NERC CIP
Categorization and Governance

NERC CIP NERCCIP-1: BES Cyber System Categorization and Security Management Controls (CIP-002 + CIP-003)

Identify and categorize Bulk Electric System (BES) Cyber Systems per CIP-002-5.1a as High Impact + Medium Impact + Low Impact based on functional criteria (Control Centers + Transmission Stations + Generation Resources + Special Protection Systems + Remedial Action Schemes + Restoration). Implement security management controls per CIP-003-8 including cyber security policies + governance + delegation of authority + low-impact cyber security plans + transient cyber asset and removable media controls. Review categorization at least every 15 months and following BES changes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.