NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
Regulatory Guide 5.71 Appendix C Security Controls

NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity RG5.71-C.3: Cyber Security Training

Personnel with access to critical digital assets must receive cyber security awareness and role-based training.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 263 controls across 111 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • DSO-3 Data Access Management
  • RMD-1 Reference Data Management
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.2 Personnel
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-2-5.7 Information model delivery
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO/IEC 27011:2024 · 4 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-6.3 Awareness and Training
  • 27011-8.1 User Endpoint Devices

SOC 2 · 4 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • SSAE18-SOC1-06 Transaction Processing Controls
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-37 Personnel management (Very Good)
  • AWWA-1.1 Security Policy and Governance
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures

ISO 22320:2018 · 3 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles

NIST SP 800-53 Rev 5 · 3 controls

  • CISABD-1 Take Ownership of Customer Security Outcomes
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights
  • 58.1 Scope
  • 58.3 Definitions
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • CAT-D1-4 Training and culture
  • CAT-IRP-4 Organizational characteristics
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • 62351-2 Glossary of terms
  • 62351-8 Role-based access control (RBAC)
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications

ISO 27799:2025 · 2 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-09 Security awareness and training program
  • ISO28001-PI-01 Personnel Security Screening
  • ISO28001-PI-02 Security Awareness and Training
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-04 Roles and responsibilities definition
  • ISO27043-14 Privileged access management

ISO/IEC 27400:2022 · 2 controls

  • 27400-3 Terms and definitions
  • 27400-6.1 Secure Device Design

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy

ISO/SAE 21434 · 2 controls

  • ISO21434-04 Roles and responsibilities definition
  • ISO21434-14 Privileged access management
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-190 · 2 controls

  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation
  • SHAREASSESS-1 Information Governance and Risk
  • SHAREASSESS-2 Access Control, Identity, Authentication

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • IM8-RES.2 Disaster Recovery
  • IM8-SEC.2 Access Control

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-SYS-04 Vulnerability Management
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border

UK Bribery Act 2010 · 2 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • UKGAMBLE-1 Scope and Applicability to Licensees
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-01 Security Architecture
  • UK-TSA-NET-02 Access Control and Authentication
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • CFR211-A-3 Section 211.3 - Definitions
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AZ-DPA-2 Article 2 - Basic Concepts

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions
  • CJIS-2 Security Awareness Training
  • FFIEC-05 Roles and responsibilities definition

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy
  • 27050-1.4 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions
  • BIPA-SEC5-1 Biometric Identifier Definition

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition
  • RIDTPPA-1 Scope, Applicability, Definitions
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • SCA-S2 Interpretation and Definitions
  • SWE-2 Relationship to GDPR
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • OB-OPS.2 Performance Standards
  • ACE-CR-4 Cargo Release Authorization
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • UGA-10 Sensitive Personal Data Prohibition

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Regulatory Guide 5.71 Appendix C Security Controls

Query this from an agent

The graph holds this control, the 263 it maps to, and the evidence behind each claim, over MCP and REST.