CIP-011

BCSI in the cloud or on-premises? Choosing a CIP compliance tool after CIP-011-3

CIP-011-3 and CIP-004-7 made cloud storage of BES Cyber System Information possible. That doesn't make it free. How to weigh SaaS and on-premises CIP compliance tools.

· 6 min read · CIP Sentry

Your CIP compliance tool holds some of the most sensitive information your utility has: asset inventories with IP addresses, Electronic Security Perimeter diagrams, firewall rules, vulnerability assessment results and incident records. In CIP terms, much of it is BES Cyber System Information (BCSI).

Since January 1, 2024, CIP-011-3 and CIP-004-7 have allowed BCSI to be stored with third parties, including cloud providers, under the right controls. So should your compliance tool be SaaS or on-premises?

What the 2024 changes actually did

CIP-011-3 R1 now expects your information protection program to address BCSI in storage, in transit and in use, including when a vendor holds it. CIP-004-7 moved BCSI access management into a new R6, focused on provisioned access: who can obtain and use the BCSI, rather than where the server sits. Together, they created a compliant path for cloud storage.

What cloud storage of BCSI still requires

None of this is impossible. Large utilities do it. For a team of one or two, it is real work that doesn’t make the grid more reliable.

The on-premises case

An on-premises tool keeps BCSI inside the protections you already operate: your network, your access control and your backups. There is no third-party storage to describe in the CIP-011 program, no provider personnel access to assess, and the tool keeps working if the vendor has an outage.

The tradeoffs are real too: you need a server, someone to apply updates, and backups you test. Modern on-premises tools reduce this with guided installs, automatic database backups and one-step updates.

Questions to ask any vendor

  1. Where is our data stored, and who at your company can access it?
  2. Does the product make any outbound connections (telemetry, license checks, AI services)?
  3. How do we verify the integrity of your software before installing it (CIP-010 R1.6)?
  4. How will you notify us of incidents and vulnerabilities (CIP-013 R1.2)?
  5. Will you complete the NATF Energy Sector Supply Chain Risk Questionnaire?
  6. If you use AI, where does the model run, and can it change compliance dates or facts?
  7. What happens to our data, and our ability to use the tool, if your company disappears?

Our view

We built CIP Sentry on-premises because we think small and mid-size utilities shouldn’t have to take on extra CIP-011 and CIP-013 work just to organize their compliance program. But the right answer depends on your team, your IT capabilities and your risk appetite. Ask the questions above of every vendor, including us: our answers are in the Trust Center.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.