NERC NERC Critical Infrastructure Protection (CIP) 2 — Questions and Answers
Question 1: What is the Electronic Security Perimeter (ESP) as defined under NERC CIP?
- A physical fence around a substation
- The logical border surrounding a network to which BES Cyber Systems are connected (Correct answer)
- The firewall protecting corporate email servers
- A regulatory boundary between NERC regions
Correct answer: The logical border surrounding a network to which BES Cyber Systems are connected
An ESP is the logical border surrounding a network to which BES Cyber Systems are connected and requiring controlled access.
Question 2: Under CIP-007, how frequently must responsible entities review or update ports and services on BES Cyber Systems?
- Every 6 months
- At least once every 35 calendar days
- At least once every 15 calendar months (Correct answer)
- Annually
Correct answer: At least once every 15 calendar months
CIP-007 requires review of ports and services at least once every 15 calendar months to disable unnecessary ports.
Question 3: Which impact level classification under NERC CIP carries the most stringent security requirements?
- Low impact
- Medium impact
- High impact (Correct answer)
- Critical impact
Correct answer: High impact
High impact BES Cyber Systems face the most stringent CIP requirements, including controls for all applicable CIP standards.
Question 4: What does NERC CIP-005 govern?
- Recovery plans for BES Cyber Systems
- Electronic security perimeters and remote access management (Correct answer)
- Physical security of control centers
- Personnel and training requirements
Correct answer: Electronic security perimeters and remote access management
CIP-005 requires responsible entities to define and manage Electronic Security Perimeters and control remote access to BES Cyber Systems.
Question 5: A 'Transient Cyber Asset' under CIP-010 is best described as:
- A permanently installed device in a control center
- A cyber asset that is temporarily connected to a BES Cyber System for 30 or fewer consecutive days (Correct answer)
- Any laptop used by field technicians
- A backup server kept offsite
Correct answer: A cyber asset that is temporarily connected to a BES Cyber System for 30 or fewer consecutive days
A Transient Cyber Asset is one connected temporarily (30 or fewer consecutive days per calendar year) to a BES Cyber System.
Question 6: Which NERC CIP standard specifically addresses personnel and training requirements?
- CIP-004 (Correct answer)
- CIP-007
- CIP-011
- CIP-014
Correct answer: CIP-004
CIP-004 requires personnel risk assessment, security awareness, training, and access management for BES Cyber Systems.
What is the Electronic Security Perimeter (ESP) as defined under NERC CIP?