Which regulatory framework imposes mandatory, enforceable cybersecurity requirements on the North American Bulk Electric System?
- A.NIST SP 800-53
- B.NERC CIP
- C.PCI DSS
- D.ISO 9001
Why B is correct
NERC CIP (Critical Infrastructure Protection) standards are mandatory and enforceable, with financial penalties, for entities operating the North American Bulk Electric System. They cover areas such as asset categorization (CIP-002), electronic security perimeters (CIP-005), and incident reporting (CIP-008).
Know someone studying for OT Security Fundamentals? Send them this one.