Project 2023-04 Modifications to CIP-003

​​​​​​​​​​​​​​​​Related Files​

Status

The drafting team is posting the final documents of CIP-003-11 – Cyber Security – Security Management Controls, but not conducting a final ballot, per the Standard Processes Manual (SPM) section 4.13, which allows the drafting team to conclude the standards action without conducting a final ballot if:

  • the previous ballot achieved at least 85% weighted segment approval;​
  • the drafting team made a good faith effort at resolving applicable objections;
  • the drafting team responded in writing to comments as required by section 4.12; and
  • the drafting team is proposing no further changes to the balloted documents. 

Consistent with these requirements, the last ballot received 93.89% approval. The drafting team has made a good faith effort to resolve objections and responded to comments in writing, including making minor corrections to two of the non-mandatory and enforceable sections of the standard.

Per SPM section 2.5: "The only mandatory and enforceable components of a Reliability Standard are the: (1) applicability, (2) Requirements, and the (3) effective dates. The additional components are included in the Reliability Standard for informational purposes and to provide guidance to Functional Entities concerning how compliance will be assessed by the Compliance Enforcement Authority." 

Background
In light of cybersecurity events and the evolving threat landscape, the NERC Board took action at its February 4, 2021 meeting to direct NERC staff, working with stakeholders, to expeditiously complete its broader review and analysis on facilities that house low impact Bulk Electric System (BES) Cyber Assets. Specifically, the degrees of risk presented by various facilities that house the low impact BES Cyber Assets and report on whether the low impact criteria should be modified. To assist in this evaluation, NERC staff assembled a team of cybersecurity experts and compliance experts representative of a cross section of industry, called the Low Impact Criteria Review Team (LICRT). The LICRT's primary purpose was to discuss the potential threat and risk posed by a coordinated cyber attack on low impact BES Cyber Systems. In its report, the LICRT documented the results of the review and analysis of degrees of risk presented by various facilities that meet the criteria that define low impact cyber facilities and recommends actions to address those risks. The Board accepted the LICRT's report at its November 2022 meeting and asked that the recommendations in the report be initiated. The Standards Committee accepted the SAR at its March 22, 2023 meeting.

Standard Affected: CIP-003-9

Purpose/Industry Need
The LICRT report recognized that low impact BES Cyber Systems may introduce BES reliability risks of a higher impact where distributed low impact BES Cyber Systems are used for a coordinated attack. The team recommended enhancing the existing low impact category to further mitigate the coordinated attack risk. The proposed project will revise CIP-003-9 to add controls to authenticate remote users, protect the authentication information in transit, and detect malicious communications assets containing low impact BES Cyber Systems with external routable connectivity. ​

Subscribe to this project's observer mailing list 
Select "NERC Email Distribution Lists" from the "Service" drop-down menu and specify “Project 2023-04 Modifications to CIP-003 Observer List” in the Description Box.


DraftActionsDatesResultsConsideration of Comments

Final Documents

CIP-003-11
Clean | Redline to last posted​ | Redline to CIP-003-10  (Last Board Approved)

Implementation Plan

Supporting Materials

Technical Rationale

VRF/VSL Justifications

RSAW​








Info






11/13/24
Draft 4

CIP-003-11
Clean | Redline to CIP-003-10​ (Last Board Approved)​​​

Implementation Plan​

Supporting Materials

Technical Rationale​

Unofficial Comment Form

VRF/VSL Justi​fications​


Additional Ballot

Ballot Open Reminder​

Info 

Vote



10/01/24 - 10/10/24

​Ballot Results​​

 CIP-003-11​

 Implementation Plan​​

 Non-binding Poll Results​ 















Consideration of Comments
​Comment Period

Info

Submit Comments​


​09/11/24 - 10/10/24


Comments Received
Draft 3

CIP-003-11
Clean | Redline to Last Posted​ | Redline to CIP-003-9 (Last Approved)​

Implementation Plan​

CIP-003-12
Red​line to CIP-003-9​

Implementation Plan

Supporting Materials

Technical Rationale​

Unofficial Comment Form​

VRF/VSL Justi​fications

Summary of Changes


Additional Ballot

Ballot Open Reminder​

Info

Vote​




07/2/24 - 07/11/24


​Ballot Results​​

 CIP-003-11​ and CIP-003-12​

 Implementation Plan​​

 Non-binding Poll Results​ 



















Consideration of Comments

Comment Period

Info

Submit Comments​


06/12/24 - 07/11/24​


Comments Received
Draft 2

CIP-003-A
Clean | Redline to Last Posted | Redline to Last Approved​

Implementation Plan


Supporting Materials


Technical Rationale​

Unofficial Comment Form​

VRF/VSL Justifications

Additional Ballot

Ballot Open Reminder​

Info

Vote




03/5/24 - 03/14/24

​​

Ballot Results

 CIP-003-A

 Implementation Plan​

 Non-binding Poll Results












​Comment Period

Info​

Submit Comments​


​01/30/24 - 03/14/24


​​Comments Received​

Draft 1

CIP-003-A
Clean | Redline to Last Approved

Implementation Plan​

 

Supporting Materials

Technical Rationale​​

Unofficial Comment Form

VRF/VSL Justifications

    



   Supplemental Drafting Team Nominations​


​Initial Ballot

Ballot Open Reminder​

Info

Vote​​



11/28/23 - 12/07/23




Ballot Results


































Join Ballot Pools​​


10/24/23 - 11/27/23
​​
​​






​​​​​Comments Received​

​Comment Period

Info

Sub​mit Comments​


10/24/23 - 12/07/23​
Supplemental Nomination Period

Info​

Submit Nominations​​

10/24/23 - 12/07/23
​​
​​Standard Authorization Request
Clean | Redline​
​​Accepted by the Standards Committee
​07/27/23

Standard Authorization Request

Low Impact Criteria Review Team Report​​

Supporting Materials

Unofficial Com​ment Form (Word)

Comment Period

Info

Submit Comments





03/31/23 - 05/15/23







Drafting Team Nominations

Supporting Materials

Unofficial Nomination Form (Word) 

Nomination Period

Info​

Submit Nominations​​


​03/31/23 - 05/15/23