StatusA 45-day formal comment period for draft one of CIP-003-A – Cyber Security – Security Management Controls, is open through 8 p.m. Eastern, Thursday, December 7, 2023.
A supplemental nomination period for drafting team members is open through 8 p.m. Eastern, Thursday, December 7, 2023. The Standards Committee is expected to appoint members to the drafting team in January, 2024. Nominees will be notified shortly after they have been appointed.
Ballot pools are being formed through 8 p.m. Eastern, Monday, November 27, 2023.
An initial ballot for the standard and implementation plan, as well as a non-binding poll of the associated Violation Risk Factors and Violation Severity Levels will be conducted November 28 – December 7, 2023.
BackgroundIn light of cybersecurity events and the evolving threat landscape, the NERC Board took action at its February 4, 2021 meeting to direct NERC staff, working with stakeholders, to expeditiously complete its broader review and analysis on facilities that house low impact Bulk Electric System (BES) Cyber Assets. Specifically, the degrees of risk presented by various facilities that house the low impact BES Cyber Assets and report on whether the low impact criteria should be modified. To assist in this evaluation, NERC staff assembled a team of cybersecurity experts and compliance experts representative of a cross section of industry, called the Low Impact Criteria Review Team (LICRT). The LICRT's primary purpose was to discuss the potential threat and risk posed by a coordinated cyber attack on low impact BES Cyber Systems. In its report, the LICRT documented the results of the review and analysis of degrees of risk presented by various facilities that meet the criteria that define low impact cyber facilities and recommends actions to address those risks. The Board accepted the LICRT's report at its November 2022 meeting and asked that the recommendations in the report be initiated. The Standards Committee accepted the SAR at its March 22, 2023 meeting.
Standard Affected: CIP-003-9
Purpose/Industry NeedThe LICRT report recognized that low impact BES Cyber Systems may introduce BES reliability risks of a higher impact where distributed low impact BES Cyber Systems are used for a coordinated attack. The team recommended enhancing the existing low impact category to further mitigate the coordinated attack risk. The proposed project will revise CIP-003-9 to add controls to authenticate remote users, protect the authentication information in transit, and detect malicious communications assets containing low impact BES Cyber Systems with external routable connectivity.
Subscribe to this project's observer mailing list Select "NERC Email Distribution Lists" from the "Service" drop-down menu and specify “Project 2023-04 Modifications to CIP-003 Observer List” in the Description Box.
CIP-003-AClean | Redline to Last Approved
Supporting MaterialsTechnical Rationale
Unofficial Comment Form
Supplemental Drafting Team Nominations
Standard Authorization Request
Low Impact Criteria Review Team Report
Unofficial Comment Form (Word)
Comment Period Info
home | account log-in/register | legal and privacy/trademark policy | site map | careers | contact us
Atlanta Office | 3353 Peachtree Road, NE Suite 600 North Tower, Atlanta, GA 30326 | 404-446-2560 Washington Office | 1401 H Street NW, Suite 410, Washington, DC 20005| 202-400-3000
Group Health Plan Transparency in Coverage Files*
*This link leads to the machine-readable files that are made available in response to the federal Transparency in Coverage Rule and includes negotiated service rates and out-of-network allowed amounts between health plans and healthcare providers. The machine-readable files are formatted to allow researchers, regulators, and application developers to more easily access and analyze data.