NERC CIP glossary
CIP terms, in plain English.
Quick explanations of the terms you meet in every CIP standard. These paraphrase the official NERC Glossary of Terms; use the official definitions for compliance decisions.
- BES Cyber AssetBCA
- A Cyber Asset whose loss, misuse or unavailability would, within 15 minutes, adversely affect the reliable operation of the BES. See CIP-002
- BES Cyber SystemBCS
- One or more BES Cyber Assets grouped together to perform one or more reliability tasks. Impact ratings are assigned to BES Cyber Systems. See CIP-002
- BES Cyber System InformationBCSI
- Information about BES Cyber Systems that could be used to gain unauthorized access or pose a security threat, such as network diagrams, security configurations and IP addresses. General public information is not BCSI. See CIP-011
- Bulk Electric SystemBES
- Generally, transmission elements operated at 100 kV or higher and the generation, reactive and other resources connected to them, as defined (with inclusions and exclusions) by NERC.
- CIP Exceptional CircumstanceCEC
- A situation, such as a risk to life, a natural disaster or an imminent hardware failure, in which certain CIP requirements can be temporarily set aside as the standards allow.
- CIP Senior ManagerCSM
- A single, named senior official with overall authority and responsibility for leading and managing the implementation of, and continuing adherence to, the CIP standards. See CIP-003
- Compliance Monitoring and Enforcement ProgramCMEP
- The ERO Enterprise program through which Regional Entities audit, spot-check and enforce compliance with Reliability Standards.
- Control Center
- One or more facilities hosting operating personnel that monitor and control the BES in real time, for example for a Reliability Coordinator, Balancing Authority, Transmission Operator or Generator Operator. CIP-002-8 revises this definition from July 2028. See CIP-012
- Cyber Asset
- A programmable electronic device, including its hardware, software and data.
- Cyber Asset Owner (Change Authorizer Officer)CAO
- Not a NERC-defined term. Utilities use CAO for the person accountable for a group of Cyber Assets who authorizes changes to their baseline configurations under CIP-010 R1. Some call the role Cyber Asset Owner, others Change Authorizer Officer. In CIP Sentry, each group has a CAO seat, and changes need that person’s authorization. See CIP-010
- Cyber Security Incident
- A malicious act or suspicious event that compromises, or attempts to compromise, an Electronic or Physical Security Perimeter or the operation of a BES Cyber System (and, in CIP-008-6, associated EACMS and PACS). See CIP-008
- Dial-up Connectivity
- A data communication link established when the communication equipment dials a phone number and negotiates a connection.
- E-ISAC
- The Electricity Information Sharing and Analysis Center, operated by NERC. Reportable Cyber Security Incidents are reported to it and to CISA. See CIP-008
- Electronic Access Control or Monitoring SystemsEACMS
- Cyber Assets that perform electronic access control or monitoring of an Electronic Security Perimeter or BES Cyber Systems, such as firewalls, jump hosts and authentication servers. See CIP-005
- Electronic Access PointEAP
- A Cyber Asset interface on an Electronic Security Perimeter that allows routable communication between Cyber Assets outside and inside the perimeter. See CIP-005
- Electronic Security PerimeterESP
- The logical border surrounding a network to which BES Cyber Systems are connected using a routable protocol. See CIP-005
- External Routable ConnectivityERC
- The ability to access a BES Cyber System from a Cyber Asset outside its Electronic Security Perimeter via a bi-directional routable protocol connection. See CIP-005
- Interactive Remote AccessIRA
- User-initiated access by a person using a remote access client or other remote access technology from outside the Electronic Security Perimeter. See CIP-005
- Intermediate System
- A Cyber Asset or group of Cyber Assets that sits between remote users and the ESP so that Interactive Remote Access never connects directly to an applicable Cyber Asset. Often a jump host. See CIP-005
- Internal Network Security MonitoringINSM
- Monitoring network traffic inside a trusted zone, such as the ESP, to detect anomalous or unauthorized activity. Required by CIP-015 from October 2028. See CIP-015
- Low Impact BES Cyber System
- A BES Cyber System at a BES asset that does not meet the high or medium impact criteria in CIP-002 Attachment 1. Covered by CIP-003 Attachment 1. See CIP-003
- Low Impact External Routable ConnectivityLERC
- A term from earlier CIP-003 versions for routable connectivity to low impact systems. It was retired with CIP-003-7, which describes the required electronic access controls directly. See CIP-003
- Physical Access Control SystemsPACS
- Cyber Assets that control, alert or log access to a Physical Security Perimeter, such as badge controllers and their servers. Locally mounted hardware such as readers and door contacts is excluded. See CIP-006
- Physical Security PerimeterPSP
- The physical border surrounding locations in which BES Cyber Assets, BES Cyber Systems or EACMS reside, and for which access is controlled. See CIP-006
- Protected Cyber AssetPCA
- A Cyber Asset connected using a routable protocol within, or on, an Electronic Security Perimeter that is not part of the highest-impact BES Cyber System in that ESP. See CIP-005
- Real-time Assessment
- An evaluation of system conditions using real-time data to assess existing and potential operating conditions. Data used for it is protected in transit by CIP-012. See CIP-012
- Regional Entity
- One of six organizations (MRO, NPCC, ReliabilityFirst, SERC, Texas RE and WECC) delegated by NERC to monitor and enforce compliance in their regions.
- Removable Media
- Storage media, such as USB drives and external disks, that are not Cyber Assets, can transfer executable code, and are connected for 30 consecutive calendar days or less to a BES Cyber Asset, a network within an ESP, or a PCA. See CIP-010
- Reportable Cyber Security Incident
- A Cyber Security Incident that compromises or disrupts a BES Cyber System performing a reliability task, an ESP, or an EACMS of a high or medium impact system. Must be reported to the E-ISAC and CISA within 1 hour of determination. See CIP-008
- Shared Cyber InfrastructureSCI
- A new term in the virtualization package (effective July 2028): hardware and software such as hypervisors or storage that host multiple virtual Cyber Assets. See CIP-002
- Technical Feasibility ExceptionTFE
- A documented, approved exception from certain CIP requirements when a device cannot technically meet them, with compensating or mitigating measures. See CIP-007
- Transient Cyber AssetTCA
- A Cyber Asset, such as a maintenance laptop, directly connected for 30 consecutive days or less to a BES Cyber Asset, network within an ESP, or PCA, and capable of transmitting executable code. See CIP-010
- Virtual Cyber AssetVCA
- A new term in the virtualization package (effective July 2028): a logical instance of an operating system or firmware running on Shared Cyber Infrastructure. See CIP-002
B
C
D
E
I
L
P
R
S
T
V
Request a quote
See CIP Sentry on your own terms.
Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.

