
GIAC Critical Infrastructure Protection (GCIP)
The GIAC Critical Infrastructure Protection (GCIP) certification validates the skills of practitioners who access, support, and maintain critical systems, with a focus on the North American Electric Reliability Corporation's Critical Infrastructure Protection (NERC CIP) standards. It bridges compliance with operational defense, equipping holders with practical implementation strategies to protect power and other critical environments. Earning GCIP demonstrates you understand regulatory requirements and can apply them to keep the grid running securely.
501 practice questions · Updated 2026-07-30
GCIP Curriculum
Every domain, objective, and concept the GCIP exam measures.
- BES Definition
- NERC Definition
- CIP Definition
- Key CIP Terms
- CIP Standard Categories
- Regulatory Context
- Audit Preparation
- Enforcement Treatment
- Reliability Standards Auditor Worksheet
- Reliability Assurance Initiative
- Interactive Remote Access
- Internal Controls Evaluation
- Senior Manager Requirements
- Security Policies
- Low Facility Requirements
- Attachment 1 Criteria
- Operational Effects and Impacts
- NERC Functional Model
- BES Reliability Operating Services
- BES Cyber Asset Identification
- Electronic Security Perimeter Architecture
- External Routable Connectivity Communication
- Access Rules
- Dial-Up Access
- Malicious Communication Detection
- Intermediate Systems
- Interactive Remote Access
- Multi-factor Authentication
- Port and Service Management
- Patch Management
- Malicious Code Prevention
- System Logging
- Authentication Requirements
- Account Management
- Monitoring and Alerting
- Physical Security Plan
- Physical Access Controls
- Visitor Control Program
- Maintenance and Testing of Physical Security
- Monitoring of Physical Security
- Logging and Alerting for Physical Security
- Awareness Program
- Cybersecurity Training Program
- Personnel Risk Assessment
- Access Management Program
- Change Management Process
- Configuration Monitoring
- Vulnerability Assessment Fundamentals
- Transient Cyber Assets
- Removable Media Controls
- Incident Response Plan Components
- Incident Response Plan Development
- Incident Response Plan Testing Methods
- Incident Response Plan Exercise Execution
- Incident Response Plan Testing Evaluation
- Incident Response Plan Reporting Requirements
- Incident Response Reporting Procedures
- Incident Response Plan Continuous Improvement
- Recovery Plan Purpose and Components
- Recovery Plan Testing and Exercise Methods
- Recovery Plan Testing Frequency and Triggers
- Recovery Plan Reporting Requirements
- Information Protection Program Overview
- Information Identification
- Information Classification
- Information Protection Measures
- Information Disposal
- Information Reuse
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCIP, so none is invented.