CIP-005 · Electronic Security Perimeter(s)

CIP-005: a defined perimeter, and controlled ways in.

CIP-005 requires a documented Electronic Security Perimeter around routable networks with medium and high impact BES Cyber Systems, controlled access points, and tightly managed Interactive Remote Access, including for vendors.

Enforceable nowCIP-005-7 (effective October 1, 2022)
Next versionCIP-005-8 “BES Cyber System Logical Isolation” (July 1, 2028)
Applies toHigh impact and medium impact BES Cyber Systems and associated PCAs; EACMS and PACS for some parts

Requirements at a glance

R1

Electronic Security Perimeter

Every applicable Cyber Asset connected by a routable protocol resides within a defined ESP. External routable connectivity passes through an identified Electronic Access Point that permits only necessary inbound and outbound access with a documented reason, and detects known or suspected malicious communications (high impact and medium impact at Control Centers).

R2

Remote access management

Interactive Remote Access goes through an Intermediate System, is encrypted to that system, and uses multi-factor authentication. Entities must be able to determine active vendor remote access sessions and disable them.

R3

Vendor remote access for EACMS and PACS

Added in CIP-005-7: methods to determine and disable active vendor remote access sessions extend to EACMS and PACS associated with high impact and medium impact systems with ERC.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

The perimeter is only as good as its reasons

Most CIP-005 findings are not missing firewalls. They are rules nobody can explain. Every permitted inbound and outbound rule at an Electronic Access Point needs a documented reason, and “vendor requested it” rarely survives an auditor’s follow-up questions. Review rule sets together with your CIP-010 baselines so the documented configuration and the real one never drift apart.

Interactive Remote Access, done right

Interactive Remote Access has three non-negotiables: an Intermediate System, encryption that terminates at the Intermediate System, and multi-factor authentication. Map every human remote path: engineers, contractors and vendors. Automated system-to-system traffic is not Interactive Remote Access, but it still has to be justified at the access point.

Vendor sessions

You must be able to see active vendor remote access sessions and cut them off, including (since CIP-005-7) for EACMS and PACS. Test the “disable” method before an auditor asks you to demonstrate it, and keep the procedure where the on-call person can find it at 2 a.m.

Evidence auditors typically ask for

  • Network diagrams showing each ESP, its Electronic Access Points and every applicable Cyber Asset inside it
  • Firewall and access point rule sets with a documented reason for each permitted rule
  • Evidence of malicious communication detection at applicable access points
  • Intermediate System architecture, encryption settings and MFA configuration for Interactive Remote Access
  • Procedures and system evidence for determining and disabling vendor remote access sessions

How CIP Sentry helps with CIP-005

Facilities & Perimeters

Document each ESP, its access points and the systems inside it, linked to the BES Cyber Systems and facilities they protect.

Remote access connectivity

Record External Routable Connectivity, connection types and dial-up authentication per Cyber Asset, and report it with the ready-made ERT report.

Change control for rules

Changes to access points and rule sets go through the same change process, authorized by the CAO (Cyber Asset Owner), as any baseline change.

Ready for logical isolation

Perimeter records map cleanly to the CIP-005-8 logical isolation model when the virtualization package takes effect in 2028.

CIP-005 FAQ

Do low impact systems need an ESP?

No. Low impact electronic access controls are covered by CIP-003 Attachment 1 Section 3, not CIP-005.

What is an Intermediate System?

A Cyber Asset or group of assets (often a jump host) that sits between the remote user and the ESP so that Interactive Remote Access never connects directly to a BES Cyber Asset.

What does CIP-005-8 change?

Under the virtualization package, CIP-005-8 is retitled “BES Cyber System Logical Isolation” and reframes perimeter requirements to cover virtual and shared infrastructure. It becomes effective July 1, 2028.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-005 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.