CIP-011 · Information Protection

CIP-011: know where your BCSI lives, and protect it everywhere.

CIP-011 requires an information protection program for BES Cyber System Information: identify it, protect it wherever it is stored, transmitted or used, and prevent it from leaking when equipment is reused or disposed of.

Enforceable nowCIP-011-3 (effective January 1, 2024)
Next versionCIP-011-4.1 (July 1, 2028) with the virtualization package
Applies toHigh impact and medium impact BES Cyber Systems and associated EACMS, PACS and PCAs

Requirements at a glance

R1

Information protection program

Document one or more methods to identify BCSI, and methods to protect and securely handle BCSI to mitigate the risk of compromising its confidentiality, in storage, in transit and in use, including when a vendor or cloud provider holds it.

R2

Cyber Asset reuse and disposal

Before releasing applicable Cyber Assets that contain BCSI for reuse outside your control, or disposing of them, take action to prevent unauthorized retrieval of the BCSI (for example sanitizing or destroying the media).

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

Your compliance data is BCSI

It is easy to forget that the CIP program itself generates some of your most sensitive information: ESP diagrams, asset inventories with IP addresses, firewall rules and vulnerability assessment results. Wherever that information is kept (a file share, a SaaS compliance platform, email attachments) is a BCSI storage location that needs protection and access control.

Cloud and third-party storage after CIP-011-3

CIP-011-3 made it possible to use cloud and third-party services for BCSI, but it did not make it free. You need methods that address the provider’s access to your data, encryption and key management, and how you would recover or delete the data. That is real program work, and it is one of the reasons many small utilities choose on-premises tools.

Disposal without surprises

Retired laptops, failed drives and RMA’d equipment are classic BCSI leaks. Put reuse and disposal into your change process, sanitize or destroy the media, and keep the record with the asset.

Evidence auditors typically ask for

  • Your BCSI identification method(s) and how information is labeled or registered
  • A register of BCSI repositories and storage locations, including third-party or cloud services
  • Protection controls for storage, transit and use (encryption, access controls, key management)
  • Access records tying BCSI access to CIP-004 R6 authorizations
  • Sanitization or destruction records for reused or disposed Cyber Assets

How CIP Sentry helps with CIP-011

Information Protection module

Keep your BCSI protection program and a register of where BCSI lives and who can access it.

BCSI stays on-premises

CIP Sentry itself runs inside your network. Your CIP records, which are themselves BCSI, never go to a vendor cloud, so there is no third-party storage to justify.

Access linked to CIP-004

BCSI access authorizations and revocations are tracked with the rest of each person's access.

Disposal records

Asset lifecycle changes (move, disposal) go through the change process with the evidence attached.

CIP-011 FAQ

Can we store BCSI in the cloud?

Since CIP-011-3 and CIP-004-7 took effect on January 1, 2024, yes, provided your information protection program covers the risks of storage, transit and use with the provider, and BCSI access is managed under CIP-004 R6. Many entities still prefer on-premises tools to avoid that extra program work.

Is our compliance tool's data BCSI?

Very often, yes. Network diagrams, asset lists with IP addresses, perimeter details and security configurations are typical BCSI. Treat your compliance repository as a BCSI repository.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-011 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.