CIP-004-7
CIP-004-7
Title: Cyber Security — Personnel & Training
Number: CIP-004-7
Purpose:
To minimize the risk against compromise that could lead to misoperation or instability in the Bulk Electric System (BES) from individuals accessing BES Cyber Systems by requiring an appropriate level of personnel risk assessment, training, security awareness, and access management in support of protecting BES Cyber Systems.
Applicability:
- Functional Entities: For the purpose of the requirements contained herein, the following list of functional entities will be collectively referred to as “Responsible Entities.” Specific functional entities are specified explicitly where applicable:
- Facilities: These requirements are applicable to specific facilities, systems, and equipment owned by the Responsible Entities:
Effective Date: See Implementation Plan for CIP-004-7.
Background:
The CIP-004 standard exists as part of a suite of CIP Standards related to cybersecurity, requiring the identification and categorization of BES Cyber Systems and a minimum level of controls to mitigate risks. Terms like “documented processes,” “program,” and “plan” refer to specific sets of instructions or approaches required for compliance.
Requirements and Measures:
- R1: Implement a documented security awareness program reinforcing cyber security practices at least once per calendar quarter for personnel with access to BES Cyber Systems. Evidence includes documentation of reinforcement activities (e.g., emails, posters, training records).
- R2: Provide a documented cyber security training program appropriate to individual roles. Evidence includes training materials and records.
- R3: Conduct documented personnel risk assessments for access to BES Cyber Systems, including identity confirmation and criminal history checks.
- R4: Maintain access management programs to authorize, verify, and revoke access to BES Cyber Systems and associated information.
- R5: Implement access revocation processes within required timeframes.
Compliance:
Evidence retention is required for three calendar years, or longer if specified by the Compliance Enforcement Authority. Non-compliance must be documented until mitigation is complete.
Associated Documents:
None.
Version History:
- Version 1: January 16, 2006 – Initial release.
- Version 7: Effective January 1, 2024 – Enhancements for managing BES Cyber System Information (BCSI).
