IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 System Integrity + Configuration

IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-SystemIntegrity-Configuration-Change-Management: IAEA NSS-17 - System Integrity + Configuration Management + Change Management + Baseline + Hardening

NSS-17 + NSS-42-G require system integrity protection through configuration management + change management + baseline control + hardening. Configuration baseline per CBS per CSL: documented hardened baseline + disabled unused services + locked BIOS + secure boot + Trusted Platform Module (TPM) where feasible + signed boot loader + tamper detection; baseline approved at commissioning + reapproved at modification + verified at periodic survey. Change management process: any change to safety/security CBS requires: change request + impact assessment + safety analysis + security analysis + Regulatory Body notification per Operational Limits and Conditions (OLCs); change approval by Plant Manager + Computer Security Officer (CSO) + safety committee + regulator where required; testing on shadow / staging environment matching production fidelity; change implementation under work permit + Operator + maintenance procedures; change verification + validation + commissioning + handover; change records + as-built configuration baseline update. Software integrity: code signing + integrity verification at boot + secure update mechanisms + rollback protection; tamper detection (TPM + intrusion sensors + integrity check); cryptographic hashes + digital signatures for distributed software + firmware + configuration files. Coordinates with IEC 61513 + IEC 62645 + IEC 62859 (Software aspects for computer-based systems performing category A functions) + IAEA Safety Guide SSG-39. IAEA NSS-17 + integrity + configuration + change + baseline + signing applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

NIST SP 800-53 Rev 5 · 3 controls

API 1164 · 2 controls

  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

IEC 62443 · 2 controls

  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems

ISO/IEC 27019:2024 · 2 controls

  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems

NIST SP 1800-32 · 2 controls

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-190 · 2 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-7 Configuration Management
  • CAT-D3-3 Corrective controls
  • FFIEC-10 Secure configuration standards

IEEE 1686 · 1 control

  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability

ISMAP (Japan) · 1 control

  • ISO-26262-8-7 Configuration management
  • ISO20000-10 Configuration management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.4 Default Configuration Security

ITIL 4 · 1 control

  • ITIL4-10 Configuration management

MTCS (Singapore) · 1 control

  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM
  • MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation
  • AQAP2110-4 Configuration Management and Change Control

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-146 · 1 control

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management

South Korea ISMS-P · 1 control

  • ISMSP-SYS-01 System Hardening and Patch Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.