ThreatLocker and NERC CIP Compliance 

16 min. readlast update: 08.28.2026

NERC CIP is a set of mandatory cybersecurity and physical-security standards for organizations that operate parts of the North American electric grid. These standards are designed to protect Bulk Electric System (BES) Cyber Systems from compromise by establishing requirements for areas such as access control, system security, monitoring, incident response, configuration management, and information protection.

ThreatLocker offers tools that support NERC CIP compliance by helping administrators implement applicable technical security controls and providing in-depth tracking and visibility into endpoint activity, configuration, and overall device health.

For more information on NERC CIP compliance, please visit: NERC CIP Documentation

Disclosure: ThreatLocker does not provide legal or compliance advice and is not a certifying authority for NERC CIP compliance. The information provided represents ThreatLocker’s best-effort assessment of how its product capabilities may support certain NERC CIP requirements when properly configured. An organization’s compliance status is dependent on multiple factors beyond the ThreatLocker platform. Any NERC CIP controls or requirements not explicitly referenced are not currently supported by ThreatLocker. 

Requirement Summary 

Due to similarities in requirements across NERC CIP standards within the same series (e.g., CIP-003-9, CIP-003-10, and CIP-003-11), applicable controls will be addressed together in this document. Where significant differences exist between versions, those changes will be identified and addressed. 

CIP-003-* (9,10,11)

Attachment 1 

Section 3 - Electronic Access Controls 

3.1 - “Permit only necessary inbound and outbound electronic access as determined by the Responsible Entity” 

ThreatLocker Zero Trust Network Access and Network Control will allow administrators to limit or restrict inbound and outbound access to the organizational network. 

ThreatLocker Application Control can restrict access to network tools using Zero Trust deny-by-default allowlisting. 

Section 4 - Cyber Security Incident Response 

4.1 - “Identification, classification, and response to Cyber Security Incidents” 

4.3 - “Identification of the roles and responsibilities for Cyber Security Incident  response by groups or individuals” 

4.4 - “Incident handling for Cyber Security Incidents” 

ThreatLocker Detect can detect a wide array of behaviors that could indicate an attack on organizational endpoints, also allowing users to create custom policies to track and identify cybersecurity incidents.  

The Cyber Hero MDR Team alongside Detect will notify when malicious behavior is detected and help in incident response. In addition, ThreatLocker Detect can be used to lock down or isolate your machine should malicious activity be detected. 

Section 5 - Transient Cyber Asset and Removable Media Malicious Code Risk Mitigation 

  • 5.1 The use of one or a combination of the following in an ongoing or on‐demand manner (per Transient Cyber Asset capability)

    • Antivirus software, including manual or managed updates of signatures or patterns;  

    • Application whitelisting; or  

    • Other method(s) to mitigate the introduction of malicious code. 

  • 5.2 -  

    • 5.2.1 Use one or a combination of the following prior to connecting the Transient Cyber Asset to a low impact BES Cyber System 

      • Review of antivirus update level;  

      • Review of antivirus update process used by the party;  

      • Review of application whitelisting used by the party;  

      • Review use of live operating system and software executable only from read‐only media; 

    • 5.2.2 For any method used pursuant to 5.2.1, Responsible Entities shall determine whether any additional mitigation actions are necessary and implement such actions prior to connecting the TCA. 

ThreatLocker Application Control can help mitigate the risk of malicious code through a Zero Trust, deny-by-default application allowlisting approach. ThreatLocker Unified Audit can further support these efforts by providing visibility into application activity and historical allowlisting records across endpoints managed through the ThreatLocker platform. 

ThreatLocker Storage Control can help mitigate the risk of malicious code introduced through removable media by restricting access to files, controlling data manipulation, and limiting connections to external storage devices. 

Section 6 - Vendor Electronic Remote Access Security Controls 

  • 6.1 - One or more method(s) for determining vendor electronic remote access;  

  • 6.2 - One or more method(s) for disabling vendor electronic remote access; and  

  • 6.3 - One or more method(s) for detecting known or suspected inbound and outbound malicious communications for vendor electronic remote access. 

ThreatLocker Application Control can help mitigate the risk of malicious code through a Zero Trust, deny-by-default application allowlisting approach. 

ThreatLocker Zero Trust Network Access and Network Control will allow administrators to limit or restrict inbound and outbound access to the organizational network. 

Note: Section 6 does not exist in CIP-003-11 

CIP-005-* (7,8) 

B. Requirements and Measures

R1. Each Responsible Entity shall implement one or more documented processes that collectively include each of the applicable requirement parts in CIP-005-7 Table R1 – Electronic Security Perimeter. 

  • 1.3 - Require inbound and outbound access permissions, including the reason for granting access, and deny all other access by default.  

  • 1.5 - Have one or more methods for detecting known or suspected malicious communications for both inbound and outbound communications. 

R2. Each Responsible Entity shall implement one or more documented processes that collectively include the applicable requirement parts, where technically feasible. 

  • 2.1 - Permit Interactive Remote Access (IRA), if any, only through an Intermediate System. 

  • 2.2 - Protect the confidentiality and integrity of IRA communications between the initiating Cyber Asset or Virtual Cyber Asset and the Intermediate System. 

  • 2.3 - Require multi-factor authentication to the Intermediate System for IRA communications between the initiating Cyber Asset or Virtual Cyber Asset and the Intermediate System. 

  • 2.4 - Have one or more methods for determining active vendor remote access sessions (including Interactive Remote Access and system-to-system remote access). 

  • 2.5 - Have one or more method(s) to disable active vendor remote access (including Interactive Remote Access and system to-system remote access). 

R3. Each Responsible Entity shall implement one or more documented processes that collectively include the applicable requirement parts in CIP-005-7 Table R3 –Vendor Remote Access Management for EACMS and PACS. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning and Same Day Operations]. 

  • 3.1 - Have one or more method(s) to determine authenticated vendor initiated remote connections. 

  • 3.2 - Have one or more method(s) to terminate authenticated vendor-initiated remote connections and control the ability to reconnect. 

ThreatLocker Network Control can help support Electronic Security Perimeter requirements by enforcing granular network communication policies and restricting unnecessary or potentially malicious network connectivityNetwork control helps to restrict-access communication and can restrict vendor source addresses and communication paths.  

 
ThreatLocker Application Allowlisting and Ringfencing can help users and administrators limit or restrict the use of remote access applications, as well as control what those applications can communicate with while in use. 

ThreatLocker DAC can help identify and remediate configuration drift or insecure settings that could weaken network protections, expose unnecessary services, or reduce the effectiveness of remote-access controls. Specifically, there are DAC analysis checks that can show when encryption is enabled on Remote Access sessions, for example. 

CIP-007-(6,7.1) 

B. Requirements and Measures 

R1. Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts in CIP-007-6 Table R1 – Ports and Services.  

  • 1.1 - Disable or prevent unneeded routable protocol network accessibility on each Applicable System, per system capability. 

  • 1.2 - Protect against the use of unnecessary physical input/output ports used for network connectivity, console commands, or Removable Media.  

ThreatLocker Zero Trust Network Access and Network Control will allow administrators to limit or restrict inbound and outbound access to the organizational network. 

R2. Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts in CIP-007-6 Table R2 – Security Patch Management. [Violation Risk Factor: Medium] [Time Horizon: Operations Planning].  

  • 2.1 - A patch management process for tracking, evaluating, and installing cyber security patches for applicable Cyber Assets. The tracking portion shall include the identification of a source or sources that the Responsible Entity tracks for the release of cyber security patches for applicable Cyber Assets that are updateable and for which a patching source exists. 

  • 2.2 - At least once every 35 calendar days, evaluate security patches for applicability that have been released since the last evaluation from the source or sources identified in Part 2.1. 

  • 2.3 - For applicable patches identified in Part 2.2, within 35 calendar days of the evaluation completion, take one of the following actions:  

    • Apply the applicable patches; or  

    • Create a dated mitigation plan; or  

    • Revise an existing mitigation plan.  

Mitigation plans shall include the Responsible Entity’s planned actions to mitigate the vulnerabilities addressed by each security patch and a timeframe to complete these mitigations. 

  • 2.4 - For each mitigation plan created or revised in Part 2.3, implement the plan within the timeframe specified in the plan, unless a revision to the plan or an extension to the timeframe specified in Part 2.3 is approved by the CIP Senior Manager or delegate. 

ThreatLocker Patch Management allows administrators to track and update applications and operating systems across the environment. Policy-based update tracks help ensure patches are deployed within defined timeframes while maintaining a record of applied updates within the ThreatLocker interface. 

R3. Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts in CIP-007-6 Table R3 – Malicious Code Prevention. [Violation Risk Factor: Medium] [Time Horizon: Same Day Operations]. 

  • 3.1 - Deploy method(s) to deter, detect, or prevent malicious code. 

  • 3.2 - Mitigate the threat of detected malicious code. 

  • 3.3 - For those methods identified in Part 3.1 that use signatures or patterns, have a process for the update of the signatures or patterns. The process must address testing and installing the signatures or patterns. 

ThreatLocker Application Allowlisting and Ringfencing can help users and administrators limit or restrict potential sources of malicious code, including applications and scripts, while also controlling what those applications are permitted to access or communicate with during execution. 

ThreatLocker Detect can help identify and respond to potential threats within the environment. Cyber Hero MDR and the Detect dashboard can be used to investigate detected risks, isolate affected systems, and remediate potential indicators of compromise. 

ThreatLocker Patch Management can be used to update applications through a verified, hash-based process, helping administrators maintain controlled and secure application versions across the environment. 

R4. Each Responsible Entity shall implement one or more documented process(es) that collectively include each of the applicable requirement parts in CIP-007-6 Table R4 – Security Event Monitoring. [Violation Risk Factor: Medium] [Time Horizon: Same Day Operations and Operations Assessment.] 

  • 4.1 - Log events at the BES Cyber System level (per BES Cyber System capability) or at the Cyber Asset level (per Cyber Asset capability) for identification of, and after-the-fact investigations of, Cyber Security Incidents that includes, as a minimum, each of the following types of events:  

  • 4.1.1. Detected successful login attempts;  

  • 4.1.2. Detected failed access attempts and failed login attempts;  

  • 4.1.3. Detected malicious code. 

  • 4.2 - Generate alerts for security events that the Responsible Entity determines necessitates an alert, that includes, as a minimum, each of the following types of events (per Cyber Asset or BES Cyber System capability):  

  • 4.2.1. Detected malicious code from Part 4.1; and  

  • 4.2.2. Detected failure of Part 4.1 event logging. 

  • 4.3 - Where technically feasibleretain applicable event logs identified in Part 4.1 for at least the last 90 consecutive calendar days except under CIP Exceptional Circumstances. 

  • 4.4 - Review a summarization or sampling of logged events as determined by the Responsible Entity at intervals no greater than 15 calendar days to identify undetected Cyber Security Incidents. 

ThreatLocker Unified Audit can support this requirement by centralizing ThreatLocker audit activity into a searchable audit trail. Administrators can use Unified Audit to investigate historical security events, maintain records of activity, and review or sample logged events as part of the Responsible Entity’s documented security-event review process. 

ThreatLocker Detect can identify suspicious or malicious activity and generate alerts when defined security conditions are detected. This can help organizations identify malicious-code-related activity and quickly escalate events that the Responsible Entity determines require investigation or response. 

The ThreatLocker System Audit retains information about administrator activities in the ThreatLocker Portal. This information shows whether administrators add or delete policies, change organization settings, etc. If an administrator has performed an unauthorized action, that information will be viewable in the System Audit, which is retained indefinitely.

CIP-008-* (6,7.1) 

B. Requirements and Measures 

R1. Each Responsible Entity shall document one or more Cyber Security Incident response plan(s) that collectively include each of the applicable requirement parts in CIP-008-6 Table R1 – Cyber Security Incident Response Plan Specifications. 

  • 1.1 - One or more processes to identify, classify, and respond to Cyber Security Incidents. 

  • 1.2 - One or more processes:  

    • 1.2.1 That include criteria to evaluate and define attempts to compromise;  

    • 1.2.2 To determine if an identified Cyber Security Incident is:  

      • A Reportable Cyber Security Incident; or  

      • An attempt to compromise, as determined by applying the criteria from Part 1.2.1, one or more systems identified in the “Applicable Systems” column for this Part; and  

    • 1.2.3 To provide notification per Requirement R4. 

  • 1.3 - The roles and responsibilities of Cyber Security Incident response groups or individuals. 

  • 1.4 - Incident handling procedures for Cyber Security Incidents. 

ThreatLocker Detect can help organizations detect and evaluate activity against established incident criteria, determine the need for further investigation and escalation, and provide supporting information for incident review, classification, and response procedures. ThreatLocker Cyber Hero MDR can further assist with reviewing threats that have been detected, while coordinating with an organization for containment and remediation actions. 

CIP-010-* (4, 5) 

B. Requirements and Measures  

R1. Each Responsible Entity shall implement one or more documented process(es) to manage configuration changes, individually or by group... 

  • 1.1 - Authorize changes that affect Applicable Systems where those changes alter the behavior of one or more cyber security controls, excluding procedural and physical controls, serving one or more requirement parts in CIP-005 or CIP-007, as defined by the Responsible Entity. 

  • 1.2 -  

    • 1.2.1 Prior to implementing any change from Part 1.1 in the production environment, except during a CIP exceptional circumstance, test the changes in a test environment that minimizes differences with the production environment or test the changes in a production environment where the test is performed in a manner that minimizes adverse effects, to ensure that required cyber security controls in CIP-005 and CIP-007 are not adversely affected; and  

    • 1.2.2 Document the results of the testing and, if a test environment was used, the differences between the test environment and the production environment, including a description of the measures used to account for any differences in operation between the test and production environments. 

  • 1.2 (CIP 010-4 exclusively) - Authorize and document changes that deviate from the existing baseline configuration. 

  • 1.3 - Prior to the installation of operating systems, firmware, software, or software patches and when the method to do so is available to the Responsible Entity from the software source:  

    • 1.3.1 Verify the identity of the software source; and  

    • 1.3.2 Verify the integrity of the software obtained from the software source. 

  • 1.4 - As a part of the changes authorized per Part 1.1, verify that the behavior(s) of the altered cyber security controls were not adversely affected.  

ThreatLocker Defense Against Configurations (DAC) can help in identifying and enforcing desired endpoint configurations, providing visibility into deviations from an organization's approved security posture.  

ThreatLocker Application Control can assist organizations in controlling which applications or software are permitted to execute, and ensures each new software is verified and sourced to the vendor. This is especially relevant when software installation and removal or application configuration forms part of a change-controlled environment. 

ThreatLocker Patch Management supports the controlled deployment of operating system and application updates while maintaining records of patches applied across the organization. 

ThreatLocker Unified Audit provides records of ThreatLocker policy and configuration activity that can support the documentation and evidence side of configuration-change management. 

R2. Each Responsible Entity shall implement one or more documented process(es) to monitor configuration changes... 

  • 2.1 - Methods to monitor, per system capability, at least once every 35 calendar days, for unauthorized changes that affect Applicable Systems, where those changes alter the behavior of one or more cyber security control, excluding procedural and physical controls, serving one or more requirement parts in CIP-007, as defined by the Responsible Entity, that include at least one cyber security control for each of the following: 

    • 2.1.1 - Configuration on each Applicable System that affect its routable protocol network accessibility; 

    • 2.1.2 - Configuration of CPU or memory sharing of VCAs on SCI. 

    • 2.1.3 - Installation, removal, and update of operating system, firmware, software, and cyber security patches. 

    • 2.1.4 - Configuration of malicious code protection methods; 

    • 2.1.5 - Configuration of security event logging or alerting; 

    • 2.1.6 - Configuration of authentication methods; and  

    • 2.1.7 - Changes to the enabled or disabled status of accounts. 

Document and investigate detected unauthorized changes. 

ThreatLocker Defense Against Configurations (DAC) will help satisfy this requirement by monitoring endpoint security configurations for unauthorized or unexpected changes DAC can help identify changes in the environment compared to systems in an expected configuration state.  

ThreatLocker Network Control will help enforce and monitor network communication policies on protected endpoints. Changes that would alter allowed network destinations, ports, protocols or communication paths can be restricted and identified, helping organizations maintain control over network protocol and accessibility.  

ThreatLocker Patch Management can help provide visibility into OS and application updates deployed across the environment. Control software deployments and maintain records of applied patches using Patch Management. 

CIP-0011-* (3, 4.1) 

B. Requirements and Measures 

R1. Each Responsible Entity shall implement one or more documented information protection program(s) for BES Cyber System Information (BCSI) pertaining to “Applicable Systems” 

  • 1.2 - Method(s) to protect and securely handle BCSI to mitigate risks of compromising confidentiality. 

ThreatLocker Storage Control will restrict access to files, storage locations, and removable media containing BES Cyber System Information, which will help limit unauthorized access to protected information. 

ThreatLocker Application Control will limit which applications are permitted to execute within the environment. By preventing unauthorized or unapproved software from running, Application Control can reduce the likelihood that malicious or untrusted applications are used to access, modify, or expose BCSI. 

ThreatLocker Ringfencing will restrict what approved applications are permitted to access or interact with. This can limit an application's access to protected files and other system resources containing BCSI, reducing unnecessary exposure of sensitive information during use. 

CIP-0013-* (2, 3) 

B. Requirements and Measures  

R1. Each Responsible Entity shall develop one or more documented supply chain cyber security risk management plan(s) for high and medium impact BES Cyber Systems and their associated Electronic Access Control or Monitoring Systems (EACMS) and Physical Access Control Systems (PACS). 

  • 1.2. One or more process(es) used in procuring BES Cyber Systems, and their associated EACMS and PACS, that address the following, as applicable: 

    • 1.2.5. Verification of software integrity and authenticity of all software and patches provided by the vendor for use in the BES Cyber System and their associated EACMS and PACS; and  

    • 1.2.6. Coordination of controls for vendor-initiated remote access. 

ThreatLocker Application Allowlisting directly controls whether software is authorized to execute. Applications can be identified and approved using trusted application binaries and hashing, allowing organizations to prevent unauthorized or altered software from executing. ThreatLocker Patch Management can expand upon this by providing pre-verified application definition patching for a significant library of high-use applications and first-party operating system updates. 

ThreatLocker Network Control directly enforces network communication restrictions on protected endpoints, allowing administrators to define which network resources, ports, and communications are permitted. When vendor remote access is allowed, these controls can restrict that connectivity to the specific resources required for the authorized vendor activity. 

CIP-0015-* (1, 2) 

B. Requirements and Measures  

R1. Each Responsible Entity shall implement one or more documented process(es) for internal network security monitoring of networks protected by the Responsible Entity’s Electronic Security Perimeter(s) of high impact BES Cyber Systems and medium impact BES Cyber Systems with External Routable Connectivity to provide methods for detecting and evaluating anomalous network activity. 

  • 1.1 - Implement, using a risk-based rationale, network data feed(s) to monitor network activity; including connections, devices, and network communications. 

  • 1.2 - Implement one or more method(s) to detect anomalous network activity using the network data feed(s) from Part 1.1. 

  • 1.3 - Implement one or more method(s) to evaluate anomalous network activity detected in Part 1.2. to determine further action(s). 

ThreatLocker Network Control provides visibility into organization network connections and communications that are occurring on protected endpointsThis can help administrators establish network activity data that can contribute to internal network security monitoring. 

ThreatLocker Unified Audit can support this control by providing centralized records of network-related activity captured through the ThreatLocker platform. These records can assist administrators in reviewing communications and demonstrating implementation of monitoring processes.  

 

Was this article helpful?