Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

NERC CIP Critical Infrastructure Protection

NERC CIP training for the people who have to produce the evidence. You work through the Critical Infrastructure Protection (CIP) standards as they apply to bulk electric system (BES) cyber assets, from categorization through to recovery plans.

Compliance and security are treated as two jobs that overlap. The course is honest about where a standard asks for paperwork and where it asks for a control that genuinely reduces risk.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
ICS and SCADA Security Essentials
Class size
Capped at 12 learners
NERC CIP Critical Infrastructure Protection

What you will be able to do

  • Categorize BES cyber systems as high, medium or low impact and document the reasoning
  • Draw an electronic security perimeter and justify every access point in it
  • Map each CIP requirement to a control you can actually evidence
  • Assemble an evidence package an auditor can follow without a guided tour
  • Write incident response and recovery plans that meet testing and reporting obligations
  • Apply supply chain requirements to a real vendor contract and remote access path
  • Identify a potential non compliance, self report it and build a mitigation plan
  • Run an internal controls process that catches configuration drift between audits

Course outline

6 modules

  • Registered entity functions and what each one owns
  • Identifying BES cyber systems and their associated assets
  • High, medium and low impact rating criteria
  • Electronic security perimeters and their access points
  • Physical security perimeters
  • Getting scope wrong: the cost in both directions

What you need before you start

  • ICS and SCADA Security Essentials, or equivalent control system experience
  • Work at or with a registered entity, or a role that soon will
  • Familiarity with your own asset base and network diagrams helps but is not required
  • Roughly five hours a week outside class for the evidence exercises

Who this course is for

  • Compliance and security staff at generation, transmission and distribution entities
  • OT security engineers whose controls end up as audit evidence
  • Internal auditors reviewing a CIP programme
  • Consultants supporting utilities through audit cycles
  • Managers accountable for a registered entity's compliance posture

Where this leads

Prepares you for

CISA

Awarded by ISACA

Audit thinking is the shared ground between this course and ISACA CISA, so the two reinforce each other in compliance roles. CISA is examined and issued by ISACA rather than by this academy, and carries its own experience requirement.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.