IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 System Integrity + Configuration

IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-SystemIntegrity-Configuration-Change-Management: IAEA NSS-17 - System Integrity + Configuration Management + Change Management + Baseline + Hardening

NSS-17 + NSS-42-G require system integrity protection through configuration management + change management + baseline control + hardening. Configuration baseline per CBS per CSL: documented hardened baseline + disabled unused services + locked BIOS + secure boot + Trusted Platform Module (TPM) where feasible + signed boot loader + tamper detection; baseline approved at commissioning + reapproved at modification + verified at periodic survey. Change management process: any change to safety/security CBS requires: change request + impact assessment + safety analysis + security analysis + Regulatory Body notification per Operational Limits and Conditions (OLCs); change approval by Plant Manager + Computer Security Officer (CSO) + safety committee + regulator where required; testing on shadow / staging environment matching production fidelity; change implementation under work permit + Operator + maintenance procedures; change verification + validation + commissioning + handover; change records + as-built configuration baseline update. Software integrity: code signing + integrity verification at boot + secure update mechanisms + rollback protection; tamper detection (TPM + intrusion sensors + integrity check); cryptographic hashes + digital signatures for distributed software + firmware + configuration files. Coordinates with IEC 61513 + IEC 62645 + IEC 62859 (Software aspects for computer-based systems performing category A functions) + IAEA Safety Guide SSG-39. IAEA NSS-17 + integrity + configuration + change + baseline + signing applies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.