Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

NERC · CIP

Bulk-electric-system cybersecurity logging.

Applies to: North American electric utilities. Built · FERC-mandatory

What the signed record shows

Security-event logs, configuration-change signals, and incident detail for BES cyber systems.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: CIP-007-6 R4; CIP-010-4; CIP-008-6; CIP-011-3

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Reliability Standards, FERC-approved and mandatory. Standards addressed (current enforced versions):

CIP-007-6 R4
Security Event Monitoring: log generation, alerting on detectable security events, and log retention (at least 90 days).
CIP-010-4
Configuration Change Management and Vulnerability Assessments: baseline configuration, change authorization/documentation (R1), configuration monitoring (R2), vulnerability assessments (R3).
CIP-008-6
Incident Reporting and Response Planning: response plan (R1), implementation/testing (R2), review (R3); reporting of Reportable Cyber Security Incidents to the E-ISAC / CISA.
CIP-011-3
Information Protection: BES Cyber System Information program.

Taken from the Regulayer entry for this instrument, which is built against the primary text.