Access Management

By Rebekah Barber
Compliance Team Lead

As the Bulk Power System (BPS) continues to transform, the increasingly distributed workforce has increased the risk of unauthorized access to sensitive system information. In response, the North American Electric Reliability Corporation (NERC) has identified access management as a risk element within the 2026 Compliance Monitoring and Enforcement Program Implementation Plan (CMEP IP). Consistent with that focus, CIP-004-6 Requirement R6 establishes expectations for managing access to BES Cyber System Information (BCSI), including provisioning, revoking, and periodically reviewing that access.

Effective identity and access management often requires ongoing coordination across departments to complete the activities required by CIP-004-6 R6. While implementation varies by operating environment, the following best practices can help Responsible Entities strengthen their access-management posture for protecting BCSI:

  • Centralize access administration: Provision and revoke BCSI access through a unified platform with defined workflows and approvals.
  • Enforce least privilege: Grant only the minimum BCSI access needed for an individual’s job responsibilities and remove access promptly when it is no longer required.
  • Audit access logs: Regularly monitor system entry records to detect anomalous behaviors, flag credential misuse, and identify accounts that should be decommissioned.

For additional guidance on implementing identity and access management best practices, Texas RE encourages Responsible Entities to consult the identity and authentication and access control families in the National Institute of Standards and Technology (NIST) Special Publication 800-53 Rev. 5.