NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
Defensive Architecture

NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity NRC7354-3: Defensive Architecture, Multi-Layer Defense, and Network Segregation

Implement Defensive Architecture per 10 CFR 73.54(c) using a defense-in-depth approach with multiple layers of protection. NRC RG 5.71 Appendix B describes the recommended Defensive Architecture with five Security Levels (Levels 4 + 3 + 2 + 1 + 0 with 4 highest assurance) separated by Security Boundary Devices (deterministic one-way data flow at the highest assurance boundaries and stateful protocol-aware enforcement at lower-assurance boundaries). Levels approximately correspond to (a) Level 4: safety + important-to-safety + security functions CDAs, (b) Level 3: emergency preparedness + balance-of-plant CDAs supporting Level 4, (c) Level 2: site IT networks supporting plant operations, (d) Level 1: corporate IT networks, (e) Level 0: external networks. Network segregation must (a) physically separate CDA networks from non-CDA networks where deterministic one-way enforcement is required, (b) use unidirectional gateways (data diodes) for the highest-assurance boundaries (Level 4 to Level 3 + Level 3 to Level 2), (c) use stateful firewall + protocol-aware enforcement + intrusion detection at lower-assurance boundaries, (d) prohibit any direct connection between Level 4 CDA networks and Level 0/1 untrusted networks. Document the architecture + boundary devices + traffic policies + monitoring.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.