| CIP-002 | Critical Cyber Assets
|
 |  | CIP 002 R1 |  |
Critical Asset (CA) Identification Methodology
|
 | | CIP-002 R2 | |
Critical Asset (CA) Identification
|
 | | CIP-002 R3 | |
Critical Cyber Asset (CCA) Identification
|
 | | CIP-002 R4 | |
Annual Approval of CA & CCA Lists
|
| CIP-003 | Security Management Controls |
 | | CIP-003 R1 | | Cyber Security Policy
|
 | | CIP-003 R2 | | Leadership
|
 | | CIP-003 R3 | | Exceptions
|
 | | CIP-003 R4 | | Information Protection
|
 | | CIP-003 R5 | | Access Control
|
 | | CIP-003 R6 | | Change Control and Configuration Management
|
| CIP-004 | Personel & Training
|
 | | CIP-004 R1 | | Awareness
|
 | | CIP-004 R2 | | Training
|
 | | CIP-004 R3 | | Personnel Risk Assessment
|
 | | CIP-004 R4 | | Access
|
| CIP-005 | Electronic Security
|
 | | CIP-005 R1 | | Electronic Security Perimeter (ESP)
|
 | | CIP-005 R2 | | Electronic Access Controls
|
 | | CIP-005 R3 | |
Monitoring Electronic Access |
 | | CIP-005 R4 | |
Cyber Vulnerability Assessment |
 | | CIP-005 R5 | |
Documentation Review and Maintenance |
| CIP-006 | Physical Security
|
 | | CIP-006 R1 | |
Physical Security Plan |
 | | CIP-006 R2 | |
Physical Access Controls |
 | | CIP-006 R3 | |
Monitoring Physical Access |
 | | CIP-006 R4 | |
Logging Physical Access |
 | | CIP-006 R5 | |
Access Log Retention |
 | | CIP-006 R6 | |
Maintenance and Testing |
| CIP-007 | Systems Security Management
|
 | | CIP-007 R1 | | Test Procedures
|
 | | CIP-007 R2 | |
Ports and Services |
 | | CIP-007 R3 | |
Security Patch Management |
 | | CIP-007 R4 | |
Malicious Software Prevention |
 | | CIP-007 R5 | |
Account Management |
 | | CIP-007 R6 | |
Security Status Monitoring |
 | | CIP-007 R7 | |
Disposal or Redeployment |
 | | CIP-007 R8 | |
Cyber Vulnerability Assessment |
 | | CIP-007 R9 | | Documentation
Review and Maintenance |
| CIP-008 | Incedent Reporting & Response Planning |
 | | CIP-008 R1 | |
Cyber Security Incident Response
Plan |
 | | CIP-008 R2 | |
Cyber
Security Incident Documentation |
| CIP-009 | Recovery Plans
|
 | | CIP-009 R1 | | Recovery Plan
|
 | | CIP-009 R2 | | Recovery Exercises
|
 | | CIP-009 R3 | |
Change Control |
 | | CIP-009 R4 | |
Backup and Restore |
 | | CIP-009 R5 | |
Testing Backup Media |