ML19350C857

From kanterella
Jump to navigation Jump to search
Information Request for the Cyber Security Baseline Security Inspection, Notification to Perform Inspection
ML19350C857
Person / Time
Site: Vogtle  Southern Nuclear icon.png
Issue date: 12/06/2019
From: Scott Shaeffer
NRC/RGN-II/DRS/EB2
To: Yox M
Southern Nuclear Company
lka1
References
Download: ML19350C857 (4)


Text

OFFICIAL USE ONLY - SECURITY RELATED INFORMATION UNITED STATES NUCLEAR REGULATORY COMMISSION REGION II 245 PEACHTREE CENTER AVENUE, N.E., SUITE 1200 ATLANTA, GEORGIA 30303-1200 December 6, 2019 Mr. Michael Yox Regulatory Affairs Director Southern Nuclear Operating Company 7825 River Road, Bldg. 302, Vogtle 3&4 Waynesboro, GA 30830

SUBJECT:

VOGTLE NUCLEAR PLANT, UNITS 3 & 4 - INFORMATION REQUEST FOR THE CYBER SECURITY BASELINE SECURITY INSPECTION, NOTIFICATION TO PERFORM INSPECTION

Dear Mr. Yox:

On March 30, 2020, the U.S. Nuclear Regulatory Commission (NRC) will begin a baseline security inspection in accordance with Inspection Procedure (IP) 81000.09 Cyber Security Inspection for Construction, dated September 20, 2016 at the Vogtle Nuclear Plant, Units 3 & 4. The inspection will be performed to evaluate and assess the requirements of the NRCs Cyber Security Rule, Title 10, Code of Federal Regulations (CFR), Part 73, Section 54, Protection of Digital Computer and Communication Systems and Networks. The onsite portion of the inspection will take place during the weeks of March 30, 2020 thru April 17, 2020.

Experience has shown that cyber security baseline inspections are extremely resource intensive, both for the NRC inspectors and the licensee staff. In this instance, with the incorporation of two currently operating units, to minimize the inspection impact on the site staff, and to ensure a productive inspection for both parties, we have enclosed a request for documents needed for the inspection.

These documents have been divided into four groups.

The first group specifies information necessary to assist the inspection team in choosing the focus areas (i.e., sample set) to be inspected by the cyber security IP. This information should be made available via secure site (i.e., SharePoint, Certrec) no later than January 13, 2020. The inspection team will review this information and will request any additional specific items that should be provided for review to aid in inspection planning and preparation.

The second group of additional requested documents will assist the inspection team in the evaluation of the critical systems and critical digital assets (CSs/CDAs), defensive architecture, and the areas of the licensees CSP selected for the cyber security inspection. This information should be made available for review via secure site (i.e., SharePoint, Certrec) before February 9, 2020.

OFFICIAL USE ONLY - SECURITY RELATED INFORMATION

OFFICIAL USE ONLY - SECURITY RELATED INFORMATION M. Yox 2 The third group of requested documents consists of those items that the inspection team will review, or need access to, during the inspection. Please have this information available by the first day of the onsite inspection, March 30, 2020.

The fourth group of information is necessary to aid the inspection team in tracking issues identified during or as a result of the inspection. It is requested that this information be provided to the lead inspector as the information is generated during the inspection. It is important that all of these documents are kept up to date and complete in order to minimize the number of additional documents requested during the preparation and/or the onsite portions of the inspection. The lead inspector for this inspection is Mr. Rodney Fanner. We understand that our regulatory contact for this inspection is Ms. Kelli Roberts of your organization. If there are any questions about the inspection or the material requested, please contact the lead inspector at 404-997-4638 or via e-mail at Rodney.fanner@nrc.gov or me at 404-997-4521.

This letter does not contain new or amended information collection requirements subject to the Paperwork Reduction Act of 1995 (44 U.S.C. 3501 et seq.). Existing information collection requirements were approved by the Office of Management and Budget, control number 3150-0011. The NRC may not conduct or sponsor, and a person is not required to respond to, a request for information or an information collection requirement unless the requesting document displays a currently valid Office of Management and Budget control number.

In accordance with 10 CFR 2.390, Public Inspections, Exemptions, Requests for Withholding, of the NRC's "Rules of Practice," a copy of this letter and its enclosure will not be available electronically for public inspection in the NRCs Public Document Room or from the Publicly Available Records (PARS) component of the NRC's Agencywide Documents Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading-rm/adams.html (the Public Electronic Reading Room).

Sincerely,

/RA/

Scott M. Shaeffer, Chief Engineering Branch 2 Division of Reactor Safety Docket Nos.: 52-025,52-026 License Nos.: NPF-91, NPF-92

Enclosure:

Security Inspection Document Request cc: See Page 3 OFFICIAL USE ONLY - SECURITY RELATED INFORMATION

ML19350C857 OFFICE RII/DRS/EB2 RII/DRS/EB2 NAME R. Fanner S. Shaeffer DATE 12/ 5 / 2019 12/ 5 /2019 E-MAIL COPY? YES NO YES NO