Regulatory vertical guide

Utility and Critical-Infrastructure Records for NERC CIP and OT Review

Energy and utility environments need precise records around physical access, electronic access, OT dependencies, control rooms, network boundaries, and vendor-maintained systems. Globin Engineering helps create the owner record that supports review by engineering, security, compliance, and OT teams.

Why it matters

Energy, Utilities & Critical Infrastructure

  • NERC CIP-006 addresses physical security plans for Bulk Electric System Cyber Systems and includes controls for physical security perimeters, physical access, alarms, monitoring, logs, and PACS related to BES Cyber Systems.
  • NERC CIP-014 addresses physical security for certain transmission stations, substations, and primary control centers through risk assessments and security plans.
  • NIST SP 800-82 recognizes OT systems as programmable systems and devices that interact with the physical environment, including building automation, physical access control, monitoring, and control systems.
Systems in scope

Technology records that commonly need verification

  • PACS, badge readers, door contacts, interlocks, alarms, and security perimeters
  • Video surveillance, intrusion detection, perimeter devices, and monitoring handoffs
  • OT/BAS controllers, gateways, sensors, meters, relays, and supervisory interfaces where in scope
  • MDF/IDF, network closets, fiber, patching, and remote support links
  • Control rooms, equipment rooms, mechanical/electrical spaces, rooftops, yards, and substations
Requirements and review drivers

What owners commonly need to prove, reconcile, or investigate.

Actual requirements depend on the organization, jurisdiction, asset type, contracts, regulator, insurer, and the owner's policies.

Physical access control

Critical infrastructure reviews often require clear maps of perimeters, controlled spaces, access points, alarmed doors, badge readers, and monitoring systems.

OT and cyber boundary context

BMS/BAS, SCADA-adjacent, telemetry, sensors, switches, and remote support systems need clear owner-vendor-platform context.

Evidence and traceability

Compliance and operations teams need records that separate confirmed field conditions from assumptions, inherited drawings, and old vendor notes.

Lifecycle and continuity

Unsupported controllers, obsolete panels, unmanaged switches, and unclear remote access can become operational risk even when they are not direct compliance findings.

How Globin assists

Field-verified inputs for your compliance review.

  • Provide an owner-side record of devices, rooms, platforms, vendors, lifecycle signals, and exceptions.
  • Support compliance, engineering, and operations teams with a baseline for their own risk assessment and compliance review.
  • Avoid stating compliance; instead, provide field evidence, traceability, and exception context for qualified stakeholders to evaluate.
Typical output

Owner-ready deliverables.

  • Device inventory and controlled-space overlays
  • Technology-room and riser diagrams
  • PACS/VMS/BAS/OT support matrix
  • Exception and uncertainty register
  • Lifecycle and high-criticality device list

Selected references

These links are provided so owners can review relevant rules, standards, guidance, trade-association resources, or industry context with counsel, compliance teams, auditors, and qualified consultants.

Start with facts

Use a field-verified owner record before deciding what is compliant, deficient, or ready for refresh.

Request Assessment