Utility and Critical-Infrastructure Records for NERC CIP and OT Review
Energy and utility environments need precise records around physical access, electronic access, OT dependencies, control rooms, network boundaries, and vendor-maintained systems. Globin Engineering helps create the owner record that supports review by engineering, security, compliance, and OT teams.
Energy, Utilities & Critical Infrastructure
- NERC CIP-006 addresses physical security plans for Bulk Electric System Cyber Systems and includes controls for physical security perimeters, physical access, alarms, monitoring, logs, and PACS related to BES Cyber Systems.
- NERC CIP-014 addresses physical security for certain transmission stations, substations, and primary control centers through risk assessments and security plans.
- NIST SP 800-82 recognizes OT systems as programmable systems and devices that interact with the physical environment, including building automation, physical access control, monitoring, and control systems.
Technology records that commonly need verification
- PACS, badge readers, door contacts, interlocks, alarms, and security perimeters
- Video surveillance, intrusion detection, perimeter devices, and monitoring handoffs
- OT/BAS controllers, gateways, sensors, meters, relays, and supervisory interfaces where in scope
- MDF/IDF, network closets, fiber, patching, and remote support links
- Control rooms, equipment rooms, mechanical/electrical spaces, rooftops, yards, and substations
What owners commonly need to prove, reconcile, or investigate.
Actual requirements depend on the organization, jurisdiction, asset type, contracts, regulator, insurer, and the owner's policies.
Critical infrastructure reviews often require clear maps of perimeters, controlled spaces, access points, alarmed doors, badge readers, and monitoring systems.
BMS/BAS, SCADA-adjacent, telemetry, sensors, switches, and remote support systems need clear owner-vendor-platform context.
Compliance and operations teams need records that separate confirmed field conditions from assumptions, inherited drawings, and old vendor notes.
Unsupported controllers, obsolete panels, unmanaged switches, and unclear remote access can become operational risk even when they are not direct compliance findings.
Field-verified inputs for your compliance review.
- Provide an owner-side record of devices, rooms, platforms, vendors, lifecycle signals, and exceptions.
- Support compliance, engineering, and operations teams with a baseline for their own risk assessment and compliance review.
- Avoid stating compliance; instead, provide field evidence, traceability, and exception context for qualified stakeholders to evaluate.
Owner-ready deliverables.
- Device inventory and controlled-space overlays
- Technology-room and riser diagrams
- PACS/VMS/BAS/OT support matrix
- Exception and uncertainty register
- Lifecycle and high-criticality device list
Selected references
These links are provided so owners can review relevant rules, standards, guidance, trade-association resources, or industry context with counsel, compliance teams, auditors, and qualified consultants.