Operate vulnerability management + configuration management + baseline control + patching per 10 CFR 73.54(c) + NRC RG 5.71 Appendix B Section B.1.3 (Configuration Management) + Section B.1.6 (System and Information Integrity). Configuration management must (a) establish documented baseline configurations per CDA class + version, (b) enforce change control with engineering + cybersecurity + operations review for CDA changes, (c) maintain inventory of CDAs at component level + with configuration attributes + ownership, (d) detect configuration drift via authenticated scanning + integrity monitoring + alerting on deviation, (e) protect baselines + change documentation under access control. Vulnerability management must (a) consume NRC vulnerability advisories + ICS-CERT advisories + vendor advisories + CISA KEV + sector ISAC, (b) assess applicability to CDAs + assign severity considering CDA function + boundary + compensating controls, (c) prioritise remediation per applicable risk + safety + regulatory considerations, (d) implement remediation via patching where feasible OR compensating controls where patching is operationally infeasible (legacy systems + vendor-restricted environments + safety-certified equipment with patch lockdown), (e) document compensating controls + management approval + reassessment cadence. Patching must (a) test patches in pre-production CDA lab matching production CDA topology + safety system configuration, (b) coordinate with vendor support + outage window + regulatory notification where applicable, (c) document the patch deployment + verification + rollback plan.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.