Operate monitoring + assessment + incident response + contingency per 10 CFR 73.54(c) + NRC RG 5.71 Appendix C + 10 CFR 73.77 (Cybersecurity Event Notification + reporting requirements established by 2015 final rule). Monitoring per RG 5.71 must (a) continuous monitoring of CDA networks + hosts + applications via OT-aware sensors + EDR where supported + SIEM correlation + threat intelligence, (b) periodic assessment via cybersecurity audits + penetration testing + tabletop exercises + control effectiveness measurements. Incident Response per RG 5.71 Appendix C must (a) document IR plan covering scenarios + roles + activation + containment + recovery + post-incident review + integrate with broader physical security + emergency preparedness response, (b) IR team including cybersecurity + plant operations + engineering + safety + EP + Public Affairs + legal + executive leadership, (c) 24x7 monitoring + on-call cybersecurity response capability. Reporting per 10 CFR 73.77: (a) cybersecurity events that adversely impact or could adversely impact safety + security + EP functions must be reported to NRC Headquarters Operations Center within timeframes specified by event severity (1 hour + 4 hour + 8 hour + 24 hour thresholds), (b) maintain reporting log + after-incident reports + NRC engagement. Contingency planning per 10 CFR 73.54(c) requires (a) backup + recovery procedures + alternate processing capability where appropriate + restoration procedures, (b) integration with broader emergency preparedness plan.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.