NERC Standards

NERC Standard CIP-001 defines requirements for Sabotage Reporting, which is beyond the scope of this configuration guide. The NERC Standards CIP-002 through CIP-012-1, covered in this guide, provide a cybersecurity framework for the identification and protection of critical cyber assets to support the reliable operation of the Bulk Electric System.

These standards recognize the differing roles of each entity in the operation of the Bulk Electric System, the criticality and vulnerability of the assets needed to manage Bulk Electric System reliability, and the risks to which they are exposed.

Business and operational demands for managing and maintaining a reliable Bulk Electric System increasingly rely on cyber assets supporting critical reliability functions and processes to communicate with each other, across functions and organizations, for services and data. This results in increased risks to these cyber assets.

Specifically, these standards include:

NERC states that the CIP reliability standards provide a comprehensive set of requirements to protect the bulk power system from malicious cyber-attacks. They require bulk power system users, owners, and operators to establish a risk-based vulnerability assessment methodology to identify and prioritize critical assets and critical cyber assets.

After the critical cyber assets are identified, the CIP reliability standards require, among other things, that the responsible entities establish plans, protocols, and controls to safeguard physical and electronic access; to train personnel on security matters; to report security incidents; and to be prepared for recovery actions. Standards are provided by TIBCO LogLogic.

Note: The CIP requirements, subrequirements, and measures outlined in the configuration guide are summarized from FERC 18 CFR Part 40, Order No. 706, and Mandatory Reliability Standards for Critical Infrastructure Protection and NERC Critical Infrastructure Protection Reliability Standards. The illustrative approaches described under each CIP Standard were obtained from FERC Order No. 706, NERC Security Guidelines for the Electricity Sector, and other resources of common IT risk management best practices. TIBCO LogLogic solution information described in the configuration guide that aligns with the CIP Standards is provided by TIBCO LogLogic.