The Lighthouse: CIP low impact from the ground up – Part 8.3, Developing your electronic access controls plan

By Lew Folkerth, Principal Reliability Consultant, External Affairs

In this recurring column, I explore various questions and concerns related to the NERC Critical Infrastructure Protection (CIP) Standards. I share my views and opinions with you, which are not binding. Rather, this information is intended to provoke discussion within your entity. It may also help you and your entity as you strive to improve your compliance posture and work toward continuous improvement in the reliability, security, resilience and sustainability of your CIP compliance programs. There are times that I also may discuss areas of the standards that other entities may be struggling with and share my ideas to overcome their known issues. As with lighthouses, I can’t steer your ship for you, but perhaps I can help shed light on the sometimes-stormy waters of CIP compliance.

Photo: Presque Isle Lighthouse, Presque Isle, Michigan (Lew Folkerth)

NERC Reliability Standard CIP-003 (Security Management Controls) Requirement R2 requires implementation of cyber security plans for low impact BES Cyber Systems. Requirement R2 calls Attachment 1 of the standard into scope, which is where the detailed plan requirements, broken into six sections, reside. I will cover each of these sections in-depth as part of this series. This article covers Section 3, Electronic Access Controls.

Electronic Access Controls

What are electronic access controls?

Of all the topics in Attachment 1, this is arguably the most technically complex and the one I see entities struggle with most often.

But what are electronic access controls? For the purposes of our discussion of CIP low impact protections, we are talking about protections for electronic traffic entering or leaving a physical asset containing a low impact BES Cyber System (BCS) using a routable protocol. This Section includes an exclusion for latency-sensitive routable traffic used for electric system protection functions, such as relay-to-relay communications.

While there are many possible electronic access control architectures, I’ll describe the perimeter-based approach as being the most common at the low impact level. If you want to up your game in electronic access control, check out Zero Trust Architecture as described in NIST SP800-207.

Figure 1 shows a simplified diagram of a physical asset containing low impact BES Cyber Systems (BCS). Communications within the physical asset are not in scope for Section 3. It is when routable traffic leaves the physical asset that this traffic becomes subject to access control.

Perimeter-based access control

Figure 1, perimeter-based access control

 

In the case of Figure 1, I’m showing the most common type of perimeter-based electronic access control, a firewall (denoted as “FW” in the figure above). In the case of the firewall and most other types of electronic access control, there is a device (the physical firewall device), its operating software, and its configuration (the firewall rule set).

Why are electronic access controls needed?

Our industry needs to defend against the many identified threat groups, as well as new or unidentified threats. The best way to start this defense is by implementing basic cyber hygiene, including restricting electronic access to only authorized users. Poland’s Energy Sector Incident Report – 29 December provides a recent look at an actual cyber compromise of energy assets. In this incident a firewall with vulnerable operating software was compromised and used as the entry point for the . Effective electronic access controls could have prevented this compromise.

A recent domestic example, Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure, says this:

“At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software. Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.”

Note that this compromise became not only an operational issue, but a safety issue as well.

Requirement Language

As of March 19, 2026, we’re dealing with three approved versions of CIP-003:

CIP-003-9

  • Became effective April 1, 2026
  • Added Section 6, Vendor Remote Access
  • Determine/disable vendor remote access
  • Detect malicious communications for vendor remote access

CIP-003-10

  • Effective July 1, 2028 with early adoption options Jan. 1, 2027, July 1, 2027, or Jan. 1, 2028 [Note: You must adopt all of the virtualization standards at the same time]
  • Part of the virtualization modifications to the CIP Standards
  • Adds protections for Shared Cyber Infrastructure and Virtual Cyber Assets

CIP-003-11

  • Effective July 1, 2029
  • Implements recommendations in the Low Impact Criteria Review Report
  • Authentication of all remote users
  • Protection of authentication information
  • Detection of malicious communications for all inbound or outbound traffic

 

The changes in CIP-003-9 resulted from the report Supply Chain Risk Assessment and are documented on the Project 2020-03 Supply Chain Low Impact Revisions site.

The CIP-003-10 revisions are a result of the virtualization modifications from Project 2016-02 Modifications to CIP Standards.

In 2022, NERC issued the Low Impact Criteria Review Report which identifies recommended changes to the low impact requirements. Project 2023-04 Modifications to CIP-003 incorporated these changes into CIP-003-11.

The effective dates for these three versions are laid out in Figure 2, CIP-003 Versions Timeline.

CIP-003 versions timeline

Figure 2, CIP-003 versions timeline

 

In this article we’ll be looking at CIP-003’s Electronic Access Controls. We’ll look at Attachment 1, Section 3, Electronic Access Controls and Section 6, Vendor Electronic Remote Access Security Controls, for versions 9 and 10. Version 11 consolidates Section 6 into Section 3, so remote access will be discussed as part of Version 11’s Section 3.

 

Choose the version you would like to read:

🔗 CIP-003-9

🔗 CIP-003-10

🔗 CIP-003-11

 

Conclusion

The changes from CIP-003-9 or CIP-003-10 to CIP-003-11 are substantial. In order to ensure compliance, advocate for a proactive approach within your organization so you are ready for the July 1, 2029, effective date.