CIP-002-5.1a is foundational to all CIP compliance. It requires identifying Bulk Electric System Cyber Systems, categorizing them by impact (High/Medium/Low), applying consistent documented classification logic, and maintaining defensible, audit-ready records. It sounds straightforward — in practice, it's one of the most judgment-heavy, audit-sensitive requirements in NERC.