An overview of the NERC CIP standards that govern cybersecurity for the North American bulk electric system.
NERC CIP (Critical Infrastructure Protection) is the mandatory, enforceable standards set for entities that own or operate parts of the North American bulk electric system — a regulatory regime with real financial penalties, unlike the largely voluntary frameworks covered in Modules 7 and 8. This module covers the CIP standard numbering scheme (CIP-002 through CIP-014), the BES Cyber System categorization process that determines which standards apply to a given asset, and how NERC CIP compliance intersects with — but doesn't replace — the broader IEC 62443/NIST CSF security program.
By the end of this module you should be able to explain why a utility's cybersecurity program has to satisfy NERC CIP as a compliance floor even when its broader security posture is already built on IEC 62443 or NIST CSF — the two are complementary, not redundant.