NERC NERC Critical Infrastructure Protection (CIP) 1 — Questions and Answers
Question 1: Which NERC CIP standard addresses security management controls for bulk electric system cyber systems?
- CIP-003 (Correct answer)
- CIP-006
- CIP-009
- CIP-013
Correct answer: CIP-003
CIP-003 establishes minimum security management controls to protect BES Cyber Systems.
Question 2: What is the primary purpose of NERC CIP-010?
- Physical security of BES assets
- Configuration change management and vulnerability management (Correct answer)
- Incident reporting and response planning
- Supply chain risk management
Correct answer: Configuration change management and vulnerability management
CIP-010 covers configuration change management and vulnerability management for BES Cyber Systems.
Question 3: Under NERC CIP, what does the term 'BES Cyber Asset' refer to?
- Any computer used by utility employees
- A cyber asset that, if rendered unavailable, could adversely impact BES reliability within 15 minutes (Correct answer)
- All servers within a utility's corporate network
- Any asset connected to the internet
Correct answer: A cyber asset that, if rendered unavailable, could adversely impact BES reliability within 15 minutes
A BES Cyber Asset is one whose unavailability, degradation, or misuse could adversely impact BES reliability within 15 minutes of the action.
Question 4: Which CIP standard requires responsible entities to have a physical security plan for high and medium impact BES Cyber Systems?
- CIP-005
- CIP-006 (Correct answer)
- CIP-007
- CIP-008
Correct answer: CIP-006
CIP-006 requires physical security plans to protect high and medium impact BES Cyber Systems and their associated Physical Security Perimeters.
Question 5: What must a responsible entity do within 35 days under CIP-008 after a reportable Cyber Security Incident?
- File a complaint with FERC
- Submit an after-action review report (Correct answer)
- Notify all interconnected utilities
- Implement new firewall rules
Correct answer: Submit an after-action review report
CIP-008 requires an after-action review and lessons-learned documentation submitted within 35 days of a reportable incident.
Question 6: NERC CIP-013 addresses which of the following risks?
- Wildfire risk to transmission lines
- Supply chain risk management for industrial control systems (Correct answer)
- Market manipulation by generators
- Cybersecurity of corporate IT networks
Correct answer: Supply chain risk management for industrial control systems
CIP-013 establishes requirements for supply chain risk management plans for industrial control system hardware, software, and services.
Which NERC CIP standard addresses security management controls for bulk electric system cyber systems?