Bulk electric system evidence

NERC CIP Audit Evidence Support

Technical evidence that traces back to the control: requirement, source system, test result, and correction remain connected for the review period supplied by the Registered Entity.

Water treatment and electrical utility infrastructure.

The engagement

Requirement to source, without gaps

GDF helps utilities and service providers collect, test, and organize technical records for NERC CIP requirements that the Registered Entity has placed in scope. Applicability depends on registration, NERC function, Bulk Electric System responsibilities, asset and system categorization, the governing standard and requirement version, implementation dates, and the review period.

The Registered Entity, compliance team, Regional Entity, and counsel retain applicability, interpretation, attestation, and submission decisions. GDF does not provide a legal compliance opinion. The engagement produces the underlying technical record the accountable roles then use.

The evidence map records the Responsible Entity designation used by the client, relevant NERC function, Regional Entity, BES Cyber System categorization, standard and requirement identifier, version and effective date, audit or review period, control owner, covered population, source system, collection method, reviewer, exception path, and retention location.

Scope

  • Asset and scope reconciliation

    BES Cyber Asset and BES Cyber System inventories reconciled against network records, configuration exports, engineering files, and change data. Categorization decisions and their basis are recorded.

  • Electronic security perimeter evidence

    ESP boundary records: firewall rules, remote-access paths, jump hosts, dial-up and cellular access, and dial-back or approval workflows. Exceptions and compensating controls are tracked with dated approvals.

  • Identity, privilege, and termination

    Account inventories, privileged access reviews, termination workflows, shared-account justifications, and periodic review evidence. Sample selection and completeness are documented for the review period.

  • Vulnerability, patch, and configuration

    Vulnerability scan coverage, patch source records, testing evidence, configuration baselines, change approvals, and exception documentation. Excluded assets and untested controls are recorded rather than treated as passed.

  • Incident, backup, recovery, and exercise

    Incident response evidence, backup test records, recovery exercise participation, corrective action tracking, and lessons-learned records reconciled against dated obligations.

  • Physical and information protection records

    Where in scope, physical access, monitoring, information handling, and awareness evidence collected against the requirement version in effect during the review period.

  • Reporting and evidence packaging

    Evidence organized by requirement identifier, sub-requirement, and reviewer expectation. Each item carries source system, collection date, operator, and hash where applicable.

Methodology

How CIP evidence work runs

  1. Scope

    The Registered Entity provides categorization, review period, requirement versions, and the applicable Regional Entity. GDF confirms scope and identifies source systems and owners.

  2. Collect

    Configuration exports, tickets, log records, identity data, and process records are collected with source, date, operator, hash, and exception notes.

  3. Reconcile

    Evidence is reconciled against requirement text, sampled, and cross-checked. Gaps become exceptions with owner, correction plan, and retest date.

  4. Package

    The evidence set is indexed by requirement, cross-referenced to source system, and organized for Regional Entity review. Readiness work for future dates is labeled separately.

Evidence commonly examined

Evidence reviewed

  • Firewall, router, and remote-access configuration exports
  • Identity provider records, privileged access reviews, and account terminations
  • Vulnerability scan coverage, patch tickets, and exception approvals
  • Change management, configuration baseline, and testing records
  • Incident response tickets, backup test logs, and exercise records
  • Physical access, monitoring, and information protection records where in scope

What you can expect

What you receive

  • Evidence map from requirement identifier to source system
  • Requirement-by-requirement evidence package with sampling notes
  • Exception and corrective-action register with owner and dates
  • Readiness memoranda for future enforcement dates, clearly separated
  • Reviewer-ready index with hashes and collection timestamps

Frequently asked

Common questions

Do you issue a compliance opinion or attest to CIP compliance?

No. GDF collects, organizes, and explains the underlying technical record. The Registered Entity, compliance team, and counsel retain applicability, interpretation, attestation, and submission.

Can readiness work be presented as current compliance evidence?

No. Readiness reviews for approved future standards or requirement versions are labeled as readiness and are not presented as evidence that a currently-effective requirement has been satisfied.

How are OT constraints handled during evidence collection?

Active methods require operator-designated authority, an approved process condition, stop points, and recovery steps. Passive review and configuration analysis are used where active methods could create risk. Exceptions and inaccessible sources are recorded.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.