IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 Detect + IR + Recovery

IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-Detect-Monitor-Logging-IR-Recovery-Exercises: IAEA NSS-17 - Detection + Monitoring + Logging + Incident Response + Recovery + Computer Security Exercises

NSS-17 + NSS-42-G require continuous monitoring + detection + incident response + recovery aligned with CSL. Logging: all CBS log security-relevant events (authentication + authorization + privileged action + configuration change + network connection + system start/stop + safety event + integrity check + emergency override); centralised log server / SIEM (on-site + air-gapped from corporate IT for CSL 1-2 zones); log retention (typically 1 year minimum + 7 years for safety/security-significant + 30 days online); log integrity protection (signed + write-once + tamper-evident); accurate time synchronisation (NTP + GPS time + atomic clock); log review periodic + automated correlation. Network monitoring: passive network traffic analysis (Dragos / Claroty / Nozomi / SCADAfence) on OT segments; intrusion detection + signatures + behavioral + anomaly; alert generation; on-site Security Operations Centre (SOC) or hybrid with national CSIRT; integration with plant computer system + alarm management. Incident Response Plan (IRP): detection triggers + classification (safety-impact + security-impact + reportable per Regulatory Body) + response team + roles + procedures + escalation + reporting + communication (operator + State + Regulatory Body + national CSIRT + IAEA Incident and Emergency Centre IEC + emergency response organisation); coordination with Emergency Preparedness arrangements per IAEA GSR Part 7. Recovery: backup strategy per CBS (frequency + location + retention + offline + air-gapped) + RTO + RPO; restoration testing + tabletop + recovery time validation; degraded mode operation procedures; safety-critical system manual override + recovery; voyage / operational continuity vs shutdown decision. Computer Security Exercises (CSE): annual minimum + scenarios + red team + tabletop + functional + capstone + IAEA NUSEC simulator; post-exercise improvement. IAEA NSS-17 + Detect + IR + Recovery + Exercises + CSE applies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.