The Lighthouse: CIP low impact from the ground up – Part 8.3-9, Electronic access controls for CIP-003-9

By Lew Folkerth, Principal Reliability Consultant, External Affairs

NERC Reliability Standard CIP-003 (Security Management Controls) Requirement R2 requires implementation of cyber security plans for low impact BES Cyber Systems. Requirement R2 calls Attachment 1 of the standard into scope, which is where the detailed plan requirements, broken into six sections, reside. I will cover each of these sections in-depth as part of this series. As of March 19, 2026, we’re dealing with three approved versions of CIP-003. In this article, part of my look at Section 3, Electronic Access Controls, I’m diving specifically into CIP-003-9.

CIP-003-9

Note: CIP-003-9, Attachment 1, Section 3, is the same as version 8.

CIP-003-9, Attachment 1, Section 3, Electronic Access Controls

For each asset containing low impact BES Cyber System(s) identified pursuant to CIP002, the Responsible Entity shall implement electronic access controls to:

3.1 Permit only necessary inbound and outbound electronic access as determined by the Responsible Entity for any communications that are:

i. between a low impact BES Cyber System(s) and a Cyber Asset(s) outside the asset containing low impact BES Cyber System(s);

ii. using a routable protocol when entering or leaving the asset containing the low impact BES Cyber System(s); and

iii. not used for timesensitive protection or control functions between intelligent electronic devices (e.g., communications using protocol IECTR61850905 RGOOSE).

3.2 Authenticate all Dialup Connectivity, if any, that provides access to low impact BES Cyber System(s), per Cyber Asset capability.

What you must do

• Develop, document and implement a cyber security plan to control electronic access to either the entire physical asset or the BES Cyber Systems within the physical asset. The decision of whether to protect the entire physical asset or each individual BES Cyber System can be determined independently for each physical asset. Note that a documented Electronic Security Perimeter is not necessary at the low impact level.

o Your cyber security plan must include controls to limit electronic access to only that traffic you deem necessary. This applies to both inbound and outbound traffic. You must identify the traffic permitted (usually by network address or range, network protocol and network port number), and the reason the traffic is considered “necessary.” For example, just saying “Port 20000 is DNP3” is insufficient, as the statement does not say why DNP3 is needed. “Port 20000 is DNP3 which is used to communicate with the historian at the control center” provides the operational need.

o Your cyber security plan must include a method to retain evidence of compliance:

▪ CIP-003-9, Section C (Compliance), Part 1.2 (Evidence Retention) requires evidence retention for three years.

o  Keep in mind that an audit period can be six years for the low impact Requirements. CIP-003 Section C (Compliance) Part 1.2 says, “For instances where the evidence retention period specified below is shorter than the time since the last audit, the CEA may ask an entity to provide other evidence to show that it was compliant for the full time period since the last audit.” You should have a means of providing evidence prior to the three-year retention period. For evidence that is not voluminous it may be simplest to keep the evidence for the period since the last audit. See my suggestion below about using change control for access control rules. I have seen some cases where an entity tries to generate evidence on-the-fly to demonstrate control of electronic access. This may be sufficient for the date the evidence is generated, but an audit team may ask for evidence of compliance for any date in the audit period. On-the-fly evidence will not suffice for such a request.

• Develop, document and implement a cyber security plan to authenticate all Dial-up Connectivity that provides access to low impact BES Cyber Systems. If you do not permit Dial-up Connectivity, ensure your plan documents this. Land-line connectivity is hard to install and easy to detect, but wireless connectivity is easy to install and hard to detect. Make sure your cyber security plan has provisions for detecting wireless access.

 

What you should do

• Implement, through your cyber security plan, a change control system for your electronic access control device (e.g., firewall).

• Include in your cyber security plan a provision to periodically review the configuration (e.g., firewall rules) of your access control device to ensure each rule has a business need identified and that obsolete rules are removed.

• Include in your cyber security plan a process to periodically examine the network traffic entering and leaving the physical asset to ensure electronic access controls are working as intended.

 

CIP-003-9 became effective April 1, 2026, adding Attachment 1, Section 6, Vendor Electronic Remote Access Security Controls.

CIP-003-9, Attachment 1, Section 6, Vendor Electronic Remote Access Security Controls

For assets containing low impact BES Cyber System(s) identified pursuant to CIP002, that allow vendor electronic remote access, the Responsible Entity shall implement a process to mitigate risks associated with vendor electronic remote access, where such access has been established under Section 3.1. These processes shall include:

6.1        One or more method(s) for determining vendor electronic remote access;

6.2        One or more method(s) for disabling vendor electronic remote access; and

6.3        One or more method(s) for detecting known or suspected inbound and outbound malicious communications for vendor electronic remote access.

 

What you must do

• Include in your cyber security plan a provision for determining (detecting and identifying) all remote access by a vendor.

• Include in your cyber security plan a provision for disconnecting existing vendor remote access sessions and disabling future vendor remote access sessions.

• Include in your cyber security plan a provision for detecting malicious communications during remote access by a vendor.

 

What you should do

• Since “vendor” in this section is not a defined term, you should prepare for your audit team taking a broad view of the term. One example I’ve been involved in is the use of “staff augmentation,” meaning using non-employees to perform tasks related to low impact BES Cyber Systems. My recommendation is that a non-employee with remote access to low impact BES Cyber Systems should be treated as a vendor unless they meet these qualifications:

o The non-employee is subject to the same hiring screening as an employee (e.g., background check),

o The non-employee undergoes the same training as an employee before being granted access,

o The non-employee uses company-issued issued equipment (e.g., laptop) and that equipment is managed as if it is employee equipment.

• When implementing detection of malicious communications, I suggest you implement this detection for all communications. This will prepare you for CIP-003-11, which will require this.

 

To read about CIP-003-10, click here, and to read about CIP-003-11, click here.