IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
The IAEA Nuclear Security Series No. 17-T (Rev 1) provides technical guidance on implementing computer security at nuclear facilities. It addresses cybersecurity for nuclear instrumentation and control (I&C) systems, safety systems, and information technology supporting nuclear security. Part of the broader IAEA Nuclear Security framework that includes physical protection, nuclear material accounting, and transport security.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Access Control
| Code | Title |
|---|---|
| NSS17-8 | Access Control for OT and IT |
Architecture
| Code | Title |
|---|---|
| NSS17-7 | Zone Model and Network Segmentation |
Assessment and Response
Assessment, monitoring, and incident response
Assurance
| Code | Title |
|---|---|
| NSS17-20 | Assurance Activities and Inspections |
Competent Authority Responsibilities
| Code | Title |
|---|---|
| NSS17-6.1 | Regulatory Requirements |
| NSS17-6.2 | Inspection and Assessment |
| NSS17-6.3 | Information Sharing |
Computer Security Architecture
| Code | Title |
|---|---|
| NSS17-3.1 | Computer Security Zones |
| NSS17-3.2 | Security Level Architecture |
| NSS17-3.3 | Network Architecture and Segmentation |
| NSS17-3.4 | Defence in Depth |
Computer Security Programme
| Code | Title |
|---|---|
| NSS17-1.1 | Computer Security Policy |
| NSS17-1.2 | Computer Security Programme Establishment |
| NSS17-1.3 | Integration with Management System |
Detection
| Code | Title |
|---|---|
| NSS17-12 | Monitoring, Logging and Detection |
Governance
| Code | Title |
|---|---|
| NSS17-1 | Computer Security Programme |
| NSS17-3 | Roles and Responsibilities |
HR
| Code | Title |
|---|---|
| NSS17-15 | Personnel Security and Trustworthiness |
| NSS17-16 | Security Awareness and Training |
Improvement
| Code | Title |
|---|---|
| NSS17-22 | Continuous Improvement and Lessons Learned |
Incident Response
| Code | Title |
|---|---|
| NSS17-13 | Incident Response and Recovery |
Lifecycle
| Code | Title |
|---|---|
| NSS17-18 | Lifecycle and Decommissioning |
Monitoring, Response and Recovery
| Code | Title |
|---|---|
| NSS17-5.1 | Continuous Monitoring |
| NSS17-5.2 | Incident Response |
| NSS17-5.3 | Recovery and Continuity |
| NSS17-5.4 | Computer Security Exercises |
Operations
| Code | Title |
|---|---|
| NSS17-10 | Vulnerability and Patch Management |
| NSS17-9 | Configuration and Change Management |
Physical Security
| Code | Title |
|---|---|
| NSS17-17 | Physical Protection of Computer Systems |
Protective Measures
| Code | Title |
|---|---|
| NSS17-4.1 | Access Control |
| NSS17-4.2 | System Integrity |
| NSS17-4.3 | Supply Chain Security |
| NSS17-4.4 | Configuration Management |
Regulatory
| Code | Title |
|---|---|
| NSS17-21 | Regulator Interface and Reporting |
Risk Assessment and Management
| Code | Title |
|---|---|
| NSS17-2.1 | Threat Assessment |
| NSS17-2.2 | Vulnerability Assessment |
| NSS17-2.3 | Risk-Informed Approach |
| NSS17-2.4 | Consequence Analysis |
Risk Management
| Code | Title |
|---|---|
| NSS17-2 | Graded Approach and Security Levels |
| NSS17-4 | Threat Assessment and DBT Alignment |
| NSS17-5 | Risk Assessment Methodology |
Safety
| Code | Title |
|---|---|
| NSS17-19 | Interfaces with Safety and Emergency Systems |
Supply Chain
| Code | Title |
|---|---|
| NSS17-14 | Supply Chain and Third Party Security |
Technical Controls
| Code | Title |
|---|---|
| NSS17-11 | Removable Media and Portable Device Control |
| NSS17-6 | Baseline Security Functions per Level |
Your Compliance Coverage
If you comply with IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), you already cover:
NIST Cybersecurity Framework 2.0
25%
11 controls mapped
Compare →HKMA Cyber Resilience Assessment Framework (C-RAF)
23%
10 controls mapped
Compare →CISA Industrial Control Systems (ICS) Security Guidance
23%
10 controls mapped
Compare →+ 636 more: NIST SP 800-82 Rev 3 - Guide to OT Security (23%), FedRAMP Rev 5 (23%)
See all 639 mapped frameworks ↓Maps to 639 other frameworks
Frequently Asked Questions
What is IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)?
IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) is a compliance framework from International (IAEA) with 23 domains and 44 controls. The IAEA Nuclear Security Series No. 17-T (Rev 1) provides technical guidance on implementing computer security at nuclear facilities. It addresses cybersecurity for nuclear instrumentation and control (I&C) systems, safety systems, and information technology supporting nuclear security. Part of the broader IAEA Nuclear Security framework that includes physical protection, nuclear material accounting, and transport security. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) have?
IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) has 44 controls organised across 23 domains. The largest domains are Computer Security Architecture (4 controls), Monitoring, Response and Recovery (4 controls), Protective Measures (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) map to?
IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) maps to 639 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (25% coverage), HKMA Cyber Resilience Assessment Framework (C-RAF) (23% coverage), CISA Industrial Control Systems (ICS) Security Guidance (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) compliance?
Start your IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required