logo

NERC CIP-015-2: EACMS, PACS, SCI Monitoring Explained

ID: 97242bb8-df11-5319-a596-15fc45150d05

STIX ID: report--97242bb8-df11-5319-a596-15fc45150d05

Feed Name: Dragos Blog

Date Published: 2026-01-21

Date Updated: 2026-04-27

...
...

Executive summary: This article explains that NERC’s CIP-015-2 proposal expands internal network security monitoring beyond the electronic security perimeter to include EACMS, PACS, and Shared Cyber Infrastructure (SCI), closing a security gap FERC identified where trusted systems outside the ESP can be abused. It describes why these systems are high‑value targets (legitimate connections to ESP, privileged functional authority, reconnaissance value), presents an adversary attack chain (initial compromise, persistence, lateral movement, achieving objectives), and signals a follow-up piece addressing practical implementation and scoping challenges for utilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.