首页> 外文会议>Annual meeting of the Institute of Nuclear Materials Management >Cyber Security Program for Facilities regulated by the U.S. Nuclear Regulatory Commission
【24h】

Cyber Security Program for Facilities regulated by the U.S. Nuclear Regulatory Commission

机译:美国核监管委员会监管的设施网络安全计划

获取原文

摘要

In March 2009, the Nuclear Regulatory Commission (NRC) published 10 CFR 73.54, "Protection of Digital Computer and Communications Systems and Networks." This rule required each power reactor licensee to submit a cyber security plan (CSP) and a proposed implementation schedule; the NRC staff reviewed and approved each CSP and implementation schedule for all operating power reactors. The implementation schedule utilized a two-phased approach. The first phase required licensees to address the major cyber security attack vectors and apply cyber security controls to the most risk-significant digital assets no later than December 2012. The second phase, requiring application of cyber security controls to all critical digital assets, is to be completed no later than December 2017. Inspection activities began in early 2013 to review and assess licensee cyber security programs, as well as to verify that the first implementation phase was completed in accordance with regulatory requirements. To date, approximately one third of the U.S. power reactors have been inspected for cyber security. Inspections for full implementation of licensees' cyber security programs will begin in late 2014 or early 2015. Upon completion of full implementation inspection activities, all licensees will be in full compliance with cyber security regulatory requirements. This paper provides an overview of the program, its status, and next steps.
机译:2009年3月,核监管委员会(NRC)发布了10 CFR 73.54,“数字计算机和通信系统与网络的保护”。该规则要求每个动力反应堆被许可方都必须提交一份网络安全计划(CSP)和拟议的实施时间表; NRC工作人员审查并批准了所有运行中的反应堆的每个CSP和实施时间表。实施时间表采用了两阶段方法。第一阶段要求被许可方应对主要的网络安全攻击媒介,并在不迟于2012年12月之前将网络安全控制应用于风险最大的数字资产。第二阶段则要求对所有关键数字资产应用网络安全控制。这项工作将于不迟于2017年12月完成。检查活动于2013年初开始,以审查和评估被许可方的网络安全计划,并验证第一实施阶段是否已按照法规要求完成。迄今为止,已经检查了大约三分之一的美国动力堆的网络安全性。将在2014年末或2015年初开始全面检查被许可人的网络安全计划。在完成全面实施检查活动后,所有被许可人将完全遵守网络安全法规要求。本文概述了该程序,其状态和后续步骤。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号