ML110940096

From kanterella
Jump to navigation Jump to search

Supplement to License Amendment Request (LAR) for Approval of Northern States Power Company - Minnesota Cyber Security Plan (TAC ME4294, ME4295, & ME4272)
ML110940096
Person / Time
Site: Monticello, Prairie Island  Xcel Energy icon.png
Issue date: 04/01/2011
From: Molden J
Northern States Power Co, Xcel Energy
To:
Document Control Desk, Office of Nuclear Reactor Regulation, Office of Nuclear Security and Incident Response
Shared Package
ML110940095 List:
References
L-XE-11-004, TAC ME4272, TAC ME4294, TAC ME4295
Download: ML110940096 (1)


Text

414 Nicollet Mall - MP4 Minneapolis, MN 55401 April 1, 201 1 L-XE-11-004 10 CFR 50.90 U.S. Nuclear Regulatory Commission ATTN: Document Control Desk Washington, DC 20555-0001 Prairie Island Nuclear Generating Plant, Monticello Nuclear Generating Plant Units 1 and 2 Docket 50-263 Dockets 50-282 and 50-306 Renewed License No. DPR-22 License Nos. DPR-42 and DPR-60 Supplement to License Amendment Request (LAR) for Approval of the Northern States Power Companv - Minnesota Cvber Security Plan (TAC Nos. ME4294, ME4295, and ME4272)

By letter dated July 20,2010, (Agencywide Documents Access and Management System (ADAMS) Accession No. ML102020164), Northern States Power Company, a Minnesota corporation, doing business as Xcel Energy (hereafter "NSPM"), submitted an LAR for the Prairie Island Nuclear Generating Plant (PINGP), Units 1 and 2, and the Monticello Nuclear Generating Plant (MNGP) requesting Nuclear Regulatory Commission (NRC) approval of the NSPM Cyber Security Plan (CSP), proposed implementation schedule, and addition of a sentence to the existing PINGP and MNGP Facility Operating Licenses (FOL) Physical Protection license conditions to require NSPM to fully implement and maintain in effect all provisions of the Commission approved CSP. NSPM supplemented the LAR requesting approval of the NSPM CSP by letters dated November 30,201 0 (ADAMS Accession No. ML103350163), and February 21,2011 (ADAMS Accession No. ML110540144).

By letter dated March 4, 201 1 (ADAMS Accession Number ML110600980), NRC Staff requested additional information to support their review of the July 20, 2010 submittal and its supplements. Enclosure 1 to this letter provides the responses to the NRC Staff requests for additional information (RAls). Enclosure 2 provides the CSP revised to incorporate the changes discussed in the RAI responses. NSPM submits this supplement in accordance with the provisions of 10 CFR 50.90. to the submittal dated July 20, 2010 (ADAMS Accession No.

M L I 02020164), included six commitments to implementation milestone dates and the date for full CSP implementation. By this letter NSPM withdraws the six commitments to implementation milestone dates provided in the July 20, 2010 letter. NRC RAI 2 states, "It is the NRC's intention to develop a license condition incorporating your

Document Control Desk Page 2 revised CSP implementation schedule containing the key milestone dates." NSPM believes milestone activity completion dates should be commitments in lieu of an NRC license condition and this letter makes seven new commitments stated below based on the response to RAI 2 in Enclosure 1.

NSPM understands that the NRC withheld the NSPM CSP submitted with the July 20, 2010 (ADAMS Accession No. ML102020164), from public disclosure as security sensitive information. Accordingly, Enclosures 1 and 2 to this letter have been marked as security related and NSPM requests that they be withheld from public disclosure in accordance with 10CFR 2.390.

The supplemental information provided in this letter does not impact the conclusions of the Determination of No Significant Hazards Consideration or Environmental Assessment presented in the July 20, 2010 submittal as supplemented November 30, 2010 and February 21, 201 1.

In accordance with 10 CFR 50.91, NSPM is notifying the State of Minnesota of this LAR supplement by transmitting a copy of this letter to the designated State Official.

If you have questions regarding this submittal, please contact Mr. Dale Vincent, P.E., at 651-388-1121.

Summarv of Commitments This letter withdraws the six implementation milestone dates included in Enclosure 4 to the July 20,2010 (ADAMS Accession No. ML102020164), submittal and makes the following new commitments:

1. By December 31, 2012, establish Cyber Security Assessment Team (CSAT) as described in Section 3.1.2 "Cyber Security Assessment Team" of the Cyber Security Plan (CSP).
2. By December 31, 2012, identify Critical Systems (CSs) and Critical Digital Assets (CDAs) as described in Section 3.1.3 "Identification of Critical Digital Assets" of the CSP.
3. By December 31, 2012, implement installation of a deterministic one way device or a combination of technologies consisting of firewall devices and intrusion detection1 intrusion prevention systems between lower level devices (level 0, 1,
2) and the higher level devices (level 3, 4) as described in Section 4.3, "Defense-In-Depth Protective Strategies" of the CSP.

By December 31, 2012, lower security level devices (level 0, 1, 2 devices) that bypass the deterministic device and connect to level 3 or 4 will be modified to prevent the digital connectivity to the higher level or will be modified to meet

Document Control Desk Page 3 cyber security requirements commensurate with the level 3 or 4 devices to which they connect.

The design modifications that are not finished by the completion date will be documented in the site configuration management and/or change control program to assure completion of the design modification as soon as possible, but no later than the final implementation date.

4. By December 31, 2012, the security control "Access Control For Portable And Mobile Devices" described in Appendix B 1.19 of NEI 08-09, Revision 6, will be implemented.
5. By December 31, 2012, implement observation and identification of obvious cyber related tampering to existing insider mitigation rounds by incorporating the appropriate elements in Appendix E Section 4.3 "Personnel Performing Maintenance And Testing Activities."
6. By December 31, 2012, identify, document, and implement NEI 08-09, Rev 6, Appendix Dl technical cyber security controls in accordance with the Cyber Security Plan Section 3.1.6 "Mitigation of Vulnerabilities and Application of Cyber Security Controls" for CDAs that could adversely impact the design function of physical security target set equipment.

The implementation of controls that require a design modification that are not finished by the completion date will be documented in the site configuration management and/or change control program to assure completion of the design modification as soon as possible, but no later than the final implementation date.

9. By December 31, 2012, ongoing monitoring and assessment activities commence, as described in Section 4.4, "Ongoing Monitoring and Assessment" of the CSP, for those target set CDAs whose security controls have been implemented.

I declare under penalty of perjury that the foregoing is true and correct.

Executed on April 1, 201 1.

/ / ~ a m e s E. Molden Vice President, Operations Support Northern States Power Company - Minnesota Enclosures (2) cc: Administrator, Region Ill, USNRC Project Manager, PINGP, USNRC

Document Control Desk Page 4 Resident Inspector, PINGP, USNRC Project Manager, MNGP, USNRC Resident Inspector, MNGP, USNRC State of Minnesota (letter only)