U.S. Cyber Security Experiences and Regulations Overview

u s cyber security u s cyber security experiences n.w
1 / 7
Embed
Share

Explore the U.S. Nuclear Regulatory Commission's (NRC) cyber security initiatives, including the development of regulations, program implementation, generic defensive architecture, and future inspection programs. Learn about key components such as the Cyber Rule 10 CFR73.54, licensee implementation schedules, industry collaborations, and assessment of security controls. Stay informed about the evolving landscape of cyber security in the nuclear industry.

  • Cyber Security
  • U.S. NRC
  • Regulations
  • Nuclear Security
  • Industry Collaboration

Uploaded on | 0 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author. If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. U.S. CYBER SECURITY U.S. CYBER SECURITY EXPERIENCES EXPERIENCES Jim Beardsley, Chief Jim Beardsley, Chief Cyber Security Branch (CSB) Cyber Security Branch (CSB) Division of Physical and Cyber Security Policy (DPCP) Division of Physical and Cyber Security Policy (DPCP) Office of Nuclear Security and Incident Response (NSIR) Office of Nuclear Security and Incident Response (NSIR) james.beardsley@nrc.gov james.beardsley@nrc.gov

  2. US NRC Cyber Security Regulation Development Development of the Cyber Rule 10 CFR73.54 for NPPs Industry s Voluntary Implementation of an Interim Cyber Security Program NRC Conducts Assessment Visits NRC Issues various Orders & Guidance Documents for NPPs and Fuel Cycle Facilities to address the Physical & Cyber Threat Updated DBT 10 CFR 73.1 (Applicable to NPPs and Fuel Cycle Facilities) DBT Update Public Law 109-58 Energy Policy Act 2005 02/11/2020 2

  3. US NRC Cyber Security Program Implementation Licensee Interim Implementation Completed RG 5.71 & NEI 08-09 Implementation Guidance Acceptable for Use NRC Cyber Security Notification Rule 10 CFR 73.77 Full Implementation NRC & Industry agree on MS 1 7 Implementation Schedule Industry s Interim Implementation Schedule MS 1 7 Inspections Cyber Security Implementation Inspections 2009 2017 2010 2011 2012 2013 2014 2015 2016 NRC & Industry collaborative work on implementation guidance: Security Frequently Asked Questions (SFAQs) All NPPs Cyber Security Plans & Implementation Schedules Approved NEI 13-10 Assessment of Security Controls NRC Participates in Industry Workshops & Tabletops to assess inspection procedure Development of Additional Guidance for Implementation Schedules 02/11/2020 3

  4. Generic Defensive Architecture Site Network Corporate Network Security / Safety Systems Internet One-way Deterministic Device 02/11/2020 4

  5. Future of US NRC Cyber Security Program Licensee Interim Implementation Completed RG 5.71 & NEI 08-09 Implementation Guidance Acceptable for Use NRC Cyber Security Notification Rule 10 CFR 73.77 Full Implementation NRC & Industry agree on MS 1 7 Implementation Schedule Full Implementation Inspections at all Licensee Sites Industry s Interim Implementation Schedule MS 1 7 Inspections Future Inspection Program 2009 2017 2010 2011 2012 2013 2014 2015 2016 2020 2018 2019 NRC & Industry collaborative work on implementation guidance: Security Frequently Asked Questions (SFAQs) All NPPs Cyber Security Plans & Implementation Schedules Approved Power Reactor Cyber Security Self-Assessment NEI 13-10 Assessment of Security Controls NRC Participates in Industry Workshops & Tabletops to assess inspection procedure Development of Additional Guidance for Implementation Schedules 02/11/2020 5

  6. Future Cyber Security Effort Review criteria for digital asset analysis and protection Emergency Preparedness, Balance-of-Plant, Security, Safety-Related and Important-to-Safety Identify best practices for digital asset assessment Evaluate the control set applied to protect digital assets Future inspection program Incorporate performance licensee metrics into inspection process Evaluate performance testing as a element in the inspection/oversight program 02/11/2020 6

  7. Questions 02/11/2020 7

More Related Content