NSS-17 + NSS-42-G require personnel security + trustworthiness verification + training + awareness aligned with CSL access. Personnel security: background check + criminal record + financial + employment history + reference check + national security clearance for CSL 1-2 access + periodic re-investigation; continuous evaluation + insider threat program + behavioral observation; foreign travel + financial holdings disclosure per national rules; security clearance reciprocity with national authority. Trustworthiness verification: trustworthiness baseline established at hire + maintained through periodic re-evaluation + adjusted on adverse events + insider threat indicators; trustworthiness criteria per CSL (CSL 1 stringent + CSL 5 minimum). Training: cyber awareness for all personnel (phishing + social engineering + USB hygiene + password + reporting + incident response basics); role-based training for: Plant Manager + Operations Manager + Shift Supervisor + Operator + Engineer + Health Physics + IT + Cyber Security + Maintenance + Vendor; refresher annually + post-incident + post-update; specialised training for: Computer Security Officer (CSO) + IR Team + Forensic + Threat Intel + Penetration Tester + national CSIRT liaison; IAEA International School of Nuclear Security NSS-17-T training; Computer Security Exercise (CSE) participation. Cyber hygiene policies: USB / removable media + email + browser + mobile + BYOD + remote work + social media + travel; insider threat reporting; suspicious activity reporting. IAEA NSS-17 + personnel + trustworthiness + clearance + training + awareness + cyber hygiene applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.