Skip to content

Evidence request lists

NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity

Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

10 CFR 73.54 Programme Requirements

NRC-73.54(a)
Cyber Security Program Scope

Establish, implement, and maintain a cyber security program that provides high assurance that digital computer and communication systems and networks associated with safety, security, and emergency preparedness functions, and support systems and equipment which if compromised would adversely impact those functions, are adequately protected against cyber attacks up to and including the design basis threat.

Artefacts an auditor will ask for
  • Approved Cyber Security Program description
  • Scope statement identifying SSEP functions
  • Mapping of systems to SSEP categories
  • Approval by senior responsible officer
Where this commonly fails
  • Scope limited to safety systems excluding security and emergency preparedness
  • Support systems not evaluated
  • Program description not updated after digital upgrades
NRC-73.54(c)
Cyber Security Plan

Develop and maintain a written cyber security plan that implements the cyber security program and is incorporated into the physical security plan, subject to NRC approval. Amendments require formal change control under 10 CFR 50.90 or 73.54(c) as applicable.

Artefacts an auditor will ask for
  • Approved Cyber Security Plan
  • NRC approval correspondence
  • Plan amendments and submissions
  • Configuration management of plan documents
Where this commonly fails
  • Plan not aligned with current organization or technology
  • Amendments not submitted under proper change process
  • Document control insufficient
NRC-73.54(d)(1)
Senior Responsible Officer Accountability

Ensure that the cyber security program is established, implemented, and maintained by a senior level officer accountable for the overall management of the program, with adequate resources, authority, and access to senior management.

Artefacts an auditor will ask for
  • Designation of senior responsible officer
  • Reporting line to senior management
  • Resource allocation evidence
  • Program governance charter
Where this commonly fails
  • Senior responsible officer not formally designated
  • Reporting line through IT only
  • Insufficient resources documented in periodic reviews
NRC-73.54(d)(2)
Cyber Security Roles and Responsibilities

Define and document cyber security roles, responsibilities, and lines of authority for personnel involved in implementing the cyber security program, including the Cyber Security Assessment Team and supporting functions.

Artefacts an auditor will ask for
  • Cyber Security Assessment Team charter
  • Position descriptions and qualifications
  • Training and qualification records
  • RACI for cyber activities
Where this commonly fails
  • CSAT charter outdated
  • No engineering representation on CSAT
  • Qualifications not periodically re verified
NRC-73.54(d)(3)
Training, Awareness, and Qualification

Provide initial and continuing cyber security training and awareness for personnel performing cyber security related responsibilities, with role specific qualification requirements for the Cyber Security Assessment Team and support functions.

Artefacts an auditor will ask for
  • Training plan and curricula
  • Completion records by role
  • Qualification cards
  • Refresher training schedule
Where this commonly fails
  • Training generic and not role specific
  • Refresher cycle exceeded
  • Contractors with CDA access untrained
NRC-73.54(h)
Cyber Security Program Review

Conduct a review of the cyber security program at least every 24 months, including an evaluation of the effectiveness of the program in protecting Critical Digital Assets, with results documented and findings tracked to closure.

Artefacts an auditor will ask for
  • Biennial program review report
  • Reviewer qualifications and independence
  • Findings and corrective actions
  • Closure evidence
Where this commonly fails
  • Review performed by program owner without independence
  • Findings open beyond corrective action deadlines
  • Review scope incomplete

Access Control + Media + Devices

NRC7354-5
Access Control, Authentication, Removable Media, and Portable Devices

Implement access control + authentication + removable media controls per 10 CFR 73.54(c) + NRC RG 5.71 Appendix B Section B.1.1 (Access Control) + Section B.1.7 (System and Communications Protection - Portable Media Controls). Access control must (a) enforce unique user identification + authentication + authorisation for all CDA access including engineering + operations + maintenance + administrative + vendor access, (b) implement multi-factor authentication for privileged access + remote access + access to highest-assurance security levels, (c) enforce least privilege + separation of duties + emergency-access procedures with audit, (d) manage shared accounts only where individual identification is operationally infeasible with compensating monitoring, (e) restrict and log remote access via authorised pathway only (jump host + PAM + session recording + JIT approval). Authentication crede

Artefacts an auditor will ask for
  • unique user IDs + MFA configuration at higher security levels + remote access via PAM + session recording
  • removable media policy + sandboxed transfer station evidence + chain of custody
  • USB port disabling configuration where feasible + workforce discipline training records
Where this commonly fails
  • shared accounts on CDA workstations
  • removable media transfer without sandbox + chain of custody
  • vendor remote access via persistent VPN without PAM

Attack Mitigation and Monitoring

NRC-73.54(e)(1)
Attack Mitigation Capability

Provide the capability to detect, respond to, and recover from cyber attacks on Critical Digital Assets, including identification of indicators, containment, eradication, recovery, and restoration of compromised assets.

Artefacts an auditor will ask for
  • Detection technology configurations
  • Incident response procedures specific to CDAs
  • Recovery runbooks
  • Sample incident records
Where this commonly fails
  • Detection limited to IT and not CDA enclaves
  • Recovery runbooks untested
  • No coordination with engineering for restoration
NRC-73.54(e)(2)
Mitigation of Adverse Impact

Ensure that the capability to perform safety, security, and emergency preparedness functions is maintained or restored following a cyber attack, with manual or independent backup measures available to compensate for compromised digital functions.

Artefacts an auditor will ask for
  • Documented manual or analog backup procedures for SSEP functions
  • Equipment for manual operation
  • Operator training for backup actions
  • Periodic exercises validating backups
Where this commonly fails
  • Manual backups exist on paper but not in operator simulator scenarios
  • Equipment unavailable or out of calibration
  • Exercises not conducted
NRC-73.54(g)
Ongoing Monitoring and Assessment

Maintain the cyber security program through ongoing monitoring and assessment activities to ensure that the security controls remain effective and that the defensive architecture continues to provide high assurance of protection.

Artefacts an auditor will ask for
  • Continuous monitoring procedures
  • Vulnerability assessment results
  • Periodic effectiveness reviews
  • Trend analysis
Where this commonly fails
  • Monitoring focused on IT only
  • Vulnerability assessments not performed for CDAs
  • Effectiveness reviews not documented

Critical Digital Asset Identification

NRC7354-2
Critical Digital Asset (CDA) Identification, Scope, and Boundary

Identify and maintain the inventory of Critical Digital Assets (CDAs) per 10 CFR 73.54(b)(1) + (b)(2). CDAs are digital computer and communication systems and networks associated with (a) safety-related and important-to-safety functions, (b) security functions, (c) emergency preparedness functions including offsite communications, (d) support systems and equipment which if compromised would adversely impact safety + security or emergency preparedness functions. CDA identification process must (a) review all digital assets per system + subsystem + component, (b) determine each assets contribution to safety + security + EP functions, (c) document the determination + rationale + evidence per asset, (d) maintain the CDA inventory under configuration management with periodic review, (e) reassess when systems are added + modified + replaced + when functional analysis changes. Boundary definiti

Artefacts an auditor will ask for
  • CDA inventory under configuration management with periodic review
  • determination evidence per CDA covering safety + security + EP functions analysis
  • boundary documentation between CDA and non-CDA networks
  • reassessment evidence for system changes + modifications
Where this commonly fails
  • under-scoped CDA inventory missing important-to-safety or EP support systems
  • boundary undocumented or not enforced
  • CDA reassessment skipped on system change

Critical Digital Assets and Defensive Architecture

NRC-73.54(b)(1)
Critical Digital Asset Identification

Analyze digital computer and communication systems and networks, and identify those assets that must be protected from cyber attacks. Identify Critical Systems and the Critical Digital Assets within them whose compromise could adversely affect safety, security, or emergency preparedness functions.

Artefacts an auditor will ask for
  • Critical Systems list
  • Critical Digital Asset inventory with attributes
  • CDA scoping methodology
  • Periodic refresh of inventory
Where this commonly fails
  • CDA inventory not reflecting modifications
  • Support assets that could affect SSEP not classified as CDAs
  • No attribute level data for assets
NRC-73.54(b)(2)
Defensive Architecture

Establish, implement, and maintain a defensive architecture consisting of five concentric defensive levels separated by security boundaries with deterministic data flow controls, such that traffic from less secure to more secure levels is restricted and one way isolation is enforced between the highest and second highest levels.

Artefacts an auditor will ask for
  • Defensive architecture diagram showing levels 0 through 4
  • Deterministic device configuration evidence (data diodes between level 4 and 3)
  • Boundary device rule sets
  • Architecture review records
Where this commonly fails
  • Bidirectional flow between levels 4 and 3
  • Boundary rules permit broad protocols
  • Architecture diagrams outdated
NRC-73.54(b)(3)
Application of Security Controls to CDAs

Implement and maintain the security controls of RG 5.71 Appendix B and C or equivalent (NEI 08 09 Appendices D and E) for each Critical Digital Asset, addressing technical, management, and operational controls, with documented basis for any alternative measures or risk informed tailoring.

Artefacts an auditor will ask for
  • Per CDA control assessment
  • Control implementation evidence
  • Alternative measure justifications
  • Risk informed analysis where used
Where this commonly fails
  • Per CDA assessment incomplete
  • Alternative measures unjustified
  • Operational controls not tied to procedures
NRC-73.54(f)
Defense in Depth

Apply defense in depth protective strategies to provide multiple layers of administrative, technical, and physical controls so that compromise of any single control does not adversely impact safety, security, or emergency preparedness functions.

Artefacts an auditor will ask for
  • Control overlay matrix showing administrative, technical, and physical layers
  • Per CDA defense in depth analysis
  • Compensating control documentation
Where this commonly fails
  • Overlay matrix not maintained
  • Single point of failure controls without compensating layers
  • Physical controls excluded from cyber analysis

Cybersecurity Plan and Programme

NRC7354-1
Cybersecurity Plan, Programme Establishment, and NRC Submission

Establish and submit a cybersecurity programme per 10 CFR 73.54(a) + 73.54(d) for NRC review and approval. The licensee must provide high assurance that digital computer and communication systems and networks are adequately protected against cyber attacks up to and including the design basis threat as described in 10 CFR 73.1. Programme establishment per 73.54(a) requires (a) analyse digital computer and communication systems and networks and identify those associated with safety-related and important-to-safety functions + security functions + emergency preparedness functions including offsite communications + support systems and equipment which if compromised would adversely impact safety + security or emergency preparedness functions (Critical Digital Assets or CDAs), (b) protect those identified CDAs from cyber attacks that would adversely impact the design function. Cybersecurity Pla

Artefacts an auditor will ask for
  • approved Cybersecurity Plan as submitted to NRC + NRC approval evidence
  • programme establishment evidence per 73.54(a)(1)
  • programme maintenance + review schedule + update history
  • operational reality matching submitted plan with change-management for variations
Where this commonly fails
  • operational drift from submitted plan
  • no formal change-management for plan variations
  • plan submitted but programme implementation incomplete

Defensive Architecture

NRC7354-3
Defensive Architecture, Multi-Layer Defense, and Network Segregation

Implement Defensive Architecture per 10 CFR 73.54(c) using a defense-in-depth approach with multiple layers of protection. NRC RG 5.71 Appendix B describes the recommended Defensive Architecture with five Security Levels (Levels 4 + 3 + 2 + 1 + 0 with 4 highest assurance) separated by Security Boundary Devices (deterministic one-way data flow at the highest assurance boundaries and stateful protocol-aware enforcement at lower-assurance boundaries). Levels approximately correspond to (a) Level 4: safety + important-to-safety + security functions CDAs, (b) Level 3: emergency preparedness + balance-of-plant CDAs supporting Level 4, (c) Level 2: site IT networks supporting plant operations, (d) Level 1: corporate IT networks, (e) Level 0: external networks. Network segregation must (a) physically separate CDA networks from non-CDA networks where deterministic one-way enforcement is required,

Artefacts an auditor will ask for
  • authoritative architecture diagrams per RG 5.71 Appendix B 5-level model
  • boundary device inventory with unidirectional gateway at highest assurance + stateful FW at lower
  • traffic policy documentation + monitoring + alerting
  • verification of physical separation from Level 0/1 untrusted networks
Where this commonly fails
  • stateful firewall used where unidirectional gateway should be
  • boundary device monitoring incomplete
  • direct connection between Level 4 CDA and Level 0/1 networks (severe finding)

Incident Reporting and Records

NRC-Incident-Reporting
Cyber Incident Reporting to NRC

Report cyber security events to the NRC consistent with 10 CFR 73.77, including notifications within prescribed timelines for events that adversely affect or could adversely affect the ability of the licensee to maintain Safety, Security, and Emergency Preparedness functions.

Artefacts an auditor will ask for
  • Cyber event reporting procedure
  • Sample NRC notifications with timelines
  • Operations center 24 hour capability
  • Coordination with corrective action program
Where this commonly fails
  • Reporting timelines miscategorized
  • Operations center unaware of 73.77 thresholds
  • Reports incomplete or delayed
NRC-Records
Records of Cyber Security Program

Retain records relating to the cyber security program including assessments, modifications, training, audits, drills, incidents, and changes for a period that meets NRC retention requirements and supports inspection by the NRC.

Artefacts an auditor will ask for
  • Records retention schedule
  • Sample records by category
  • Access controls protecting safeguards information
  • Inspection readiness binder
Where this commonly fails
  • Records dispersed across sites without index
  • Safeguards Information markings inconsistent
  • Inspection preparation reactive rather than continuous

Monitoring, IR, Reporting, Contingency

NRC7354-7
Monitoring, Assessment, Incident Response, Reporting, and Contingency

Operate monitoring + assessment + incident response + contingency per 10 CFR 73.54(c) + NRC RG 5.71 Appendix C + 10 CFR 73.77 (Cybersecurity Event Notification + reporting requirements established by 2015 final rule). Monitoring per RG 5.71 must (a) continuous monitoring of CDA networks + hosts + applications via OT-aware sensors + EDR where supported + SIEM correlation + threat intelligence, (b) periodic assessment via cybersecurity audits + penetration testing + tabletop exercises + control effectiveness measurements. Incident Response per RG 5.71 Appendix C must (a) document IR plan covering scenarios + roles + activation + containment + recovery + post-incident review + integrate with broader physical security + emergency preparedness response, (b) IR team including cybersecurity + plant operations + engineering + safety + EP + Public Affairs + legal + executive leadership, (c) 24x7

Artefacts an auditor will ask for
  • continuous monitoring architecture with OT-aware sensors + SIEM + threat intel
  • IR plan + team + 24x7 capability + tabletop and technical exercise evidence
  • 10 CFR 73.77 reporting decision tree + on-call duty officer + NRC Operations Center contact procedure + practiced procedure
  • contingency plan + backup/recovery + integration with EP
Where this commonly fails
  • 10 CFR 73.77 reporting decision tree absent or unfamiliar to on-call
  • monitoring limited to network perimeter (no host + device telemetry on CDAs)
  • no tabletop exercise in 12+ months

Programme Oversight and Records

NRC7354-8
Programme Oversight, Independent Review, Documentation, Training, Supply Chain

Operate programme oversight + independent review + documentation + training + supply chain per 10 CFR 73.54(d) + (g) + NRC RG 5.71 Appendix C. Programme oversight per 73.54(d)(2) requires the cybersecurity programme to be (a) reviewed as a component of the physical security programme + maintained for the life of operating licence per 73.54(g), (b) independently reviewed at least every 24 months + assessed for effectiveness against the cybersecurity plan + and against current threats + technology + organisational changes, (c) management review of programme metrics + control performance + incident trends + audit findings with documented closure tracking. Documentation per 73.54(d) + (e) must (a) maintain records sufficient to demonstrate compliance with the cybersecurity plan + maintain change history + assessment results + incident records + training records, (b) records preservation for

Artefacts an auditor will ask for
  • biennial independent review reports + closure tracking
  • management review records + programme metrics
  • training records (initial + annual refresher + role-specific) + tabletop participation
  • supply chain cybersecurity requirements in procurement + vendor assessment + vendor monitoring + verified-clean media procedures
Where this commonly fails
  • biennial independent review by people too close to programme producing soft findings
  • training generic IT not nuclear-CDA specific or not refreshed
  • procurement does not include cybersecurity requirements for CDA-relevant systems

Regulatory Guide 5.71 Appendix C Security Controls

RG5.71-C.3
Cyber Security Training

Personnel with access to critical digital assets must receive cyber security awareness and role-based training.

Artefacts an auditor will ask for
  • Defence-in-depth architecture diagrams for safety and security functions
  • Incident response procedures aligned to RG 5.71 Appendix C
  • Configuration management baseline records for CDAs
Where this commonly fails
  • Continuous monitoring coverage gaps for legacy safety-related systems
  • CDA inventory incomplete for support systems and balance-of-plant equipment
  • Defence-in-depth boundaries inadequately documented or enforced
RG5.71-C.4
Incident Response Plan

Licensees must develop and maintain a cyber security incident response plan with defined procedures.

Artefacts an auditor will ask for
  • Defence-in-depth architecture diagrams for safety and security functions
  • Incident response procedures aligned to RG 5.71 Appendix C
  • Configuration management baseline records for CDAs
  • Cyber security training and awareness records for personnel
  • Cyber Security Plan documented under 10 CFR 73.54(e)
Where this commonly fails
  • Defence-in-depth boundaries inadequately documented or enforced
  • Insider threat considerations not integrated with access authorisation programme
  • Configuration management drift between as-built and as-documented states
  • Continuous monitoring coverage gaps for legacy safety-related systems
RG5.71-C.5
Recovery and Restoration

Licensees must have procedures to recover and restore critical digital assets following a cyber security event.

Artefacts an auditor will ask for
  • Defence-in-depth architecture diagrams for safety and security functions
  • Incident response procedures aligned to RG 5.71 Appendix C
  • Configuration management baseline records for CDAs
  • Cyber security training and awareness records for personnel
  • Cyber Security Plan documented under 10 CFR 73.54(e)
Where this commonly fails
  • Defence-in-depth boundaries inadequately documented or enforced
  • Insider threat considerations not integrated with access authorisation programme
  • Configuration management drift between as-built and as-documented states
RG5.71-C.6
Configuration Management

Licensees must maintain configuration management for critical digital assets throughout their lifecycle.

Artefacts an auditor will ask for
  • Incident response procedures aligned to RG 5.71 Appendix C
  • Configuration management baseline records for CDAs
  • Cyber security training and awareness records for personnel
  • Cyber Security Plan documented under 10 CFR 73.54(e)
Where this commonly fails
  • Continuous monitoring coverage gaps for legacy safety-related systems
  • CDA inventory incomplete for support systems and balance-of-plant equipment
  • Defence-in-depth boundaries inadequately documented or enforced
  • Insider threat considerations not integrated with access authorisation programme
RG5.71-C.7
Continuous Monitoring

Licensees must implement continuous monitoring mechanisms to detect anomalies and potential cyber security events.

Artefacts an auditor will ask for
  • Cyber Security Plan documented under 10 CFR 73.54(e)
  • Critical Digital Asset (CDA) inventory and classification register
  • Defence-in-depth architecture diagrams for safety and security functions
  • Incident response procedures aligned to RG 5.71 Appendix C
  • Configuration management baseline records for CDAs
  • Cyber security training and awareness records for personnel
Where this commonly fails
  • Configuration management drift between as-built and as-documented states
  • Continuous monitoring coverage gaps for legacy safety-related systems
  • CDA inventory incomplete for support systems and balance-of-plant equipment

Security Controls Implementation

NRC7354-4
Security Controls Implementation per NRC RG 5.71 Appendix B/C

Implement security controls per 10 CFR 73.54(c) consistent with NRC Regulatory Guide 5.71 Appendix B (Technical and Operational Cyber Security Controls) + Appendix C (Cyber Security Programme Controls). Technical controls per Appendix B cover (a) access control including unique identification + authentication + authorisation + concurrent session control + remote access + wireless restrictions + portable and mobile device controls, (b) audit and accountability including event types + content + storage + reporting + analysis + retention, (c) configuration management including baselines + least functionality + change control + verification, (d) system and information integrity including malicious code protection + monitoring + spam protection + flaw remediation + integrity verification, (e) defence-in-depth including boundary protection + isolation + monitoring at boundaries + protection fr

Artefacts an auditor will ask for
  • mapping evidence to RG 5.71 Appendix B technical/operational controls + Appendix C programmatic controls per CDA
  • control-by-control evidence library with documentation + screenshots + scan results + policies + records
  • internal sampling against RG 5.71 controls + closure of identified gaps
Where this commonly fails
  • evidence not mapped to RG 5.71 control IDs producing inspection-time scramble
  • internal sampling skipped + gaps surface only during NRC inspection
  • Appendix C programmatic controls treated less seriously than Appendix B technical controls

Technical Controls for Critical Digital Assets

NRC-Access-Control
Access Control to CDAs

Implement access controls for Critical Digital Assets including unique user identification, authentication appropriate to the asset, role based authorization, separation of duties, and recertification of access on a defined cycle.

Artefacts an auditor will ask for
  • Identity and access management procedures for CDAs
  • MFA evidence for privileged access
  • Role matrix
  • Recertification records
Where this commonly fails
  • Shared accounts on engineering workstations
  • MFA not feasible documented without compensating control
  • Recertification overdue
NRC-Audit-Logging
Audit and Accountability

Generate, protect, and review audit logs from Critical Digital Assets and supporting boundary devices for events relevant to security including access, privilege use, configuration changes, and anomalous activity, with retention and review procedures.

Artefacts an auditor will ask for
  • Audit logging standard for CDAs
  • Log collection architecture
  • Review procedure and schedule
  • Retention configuration
Where this commonly fails
  • CDAs lack logging capability without compensating control
  • Logs reviewed only after incidents
  • Retention insufficient for forensic needs
NRC-Configuration-Management
Configuration Management of CDAs

Apply configuration management to Critical Digital Assets including baseline configurations, change control with security impact analysis, configuration verification, and integration with the corrective action program for deviations.

Artefacts an auditor will ask for
  • Baseline configuration documents per CDA
  • Change records with security impact analysis
  • Configuration verification evidence
  • Corrective action program records for deviations
Where this commonly fails
  • Baselines not maintained
  • Security impact analysis missing in modifications
  • Configuration verification ad hoc
NRC-Portable-Media
Portable Media and Mobile Devices

Control the use of portable media and mobile devices in the protected and vital areas including authorization, scanning at trusted scanning stations, restrictions on connection to CDAs, and tracking of devices used for maintenance activities.

Artefacts an auditor will ask for
  • Portable media procedure
  • Trusted scanning station configuration
  • Authorization records for device use
  • Inventory of plant approved devices
Where this commonly fails
  • Scanning station bypassed in time pressured maintenance
  • Vendor laptops not tracked
  • Devices reused across levels without sanitization
NRC-Supply-Chain
Supply Chain Protection

Manage supply chain risk for Critical Digital Assets and related services including procurement security requirements, vendor assessments, integrity verification, counterfeit detection, and end of life management for hardware and software.

Artefacts an auditor will ask for
  • Procurement requirements for CDAs
  • Vendor security assessments
  • Integrity verification at receipt
  • End of life planning
Where this commonly fails
  • Supply chain provisions not flowed down to suppliers
  • Integrity checks only on safety related equipment
  • End of life software still in use on CDAs

Vulnerability and Configuration Management

NRC7354-6
Vulnerability Management, Configuration Management, Baseline Control, and Patching

Operate vulnerability management + configuration management + baseline control + patching per 10 CFR 73.54(c) + NRC RG 5.71 Appendix B Section B.1.3 (Configuration Management) + Section B.1.6 (System and Information Integrity). Configuration management must (a) establish documented baseline configurations per CDA class + version, (b) enforce change control with engineering + cybersecurity + operations review for CDA changes, (c) maintain inventory of CDAs at component level + with configuration attributes + ownership, (d) detect configuration drift via authenticated scanning + integrity monitoring + alerting on deviation, (e) protect baselines + change documentation under access control. Vulnerability management must (a) consume NRC vulnerability advisories + ICS-CERT advisories + vendor advisories + CISA KEV + sector ISAC, (b) assess applicability to CDAs + assign severity considering C

Artefacts an auditor will ask for
  • baseline configurations + change control records + drift detection evidence
  • vulnerability advisory consumption (NRC + ICS-CERT + vendor + KEV) + applicability assessment + remediation
  • patch test lab + production deployment record + compensating controls for unpatchable systems
  • vulnerability management metrics + age tracking + management review
Where this commonly fails
  • no patch test lab matching CDA topology + safety configuration
  • compensating controls undocumented + not approved + not reassessed
  • ICS-CERT advisories not consumed or not actioned
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.