NERC CIP and the AIC Kits
North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards apply to bulk electric system cyber systems. Analog Informatics Corporation (AIC) kits help with electronic access, credentials, configuration records, incident records, and evidence. Physical security, recovery, and the registered entity's compliance program stay with the entity. The regional entity decides compliance.

Reliability Standards
| Standard | What the Kit Does |
|---|---|
| CIP-002 BES Cyber System Categorization | Categorization stays with the entity. The Assessment Binder stores the record. |
| CIP-003 Security Management Controls | Policy stays with the entity. Kit records support the plan. |
| CIP-004 Personnel and Training | Training and attestation, and account removal in the kit when directed. Personnel risk assessment stays with the entity. |
| CIP-005 Electronic Security Perimeters | Jump as the intermediate system for interactive remote access, with another step beyond a password. |
| CIP-006 Physical Security of BES Cyber Systems | Physical security stays with the entity. |
| CIP-007 System Security Management | Privileged Identity Management for shared and default accounts, Audit for security events, and configuration compliance. |
| CIP-008 Incident Reporting and Response Planning | Incident Response records and alerts. Reporting to authorities stays with the entity. |
| CIP-009 Recovery Plans for BES Cyber Systems | Recovery stays with the entity. |
| CIP-010 Configuration Change Management and Vulnerability Assessments | Configuration compliance records baselines and changes. Vulnerability assessment is planned. |
| CIP-011 Information Protection | Document sharing vault and validated cryptography on kit paths. |
| CIP-012 Communications between Control Centers | Control center links stay with the entity. |
| CIP-013 Supply Chain Risk Management | Supplier review stays with the entity. Vendor remote access can go through Jump. |
| CIP-014 Physical Security | Physical security stays with the entity. |
| CIP-015 Internal Network Security Monitoring | Network monitoring sensors stay with the entity. Kit audit can feed the entity's monitoring system. |
See Operational Technology and IEC 62443.
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.