Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Cloud Comes to NERC CIP: The 100-Series and Project 2023-09
NERC did not revise the CIP Standards for the cloud. It forked them. Project 2023-09 introduces a parallel 100-Series, an entity can elect into per system, built on a new foundation called BES Cyber Services and Systems (BCSS), with System Security Plans replacing asset lists and Cyber Security Zones replacing the Electronic Security Perimeter. Here is how the parallel track works, what the first drafts actually say, and the open problems worth commenting on before August 21.
Using the Work of Others in NERC CIP and O&P Compliance
The work of others lets you lean on someone else's assessment as compliance evidence. It does not transfer accountability. This breakdown maps the ERO guidance stack, the two-part test auditors apply, worked examples for CIP-013 vendor assessments and BCSI in the cloud, the FERC FY2025 findings on delegation gone wrong, and the audit prep questions to answer first.