NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
Access Control + Media + Devices

NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity NRC7354-5: Access Control, Authentication, Removable Media, and Portable Devices

Implement access control + authentication + removable media controls per 10 CFR 73.54(c) + NRC RG 5.71 Appendix B Section B.1.1 (Access Control) + Section B.1.7 (System and Communications Protection - Portable Media Controls). Access control must (a) enforce unique user identification + authentication + authorisation for all CDA access including engineering + operations + maintenance + administrative + vendor access, (b) implement multi-factor authentication for privileged access + remote access + access to highest-assurance security levels, (c) enforce least privilege + separation of duties + emergency-access procedures with audit, (d) manage shared accounts only where individual identification is operationally infeasible with compensating monitoring, (e) restrict and log remote access via authorised pathway only (jump host + PAM + session recording + JIT approval). Authentication credentials must follow strong-cryptography requirements with periodic review. Removable media and portable devices controls per RG 5.71 require (a) prohibit removable media + portable devices on highest-assurance security levels except via authorised transfer process, (b) implement sandboxed transfer stations with antivirus + integrity check + content inspection between non-CDA and CDA boundaries, (c) maintain inventory + chain of custody for all media authorised to cross boundaries, (d) configure CDA systems to disable removable media interfaces where operationally feasible.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.