← Frameworks / Nuclear Regulation

10 CFR 73.54 Protection of Digital Computer and Communication Systems and Networks

US Nuclear Regulatory Commission mandatory cybersecurity regulation for nuclear power plants and fuel cycle facilities. Requires protection of Critical Digital Assets (CDAs) associated with safety, security, and emergency preparedness functions from cyber attacks up to and including the Design Basis Threat. Implements defense-in-depth through a 5-level security architecture per NRC Regulatory Guide 5.71. Covers technical, operational, and management controls with NRC-approved Cyber Security Plans, ongoing assessment, and integration with physical protection programs.

Clause Title SP 800-53 Controls
73.54(a) Scope and Applicability
73.54(b) Cyber Security Plan
73.54(c)(1) Protection of Critical Digital Assets
73.54(c)(2) Defense-in-Depth Protective Strategies
73.54(d) Ongoing Assessment and Program Review
RG5.71-A-AC Technical Controls - Access Control
RG5.71-A-AU Technical Controls - Audit and Accountability
RG5.71-A-SC Technical Controls - System and Communications Protection
RG5.71-A-SI Technical Controls - System and Information Integrity
RG5.71-B-CM Operational Controls - Configuration Management
RG5.71-B-CP Operational Controls - Contingency Planning
RG5.71-B-MA Operational Controls - Maintenance
RG5.71-B-PE Operational Controls - Physical and Environmental Protection
RG5.71-C-AT Management Controls - Awareness and Training
RG5.71-C-CA Management Controls - Security Assessment and Authorization
RG5.71-C-PL Management Controls - Planning and Risk Assessment
RG5.71-C-PS Management Controls - Personnel Security
RG5.71-C-SR Management Controls - Supply Chain