ML103270521

From kanterella
Jump to navigation Jump to search

Draft NRC RAI Exelon Fleet Cyber Security Plan LAR
ML103270521
Person / Time
Site: Dresden, Quad Cities  Constellation icon.png
Issue date: 11/23/2010
From: Nicholas Difrancesco
Plant Licensing Branch III
To: Walker D
Exelon Corp
Di Francesco N, NRR/DORL/LPL3-2, 415-111
References
TAC ME4298, TAC ME4299, TAC ME4300, TAC ME4301, TAC ME4302, TAC ME4303, TAC ME4304, TAC ME4305, TAC ME4306, TAC ME4307, TAC ME4308, TAC ME4309, TAC ME4310, TAC ME4311, TAC ME4312, TAC ME4313, TAC ME4314
Download: ML103270521 (2)


Text

From:

DiFrancesco, Nicholas Sent:

Tuesday, November 23, 2010 12:35 PM To:

douglas.walker@exeloncorp.com Cc:

Brown, Eva; DiFrancesco, Nicholas; 'jeff.hansen@exeloncorp.com';

'Pamela.Cowan@exeloncorp.com'; Wohl, Marilyn

Subject:

Draft NRC RAI Re: Exelon Fleet Cyber Security Plan LAR (TAC NOs. ME4298-ME4314)

Mr. Walker, By letter to the U.S. Nuclear Regulatory Commission (NRC) dated November 23, 2009, Exelon Generation Company, LLC (EGC, the licensee), submitted for NRC review and approval the Exelon Cyber Security Plan (CSP) License Amendment Request (LAR) for Braidwood Station, Units 1 & 2, Byron Station, Unit Nos. 1 & 2, Clinton Power Station, Unit No. 1, Dresden Nuclear Power Station, Units 2 & 3, LaSalle County Station, Units 1 & 2, Limerick Generating Station, Units 1 & 2, Oyster Creek Nuclear Generating Station, Peach Bottom Atomic Power Station, Units 1 & 2, Quad Cities Nuclear Power Station, Units 1 & 2, and Three Mile Island Nuclear Station, Unit 1. By letter dated July 23, 2010, EGC superseded the CSP to be based on NRC-endorsed methodology Nuclear Energy Institute 08-09, Cyber Security Plan Template, Revision 6.

The Integrated Security Coordination and Policy Branch within the Office of Nuclear Security and Incident Response has reviewed the information provided for EGC CSP LAR, and has determined that additional information is required to complete its review. The draft request for additional information (RAI) related to the NRC staff review is provided below.

After reviewing the draft RAI, please contact Eva Brown at 301-415-2315 to discuss the need for a teleconference to clarify the draft RAI and to establish a due date for the response.

Respectfully, Nick DiFrancesco Project Manager, Braidwood, Byron, and Clinton (Fleet Backup)

Nuclear Regulatory Commission Division of Operating Reactor Licensing nicholas.difrancesco@nrc.gov Tel: (301) 415-1115 Fax: (301) 415-1222 DRAFT RAI

RAI 1

CSP Section: 4 Establishing, Implementing, and Maintaining the Cyber Security Program

Title:

Defense-in-Depth Protective Strategies - Critical Digital Asset isolation strategies 10 CFR 73.54(c)(2) requires the licensee to apply and maintain defense-in-depth protective strategies to ensure the capability to detect, respond to, and recover from cyber attacks. Section 4.3, Defense-in-Depth Protective Strategies, of the Exelon Generation Company, LLC (Braidwood, Byron, Clinton, Dresden, LaSalle, Limerick, Oyster Creek, Peach Bottom, Quad Cities, and Three Mile Island) Cyber

Security Plan states (1) when referring to protections which isolate or secure Safety related Critical Digital Assets (CDAs) within Level 4 and Security CDAs within cyber security defensive levels 4 and 3, that these devices may be secured via one or more deterministic devices (i.e., data diodes, air gaps) that isolate CDAs in level 4, or one or more non-deterministic network isolation devices.

Please clarify if any of the non-deterministic devices for the safety related CDAs and security CDAs are in parallel (i.e., connecting the same network segments) with the deterministic devices because that would negate the protection afforded by the deterministic devices.

DRAFT RAI E-mail Properties Mail Envelope Properties (0046140293E11F408991442DB4FE25CA127DAF3EB3)

Subject:

Draft NRC RAI Re: Exelon Fleet Cyber Security Plan LAR (TAC NOs.

ME4298-ME4314)

Sent Date: 11/23/2010 12:35:10 PM Received Date: 11/23/2010 12:35:10 PM From: DiFrancesco, Nicholas Created By: Nicholas.DiFrancesco@nrc.gov Recipients:

douglas.walker@exeloncorp.com (douglas.walker@exeloncorp.com)

Tracking Status: None Eva.Brown@nrc.gov (Brown, Eva)

Tracking Status: None Nicholas.DiFrancesco@nrc.gov (DiFrancesco, Nicholas)

Tracking Status: None jeff.hansen@exeloncorp.com ('jeff.hansen@exeloncorp.com')

Tracking Status: None Pamela.Cowan@exeloncorp.com ('Pamela.Cowan@exeloncorp.com')

Tracking Status: None Marilyn.Wohl@nrc.gov (Wohl, Marilyn)

Tracking Status: None Post Office:

HQCLSTR01.nrc.gov Files Size Date & Time MESSAGE 22613 11/23/2010 Options

Expiration Date:

Priority: olImportanceNormal ReplyRequested: False Return Notification: False Sensitivity: olNormal Recipients received: