10 CFR 73.54 Protection of Digital Computer and Communication Systems and Networks
US Nuclear Regulatory Commission mandatory cybersecurity regulation for nuclear power plants and fuel cycle facilities. Requires protection of Critical Digital Assets (CDAs) associated with safety, security, and emergency preparedness functions from cyber attacks up to and including the Design Basis Threat. Implements defense-in-depth through a 5-level security architecture per NRC Regulatory Guide 5.71. Covers technical, operational, and management controls with NRC-approved Cyber Security Plans, ongoing assessment, and integration with physical protection programs.
Clauses: 18
Avg Coverage: 75.1%
Publisher: U.S. Nuclear Regulatory Commission (NRC) Version: 2009 (RG 5.71: 2010) | Clause | Title | SP 800-53 Controls |
|---|---|---|
| 73.54(a) | Scope and Applicability | |
| 73.54(b) | Cyber Security Plan | |
| 73.54(c)(1) | Protection of Critical Digital Assets | |
| 73.54(c)(2) | Defense-in-Depth Protective Strategies | |
| 73.54(d) | Ongoing Assessment and Program Review | |
| RG5.71-A-AC | Technical Controls - Access Control | |
| RG5.71-A-AU | Technical Controls - Audit and Accountability | |
| RG5.71-A-SC | Technical Controls - System and Communications Protection | |
| RG5.71-A-SI | Technical Controls - System and Information Integrity | |
| RG5.71-B-CM | Operational Controls - Configuration Management | |
| RG5.71-B-CP | Operational Controls - Contingency Planning | |
| RG5.71-B-MA | Operational Controls - Maintenance | |
| RG5.71-B-PE | Operational Controls - Physical and Environmental Protection | |
| RG5.71-C-AT | Management Controls - Awareness and Training | |
| RG5.71-C-CA | Management Controls - Security Assessment and Authorization | |
| RG5.71-C-PL | Management Controls - Planning and Risk Assessment | |
| RG5.71-C-PS | Management Controls - Personnel Security | |
| RG5.71-C-SR | Management Controls - Supply Chain |