Operate programme oversight + independent review + documentation + training + supply chain per 10 CFR 73.54(d) + (g) + NRC RG 5.71 Appendix C. Programme oversight per 73.54(d)(2) requires the cybersecurity programme to be (a) reviewed as a component of the physical security programme + maintained for the life of operating licence per 73.54(g), (b) independently reviewed at least every 24 months + assessed for effectiveness against the cybersecurity plan + and against current threats + technology + organisational changes, (c) management review of programme metrics + control performance + incident trends + audit findings with documented closure tracking. Documentation per 73.54(d) + (e) must (a) maintain records sufficient to demonstrate compliance with the cybersecurity plan + maintain change history + assessment results + incident records + training records, (b) records preservation for life of operating licence + accessible to NRC inspectors. Training and awareness per RG 5.71 Appendix C requires (a) initial training for all personnel with CDA access or cybersecurity responsibilities, (b) annual refresher + role-specific advanced training + tabletop participation, (c) measure effectiveness via testing + observation + incident-rate metrics. Supply chain protection per 73.54(c) + RG 5.71 requires (a) cybersecurity requirements in procurement + RFPs + contracts + acceptance testing for CDA-relevant systems + components + services, (b) vendor cybersecurity assessment + ongoing oversight + vulnerability disclosure agreements + product security incident response, (c) trusted-source verification + tamper-evident seal + verified-clean media for CDA software and firmware, (d) align with NIST SP 800-161 SCRM where applicable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.