|
|
By Rebekah Barber
|
As the Bulk Power System (BPS) continues to transform, the increasingly distributed workforce has increased the risk of unauthorized access to sensitive system information. In response, the North American Electric Reliability Corporation (NERC) has identified access management as a risk element within the 2026 Compliance Monitoring and Enforcement Program Implementation Plan (CMEP IP). Consistent with that focus, CIP-004-6 Requirement R6 establishes expectations for managing access to BES Cyber System Information (BCSI), including provisioning, revoking, and periodically reviewing that access.
Effective identity and access management often requires ongoing coordination across departments to complete the activities required by CIP-004-6 R6. While implementation varies by operating environment, the following best practices can help Responsible Entities strengthen their access-management posture for protecting BCSI:
For additional guidance on implementing identity and access management best practices, Texas RE encourages Responsible Entities to consult the identity and authentication and access control families in the National Institute of Standards and Technology (NIST) Special Publication 800-53 Rev. 5.