NERC CIP
Supply Chain Risk Management

NERC CIP NERCCIP-8: Supply Chain Risk Management (CIP-013)

Develop and implement supply chain cyber security risk management plan per CIP-013-2 (effective 1 October 2022) covering: identification and assessment of cyber security risks from vendor products and services + vendor security event notification + vendor personnel access termination notification + disclosure of vendor-known vulnerabilities + verify integrity and authenticity of software and patches + coordination of vendor remote access controls + coordination with vendors on Electronic Access Control and Monitoring Systems (EACMS). Review and approve plan at least every 15 months. Apply to high and medium impact BES Cyber Systems.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.