NERC CIP-004 training requirements (R2.1, R2.2, R2.3) are explained for entities managing Bulk Electric System (BES) Cyber Systems. The minimum training objectives under R2.1 include cyber security policies, physical and electronic access controls, incident response, recovery plans, and cybersecurity risks from electronic interconnectivity. R2.2 mandates that training must be completed before granting electronic or physical access to BES Cyber Assets, covering all personnel including contractors and vendors. R2.3 requires retraining every 15 months (a 'CIP year'). Auditors typically verify compliance by interviewing staff and reviewing training and access records to confirm dates align with access grants.