The Lighthouse: CIP low impact from the ground up – Part 8.3-10, Electronic access controls for CIP-003-10

By Lew Folkerth, Principal Reliability Consultant, External Affairs

NERC Reliability Standard CIP-003 (Security Management Controls) Requirement R2 requires implementation of cyber security plans for low impact BES Cyber Systems. Requirement R2 calls Attachment 1 of the standard into scope, which is where the detailed plan requirements, broken into six sections, reside. I will cover each of these sections in-depth as part of this series. As of March 19, 2026, we’re dealing with three approved versions of CIP-003. In this article, part of my look at Section 3, Electronic Access Controls, I’m diving specifically into CIP-003-10.

CIP-003-10

CIP-009-10 will become effective on July 1, 2028, although there are options for early adoption that I will discuss below.

CIP-003-10, Attachment 1, Section 3, Electronic Access Controls

For each asset containing low impact BES Cyber System(s) identified pursuant to CIP-002, the Responsible Entity shall implement electronic access controls to:

3.1 Permit only necessary inbound and outbound electronic access as determined by the Responsible Entity for any communications that are:

i. Between:

• a low impact BCS; or

• An SCI that supports a low impact BCS

and a Cyber System(s) outside the asset containing:

• the low impact BCS(s); or

• the SCI that supports a low impact BCS;

ii. using a routable protocol when entering or leaving the asset containing the low impact BCS or SCI that supports a low impact BCS; and

iii. not used for time-sensitive communications of Protection Systems.

3.2        Authenticate all Dial-up Connectivity, if any, that provides access to low impact BCS or SCI that supports a low impact BCS, per system capability.

 

What you must do

Develop, document and implement a cyber security plan to control electronic access to either the entire physical asset or the BES Cyber Systems, including any Shared Cyber Infrastructure (SCI) that supports a BES Cyber System, within the physical asset. The decision of whether to protect the entire physical asset or each individual BES Cyber System and SCI can be determined independently for each physical asset. Note that a documented Electronic Security Perimeter is not necessary at the low impact level.

o Your cyber security plan must include controls to limit electronic access to only that traffic you deem necessary. This applies to both inbound and outbound traffic. You must identity the traffic permitted (usually by network address or range, network protocol and network port number), and the reason the traffic is considered “necessary.” For example, just saying “Port 20000 is DNP3” is insufficient, as the statement does not say why DNP3 is needed. “Port 20000 is DNP3 which is used to communicate with the historian at the control center” provides the operational need.

o Your cyber security plan must include a method to retain evidence of compliance:

▪ CIP-003-10, Section C (Compliance), Part 1.2 (Evidence Retention) requires evidence retention for three years.

▪ Keep in mind that an audit period can be six years for the low impact Requirements. CIP-003 Section C (Compliance) Part 1.2 says, “For instances where the evidence retention period specified below is shorter than the time since the last audit, the CEA may ask an entity to provide other evidence to show that it was compliant for the full time period since the last audit.” You should have a means of providing evidence prior to the three-year retention period. For evidence that is not voluminous it may be simplest to keep the evidence for the period since the last audit. See my suggestion below about using change control for access control rules.

▪ I have seen some cases where an entity tries to generate evidence on-the-fly to demonstrate control of electronic access. This may be sufficient for the date the evidence is generated, but an audit team may ask for evidence of compliance for any date in the audit period. On-the-fly evidence will not suffice for such a request.

• Develop, document and implement a cyber security plan to authenticate all Dial-up Connectivity that provides access to low impact BES Cyber Systems. If you do not permit Dial-up Connectivity, ensure your plan documents this. Land-line connectivity is hard to install and easy to detect, but wireless connectivity is easy to install and hard to detect. Make sure your cyber security plan has provisions for detecting wireless access.

 

What you should do

• Implement, through your cyber security plan, a change control system for your electronic access control device (e.g., firewall).
• Include in your cyber security plan a provision to periodically review the configuration (e.g., firewall rules) of your access control device to ensure each rule has a business need identified and that obsolete rules are removed.
• Include in your cyber security plan a process to periodically examine the network traffic entering and leaving the physical asset to ensure electronic access controls are working as intended.

 

CIP-003-10 retains Attachment 1, Section 6, Vendor Electronic Remote Access Security Controls.

CIP-003-10, Attachment 1, Section 6, Vendor Electronic Remote Access Security Controls

For assets containing low impact BES Cyber System(s) identified pursuant to CIP002, that allow vendor electronic remote access, the Responsible Entity shall implement a process to mitigate risks associated with vendor electronic remote access, where such access has been established under Section 3.1. These processes shall include:

6.1        One or more method(s) for determining vendor electronic remote access;

6.2        One or more method(s) for disabling vendor electronic remote access; and

6.3        One or more method(s) for detecting known or suspected inbound and outbound malicious communications for vendor electronic remote access.

 

What you must do

• Include in your cyber security plan methods for determining (detecting and identifying) all remote access by a vendor.
• Include in your cyber security plan methods for disconnecting existing vendor remote access sessions and disabling future vendor remote access sessions.
• Include in your cyber security plan methods for detecting malicious communications during remote access by a vendor.

 

What you should do

• Since “vendor” in this section is not a defined term, you should prepare for your audit team taking a broad view of the term. One example I’ve been involved in is the use of “staff augmentation,” meaning using non-employees to perform tasks related to low impact BES Cyber Systems. My recommendation is that a non-employee with remote access to low impact BES Cyber Systems should be treated as a vendor unless they meet these qualifications:

o The non-employee is subject to the same hiring processes as an employee (e.g., background check, nondisclosure, etc.),

o The non-employee undergoes the same training as an employee before being granted access,

o The non-employee uses company-issued issued equipment (e.g., laptop) and that equipment is managed as if it is employee equipment.

• When implementing detection of malicious communications, I suggest you implement this detection for all communications. This will prepare you for CIP-003-11, which will require this.

 

Early adoption of CIP-003-10

CIP-003-10 is one of the eleven revised CIP standards formally known as the Project 2016-02 Modifications to CIP Standards, or informally as the Virtualization Standards. The Implementation Plan for these standards provides for voluntary early adoption. If you do not choose early adoption, these standards will become effective on July 1, 2028, in the US. If you choose to adopt early, here’s what you need to know.

  1. You must adopt all eleven of the revised standards at the same time. There is no provision to adopt the revised standards piecemeal.
  2. You must choose one of these early adoption dates: January 1, 2027, July 1, 2027, or January 1, 2028.
  3. You must inform each Regional Entity with which you are registered of your adoption of the revised standards within 15 days after the adoption date. I recommend keeping your regions informed of your early adoption plans so you can receive any lessons learned from other entities following this path. If RF is your lead region, I recommend working with your Case Manager on this.
  4. Early adoption does not change the effective date of the virtualization standards. This means that early adoption does not change the effective date of any standard dependent on the effective date of the virtualization standards, such as CIP-002-8.

 

To read about CIP-003-9, click here, and to read about CIP-003-11, click here.