ESP-005.1 Implement one or more documented processes for Electronic Security Perimeter ESP-005 ESP-005.1
Each Responsible Entity shall implement one or more documented processes that collectively include each of the applicable requirement parts of Electronic Security Perimeter. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning and Same Day Operations].
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of Electronic Security Perimeter and additional evidence to demonstrate implementation as described in the Measures section.
ESP-005.2 Implement one or more documented processes for Interactive Remote Access Management ESP-005 ESP-005.2
Each Responsible Entity allowing Interactive Remote Access to BES Cyber Systems shall implement one or more documented processes that collectively include the applicable requirement parts, where technically feasible, in Interactive Remote Access Management. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning and Same Day Operations].
Evidence must include the documented processes that collectively address each of the applicable requirement parts of Remote Access Management and additional evidence to demonstrate implementation as described in the Measures section.
PSBCS-006.1 Implement one or more documented physical security plan(s) PSBCS-006 PSBCS-006.1
Each Responsible Entity shall implement one or more documented physical security plan(s) that collectively include all of the applicable requirement parts of Physical Security Plan. [Violation Risk Factor: Medium] [Time Horizon: Long Term Planning and Same Day Operations].
Evidence must include each of the documented physical security plans that collectively include all of the applicable requirement parts of Physical Security Plan and additional evidence to demonstrate implementation of the plan or plans as described in the Measures section.
PSBCS-006.2 Implement one or more documented visitor control program(s) PSBCS-006 PSBCS-006.2
Each Responsible Entity shall implement one or more documented visitor control program(s) that include each of the applicable requirement parts of Visitor Control Program. [Violation Risk Factor: Medium] [Time Horizon: Same Day Operations].
Evidence must include one or more documented visitor control programs that collectively include each of the applicable requirement parts of Visitor Control Program and additional evidence to demonstrate implementation as described in the Measures section.
PSBCS-006.3 Implement one or more documented Physical Access Control System maintenance and testing program(s) PSBCS-006 PSBCS-006.3
Each Responsible Entity shall implement one or more documented Physical Access Control System maintenance and testing program(s) that collectively include each of the applicable requirement parts of Physical Access Control System Maintenance and Testing Program. [Violation Risk Factor: Medium] [Time Horizon: Long Term Planning].
Evidence must include each of the documented Physical Access Control System maintenance and testing programs that collectively include each of the applicable requirement parts of Physical Access Control System Maintenance and Testing Program and additional evidence to demonstrate implementation as described in the Measures section.
SSM-007.1 Implement one or more documented process(es) for Ports and Services SSM-007 SSM-007.1
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of Ports and Services. [Violation Risk Factor: Medium] [Time Horizon: Same Day Operations.]
Evidence must include the documented processes that collectively include each of the applicable requirement parts of Ports and Services and additional evidence to demonstrate implementation as described in the Measures section.
SSM-007.2 Implement one or more documented process(es) for Security Patch Management SSM-007 SSM-007.2
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of Security Patch Management. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning].
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of Security Patch Management and additional evidence to demonstrate implementation as described in the Measures section.
SSM-007.3 Implement one or more documented process(es) for Malicious Code Prevention SSM-007 SSM-007.3
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of Malicious Code Prevention. [Violation Risk Factor: Medium] [Time Horizon: Same Day Operations].
Evidence must include each of the documented processes that collectively include each of the applicable requirement parts of Malicious Code Prevention and additional evidence to demonstrate implementation as described in the Measures section.
SSM-007.4 Implement one or more documented process(es) for Security Event Monitoring SSM-007 SSM-007.4
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of Security Event Monitoring. [Violation Risk Factor: Medium] [Time Horizon: Same Day Operations and Operations Assessment.]
Evidence must include each of the documented processes that collectively include each of the applicable requirement parts of Security Event Monitoring and additional evidence to demonstrate implementation as described in the Measures section.
SSM-007.5 Implement one or more documented process(es) for System Access Control SSM-007 SSM-007.5
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of System Access Controls. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning].
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of System Access Controls and additional evidence to demonstrate implementation as described in the Measures section.
IRRP-008.1 Document one or more Cyber Security Incident response plan(s) IRRP-008 IRRP-008.1
Each Responsible Entity shall document one or more Cyber Security Incident response plan(s) that collectively include each of the applicable requirement parts of Cyber Security Incident Response Plan Specifications. [Violation Risk Factor: Lower] [Time Horizon: Long Term Planning].
Evidence must include each of the documented plan(s) that collectively include each of the applicable requirement parts of Cyber Security Incident Response Plan Specifications.
IRRP-008.2 Implement each of the documented Cyber Security Incident response plans IRRP-008 IRRP-008.2
Each Responsible Entity shall implement each of its documented Cyber Security Incident response plans to collectively include each of the applicable requirement parts of Cyber Security Incident Response Plan Implementation and Testing. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning and Real-Time Operations].
Evidence must include, but is not limited to, documentation that collectively demonstrates the implementation of each of the applicable requirement parts of Cyber Security Incident Response Plan Implementation and Testing.
IRRP-008.3 Maintain each of the Cyber Security Incident response plans IRRP-008 IRRP-008.3
Each Responsible Entity shall maintain each of its Cyber Security Incident response plans according to each of the applicable requirement parts of Cyber Security Incident Response Plan Review, Update, and Communication. [Violation Risk Factor: Lower] [Time Horizon: Operations Assessment].
Evidence must include, but is not limited to, documentation that collectively demonstrates maintenance of each Cyber Security Incident response plan according to the applicable requirement parts of Cyber Security Incident.
RPBCS-009.1 Have one or more documented recovery plan(s) RPBCS-009 RPBCS-009.1
Each Responsible Entity shall have one or more documented recovery plan(s) that collectively include each of the applicable requirement parts of Recovery Plan Specifications. [Violation Risk Factor: Medium] [Time Horizon: Long Term Planning].
Evidence must include the documented recovery plan(s) that collectively include the applicable requirement parts of Recovery Plan Specifications.
RPBCS-009.2 Implement the documented recovery plan(s) RPBCS-009 RPBCS-009.2
Each Responsible Entity shall implement its documented recovery plan(s) to collectively include each of the applicable requirement parts of Recovery Plan Implementation and Testing. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning and Real-time Operations.]
Evidence must include, but is not limited to, documentation that collectively demonstrates implementation of each of the applicable requirement parts of Recovery Plan Implementation and Testing.
RPBCS-009.3 Maintain each of the recovery plan(s) RPBCS-009 RPBCS-009.3
Each Responsible Entity shall maintain each of its recovery plan(s) in accordance with each of the applicable requirement parts of Recovery Plan Review, Update and Communication. [Violation Risk Factor: Lower] [Time Horizon: Operations Assessment].
Acceptable evidence includes, but is not limited to, each of the applicable requirement parts of Recovery Plan Review, Update, and Communication.
CCC-010.1 Implement one or more documented process(es) for Configuration Change Management CCC-010 CCC-010.1
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of Configuration Change Management. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning].
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of Configuration Change Management and additional evidence to demonstrate implementation as described in the Measures section.
CCC-010.2 Implement one or more documented process(es) for Configuration Monitoring CCC-010 CCC-010.2
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of Configuration Monitoring. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning].
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of Configuration Monitoring and additional evidence to demonstrate implementation as described in the Measures section.
CCC-010.3 Implement one or more documented process(es) for Vulnerability Assessments CCC-010 CCC-010.3
Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts of Vulnerability Assessments. [Violation Risk Factor: Medium] [Time Horizon: Long-term Planning and Operations Planning]
Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts of Vulnerability Assessments and additional evidence to demonstrate implementation as described in the Measures section.
CCC-010.4 Implement one or more documented plan(s) for Transient Cyber Assets and Removable Media CCC-010 CCC-010.4
Each Responsible Entity, for its high impact and medium impact BES Cyber Systems and associated Protected Cyber Assets, shall implement, except under CIP Exceptional Circumstances, one or more documented plan(s) for Transient Cyber Assets and Removable Media that include the sections of Plans for Transient Cyber Assets and Removable Media. [Violation Risk Factor: Medium] [Time Horizon: Long-term Planning and Operations Planning]
Evidence shall include each of the documented plan(s) for Transient Cyber Assets and Removable Media that collectively include each of the applicable sections of Plans for Transient Cyber Assets and Removable Media and additional evidence to demonstrate implementation of the plan(s) for Transient Cyber Assets and Removable Media. Additional examples of evidence per section are also part of Plans for Transient Cyber Assets and Removable Media. If a Responsible Entity does not use Transient Cyber Asset(s) or Removable Media, examples of evidence include, but are not limited to, a statement, policy, or other documents that state the Responsible Entity does not use Transient Cyber Asset(s) or Removable Media.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics