OT & UTILITIES
What Is BES Cyber System?
DEFINITION
A BES Cyber System is one or more BES Cyber Assets grouped under NERC CIP-002 that, if rendered unavailable, degraded, or misused, would adversely impact reliable operation of the bulk electric system within 15 minutes. Each system is categorized as high, medium, or low impact, and that categorization determines which NERC CIP requirements apply to it.
A BES Cyber System is defined in the NERC glossary as one or more BES Cyber Assets logically grouped to perform one or more reliability tasks. The operative test comes from the underlying BES Cyber Asset definition: a cyber asset that, if rendered unavailable, degraded, or misused, would adversely impact the reliable operation of the bulk electric system within 15 minutes. CIP-002 requires responsible entities to identify their BES Cyber Systems and categorize them as high, medium, or low impact using bright-line criteria.
The concept matters because categorization drives everything else in the NERC CIP standards. A high impact control center system carries dozens of requirements across electronic security perimeters, system security management, monitoring, and change management, while a low impact system faces a much shorter list under CIP-003.
The practical implication is that scoping is the highest-leverage compliance decision a utility makes. Grouping choices, the 15-minute impact analysis, and the treatment of associated assets such as EACMS and PACS determine audit exposure for years. Misidentified or unidentified BES Cyber Systems are among the most common and costly audit findings, so the categorization exercise deserves engineering rigor, not a spreadsheet afterthought.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →