NERC CIP-002 through CIP-014 Revision 6
Security Awareness Program
CIP-004-6 R1
R1. Each Responsible Entity shall implement one or more documented processes that collectively include each of the applicable requirement parts in CIP-004-6 Table R1 ? Security Awareness Program. [Violation Risk Factor: Lower] [Time Horizon: Operations Planning]
M1. Evidence must include each of the applicable documented processes that collectively include each of the applicable requirement parts in CIP-004-6 Table R1 Security Awareness Program and additional evidence to demonstrate implementation as described in the Measures column of the table.CIP-004-6 Table R1 — Security Awareness Program Part Applicable Systems Requirements Measures 1.1 High Impact BES Cyber Systems Medium Impact BES Cyber Systems Security awareness that at least once each calendar quarter reinforces cyber security practices (which may include associated physical security practices) for the Responsible Entity’s personnel who have authorized electronic or authorized unescorted physical access to BES Cyber Systems. An example of evidence may include but is not limited to documentation that the quarterly reinforcement has been provided. Examples of evidence of reinforcement may include but are not limited to dated copies of information used to reinforce security awareness as well as evidence of distribution such as: direct communications (for example e-mails memos computer-based training); orindirect communications (for example posters intranet or brochures); ormanagement support andreinforcement (for example presentations or meetings).
Click here to Start your FREE trial today!
What is a Cybersecurity Compliance Framework?
You don’t need to clutter your security and privacy programs with an ever-increasing number of tools as they become more sophisticated. The Lionfish platform offers a one-stop solution to track progress and monitor any framework, from custom-built ones to highly-specialized and in-demand top security and privacy frameworks and certifications.
With the Lionfish platform, every framework is supported with guided scoping, policies, controls, automated evidence collection, and continuous monitoring, ensuring efficient preparation for audits or attestation in minimal time.
The Lionfish platform is compatible with a wide range of security and privacy frameworks, including:
- CMMC v2
- HIPAA
- NERC CIP-002 through CIP-014 Revision 6
- NIST 800-171
- NIST 800-172
- PCI (Payment Card Industry Security Standard)
- SOC 2
- NIST 800-53
- NIST SP800-161 Supply Chain Risk Management
- NIST-CSF
- CIS Framework Controls V8
Click here to Start your FREE trial today!