The North American Electric Reliability Corporation (NERC) is an international regulatory authority tasked with maintaining the safety and reliability of our nation’s bulk power systems. To accomplish that mission, NERC has issued a series of Critical Infrastructure Protection (CIP) Security Standards that serve as the minimum security requirements for power generation, transmission, and distribution enterprises.
The NERC CIP standards are developed using a results-based approach that focuses on performance, risk management, and entity capabilities. It includes guidelines for testing, repair, and prevention of security issues of critical infrastructure assets.
RedTeam Security’s consultants are highly experienced in the field of critical infrastructure penetration testing and helping clients meet the NERC-CIP Standards. We can help you identify and analyze vulnerabilities in your networks, applications, industrial systems, and facilities and put you on the right path to correct them.
On November 22, 2013, NERC approved what’s known as CIP Version 5, the current set of standards for mitigating cyber risks to the bulk power system. Click on any of the standards below to see NERC’s full explanation and requirements.
Please note these standards are authored directly by NERC and are not affiliated with RedTeam Security. Many thanks to NERC for making this important security documentation available for public dissemination. For additional information, please visit NERC.com.
Strengthening critical infrastructure security and resilience depends on public and private critical infrastructure owners and operators making risk-informed decisions when allocating limited resources.
With RedTeam Security’s critical infrastructure penetration testing, risk evaluation, and risk management planning help, critical infrastructure owners, operators, and partners can more effectively meet the CIP Standards to maintain the integrity of the bulk power system.
Learn more about RedTeam Security’s advanced Application, Network and Physical Penetration Testing, Social Engineering and Red Teaming services.