ML23348A078

From kanterella
Jump to navigation Jump to search
NRR E-mail Capture - Voluntary Request for Closed Meeting Regarding Cyber Security Assessments at Vogtle, Units 3 and 4
ML23348A078
Person / Time
Site: Vogtle  Southern Nuclear icon.png
Issue date: 12/13/2023
From: John Lamb
Plant Licensing Branch II
To: Coleman J
Southern Nuclear Operating Co
References
Download: ML23348A078 (2)


Text

From:

John Lamb Sent:

Wednesday, December 13, 2023 11:45 AM To:

Coleman, Jamie Marquess Cc:

Joyce, Ryan M.; Pournaras, DeLisa S.; Lowery, Ken G.; Michael Markley; Eric Lee; Christopher Cook; Vic Cusumano; Bo Pham; Jamie Heisserer (She/Her/Hers)

Subject:

Voluntary Request for Closed Meeting regarding Cyber Security Assessments at Vogtle, Units 3 and 4

Jamie, The U.S. Nuclear Regulatory Commission (NRC) staff is currently conducting research to develop a method to efficiently evaluate the cyber security assessment of a Critical Digital Asset (CDA) that used the Electric Power Research institute (EPRI), 2018 Technical Report, Cyber Security Technical Assessment Methodology [TAM] - Risk Informed Exploit Sequence Identification and Mitigation, Revision 1. The goal of this research is to allow the NRC staff to efficiently perform a cyber security inspection at a facility that used the TAM to perform a cyber security inspection at a facility that used the TAM to perform a cybersecurity assessment of its CDAs. This would enable licensees to prepare for and support these inspections more efficiently. The NRC Office of Nuclear Regulatory Research (RES) initiated a research project to study the TAM assessment data to develop a method that would allow the NRC to efficiently perform the cybersecurity inspections at a facility that used the TAM to protect CDAs and licensees to efficiently support those inspections. For this research, the RES team is requesting Southern Nuclear Operating Company (SNC, the licensee) to share the Vogtle Electric Generating Plant (Vogtle), Unit 4, TAM assessment process by engaging with the RES staff and its contractors and explain how SNC addressed the cybersecurity controls provided in its cyber security plan (CSP).

Specifically, the RES staff would like to know how SNC used the result of TAM and how SNC go back through its CSP cyber security controls and map them to the appropriate control method sections of each TAM.

The RES staff learned from the cyber security inspectors who visited Vogtle, Unit 4, that SNC staff did an excellent job in addressing gaps between TAM and the cyber security controls provided in its CSP. If possible, the RES would like to incorporate insights and knowledge gained by the SNC staff into the method that RES is developing through this research project.

Therefore, the RES staff requests a closed meeting with SNC in the first or second week of January 2024 to discuss and assist RES staff understand how SNC used the result of TAM to address regulatory compliance with itsr cyber security program.

Can SNC support this?

Thanks.

John

Hearing Identifier:

NRR_DRMA Email Number:

2337 Mail Envelope Properties (MN2PR09MB5084123C84B92C5E6A552239FA8DA)

Subject:

Voluntary Request for Closed Meeting regarding Cyber Security Assessments at Vogtle, Units 3 and 4 Sent Date:

12/13/2023 11:44:33 AM Received Date:

12/13/2023 11:44:00 AM From:

John Lamb Created By:

John.Lamb@nrc.gov Recipients:

"Joyce, Ryan M." <RMJOYCE@southernco.com>

Tracking Status: None "Pournaras, DeLisa S." <DSPOURNA@SOUTHERNCO.COM>

Tracking Status: None "Lowery, Ken G." <KGLOWERY@southernco.com>

Tracking Status: None "Michael Markley" <Michael.Markley@nrc.gov>

Tracking Status: None "Eric Lee" <Eric.Lee@nrc.gov>

Tracking Status: None "Christopher Cook" <Christopher.Cook@nrc.gov>

Tracking Status: None "Vic Cusumano" <Victor.Cusumano@nrc.gov>

Tracking Status: None "Bo Pham" <Bo.Pham@nrc.gov>

Tracking Status: None "Jamie Heisserer (She/Her/Hers)" <Jamie.Heisserer@nrc.gov>

Tracking Status: None "Coleman, Jamie Marquess" <JAMIEMCO@SOUTHERNCO.COM>

Tracking Status: None Post Office:

MN2PR09MB5084.namprd09.prod.outlook.com Files Size Date & Time MESSAGE 2294 12/13/2023 11:44:00 AM Options Priority:

Normal Return Notification:

No Reply Requested:

No Sensitivity:

Normal Expiration Date: