The Lighthouse: CIP low impact from the ground up – Part 8.3-11, Electronic access controls for CIP-003-11

By Lew Folkerth, Principal Reliability Consultant, External Affairs

NERC Reliability Standard CIP-003 (Security Management Controls) Requirement R2 requires implementation of cyber security plans for low impact BES Cyber Systems. Requirement R2 calls Attachment 1 of the standard into scope, which is where the detailed plan requirements, broken into six sections, reside. I will cover each of these sections in-depth as part of this series. As of March 19, 2026, we’re dealing with three approved versions of CIP-003. In this article, part of my look at Section 3, Electronic Access Controls, I’m diving specifically into CIP-003-11.

CIP-003-11

CIP-003-11 will become effective on July 1, 2029. Attachment 1 Section 6 is removed and integrated with Section 3. Additional protections are added to Section 3. As I write this, the effective date is just under three years away. This is to give you time to assess the security changes needed, budget for those changes, obtain equipment and configure and install equipment. For a medium or large entity three years may prove to be an aggressive timeline. Based on the experience with CIP-012-1, equipment lead times may become a significant factor in your implementation timeline.

CIP-003-11, Attachment 1, Section 3, Electronic Access Controls

Each Responsible Entity shall control electronic access as outlined below.

3.1 For each asset containing low impact BCS identified pursuant to CIP-002 and for Shared Cyber Infrastructure (SCI) that supports a low impact BCS, if any, where electronic access is:

i. Between:

• a low impact BCS; or

• an SCI that supports a low impact BCS

and a Cyber System(s) outside the asset containing:

• the low impact BCS(s); or

• the SCI that supports a low impact BCS;

ii. using a routable protocol when entering or leaving the asset containing the low impact BCS or SCI that supports a low impact BCS; and

iii. not used for time-sensitive communications of Protection Systems;

the Responsible Entity shall implement one or more controls, where Section 3.1. Parts (i), (ii), and (iii) are met, that:

3.1.1 Permit only necessary inbound and outbound electronic access as determined by the Responsible Entity;

3.1.2 Detect known or suspected malicious communications for both inbound and outbound electronic access;

3.1.3 Authenticate each user prior to permitting access to a network(s) containing low impact BCS or SCI that supports a low impact BCS, through which user-initiated electronic access applicable to Section 3.1 is subsequently permitted;

3.1.4 Protect user authentication information for user-initiated electronic access applicable to Section 3.1.3 while in transit between the Cyber System(s) outside the asset containing low impact BCS or SCI that supports a low impact BCS and

• the authentication system used to meet Section 3.1.3, or

• the asset containing low impact BCS or SCI that supports a low impact BCS;

3.1.5 Include one or more method(s) for determining vendor electronic access, where vendor electronic access is permitted; and

3.1.6 Include one or more method(s) for disabling vendor electronic access, where vendor electronic access is permitted.

3.2 For each asset containing low impact BCS identified pursuant to CIP-002 and for SCI that supports a low impact BCS, if any, the Responsible Entity shall implement one or more control(s) that authenticate all Dial-up Connectivity, if any, that provides access to low impact BCS or SCI that supports a low impact BCS, per system capability.

CIP-003-11 includes significant changes from CIP-003-10. Version 11 adds detection of malicious communications, user authentication prior to permitting network access, and protection of user authentication information. Provisions for controlling vendor electronic access are moved from Section 6 to Section 3.

Figures 4-7 are adapted from Technical Rationale for Reliability Standard CIP-003-11. In each of the figures I reference the standard and its subparts to provide guidance on addressing these as you develop your low impact protection plan. Figure 4 shows a typical method of controlling electronic access to an entire physical asset. A firewall is positioned at the electronic perimeter of the physical asset and controls electronic access to the entire physical asset. Note that Figure 4 only shows electronic access control and does not demonstrate the new requirements in the remaining parts of Section 3.

Permit only necessary electronic access

Figure 4, Permit only necessary electronic access

 

Figure 5 shows one possible method of implementing detection of malicious communication. In this case, the monitoring device is placed at a central location and communications to and from field locations route through this device.

Detect malicious communications

Figure 5, Detect malicious communications

 

User authentication must be performed before network access to low impact systems is granted. Figure 6 shows that the authentication devices must be on a separate network from the low impact systems, while Figure 7 shows a method that uses a separate network protected by the site’s firewall. Remember that these diagrams are just examples of one way to implement the standard.

Authenticate each user - what not to do

Figure 6, Authenticate each user – what not to do

 

Authenticate each user prior to access

Figure 7, Authenticate each user prior to access

 

What you must do

• Develop, document and implement a cyber security plan to control electronic access to either the entire physical asset or the BES Cyber Systems within the physical asset. The decision of whether to protect the entire physical asset or each individual BES Cyber System can be determined independently for each physical asset. Note that a documented Electronic Security Perimeter is not necessary at the low impact level.

o Your cyber security plan must include controls to limit electronic access to only that traffic you deem necessary. This applies to both inbound and outbound traffic. You must identity the traffic permitted (usually by network address or range, network protocol and network port number), and the reason the traffic is considered “necessary.” For example, just saying “Port 20000 is DNP3” is insufficient, as the statement does not say why DNP3 is needed. “Port 20000 is DNP3 which is used to communicate with the historian at the control center” provides the operational need.

o Your cyber security plan must include controls to detect malicious communications. Note that this now applies to all inbound and outbound electronic access, not just vendor access. Also, while not explicitly stated, there is an implied requirement to activate your incident response plan from Section 4 to respond to “known or suspected” malicious communications.

o Your cyber security plan must include controls to authenticate each user before the user is permitted access to a network containing BES Cyber Systems. After authentication, that user may be permitted electronic access to the BES Cyber Systems on that network. The concept of a “user” here is not defined. It could be a single human, a group such as an operations center, agentic AI, or any type of automated system. The objective here is that no external access should be permitted unless authenticated.

o Your cyber security plan must include controls to protect user authentication information in transit. Figure 7 illustrates an example of the span of protection required.

o Include in your cyber security plan a provision for determining (detecting and identifying) all remote access by a vendor.

o Include in your cyber security plan a provision for disconnecting existing vendor remote access sessions and disabling future vendor remote access sessions.

o Your cyber security plan must include a method to retain evidence of compliance:

▪ CIP-003-9, Section C (Compliance), Part 1.2 (Evidence Retention) requires evidence retention for three years.

▪ Keep in mind that an audit period can be six years for the low impact Requirements. CIP-003 Section C (Compliance) Part 1.2 says, “For instances where the evidence retention period specified below is shorter than the time since the last audit, the CEA [Compliance Enforcement Authority] may ask an entity to provide other evidence to show that it was compliant for the full time period since the last audit.” You should have a means of providing evidence prior to the three-year retention period. For evidence that is not voluminous it may be simplest to keep the evidence for the period since the last audit. See my suggestion below about using change control for access control rules.

▪ I have seen some cases where an entity tries to generate evidence on-the-fly to demonstrate control of electronic access. This may be sufficient for the date the evidence is generated, but an audit team may ask for evidence of compliance for any date in the audit period. On-the-fly evidence will not suffice for such a request.

• Develop, document and implement a cyber security plan to authenticate all Dial-up Connectivity that provides access to low impact BES Cyber Systems. If you do not permit Dial-up Connectivity, ensure your plan documents this. Land-line connectivity is hard to install and easy to detect, but wireless connectivity is easy to install and hard to detect. Make sure your cyber security plan has provisions for detecting wireless access.

 

What you should do

• Implement, through your cyber security plan, a change control system for your electronic access control device (e.g., firewall).

• Include in your cyber security plan a provision to periodically review the configuration (e.g., firewall rules) of your access control device to ensure each rule has a business need identified and that obsolete rules are removed.

• Include in your cyber security plan a process to periodically examine the network traffic entering and leaving the physical asset to ensure electronic access controls are working as intended.

• Since “vendor” in this section is not a defined term, you should prepare for your audit team taking a broad view of the term. One example I’ve been involved in is the use of “staff augmentation,” meaning using non-employees to perform tasks related to low impact BES Cyber Systems. My recommendation is that a non-employee with remote access to low impact BES Cyber Systems should be treated as a vendor unless they meet these qualifications:

o The non-employee is subject to the same hiring processes as an employee (e.g., background check, nondisclosure, etc.),

o The non-employee undergoes the same training as an employee before being granted access,

o The non-employee is issued company equipment (e.g., laptop) and that equipment is managed as if it is employee equipment.

 

To read about CIP-003-9, click here, and to read about CIP-003-10, click here.