NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity NRC7354-2: Critical Digital Asset (CDA) Identification, Scope, and Boundary
Identify and maintain the inventory of Critical Digital Assets (CDAs) per 10 CFR 73.54(b)(1) + (b)(2). CDAs are digital computer and communication systems and networks associated with (a) safety-related and important-to-safety functions, (b) security functions, (c) emergency preparedness functions including offsite communications, (d) support systems and equipment which if compromised would adversely impact safety + security or emergency preparedness functions. CDA identification process must (a) review all digital assets per system + subsystem + component, (b) determine each assets contribution to safety + security + EP functions, (c) document the determination + rationale + evidence per asset, (d) maintain the CDA inventory under configuration management with periodic review, (e) reassess when systems are added + modified + replaced + when functional analysis changes. Boundary definition between CDA and non-CDA networks must be enforced via Defensive Architecture per NRC7354-3 with technical and procedural controls preventing unauthorised cyber pathways between non-CDA and CDA networks. NRC RG 5.71 provides additional implementation guidance for CDA identification.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 152 controls across 88 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties