Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 29 pages
Exam (elaborations)

NERC CIP V7 STANDARDS AND REQUIREMENTS|QUESTIONS AND 100% CORRECT WELL DETAILED ANSWERS|LATEST UPDATE!!!!!2026|GUARANTEED PASS|GRADED A+|VERIFIED

Document preview thumbnail
Preview 3 out of 29 pages

NERC CIP V7 STANDARDS AND REQUIREMENTS|QUESTIONS AND 100% CORRECT WELL DETAILED ANSWERS|LATEST UPDATE!!!!!2026|GUARANTEED PASS|GRADED A+|VERIFIED

Content preview

CIP-002-5.1 - ANSWER BES Cyber System Categorization



CIP-002 R1 - ANSWER Each Responsible Entity shall implement a process that
considers each of the following assets for purposes of parts 1.1 through 1.3: Control Centers
and backup Control Centers, Transmission stations and substations, Generation resources,
Systems and facilities critical to system restoration, including Blackstart Resources and
Cranking Paths and initial switching requirements, Special Protection Systems that support
the reliable operation of the Bulk Electric System; and For Distribution Providers



CIP-002 R1.1 - ANSWER Identify each of the high impact BES Cyber Systems according
to Attachment 1, Section 1, if any, at each asset;



CIP-002 R1.2 - ANSWER Identify each of the medium impact BES Cyber Systems
according to Attachment 1, Section 2, if any, at each asset;



CIP-002 R1.3 - ANSWER Identify each asset that contains a low impact BES Cyber
System according to Attachment 1, Section 3, if any (a discrete list of low impact BES Cyber
Systems is not required).



CIP-002 R2.1 - ANSWER Review the identifications in Requirement R1 and its parts
(and update them if there are changes identified) at least once every 15 calendar months,
even if it has no identified items in Requirement R1,




1

,CIP-002 R2.2 - ANSWER Have its CIP Senior Manager or delegate approve the
identifications required by Requirement R1 at least once every 15 calendar months, even if it
has no identified items in Requirement R1.



CIP-003-7 - ANSWER Security Management Controls



CIP-003 R1 - ANSWER Each Responsible Entity shall review and obtain CIP Senior
Manager approval at least once every 15 calendar months for one or more documented
cyber security policies that collectively address the following topics:



CIP-003 R2 - ANSWER Each Responsible Entity with at least one asset identified in CIP-
002 containing low impact BES Cyber Systems shall implement one or more documented
cyber security plan(s) for its low impact BES Cyber Systems that include the sections in
Attachment 1.



CIP-003 R3 - ANSWER Each Responsible Entity shall identify a CIP Senior Manager by
name and document any change within 30 calendar days of the change.



CIP-003 R4 - ANSWER The Responsible Entity shall implement a documented process
to delegate authority, unless no delegations are used. Where allowed by the CIP Standards,
the CIP Senior Manager may delegate authority for specific actions to a delegate or
delegates. These delegations shall be documented, including the name or title of the
delegate, the specific actions delegated, and the date of the delegation; approved by the CIP
Senior Manager; and updated within 30 days of any change to the delegation. Delegation
changes do not need to be reinstated with a change to the delegator.



CIP-003 Attachment 1 Section 2 - ANSWER Lows Physical Security Controls: Each
Responsible Entity shall control physical access, based on need as determined by the
Responsible Entity, to (1) the asset or the locations of the low impact BES Cyber Systems
within the asset, and (2) the Cyber Asset(s), as specified by the Responsible Entity, that
provide electronic access control(s) implemented for Section 3.1, if any.




2

, CIP-003 Attachment 1 Section 3 - ANSWER Lows Electronic Access Controls: For each
asset containing low impact BES Cyber System(s) identified pursuant to CIP-002, the
Responsible Entity shall implement electronic access controls to:

3.1 Permit only necessary inbound and outbound electronic access as determined by the
Responsible Entity for any communications that are:

between a low impact BES Cyber System(s) and a Cyber Asset(s) outside the asset containing
low impact BES Cyber System(s); using a routable protocol when entering or leaving the
asset containing the low impact BES Cyber System(s); and

not used for time-sensitive protection or control functions between intelligent electronic
devices (e.g., communications using protocol IEC TR- 61850-90-5 R-GOOSE).

3.2 Authenticate all Dial-up Connectivity, if any, that provides access to low impact BES Cyber
System(s), per Cyber Asset capability.



CIP-003 Attachment 1 Section 1 - ANSWER Lows Cyber Security Awareness: Each
Responsible Entity shall reinforce, at least once every 15 calendar months, cyber security
practices (which may include associated physical security practices).



CIP-003 Attachment 1 Section 4 - ANSWER Lows Cyber Security Incident Response:
Each Responsible Entity shall have one or more Cyber Security Incident response plan(s),
either by asset or group of assets, which shall include:

4.1 Identification, classification, and response to Cyber Security Incidents;

4.2 Determination of whether an identified Cyber Security Incident is a Reportable Cyber
Security Incident and subsequent notification to the Electricity Sector Information Sharing
and Analysis Center (ES-ISAC), unless prohibited by law;

4.3 Identification of the roles and responsibilities for Cyber Security Incident response by
groups or individuals;

4.4 Incident handling for Cyber Security Incidents;

4.5 Testing the Cyber Security Incident response plan(s) at least once every 36 calendar
months by: (1) responding to an actual Reportable Cyber Security Incident; (2) using a drill or
tabletop exercise of a Reportable Cyber Security Incident; or (3) using an operational
exercise of a Reportable Cyber Security Incident; and




3

Document information

Uploaded on
January 27, 2026
Number of pages
29
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$14.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
THESTUDYVAULT
3.3
(16)
Sold
125
Followers
5
Items
12887
Last sold
5 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions