NERC Reliability Standard CIP-014
CIP-014 requires utilities to identify their most critical transmission assets and to assess and plan for their physical security. Aerial exposure is an input to an assessment that is already required.
- Status
- in force
- Authority
- North American Electric Reliability Corporation, approved by FERC
- Applies to
- Transmission owners and operators, for transmission stations, substations and primary control centres whose loss could cause instability, uncontrolled separation or cascading outages.
Key points
- CIP-014 requires transmission owners to identify transmission stations, substations and primary control centres whose loss could result in instability, uncontrolled separation or cascading outages within an interconnection.
- For those identified assets it requires an evaluation of potential physical threats and vulnerabilities, and the development and implementation of a physical security plan.
- The standard requires third-party review of both the asset identification and the evaluation, which is one reason external assessment work is common in this sector.
- CIP-014 does not mandate any particular technology, including drone detection. It requires assessment and planning, and leaves the measures to the utility.
- Because the standard applies to a defined subset of assets rather than to every substation, the practical question for a utility is usually which sites are in scope.
What the standard requires
CIP-014 concerns the physical security of the transmission assets that matter most. It requires a transmission owner to identify stations, substations and primary control centres whose loss, through a physical attack, could result in instability, uncontrolled separation or cascading outages within an interconnection.
For those assets it then requires an evaluation of potential physical threats and vulnerabilities, and a physical security plan developed and implemented in response.
Both the identification and the evaluation are subject to review by an independent third party. That requirement shapes how utilities work in this area and is one reason external assessment is a normal part of the process.
What it does not require
The standard does not name technologies. It does not require drone detection, cameras, radar or any other measure. It requires the utility to assess and to plan, and leaves the choice of measures to the utility.
This distinction is worth holding on to when reading vendor material. A proposal that presents CIP-014 as mandating a product is overstating what the standard says.
Where aerial exposure fits
The threat an aircraft presents at a substation is usually information rather than direct damage. A drone can photograph transformer banks, the control house, relay and protection equipment, the fence line, the access road and the position of cameras. That imagery supports an attack conducted from outside the perimeter using conventional means.
Because CIP-014 already requires an evaluation of physical threats and vulnerabilities, aerial observation belongs inside a document the utility is producing anyway. It does not need a separate justification or a separate budget line, which is a practical advantage over sectors where no assessment obligation exists.
Scope in practice
The most common question from a utility is which of its sites the standard covers, and the answer is a defined subset rather than the whole fleet.
That has a direct consequence for security spending. Detection deployed evenly across hundreds of substations is expensive and poorly targeted. The assets identified under CIP-014 are, by definition, the ones where consequence is highest, and they are the sensible place to begin an aerial exposure assessment.
Related work
FAQ
▸Does CIP-014 require drone detection?
No. It requires identification of critical assets, evaluation of physical threats and vulnerabilities to them, and a physical security plan. Aerial observation is one threat that an evaluation may reasonably consider. Any reading that arrives at a mandated technology goes beyond the text, and the standard itself governs rather than a summary of it.
▸How does aerial exposure fit an existing CIP-014 evaluation?
As a route by which an attacker gathers the information needed to act. Imagery of transformer banks, control houses, relay equipment, fence lines and access roads supports an attack carried out from outside the perimeter. That makes it relevant to the threat and vulnerability evaluation the standard already requires.
▸We have hundreds of substations. Are they all in scope?
Almost certainly not. The standard applies to assets whose loss could cause instability, uncontrolled separation or cascading outages, which is a defined subset. The identification step, and its third-party verification, is how that subset is established.
▸Why does the standard require third-party review?
Because the consequence of misidentifying a critical asset is significant, and independent verification reduces that risk. In practice it also means utilities are accustomed to commissioning external assessment work in this area, which is not true of every sector.