The North American electric grid depends on cybersecurity standards developed by the North American Electric Reliability Corporation (NERC). Among these is the Cyber Security – Information Protection standard, CIP-011, which establishes requirements for protecting and sanitizing BES Cyber System Information in both traditional and virtualized environments. CIP-011-4 remains the currently enforceable version. The Federal Energy Regulatory Commission (FERC) has approved version 4.1, which is scheduled to become effective on July 1, 2028.
What is BES Cyber System Information?
BES Cyber System Information (BCSI) refers to information that is not available publicly and could be used to gain unauthorized access to or adversely affect the reliable operation of the Bulk Electric System (BES). Examples may include network diagrams, configuration files, access credentials, security settings, and other sensitive information associated with BES Cyber Systems.
However, it does not include individual pieces of information that by themselves do not pose a threat or could not be used to allow unauthorized access to BES Cyber Systems.
Who Falls Under CIP-011-4?
CIP-011-4 applies to all Responsible Entities with applicable BES Cyber Systems that are of high or medium impact. Such entities may include Balancing Authorities, Distribution Providers, Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, and other functional entities that own or operate Applicable Systems.
The CIP requirements apply only to high and medium-impact BES Cyber Systems and their associated systems: Electronic Access Control or Monitoring Systems (EACMS), Physical Access Control Systems (PACS), Protected Cyber Assets (PCA), and Shared Cyber Infrastructure (SCI), as applicable.
Note: R1 (Information Protection) scopes to EACMS, PACS, and SCI, while R2 (Reuse and Disposal) additionally includes PCA.
What are the Key Provisions and Structure of CIP-011-4?
CIP-011-4 is organized around two core requirements: R1 and R2. Each supports specifications around applicable systems, requirement parts, and acceptable evidence. Together, R1 and R2 form an integrated compliance framework, where R1 establishes the Information Protection program that governs how BCSI is identified and handled; R2, on the other hand, requires one or more documented processes governing the Reuse and Disposal of these systems.
Requirement R1: Information Protection
R1 focuses on establishing a documented Information Protection Program for BCSI and carries a Violation Risk Factor of Medium. The program must address two things:
- Part 1.1 requires documented methods to identify BCSI, which may include classification labels, designated storage locations, or training materials that give personnel sufficient knowledge to recognize BCSI in practice.
- Part 1.2 goes further, requiring methods to protect and securely handle BCSI to mitigate the risk of confidentiality compromise.
Requirement R2: Documented Processes for ‘Reuse and Disposal’
Under the consolidated R2, the Responsible Entity must implement one or more documented processes that include methods to prevent unauthorized retrieval of BCSI from any applicable system before its disposal or reuse outside of the systems identified in the standard.
Acceptable evidence under this requirement includes maintaining records to track sanitization actions such as Clearing, Purging, or Destroying media, as well as records of alternative approaches such as Encrypting the asset or retaining it within the Physical Security Perimeter before disposition. The mention of reuse and disposal in a single part also means organizations have greater flexibility in how they prevent unauthorized retrieval of information.
Sanitization Methods Recognized Under the NERC-CIP Standard
CIP-011-4 provides examples of methods to prevent unauthorized retrieval of BCSI from applicable systems before reuse or disposal. The standard provides examples of sanitization techniques like Clearing, Purging, and Destroying as compliant data sanitization actions, each appropriate to different media states and disposition scenarios. Refer to NIST 800-88 Rev.2 and IEEE 2883:2022 to understand Clear, Purge, Destroy.
What is Non-Compliance Under CIP-011-4?
Understanding the violation structure is as important as understanding the requirements themselves. The Violation Severity Levels (VSLs) under CIP-011-4 follow a clear escalation pattern for both R1 and R2, and the compliance teams must be familiar with where the boundaries sit.
For R1, there is no Lower or Moderate VSL. A High violation is triggered when a Responsible Entity:
- Does not implement one or more BCSI protection programs,
- Does not implement at least one method to identify BCSI under Part 1.1,
- Does not implement at least one method to protect and securely handle BCSI under Part 1.2.
Similarly, a Severe violation occurs when:
- The Responsible Entity neither documents nor implements one or more BCSI protection programs.
For R2, the escalation is similarly structured.
- A Moderate violation occurs when the entity did not include processes for reuse to prevent unauthorized retrieval of BCSI from an applicable system.
- A High violation occurs when the entity does not include disposal processes to prevent unauthorized retrieval.
- A Severe violation occurs when the entity neither documented nor implemented any processes under R2 at all.
It is worth noting that the absence of either the reuse or the disposal component independently triggers a distinct severity level. As a result, documented processes that address only one aspect of the requirement, such as disposal but not reuse, do not fully satisfy R2. Because CIP-011 is a mandatory NERC Reliability Standard approved under Section 215 of the Federal Power Act, violations may result in civil penalties of up to $1,584,648 per violation, per day (as adjusted periodically for inflation), depending on the nature and severity of the violation.
How to Develop a Documented Sanitization Process to Comply with CIP-011?
CIP-011 does not define a specific data sanitization process. It requires that processes be documented, that they include reuse and disposal considerations, and that records be kept for a minimum period of three calendar years. Hence, a defensible process should contain:
- A method for identifying which systems hold BCSI.
- A decision framework that maps each system's disposition path to the appropriate sanitization method.
- Sanitization records to capture the asset identifier, system type, sanitization method applied, date, and responsible personnel.
- A chain-of-custody log for any system removed from the Physical Security Perimeter before data sanitization is complete.
For Responsible Entities managing large inventories of BES Cyber Assets, maintaining consistent sanitization records across physical and virtual environments can be challenging. Certified tools like BitRaser can help standardize sanitization workflows while generating the documentation required to support compliance audits. The software supports both traditional storage like hard drives and virtual machines through its drive eraser and VM eraser, respectively.