IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 Assurance + Regulator + Improvement

IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-Assurance-Regulator-Inspection-Reporting-Improvement: IAEA NSS-17 - Assurance Activities + Regulator Interface + Inspection + Reporting + Information Sharing + Continuous Improvement

NSS-17 + NSS-42-G require ongoing assurance + regulator interface + reporting + continuous improvement. Assurance activities: internal cyber security audit + management review + control effectiveness testing + penetration testing + red team exercises + ISO 27001 alignment + ISO 19011 audit principles; assessment per CSL (CSL 1 quarterly + annual external; CSL 5 annual internal); root cause analysis on incidents + deficiencies + control failures. Regulator interface: routine reporting (monthly / quarterly status + CSE results + incident summary + audit results + change request + DBT alignment); event-based reporting (significant cyber event + breach + control failure + DBT escalation per Operating Limits and Conditions OLCs); regulator inspection (announced + unannounced + targeted) + inspection response + corrective action; license amendment for material changes (architecture + DBT + CSL re-assignment + decommissioning). Information sharing: national CSIRT (sectoral) + national authority + IAEA Information Circular INFCIRC + Nuclear Threat Initiative (NTI) + International Working Group on Reactors with Innovative Fuels (IWG-RIF) + bilateral agreements + classified information protection per NSS-23-G; cyber threat intel sharing through trusted channels; vulnerability disclosure to vendors + coordinated disclosure. Continuous improvement: lessons learned database + cross-facility sharing + IAEA NUSEC simulator + Computer Security Exercise (CSE) + maturity assessment progression (CSL benchmarking + ISO/IEC 27001 + NIST CSF + ICS Cybersecurity Capability Maturity Model C2M2 + IAEA NSS Maturity Model); industry good practice review (WANO + INPO + Nuclear Energy Agency NEA + EPRI + Idaho National Lab INL Cyber Resilience Center). 2024-2025 pipeline: NSS-17-T Rev 2 + NSS-42-G updates + AI / generative AI for nuclear + quantum-resistant crypto + supply chain assurance + Small Modular Reactor (SMR) + Advanced Reactor cyber. IAEA NSS-17 + Assurance + Regulator + Reporting + Information Sharing + Continuous Improvement applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 23 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CAT-D2-1 Threat intelligence
  • CAT-D2-2 Monitoring and analyzing
  • CAT-IRP-5 External threats
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources

BSI IT-Grundschutz · 1 control

  • BSI-16 Threat intelligence integration
  • IS.D.OR.225 External Reporting of Information Security Events

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

ISO/IEC 27011:2024 · 1 control

  • 27011-5.4 Threat intelligence for telecom

ISO/IEC 27400:2022 · 1 control

  • 27400-5.1 IoT Security and Privacy Governance
  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA
  • NATO-NCIRC-4 Cyber Threat Intelligence Sharing and Coordinated Vulnerability Disclosure
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling

OWASP Top 10:2025 · 1 control

  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 23 it maps to, and the evidence behind each claim, over MCP and REST.