NSS-17 + NSS-42-G require vulnerability + patch management + removable media + portable device controls. Vulnerability management: vendor security advisories + CVE feeds + ICS-CERT + national CERT subscriptions; vulnerability scanning (active where feasible on IT + passive on OT); penetration testing in safe context (non-production / commissioning); SBOM-based vulnerability identification (open source + dependencies); risk-rating per CSL + remediation timeline (CSL 1 critical patches within 30 days + emergency same day; CSL 5 within 90 days). Patch management: patch identification per CBS + version tracking + vendor + OEM patch lifecycle; risk-based patch testing on shadow / staging matching production; emergency patch procedure with Regulatory Body notification for safety-critical CBS; patch deferral risk acceptance documented + compensating controls during deferral; firmware + BIOS + microcode + container updates; coordination with refueling outage and maintenance windows + plant availability. Removable media + portable device control: USB / removable media policy (block + scan + approve + log + chain of custody); kiosks for media sanitisation (whitelisted + signature-checked); read-only by default; portable device (laptop + tablet) policy (separate device for OT + sanitisation before connection + escort + supervision); cellular phone / BYOD prohibited or restricted in CSL 1-2 zones. Coordinates with NSS-23-G information classification + NRC RG 5.71 Annex A Group 4 controls. IAEA NSS-17 + vulnerability + patch + media + portable + CSL-scaled applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.