White Paper

Beyond the Electronic Security Perimeter: Preparing for CIP-015 Compliance

As regulatory standards expand from guarding boundaries to monitoring internal operations, electric utilities must adapt. Achieving compliance requires a defensible internal network monitoring strategy supported by rigorous documentation and clear baselines. This transition presents significant logistical hurdles, but starting early lets utilities build operational resilience ahead of enforcement deadlines.


For years, electric utilities have built cybersecurity programs around protecting the electronic security perimeter. NERC CIP-005 established the controls utilities use to manage electronic access to critical operational technology (OT) environments, including network segmentation, firewalls, remote access controls and continuous logging.

CIP-015-1 introduces another layer to that strategy. Rather than focusing primarily on preventing unauthorized access at the perimeter, CIP-015-1 requires applicable utilities to establish internal network security monitoring (INSM) to improve visibility into activity occurring inside protected environments.

That shift has significant implications for utilities preparing for compliance. Organizations need to determine which network data feeds to collect, how anomalous activity will be detected and evaluated, how monitoring decisions will be documented, and what evidence will need to be available during an audit.

For utilities with a large number of substations, legacy OT systems and limited communications bandwidth, those decisions cannot wait until the compliance deadline is imminent.

 

Read More  

CIP-015 Changes the Focus

CIP-005 and CIP-015 should not be viewed as competing requirements. Together, they create a more layered approach to cybersecurity.

CIP-005 establishes electronic boundaries and controls designed to restrict access to BES cyber systems. CIP-015 extends visibility inside those boundaries by requiring utilities to establish processes for monitoring network activity and identifying anomalous behavior.

Under CIP-015-1, applicable high- and medium-impact BES cyber systems with external routable connectivity will require documented INSM processes. These processes include selecting network data feeds using a risk-based rationale, establishing methods for detecting anomalous network activity, and defining how detected activity will be evaluated.

The challenge for utilities is therefore not limited to purchasing a monitoring platform. The larger task is developing a defensible monitoring strategy that can be implemented across operational environments and demonstrated during an audit.

Audit Readiness Starts With the Monitoring Strategy

One of the most important elements of CIP-015 preparation is documentation. Utilities will need to document the network data feeds included in their monitoring strategy and the rationale behind those decisions. They will need processes for detecting and evaluating anomalies and maintaining evidence associated with the monitoring program.

That means many decisions utilities make before deployment are particularly important:

  • Which communication paths and assets present the greatest risk?
  • What network traffic should be monitored?
  • What constitutes normal network behavior?
  • How will anomalous activity be identified and investigated?
  • Where will monitoring data be stored?
  • How will alerts and other evidence be retained?
  • Who will be responsible for reviewing and responding to identified activity?
  • How will changes to the network be reflected in established baselines?

A mock audit or readiness assessment, conducted before implementation is complete, can help identify gaps in these areas. That gives utilities time to address documentation, technology and process issues before they become compliance findings.

Establishing a Useful Network Baseline

Effective internal network monitoring depends on understanding what normal activity looks like.

A network baseline documents typical communications within an operational environment, including expected communication paths, protocols and traffic patterns. Establishing that baseline generally requires observing the network during normal operating conditions while accounting for activities such as planned outages or major maintenance events that may temporarily alter traffic.

Once established, the baseline must be updated continually as legitimate network modifications occur. Utilities will need processes to review alerts, determine whether new activity represents an authorized change, and update baseline documentation to reflect the new normal.

A well-maintained baseline can help security teams distinguish meaningful anomalies from expected operational changes and reduce unnecessary alert volume.

Technology Is Only Part of the Equation

Utilities have several options for gaining visibility into internal OT communications. Network test access ports (TAPs) can passively copy traffic from selected network links and forward that traffic to monitoring platforms without disrupting production communications. Embedded monitoring capabilities, such as industrial network sensors, can also provide asset and communication visibility directly from compatible network infrastructure.

Although these technologies support CIP-015 objectives, neither approach removes the need for thoughtful architecture and operating processes. Utilities need to account for legacy equipment, available rack space and power, communications bandwidth, data storage, network architecture, and the number of sites that ultimately require monitoring.

At scale, indiscriminate data collection can create its own problems. Full packet replication across large utility environments can generate substantial data volumes, increase storage and bandwidth requirements, and contribute to alert fatigue.

A risk-based approach can help utilities prioritize the communication paths and assets that provide the greatest security value rather than attempting to monitor every possible connection.

Connecting INSM, SIEM and Security Operations

Internal network monitoring becomes more valuable when it is connected to a broader security operations process.

Telemetry and alerts generated by INSM platforms can be integrated with security information and event management (SIEM) platforms. This allows security teams to correlate OT network activity with information from firewalls, servers, endpoint tools and other security systems.

Security operations center personnel can then review alerts, investigate potential incidents and coordinate response activities with personnel who understand the operational environment.

For many utilities, this coordination among cybersecurity, compliance, engineering, telecommunications and operations may be one of the more significant organizational changes associated with CIP-015.

Compliance Dates Are Years Away, But Implementation Takes Time

Full compliance for applicable high- and medium-impact systems located in control centers and backup control centers is required beginning Oct. 1, 2028. Other applicable medium-impact systems follow on Oct. 1, 2030.

Those dates can give the impression that utilities have significant time remaining. In practice, implementation likely will require time-consuming hardware procurement, network engineering, site access, outage planning, sensor deployment, data architecture, procedure development, personnel training and testing across numerous locations. Legacy infrastructure and remote sites can further stretch those timelines.

Utilities that begin by assessing existing infrastructure, identifying monitoring gaps and establishing a risk-based implementation road map will be better positioned to spread investment and deployment work over time, rather than approaching CIP-015 as a deadline-driven technology project.

Preparing Now for CIP-015

CIP-015 represents an evolution in how utilities are expected to demonstrate the security of critical operational environments. Protecting the electronic perimeter remains essential, but utilities also will need to demonstrate they can identify and evaluate suspicious activity occurring inside that perimeter.

Preparation should begin with more than a technology selection. Utilities should understand their current network visibility, establish a defensible monitoring strategy, identify the evidence that will be required during an audit, and create a realistic implementation road map that accounts for the operational realities of their systems.

By addressing those questions early, utilities can approach CIP-015 as an opportunity to strengthen cybersecurity monitoring and operational resilience, not merely another compliance deadline.


Authors

Beaux Gonzales

Beaux Gonzales

Assistant Telecommunications Engineer

Adam Holl

Adam Holl

Staff Telecommunications Engineer

Andrew Shimamoto

Andrew Shimamoto

Senior Telecommunications Engineer