NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
Cybersecurity Plan and Programme

NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity NRC7354-1: Cybersecurity Plan, Programme Establishment, and NRC Submission

Establish and submit a cybersecurity programme per 10 CFR 73.54(a) + 73.54(d) for NRC review and approval. The licensee must provide high assurance that digital computer and communication systems and networks are adequately protected against cyber attacks up to and including the design basis threat as described in 10 CFR 73.1. Programme establishment per 73.54(a) requires (a) analyse digital computer and communication systems and networks and identify those associated with safety-related and important-to-safety functions + security functions + emergency preparedness functions including offsite communications + support systems and equipment which if compromised would adversely impact safety + security or emergency preparedness functions (Critical Digital Assets or CDAs), (b) protect those identified CDAs from cyber attacks that would adversely impact the design function. Cybersecurity Plan per 73.54(d) must describe how the licensee will implement the requirements of this section + must account for the site-specific conditions that affect implementation + describe how the licensee will maintain the cybersecurity programme + must be submitted to the NRC for approval. Programme must be implemented + maintained + reviewed and updated per 73.54(d)(2).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.