November 10, 2014

CIP-009 Recovery Plans for Critical Cyber Assets

Standard CIP-009-3 ensures that recovery plan(s) are put in place for Critical Cyber Assets and that these plans follow established business continuity and disaster recovery techniques and practices. Standard CIP-009-3 should be read as part of a group of standards numbered Standards CIP-002-3 through CIP-009-3.

Applicability
Within the text of Standard CIP-009-3, “Responsible Entity” shall mean:

  • Reliability Coordinator
  • Balancing Authority
  • Interchange Authority
  • Transmission Service Provider
  • Transmission Owner
  • Transmission Operator
  • Generator Owner
  • Generator Operator
  • Load Serving Entity
  • NERC
  • Regional Entity

The following are exempt from Standard CIP-009-3:

  • Facilities regulated by the U.S. Nuclear Regulatory Commission or the Canadian Nuclear Safety Commission.
  • Cyber Assets associated with communication networks and data communication links between discrete Electronic Security Perimeters.
  • Responsible Entities that, in compliance with Standard CIP-002-3, identify that they have no Critical Cyber Assets.

See the NERC website for more details regarding Critical Infrastructure Protection Standards.

SureID and Force 5 Partner to Deliver Innovative Vetting and Cost Recovery OfferingPress Release