CIP Standards Basics Flashcards
Goal is to understand the general basis of each CIP standard. (14 cards)
CIP-002
Asset Identification and Classification
- Facility Classification
- Asset Identification
- Inventory Approval
CIP-003
Policy and Governance
- Designation of Senior Responsible Official
- Policy Creation and Maintenance
- Policy Creation and Maintenance for Low-Impact Assets
CIP-004
Personnel and Training
- Security Awareness
- Background Checks
- Training
- Access Management
- Access Review
CIP-005
Network Security
- Creation of Electric Security Perimeters or Virtualized Equivalents
- Management of Secure Interactive Remote Access
CIP-006
Physical Security of Cyber Assets
- Physical Security Plans
- Creation and Monitoring of Physical Security Parameters
CIP-007
System Security Controls
- Patch Management
- Management of Ports and Services
- Malware Prevention
- Security Event Logging
- Management of Shared Accounts
- Password and Credential Management
CIP-008
Cyber Security Incident Response
- Basically self explanatory, just make sure the incident response is in place
CIP-009
Recovery Plans
- Continuity of Operations
- Backup and Restoration
CIP-010
Change and Vulnerability Management
- Configuration Capture and Management
- Change Management and Monitoring
- Vulnerability Management
- Management of Transient Cyber Assets
CIP-011
Protection of BES Cyber System Information
- Classification and Protection of Information
- Disposal of Media
CIP-012
Control Center Communications
CIP-013
Supply Chain Security
CIP-014
Physical Security of Key Substations
CIP-015-1
Internal Network Security Standard to Strengthen ICS Defenses (Industrial Control Systems)