Templates
Regulatory
NERC CIP Compliance Checklist
📋

NERC CIP Compliance Checklist

1
Identify critical cyber assets related to the Bulk Electric System (BES)
2
Document processes for each identified critical cyber asset
3
Create a list of all personnel with access to BES Cyber Assets
4
Establish and document cyber security policies
5
Set up a security awareness program for personnel with unescorted physical access to BES Cyber Assets
6
Generate and implement procedures for electronic access controls to BES Cyber Assets
7
Develop a process for change management and configuration monitoring of BES Cyber Assets
8
Implement incident response planning
9
Review and update all relevant documentation regularly
10
Carry out self-certifications of compliance
11
Perform a risk assessment of BES Cyber Assets
12
Create a recovery plan for BES Cyber Assets
13
Implement physical security plan for protection of BES Cyber Assets
14
Identify and analyze potential vulnerabilities of BES Cyber Assets
15
Implement a patch management process for updating and modifying BES Cyber Assets
16
Approval: Risk Assessment
17
Train the relevant personnel on the implemented security policies
18
Monitor the access to BES Cyber Assets regularly
19
Approval: Security Policies
20
Address any identified non-compliance issues