IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 Access Control

IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-AccessControl-OT-IT-Authentication-Authorization: IAEA NSS-17 - Access Control + Authentication + Authorization + IAM + Privileged Access for OT and IT

NSS-17 + NSS-42-G require comprehensive access control aligned with CSL: unique user identification + no shared accounts where feasible (emergency shared accounts logged + reviewed); strong authentication scaled to CSL (CSL 1 requires multi-factor + smartcard + biometric where feasible; CSL 5 minimum username + strong password); role-based access control (RBAC) with least privilege + need-to-know + separation of duties between safety + security + operations + maintenance + IT + cyber security; account lifecycle management (provisioning at hire + transfer + termination + retirement) with trustworthiness verification per Personnel Security (CSL-1 cleared personnel only); session management + timeout + lock + concurrent session limits + termination; privileged access management (PAM) with logging + approval workflow + just-in-time access + time-limited + supervised; remote access (vendor + OEM + national authority + IAEA) with prior authorisation + MFA + jump host + supervised + recorded sessions + boundary controls; emergency override + bypass procedures (Captain / Shift Supervisor / Emergency Director) logged + reviewed within 24 hours; access reviews periodic (CSL 1 monthly + CSL 5 annual). Aligned with IEC 62443-3-3 SR 1.1-1.13 + IEC 62443-4-2 CR 1.1-1.13 + NIST SP 800-53 AC family. OT-specific: legacy CBS without native authentication wrapped with overlay (jump server) + compensating physical controls + network segmentation. IAEA NSS-17 + access + authentication + IAM + PAM + RBAC + CSL-scaled applies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.