Awareness helps define individual responsibilities, tasks, and governance authority for reliability-critical cyber assets.

Definition for Low Impact Awareness For Low Impact systems the definition for awareness may be limited to teams carrying out the routine operations or engineering activities on the system. Definition for Medium Impact Awareness Definition for Medium Impact Awareness may need to be broader covering for example Operations, Engineering, IT and Management teams.

Role clarity reduces ambiguity and supports consistent decision-making.

Decision-Making and Reliability Risk Most control systems fall under the auspices of existing operational control, which includes existing IT governance arrangements and control processes. The approach to managing cybersecurity reliability is determined by the governance structures that are in place. Typical decisions are influenced by a host of factors that relate to the potential impact on operational reliability that could result from a change to the system architecture, access methods, connection mechanisms or procedures for making changes.

For Medium Impact systems the governance mechanisms described above are for coordinating and reviewing activities because the system impact is significant. For Low Impact systems the individual components may make relatively localized decisions but they are still required to consider the overall reliability objective.

The framework emphasizes informed decision-making rather than prescriptive approval processes.

Continuity and Organizational Change Organizations grow, change and evolve because of new staff, reorganization or technological advancements. Governance helps to ensure the continuity of these organizational decisions by clearly defining roles and responsibilities.

Continuity for Low and Medium Impact systems ensures that the Cybersecurity Reliability of these systems is not compromised by changes in people or organization.

This continuity is essential to sustaining reliability in a dynamic operating environment.

Oversight Perspective Cybersecurity Governance and Accountability provides insight into how an organization manages its cybersecurity risk related to potential reliability impacts. NERC Oversight Bodies will determine the level of alignment between responsibility and system impact.

Oversight does not inform the design of the teams that manage risk. Rather, it is a perspective on the governance of that risk, to confirm that the governance controls are used in a manner that supports the holistic and deliberate management of that risk.

This approach reinforces accountability while preserving flexibility.

For executives who are interested in finding out more about governance of Low and Medium Impact systems and what their decisions mean to the overall security reliability of their information assets, this paper provides a clear and understandable direction and accountability within organisations. Governance for executives, Low and Medium Impact systems provides clear direction to executives enabling informed decision-making on the management and oversight of cybersecurity risks.

For engineers and operators, governance provides context to their technical tasks. It defines their scope of authority, facilitates communication and coordination, and ensures that all technical actions are aligned with reliability targets.

Governance and accountability for CIP systems increase as the potential reliability impact to the Bulk Electric System (BES) increases. For Low and Medium Impact systems, the responsibility for control of critical assets should be commensurate with the importance of those assets. Good governance practices are fundamental to ensuring awareness, business continuity, and sound business decisions in support of treating cybersecurity as a reliability discipline.

This knowledge of general systems will carry over to the Personnel and Access considerations for Low and Medium Impact systems discussed in the next chapter.

FROM THE FIELD

Governance escalates with consequence. Low Impact governance can be lighter; Medium Impact cannot. The accountability hooks are different and the documentation has to reflect that.

The CIP framework expects an executive accountable for cybersecurity. That role is named, assigned, and audited. Whoever holds it should know they hold it.

A governance program that hasn't been exercised is a governance program that doesn't exist for audit purposes. Tabletop and live exercises produce evidence that policies alone don't.

Chapter 7

Personnel and Access Considerations for Low and Medium Impact Systems

This chapter examines how personnel and access issues relate to Low Impact and Medium Impact systems in the NERC CIP Reliability Standard. It discusses the reasons reliability risks are associated with humans and how these risks vary with the impact of the system and how the CIP standard deals with the access issue in a conceptual rather than procedural manner.

Human Interaction as a Reliability Interface Personnel interaction with cyber systems represents one of the most significant interfaces between organizational behavior and system reliability. Individuals may interact with a system in order to operate, maintain, program, or support reliability-critical functions.

Personnel reliability within the context of the CIP deals not with the undesirable aspects of human involvement, but with the effects of the human element on the reliability of the system. Errors, misunderstandings or misuse can introduce a risk independent of whether it is a question of intent, carelessness or other factors.

The Human System Reliability (HSR) interface model viewed human interaction with other human or technical elements as a reliability interface.

Scaling Personnel Risk With Impact The potential reliability consequence of personnel interaction with a system varies with the system impact to the operation. Low Impact systems have a local operational impact, while Medium Impact systems may have an impact on coordination or situational awareness.

As reliability consequence increases, the framework would place greater emphasis on accessibility and visibility of information so as to properly reflect the increased risk management needs rather than necessarily basing actions on assumed human behavior.

Note that the Framework does not assume that higher impact levels are associated with a greater likelihood of attack. Rather it recognises that an attacker may have more to gain from their actions if they access assets with a higher consequence level.

Access as a Point of Control This e-book discusses the issues, consequences and mitigations relative to accessing reliability-critical cyber systems. The entry points for these systems are rich in the sort of human judgment that necessarily interacts with system behavior. Thus access to these systems may be physical, or through logical access mechanisms or from remote locations and each case has different reliability considerations.

In CIP, access is viewed as a logical control point versus a technical control. Determining who has access to what, under what circumstances and with what level of authority provides a level of predictability to the overall system.

This view reinforces access management as a reliability measure rather than an administrative function.

Authorized Interaction and Accountability It is important to be able to clearly define what constitutes authorised versus unauthorised access to a system to ensure reliable oversight. Authorised access can involve many valid activities that are conducted in the normal course of operations and maintenance. Unauthorised access brings in large measure of uncertainty, and potentially a lot of risk.

Low Impact: - Accountability may remain within a small group of personnel or a single facility. - For medium impact damage, the system’s complexity is generally such that a small group or a single location can effectively manage accountability.

Clarity of authorization supports disciplined system interaction across impact levels.

Insider Risk and Unintentional Actions Personnel-related risk is the likelihood that someone will perform an action intentionally or unintentionally that could impact the availability or integrity of the Information Technology resources. In reliability terms, an unintentional action (for example a system misconfiguration or misunderstanding of a procedure) can have the same impact as a malicious action.

As many would agree, life is not always a straightforward proposition. Clearer thinking, role clarity, and greater awareness of the human and organisational dynamics at play can help make complex people issues more manageable. The CIP framework provides a basis for this approach. It is consistent with principles of reliability which are concerned with reducing uncertainty and variability.

Understanding insider risk in this context supports balanced interpretation of personnel considerations.

Continuity Through Personnel Changes Personnel turnover, role changes and organizational restructurings are inevitable events. Reliability demands that access to resources be consistent with current job responsibilities.

Continuity at the Medium Impact level will typically involve cooperation from more than one team or level of management because of the larger area affected. At the Low Impact level, continuity may be more contained but is still an important consideration.

Continuity underpins reliability because continuous interaction among people and systems helps to ensure that that interaction is purposeful and traceable.

Oversight Perspective Staff and access considerations look at human relationships with reliability-critical components from the perspective of oversight and provide insight into how organisations may manage people interacting with these components. Oversight is about visibility and consistency rather than the specifics of access control mechanisms.

This approach preserves organizational flexibility while reinforcing accountability consistent with reliability objectives.

Cybersecurity and workforce management - for Executives, personnel and access issues The reliability risk of cybersecurity threats is also linked to issues that arise in executive, personnel and access management. These include workforce planning decisions, levels of authority, and other organizational design aspects.

For engineers and operators, this material helps emphasize the impact of their personal actions on system-wide performance and helps them understand the need for discipline and strict adherence to role responsibilities in reliability-critical situations.

Personnel and access is a consideration within the CIP reliability risk framework that addresses the reliability risk associated with the interaction of people with cyber systems. This consideration is proportional to the potential impact to the cyber system and is intended to hold accountabilty for reliability risks and to ensure continuity of operations without prescribing specific workforce reliability risk management practices.

This material should be remembered prior to proceeding to the description of the security and technical protection of Low and Medium Impact systems, which are detailed in the next chapter.

FROM THE FIELD

Most cyber incidents on the BES start with credentials, not exploits. Personnel and access controls are the single biggest determinant of a CIP program's actual security posture.

A revoked credential that's still active in the system is the most preventable finding in CIP. It's also one of the most common.

Access is a process, not a state. The CIP standard expects programs that prove access was authorized, used as authorized, and removed when authorization ended. Each step needs evidence.

Chapter 8

System Security Concepts for Low and Medium Impact Systems

This chapter discusses how the concepts of system security and technical protection that were originally defined in the context of Low Impact and Medium Impact systems in the NERC CIP regulation have direct applicability. We explain why technical protections are important from a reliability perspective and how their expected value or importance varies with system impact without attempting to define the specific controls or architectures that should be implemented.

Technical Protection as Reliability Support Per NERC and FERC rules, technical controls within the CIP framework were originally identified to protect the Bulk Power System by preventing potential cyber related disturbances that could impact the ability to collect, process, display, or use SCADA, supervisory control, or automation information for the reliable operation of the BPS.

In Low and Medium Impact systems technical controls are considered a design feature to ensure system reliability, not for cyber security. They are there to ensure system behavior can be relied upon under normal as well as off normal conditions.

This framing reinforces that cybersecurity protections are aligned with reliability outcomes.

Scaling Protection With Reliability Consequence The level of technical protection required for a system is a function of the potential reliability consequence of that system. Low Impact systems require only the minimum level of protection appropriate to their local reliability function. Medium Impact systems call for more formal protection because of their broader impact.

This is a proportional and expectation-based scaling framework, rather than a prescriptive one, where the scale of impacts and consequences is related to the type and magnitude of release, but does not prescribe specific control measures.

Proportionality ensures that protections are meaningful without imposing unnecessary complexity.

System Boundaries and Reliability Focus Within the CIP framework, one of the central concepts relates to the establishment and understanding of system boundaries. System boundaries are used to define which portions of a grid are reliability-critical and thus are not exempt from CIP regulation.

For Low Impact systems, the System Boundary will generally follow the physical perimeter of the single facility or local environment. For Medium Impact systems the System Boundary will usually follow the physical perimeter of a number of aggregated functions, a central control facility, or an integrated operational centre.

Boundaries can be used to contain and isolate events, preventing them from affecting other portions of the system and thus reducing the likelihood of disruption spreading to unintended areas.

Connectivity and Reliability Risk Connectivity between systems offers many operational benefits but also presents significant reliability risks. Where systems are interconnected the number of potential paths for a disruption to occur can be a concern.

The CIP identifies several aspects of the Connectivity concept, noting that it is more about awareness of the connections between systems rather than the design of the connections. The CIP makes the general comment that for Medium Impact systems generally more connections means more consequences, and thus more attention is required.

Understanding connectivity through a reliability lens supports intentional system design and operation.

Change, Configuration, and Stability Changes to systems can impact reliability if not well understood and managed. Unplanned change is therefore a source of risk from a reliability perspective. Changes can arise from a variety of sources including changes to system configuration, changes to software and changes to systems architecture.

Technical protection concepts within the CIP are used to maintain system stability by ensuring predictable behavior across all impact levels. In general, systems with a Medium Impact will require more coordination due to the wider implications of their failure.

Stability is a foundational reliability objective.

Detection and Awareness as Technical Concepts Understanding the state of a system allows users to react more quickly to unusual activity. Low Impact systems may only require knowledge at the device or property level in order to understand normal operation and to know when something is not correct. For the case of Medium Impact systems, there may be an operational coordination aspect.

Reliability and maintenance begin with awareness The Reliability Framework of Amsterdam defines detection and awareness of defects and potential failures conceptually rather than technically, and focuses on awareness as a key factor in achieving reliability. Awareness contributes to reliability because unawareness creates uncertainty, and ignorance makes it impossible to make the right choices.

This concept aligns cybersecurity monitoring with operational situational awareness.

Technical Controls in Organizational Context The implementation and use of technical countermeasures is not possible without considering the governance and human factor aspects, as these systems have to be properly deployed and accepted within the overall organizational context and operations.

The CIP standard emphasizes the relationship between security controls implemented on information technology and the environments in which that technology operates. It cautions that stand alone controls which do not take into account normal use of systems can add complexity to a control system without increasing the overall reliability of the system.

Understanding this context supports balanced interpretation of technical expectations.

Oversight Perspective Security control oversight, Part 3: System security concepts This part of IEC 62433 provides views from which the concepts defined in Clause 3 may be considered. The first view is from an oversight perspective to provide information on how security controls for an identified system security concept can relate to the protection provided to reliability critical systems by measures designed to mitigate one or more specific impact levels that could affect such systems. The second view is from an oversight perspective based on the relation of security control measures to reliability of the systems they protect.

This approach supports flexibility while reinforcing accountability.

System Security Concepts for Executives The purpose of this module is to show executives in information technology how technical decisions impact the exposure of a system to reliability risk, and to cause them to think about the system consequences when making investments in architecture, integration and protection.

Reliability Relating Concepts These concepts are useful for engineers and operators to understand the implications of various system behavior, connectivity and change-related phenomena on system reliability and to help ensure disciplined design and operations for all levels of impact.

System security concepts defined in the CIP Reliability Standard apply at varying levels of significance with respect to reliability consequence based on the reliability impact level of the system. Low and Medium Impact systems will be protected by technical controls that are commensurate with the relatively minor consequences of loss of

reliability. These controls will be part of an overall program of measures that will help to maintain reliability when combined with governance and workforce reliability measures.

This chapter discusses groundwork that must be considered before going into details about the concept of monitoring, detection, response and recovery within Low and Medium Impact systems; concepts that will be detailed further in the next chapter.

FROM THE FIELD

Technical controls are necessary but not sufficient. The CIP framework codifies that lesson into the standard structure.

A firewall rule that's never been audited internally is a firewall rule that may not do what its name suggests. CIP-007 expects ongoing verification, not one-time configuration.

System hardening that wasn't validated against actual operating conditions is documentation, not protection. The auditor knows the difference.

Chapter 9

Monitoring, Detection, Response, and Recovery Across Impact Levels

Monitoring, detection, response, and recovery identify one aspect of building cybersecurity reliability for Low Impact and Medium Impact systems defined in the CIP Reliability Standard. This section explains why these capabilities are important to reliability and how expectations for reliability capabilities change as they are applied to systems of higher impact, without describing particular approaches or tools.

Cyber Events as Reliability Conditions Cyber events are assessed for their potential impact on reliability within the CIP framework, not based on technical criteria. For Low and Medium Impact Bulk Electric Systems, a cyber incident that results in a power outage would not be based on the technical characteristics of the system that was affected, but rather on the size of the area affected. For visibility, control, or coordination at the local level, the impact would be considered low if the area affected is less than 1,000 square miles.

Low Impact refers to cyber events that generally have a localized impact to business operations and do not significantly impact individual facilities. Medium Impact cyber events are those that potentially impact the provider’s situational awareness of operations and the command center’s ability to promptly and effectively respond to changing events, while being critical to maintaining reliable grid operations.

This security control provides visibility into actions taken by authorized personnel that could impact the availability and operational integrity of resources providing critical enterprise services. This control is a critical component of a holistic security governance strategy and serves to affirm that monitoring and mitigation activities are designed to support reliability objectives.

Monitoring as Operational Awareness Monitoring is the operational awareness mechanism for the cyber systems of reliability functions. The operational awareness of the system status and behavior can provide warning of the occurrence of reliability related anomalies.

Low Impact systems typically monitor for local awareness of system operation. Medium Impact systems are typically monitored for coordination and operational decisionmaking between operational areas.

Within this framework, awareness is considered as a control factor for reliability rather than as a purely technical activity aimed at cybersecurity.

Detection and Impact Sensitivity Detection refers to the ability of identifying something that has gone wrong, that is, that there is some deviation from the expected normal behaviour of the system. In CIP terms, the sensitivity of the detection is generally proportional to the magnitude of the impact that the deviation can have on the system.

A Medium Impact attack often requires a lower level of attackers’ technical skills due to the fact that these systems generally have wider exposure to the public. Any delays in identifying the system compromise will result in further loss of operational capabilities and introduce additional uncertainty when it is time to coordinate an effective countermeasure.

For Low Impact systems, detection supports timely local response and containment to prevent wider consequences.

Response as Coordinated Reliability Action These Concepts identify issues to be considered when implementing activities specified within the CIP for the respective work package. Implementation of all Response Concepts within this work package are tightly aligned to identified business critical operational requirements. Any response taken as a result of a cyber event must ensure they assist in achieving overall reliability goals and do not expose other business systems to increased levels of risk.

Low Impact systems may require only a localized response action to correct an incident and resume normal operations. For Medium Impact systems, however, it may be necessary to bring in other teams or departments to resolve the effects of the incident.

The framework highlights integration between cybersecurity response and reliability operations.

Recovery and System Resilience Recovery is the capability to restore systems and applications to the state required for the processing of business functions following a cyber-attack. In relation to reliability, it is one of the factors that constitute the resilience and the continuity of operations.

In the case of a Medium Impact system, when determining appropriate recovery actions consider prioritization and coordination. A number of system elements may be impacted, potentially interacting with other systems, and/or requiring coordination. In the case of a Low Impact system, even though a little recovery work may be required to restore redundancy, consider the operation of the system.

The framework treats recovery as a reliability capability and not only as a technical process.

Learning and Continuous Awareness The purpose of monitoring and response is to enhance learning within the reliability framework. Lessons learned from unusual events or observations are invaluable in improving system design, governance and regulation.

This learning has been created to allow ongoing learning and improvement across Low and Medium Impact areas. Reporting near incidents and insignificant disruptions to availability may help to prevent future availability risk.

Continuous awareness strengthens resilience over time.

Boundaries and Scope As with other CIP concepts, monitoring and response expectations for security incidents are limited by reliability relevance. There is no requirement for enterprises to adhere to incident response best practices unless they relate to reliability-critical cyber assets.

Boundary Purpose: This boundary separates work of maintaining a reliability focus from the broader Cyber Security Governance activity.

Oversight Perspective As far as oversight is concerned, monitoring and response capabilities provide visibility into an organization’s handling of cyber-related reliability risk. Oversight, however, is primarily focused on reliability, and less so on individual technologies and processes.

This approach supports proportional evaluation across impact levels.

For executives, monitoring and response concepts illustrate the readiness and coordination needed to mitigate the consequences of cyber-related reliability risks. Governance decisions can impact an organization’s ability to identify and respond to cyberrelated reliability risks.

All the concepts listed above are critical for engineers and operators to understand and realize the relationship between the cyber system behaviour and operational reliability. Being aware and taking the appropriate counter-measures are important.

The concepts of monitoring, detection, response and recovery are used to achieve Cybersecurity Reliability for Low and Medium Impact (L/M-I) systems to provide visibility, a means for collaboration and thereby increased system reliability. These expectations will vary based on system consequence and will be reflective of a proportional risk reduction approach as outlined in the CIP.

This discussion lays the groundwork for the discussion in Chapter 4 of how compliance monitoring and enforcement relate to Low and Medium Impact sources.

Chapter 10

Compliance Monitoring and Enforcement for Low and Medium Impact CIP

This chapter discusses compliance monitoring and enforcement as it relates to Low Impact and Medium Impact systems in the context of the NERC Critical Infrastructure Protection (CIP) rules. This material is intended to provide an understanding of the purpose, structure, and reliability rationale behind compliance activities, and is not intended to focus on audit preparation, evidence management, or compliance strategy.

Low and Medium Impact Within the Mandatory Framework Low Impact and Medium Impact CIP requirements are mandatory and enforceable Reliability Standards. While the expectations for enforceability differ between Low and Medium Impact and the statutory reliability framework under Section 215 of the FPA is different for each, the CIP requirements for each category are entirely within the statutory framework.

This means that the oversight, monitoring, and enforcement for Low and Medium Impact systems will be accomplished under the same laws and procedures as other Reliability Standards. The impact level will only affect the scope and level of expectations for compliance – not enforcement.

A thorough grasp of the difference between Low Impact and Medium Impact substantive obligations is crucial to appreciating their importance.

Purpose of Oversight for Lower Impact Systems The primary goal of compliance monitoring for Low and Medium Impact systems is to confirm that cybersecurity risks associated with reliability-relevant cyber assets are being managed proportionately and consistently.

Our analysis indicates that most stakeholders do not consider the purpose of an oversight program to be to assess the overall Cybersecurity Maturity of an enterprise or its readiness to respond to sophisticated threats. Rather, it is a mechanism to confirm that established expectations (baseline and structured expectations based on reliability consequences) are recognized and appropriately applied.

Low Impact: Focuses on awareness and management. Medium Impact: Reflects greater coordination and more significant consequences associated with more extensive operational responsibilities.

Risk-Informed Oversight Perspective Compliance monitoring for Low and Medium Impact systems is risk based rather than rule-based, and regulation body focus and intensity on reliability and safety issues will generally take into account possible reliability consequences.

Risk-informed approaches are proportional to the activities and risks involved, enabling more effective and efficient use of evaluation and oversight resources. They also recognize that the intensity of oversight should be greater for higher-impact projects than for lower-impact projects, regardless of the size of the implementing organization or the maturity of its cybersecurity practices.

Risk-informed oversight strengthens credibility and fairness within the framework.

Consistency Across Regions and Entities Other than at low impact, the consistency of CIP compliance monitoring for all other levels of impact is a matter of broader policy. Entities that perform essentially the same function with the same degree of reliability should be held to the same oversight expectations.

Low and Medium Impact The National Electricity Regulation Council (NERC) and the Regional Entities coordinate with each other to ensure consistency of interpretation and implementation of Low and Medium Impact regulations, to minimize the level of uncertainty for Registered Entities.

Consistency reinforces confidence in the oversight process while preserving flexibility.

Enforcement as an Accountability Mechanism Low and Medium Impact CIP enforcement is intended as a compliance and compliance verification tool, not as a punitive measure. It is intended to ensure accountability that address’s OM and ROE risk related to mandatory risk reducing controls specified in the low and medium impact CIP Reliability Standards.

Whether a cyber incident is experienced or not is irrelevant to enforcement activities. Enforcement activities focus on the standards as opposed to the outcomes of system operation.

This distinction reinforces that accountability is tied to compliance with reliability expectations.

Due Process and Procedural Safeguards Monitoring and enforcement of Compliance by Low and Medium Impact systems will occur within procedures that provide adequate protections of process and fairness. All rights of Registered Entities will be preserved in line with the reliability enforcement framework.

These safeguards promote fairness and the legitimacy of regulatory activities. They serve to ensure that administrative actions pursuant to regulatory procedures are conducted in accordance with the formality of the underlying regulatory requirements, rather than with the informality of regulatory enforcement discretion.

Procedural integrity is a foundational element of reliability oversight.

Relationship Between Compliance and Risk Reduction Many control systems are currently being modified to comply with Low and Medium Impact CIP cyber reliability risk standards, as a method to reduce the risk of cyber attacks, but do not eliminate all forms of cyber risk to the grid. The Cyber Reliability Risk Reduction Framework provides a baseline level of protection, and in some cases, a structured method to help reduce the likelihood and impact of cyber threats on the reliability of our grid.

Audits are about accountability and awareness rather than validating the effectiveness of the measures you have implemented for managing cybersecurity risks. Reliability is a complex system that is influenced by a multitude of technical and procedural components, which cannot all be guaranteed through audits alone.

Recognizing this relationship supports realistic expectations.

Oversight Perspective Low and Medium Impact compliance monitoring provides visibility into how organizations manage cybersecurity risk in relation to reliability consequences. Oversight is about ensuring that the right things are happening, that things are happening consistently and that everyone is held to account. It is not about mandating that certain countermeasures be implemented.

This perspective supports proportional oversight while maintaining focus on reliability objectives.

In general for executives compliance monitoring of Low and Medium Impact systems is an element of cybersecurity governance and to reinforce the aspect of reliability related to governance in the field of cybersecurity. It is related to organizational choices that impact how an organization can ensure it manages its security governance control obligations in an optimal way.

Giving Engineers & Operators a glimpse into the oversight context helps understand how the expectations in relation to Cybersecurity will be validated. Provides appreciation for the relationship between cyber protections and overall system availability.

Compliance monitoring and enforcement for Low and Medium Impact CIP systems will be performed within the mandatory reliability framework of other NERC standards with reliability consequence scaled to the level of risk associated with Low and Medium Impact CIP systems. Enforcement actions will focus on ensuring that enforcement actions are proportionate, consistent and individually tailored to the circumstances presented by each violation, rather than on the cybersecurity maturity of the system or area being enforced.

This discussion sets the stage for the following chapter, where several misconceptions related to Low and Medium Impact CIP will be discussed.

FROM THE FIELD

CIP audit findings cluster around the same handful of standards every cycle. Knowing the pattern is most of the preparation.

The Region audits CIP differently than non-CIP standards. The evidence packages are denser, the rolling questions are deeper, and the consequence of a finding compounds across requirements.

A CIP self-report is materially different from a non-CIP self-report. Disclosure obligations, mitigation expectations, and timeline pressure are all elevated.

Chapter 11

Common Misunderstandings About Low and Medium Impact CIP

Low/Medium Impact Clarification This chapter is designed to address a number of misconceptions and misunderstandings about what constitutes Low Impact and Medium Impact in the context of the NERC Critical Infrastructure Protection (CIP) rules. The intent is to clarify the definitions, parameters and relationships to reliability that may be subject to misinterpretation and incorrect perceptions.

“Low Impact” Does Not Mean Low Importance One of the most enduring myths in the field of missile defense is the idea that Low Impact systems are of little use. This is a misunderstanding of what Low Impact really means: a missile defense system being described as a Low Impact system is a reflection of the reliability and consequence of impact expected from that system – not on the operational value or relevance of the system.

Low Impact typically refers to systems that are providing some level of vital service at the local level. While damage to low impact systems can impact operational activities, safety, and recovery work, damage to these systems does not result in any significant system-wide consequences and are therefore classified as low impact.

Understanding the difference between these systems is crucial for knowing why Low Impact developments are not exempt from regulation.

Medium Impact Is Not a Stepping Stone to High Impact Medium Impact classification is sometimes considered as an intermediate level or as an early alert of potential High Impact, which is not correct.

The term “Medium Impact” will be used to describe systems that are assessed as being of such functional importance and potential reliability consequence. Their designation as “Medium Impact” will be independent of their developmental status (i.e., immature, mature, or aging). It is expected that “Medium Impact” systems may remain in this classification for substantial periods of time due to the nature of their operational function.

Understanding this helps avoid unnecessary concern or misalignment of resources.

Impact Classification Is Not a Cyber Threat Assessment Some Source classification models tend to mix up Impact and the likelihood of a cyber threat. They should not be confused: the Impact gives the consequences, and not the probability of the threat.

A cyber threat may be equally likely to occur on all systems across all Levels of Impact. The difference will be the reliability effect in the event that the threat is successful. Consequence and threat likelihood have been differentiated in this threat categorization framework.

This separation reinforces the reliability focus of the CIP framework.

Applicability Is Not Organization-Wide Low and Medium Impact classifications are sometimes applied too widely across an organization, in the absence of an appropriate review.

It is essential to understand that the CIP applies to systems in the context of their functional role and their reliability contribution, and that it does not respect organizational boundaries, thus proper interpretation and application of requirements, and correct and proportionate level of coverage is achieved.

Precision is central to consistent interpretation.

Compliance Does Not Replace Judgment Another misconception in this field is that complying with Low or Medium Impact requirements ensures that cybersecurity reliability risk is fully managed. However, although compliance with controls contributes to managing baseline risk, it in no way replaces technical and operational judgments and system awareness.

Reliability outcomes will depend on the real-life performance of the systems involved and cannot be reduced to the mere minimum standards required. This framework for the assessment of reliability is primarily aimed at increasing the degree of responsibility of operators, manufacturers and suppliers, and it is not claimed to cover all possible situations that may arise during normal operation.

Recognizing this limitation supports balanced engagement with the framework.

Oversight Is Not Adversarial Low and Medium Impact system oversight is often misunderstood as being negative or even a ‘punishment’. In fact, oversight of Low and Medium Impact systems is about ensuring accountability, consistency, and awareness of reliability issues.

The purpose of enforcement actions is not related to cybersecurity incidents but rather to cases in which mandatory requirements are not met. This approach is closely tied to NERC’s Reliability First Initiative, which focuses on identifying problems rather than criticizing utilities for individual faults that occur.

Understanding this intent supports constructive engagement.

Uniform Controls Are Not Required Another misconception is that Low and Medium Impact systems must be protected with the same controls or in the same manner as High Impact systems. This is not a requirement of CIP.

FARE-1 focuses on the relation between reliability consequence and the respective cybersecurity expectations. The method provides enough flexibility to accommodate various system architectures as long as the reliability of critical functions remains the same.

Uniformity is not the goal. Proportionality is.

Organizational Responsibility Is Broader Than Compliance Teams Another common misconception is that teams responsible for Low and Medium Impact CIP are Compliance and/or Cybersecurity. While these teams certainly play a role in the overall CIP reliability responsibility, Reliability goes far beyond just a few teams, and includes operations, engineering and governance.

Non-Cybersecurity business decisions and activities that impact the production process may have unintended consequences that influence CIP identification of critical assets and resultant risk evaluations. Recognizing shared responsibility for asset reliability is an important step towards better reliability management.

Clarifying the Purpose of Impact Differentiation A lot of confusion occurs as a result of treating Impact Differentiation as a administrative tool, as opposed to a reliability tool. The impact levels are there to make sure that expectations are aligned to the consequences of actions and to allow for efficient and credible oversight.

The purpose of a CIP or CIP procedure helps to clarify where Low and Medium Impact systems sit in relation to CIP.

The purpose of this document is to clarify a number of misunderstandings, particularly concerning Low and Medium Impact CIP classification, scope and intent. It is important to bear in mind that such classifications relate to the level of reliability consequence that can be afforded in a particular case and do not signify in any way that the item in question is unimportant or is in a phase of transition. Dispelling these misunderstandings will facilitate a more constructive engagement with the CIP activity as a whole.

This discussion is designed to set the stage for a broad overview that will be provided in the final chapter relating to how organizations deal with Low and Medium Impact CIP.

FROM THE FIELD

"Low Impact means light obligations" is the misunderstanding that keeps showing up at audit. Light is not the same as absent.

Chapter 12

Executive and Engineering Takeaways

This chapter ties together the various themes discussed in previous chapters in relation to Low and Medium Impact (LM) Critical Cyber Systems as defined by the NERC Critical Infrastructure Protection (CIP) regulations. This is particularly relevant to executive, engineering, and senior management personnel and is a valuable tool for understanding how ensuring that appropriate levels of cybersecurity oversight are in place can support the overall reliability of the bulk electric system (BES).

Proportionality Is the Foundation Central to the Low and Medium Impact CIP standard is the principle of proportionality. In particular, the standard aligns expected levels of cybersecurity with the potential impact of reliability consequences, as opposed to treating all equally regardless of consequence.

Each grid entity’s system is evaluated in relation to its specific role in the broader power system and corresponding levels of reliability risk related to cybersecurity. This approach to proportional regulation ensures effective, reliable oversight.

For leaders and practitioners alike, understanding proportionality helps align effort with impact.

Low Impact Does Not Mean Minimal Responsibility Low Impact systems support the functions necessary to enable local reliability-restoring measures that remain important for assuring operational safety and predictability. The lower system-wide consequence is a factor but not a reason for not being accountable.

Management of Cyber Reliability Risks in Low Impact Processes Management of Cyber Reliability Risks Key Takeaways • Low Impact is a relative term and not a qualification of the importance of the consequences in case of a failure. It is important to refer to the Baseline of Expectations to manage and control cyber reliability risks. • Recommendations are primarily directed towards management and the engineering community.

This understanding supports disciplined operational behavior.

Medium Impact Reflects Broader Operational Influence Medium Impact systems affect activities that may impact coordination, situational awareness and the management of the grid across a region. Outage

of medium impact systems will pose additional challenges to restore and recover from an event even if no primary or alternate transmission infrastructure has been affected.

The CIP is one mechanism by which the broader influence on sustainability is translated into more specific expectations. By understanding the underlying rationale of these expectations, decision-makers are better equipped to design effective governance and technical strategies.

A classification of risk resulting from potential failure to Cyber-Physical Systems in a given area, that, in accordance with the evaluation criteria established by the System Manager, exceeds the risks related to the immediate environment of each facility and/ or the damage that each facility is capable of generating on its own.

Governance Shapes Reliability Outcomes Decisions made in relation to governance will have a significant influence on the management of Low and Medium Impact controls required for the OCRO Cybersecurity Obligations. Consideration needs to be given to the overall structure, delegations and communication processes that will enable risk management activities to occur reliably.

A reminder to all executives that IT reliability cannot be left to IT to ensure that it is reliable. Executive level decisions set the stage for the rest of the organization to meet the expectations for reliability that are set. This is especially relevant when it comes to ensuring that cybersecurity is reliable.

Effective governance aligns cybersecurity efforts with reliability priorities.

Engineering Judgment Remains Central The CIP framework identifies required elements that must be addressed by design. However, it does not replace individual engineering judgment. It is the sole responsibility of the engineer and the operator to understand the system’s operations, its interconnections, and potential impacts.

When it comes to bringing a level of cybersecurity to operational environments, the application of professional judgment is required. Standards only set the parameters of the border, and it is the expertise of the system and how it can be designed to contribute to reliability that truly matters.

This balance between standardization and judgment is fundamental to the framework.

Compliance Supports but Does Not Define Reliability Compliance with Low and Medium Impact CIP requirements does contribute to achieving some aspect of the reliability of cybersecurity controls but does not directly contribute to defining reliability outcomes. Other technical, managerial, and environmental factors will also influence reliability outcomes.

Understanding that compliance sits in the space between required standards and maximum capability is critical to ensuring proper risk management.

Compliance reinforces accountability without guaranteeing outcomes.

Shared Responsibility Across Functions Cybersecurity reliability is a shared responsibility that will necessarily transcend organizational boundaries of Operations, Engineering, Information Technology and Governance. Many decisions made in each of these functions can have unintended consequences on the role that cyber systems play in supporting reliable operation.

Awareness of shared responsibility helps to prevent silos and fosters greater collaboration. It also aids in having more effective management of reliability risk to Low and Medium Impact systems.

Adaptation and Awareness The CIP framework will evolve as the system, technologies and operational conditions change. Monitoring change is important for building resilience and providing continuity of operations.

High level reminders for all Executives and Engineers. Impact classification and the associated cyber expectations may change over time. Familiarity with the FSF is key to an effective engagement with the framework.

Low and Medium Impact CIP Reliability Classifications provide proportional coverage of the relationships between expected cybersecurity performance and the consequences of reliability failures. Governance, engineering judgment, and organizational factors all play a significant role in determining reliability outcomes.

It is important for Executives and Engineers to understand the purpose and structure of Low and Medium Impact CIP in order to make informed, exercise proper oversight and actively participate in the interconnected bulk electric system.

Glossary of Low & Medium Impact CIP Terms Introduction

Glossary of Low & Medium Impact CIP Terms Introduction

This glossary contains a number of terms from the NERC Critical Infrastructure Protection (CIP) guidelines. In addition, terms appropriate to Low Impact and Medium Impact systems have been added.

Definitions are taken from the NERC Glossary of Terms Used in NERC Reliability Standards, as applicable. Definitions are for informational and educational purposes only and are subject to revision.

Defined Terms Bulk Electric System (BES)- Except as provided by exception, all Transmission Elements above 100 kV and all Real Power and Reactive Power resources connected at voltages above 100 kV, except for those facilities engaged in the direct distribution of electric energy to customers.

BES Cyber System–One or more Cyber Assets that are logically grouped by a functional entity (e.g., operations center personnel or utility control center personnel) to perform one or more reliability tasks associated with a functional entity.

Cyber Asset refers to the hardware, software or data components of programmable electronic devices.

Critical Infrastructure Protection (CIP) - Reliability Standards issued by NERC to ensure the confidentiality, integrity and availability of cyber systems that support reliable generation, transmission and/or distribution of BES power.

Impact Rating- The classification of a BES Cyber System based on the potential reliability impact associated with its loss, compromise, or misuse.

Low Impact BES Cyber System A BES Cyber System whose compromise could affect local reliability functions but is not expected to result in widespread or system-wide reliability consequences.

Medium Impact BES Cyber System A BES Cyber System whose compromise could impact more than local operations, disrupt situational awareness at more than one location, or potentially affect regional reliability in a way that does not rise to the level of system-wide consequence thresholds.

Electronic Security Perimeter (ESP) - The logical boundary surrounding a network to which BES Cyber Systems are connected and access is controlled.

PSP (Physical Security Perimeter) Physical barrier which surrounds an area that contains BES Cyber Assets and access to which is controlled.

Reliability– The ability of the Bulk Electric System to perform its intended function under both normal and abnormal conditions.

Registered Entity - A legal entity registered under the NERC registration process to provide one or more reliability services as outlined in the applicable Reliability Standards.

Reliability Standard- A FERC-approved rule under Section 215 of the Federal Power Act that governs the conduct of Users, Owners, and Operators of the BES.

About the Author

About the Author

Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.

Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.

Rob’s compliance authority extends across both reliability and cybersecurity domains. His work on Critical Infrastructure Protection includes audit and oversight of CIP-002 through CIP-014, scope and impact classification reviews, ESP and PSP boundary analysis, and program assessments for entities with Low, Medium, and High Impact Cyber Systems.

Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.

About Energy Compliance, Inc.

About Energy Compliance, Inc.

Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.

Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.

We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.

Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.

CIP-Focused Services

Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.

Energy Compliance services related to Critical Infrastructure Protection include, but are not limited to:

  • CIP applicability and scope analysis (CIP-002 through CIP-014)
  • Cyber asset and BES Cyber System identification and impact classification
  • Electronic Security Perimeter and Physical Security Perimeter boundary analysis
  • CIP governance and program assessments
  • Integration of cybersecurity oversight with broader reliability programs
  • Audit and enforcement support for CIP findings (non-advocacy)
  • CIP framework reviews, gap analyses, and improvement plans
  • Training focused on CIP framework, requirements, and audit expectations
  • Executive and board-level CIP awareness briefings

Services are tailored to the functional role, system impact, and regulatory posture of each organization.

ENERGY COMPLIANCE PROFESSIONAL REFERENCE

Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.

N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.

I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.

CONNECT WITH US Scan to visit

E N E RGY COMPL IAN CE , IN C. · EC-WP-201 · © 2026 · AL L RIGHTS RES E RV E D

Cybersecurity / CIP