IR 05000483/2022401

From kanterella
Jump to navigation Jump to search
Cyber Security Inspection Report 05000483/2022401
ML22117A222
Person / Time
Site: Callaway Ameren icon.png
Issue date: 05/05/2022
From: Nick Taylor
NRC/RGN-IV/DORS/EB2
To: Diya F
Ameren Missouri
References
IR 202401
Download: ML22117A222 (10)


Text

May 5, 2022

SUBJECT:

CALLAWAY PLANT - CYBER SECURITY INSPECTION REPORT 05000483/2022401

Dear Mr. Diya:

On March 31, 2022, the U.S. Nuclear Regulatory Commission (NRC) completed an inspection at Callaway Plant and discussed the results of this inspection with Mr. F. J. Bianco, Senior Director, Nuclear Operations, and other members of your staff. The results of this inspection are documented in the enclosed report.

No findings or violations of more than minor significance were identified during this inspection.

This letter, its enclosure, and your response (if any) will be made available for public inspection and copying at http://www.nrc.gov/reading-rm/adams.html and at the NRC Public Document Room in accordance with Title 10 of the Code of Federal Regulations 2.390, Public Inspections, Exemptions, Requests for Withholding.

Sincerely, Nicholas H. Taylor, Chief Engineering Branch 2 Division of Operating Reactor Safety Docket No. 05000483 License No. NPF-30 Enclosure:

Inspection Report 05000483/2022401 Distribution via Listserv

ML22117A222 X SUNSI Review ADAMS: Sensitive Non-Publicly Available Keyword By: STG X Yes No X Non-Sensitive X Publicly Available NRC-002 OFFICE DORS\SRI\EB2 OE\AS C:DORS\PBB C:DORS\EB2 NAME SGraves SOpara GWerner NTaylor SIGNATURE /RA/ /RA/ GEW /RA/

DATE 5/28/2022 5/28/2022 04/28/2022 5/3/2022

U.S. NUCLEAR REGULATORY COMMISSION

Inspection Report

Docket Number: 05000483 License Number: NPF-30 Report Number: 05000483/2022401 Enterprise Identifier: I-2022-401-0004 Licensee: Ameren Missouri Facility: Callaway Plant Location: Steedman, MO Inspection Dates: March 28, 2022, to March 31, 2022 Inspectors: S. Graves, Senior Reactor Inspector, Lead S. Opara, Allegation Specialist M. Fernandez, Cyber Security Specialist A. Konkal, Contractor - Cyber Security F. Priester, Contractor - Cyber Security Approved By: Nicholas H. Taylor, Chief Engineering Branch 2 Division of Operating Reactor Safety Enclosure

SUMMARY

The U.S. Nuclear Regulatory Commission (NRC) continued monitoring the licensees performance by conducting a cyber security inspection at Callaway Plant, in accordance with the Reactor Oversight Process. The Reactor Oversight Process is the NRCs program for overseeing the safe operation of commercial nuclear power reactors. Refer to https://www.nrc.gov/reactors/operating/oversight.html for more information.

List of Findings and Violations

No findings or violations of more than minor significance were identified.

Additional Tracking Items

None.

INSPECTION SCOPES

Inspections were conducted using the appropriate portions of the inspection procedures (IPs) in effect at the beginning of the inspection unless otherwise noted. Currently approved IPs with their attached revision histories are located on the public website at http://www.nrc.gov/reading-rm/doc-collections/insp-manual/inspection-procedure/index.html. Samples were declared complete when the IP requirements most appropriate to the inspection activity were met consistent with Inspection Manual Chapter (IMC) 2201, Security Inspection Program for Commercial Nuclear Power Reactors. The inspectors reviewed selected procedures and records, observed activities, and interviewed personnel to assess licensee performance and compliance with Commission rules and regulations, license conditions, site procedures, and standards.

SAFEGUARDS

71130.10 - Cybersecurity

The inspectors reviewed implementation of the Callaway Cyber Security Plan and focused on evaluating changes to the program, critical systems, and Critical Digital Assets (CDAs).

Cybersecurity (1 Sample)

(1) The following IP sections were completed and constitute completion of 1 sample:
  • 03.01, Review Ongoing Monitoring and Assessment Activities
  • 03.02, Verify Defense-in-Depth Protective Strategies
  • 03.03, Review of Configuration Management Change Control
  • 03.05, Evaluation of Corrective Actions The inspection also reviewed the following cyber security program changes, as well as boundary device configurations, portable media and mobile device procedures, portable media and mobile device scanning kiosk operations and incident response implementation procedures.
  • thermal pan-tilt-zoom security camera replacement - security
  • upgrades to security information and event management servers, network kiosks, addition of plant computer diode, centralize anti-virus updates, and plant process computer workstations - important-to-safety
  • addition of dedicated security information and event management workstations -

safety/important-to-safety/support system

  • security computer/access authorization - security

INSPECTION RESULTS

No findings were identified.

EXIT MEETINGS AND DEBRIEFS

The inspectors verified no proprietary information was retained or documented in this report.

  • On March 31, 2022, the inspectors presented the cyber security inspection results to Mr. F. J. Bianco, Senior Director, Nuclear Operations, and other members of the licensee staff.

DOCUMENTS REVIEWED

Inspection Type Designation Description or Title Revision or

Procedure Date

71130.10 Corrective Action CR - 201904128, 201905661, 202001842, 202004225,

Documents 202004652, 202005670, 202105183, 202105572,

2106145, 202106213, 202106265, 202106517,

2107043, 202201664

71130.10 Corrective Action CR - 202201799, 202201818, 202201842, 202201844,

Documents 202201845, 202201846, 202201860, 202201862,

Resulting from 202201864

Inspection

71130.10 Drawings 8600-X-90398 SAS Block Diagram Video 5

8600-X-90454 CAS Block Diagram Video 13

8600-X-90455 IRIScan Interconnection Diagram 7

8600-X-90456 Security Computer System Interconnection Drawing 4

J-113G-00010 MUX Block Diagram 8

J-113G-00515 Centralized Logging System Functional Block Diagram 6

J-113G-00516 Network Intrusion Detection System Functional Block 4

Diagram

J-2021-00041 PCS Replacement Functional Block Diagram 7

S001

71130.10 Engineering Design Equivalent PELCO SARIX ESTI350-2N, Thermal PTZ Camera 2

Changes Change Package Replacement

MP 19-0009

Design Equivalent 2018 Operating Experience Changes for Cyber Security 5

Change Package Program

MP 19-0084

Design Equivalent Addition of SPLUNK workstation in Security Computer 0

Change Package System

MP 21-0018

71130.10 Miscellaneous Presentation - Callaway Cyber Security 03/28/2022

Callaway CSAT Team Training 3

Tech Specialist Qualmaster Requirements 03/29/2022

Thermal Camera Configuration Baseline

Cyber Security Drills - Drill Packages (2019, 2020, 2021)

Inspection Type Designation Description or Title Revision or

Procedure Date

AXIS Q1942-E PT Mount Thermal Network Camera User

Manual

CA3188 Event/Incident Summary and Incident Response Plan 03/24/2022

CA4651 - Critical SK- Security Computer Modification Package: MP 21-0018 07/12/2021

Digital Asset

(CDA)

Modification

Mitigation Plan

CA4651 - CDA Network Intrusion Detection System and Centralized Logging 08/09/2019

Modification System MP 19-0084

Mitigation Plan

SKNH0012 Switch Configuration File 11/17/2021

SKNH0013 Switch Configuration File 11/17/2021

SKXX0003 Firewall Configuration File 10/21/2021

SKXX0004 Firewall Configuration File 10/21/2021

SKXX0010 Firewall Configuration File 10/21/2021

SKXY0003 Splunk Server Services 11/22/2021

SKXY0005 Splunk L2 Sever Services 11/17/2021

T.68.2943.S Cyber Security Incident Response Team Training 08/31/2017

71130.10 Procedures APA-ZZ-00907 Personnel Processing Requirements for Unescorted Access 30

to The Callaway Energy Center and Maintenance of

Associated Personnel Data

APA-ZZ-01104 Access Authorization Program for Callaway Energy Center 49

APA-ZZ-01108 Cyber Security Program 9

APA-ZZ-01108 CDA-Related Removable Media and Removable / Portable 11

ADDENDUM A Device Management

DTI-CS-002 Virus Scanning Station (Kiosk) DTI 5

DTI-CS-003 CDA Laptop Hardening DTI 7

DTI-CS-014 Vulnerability Scan and Assessment DTI 7

DTI-CS-018 Non-Engineering Configuration Control CDA Change 1

Process

EDP-SK-DR012 Network Intrusion Detection System and Centralized Logging 2

System Disaster Recovery

EDP-SK-DR014 Security Computer Log Forwarder Recovery Plan 2

Inspection Type Designation Description or Title Revision or

Procedure Date

EDP-ZZ-01108 Cyber Security Program Implementation 11

EDP-ZZ-01108 Cyber Security Program Implementation 12

EDP-ZZ-01108 Digital Assessment Process 14

ADDENDUM 1

EDP-ZZ-01108 Security Control Implementation Strategy 9

ADDENDUM 2

EDP-ZZ-01108 Callaway Ongoing Monitoring for Critical Digital Assets 10

ADDENDUM 3

EDP-ZZ-01108 Cyber Security Threat and Vulnerability Notification 4

ADDENDUM 4 Assessment Process

EDP-ZZ-01108 Callaway Cyber Security Incident Response Procedure 5

ADDENDUM 5

EDP-ZZ-01108 Cyber Security Contingency and Disaster Recovery Plans 2

ADDENDUM 6

EDP-ZZ-01108 Centralized Cyber Security Monitoring System 4

ADDENDUM 8

EDP-ZZ-01108 Threat Detection Software Configuration and Update 1

ADDENDUM 9

EDP-ZZ-01108 Cyber Security Defensive Strategy 6

APPENDIX A

EDP-ZZ-04056 Development And Configuration Management of Digital Plant 18

Systems

SDP-PI-CYBER Cyber Security 9

71130.10 Self-Assessments Cyber Security Effectiveness Review 12/14/2021

Cyber Security Effectiveness Review 02/01/2022

MAPPING - SK - Thermal PTZ Cameras

MAPPING - SK - Thermal Camera Decoders

SK - Security Computer Heavy Forwarder Control Mapping

MP21-0018

SSA-202104890- Cyber Security Self-Assessment 11/29/2021

001

71130.10 Work Orders SKHVF0001 (Splunk Heavy Forwarder) hardening checklist 01/19/2022

20511855/550 Perform Ongoing Monitoring Plant Computer System Critical 11/14/2020

Devices Inside Diode

Inspection Type Designation Description or Title Revision or

Procedure Date

20512939/500 Network Intrusion Detection and Centralized Logging Level 4 12/11/2020

Ongoing Monitoring

20512940/500 Network Intrusion Detection and Centralized Logging Level 12/11/2020

2P Ongoing Monitoring

21502460/550 Cyber Security Monitoring for Security Computer -SK 03/04/2021

21505642/500 Perform Cyber Security Effectiveness Program Review Per 08/08/2021

EDP-ZZ-01108

CYB00000613 CDA Modification Mitigation Plan - SK - Security Computer 0

MP 19-0009 Thermal Camera and Thermal Decoder Vulnerability 02/15/2022

Assessment

PM21503727/500 Perform Cyber Security Monitoring for Thermal Cameras 04/09/2021

PM21505642/500 Perform Cyber Security Effectiveness Program Review per 06/08/2021

EDP-ZZ-01108

8