OT

Teaching Operational Technologies

Core Frameworks โ€” Student Guide

โ† Course Navigation
Sector Compliance ยท Mandatory Standard

NERC CIP-008 โ€” Cyber Security Incident Reporting & Response Planning

A student's walk-through of the only mandatory, legally enforceable framework in this course's Core Frameworks set โ€” what it requires, who enforces it, how it relates to the sibling frameworks, and how to teach it.

โ† Back to Course Navigation

Quick Facts

Type
Mandatory Reliability Standard
Governing Body
NERC (ERO), under FERC oversight
Current Version
CIP-008-6
Applies To
Responsible Entities' BES Cyber Systems
Test Cycle (R2)
At least every 15 months
Fastest Report Window
As little as 1 hour after determination
01

Foundations

02

How to Use This Guide

  1. 1

    Skim the Quick Facts panel first. It compresses the entire standard into six numbers โ€” type, authority, version, scope, test cycle, and report window.

  2. 2

    Read Section 03 before the requirements. Seeing where CIP-008 sits relative to the other three Core Frameworks pages makes R1โ€“R3 easier to place mentally.

  3. 3

    Work through Section 04's four stage cards in order โ€” Plan โ†’ Test โ†’ Improve โ†’ Report. They mirror the standard's own R1 โ†’ R2 โ†’ R3 structure, with reporting layered across all three.

  4. 4

    Treat Section 05 as a lookup, not a read-through. Come back to it whenever a term โ€” BES Cyber System, ESP, EACMS โ€” is unfamiliar.

  5. 5

    If you're prepping to teach, start at Section 08. That's where the lesson plan actually lives; everything above it is the material the lesson plan draws from.

03

Positioning: CIP-008 vs. the Other Core Frameworks

IEC 62443, NIST SP 800-82, and MITRE ATT&CK for ICS all answer how to design, manage, or understand attacks against control systems. CIP-008 answers a different question entirely: did you report and respond the way the law requires? The table below makes that split explicit.

AttributeNERC CIP-008IEC 62443 / SP 800-82 / ATT&CK for ICS
TypeMandatory Reliability StandardVoluntary guidance, best practice, or threat-intel reference
Origin / AuthorityNERC (the ERO), under FERC statutory oversightISA/IEC standards body, NIST (U.S. federal), MITRE (federally funded R&D)
Primary Question"Did you plan, test, and report this the way CIP-008 requires?""How do you design, manage risk for, or detect attacks against this system?"
EnforcementAudited by Regional Entities; violations carry financial penaltiesNo inherent penalty โ€” adoption is a business or contractual decision
Typical PairingSupplies the must-report obligation once an incident is detectedSupply the design (62443), risk-management (800-82), and detection/classification (ATT&CK for ICS) that feed into that report
04

The Standard โ€” Requirements R1โ€“R3 & Reporting

CIP-008-6 is built from three requirements plus a reporting obligation (Attachment 1) woven through R1. The stage colors below deliberately reuse this site's existing strand colors: Plan borrows the purple used for "Frameworks," Test borrows the blue used for "Protocols," Improve borrows the green used for "Operations," and Report borrows the red used for "Threats" โ€” because reporting is the one step where the clock is against you.

R1Plan
Incident Response Plan(s)
Define roles, responsibilities, incident-handling procedures, and the criteria for classifying an event as a Reportable Cyber Security Incident.
R2Test
Implementation & Testing
Test the plan(s) at least once every 15 months โ€” a paper drill, an operational (tabletop) exercise, or an actual incident response all count.
R3Improve
Review, Update & Notify
Review after each test or real incident, document lessons learned, update the plan within the required window, and notify personnel when roles change.
Att. 1Report
Incident Reporting
Notify the E-ISAC and CISA of Reportable Cyber Security Incidents and attempts, with defined content and timing woven into the R1 plan.

R1 โ€” Incident Response Plan(s)

R2 โ€” Implementation & Testing

R3 โ€” Review, Update & Notification

Reporting Obligation (Attachment 1 & 2)

05

Definitions & Scope

These terms recur throughout CIP-008 and the wider CIP suite. Students who are shaky on them will misclassify almost every scenario you give them.

BES Cyber System

One or more BES Cyber Assets logically grouped to perform one or more reliability tasks for the Bulk Electric System.

BES Cyber Asset

A Cyber Asset that, if rendered unavailable, degraded, or misused, would affect the reliable operation of the BES within 15 minutes.

Electronic Security Perimeter (ESP)

The logical border surrounding a network to which BES Cyber Systems are connected, using a routable protocol.

EACMS

Electronic Access Control or Monitoring Systems โ€” the devices that enforce or log access across the ESP, and are themselves in reporting scope.

Cyber Security Incident

A malicious act or suspicious event that compromises, or attempts to compromise, an ESP, a Physical Security Perimeter, or a BES Cyber System.

Reportable Cyber Security Incident

A Cyber Security Incident that meets Attachment 1's compromise or attempted-compromise criteria โ€” the specific subset of incidents CIP-008 requires you to report externally.

Responsible Entity

The registered entity (generation, transmission, balancing authority, etc.) legally obligated to comply with the applicable CIP standard.

Impact Rating (High / Medium / Low)

CIP-002's categorization of a BES Cyber System's criticality โ€” the rating that determines exactly which CIP-008 obligations apply to it.

06

Related CIP Standards

CIP-008 does not stand alone โ€” it depends on several other CIP standards for scope, policy, and the raw signals that surface an incident in the first place.

StandardFocusHow It Feeds CIP-008
CIP-002BES Cyber System CategorizationDetermines which systems' incidents even need a plan and reporting path
CIP-003Security Management ControlsEstablishes the governing policy framework CIP-008's plan sits under
CIP-004Personnel & TrainingEnsures the people executing the incident response plan are trained and vetted
CIP-005Electronic Security Perimeter(s)Defines the ESP boundary whose compromise is what triggers CIP-008 reporting
CIP-007System Security ManagementSupplies the logging and alerting that surfaces a Cyber Security Incident to begin with
CIP-010Configuration Change Mgmt. & Vulnerability AssessmentBaseline data used to scope "functional impact" when writing the report
CIP-011Information ProtectionGoverns how incident-related BES Cyber System Information is handled and shared
07

Enforcement & Compliance

CIP-008 is enforced through NERC's Compliance Monitoring and Enforcement Program (CMEP). NERC, certified by FERC as the Electric Reliability Organization, delegates day-to-day audits to Regional Entities (e.g., WECC, RF, SERC, Texas RE, NPCC), which review evidence, conduct audits, and process self-reports.

Who Audits

Regional Entities conduct scheduled audits and investigate self-reports and complaints under NERC's CMEP framework.

Penalty Structure

Penalties are assessed per violation, per day, up to a statutory cap that has historically reached $1,000,000 โ€” actual penalties vary widely and are published in NERC's public Notice of Penalty filings.

Self-Reporting & Mitigation

Entities that self-report a violation and file a credible mitigation plan typically receive more favorable treatment than those found non-compliant through audit.

Evidence Trail

Everything in R1โ€“R3 โ€” the plan, the test records, the review documentation โ€” exists because it is also the audit evidence an entity must produce on request.

๐Ÿ“– Teaching Note

This is a natural bridge to Lesson 9's audit-evidence and POA&M content: everything a Responsible Entity does under R1โ€“R3 exists twice โ€” once as an operational safeguard, and once as the paper trail an auditor will actually ask to see.

08

Classroom Uses

Reportable-or-Not Drill

Give students a redacted incident timeline. Using Attachment 1's criteria, they decide: Reportable Cyber Security Incident, attempt, or neither โ€” and justify the call in writing.

Attachment 1 Notification Draft

Students draft the initial E-ISAC/CISA notification for a scenario incident โ€” functional impact, attack vector, level of intrusion โ€” inside the applicable reporting window.

R2 Test Design

Assign a hypothetical Medium-impact BES Cyber System. Students design a 15-month test (tabletop, operational exercise, or citing an actual incident) and justify the choice.

Cross-Framework Mapping

Take a documented incident already mapped to MITRE ATT&CK for ICS tactics (see that framework's page) and mark exactly where technical detection ends and the CIP-008 reporting clock begins.

โš  Scenario-based compliance analysis only โ€” no real entity data
09

Sources & Further Reading

This page is a teaching summary of a publicly available Reliability Standard, not a reproduction of NERC's standard text or a compliance determination. Specific requirement numbers, timelines, and penalty figures should be verified against the current official CIP-008 standard before use in any real compliance context โ€” per this course's own Safeguards policy on faculty review of generated content.