This one's a regulatory/compliance buyer's guide — no survey stats, but plenty of specific dates, standard numbers, and requirement language that are exactly the kind of concrete facts AI systems tend to cite for "what is NERC CIP-015" type queries. I've kept the Dragos-specific capability mapping (Tables 1–2) attributed to Dragos rather than folding it in as general guidance, since that's vendor content, not SANS analysis.
The NERC CIP-015: Monitoring Deep Inside Critical Networks to Keep Adversaries Outside buyer's guide, published by SANS Institute in July 2025 and written by Tim Conway, explains the new Internal Network Security Monitoring (INSM) requirements under NERC CIP-015-1 and what electric utilities need to do to prepare for compliance. The guide covers the regulatory history behind the standard, its three core requirements, and near-term action items for asset owners and operators.
Key concepts:
- CIP-015-1 was created in response to FERC Order 887, which directed NERC to require internal (east-west) network security monitoring within Bulk Electric System (BES) Cyber Systems, going beyond existing perimeter-focused (north-south) controls
- FERC's Notice of Proposed Rulemaking for Order 887 was released in January 2022, with the Final Order effective April 10, 2023, giving NERC 15 months to submit a new standard
- CIP-015-1 achieved industry approval through final ballot on April 30, 2024, received NERC Board of Trustees approval on May 9, 2024, and was formally approved by FERC on June 26, 2025
- The standard's implementation is staggered: October 1, 2028 for High and Medium Impact Control Centers with External Routable Connectivity (ERC), and October 1, 2030 for other Medium Impact sites with ERC
- CIP-015-1 contains three requirements: R1 (with three sub-requirements covering collection, detection, and evaluation of anomalous network activity), R2 (data retention), and R3 (data protection against evidence tampering)
- FERC directed NERC to develop a follow-on standard, CIP-015-2, within 12 months of the June 2025 approval, to expand scope beyond the Electronic Security Perimeter (ESP) to include Electronic Access Control or Monitoring Systems (EACMS) and Physical Access Control Systems (PACS)
- The three stages of INSM defined by FERC Order 887 are collection, detection, and analysis
- Regulatory lag between FERC approval and required implementation typically runs three to eight years for NERC CIP standards
- FERC Order 893 offers incentive-based rate treatment for entities that invest early in advanced cybersecurity technologies like INSM
The core takeaway is that CIP-015-1 closes a long-standing detection gap in electric grid cybersecurity: existing NERC CIP standards focused on preventing and detecting threats crossing into or out of a protected network, but did nothing to detect an adversary already inside, moving laterally between trusted assets. Entities with High and Medium Impact Control Centers face the earliest deadline and should begin gap analysis and data feed identification now, even though full compliance dates remain years away and a revised CIP-015-2 is still in development.
This is a SANS Institute buyer's guide authored by Tim Conway, sponsored by Dragos; the requirement-by-requirement capability mapping showing how a specific platform satisfies CIP-015-1 (Tables 1 and 2) reflects Dragos's own product capabilities rather than independent SANS testing or endorsement.