ML17279A056

From kanterella
Jump to navigation Jump to search

Use of Encryption Software for Electronic Transmission of Safeguards Information
ML17279A056
Person / Time
Site: Cooper Entergy icon.png
Issue date: 11/15/2017
From: Thomas Wengert
Plant Licensing Branch IV
To: Dent J
Nebraska Public Power District (NPPD)
Wengert T, NRR/DORL/LPLIV, 415-4037
References
EPID L-2017-LRO-0030
Download: ML17279A056 (3)


Text

UNITED STATES NUCLEAR REGULATORY COMMISSION WASHINGTON, D.C. 20555-0001 November 15, 2017 Mr. John Dent, Jr.

Vice President-Nuclear and CNO Nebraska Public Power District 72676 648A Avenue Brownville, NE 68321

SUBJECT:

COOPER NUCLEAR STATION - USE OF ENCRYPTION SOFTWARE FOR ELECTRONIC TRANSMISSION OF SAFEGUARDS INFORMATION (EPID L-2017-LR0-0030)

Dear Mr. Dent:

By letter dated September 13, 2017 (Agencywide Documents Access and Management System (ADAMS) Accession No. ML17264A069}, Nebraska Public Power District (NPPD), requested that the U.S. Nuclear Regulatory Commission (NRC) approve the use of Symantec Endpoint Encryption by PGP Technology, 11.1, or the latest validated version, to process and transmit safeguards information (SGI) at the Cooper Nuclear Station. This request was made pursuant to paragraph 73.22(f)(3), "External transmission of documents and material," of Title 1O of the Code of Federal Regulations (10 CFR).

The regulations in 10 CFR 73.22(f)(3) describe requirements for the transmission of SGI outside an authorized place of use or storage. The regulations in 10 CFR 73.22(f)(3) state, in part:

Except under emergency or extraordinary conditions, Safeguards Information shall be transmitted outside an authorized place of use or storage only by NRC approved secure electronic devices, such as facsimiles or telephone devices, provided that transmitters and receivers implement processes that will provide high assurance that Safeguards Information is protected before and after the transmission or electronic mail through the internet, provided that the information is encrypted by a method (Federal Information Processing Standard [Fl PS] 140-2 or later) approved by the appropriate NRC Office; the information is produced by a self contained secure automatic data process system; and transmitters and receivers implement the information handling processes that will provide high assurance that Safeguards Information is protected before and after transmission.

Guidance to licensees on the electronic transmission of SGI is provided in NRC Regulatory Issue Summary (RIS) 2002-15, Revision 1, "NRC Approval of Commercial Data Encryption Products for the Electronic Transmission of Safeguards Information," dated January 26, 2006 (ADAMS Accession No. ML050460031 ).

J. Dent As stated in NPPD's letter, Symantec Endpoint Encryption by PGP Technology, 11.1, was developed with Symantec PGP Cryptographic Engine, Software Version 4.3, and complies with FIPS 140-2 requirements, as validated by the National Institute of Standards and Technology (NIST) Consolidated Certificate No. 0053. A copy of the certificate was enclosed with NPPD's letter.

The NRC approves only those cryptographic algorithms approved by NIST. Based on the NIST validation that the encryption software complies with FIPS 140-2, the NRC staff finds that the use of Symantec Endpoint Encryption, Version 11.1, is acceptable to use for electronic transmission of SGI in accordance with 10 CFR 73.22(f)(3). As described in RIS 2002-15, newer versions of encryption software may be used without prior NRC approval, provided that it is documented that the newer version uses the same cryptographic module as the current version. Therefore, in accordance with 10 CFR 73.22(f)(3), the staff approves the use of Symantec Endpoint Encryption, Version 11.1 at Cooper Nuclear Station. If NIST no longer approves certain cryptographic algorithms, the NRC also does not approve use of that cryptographic algorithm.

If you have any questions, please contact me at 301-415-4037 or via e-mail at Thomas.Wengert@nrc.gov.

Sincerely,

~~

Thomas J. Wengert, Seni~~roject Manager Plant Licensing Branch IV Division of Operating Reactor Licensing Office of Nuclear Reactor Regulation Docket No. 50-298 cc: Listserv

ML17279A056 *via e-mail OFFICE N RR/D0RL/LPL4/PM NRR/DORL/LPL4/LA NSI R/DSO/ISB/BC*

NAME TWengert PBlechman DParsons DATE 10/6/17 10/6/17 10/30/17 OFFICE OGC-NLO NRR/DORL/LPL4/BC NRR/D0RL/LPL4/PM NAME AWase RPascarelli TWengert DATE 11/13/17 11/14/17 11/15/17