CIP-015 Changes the Focus
CIP-005 and CIP-015 should not be viewed as competing requirements. Together, they create a more layered approach to cybersecurity.
CIP-005 establishes electronic boundaries and controls designed to restrict access to BES cyber systems. CIP-015 extends visibility inside those boundaries by requiring utilities to establish processes for monitoring network activity and identifying anomalous behavior.
Under CIP-015-1, applicable high- and medium-impact BES cyber systems with external routable connectivity will require documented INSM processes. These processes include selecting network data feeds using a risk-based rationale, establishing methods for detecting anomalous network activity, and defining how detected activity will be evaluated.
The challenge for utilities is therefore not limited to purchasing a monitoring platform. The larger task is developing a defensible monitoring strategy that can be implemented across operational environments and demonstrated during an audit.