CIP-003_Workbook_10152019

Page 4 of 44

CIP-003 Effective Dates The following table lists the effective dates for the parts of CIP-003.

Implementation Dates

Standard/Requirement

CIP-003-8

CIP-003-7 7/1/2016 1/1/2020 7/1/2016 1/1/2020 7/1/2017 7/1/2017

CIP-003-6

BES Cyber System Categorization

CIP-002-5.1 R1 & R2

CIP-003

Security Management Controls Policies for high & medium impact BCS Policies for assets containing low impact BCS

4/1/2020 7/1/2016 1/1/2020 7/1/2017 7/1/2017

7/1/2016 7/1/2016 4/1/2017 7/1/2017 4/1/2017 9/1/2018

CIP-003-7 R1.1 CIP-003-7 R1.2 CIP-003-7 R2 CIP-003-7, Att 1, Section 1 CIP-003-7, Att 1, Section 2 CIP-003-7, Att 1, Section 3 CIP-003-7, Att 1, Section 4 CIP-003-7, Att 1, Section 5

Implement Sections 1-5

Cyber Security Awareness

Physical Security Controls

1/1/2020

1/1/2020

9/1/2018

Electronic Access Controls Cyber Security Incident Response Transient Cyber Assets and Removable Media Malicious Code Risk Mitigation Identify a CIP Senior Manager Delegate CIP Senior Manager Authority Section 5.2.2 (new)

1/1/2020 4/1/2017

1/1/2020

4/1/2017

4/1/2017

1/1/2020

n/a

4/1/2020 7/1/2016 7/1/2016

CIP-003-7 R3 CIP-003-7 R4

7/1/2016 7/1/2016

7/1/2016 7/1/2016

Made with FlippingBook - Online magazine maker