Remote Connectivity

By Jason Georgoulis
CIP Cyber and Physical Security Analyst

Remote connectivity remains a key area of focus in the Electric Reliability Organization (ERO) Compliance Monitoring and Enforcement Program (CMEP) Implementation Plan (IP) for 2026, underscoring the importance of implementing and maintaining security controls for remote access. Interactive Remote Access (IRA) is a NERC-defined term for user-initiated access through remote access technology while using a routable protocol. IRA is commonly used in the support and maintenance of BES Cyber Systems. However, the same connectivity that improves operational efficiency also introduces the risk of malicious actors gaining access. Inadequate safeguards for IRA can lead to unauthorized access of Responsible Entities’ networks, with potentially serious consequences.

CIP-005-7 Requirement R2 establishes security controls for all IRA sessions within an Electronic Security Perimeter (ESP). One of the safeguards is to ensure that all Cyber Assets that initiate IRA must first connect to an Intermediate System instead of directly accessing a BES Cyber System. This creates a security boundary that requires additional authorization before accessing BES Cyber Systems. The connection must also utilize encryption that terminates at the Intermediate System, and all IRA sessions require multi-factor authentication. Registered entities should consider encryption protocols that protect the confidentiality and integrity of any data or credentials that may be present in the communication path.

Responsible Entities can further protect IRA connections by implementing remote access control procedures that provide robust identification and authorization techniques. Having strong multi-factor authentication is one of the most important controls to reduce the risk of compromised credentials being used for unauthorized access.

Additionally, Registered Entities must have one or more methods for determining and disabling active vendor remote access sessions. This includes Interactive Remote Access and system-to-system remote access. Supply chains are another area of focus within the CMEP IP, and vendor remote access may serve as a vector for exploitation without proper controls.

Maintaining an effective remote access program requires continuous oversight. Organizations should consider imposing a least privileged approach, which grants only the minimum level of access necessary for a user, to remote access and periodically review who has remote access. Users who no longer have a need to access BES Cyber Systems should have access revoked to reduce the potential attack surface.

Additional internal controls such as automated mechanisms for monitoring access, setting session limits either by time and/or geolocation of remote users, and periodic reviews of allowed protocols and services can bolster the overall security posture. For best practices surrounding remote access Texas RE encourages Responsible Entities to refer to the AC-17 group of controls in the National Institute of Standards and Technology (NIST) SP 800-53 Rev. 5.