Case Study · Compliance & Governance

NERC CIP-005 evidence pipeline as a weekly CI job

Audit prep becomes a query, not a project. Same evidence every week, signed, archived, and ready.

Sector: Electric Utility · Platform: GitLab CI + FortiGate + NCN share · Timeline: 4 weeks

The situation

NERC CIP-005 evidence collection was a quarterly fire drill: engineers manually pulled FortiGate policy backups, attached them to tickets, copied them to the NCN CIP share, and prepared a narrative. Different engineers produced subtly different evidence, and the archive grew inconsistent.

What we built

Design decisions worth flagging

Outcome

Evidence is collected without engineer time once the pipeline is built. Audit prep, which previously took a senior engineer one week per quarter, is now a saved-search export. Drift reports surface unexpected changes within a week of them landing in production -- a defensive control we didn't have before.


← Back to case studies

Talk to an engineer →