CIP 5 Overview
In response to these existing and emerging threats to the power grid, NERC released Version 5 of its standard entitled, Critical Infrastructure Protection Reliability Standards (CIP). NERC CIP 5 extends the scope of critical systems covered to include cyber assets.
CIP 5 provides a comprehensive framework for monitoring threats to and managing response to incidents on the electric grid’s systems, networks, and assets.
CIP 5 is enforced via three methods:
Regularly scheduled compliance audits
Random spot checks
Specific investigations as warranted by indications that a standard may have been violated

