How to Support CIP-015-1 Compliance

Network Visibility for CIP-015-1
+ Network Visibility for CIP-015-1

Strengthen Network Visibility Inside Critical Utility Grid Networks

Perimeter controls remain essential, but CIP-015-1 addresses what happens inside protected networks after an attacker, compromised account, or unauthorized device gets through. For high-impact bulk electric system (BES) cyber systems and medium-impact BES cyber systems with external routable connectivity, Requirement R1 requires documented internal network security monitoring (INSM) processes for networks protected by the electronic security perimeter (ESP). Those processes must use risk-based network data feeds to monitor connections, devices, and communications, then detect anomalous activity and evaluate it to determine further action. This shifts the focus from perimeter-only defense toward continuous internal visibility and evidence-backed response.

A practical INSM architecture therefore needs dependable packet access across east-west operational technology (OT) traffic, and a scalable way to deliver relevant data to security analytics, packet capture, and forensic storage. It should minimize blind spots, avoid unnecessary load on production networks, and preserve packet fidelity for investigation. It must also support R2 retention of data associated with anomalous activity until the related action is complete, and R3 protection of collected and retained monitoring data against unauthorized deletion or modification. A modular visibility layer lets utilities change or add security tools without redesigning how traffic is collected and distributed.

Network Visibility Solution for CIP-015-1 Compliance

Strengthening network visibility within the utility grid requires using network packet brokers to aggregate traffic from multiple network taps and switched port analyzer (SPAN) ports, then filter, deduplicate, and steer relevant traffic to security, behavioral analytics, forensic storage, and other monitoring systems. This provides those systems with clean, relevant network data for anomaly detection, evaluation, and investigation. For CIP-015-1, this supports the network visibility data process: collect the right traffic for R1.1; feed high-quality data to analytics for R1.2 and R1.3. Keysight’s application fusion program helps security teams run software sensors from OT security and asset identification vendors such as Forescout, Nozomi, Dragos, Claroty, or Armis, and/or network behavior analysis vendors such as Corelight and Extrahop, directly on their Keysight NPBs. This lets utilities combine Keysight packet access and traffic optimization with the analytics platform that best fits their INSM strategy, while reducing additional sensor hardware and integration overhead.

See Architecture Diagram of Visibility Layer Solutions for CIP-015-1

See Architecture Diagram of Visibility Layer Solutions for CIP-015-1

Explore Products for Our Network Visibility Solution for CIP-015-1 Compliance

Related Use Cases

contact us logo

Get in Touch with One of Our Experts

Need help finding the right solution for you?