首页> 外文会议>Annual meeting of the Institute of Nuclear Materials Management >Cyber Security Program for Facilities regulated by the U.S. Nuclear Regulatory Commission
【24h】

Cyber Security Program for Facilities regulated by the U.S. Nuclear Regulatory Commission

机译:U.S核监管委员会规定的设施网络安全计划

获取原文

摘要

In March 2009, the Nuclear Regulatory Commission (NRC) published 10 CFR 73.54, "Protection of Digital Computer and Communications Systems and Networks." This rule required each power reactor licensee to submit a cyber security plan (CSP) and a proposed implementation schedule; the NRC staff reviewed and approved each CSP and implementation schedule for all operating power reactors. The implementation schedule utilized a two-phased approach. The first phase required licensees to address the major cyber security attack vectors and apply cyber security controls to the most risk-significant digital assets no later than December 2012. The second phase, requiring application of cyber security controls to all critical digital assets, is to be completed no later than December 2017. Inspection activities began in early 2013 to review and assess licensee cyber security programs, as well as to verify that the first implementation phase was completed in accordance with regulatory requirements. To date, approximately one third of the U.S. power reactors have been inspected for cyber security. Inspections for full implementation of licensees' cyber security programs will begin in late 2014 or early 2015. Upon completion of full implementation inspection activities, all licensees will be in full compliance with cyber security regulatory requirements. This paper provides an overview of the program, its status, and next steps.
机译:2009年3月,核监管委员会(NRC)公布了10 CFR 73.54,“保护数字计算机和通信系统和网络。”这条规则要求每个电力堆被许可人提交网络安全计划(CSP)和拟议的实施计划; NRC工作人员审查并批准了所有经营电源堆的每个CSP和实施计划。实施时间表利用了双相方法。第一个阶段要求许可人解决主要的网络安全攻击向量,并在2012年12月之前向最大风险重要的数字资产应用网络安全控制。第二阶段,需要将网络安全控制应用于所有关键数字资产,是不迟于2017年12月完成。检验活动于2013年初开始审查和评估被许可人网络安全计划,并核实第一个实施阶段按照监管要求完成。迄今为止,已经检查了大约三分之一的美国电力电抗器的网络安全。全面实施被许可人的网络安全计划的检查将于2014年底或2015年初开始。完成全面执行检查活动后,所有持牌人将全面遵守网络安全监管要求。本文概述了程序,其状态和下一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号