Implement security controls per 10 CFR 73.54(c) consistent with NRC Regulatory Guide 5.71 Appendix B (Technical and Operational Cyber Security Controls) + Appendix C (Cyber Security Programme Controls). Technical controls per Appendix B cover (a) access control including unique identification + authentication + authorisation + concurrent session control + remote access + wireless restrictions + portable and mobile device controls, (b) audit and accountability including event types + content + storage + reporting + analysis + retention, (c) configuration management including baselines + least functionality + change control + verification, (d) system and information integrity including malicious code protection + monitoring + spam protection + flaw remediation + integrity verification, (e) defence-in-depth including boundary protection + isolation + monitoring at boundaries + protection from cyber-attacks during processing + transmission + storage, (f) maintenance including controlled maintenance + maintenance personnel + remote maintenance + diagnostic tools. Programme controls per Appendix C cover policy + procedures + roles and responsibilities + training and awareness + system security planning + security assessment + incident response + system and services acquisition + supply chain + risk assessment + contingency planning + safeguards. NRC RG 5.71 Appendix B contains approximately 145 control objectives + Appendix C contains 30 programmatic control objectives. Mapping evidence to RG 5.71 controls is the primary basis for NRC inspection findings.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 152 controls across 88 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties