IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 Assurance + Regulator + Improvement

IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-Assurance-Regulator-Inspection-Reporting-Improvement: IAEA NSS-17 - Assurance Activities + Regulator Interface + Inspection + Reporting + Information Sharing + Continuous Improvement

NSS-17 + NSS-42-G require ongoing assurance + regulator interface + reporting + continuous improvement. Assurance activities: internal cyber security audit + management review + control effectiveness testing + penetration testing + red team exercises + ISO 27001 alignment + ISO 19011 audit principles; assessment per CSL (CSL 1 quarterly + annual external; CSL 5 annual internal); root cause analysis on incidents + deficiencies + control failures. Regulator interface: routine reporting (monthly / quarterly status + CSE results + incident summary + audit results + change request + DBT alignment); event-based reporting (significant cyber event + breach + control failure + DBT escalation per Operating Limits and Conditions OLCs); regulator inspection (announced + unannounced + targeted) + inspection response + corrective action; license amendment for material changes (architecture + DBT + CSL re-assignment + decommissioning). Information sharing: national CSIRT (sectoral) + national authority + IAEA Information Circular INFCIRC + Nuclear Threat Initiative (NTI) + International Working Group on Reactors with Innovative Fuels (IWG-RIF) + bilateral agreements + classified information protection per NSS-23-G; cyber threat intel sharing through trusted channels; vulnerability disclosure to vendors + coordinated disclosure. Continuous improvement: lessons learned database + cross-facility sharing + IAEA NUSEC simulator + Computer Security Exercise (CSE) + maturity assessment progression (CSL benchmarking + ISO/IEC 27001 + NIST CSF + ICS Cybersecurity Capability Maturity Model C2M2 + IAEA NSS Maturity Model); industry good practice review (WANO + INPO + Nuclear Energy Agency NEA + EPRI + Idaho National Lab INL Cyber Resilience Center). 2024-2025 pipeline: NSS-17-T Rev 2 + NSS-42-G updates + AI / generative AI for nuclear + quantum-resistant crypto + supply chain assurance + Small Modular Reactor (SMR) + Advanced Reactor cyber. IAEA NSS-17 + Assurance + Regulator + Reporting + Information Sharing + Continuous Improvement applies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.