Insights & Resources

Insights from the Field

Expert perspectives on critical infrastructure protection, compliance, and the evolving security landscape for utilities and industrial sites.

GridGuard News

NERC CIP 014 Security Documentation That Holds Up

NERC CIP 014 Security Documentation That Holds Up

A physical-security plan is only as defensible as the record behind it. NERC CIP 014 security documentation must show more than that a site had a guard, a camera, or a policy on file. It needs to establish what occurred at the facility, who responded, what authority they had, what actions were taken, and how the event was closed or escalated.

For transmission owners and operators managing high-consequence substations and other covered facilities, this documentation supports a larger compliance and risk-management process. For site operations teams, it also protects crews, schedules, equipment, and the public when trespass, theft, vandalism, or suspicious activity occurs. The difference is operational discipline: records created during a shift are often the records reviewed after an incident.

What CIP-014 Documentation Must Support

CIP-014 is not a generic guard-log requirement. Its applicability, facility identification, verification, threat-vulnerability assessment, and security-plan obligations depend on the registered entity and the facility at issue. Security staffing documentation should therefore support the entity's approved processes rather than attempt to replace them.

At the field level, the record should help answer a straightforward set of questions. Was the site secured according to the plan? Were access points checked and controlled? Did an officer identify an unauthorized person, vehicle, or condition? Was law enforcement, site management, dispatch, or emergency response notified? Can the organization produce a clear timeline with supporting evidence?

A one-line note stating "all clear" does not answer those questions. It may show that a shift occurred, but it does not establish meaningful observation, patrol activity, or response. By contrast, a properly completed report documents conditions, decisions, actions, and escalation. That matters during internal review, a post-event investigation, and any examination of how the site carried out its security measures.

Build the Record Around Site Conditions

Good documentation begins before the first patrol. Each location needs a defined post order that reflects its real exposure, not a recycled checklist. A transmission yard under active construction has different risks than an operating substation with limited entry points. A storm-damaged site may need immediate perimeter control and crew-access coordination, while a remote facility may require recurring patrols supported by monitored cameras.

The post order should identify the protected area, controlled entrances, patrol intervals, access procedures, prohibited activity, escalation contacts, communications expectations, and reporting requirements. It should also identify conditions that require immediate action, such as an open gate, cut fence, damaged lock, evidence of copper theft, an unknown vehicle near equipment, or an unauthorized person inside the perimeter.

Documentation should capture both routine activity and exceptions. Routine records establish that the officer was present, performed assigned checks, and observed key security conditions. Exception reports establish what changed, why it mattered, and how it was handled. Both are necessary. An incident file without shift logs can lack context. Shift logs without detailed exception reports can fail to show an adequate response.

Shift Logs Should Be Specific Enough to Verify Work

A useful shift log records the officer's identity, arrival and relief times, assigned location, patrol times, access-control activity, relevant site conditions, and communications with designated contacts. Entries should be time-stamped and written in plain language.

The standard is not to create unnecessary paperwork. The standard is to make the work verifiable. If an officer checked a vehicle gate, pedestrian gate, transformer perimeter, control-house exterior, material storage area, or camera status, the record should identify the check and any condition requiring follow-up.

Vague language creates avoidable exposure. "Patrolled property" does not tell a reviewer what was checked. "Conducted perimeter patrol; south vehicle gate secured, west fence line intact, no unauthorized vehicles observed, damaged warning sign at north access photographed and reported to site contact at 0215" does.

Access Records Need a Clear Chain of Accountability

Unauthorized access is not always dramatic. It can begin with a contractor arriving outside an approved work window, a delivery vehicle using the wrong entry point, a visitor without confirmed authorization, or a former worker attempting to retrieve property. Security documentation should show how access was verified and what happened when it could not be verified.

Where officers are assigned to an entrance or controlled point, records should identify the visitor or company, vehicle information when appropriate, time of entry and exit, authorizing contact, and any denied or delayed access. The depth of the record depends on the site plan and the system already in use. The goal is consistency with the facility's access-control process, not duplicate paperwork for its own sake.

When access is denied, the report should document the reason, the officer's actions, notifications made, and the person's disposition. If a sworn officer addresses trespass or suspected criminal activity, the report should clearly distinguish observed facts from conclusions and identify any enforcement action taken under applicable authority.

Incident Reports Must Preserve Facts and Evidence

The most valuable incident report is written while details are fresh and evidence is preserved. It should state what the officer observed, when and where it occurred, who was involved, what actions were taken, who was notified, and whether the condition remained open at shift end.

Photographs, documented incident footage, dispatch records, call numbers, and witness information can strengthen the report when available and permitted by site procedures. These materials should be retained and handled under the utility's records, evidence, and confidentiality requirements. Camera footage is useful, but it is not a substitute for a trained officer's written account of the condition, response, and enforcement decision.

A report also needs to distinguish between a security event and an unresolved operational issue. For example, an officer may secure an open gate and notify the appropriate contact. If the gate cannot be secured because of a mechanical failure, the report should identify the temporary protective measure, the notified party, and the required follow-up. Closing a report without documenting the remaining vulnerability leaves the organization with an incomplete record.

Why Sworn-Officer Reporting Changes the Security Record

A conventional guard can observe and report. A licensed, insured, off-duty sworn law enforcement officer can observe, report, and directly address criminal conduct within the scope of legal authority. That distinction affects response quality when trespassers refuse to leave, theft is in progress, or a site encounter requires detention, coordination with local agencies, or formal enforcement action.

It also affects documentation. Officers are trained to produce factual reports that preserve timelines, identify involved parties, record notifications, and support later investigation. For critical infrastructure operators, that means the security record is not simply a vendor attendance sheet. It is a field account prepared by personnel accustomed to incident command, evidence awareness, and legal scrutiny.

GridGuard Protective Services deploys sworn Georgia officers for substation, transmission-yard, construction, and outage security, with documentation structured around the site's post orders and escalation requirements. For higher-risk locations, an on-site officer can be paired with remotely monitored solar-camera coverage, 24/7 surveillance, dispatch support, and documented incident footage.

Set Documentation Rules Before Coverage Begins

The strongest reporting program is established during mobilization, not after the first incident. Before coverage starts, confirm who receives daily activity reports, who receives immediate notifications, what events require a written incident report, how photos or video are transmitted, and which contact has authority to direct site access after hours.

This is especially important during storm response and emergency restoration. Conditions change quickly, crews rotate, equipment arrives after dark, and normal access patterns break down. A defined reporting chain keeps security from becoming an isolated function. It gives operations, safety, compliance, and project leadership the same factual picture of site conditions.

Retention practices deserve the same attention. Reports, logs, footage, and related communications should be stored in a way that protects integrity and allows retrieval under the entity's established document-control process. The correct retention period and evidence-handling method depend on the organization's policies, applicable requirements, and the nature of the event. Security vendors should be able to provide records promptly, but the utility or operator should control how those records fit into its broader compliance file.

Measure Documentation by Its Usefulness Under Pressure

The best test of a security record is not whether it looks complete at the end of a quiet shift. It is whether a site manager can use it at 3:00 a.m. to understand an open condition, whether an investigator can reconstruct an event, and whether a compliance team can see that security measures were performed and escalated as required.

That standard calls for clear post orders, accountable staffing, timely reports, documented evidence, and an escalation path with real authority behind it. When those elements are in place, security documentation becomes a working control that protects the facility long before anyone needs to review it.