IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 Architecture + Zones
IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-Architecture-Zones-DefenceInDepth-Segmentation: IAEA NSS-17 - Computer Security Architecture + Zone Model + Defence in Depth + Network Segmentation + Boundary
NSS-17 + NSS-42-G require facility computer security architecture organised by Computer Security Zones (CSZs) implementing IAEA zone model. Zones correspond to Computer Security Levels (CSL 1 to CSL 5) with stricter security at higher levels: CSL 1 zones (Safety + Security critical) air-gapped or one-way data flow only + most stringent controls + smallest equipment count + highest assurance; CSL 2 zones (Important to safety / security) limited interconnect with strict boundary + monitoring; CSL 3-4 zones (Operational + business) progressively less restrictive; CSL 5 zones (Untrusted administrative + internet-connected). Conduits between zones use industrial firewalls + data diodes (unidirectional gateways) + DMZ patterns + jump hosts + bastion + protocol breaks + content inspection. Direct connections between Untrusted (CSL 5) and Safety/Security Critical (CSL 1) zones strictly prohibited. Defence in Depth: multiple independent layers of protection per zone (perimeter + network + host + application + data); compensating controls if single layer fails; no single point of failure for critical security functions; assume breach mindset for resilience. Architecture documentation: zone + conduit diagram + boundary devices + access paths + remote support entries + wireless + external interfaces (satellite + leased line + IT integration). Coordinates with IEC 62443-3-3 system requirements + IEC 62645 nuclear-specific industrial cyber + NIST SP 800-82 ICS. IAEA NSS-17 + Zones + CSL + Defence in Depth + Boundary + Conduit applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 182 controls across 113 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
IsraelPPL-Scope-5741-1981-Knesset-Amendment13-March2024-BasicLaw-Dignity-Sec1-Right-Privacy Israel Protection of Privacy Law 5741-1981 Scope + Knesset + Amendment No. 13 March 2024 + Basic Law Human Dignity and Liberty + Section 1 Right to Privacy + Constitutional Status + Chapter 1 Infringement of Privacy
NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
ITU-Scope-Constitution-Convention-Radio-Regulations-WRC-Quadrennial-Treaty-Art1-Definitions ITU Constitution + Convention + Radio Regulations Scope + Article 1 Definitions + Article 2 Nomenclature + WRC World Radiocommunication Conference Quadrennial Treaty Process + Member States + Sector Members