Sat, Jul 11

Scoping out the CIP “100 series”

Yesterday, the NERC “Cloud CIP” (my term) Standards Drafting Team (SDT) released about 17 documents related to the new set of about eleven standards that they plan to develop; they’re called the “100 series” standards, since they will all relate to one or two of the existing standards CIP-002 through CIP-015, with 100 added to the original number. Yesterday’s drop included four new draft standards and a revised version of CIP-002.[i] It also included a set of Definitions, plus a Technical Rationale document for each new standard and for the new Definitions[ii]. There is a 45-day comment period for NERC entities, which opened today.

Until this week, I had been told by SDT members that they were expecting to start the NERC balloting process in September (the balloting process alone will probably take at least a year. See below). Given that the SDT just finished drafting their first four standards and the definitions that go with them (two years after they started work), and that none of their standards have been previously reviewed by either NERC entities, the CIP auditors, or the NERC legal staff - I regarded their September target date as just a way of showing they have a sense of humor.

Fortunately, an SDT member told the ERCOT CIPWG yesterday that the team is now aiming for early 2027 to post the standards (all of them) for the first ballot. Given the big changes that I can already see are required, I believe even that date is optimistic - unless the SDT decides to just make the seven small, and one medium-sized, changes that I suggested would accomplish their goals, in this post last fall.

But the SDT isn’t planning on doing that. Ironically, I now realize that my eight changes will almost certainly still be needed anyway, even if the SDT is able to get something like their current standards and definitions approved. This is because the three “Cloud CIP” problems that need to be solved – in order of importance, EACMS in the cloud, PACS in the cloud and BCS in the cloud – all have to do with the current definitions of EACMS, PACS and BCS, none of which the SDT proposes to change. While it’s true that entities who fully adopt the 100 series standards will have full use of the cloud for BCS, EACMS and PACs, NERC entities who wish to stay on the existing CIP standards still won’t be able to utilize EACMS and PACS based in the cloud.

It won’t take long to add my changes to the standards when the time comes (perhaps a year, which is lightning fast in NERC Time). But if this had been done last fall, or even today, at least the EACMS and PACS problems would have been fixed a year earlier than they will be, and probably more than that.

To be blunt, the draft standards released yesterday are loaded with problems. Since I probably can’t discuss all of them in twenty posts (which I certainly don’t have time for anyway, even in the next 20 weeks), I will focus for now just on what I call the showstopper problems: the problems that are so serious that they need to be fixed before the draft standards are put up for ballot. In other words, waiting for the balloting to start and then trying to make all the needed changes is a terrible idea; it might lead to a total breakdown of the balloting process for the 100 series (after all, nobody benefits if the balloting process goes on for 2-3 years).

Instead, this SDT should do what all the other NERC CIP SDTs that I have followed have done: try their hardest to fix all the problems that have been identified before they submit the standards for balloting.

For example, the CIP version 5 balloting process (which was the last – and so far the only – time that the CIP standards were completely rewritten) required four ballots over a year, with a comment period after each ballot except the fourth one. In at least one of those periods, NERC entities submitted over 1,000 pages of comments, all of which needed to be responded to – and acted on, if needed – by the SDT[iii]. Given how much more ambitious the 100 series standards are and how many fundamental new questions they raise (far beyond those raised by CIP v5), I think even one year may be too little to allocate for the balloting process.

Here’s the first of the showstopper problems that needs to be fixed before the SDT can seriously hope to have draft versions of the CIP 100 Series that won’t be completely rejected when balloting starts. The problem is with the Technical Rationale (TR) documents. The content of those documents is incredibly dense. As an example, I recommend you read through the TR for CIP 100 Series Definitions – all 16 pages of it. As you do this, keep in mind that you’re reading not just a book review but a guidance document which may well determine whether you are in compliance with probably over one hundred CIP requirements and requirement parts.

The six TRs that were released yesterday contained a total of 54 pages – an average of nine pages per TR. Since there are still at least six standards to be developed and released, it’s safe to say there are at least six more TRs coming, so the total pages of TRs will be over 100. Keep in mind that at least one person in every NERC entity subject to CIP compliance (or at least each entity with a medium or high impact BES environment) will need to understand each word of these documents, as well as each of the standards themselves; of course, large entities will probably require 20-100 people to understand these documents very well. Does your organization have those people available?

However, there’s another point about the TRs: As far as I know, the SDT has decided not to submit these for balloting, meaning they won’t be approved NERC guidance. This means that, if you believe a certain requirement means one thing but an auditor believes something completely opposite, you can’t win the argument by pointing to the TR. As is often the case today, you will essentially need to “negotiate” a mutually acceptable interpretation of the requirement in question. Thus, the TRs will just fall into the “nice to know” bucket, nothing more – which is the case with most of what’s called compliance guidance (or guidelines) today.

Most importantly, the fact that the TRs are so voluminous, yet still will only have unofficial status, raises a big red flag about the 100 series standards themselves. Why do the standards need so much explanation? And why isn’t the SDT willing to go through the trouble of getting the TRs approved as official guidance? In other words, if the SDT thinks so much verbiage is required to make the 100 series standards comprehensible, why isn’t it willing to defend that verbiage during the balloting process?

Tom Alrich’s Blog, too is a reader-supported publication. You can view new posts for three months after they come out by becoming a free subscriber. You can also access all of my 1300 existing posts dating back to 2013, as well as support my work, by becoming a paid subscriber for $30 for one year (and if you feel so inclined, you can become a founding subscriber for $100). Whether free or paid, please subscribe.

If you would like to comment on what you have read here, I would love to hear from you. Please comment in my chat or email me at [email protected].


[i] As you may know, there are already two new versions of CIP-002: CIP-002-7 and CIP-002-8. These will both be implemented on the same day, July 1, 2028. The new version, CIP-002-9, will presumably be implemented at least a year after that date (the Implementation Plan is silent on this topic). Since CIP-002-9 will need to be in place when the 100 series requirements are implemented, this means the 100 series probably can’t be implemented until July 1, 2029, at the earliest.

[ii] It is quite odd that the SDT is even publishing a Technical Rationale for a set of definitions, let alone a 16-page Technical Rationale. The whole idea of a definition, in my opinion, is that it’s supposed to be the final word on some issue; it’s not supposed to need another document to clarify it. What if someone doesn’t understand a single word in the TR, even if it happens to have a dictionary definition? Will there need to be another TR for each ambiguous word in the first TR? And on and on?

[iii] Although the SDT can group similar comments and answer them together.

1