| CIP-002 |
Identify and categorise BES Cyber Systems by impact rating |
Passive asset discovery with automatic classification proposals against your impact criteria |
Dated asset list with discovery source, categorisation rationale and change history |
| CIP-005 |
Electronic Security Perimeter with controlled, logged and encrypted remote access |
Conduit enforcement at every ESP boundary; brokered interactive remote access with full session recording |
Per-boundary flow record and a session register with user, asset, duration and recording reference |
| CIP-007 |
Ports and services, patching within 35 days, malicious-code prevention, event logging |
Continuous port and service inventory, patch-state tracking with deviation reporting, behavioural prevention on all in-scope hosts |
35-day patch cycle report with exceptions, and an unbroken security-event log with integrity attestation |
| CIP-008 |
Incident reporting and response planning, including reportable Cyber Security Incidents |
Automated incident narrative with detection, containment and notification timestamps; E-ISAC reporting template pre-filled |
Per-incident timeline and the one-hour reportability determination record |
| CIP-010 |
Configuration change management and vulnerability assessments |
Baseline configuration monitoring with change attribution to a process, a user and a work order |
Change log showing authorised versus observed configuration, with unexplained deltas isolated |
| CIP-013 |
Supply-chain risk management for BES Cyber System vendors |
Vendor access brokering, vendor software integrity checks and vendor session analytics |
Per-vendor access report with what they connected to, when, and what they did |
| CIP-015 |
Internal network security monitoring inside the Electronic Security Perimeter |
East-west sensing within the ESP with protocol-aware anomaly detection and retained flow data |
Continuous internal monitoring record with anomaly disposition and retention proof |