Published December 2018 | Version v1
Report

A Graded Approach to Cybersecurity: Smaller Facilities, Temporary Jobsites, or Multiple Authorities

  • 1. United States Nuclear Regulatory Commission (United States)

Description

In 2013, a U.S. Nuclear Regulatory Commission (NRC)/Agreement State working group, the Byproduct Materials Cyber Security Working Group, was formed to evaluate: (1) the potential consequences that may occur if the availability, integrity, or confidentiality of data or systems associated with risk-significant quantities of radioactive material* were compromised by a cyberattack, and (2) whether additional regulatory measures or guidance were needed to ensure adequate protection against cyber security threats. The working group completed its evaluation in summer 2017 and, as a result of its comprehensive analysis, concluded that risk-significant radioactive materials licensees do not rely solely on digital systems to ensure either safety or physical protection. Rather, these licensees generally employ a suite of measures, such as doors, locks, barriers, human resources, and operational processes, to ensure security, reflecting a defence-in-depth approach to physical protection. The working group found that a compromise of digital assets (including only the operability of those systems for which the NRC has regulatory authority) would not result in a direct dispersal of risk-significant quantities of radioactive material, or an exposure of individuals to radiation, without a concurrent and targeted breach of the physical protection measures in force for these licensees. Such a cyber attack alone would not result in any onsite or offsite consequences. Therefore, the working group determined that the current cyber security threat faced by risk-significant radioactive materials licensees does not warrant developing new regulations related to protection of their material against cyber security threats. This determination also aligns with the determination made with respect to facilities (such as non-power reactor facilities and independent spent fuel storage installations) that could have similar resultant consequences from a cyberattack. Although the working group determined that no regulatory changes were warranted, they identified that it would be prudent to communicate effective practices for cyber security for risk- significant radioactive materials licensees. This is intended to provide licensees a better understanding of contemporary cybersecurity issues and enable licensees to consider strategies to protect digital assets (e.g., computers, digital alarm systems), including those assets used to facilitate compliance with physical security requirements. This paper will describe the process the working group used in the evaluation. It will also describe the development of the effective practices paper that will leverage existing cybersecurity guidance developed for other classes of licensees, such as for non-power reactors, and guidance developed by other US Government agencies. The NRC will also continue to monitor the constantly evolving cyber security threat landscape and coordinate cyber security efforts such as sharing of effective practices and outreach efforts with US Government agencies, State agencies, and stakeholders. *Risk-significant quantities of radioactive material are defined as those meeting the thresholds for Category 1 and Category 2 as included in the IAEA Code of Conduct on the Safety and Security of Radioactive Sources. (author)

Part of:
International Conference on the Security of Radioactive Material: The Way Forward for Prevention and Detection. Book of Synopses

Additional details

Publishing Information

Imprint Title
International Conference on the Security of Radioactive Material: The Way Forward for Prevention and Detection. Book of Synopses
Imprint Pagination
529 p.
Journal Page Range
p. 223-224
Report number
IAEA-CN--269

Conference

Title
The Way Forward for Prevention and Detection
Acronym
International Conference on the Security of Radioactive Material
Dates
3-7 Dec 2018
Place
Vienna (Austria)

INIS

Country of Publication
International Atomic Energy Agency (IAEA)
Country of Input or Organization
International Atomic Energy Agency (IAEA)
INIS RN
51006936
Subject category
S98: NUCLEAR DISARMAMENT, SAFEGUARDS AND PHYSICAL PROTECTION;
Resource subtype / Literary indicator
Conference
Descriptors DEI
ALARM SYSTEMS; CYBER ATTACKS; DIGITAL SYSTEMS; HAZARDS; IAEA; LICENSES; MONITORS; PHYSICAL PROTECTION; POWER REACTORS; RADIATION SOURCES; RADIOACTIVE MATERIALS; REGULATIONS; SAFETY; SECURITY; SPENT FUEL STORAGE; VENTILATION BARRIERS
Descriptors DEC
CRIME; ENGINEERED SAFETY SYSTEMS; INTERNATIONAL ORGANIZATIONS; LAWS; MATERIALS; MEASURING INSTRUMENTS; REACTORS; SABOTAGE; STORAGE

Optional Information

Secondary number(s)
IAEA-CN--269-166