Medium Impact BES Cyber Systems make up the bulk of operational technology under NERC CIP. The control architecture for Medium Impact is calibrated to balance adequate cybersecurity protection against the operational realities of high-availability, low-downtime SCADA environments. Get the calibration wrong in either direction and the program produces the wrong outcomes — over-engineered, under-protected, or both. Medium Impact is where most CIP audit findings live. Not because Medium is harder. Because Medium covers most of the registered population. CIP-003 is where CIP becomes a managed program rather than a set of technical controls. CIP-005 defines the Electronic Security Perimeter. Most CIP-005 findings are undocumented crossings, not control failures. Physical security is not secondary to electronic security. A bypass at the physical layer renders electronic controls irrelevant. CIP-007 is where most operational compliance effort lives. It's also where most findings cluster. The two facts are connected. CIP-008 and CIP-009 assume prevention will fail. Programs designed only for prevention are designed for the wrong scenario.
Contents
- Foreword
- CIP-002 and the Logic of Medium Impact Classification
- CIP-003 and Governance Controls for Medium Impact Systems
- CIP-005 and the Electronic Security Perimeter for Medium Impact Systems
- CIP-006 and Physical Security Controls for Medium Impact Systems
- CIP-007 and System Security Management for Medium Impact Systems
- CIP-010 and Configuration Change Management for Medium Impact Systems
- CIP-011, Information Protection, and Data Integrity
- CIP-008 and CIP-009: Incident Response and Recovery for Medium Impact Systems
- Oversight, Audit Posture, and Enforcement Trends for Medium Impact Systems
- Medium Impact Systems and the Operational Reliability Interface
- Glossary
- About the Author
- About Energy Compliance, Inc.
Read offline
The complete reference is on this page. The PDF is for circulation inside your organization.
Download the PDFForeword
Foreword
This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.
I’ve spent more than thirty years on every side of the bulk electric system. I’ve operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I’ve audited grid facilities and signed off on findings as a senior compliance auditor. I’ve worked enforcement matters from inside the regulator’s process. For the last several years I’ve advised registered entities directly through the firm I founded.
The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn’t. They prepare for audits by building programs that survive real questions, not binders that look thick.
That’s the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.
These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who’s been told that compliance and reliability are the same thing and suspects they aren’t. And for the new compliance hire who got handed a binder and told good luck.
These references aren’t marketing material disguised as content. They’re the result of three decades of doing this work and watching it succeed and fail. I’ve written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.
Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don’t bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you’re looking for in a compliance partner, the back of this reference has our contact information.
If not, the reference still belongs to you. Take what’s useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?
Rob Smith, Founder, Energy Compliance, Inc.
EC-WP-202 CIP Medium Impact
Chapter 1
CIP-002 and the Logic of Medium Impact Classification
Medium Impact controls are being established in a compromise between two competing needs: adequate protection against both cyber and physical threats to ensure that SCADA systems can continue to operate without disruption; and the need to accommodate expected SCADA operational environments of high availability with low allowed down time. This means that our reliability
requirement for controls is that they must be able to provide continuous control and system integrity, and the fact that today’s security controls may not be aligned with standard information security practices and regulatory requirements for non-reliability systems is not relevant.
Our enforcement experience has shown that Medium Impact relabeling decisions, perimeter boundaries and control implementation of affected systems are focal points of enforcement compliance monitoring activities. Review of Reliability Standard Audit Worksheets and enforcement actions publicly available on our website give an idea of the level of detail required to show compliance with the Requirements. The Measures in the Standards emphasize the importance of implementation of measures and reflect the overall shift to focus on operational reliability of the compliance monitoring program.
This report examines the institutional design of the regulatory framework of the Medium Impact CIP reliability standard. It examines the classification logic set out in CIP-002, the control layers as described throughout the CIP regulations, the relationship between cybersecurity regulation of grid operations on a real-time basis, and the role of Regional Entities within this institutional design. The report is structural and analytical as opposed to instructive.
Medium Impact BES Cyber Systems is one of the categories of Cyber Systems defined in the cybersecurity reliability standard for the Bulk Electric System (BES) developed by the Federal Energy Regulatory Commission (FERC). As such, the definitions provided here, will provide insight into the categorization of BES Cyber Systems in the reliability framework, specifically with regards to the control architecture that defines the place of cyber risk in this framework.
All other Requirements in the CIP Reliability Standard flows down from the initial asset identification event. The CIP framework is triggered by asset identification. The entity’s process for identifying and classifying BES Cyber Systems is described in CIP-002. This process determines which Requirements are applicable and the degree of rigor with which they must be implemented. Accordingly, the determination of whether a control or system has Medium Impact is a threshold determination that drives the entirety of the control measures implemented on a system.
CIP-002 requires the identification of BES Cyber Systems that correspond to the defined functional criteria. The criteria are based on the potential reliability consequence to the BES of a Cyber System breach. High Impact is reserved for primary control centers and other BES Cyber Systems defined by the Bright Line Thresholds. Low Impact is defined as BES Cyber Systems that do not meet the criteria for Medium or High Impact. Medium Impact is defined by listing specific functional criteria related to Generation, Transmission and Control environments.
Some or all generation resources above specified nameplate capacity levels of certain transmission stations and/or backup control centers may be classified as Medium Impact. The placement of these facilities in this category recognizes that a potential compromise of a control system at these places
could interfere with reliable system operation, although these facilities are not necessarily high-impact locations within an Interconnection. The criteria function in this category is based on objective standards to remove the potential for subjective interpretation of high and low impact risk.
While seemingly straightforward, applying the logic of CIP-002 can be quite complicated. The CIP-002 R1 requirements are cumulative and entities must comply with each step in the following sequence or face enforcement actions: • Define BES Assets according to the definitions contained in the Bulk Electric System rule. • Identify Cyber Assets which are contained within such BES Assets and which perform reliability functions. • Group such identified Cyber Assets as BES Cyber Systems because of their associated reliability functions. • Apply the impact category test in the same manner as applies to BES Cyber Systems and the related BES Cyber Assets. Misapply any part of this sequence and you are in risk of noncompliance.
Medium Impact determinations generally depend on the interpretation of the enumerated criteria in the standard. For example, analyses relating to capacity limits and substation and backup control center inclusion or exclusion will depend on an accurate determination of the applicability of the specific criteria language set forth in the standard. The determination of control is not a matter of BUR discretion. Rather, it must be based on the criteria set forth in the standard and as the Commission has found in the context of a public enforcement proceeding, a false determination of control is a violation in and of itself and does not present a further question of the effectiveness of the required measure to exert control over the operations of the ITC system.
The choice to use Medium Impact is a policy decision that was made during the development of this framework. In this context, the framework calls for the application of more stringent controls than those that would be required in the event of a Low Impact system vulnerability. The Medium Impact controls are not as stringent as those
called for with a High Impact system vulnerability because not all operational technology systems and networks have the same level of reliability exposure. It is also recognition that it may not be feasible or practical to apply the same set of cybersecurity controls across different OT systems.
The expectation for the evidence related to the classification criteria of CIP-002 is not limited to a simple classification label. Utilities are required to document the methods and analyses they used to determine their classification. This documentation can vary and may include asset inventories, functional analyses and correlation of criteria to specific assets or facilities. Upon reviewing the Reliability Standard Audit Worksheets, it becomes apparent that the focus is on having traceability and being able to defend the classification determinations.
The Medium Impact classification of CIP-002-6 is not always straightforward. Realworld operational issues often arise and can significantly impact the initial categorization. Stations evolve, capacities
change and system configurations are modified. CIP-002-6 requires that Asset Categorization Reviews be conducted on a scheduled basis or when a Significant Change occurs. Assets are expected to be categorized based on the current configuration of the Bulk Electric System. Not the historic configuration.
CIP-002 describes the boundary conditions for what constitutes the Medium Impact regime. This sets out criteria for determining control effectiveness on a continent-wide basis. The reliability objective underpinning these conditions is the prevention of adverse conditions (i.e., loss of control authority or stability) resulting from a system or network being compromised. The categorization function in CIP-002 provides a means of operationalizing that objective.
End-of-Chapter Summary
CIP-002 defines the enforceable process for identifying and classifying BES Cyber Systems and provides the definition of the Medium Impact criterion used in the other CIP Reliability Standards to determine the extent of control over Cyber Systems that support BES reliability. CIP-002 uses criteria and documentation to guide utilities in their application of a risk-based methodology to determine the level of cybersecurity controls that need to be implemented to protect certain BES Cyber Systems.
FROM THE FIELD
CIP-002 is the gate. Everything else in CIP runs through it. Get the classification right and the rest of the program is calibrated. Get it wrong and the program is built on the wrong scope.
Medium Impact is the most common classification for registered entities, and the most common source of audit findings. The two facts are connected.
The classification logic isn't arbitrary. It traces consequence of compromise to a specific impact rating. Reading the rationale, not just the threshold, is what makes the classification defensible.
Chapter 2
CIP-003 and Governance Controls for Medium Impact Systems
Once a BES Cyber System is determined to be classified as Medium Impact under CIP-002, this system then falls under the governance requirements established in CIP-003. This standard includes fundamental cybersecurity management controls applicable to Cyber Systems classified as Medium Impact and/or High Impact under CIP-002. This standard sets out the management framework that provides the context in which the technical controls defined in subsequent standards will be exercised. This Standard establishes documentation requirements for cybersecurity policies for certain activities and systems. For Medium Impact BES Cyber Systems, the Cybersecurity Policies must address the following topics and any additional topics applicable to the specific system or activity, including: Access controls procedures for granting, modifying or revoking users’ or processes’ permissions to access information systems Change controls procedures for modifications to information systems, including changes to software, hardware, network topology or any other system components Information security controls for protecting information systems, including measures to prevent unauthorized access to the information systems Incident response procedures to detect, contain, correct and learn from hacking incidents or other cyber-attacks Business recovery planning procedures for disaster recovery and business continuity supply chain risk management procedures as they relate to information systems The existence of a policy does not necessarily mean the entity has met the enforceable obligation. Instead, the entity must show that the policies are: - Approved - Current - Consistent with the requirements of this part and parts 501 through 508 of the regulations. CIP-003 is a governance model that acknowledges the fact that management controls cannot be enforced on technology without some accountability. Policy approval authority, roles and procedures ensure visibility of responsibility. In a Medium Impact environment, where the lines between operational technology and cybersecurity often blur, a governance model can serve to reduce the potential for confusion and ambiguity surrounding who is responsible for implementation, monitoring, etc. As it
pertains to Medium Impact, CIP-003 also includes documented procedures for access, for training individuals with access, and for the periodic review of access rights. These administrative control requirements form the base governance layer. The more prescriptive technical controls, as found in CIP-005 and CIP-007, sit atop this governance layer. This standard is essential for defining the overarching governance expectations for an organization and obtaining management approval for those
expectations. Change management and configuration management governance elements in CIP-003 R1 provide an additional layer of reliability and continuity. Operation technology systems are designed to be always available. Uncontrolled changes to these systems can cause instability and are a vector for security vulnerabilities. The documentation of governance processes outline the expectations for pre change reviews, procedures for obtaining approval for changes, and the required documentation. For R1, the expectation is that RCAU/EUA has evidence of the procedures as they exist in policy, dated versions of the policy as it has changed over time, and evidence of the frequency of policy reviews. The management of supply chain risks has become a key component of CIP-003 revisions. The recently publicly approved changes include additional vendor risk assessment and procurement controls for applicable BES Cyber Systems. The scope of BES Cyber Systems can vary by impact category and system characteristics; however, the inclusion of supply chain language in the Reliability Risk (RR) category and elsewhere acknowledges that reliability risks can occur from sources outside of normal operations and business practices. Measures related to CIP-003 generally look to confirm that utilities have implemented their governance processes in tangible ways. Audit evidence may include examples of regulatory documents, approval records, training rosters, and examples of regular access audits. Governance controls are not simply about having documents on the shelf, but rather it is about having living processes that integrate controls and procedures to protect operational activities, as well as IT/ Cybersecurity systems. The processes to be identified and implemented in order to fulfill the Medium Impact governance controls shall take into account operational requirements. Control centres, substations and generation facilities are always on the air. It shall not therefore be possible to undermine the reliability of the grid operations by imposing governance controls on Cybersecurity. The Standards do not provide nor prescribe any particular technology, or organisational structure. Instead they aim to ensure that processes have been defined and implemented which ensure continued grid operation reliability as described within the corresponding Control Architecture. These Violation Risk Factors (VRFs) relate
to the specific CIP-003 Requirements and are determined by the potential reliability consequence of a governance deficiency. For absence of an approved policy where a system may be at risk of not being properly managed, the VRFs capture this exposure. However, for a requirement that is more focused on the implementation and review of a governance procedure or control and less so on administrative errors, enforcement focus may be on the actual implementation and review of such procedures rather than on technical accuracy of paperwork. CIP-003 provides the governance requirements for the Medium Impact category. It addresses aspects of accountability, regulation, and compliance that will interact with the technical controls addressed in the subsequent CIP standards. Without this governance overlay, perimeter controls, access controls, and system security controls would be inoperative.
End-of-Chapter Summary
CIP-003 requires regionally enforceable cyber security governance and management controls for Medium Impact BES Cyber Systems, including written policies, identified responsibilities and procedures for administration. The governance controls that are required establish a foundational level of cyber security governance for technological controls covered under CIP and support the continued reliable operation of the BES through a structured framework of governance and accountability.
FROM THE FIELD
Governance is what the standard expects from leadership. Procedure is what the standard expects from operations. CIP-003 holds both ends accountable.
A Cyber Security Senior Manager isn't a title; it's a named role with named responsibility. CIP-003 expects that role to be filled by someone who knows they hold it.
Policies that haven't been reviewed in fifteen months are policies that haven't been reviewed. CIP-003 sets the cadence; the program has to operate it.
Chapter 3
CIP-005 and the Electronic Security Perimeter for Medium Impact Systems
CIP-005 deals with Electronic Security Perimeters (ESPs) and interactive remote access to BES Cyber Systems. For Medium Impact assets, this standard defines the logical boundary around which technical security controls must be implemented. The Electronic Security Perimeter is not a conceptual entity, but a defined construct that delineates where access controls, monitoring functions, and authentication functions must be implemented. The Electronic Security Perimeter (ESP) element includes identifying Electronic BES Systems (BES Cyber Systems) and their associated Cyber Assets. The institution’s objective is containment. The control to meet this objective is identifying all Cyber Assets associated with BES Cyber Systems, determining the boundaries of the Electronic Security Perimeter for the BES, and ensuring all external routable connections to the systems are to authorized access points. CIP-005 Part 3a, Medium Impact: Electronic Access Control for Medium Impact systems is primarily focused on the control of Electronic Access Points (EAPs) through access control measures such as authentication, logging and monitoring. The technology is not specified. Instead, the outcome is. And that outcome is – controlled access, authenticated individuals with audit trails of sufficient depth to demonstrate the entity is aware of all activity. Typical evidence includes network diagrams, firewall rules, access control lists and access logs. Interactive Remote Access is a key component of CIP-005. Vendor support, engineering access, and operational troubleshooting for Medium Impact BES Cyber Systems may routinely require an individual located in a remote area to interact with the system. The standard establishes new controls over interactive remote access by requiring multifactor authentication and encryption. These additional controls are also a reflection of the increased risk of remote access. Enforcement actions have also confirmed that non-compliance to the remote access provisions of CIP-005 is an ongoing compliance issue. Electronic Security Perimeter (ESP) is a concept that also complements the layered architecture provided for by the CIP framework. CIP-003 deals with governance aspects and CIP-007 provides rules for system security management. The network boundary defined in CIP-005 is the area surrounding Critical Cyber Systems that limits interactions with the external environment. Any weakness in ESP could compromise the effectiveness of control placed on the CS down stream. An improperly configured access point can destroy the effectiveness of even best
practice controls implemented inside the ESP. Medium Impact environments have added complications for perimeter designs. Potential limitations include the legacy system design, operational technology constraints, and vendorbased restrictions on segmentation. The standards do not imply uniform architectural models, but instead require that the Electronic Security Perimeter (ESP) be defined so as to encompass all relevant systems, and that all routable communication is governed by the control provisions established within the standards for demonstrable isolation, regardless of architectural complexity. This requirement deals with documentation associated with CIP-005’s requirement for current network diagrams for the bulk electric system that show BES Cyber Systems and Electronic Access Points. From an operational perspective the purpose of these diagrams is to show the paths by which the BES Cyber System elements are connected to one another. From a compliance perspective the purpose of these diagrams is to enable tracking of the basis of the grid entity’s perimeter. The Reliability Standard Audit Worksheets associated with CIP-005 often seek to confirm that the drawings are current and accurate representations of the BES Cyber System elements and their connectivity. Violation Risk Factors (VRFs) that address CIP-005 Requirements typically focus on the reliability risks associated with perimeter failures. For example, potential reliability impacts from physical penetration of the perimeter to access computers and networks to disrupt real-time control and compromise system reliability. However, VRFs associated with requirements for access control implementations and interactive remote control typically carry a higher risk value. This Standard operates as a structural boundary within the Electronic Security Perimeter (ESP) of the Medium Impact control systems defined in CIP-002-6.1. This limits exposure to potential threats and holds an entity accountable for access control management within the ESP of the system, while still enabling reasonable assurance of continued reliable operation. The identification of BES Cyber Systems under CIP-002 and governance procedures under CIP-003 must be taken into account when considering this standard to highlight the interrelationship among the CIP standards.
End-of-Chapter Summary
This Standard revises current Mandatory Reliability Standards to cover Electronic Security Perimeters and interactive remote access for Medium Impact BES Cyber Systems. The controls in CIP-005 require defined points of entry, authenticated links and a description of the perimeter architecture to create a boundary to contain operational technology (OT) environments to protect against unAuthorized external interactions.
FROM THE FIELD
The Electronic Security Perimeter isn't a concept. It's a defined boundary, drawn on a network diagram, with specific controls at each crossing. CIP-005 expects the diagram and the controls to match.
The most common CIP-005 finding is an undocumented crossing. A connection that exists on the network but not on the perimeter diagram is a crossing the program didn't know it had.
Chapter 4
CIP-006 and Physical Security Controls for Medium Impact Systems
While the Electronic Security Perimeters section defines the logical boundaries of our network, CIP-006 defines the physical security of the BES Cyber Systems. Physical security of medium impact assets are not secondary, as the network controls do not necessarily mitigate physical access, and compromise via physical access may be achieved despite logical access controls, malware introduced via USB or other means, and asset availability disrupted. This standard will define physical security perimeters and processes to enforce these requirements. Physical Security Perimeter A Physical Security Perimeter is defined as a geographic area that surrounds all physical locations of Medium Impact BES Cyber Systems. The perimeter must be adequate to preclude unescorted physical access to any area that contains such systems. The reliability objective of physical security is to prevent any potential for unauthorized physical access to or interaction with devices that perform reliability functions. CIP-006 is generally applicable only to a limited number of systems identified as part of CIP-002. For Medium Impact, entities shall implement one of the following physical access control measures: - Badge system - Keyed access Unmanned access points (e.g. doors) under constant monitoring - Alternative measures that are reasonably comparable The Entity does not have discretion as to what measures are implemented, only which measure is implemented. In implementing measures the Entity shall ensure that access to the relevant protected electronic assets is limited and that access is logged and reviewed in accordance with procedures. The Evidences for this control are records from access control systems, visitor logs, records of access audits performed to ensure that access controls are functioning as intended and other relevant procedures. Visitor control is a recurring focal area. The controls for access to, and movement within, the Physical Security Perimeter for non-authorized personnel must be clearly defined. The key concern at the facility is visibility/traceability of visitors. Exposure was found in inadequate removal of authorized access from non-authorized personnel, inadequate logging of events or failure to properly review the access logs for visitors. The
Measures within CIP-006 R2 dealing with access authorization and denial for physical access to the Physical Security Perimeter have clarified the need to track all events (i.e. grant, deny) associated with granting physical access. This part also deals with the measures of protection to be provided for monitoring systems. In Medium Impact cases, means shall be available to enable detection of attempted access in breach of access provisions. This could be in the form of alarms, monitoring equipment etc. The
entity shall also be prepared to take any necessary countermeasures in the event that access is actually detected, in accordance with appropriate procedures. This reliability element is intended to provide continuity of control as well as to prevent any act of tampering. Physical security and operations do not always align. Substations, control centers and generation plants require access for operational personnel, maintenance personnel and contract workers. The control of access to these facilities must balance security with operational needs. Rather than being prescriptive of facility design, this standard focuses on procedures and accountability. The enforceable control is that access to facilities is controlled, recorded and audited on a regular basis. CIP-006 also interacts with CIP-008, Incident Reporting. A physical security event affecting BES Cyber Systems may be considered an incident. This standard was written with layers of detection, response and reporting in mind. Physical compromise of cyber systems is not to be treated in a vacuum of the overall cybersecurity reliability standard. Violation Risk Factors for certain CIP-006 Requirements that pertain to Reliability Functional Areas are sometimes associated with the potential reliability impact of unauthorized physical access. Although the impact may not be significant in situations where a breach would not affect system operation and no malicious hardware would be introduced, Vulnerability RFs in these situations are intended to acknowledge the possible exposure. For documentation-centric Requirements the RFs are considered to be relatively low but the Requirements are considered to be high value since they represent documentation that is critical to ensuring that control integrity is maintained. CIP-006 completes the boundary pairing started in CIP-005. While CIP-005 defined electronic boundaries, CIP-006 now defines the physical boundaries for the dual perimeter architecture protecting Medium Impact BES Cyber Systems. Risk to reliability is not limited to electronic connectivity; physical access can provide equivalent exposure.
End-of-Chapter Summary
CIP-006 provides mandatory physical security controls for the protection of Medium Impact BES Cyber Systems within defined Physical Security Perimeters that include controls for access, monitoring, and accountability. This physical access control complements electronic perimeter controls for overall cybersecurity reliability.
FROM THE FIELD
Physical security isn't secondary to electronic security. A bypass at the physical layer renders the electronic controls irrelevant.
CIP-006 expects the same operational discipline as CIP-005: documented perimeter, controlled access, logged entry, reviewed cadence. The auditor checks each.
The most common CIP-006 finding is a stale access list. People who left the company three years ago should not have active badge credentials. The audit finds out fast when they do.
Chapter 5
CIP-007 and System Security Management for Medium Impact Systems
CIP-007 covers the security management of BES Cyber Systems that are inside the Electronic Security Perimeter. For Medium Impact assets, this standard covers the baseline technical controls for any operational technology that the utility applies directly to the component. Where CIP-005 and CIP-006 cover the boundary protections, CIP-007 covers the internal configuration and management of the BES Cyber Systems. These requirements were covered within the ports and services management, security patch management, malicious code prevention, security event monitoring, account management and system access controls sections of CIP-007. The institutional goal was to mitigate or minimize in-scope, in-privilege, and in-view exploitable vulnerabilities within a defined perimeter while increasing visibility into system behaviors that could impact power system reliability. The management of port and services requires you to justify and identify the ports that are enabled on the relevant Cyber Assets. It is not mandatory that all the ports should be disabled, but the enabled services have to be documented, approved and must be necessary. This requirement is about minimizing the attack surface while at the same time retaining the functionalities needed to operate business systems effectively. This requirement is about documentation of the configurations, service list, and statements or justification in relation to the required services. The Security patch management standard focuses on the requirements related to the identification, assessment and implementation of patches provided by vendors. These can be particularly challenging to manage in Medium Impact systems. Many Operational Technology systems cannot be taken offline to apply patches without significant operational disruption. This standard requires controls to be implemented in relation to the assessment and timely implementation of patches and mitigation of risks where implementation of patches is not warranted. Audits have focused on the adherence to documented processes, the justification of implementation timelines and whether timely implementation has occurred. Malicious code prevention controls are also risk-based. The standard requires the implementation of controls to deter, detect
or prevent malicious code or the provision of a detailed explanation for cases where this is not technically possible. In operating environments where the use of traditional antivirus software is prohibited on certain systems due to operational stability issues, alternative compensatory controls must be demonstrated. As with other control types, the focus of the standard is on documented risk analysis and consistency of control implementation. Account management and authentication control
requirements under CIP-007 support the perimeter controls in CIP-005. Entities are required to maintain system account management activities, including disabling unnecessary accounts and reviewing the level of access provided to individual users on a regular basis. For Medium Impact systems where availability is critical and an effective rapid response cannot be compromised, access control activities must be robust. Evidence requirements for accounts management under CIP-007 may include: - A listing of accounts - Records of when accounts were reviewed for access levels - Records and documentation for accounts that were disabled. The Security event monitoring Requirements describe the events that must be logged and monitored, and what frequency the logs are to be audited and reviewed. The reliability objective of logging security events is for the early detection of suspicious activity and potential compromise. The audit focus for this control is generally to validate the configuration of logging for the logged events and that the audit and review periods are in line with those stated in the process documentation. CIP-007 has a close relationship to CIP-010. The basic work for identifying what requires port, service, and patch level management is provided by the functions of CIP-010, Baseline Configuration. The mutual reinforcement of standards and the continuity of systems security management processes are intended to validate the notion that managing the security of controlled cyber systems is not an episodic function. This list identifies the Violation Risk Factors for selected CIP-007 requirements that relate to the potential impacts of open vulnerabilities or unauthorised access to the control system environment. Failure to properly address patching and disable unused services may leave control systems at risk for malicious activities that could impact reliable operation. In such cases, the standard provides an exception that accounts for operational requirements and allows for documented technical justification as required. Cybersecurity for the Operational Technologies (OTs) of Medium Impact (MI) assets is addressed through Regulation CIP-007, System Planning and Implementation for Cybersecurity. This regulation transforms the expectations of electric utilities’ Board of Directors and NERC into specific technical controls that are incorporated into normal operational procedures to be followed by operational teams on a day-to-day basis. The enforceable elements of this regulation address procedures, adherence, recordkeeping, etc. and provide the documentation necessary to demonstrate that the requisite controls have been exercised.
End-of-Chapter Summary
Reliability Standard CIP-007 establishes System Security Management controls for Medium Impact BES Cyber Systems, to include controls associated with port and service management, patch evaluation, malicious code detection, account management, and security event monitoring. The documented and implemented technical controls specified in this Standard are incorporated within the Electronic Security Perimeter in accordance with CIP001 (Version 5 and later) to further enhance the overall cybersecurity reliability architecture of the BES.
Chapter 6
CIP-010 and Configuration Change Management for Medium Impact Systems
CIP-010 deals with configuration change management and vulnerability addressing for BES Cyber Systems. For Medium Impact assets, this standard simply formalizes the basic understanding that system configurations are known, managed and reviewed for security vulnerabilities on a regular basis. The intent of the standard is to prevent unauthorized and unmanaged changes to the system that could cause reliability problems and open vulnerabilities for exploitation. One of the key elements in CIP-010 is the concept of a Baseline Configuration for Applicable BES Cyber Systems. This means that the utility must document their configuration of BES Cyber Systems including hardware, software, firmware versions, logical network accessible ports, security patches, etc. and it is against this baseline that all subsequent changes are validated. The baseline is not a static inventory of items that make up the BES. Rather, it is a description of the current configuration of the system. It must be updated any time the utility authorizes a change. Configuration change management Requirements mandate that entities obtain approval for changes; make a record of them; and carry them out in accordance with procedures. They must record the reasons for the change; assess the impact on the security of the protected information; and update the appropriate documentation accordingly. In operational environment change management may be impacted by reliability concerns. For example, there may be periods when maintenance is scheduled and there are interactions with the control room. The standard requires procedures be documented; it does not imply that procedures must include timelines for when changes must occur. The vulnerability assessment component of CIP-010 requires entities to perform periodic evaluations of applicable BES Cyber Systems to identify exploitable weaknesses. For Medium Impact systems, these assessments must be conducted within defined intervals and in accordance with documented methodologies. The assessment scope includes evaluation of system configurations and security controls. Evidence expectations typically include assessment reports,
identified findings, and documentation of mitigation actions. Emphasis in this requirement is on process integrity and follow through. A vulnerability assessment cannot be performed as a one time activity. It must address all known vulnerabilities at the time it is performed. All documentation relative to this activity must show that the identified potential vulnerabilities were addressed and the procedures used
to address them. There have been several enforcement actions taken in regards to failure to update baseline configurations and to perform vulnerability assessments within required timeframes. This topic is also covered in CIP-007 R2 Table 2 - Patch Management. The patches or updates must be documented in the Baseline Configuration after being implemented and the reason for not implementing the deferred patches must be documented with a technical or operational explanation. All medium impact environments have legacy systems with unsupported functions. Configuration management processes will have to take account of these while still ensuring full visibility and accountability of their actions. This standard does not say anything about the need for modernisation. Rather it is saying that changes, supported or otherwise, shall be fully documented, tested and brought into production in a controlled fashion and in line with the production environment. Violation Risk Factors for CIP-010 Requirements that cover various Vulnerability Risk Factors associated with Configuration Item descriptions that describe potential reliability impacts of unaddressed Configuration Drift or Voltage Regulation issues (e.g., impacts of changes that could affect the reliability of the Bulk Electric System); impacts of managed or unmanaged vulnerabilities. An improperly configured system can compromise the integrity of the perimeter defenses and system-level security controls. Therefore, Violation Risk Factors have been assigned for ongoing baseline configuration management and vulnerability testing activities to ensure that continuous monitoring enforcement activities are aligned with fundamental controls necessary for ensuring cyber reliability. The purpose of CIP-010 is to ensure that the configurations of Medium Impact BES Cyber Systems are properly managed through the implementation of configuration discipline. This includes the identification of desired system states, approval and recording of changes, the discovery and remediation of known cyber vulnerabilities, and the regulation of the manner in which systems may be modified. Ensuring the reliability of BES Cyber Systems through regulation of dynamic system behavior rather than regulating spontaneous changes to that behavior is a fundamental tenet of reliability-based cyber security.
End-of-Chapter Summary
This version of CIP-010 imposes mandatory configuration change management and vulnerability assessments for Medium Impact BES Cyber Systems. By requiring baseline configuration documentation, adherence to approved procedures for changes, and periodic vulnerability scanning, the rule is intended to ensure that all BES Cyber Systems are properly managed to avoid the reliability risk posed by unchecked configuration drift.
FROM THE FIELD
A change made without going through the change process is a change the audit will find. CIP-010 is unforgiving on undocumented changes.
The vulnerability assessment requirement isn't a one-time scan. It's a recurring obligation, and the recurrence cadence is part of what gets audited.
Chapter 7
CIP-011, Information Protection, and Data Integrity
CIP-011 establishes standards for protection of BES Cyber System Information. For Medium Impact BES Cyber Systems, this standard builds upon existing control technologies addressing devices and networks by including the information (e.g., configuration, operational) required to support those devices and networks. The institutional control for this standard is to maintain the confidentiality and integrity of critical information, where exposure of that information or its modifications could cause a reliability risk. BES Cyber System Information refers to documentation and configurations of cyber systems, including system design diagrams, security settings, and process descriptions, that if breached, could potentially impact the operation of the cyber system. This standard requires that documented procedures be developed to safeguard BES Cyber System Information at rest and in transit. The expectations for protecting BES Cyber System Information include, but are not limited to, requiring appropriate access controls, using encryption where appropriate, and handling BES Cyber System Information accordingly. The regulatory requirement is risk-based. It requires the identity of the BES Cyber System Information at risk in the organization’s information technology environment and the application of appropriate measures of protection as provided in the organization’s policies. It does not require elimination of risk below a specific level. Rather it requires that the controls applied to the BES Cyber System Information be commensurate with the risk determination as documented in the organization’s policies. This standard also covers disposal and re-use of data storage media applicable to CIP-011. Information on the BES Cyber System contained on media that has been retired or re-purposed must be completely eliminated so that it cannot be retrieved by any authorized or unauthorized means. Examples of sanitization procedures/ evidences are required as part of the procedures/documentation for sanitization of such media. Information protection is closely aligned with several other CIP standards. For example, network diagrams that define Electronic Security Perimeters (ESP) in CIP-005, baseline configurations described in CIP-010, and access control lists referenced in CIP-007 contain information that would be considered protected. With these standards, the additional layer of protection helps to not only protect the systems, but also the information required to access or manipulate the systems. At Medium Impact sites, in some cases, proprietary technology will be shared with vendors, external contractors and other affiliates. CIP-011 includes requirements that relate to procedures for disclosing such information as well as any special precautions that must be taken during the sharing. Reliability risks associated with this CIP-011 requirement include increased vulnerability due to release of system
passwords or other configuration details that could open doors to potential hackers. Violation Risk Factors for CIP-011 Requirements are risk factors that assess the reliability impact of information that could be compromised and thereby increase the risk of a violation occurring. Potential violations may occur if confidential information such as security documentation and passwords are released and could be used by malicious actors to gain control over the system. Enforcement reviews are used to determine if documented procedures were actually implemented and if sensitive information is handled in accordance with stated policies and procedures. This element of CIP-011 is based on the institutional logic that access to information systems is not the only risk exposure. The more one knows about a system’s configuration, security features and operations, the greater one’s capability to exploit any vulnerabilities in the system. Consequently, protecting information not only complements measures to physically and electronically secure the perimeter, but also to guard against unauthorized access once inside. CIP-011 adds another control layer for Medium Impact systems as defined in CIP-005, Part 4, R1 to R2. It makes clear that reliability exposure goes beyond just hardware and software availability, and that operational knowledge (information) must be properly controlled. CIP-011 is a means to ensure that Informational controls in the Medium Impact category of systems provide adequate mitigation of the risk of forced exposure of operational knowledge in a way that does not negatively impact reliability of operations through the reduction of possible entry points for malicious knowledge that could be used by adversaries to attack the Bulk Electric System.
End-of-Chapter Summary
CIP-011 sets forth standards for Reliability Threat and Vulnerability Reporting Requirements for BES Cyber Systems related to Medium Impact assets for the documentation of procedures for the protection of sensitive configuration and operational information prior to being stored, transmitted or discarded. CIP-011 brings informational cybersecurity controls under the umbrella of the broad cybersecurity regime that is integral to the CIP reliability protection architecture.
FROM THE FIELD
BES Cyber System Information is the data about the system. Protecting it is part of protecting the system, because the data describes how to compromise the system.
A network diagram emailed to a vendor unencrypted is a CIP-011 finding waiting to happen. The standard expects information handling that matches the sensitivity of the information.
The boundaries of CIP-011 are wider than most programs first assume. Anything that describes the cyber asset is potentially BCSI, and the program has to think clearly about scope.
Chapter 8
CIP-008 and CIP-009: Incident Response and Recovery for Medium Impact Systems
1.1 The assumed control architecture for a Medium Impact BES Cyber System is that preventive controls will not be 100 percent effective in preventing threats to cyber systems. Reliability requirements CIP-008 and CIP-009 address the expectation of all stakeholders that a Bulk Electric System (BES) Reliability organization and Entity will be able to provide sufficient readiness to respond to and recover from any BES Cyber Incident affecting one or more applicable BES Cyber Systems. Building this level of resilience into the CIP reliability regulations, through formal incident response and restoration planning, testing, and documentation is an important step toward enhancing the reliability of the BES. CIP-008 establishes requirements for developing Cybersecurity Incident Response Plans (CIRP). For Medium Impact systems, stakeholders shall document procedures for identifying, determining the appropriate response to, and reporting relevant cyber incidents. CIP-008 also contains reporting requirements for specific types of incidents listed in the Standard. The overall reliability initiative objective is to provide for institution-wide awareness and rapid containment of cyber incidents to reduce reliability impact. The standard contains requirements that involve identifying roles and responsibilities for cyber incident response activities. As noted in the previous blog regarding CIP-003, it is important that roles and responsibilities are clearly defined prior to a cyber incident occurring. Expectations related to this requirement typically involve documentation of incident response plans, procedures and associated personnel training records. Additional expectations may involve documentation regarding the frequency and nature of tabletop exercises or other types of testing and validation activities that are utilized to test the effectiveness of such preparations. Regulations that establish the thresholds for defining particular types of incidents that must be reported depend on the standards and guidelines incorporated into the CIP rules. Reporting incidents is mandatory; each entity must determine, document and otherwise assess whether the criteria set for an incident has been met. Enforcement actions may be brought for failure to report reportable incidents as well as for the entity’s documentation of its decision that an incident did not need to be reported. This topic and the others that are included in subpart B stress the care and documentation that must be provided by each bank in deciding whether an incident of the type described in a particular regulation is reportable. CIP-009 focuses on the requirement for redundancy
and recovery planning for BES Cyber Systems. For Medium Impact assets, Reliability Standard CIP-009-R1 requires documented recovery plans to restore to BES Cyber Systems to a state so that business and operations can continue following a cyber attack. The plan should include procedures for recovery from backed-up data, lists of system restoration priorities, procedures for validating restored systems, and the process for engaging Operations personnel. The reliability objective is to provide continuity of control authority and timely restoration of Bulk Power System (BPS) operations. It is enforceable under this Standard that plans must be periodically tested. The standard does not prescribe the methodology for such testing, but only that plans are implemented and verified for validity. The expected evidence of conformance with this requirement is typically in the form of written test reports documenting findings, listing deficiencies noted in the plans and the corrective actions taken to address them. The enforceable expectation is that recovery capabilities and associated procedures are more than conceptual and that they can be verified and validated. Standards for incident response and recovery are closely tied to the operational reliability requirements. When a cyber incident is detected in a Medium Impact control system, it may need to be reported to Transmission Operators, Balancing Authorities, or Reliability Coordinators. Any steps taken to mitigate the incident must be consistent with established operating procedures to prevent any unintended consequences on the larger system. These standards identify the processes required, but do not specify how the system is to be operated during the incident. Violation Risk Factors for Incident Response and Recovery Requirements are the potential system impact from not identifying, documenting, treating, reporting, containing or recovering from a cyber-attack in a timely manner. In these cases, the enforcement review will assess the compliance with the associated procedure and assess whether the implementation provides the required level of resilience. Preventive controls described in CIP-008 and incident response controls described in CIP-009 are combined to describe a Layered approach to the Medium Impact (MI) regime. Controls implemented to prevent compromises of BES Cyber Systems reduce the likelihood of a compromise occurring. Controls implemented in the event a compromise is detected limit the potential impact of the compromise. The
recovery planning requirements restore systems, services and networks to a healthy state. These preventive, incident response and recovery controls are fundamental elements of the Cybersecurity reliability framework defined in the RRC.
End-of-Chapter Summary
Bureau Notice CIP-008 and CIP-009 impose binding requirements for incident response and recovery planning for Medium Impact BES Cyber Systems. By outlining incident response procedures, reporting thresholds and validating their ability to restore service, resilience and accountability are integrated into the layered cybersecurity reliability architecture that protects operational technology systems.
Chapter 9
Oversight, Audit Posture, and Enforcement Trends for Medium Impact Systems
Medium Impact BES Cyber Systems make up a substantial portion of operational technology as described in the CIP Reliability Standard. Compliance monitoring activities in this category have focused on the oversight by Regional Entities of Medium Impact BES Cyber Systems. The posture of the audits in this category is reflective of the technological diversity and complexity of operational technology as well as the ongoing evolution of the compliance requirements set forth in the CIP Reliability Standard. Medium Impact systems require compliance monitoring that includes document review, technical interviews, configuration validation and sampling of implementation evidence. Auditors may request network diagrams showing Electronic Security Perimeters (ESPs), baseline configuration of the system, access control lists (ACLs), the patch review process and any documented incident response activities. The focus is on ensuring that the documented processes actually reflect the state of the system. Reliability Standard Audit Worksheets (RSAWs) are tools to assist utilities in understanding the type of evidence that should be available for each Requirement in a reliability standard. For the Medium Impact CIP Reliability Standards, RSAWs identify the expected categories of evidence for each Requirements, such as access review records, configuration change approvals, vulnerability assessment reports, and media sanitization records. RSWs do not change the approved language of the reliability standard, but rather describe the policies of the utility with respect to traceability of evidence in the audit documentation and the level of detail included. Enforcement filings have highlighted patterns of Medium Impact compliance exposure that have been appearing in publicly released Notices of Penalty. Those include: • Misclassification under CIP-002 • Incomplete perimeter definitions under CIP-005 • Untimely patch evaluations under CIP-007 • Deficiencies in updates to baseline configurations under CIP-010. These issues highlight the need for rigorous documentation and uniform control processes throughout the system. The Medium Impact (MI) system enforcement environment has also matured over time as the controls have become more
widely adopted and accepted as standard practice. Early on, these audits uncovered basic governance issues. As the audits progressed they have shifted focus to the technical, and even the mundane, issues such as proper configuration and documentation being sufficient evidence of compliance. This evolution
is largely driven by the growing awareness of the CIP-CMI controls within the U.S. owners and operators, as well as the increasing recognition of the importance of advancing the overall cybersecurity program maturity within the enterprise. Recent topics include Regional Entity coordination and consistency of oversight. Interpretation consistency for the CIP technical requirements for establishing CIP controls is important, particularly in light of the NERC oversight reviews and the compliance monitoring program evaluations, which have highlighted issues of audit consistency and enforcement outcomes. This topic has been discussed in past public technical conferences and addressed in periodic updates to Reliability Guidelines and other NERC guidance, such as issues related to determining whether something is a Medium Impact Reliability Control or System Security Plan and associated expected evidence. The risk based compliance monitoring method of auditing affects the scope of the audit. Entities which present a higher risk because of their functional profile, past compliance record or system design will receive a more detailed technical examination. The risk-based auditing system exposes reliability risk more directly rather than conducting an equal level of scrutiny of all licencees. This module focuses on audit practices for environments described as Medium Impact. Control systems in these environments may be always on and provide a variety of operational services, including reliability, stability and other critical operations. It is possible to adequately perform an audit of control systems in Medium Impact environments without bringing down operational systems. The audit process requires sufficient validation of control system processes and activities to confirm that implemented controls are in place and that documented procedures are being followed. This regulation clarifies that Medium Impact means that the entity has Compliance Responsibility in relation to that Medium Impact Regulation. It also clarifies that CIP Reliability Critical Cybersystem Controls should be supported by documentation, system configuration, and/or implementation of governance processes that validate the existence of this layered control architecture. The Audit Posture also clarifies that controls for the cybersecurity of operational technology that support the reliability of the Bulk Electric System.
End-of-Chapter Summary
Regional Entity oversight of Medium Impact BES Cyber Systems is focused on ensuring reliable documentation, appropriate technical control and uniform implementation of the Required CIP v5 Revision 4 and 5 or later version(s) controls in a layered approach. The compliance monitoring activities of conducting audits and RSAW facilitated review of the evidence with selective risk-based enforcement of controls enhances Cybersecurity of operational technology environments.
FROM THE FIELD
The Region tells you what they're going to look at, in the audit notice. Programs that read the notice carefully and prepare specifically rarely get surprised.
Audit findings against Medium Impact programs cluster around the same handful of standards every cycle. Knowing the cluster is most of the preparation.
Chapter 10
Medium Impact Systems and the Operational Reliability Interface
Medium Impact BES Cyber Systems frequently reside at the intersection of cybersecurity governance and real-time operational control. Control centers, generation control systems, substation automation platforms, and related infrastructure are not abstract information technology environments. They are embedded in operational workflows that support frequency control, voltage management, contingency mitigation, and restoration coordination. The institutional design of the Medium Impact CIP framework must therefore coexist with operational imperatives. Operational technology environments prioritize availability and deterministic performance. Control systems often operate continuously and may not tolerate frequent reboot cycles, intrusive scanning, or unplanned configuration changes. The CIP standards applicable to Medium Impact systems recognize this constraint by emphasizing documented processes, risk evaluation, and justified exceptions rather than mandating rigid technical prescriptions. The enforceable expectation is disciplined governance aligned with reliability continuity. Cybersecurity controls must integrate with operational authority structures. For example, implementation of multi factor authentication for interactive remote access under CIP-005 must be compatible with time sensitive operational troubleshooting. Patch evaluation timelines under CIP-007 must account for maintenance windows and coordination with operations personnel. Configuration change management under CIP-010 must align with outage scheduling and reliability coordinator visibility where applicable. The interface between cybersecurity and operations becomes particularly evident during incident response. A cybersecurity event affecting a Medium Impact control system may necessitate coordination among cybersecurity staff, operations personnel, and reliability leadership. Decisions regarding system isolation, restoration sequencing, or temporary control modifications must balance cyber containment with system stability. The standards do not prescribe tactical decisions in these scenarios. They require that entities have defined processes and documented authority pathways. Medium Impact classification also intersects with transmission and generation operational planning. Facilities meeting specified capacity or voltage thresholds often play meaningful roles in contingency analysis and restoration sequencing. The cybersecurity controls applied to these systems therefore protect assets that are operationally significant even if they are not designated as High Impact under CIP-002. The risk allocation embedded in the Medium Impact tier reflects this operational relevance. The layered control architecture, governance under CIP-003, electronic perimeter controls under CIP-005, physical protections under CIP-006, system security management under CIP-007, configuration discipline under
CIP-010, information protection under CIP-011, and resilience planning under CIP-008 and CIP-009, forms a cohesive structure. Each layer mitigates a distinct threat vector while preserving the availability required for reliable operation. The institutional balance lies in ensuring that security measures reinforce, rather than impair, control authority. Technological evolution continues to influence this interface. Increased automation, expanded remote monitoring, and integration of distributed resources introduce additional connectivity pathways. As operational architectures evolve, the Medium Impact classification and associated controls must be applied consistently to new configurations. The standards provide a structured mechanism for doing so through periodic review of asset categorization and baseline configuration updates. The durability of the Medium Impact framework rests on its integration into operational culture. Cybersecurity is not positioned as an external overlay. It is embedded within reliability governance. Audit and enforcement experience reinforce this integration by evaluating whether cybersecurity controls are aligned with operational realities and consistently implemented. Medium Impact BES Cyber Systems represent a central tier in the cybersecurity reliability regime. They protect operational environments whose compromise could degrade Bulk Electric System performance. The standards governing these systems reflect an institutional judgment that layered, risk-based controls are necessary to sustain reliable operation in an increasingly digital grid environment.
End-of-Chapter Summary
Medium Impact BES Cyber Systems operate at the intersection of cybersecurity governance and real time operational control. The layered CIP control architecture is designed to protect operational technology environments while preserving availability
and reliability authority. Through risk-based classification and integrated control requirements, the Medium Impact framework embeds cybersecurity resilience within the broader Bulk Electric System reliability structure.
Glossary
Glossary
The following terms are defined in the NERC Glossary of Terms and are reproduced verbatim as published. Only terms used within this volume are included.
Bulk Electric System (BES) - As defined by the NERC Reliability Standards.
BES Cyber Asset - A Cyber Asset that, if rendered unavailable, degraded, or misused, would, within 15 minutes of its required operation, misoperation, or non-operation, adversely impact one or more facilities, systems, or equipment, which, if destroyed, degraded, or otherwise rendered unavailable when needed, would affect the reliable operation of the Bulk Electric System.
BES Cyber System - One or more BES Cyber Assets logically grouped by a responsible entity to perform one or more reliability tasks for a functional entity.
Cyber Asset - Programmable electronic devices and communication networks including hardware, software, and data.
Electronic Security Perimeter (ESP) - The logical border surrounding a network to which BES Cyber Systems are connected using a routable protocol.
Physical Security Perimeter (PSP) - The physical border surrounding locations in which BES Cyber Systems reside, and for which physical access is controlled.
High Impact BES Cyber System - As defined by the criteria in CIP-002.
Medium Impact BES Cyber System - As defined by the criteria in CIP-002.
Low Impact BES Cyber System - As defined by the criteria in CIP-002.
Interactive Remote Access - User-initiated access by a person to a BES Cyber System from a Cyber Asset that is not an Intermediate System.
The definitions above are reproduced from the NERC Glossary of Terms as publicly published. Readers are responsible for consulting the most current official version of the NERC Glossary for authoritative language and updates.
About the Author
About the Author
Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.
Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk based oversight of utility mitigation activities.
Rob’s compliance authority extends across both reliability and cybersecurity domains. His work on Critical Infrastructure Protection includes audit and oversight of CIP-002 through CIP-014, scope and impact classification reviews, ESP and PSP boundary analysis, and program assessments for entities with Low, Medium, and High Impact Cyber Systems.
Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.
About Energy Compliance, Inc.
About Energy Compliance, Inc.
Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.
Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.
We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don’t staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.
Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.
CIP-Focused Services
Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor’s question, not the consultant’s binder.
Energy Compliance services related to Critical Infrastructure Protection include, but are not limited to:
- CIP applicability and scope analysis (CIP-002 through CIP-014)
- Cyber asset and BES Cyber System identification and impact classification
- Electronic Security Perimeter and Physical Security Perimeter boundary analysis
- CIP governance and program assessments
- Integration of cybersecurity oversight with broader reliability programs
- Audit and enforcement support for CIP findings (non-advocacy)
- CIP framework reviews, gap analyses, and improvement plans
- Training focused on CIP framework, requirements, and audit expectations
- Executive and board-level CIP awareness briefings
Services are tailored to the functional role, system impact, and regulatory posture of each organization.
ENERGY COMPLIANCE PROFESSIONAL REFERENCE
Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.
N ERC CO MP LIANC E S ENIO R ADV ISO RY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.
I ND USTRY ENGAGEMENT AUD IT D EFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.
CONNECT WITH US Scan to visit
E N E RGY COMPL IAN CE , IN C. · EC-WP-202 · © 2026 · AL L RIGHTS RES E RV E D