IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
IAEA NSS-17 Access Control
NSS-17 + NSS-42-G require comprehensive access control aligned with CSL: unique user identification + no shared accounts where feasible (emergency shared accounts logged + reviewed); strong authentication scaled to CSL (CSL 1 requires multi-factor + smartcard + biometric where feasible; CSL 5 minimum username + strong password); role-based access control (RBAC) with least privilege + need-to-know + separation of duties between safety + security + operations + maintenance + IT + cyber security; account lifecycle management (provisioning at hire + transfer + termination + retirement) with trustworthiness verification per Personnel Security (CSL-1 cleared personnel only); session management + timeout + lock + concurrent session limits + termination; privileged access management (PAM) with logging + approval workflow + just-in-time access + time-limited + supervised; remote access (vendor +
- User account inventory per CBS + CSL + unique ID + shared account log
- MFA enrollment evidence scaled to CSL (CSL 1 MFA + biometric / smartcard mandatory; CSL 5 password adequate)
- RBAC matrix tying role (Operator + Engineer + Health Physics + Security + IT + Vendor) to CBS access
- PAM logs + just-in-time access + approval workflow + vendor remote access supervised
- Account lifecycle tied to Personnel Security (CSL 1 cleared personnel only + trustworthiness verification)
- Emergency override register + 24-hour review evidence
- Periodic access review (CSL 1 monthly + CSL 5 annual)
- Shared operator accounts on control room workstations (no individual accountability)
- MFA not feasible on legacy CBS without compensating physical access
- PAM vendor permanent credentials still active + unsupervised
- RBAC over-permissive (everyone shift supervisor)
- Emergency override not logged or reviewed
IAEA NSS-17 Architecture + Zones
NSS-17 + NSS-42-G require facility computer security architecture organised by Computer Security Zones (CSZs) implementing IAEA zone model. Zones correspond to Computer Security Levels (CSL 1 to CSL 5) with stricter security at higher levels: CSL 1 zones (Safety + Security critical) air-gapped or one-way data flow only + most stringent controls + smallest equipment count + highest assurance; CSL 2 zones (Important to safety / security) limited interconnect with strict boundary + monitoring; CSL 3-4 zones (Operational + business) progressively less restrictive; CSL 5 zones (Untrusted administrative + internet-connected). Conduits between zones use industrial firewalls + data diodes (unidirectional gateways) + DMZ patterns + jump hosts + bastion + protocol breaks + content inspection. Direct connections between Untrusted (CSL 5) and Safety/Security Critical (CSL 1) zones strictly prohibite
- Zone and conduit architecture diagram per facility + CSL mapping + boundary devices + access paths
- Defence in Depth control register per zone + perimeter / network / host / application / data layers
- Conduit configuration register + firewall + diode + DMZ + protocol break + content inspection
- Untrusted-to-Critical air-gap evidence + cross-zone connectivity prohibition
- External interface boundary security (satellite + leased line + IT integration) + access logs
- Flat network without CSL zoning
- Crew/admin network with direct connectivity to safety/security critical zones (CSL 5 to CSL 1)
- Single-layer firewall (no defence in depth)
- Conduit firewall rules permissive (any-any) between zones
- Data diodes bypassed via maintenance backdoor
IAEA NSS-17 Assurance + Regulator + Improvement
NSS-17 + NSS-42-G require ongoing assurance + regulator interface + reporting + continuous improvement. Assurance activities: internal cyber security audit + management review + control effectiveness testing + penetration testing + red team exercises + ISO 27001 alignment + ISO 19011 audit principles; assessment per CSL (CSL 1 quarterly + annual external; CSL 5 annual internal); root cause analysis on incidents + deficiencies + control failures. Regulator interface: routine reporting (monthly / quarterly status + CSE results + incident summary + audit results + change request + DBT alignment); event-based reporting (significant cyber event + breach + control failure + DBT escalation per Operating Limits and Conditions OLCs); regulator inspection (announced + unannounced + targeted) + inspection response + corrective action; license amendment for material changes (architecture + DBT + CSL
- Internal cyber audit programme + ISO 27001 + ISO 19011 + management review records
- Regulator routine + event-based reporting + inspection response + license amendment register
- National CSIRT + IAEA + INFCIRC + bilateral information sharing engagement
- Computer Security Exercise (CSE) lessons learned + cross-facility sharing + IAEA NUSEC
- Maturity assessment (NIST CSF + ISO 27001 + C2M2 + IAEA NSS) + benchmarking + improvement plan
- Internal audit absent or only IT-focused (missing OT + CBS)
- Regulator reporting reactive (event-based only, no routine status)
- Information sharing one-way (receive but not contribute)
- Lessons learned local (not shared with cross-facility / IAEA)
- Maturity assessment one-shot (no periodic progression)
IAEA NSS-17 Detect + IR + Recovery
NSS-17 + NSS-42-G require continuous monitoring + detection + incident response + recovery aligned with CSL. Logging: all CBS log security-relevant events (authentication + authorization + privileged action + configuration change + network connection + system start/stop + safety event + integrity check + emergency override); centralised log server / SIEM (on-site + air-gapped from corporate IT for CSL 1-2 zones); log retention (typically 1 year minimum + 7 years for safety/security-significant + 30 days online); log integrity protection (signed + write-once + tamper-evident); accurate time synchronisation (NTP + GPS time + atomic clock); log review periodic + automated correlation. Network monitoring: passive network traffic analysis (Dragos / Claroty / Nozomi / SCADAfence) on OT segments; intrusion detection + signatures + behavioral + anomaly; alert generation; on-site Security Operati
- Logging configuration per CBS + event types + retention (1 year minimum, 7 years safety) + integrity
- SIEM + on-site SOC + national CSIRT coordination + IAEA IEC integration
- Incident Response Plan + categories + escalation + Regulatory Body + IAEA + emergency response coordination
- Backup strategy per CBS + RTO + RPO + offline + air-gapped + restoration testing
- Annual Computer Security Exercise + scenarios + red team + tabletop + lessons learned + improvement
- Logs only on individual CBS without centralised SIEM
- Network monitoring active scanning prohibited on OT (passive required)
- IRP missing Regulatory Body + IAEA notification procedures
- Backup encryption keys on same network (ransomware encrypts both)
- Annual CSE skipped or perfunctory tabletop (no red team)
IAEA NSS-17 Graded Approach + Security Levels + Risk + DBT
NSS-17 + NSS-42-G adopt a graded approach with Computer Security Levels (CSLs) ranging from 1 (highest, applied to safety + security critical systems) to 5 (lowest, applied to general administrative systems). CSL assignment based on consequence analysis: potential adverse impact of compromise on nuclear safety + nuclear security + physical protection + emergency response + safeguards + safe operation + radiation protection. Risk-informed methodology: Threat Assessment evaluates capability + intent + opportunity of adversary; Vulnerability Assessment evaluates technical + procedural + physical weaknesses; Consequence Analysis evaluates impact on safety + security + radiological + financial + reputational + operational; Risk = Threat x Vulnerability x Consequence with treatment options. Design Basis Threat (DBT) alignment: facility cyber controls must address DBT scenarios issued by State
- CSL assignment per CBS + consequence analysis justification (safety / security / radiological / safeguards)
- DBT alignment matrix per CBS + cyber adversary scenarios (insider + outsider + state-sponsored + hybrid)
- Vulnerability assessment per CBS + technical + procedural + physical
- Risk register per CBS + treatment decisions + residual risk + monitoring
- DBT periodic review evidence + Regulatory Body notification + facility update
- CSL assignment generic not tied to consequence analysis
- DBT alignment absent (facility plans against generic threat, not State-issued DBT)
- Vulnerability assessment only technical (missing procedural + physical)
- Consequence analysis only safety (missing security + safeguards + radiological)
- DBT review periodicity missed (stale DBT used)
IAEA NSS-17 Personnel + Training
NSS-17 + NSS-42-G require personnel security + trustworthiness verification + training + awareness aligned with CSL access. Personnel security: background check + criminal record + financial + employment history + reference check + national security clearance for CSL 1-2 access + periodic re-investigation; continuous evaluation + insider threat program + behavioral observation; foreign travel + financial holdings disclosure per national rules; security clearance reciprocity with national authority. Trustworthiness verification: trustworthiness baseline established at hire + maintained through periodic re-evaluation + adjusted on adverse events + insider threat indicators; trustworthiness criteria per CSL (CSL 1 stringent + CSL 5 minimum). Training: cyber awareness for all personnel (phishing + social engineering + USB hygiene + password + reporting + incident response basics); role-based
- Personnel security clearance per role per CSL + national authority issued
- Trustworthiness re-investigation schedule + adverse event tracking + insider threat indicators
- Annual cyber awareness training records + role-based modules + STCW-equivalent maritime not applicable; IAEA NSS curriculum used
- Specialised training certificates for CSO + IR Team + Forensic + national CSIRT liaison + IAEA NUSEC + Computer Security Exercise
- Cyber hygiene policies + USB + BYOD + remote work + suspicious reporting + insider threat program
- Clearance only at hire (no periodic re-investigation)
- Insider threat program absent (focus only on external)
- Generic cybersecurity training not adjusted to nuclear-specific (CBS + safety + DBT + Computer Security Exercise)
- CSO without IAEA NSS-17/42-G specific training
- No insider threat reporting channel or whistleblower protection
IAEA NSS-17 Physical + Lifecycle + Safety Interface
NSS-17 + NSS-42-G require physical protection + lifecycle management + safety/EP integration. Physical protection of CBS: equipment in secure compartments + control rooms + protected areas per CSL (CSL 1 in Vital Area or Inner Area per physical protection); controlled access + tamper-evident seals + intrusion detection + alarm + CCTV + access logs; environmental controls (climate + power + uninterruptible power supply + grounding + EMI shielding + fire protection + flooding mitigation); cabling protected + conduit + tamper-evident + segregated from CSL boundaries; spare parts secured + traceability. Coordinates with NSS-13 Physical Protection + NSS-27-G nuclear material security. Lifecycle management: cradle-to-grave for CBS from acquisition + commissioning + operation + maintenance + modification + decommissioning + disposal; secure disposal of media + components + cryptographic devices
- Physical protection per CBS + CSL + Vital Area / Inner Area / Protected Area placement + tamper seals + CCTV + access log
- CBS lifecycle register + acquisition + commissioning + operation + modification + decommissioning + disposal
- Secure disposal procedure + media sanitisation + degaussing + physical destruction per IEC 21964 / NIST SP 800-88 for CSL 1
- Safety system cyber protection + I&C + ECCS + EDG + AFW + cyber-induced safety event prevention
- EP integration + GSR Part 7 emergency response + cyber attack as Initiating Event in PSA
- CBS in standard office space without CSL-appropriate physical protection
- End-of-life equipment retired without cryptographic sanitisation (data leak risk)
- Cyber attack not modelled as Initiating Event in PSA
- Safety system I&C cyber-vulnerable (operator-facing HMI shared)
- EP arrangements separate from cyber incident response (slow coordination)
IAEA NSS-17 Scope + CSP Establishment
IAEA Nuclear Security Series (NSS) is the family of publications providing internationally agreed guidance on nuclear security developed in consultation with Member States. NSS-17 Computer Security at Nuclear Facilities (Technical Guidance Reference Manual, original December 2011) was the foundational Implementing Guide; superseded by NSS-17-T Rev 1 modernisation and complemented by NSS-42-G Computer Security for Nuclear Security (Implementing Guide, 2021) which expanded scope beyond facilities to cover the full nuclear security regime including material in transport + radioactive sources + material out of regulatory control. NSS family categories: Nuclear Security Fundamentals (objectives + concepts + principles); Recommendations (best practices for Member States); Implementing Guides (further elaboration of Recommendations); Technical Guidance (Reference Manuals + Training + Service Gu
- NSS-17 + NSS-42-G applicability assessment per facility + scope mapping
- Computer Security Programme (CSP) charter + policy + scope + objectives
- Senior management commitment letter + executive sponsorship + reporting line
- Roles + responsibilities + RACI for operator + State + Regulatory Body + competent authority + national CSIRT
- Integration evidence with facility management system (Quality + Safety + Physical Security + EP + Information Security)
- CSP exists on paper without senior management sponsorship
- Roles split unclear between operator + Regulatory Body + competent authority
- CSP siloed from facility quality + safety + physical security management
- No designated computer security function at facility level
- CPPNM/A obligations not mapped to facility CSP
IAEA NSS-17 Supply Chain + Third Party
NSS-17 + NSS-42-G require supply chain + third party + OEM security across CBS lifecycle. Vendor due diligence: cyber maturity assessment + ISO 27001 / IEC 62443 / IEC 27036 alignment + cybersecurity governance + secure development + incident history + foreign ownership control or influence (FOCI) per national rules + national security clearance where required; contract clauses (security requirements + audit right + breach notification 24 hours + patch obligations + EOL commitment + intellectual property + non-disclosure + sanctions compliance); vendor cybersecurity scorecard + periodic re-assessment. Trustworthy components: SBOM (per CISA SBOM Minimum Elements + SPDX/CycloneDX) + signed firmware + secure boot + integrity verification + counterfeit detection + provenance tracking; component categorisation (commercial off-the-shelf + open source + custom + Government-Off-The-Shelf GOTS);
- Vendor cyber maturity assessment + ISO 27001 / IEC 62443 / 27036 + FOCI evaluation
- Contract clauses (security + audit + breach + patch + EOL + sanctions) per vendor
- SBOM per CBS + SPDX/CycloneDX + signed firmware + secure boot + provenance tracking
- Trustworthy delivery procedure + tamper-evident + receiving inspection + sanitisation
- Vendor remote access + field service escort + clearance per Personnel Security
- Vendor due diligence absent (only price-based selection)
- SBOM not requested or vendor refuses to provide
- Tamper-evident packaging not verified at receiving
- Vendor field service unsupervised in CSL 1 zones
- No FOCI evaluation for foreign vendors in safety-critical CBS
IAEA NSS-17 System Integrity + Configuration
NSS-17 + NSS-42-G require system integrity protection through configuration management + change management + baseline control + hardening. Configuration baseline per CBS per CSL: documented hardened baseline + disabled unused services + locked BIOS + secure boot + Trusted Platform Module (TPM) where feasible + signed boot loader + tamper detection; baseline approved at commissioning + reapproved at modification + verified at periodic survey. Change management process: any change to safety/security CBS requires: change request + impact assessment + safety analysis + security analysis + Regulatory Body notification per Operational Limits and Conditions (OLCs); change approval by Plant Manager + Computer Security Officer (CSO) + safety committee + regulator where required; testing on shadow / staging environment matching production fidelity; change implementation under work permit + Operato
- Configuration baseline per CBS + CSL + hardening evidence + secure boot
- Change management procedure + impact assessment + safety + security + regulator notification + approval workflow
- Software integrity protection + code signing + secure boot + integrity verification at runtime + tamper detection
- Change testing on shadow / staging environment + production fidelity validation
- As-built configuration records + version control + change history
- Vendor default configuration in production (no hardening baseline)
- Change management absent for safety/security CBS (changes via maintenance without Regulator review)
- Software updates unsigned + no rollback protection
- TPM disabled for performance + secure boot bypassed
- Changes implemented without staging testing (production-only)
IAEA NSS-17 Vulnerability + Patch + Media
NSS-17 + NSS-42-G require vulnerability + patch management + removable media + portable device controls. Vulnerability management: vendor security advisories + CVE feeds + ICS-CERT + national CERT subscriptions; vulnerability scanning (active where feasible on IT + passive on OT); penetration testing in safe context (non-production / commissioning); SBOM-based vulnerability identification (open source + dependencies); risk-rating per CSL + remediation timeline (CSL 1 critical patches within 30 days + emergency same day; CSL 5 within 90 days). Patch management: patch identification per CBS + version tracking + vendor + OEM patch lifecycle; risk-based patch testing on shadow / staging matching production; emergency patch procedure with Regulatory Body notification for safety-critical CBS; patch deferral risk acceptance documented + compensating controls during deferral; firmware + BIOS + m
- Vendor advisory + CVE feed + ICS-CERT subscription register + per-CBS tracking
- Patch testing on staging + Regulatory Body notification + emergency patch procedure
- Removable media policy + USB kiosk + signature check + chain of custody + log
- Portable device policy + separate OT laptops + sanitisation procedure
- Risk acceptance documentation for deferred patches + compensating controls
- Vulnerability scanning active on OT (production disruption risk)
- Patches deferred indefinitely without risk acceptance + compensating controls
- USB used freely on operator workstations without kiosk sanitisation
- Personal cellular phones in CSL 1 control rooms
- Maintenance laptops shared between OT and corporate IT
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) framework page.