North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) – Standards for planning, operating, and securing North America’s Bulk Power System. Protects “Critical Cyber Assets”
There are 97 Critical Infrastructure Protection controls in the current NERC CIP Reliability Standard. 78 have been placed into inactive status, and over 20 are in various stages towards adoption. As with all standards, always know the correct location for current information. We gather the content while we map to a client's organic QMS and we update our content at the start of each engagement. Migrating from out of date to current content is a common assignment for EnterpriseGRC Solutions. The live source is https://www.nerc.com/pa/Stand/Pages/CIPStandards.aspx
At the time of our last engagement, there were 82 CIP Standards (domains): 11 are subject to enforcement, 71 are inactive. The 11 domains included 25 universes and hundreds of tests, subtests, and sub-subtests all of which are publicly accessible and free. The hard part is that each domain has its own pdf. If you think you can do this without specific industry knowledge, you are wrong. Even if you do have the background, the information is merely the download of a single pdf. It's no less of a commitment than the FFIEC Examination Handbook or HIPAA HITECH. The most important aspect is the authentic assignment of owners to controls, the mapping of the corporate CMS and the relationship of assigned responsibilities to enforce and measure that enforcement.
If you have the industry background but you'd like some help to normalize the NERC CIP to programs to your other existing efforts such as NIST frameworks and CIS CSC, we are ready to help. From the perspective of mapping, here are some of the raw data exposed to help you plan your own journey, and also two major resources to perform your own mapping.
EnterpriseGRC Solutions is prepared to map your NERC CIP effort to NIST SP800-53 rev 5, CCM v4, NIST CSF 1.1, and various other relevant cybersecurity frameworks and standards.

*Please note we do not represent HITRUST content except to the extent that if you have a licensed project we will keep a record of where your documents have met with their mapped relationships. THIS CONTENT IS OUT OF DATE AND WILL UPDATE WHEN WE NEXT USE NERC CIP
Resources:
- Mapping to NIST: https://pdfs.semanticscholar.org/8fd7/e6c2bb443481a42ca303f015e32e675282af.pdf
- Mapping to CIS CSC: https://www.sans.org/media/critical-security-controls/nerc-cip-mapping-sans20-csc.pdf
BCSC-002.1 Implement a process that considers assets BCSC-002 BCSC-002.1
BCSC-002.2 Review and approve identifications BCSC-002 BCSC-002.2
The Responsible Entity shall follow the related parts. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning] Acceptable evidence includes, but is not limited to, electronic or physical dated records to demonstrate that the Responsible Entity has reviewed and updated, where necessary, the identifications required in Requirement BCSC-002.1 and its parts, and has had its CIP Senior Manager or delegate approve the identifications required in Requirement 002.1 and its parts at least once every 15 calendar months, even if it has none identified in Requirement 002.1 and its parts, as required by Requirement 002.2.
SMC-003.1 Review and obtain CIP Senior Manager approval SMC-003 SMC-003.1
Each Responsible Entity shall review and obtain CIP Senior Manager approval at least once every 15 calendar months for one or more documented cyber security policies that collectively address the related parts and their topics.
[Violation Risk Factor: Medium] [Time Horizon: Operations Planning]
Examples of evidence may include but are not limited to, policy documents; revision history, records of review, or workflow evidence from a document management system
that indicate review of each cyber security policy at least once every 15 calendar months, and documented approval by the CIP Senior Manager for each cyber security policy.
SMC-003.2 Implement one or more cybersecurity plan(s) for low impact BES Cyber Systems SMC-003 SMC-003.2
Each Responsible Entity with at least one asset identified in BCSC-002 containing low impact BES Cyber Systems shall implement one or more documented cyber security plan(s) for its low impact BES Cyber Systems that include the related tests. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning]
Note: An inventory, list, or discrete identification of low-impact BES Cyber Systems or their BES Cyber Assets is not required. Lists of authorized users are not required.Evidence shall include each of the documented cyber security plan(s) that collectively include each of the sections in the related tests and additional evidence to demonstrate implementation of the cyber security plan(s). Additional examples of evidence per section are also located in the related tests.
SMC-003.3 Identify a CIP Senior Manager and document change SMC-003 SMC-003.3
Each Responsible Entity shall identify a CIP Senior Manager by name and document any change within 30 calendar days of the change. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning]
An example of evidence may include, but is not limited to, a dated and approved document from a high level official designating the name of the individual identified as the CIP Senior Manager.
SMC-003.4 Implement a documented process to delegate authority SMC-003 SMC-003.4
The Responsible Entity shall implement a documented process to delegate authority unless no delegations are used. Where allowed by the CIP Standards, the CIP Senior Manager may delegate authority for specific actions to a delegate or delegate. These delegations shall be documented, including the name or title of the delegate, the specific actions delegated, and the date of the delegation; approved by the CIP Senior Manager, and updated within 30 days of any change to the delegation. Delegation changes do not need to be reinstated with a change to the delegator. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning]
An example of evidence may include, but is not limited to, a dated document, approved by the CIP Senior Manager, listing individuals (by name or title) who are delegated the authority to approve or authorize specifically identified items.
PT-004.1 Implement one or more documented processes that include requirement parts from the Security Awareness Program PT-004 PT-004.1
Each Responsible Entity shall implement one or more documented processes that collectively include each of the applicable requirement parts of Security Awareness Program. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning]
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of Security Awareness Program and additional evidence to demonstrate implementation as described in the Measures section.
PT-004.2 Implement one or more cyber security training program(s) PT-004 PT-004.2
Each Responsible Entity shall implement one or more cyber security training program(s) appropriate to individual roles, functions, or responsibilities that collectively includes each of the applicable requirement parts of Cyber Security Training Program. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning]
Evidence must include the training program that includes each of the applicable requirement parts of Cyber Security Training Program and additional evidence to demonstrate implementation of the program(s).
PT-004.3 Implement one or more documented personnel risk assessment program(s) PT-004 PT-004.3
Each Responsible Entity shall implement one or more documented personnel risk assessment program(s) to attain and retain authorized electronic or authorized unescorted physical access to BES Cyber Systems that collectively include each of the applicable requirement parts of the Personnel Risk Assessment Program. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning].
Evidence must include the documented personnel risk assessment programs that collectively include each of the applicable requirement parts of Personnel Risk Assessment Program and additional evidence to demonstrate implementation of the program(s).
PT-004.4 Implement one or more documented access management program(s) PT-004 PT-004.4
Each Responsible Entity shall implement one or more documented access management program(s) that collectively include each of the applicable requirement parts of Access Management Program. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning and Same Day Operations].
Evidence must include the documented processes that collectively include each of the applicable requirement parts of Access Management Program and additional evidence to demonstrate that the access management program was implemented as described in the Measures section.
PT-004.5 Implement one or more documented access revocation program(s) PT-004 PT-004.5
Each Responsible Entity shall implement one or more documented access revocation program(s) that collectively include each of the applicable requirement parts of Access Revocation. [Violation Risk Factor: Medium] [Time Horizon: Same Day Operations and Operations Planning].
Evidence must include each of the applicable documented programs that collectively include each of the applicable requirement parts of Access Revocation and additional evidence to demonstrate implementation as described in the Measures section.


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics