# FERC Orders Directing NERC CIP Standard Development

Framework id: `ferc_cip`. Energy Regulation. Publisher: Federal Energy Regulatory Commission (FERC). Version: 2006-2024. Region: USA. Mapping licence: CC BY-SA 4.0.
Source text: https://www.ferc.gov/industries-data/electric/industry-activities/critical-infrastructure-protection

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (8, average coverage 70%)
- Order 706 Mandatory Reliability Standards for CIP: PM-01, PM-02, PM-09, PL-01, PL-02 (70%)
- Order 829 Supply Chain Risk Management: SR-01, SR-02, SR-03, SR-05, SR-06, SA-04, SA-09, SA-22, CM-14 (78%)
- Order 850 Supply Chain Enhancements (EACMS/PACS Expansion): SR-01, SR-02, SR-03, SR-06, SR-11, PE-03, AC-02, IA-02 (72%)
- Order 881 Internal Network Security Monitoring (INSM): SI-04, CA-07, SC-07, AU-06, SC-48, IR-04 (70%)
- Order 887 Virtualization and Cloud for BES Cyber Systems: SC-07, AC-04, CM-02, CM-07, SC-02, SC-39 (72%)
- Order 888 CIP Low-Impact BES Cyber Systems Enhancements: AC-01, AT-01, AT-02, PE-01, PE-03, IR-01, IR-04 (78%)
- Order 893 Incentive-Based Rate Treatment for CIP Cybersecurity Investment: PM-01, PM-09, PM-14, CA-07 (55%)
- Order 2222 DER Cybersecurity for Wholesale Market Participation: AC-04, SC-07, IA-03, IA-09, SC-08, PM-11 (62%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=ferc_cip
- Control-to-clause mappings as JSON: /api/v1/frameworks/ferc_cip?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/ferc-cip.json
- Page for people: /frameworks/ferc-cip/
