NERC CIP
System Security and Configuration

NERC CIP NERCCIP-5: System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)

Implement system security management per CIP-007-6 including: ports and services management + security patch management (35-day evaluation + plan for mitigating actions) + malicious code prevention + security event monitoring + system access control (shared accounts + default accounts + interactive remote access password change + account lockout). Manage configuration change management per CIP-010-4 including: baseline configuration documentation + authorization for changes + monitoring for unauthorized changes + vulnerability assessment prior to deployment + annual paper-based and 36-month active vulnerability assessment + Transient Cyber Asset and Removable Media controls.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.