skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: A PROVEN APPROACH FOR EFFECTIVE COMPUTER SECURITY SELF-ASSESSMENTS AT NUCLEAR FACILITIES

Conference ·
OSTI ID:1604145

A proven method for conducting cybersecurity self-assessments at nuclear power plants is now available for international use. This method was originally developed by Pacific Northwest National Laboratory, under the sponsorship of the U.S. Nuclear Regulatory Commission (NRC), for use at U.S. nuclear power plants. The “Method,” described in NUREG/CR-6847 “Cyber Security Self-Assessment Method for U.S. Nuclear Power Plants,” was originally a limited release document that was withheld from public disclosure but is now publicly available. The Method provides a systematic, phased, and risk-informed approach to help decision makers and security specialists understand their relative cybersecurity posture. Completed Method assessments may be used to support or validate selection of computer security controls to mitigate cyber threats as well as demonstrate compliance with regulations or statutes enacted by competent authorities. The Method assesses the cybersecurity posture of key systems at a nuclear facility with a focus on protection of design base functions. It considers both physical and digital elements of system vulnerabilities and the resulting potential consequences from exploitation. It is well-suited for addressing blended cyberattacks. A semi-quantitative analytical approach is used in the evaluation of potential vulnerabilities, consequences, and risks and provides a technical basis for the selection of security controls to mitigate cyberattacks. The Method’s application at U.S. nuclear power plants has been very encouraging. The only nuclear plant in the United States that did not have adverse findings during its initial NRC computer security inspection prepared for inspection through the diligent application of this self-assessment method and the implementation of recommendations that came out of that self-assessment. Nuclear facilities around the world might find application of the Method extremely helpful for making cost-effective, risk-based decisions regarding computer security and for preparing to pass computer security inspections by their competent authorities.

Research Organization:
Pacific Northwest National Lab. (PNNL), Richland, WA (United States)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC05-76RL01830
OSTI ID:
1604145
Report Number(s):
PNNL-SA-149277
Resource Relation:
Conference: IAEA International Conference on Nuclear Security (ICONS 2020), February 10-14, 2020, Vienna, Austria
Country of Publication:
Austria
Language:
English

Similar Records

Cybersecurity for Distance Relay Protection
Technical Report · Wed Feb 19 00:00:00 EST 2020 · OSTI ID:1604145

Assessing Vulnerabilities, Risks, and Consequences of Damage to Critical Infrastructure
Technical Report · Fri Feb 04 00:00:00 EST 2011 · OSTI ID:1604145

Cybersecurity Resiliency of Marine Renewable Energy Systems Part 2: Cybersecurity Best Practices and Risk Management
Journal Article · Mon Mar 01 00:00:00 EST 2021 · Marine Technology Society Journal · OSTI ID:1604145