Compliance at the Edge of the Envelope: CIP Moves to the Cloud
Cloud migration is no longer a theoretical question for utility operations. Asset owners are actively evaluating and intend on deploying cloud-hosted control systems, and asking a harder question alongside it: what happens to CIP-protected data when it moves off-premises? This panel will discuss both challenges: building and operating a NERC CIP Low Impact Control Center in the cloud, and managing BES Cyber System Information in a cloud infrastructure environment.
This panel brings together three perspectives that rarely share a stage: a utility asset owner, a Regional Entity, AWS, and a CIP consulting firm on what the shared responsibility model means when the tenant is a registered BES asset owner with CIP obligations.
Attendees will leave with a practical framework for evaluating cloud feasibility across CIP impact levels, a clear picture of what Regional Entity scrutiny looks like from the inside, and an honest accounting of what the compliance architecture actually costs in time, design, and rigor.
Intended Audience: CIP Compliance Managers, CIP-011 Compliance Leads, CIP Program Managers, OT Security Architects, Engineering and Operations Leadership, IT/OT Cloud Strategy Teams
