logo

Implementing CIP-015-2: EACMS and PACS Monitoring

ID: b718b413-c461-5834-8908-98e033bedab2

STIX ID: report--b718b413-c461-5834-8908-98e033bedab2

Feed Name: Dragos Blog

Date Published: 2026-02-19

Date Updated: 2026-04-27

...
...

This report provides guidance on implementing NERC CIP‑015‑2 by extending Internal Network Security Monitoring beyond the ESP to EACMS, PACS, and SCI, detailing expected collection, detection, analysis, retention, and protection requirements. It addresses architectural implications (visibility, sensor placement, data aggregation), technology considerations (flexible deployment, cross‑environment correlation, IT/OT protocol awareness), and actionable steps for utilities (inventorying systems, assessing monitoring gaps, engaging IT, evaluating solutions, planning architectures, and developing processes). The document emphasizes integrating anomaly detection with CIP‑008 incident response workflows and highlights how platforms like Dragos can operationalize detections, baselining, and evidence retention to streamline compliance and improve OT security resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.