Requirements at a glance
Electronic Security Perimeter
Every applicable Cyber Asset connected by a routable protocol resides within a defined ESP. External routable connectivity passes through an identified Electronic Access Point that permits only necessary inbound and outbound access with a documented reason, and detects known or suspected malicious communications (high impact and medium impact at Control Centers).
Remote access management
Interactive Remote Access goes through an Intermediate System, is encrypted to that system, and uses multi-factor authentication. Entities must be able to determine active vendor remote access sessions and disable them.
Vendor remote access for EACMS and PACS
Added in CIP-005-7: methods to determine and disable active vendor remote access sessions extend to EACMS and PACS associated with high impact and medium impact systems with ERC.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
The perimeter is only as good as its reasons
Most CIP-005 findings are not missing firewalls. They are rules nobody can explain. Every permitted inbound and outbound rule at an Electronic Access Point needs a documented reason, and “vendor requested it” rarely survives an auditor’s follow-up questions. Review rule sets together with your CIP-010 baselines so the documented configuration and the real one never drift apart.
Interactive Remote Access, done right
Interactive Remote Access has three non-negotiables: an Intermediate System, encryption that terminates at the Intermediate System, and multi-factor authentication. Map every human remote path: engineers, contractors and vendors. Automated system-to-system traffic is not Interactive Remote Access, but it still has to be justified at the access point.
Vendor sessions
You must be able to see active vendor remote access sessions and cut them off, including (since CIP-005-7) for EACMS and PACS. Test the “disable” method before an auditor asks you to demonstrate it, and keep the procedure where the on-call person can find it at 2 a.m.
Evidence auditors typically ask for
- Network diagrams showing each ESP, its Electronic Access Points and every applicable Cyber Asset inside it
- Firewall and access point rule sets with a documented reason for each permitted rule
- Evidence of malicious communication detection at applicable access points
- Intermediate System architecture, encryption settings and MFA configuration for Interactive Remote Access
- Procedures and system evidence for determining and disabling vendor remote access sessions
How CIP Sentry helps with CIP-005
Facilities & Perimeters
Document each ESP, its access points and the systems inside it, linked to the BES Cyber Systems and facilities they protect.
Remote access connectivity
Record External Routable Connectivity, connection types and dial-up authentication per Cyber Asset, and report it with the ready-made ERT report.
Change control for rules
Changes to access points and rule sets go through the same change process, authorized by the CAO (Cyber Asset Owner), as any baseline change.
Ready for logical isolation
Perimeter records map cleanly to the CIP-005-8 logical isolation model when the virtualization package takes effect in 2028.
CIP-005 FAQ
Do low impact systems need an ESP?
No. Low impact electronic access controls are covered by CIP-003 Attachment 1 Section 3, not CIP-005.
What is an Intermediate System?
A Cyber Asset or group of assets (often a jump host) that sits between the remote user and the ESP so that Interactive Remote Access never connects directly to a BES Cyber Asset.
What does CIP-005-8 change?
Under the virtualization package, CIP-005-8 is retitled “BES Cyber System Logical Isolation” and reframes perimeter requirements to cover virtual and shared infrastructure. It becomes effective July 1, 2028.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

