Skip to main content

OT & UTILITIES

What Is Internal Network Security Monitoring (INSM, CIP-015)?

DEFINITION

Internal Network Security Monitoring (INSM) is the NERC CIP-015-1 requirement to collect, analyze, and retain network traffic data inside Electronic Security Perimeters so anomalous east-west activity can be detected. It applies to high impact BES Cyber Systems and medium impact systems with External Routable Connectivity, with compliance deadlines in September 2028 and September 2030 depending on asset category.

Internal Network Security Monitoring is the capability required by NERC standard CIP-015-1: collecting and analyzing network traffic inside the Electronic Security Perimeter to detect anomalous or malicious east-west activity that perimeter controls cannot see. The standard requires responsible entities to implement methods for data collection, detection, and evaluation of anomalous network activity, and to retain the associated data to support investigation.

CIP-015-1 applies to high impact BES Cyber Systems and to medium impact BES Cyber Systems with External Routable Connectivity. Compliance deadlines run in two phases: September 2028 for high impact systems and for medium impact systems with ERC located at Control Centers, and September 2030 for the remaining medium impact systems with ERC.

The practical work is substantial. It means placing sensors in OT networks that were never designed for monitoring, baselining traffic on industrial protocols, and staffing the evaluation of the alerts that follow. Utilities should treat the years before the deadline as design, procurement, and pilot time rather than waiting for the compliance date. See NERC CIP requirements explained and Z Cyber's utilities practice for scoping the effort.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →