ML14321A713: Difference between revisions

From kanterella
Jump to navigation Jump to search
(Created page by program invented by StriderTol)
(Created page by program invented by StriderTol)
Line 2: Line 2:
| number = ML14321A713
| number = ML14321A713
| issue date = 12/10/2014
| issue date = 12/10/2014
| title = Issuance of Amendment No. 241, Revise Operating License Condition for Change to Cyber Security Plan Milestone 8 Full Implementation Date (TAC No. MF4675)
| title = Issuance of Amendment No. 241, Revise Operating License Condition for Change to Cyber Security Plan Milestone 8 Full Implementation Date
| author name = Wang A B
| author name = Wang A B
| author affiliation = NRC/NRR/DORL/LPLIV-2
| author affiliation = NRC/NRR/DORL/LPLIV-2

Revision as of 14:54, 7 February 2019

Issuance of Amendment No. 241, Revise Operating License Condition for Change to Cyber Security Plan Milestone 8 Full Implementation Date
ML14321A713
Person / Time
Site: Waterford Entergy icon.png
Issue date: 12/10/2014
From: Wang A B
Plant Licensing Branch IV
To:
Entergy Operations
Wang A B
References
TAC MF4675
Download: ML14321A713 (13)


Text

UNITED STATES NUCLEAR REGULATORY COMMISSION WASHINGTON, D.C. 20555-0001 Vice President, Operations Entergy Operations, Inc. Waterford Steam Electric Station, Unit 3 17265 River Road Killona, LA 70057-3093 December 10, 2014

SUBJECT:

WATERFORD STEAM ELECTRIC STATION, UNIT 3-ISSUANCE OF AMENDMENT RE: MILESTONE 8 OF THE CYBER SECURITY PLAN (TAC NO. MF4675)

Dear Sir or Madam:

The Commission has issued the enclosed Amendment No. 241 to Facility Operating License No. NPF-38 for the Waterford Steam Electric Station, Unit 3 (WF3). This amendment consists of changes to the facility operating license in response to your application dated August 4, 2014. The amendment approves a change to the WF3 facility operating license to revise the date for implementation of Milestone 8 of the Cyber Security Plan (CSP) Implementation Schedule and the existing license conditions in the facility operating license. Milestone 8 of the CSP implementation schedule concerns the full implementation of the CSP. A copy of our related Safety Evaluation is also enclosed.

The Notice of Issuance will be included in the Commission's next biweekly Federal Register notice. Docket No. 50-382

Enclosures:

1. Amendment No. 241 to NPF-38 2. Safety Evaluation cc w/encls: Distribution via Listserv Sincerely, Michael D. Orenak, Project Manager Plant Licensing IV-2 and Decommissioning Transition Branch Division of Operating Reactor Licensing Office of Nuclear Reactor Regulation UNITED STATES NUCLEAR REGULATORY COMMISSION WASHINGTON, D.C. 20555-0001 ENTERGY OPERATIONS, INC. DOCKET NO. 50-382 WATERFORD STEAM ELECTRIC STATION, UNIT 3 AMENDMENT TO FACILITY OPERATING LICENSE Amendment No. 241 License No. NPF-38 1. The Nuclear Regulatory Commission (the Commission) has found that: A. The application for amendment by Entergy Operations, Inc. (EOI, the licensee), dated August 4, 2014, complies with the standards and requirements of the Atomic Energy Act of 1954, as amended (the Act), and the Commission's rules and regulations set forth in 10 CFR Chapter I; B. The facility will operate in conformity with the application, the provisions of the Act, and the rules and regulations of the Commission; C. There is reasonable assurance (i) that the activities authorized by this amendment can be conducted without endangering the health and safety of the public, and (ii) that such activities will be conducted in compliance with the Commission's regulations; D. The issuance of this license amendment will not be inimical to the common defense and security or to the health and safety of the public; and E. The issuance of this license amendment is in accordance with 10 CFR Part 51 of the Commission's regulations and all applicable requirements have been satisfied.

Enclosure 1 2. Accordingly, the license is amended by changes to the facility operating license as indicated in the attachment to this license amendment, and Paragraph 2.E. of Facility Operating License No. NPF-38 is hereby amended to read, in part, as follows: EOI shall fully implement and maintain in effect all provisions of the Commission-approved cyber security plan (CSP), including changes made pursuant to the authority of 10 CFR 50.90 and 10 CFR 50.54(p).

The EOI CSP was approved by License Amendment No. 234 and supplemented by a changes approved by Amendment Nos. 239 and 241. 3. This license amendment is effective as of its date of issuance and shall be implemented within 60 days from the date of issuance.

Attachment:

Changes to the Facility Operating License No. NPF-38 FOR THE NUCLEAR REGULATORY COMMISSION Douglas A. Broaddus, Chief Plant Licensing IV-2 and Decommissioning Transition Branch Division of Operating Reactor Licensing Office of Nuclear Reactor Regulation Date of Issuance:

December 10, 2014 ATTACHMENT TO LICENSE AMENDMENT NO. 241 TO FACILITY OPERATING LICENSE NO. NPF-38 DOCKET NO. 50-382 Replace the following page of the Facility Operating License with the attached revised page. The revised page is identified by amendment number and contains marginal lines indicating the areas of change. Facility Operating License REMOVE INSERT (a) The first performance of SR 6.5.17, in accordance with Specification 6.5.17.c.(i), shall be within the specified Frequency of 6 years, plus the 18-month allowance of SR 4.0.2, as measured from April 17, 2004, the date of the most recent successful tracer gas test, as stated in the October 8, 2004 letter response to Generic Letter 2003-01, or within the next 18 months if the time period since the most recent successful tracer gas test is greater than 6 years. (b) The first performance of the periodic assessment of CRE habitability, Specification 6.5.17.c.(ii), shall be within 3 years, plus the 9-month allowance of SR 4.0.2, as measured from April17, 2004, the date of the most recent successful tracer gas test, as stated in the October 8, 2004 letter response to Generic Letter 2003-01, or within the next 9 months if the time period since the most recent successful tracer gas test is greater than 3 years. (c) The first performance of the periodic measurement of CRE pressure, Specification 6.5.17 .d, shall be within 18 months, plus the 138 days allowed by SR 4.0.2, as measured from August 13, 2008, the date of the most recent successful pressure measurement test, or within 138 days if not performed previously.

D. The facility requires an exemption from certain requirements of Appendices E and J to 10 CFR Part 50. These exemptions are described in the Office of Nuclear Reactor Regulation's Safety Evaluation Report, Supplement No. 10 (Section 6.1.2) and Supplement No. 8 (Section 6.2.6), respectively.

These exemptions are authorized by law and will not endanger life or property or the common defense and security and are otherwise in the public interest.

These exemptions are, therefore, hereby granted pursuant to 10 CFR 50.12. With the granting of these exemptions, the facility will operate, to the extent authorized herein, in conformity with the application, as amended, the provisions of the Act, and the rules and regulations of the Commission.

E. EOI shall fully implement and maintain in effect all provisions of the approved physical security, training and qualification, and safeguards contingency plans including amendments made pursuant to provisions of the Miscellaneous Amendments and Search Requirements revisions to 10 CFR 73.55 (51 FR 27817 and 27822) and to the authority of 10 CFR 50.90 and 10 CFR 50.54(p).

The plan, which contains Safeguards Information protected under 10 CFR 73.21, is entitled: "Physical Security, Safeguards Contingency and Training & Qualification Plan," and was submitted on October 4, 2004. EOI shall fully implement and maintain in effect all provisions of the approved cyber security plan (CSP), including changes made pursuant to the authority of 10 CFR 50.90 and 10 CFR 50.54(p).

The EOI CSP was approved by License Amendment No. 234 and supplemented by a change approved by Amendment Nos. 239 and 241. AMENDMENT NO. 171,218,234,239,241 Revised by letter dated July 26, 2007 UNITED STATES NUCLEAR REGULATORY COMMISSION WASHINGTON, D.C. 20555-0001 SAFETY EVALUATION BY THE OFFICE OF NUCLEAR REACTOR REGULATION RELATED TO AMENDMENT NO. 241 TO FACILITY OPERATING LICENSE NO. NPF-38 ENTERGY OPERATIONS, INC. WATERFORD STEAM ELECTRIC STATION, UNIT 3 DOCKET NO. 50-382

1.0 INTRODUCTION

By application dated August 4, 2014 (Agencywide Documents Access and Management System (ADAMS) Accession Nos. ML 14217A498, ML 14217A496, and ML 14217A497), Entergy Operations Inc. (Entergy, the licensee), requested a change to the facility operating license (FOL) for the Waterford Steam Electric Station, Unit 3 (WF3). The proposed change would revise the date of Cyber Security Plan (CSP) Implementation Schedule Milestone 8 and the existing license condition in the FOL. Milestone 8 of the CSP implementation schedule concerns the full implementation of the CSP. Portions of the letter dated August 4, 2014, contain sensitive unclassified non-safeguards information and, accordingly, those portions are withheld from public disclosure in accordance with the provisions of paragraph 2.390(d)(1) of Title 10 of the Code of Federal Regulations (CFR).

2.0 REGULATORY EVALUATION

The U.S. Nuclear Regulatory Commission (NRC) staff reviewed and approved the licensee's existing CSP implementation schedule in WF3 License Amendment No. 234 dated July 20, 2011 (ADAMS Accession No. ML 111800021

), concurrent with the incorporation of the CSP into the facility's current licensing bases. The NRC staff considered the following regulatory requirements and guidance in its review of the August 4, 2014, license amendment request (LAR) to modify the existing CSP implementation schedule:

  • The regulations in 10 CFR 73.54, "Protection of digital computer and communication systems and networks," of 10 CFR state, in part, that: "Each [CSP] submittal must mclude a proposed implementation schedule.

Implementation of the licensee's cyber security program must be consistent with the approved schedule." Enclosure 2

  • The licensee's FOL includes a license condition that requires the licensee to fully implement and maintain in effect all provisions of the Commission-approved CSP.
  • In a publically available NRC memorandum dated October 24, 2013 (ADAMS Accession No. ML 13295A467), the NRC staff listed criteria that it would consider during its evaluations of licensees' requests to postpone their cyber security programs implementation dates (commonly known as Milestone 8). The NRC staff does not regard the CSP milestone implementation dates as regulatory commitments that can be changed unilaterally by the licensee, particularly in light of the regulatory requirement at 10 CFR 73.54, that "[i]mplementation of the licensee's cyber security program must be consistent with the approved schedule." As the NRC staff explained in its letter to all operating reactor licensees dated May 9, 2011 (ADAMS Accession No. ML 11 0980538), the implementation of the plan, including the key intermediate milestone dates and the full implementation date, shall be in accordance with the implementation schedule submitted by the licensee and approved by the NRC. All subsequent changes to the approved CSP implementation schedule, thus, will require prior NRC approval as required by 10 CFR 50.90. 3.0 TECHNICAL EVALUATION

3.1 Licensee's

Requested Change License Amendment No. 234 to FOL No. NPF-38 for WF3 was issued by the NRC staff on July 20, 2011. The NRC staff also approved the licensee's CSP implementation schedule, as discussed in the safety evaluation issued with the amendment.

The implementation schedule had been submitted by the licensee based on a template prepared by the Nuclear Energy Institute (NEI) (ADAMS Accession No. ML 11 0600218), which the NRC staff found acceptable for licensees to use to develop their CSP implementation schedules.

The licensee's proposed implementation schedule for the CSP identified completion dates and bases for the following eight milestones:

1) Establish the Cyber Security Assessment Team (CSAT); 2) Identify Critical Systems (CSs) and Critical Digital Assets (CDAs); 3) Install a data diode device between lower level devices and higher level devices; 4) Implement the security control "Access Control For Portable And Mobile Devices";
5) Implement observation and identification of obvious cyber related tampering to existing insider mitigation rounds; 6) Identify, document, and implement cyber security controls in accordance with "Mitigation of Vulnerabilities and Application of Cyber Security Controls" for CDAs that could adversely impact the design function of physical security target set equipment; 7) Commence ongoing monitoring and assessment activities for those target set CDAs whose security controls have been implemented; and 8) Full implementation of the CSP for all safety, security, and emergency preparedness functions.

Currently, Milestone 8 of the WF3 CSP requires the licensee to fully implement the CSP by December 15, 2014. In its August 4, 2014, application, Entergy proposed to change the Milestone 8 completion date to June 30, 2016. The licensee's application addressed the eight criteria in the NRC's October 24, 2013, guidance memorandum.

The licensee provided the following information pertinent to each of the criteria identified in the NRC guidance memorandum dated October 24, 2013: 1) Identification of the specific requirement or requirements of the cyber security plan that the licensee needs additional time to implement.

The licensee stated that the CSP, Sections 3 and 4, which describe requirements for application and maintenance of security controls listed in NEI 08-09, Revision 6, "Cyber Security Plans for Nuclear Power Reactors," Appendices D and E, needed additional time to implement.

The licensee provided a list of specific requirements needing additional time. 2) Detailed justification that describes the reason the licensee requires additional time to implement the specific requirement or requirements identified.

The licensee stated that the cyber security assessment process was completed in the second quarter of 2014. The output of this process includes identification of specific remediation actions required to close gaps and satisfy each control. Since the number of CDAs and existing procedures is in the hundreds and the number of individual cyber security control attributes is also in the hundreds, the total of physical, logical, and programmatic changes required constitutes a significant project involving plant components and systems, and substantial planning and resources.

Additionally, changes to CDAs and procedures must be integrated into the plant operational schedule including on-line operations, maintenance and testing, as well as planning and execution of refueling outages. With this analysis concluding in the second quarter of 2014, it is expected that insufficient time will remain in 2014 to conduct modification and change management planning activities and execution.

Planning is expected to occur in 2014 and implementation during the following 18 months. 3) A proposed completion date for Milestone 8 consistent with the remaining scope of work to be conducted and the resources available.

The licensee proposed a Milestone 8 completion date of June 30, 2016, and said this is based on designing and planning modifications in 2014 and installing them in 2015, with an additional contingency of 6 months. 4) An evaluation of the impact that the additional time to implement the requirements will have on the effectiveness of the licensee's overall cyber security program in the context of milestones already completed. The licensee indicated the impact of the requested additional implementation time on the effectiveness of the overall cyber security program is considered to be very low, because milestones 1-7 have already been completed and have resulted in a high degree of protection of safety-related, important-to-safety, and security CDAs against common threat vectors. Additionally, extensive physical and administrative measures are already in place for CDAs because they are plant components, pursuant to the Physical Security Plan and technical specification requirements.

The licensee provided details about the implementation of the various milestones.

5) A description of the licensee's methodology for prioritizing completion of work for critical digital assets associated with significant safety, security, or emergency preparedness consequences and with reactivity effects in the balance-of-plant.

The licensee stated that because CDAs are plant components, prioritization follows the normal work management process that places the highest priority on apparent conditions adverse to quality in system, structure, and component design function and related factors such as safety risk and nuclear defense-in-depth, as well as threats to continuity of electric power generation in the balance-of-plant.

This prioritization enabled completion of cyber security Interim Milestones 3 and 4 in 2012. Heightened attention is being maintained for any emergent issues with these CDAs that would potentially challenge the established cyber protective barriers.

6) A discussion of the licensee's cyber security program performance up to the date of the license amendment request. The licensee stated that there has been no identified compromise of safety, security, and emergency preparedness function by cyber means at any Entergy plant. A formal Quality Assurance (QA) audit was conducted in the fourth quarter of 2013 pursuant to the 24-month physical security program review required by 10 CFR 73.55(m).

The QA audit included review of cyber security program implementation.

There were no significant findings related to overall cyber security program performance and effectiveness.

7) A discussion of cyber security issues pending in the licensee's corrective action program. The licensee stated there are presently no significant (constituting a threat to a CDA via cyber means or calling into question program effectiveness) nuclear cyber security issues pending in the corrective action program (CAP). Several non-significant issues identified during the QA audit described above have been entered in the CAP for evaluation by the CSA T. The licensee also provided an example of cyber security issues in the CAP. 8) A discussion of modifications completed to support the cyber security program and a discussion of pending cyber security modifications.

The licensee provided a discussion of completed modifications and pending modifications. 3.2 NRC Staff Evaluation The NRC staff has evaluated the licensee's application using the regulatory requirements and the guidance above in Section 2.0 of this safety evaluation.

The NRC staff's evaluation is below. The licensee indicated that the milestones already completed have resulted in a high degree of protection of safety-related, important-to-safety, and security CDAs against threat vectors. The licensee detailed activities completed for each milestone.

The NRC staff finds that the licensee's site is much more secure after implementation of Milestones 1 through 7 because the activities the licensee completed mitigate the most significant cyber-attack vectors for the most significant CDAs. The licensee stated that there is insufficient time remaining in 2014 to complete the scope of actions required to fully implement its CSP (the cyber security assessment process).

The NRC staff recognizes that cyber security assessment work is much more complex and resource intensive than originally anticipated, in part due to the NRC expanding the scope of the cyber security requirements to include balance-of-plant.

As a result, the licensee has a large number of additional tasks not originally considered when developing its CSP implementation schedule.

The NRC staff concludes that the licensee's request for additional time to implement Milestone 8 is reasonable given the unanticipated complexity and scope of the remaining work required to fully implement its CSP. The licensee proposed a Milestone 8 completion date of June 30, 2016. The licensee stated that changing the completion date of Milestone 8 allows for designing and planning for security features to fully implement the security controls required by the CSP. It also allows for activities that require a refueling outage for implementation.

The licensee stated its methodology for prioritization of work for CDAs follows the normal work management process that places the highest priority on apparent conditions adverse to quality in system, structure, and component design function and related factors such as safety risk and nuclear defense-in-depth, as well as threats to continuity of electric power generation in the balance-of-plant.

The NRC staff concludes that based on the large number of digital assets described above and the limited resources with the appropriate expertise to perform these activities, the licensee's methodology for prioritizing work on CDAs is appropriate.

The NRC staff further concludes that the licensee's request to delay final implementation of the CSP until June 30, 2016, is reasonable given the complexity of the remaining unanticipated work and the need to perform certain work during the scheduled refueling outage. 3.3 Technical Evaluation Conclusion The NRC staff concludes that the licensee's request to delay full implementation of its CSP until June 30, 2016 is reasonable for the following reasons: (i) the licensee's implementation of Milestones 1 through 7 provides mitigation for significant cyber attack vectors for the most significant CDAs as discussed in the staff evaluation above; (ii) the scope of the work required to come into full compliance with the CSP implementation schedule was much more complicated than anticipated and not reasonably foreseeable when the CSP implementation scheduled was originally developed; and (iii) the licensee has reasonably prioritized and scheduled the work required to come into full compliance with its CSP implementation schedule.

Therefore, the NRC has reasonable assurance that full implementation of the CSP by June 30, 2016 will provide adequate protection of the public health and safety and the common defense and security.

3.4 Revision

to License Condition 2.E By letter dated August 4, 2014, the licensee proposed to modify Paragraph 2.E of FOL No. NPF-38 for WF3, which provides a license condition to require the licensee to fully implement and maintain in effect all provisions of the NRC-approved CSP. The license condition in Paragraph 2.E of FOL No. NPF-38 for WF3 is modified, in part, as follows: EOI shall fully implement and maintain in effect all provisions of the approved cyber security plan (CSP), including changes made pursuant to the authority of 10 CFR 50.90 and 10 CFR 50.54(p).

The EOI CSP was approved by License Amendment No. 234 and supplemented by a change approved by Amendment Nos. 239 and 241. 3.5 Regulatory Commitment In the letter dated August 4, 2014, Entergy made the following regulatory commitment, with a scheduled completion date of June 30, 2016: Full implementation of the Waterford 3 Cyber Security Plan for all safety, security, and emergency preparedness functions will be achieved.

4.0 STATE CONSULTATION

In accordance with the Commission's regulations, the Louisiana State official was notified on November 14, 2014, of the proposed issuance of the amendment.

The State official had no comments.

5.0 ENVIRONMENTAL

CONSIDERATION This amendment to a Part 50 license relates solely to safeguards matters and does not involve any significant construction impacts. This amendment is an administrative change to extend the date by which the licensee must have its cyber security plan fully implemented.

The Commission has previously issued a proposed finding that the amendment involves no significant hazards consideration, and there has been no public comment on such finding published in the Federal Register on October 7, 2014 (79 FR 60518). Accordingly, the amendment meets the eligibility criteria for categorical exclusion set forth in 10 CFR 51.22(c)(12).

Pursuant to 10 CFR 51.22(b), no environmental impact statement or environmental assessment need be prepared in connection with the issuance of the amendment.

6.0 CONCLUSION

The Commission has concluded, based on the considerations discussed above, that: (1) there is reasonable assurance that the health and safety of the public will not be endangered by operation in the proposed manner, (2) there is reasonable assurance that such activities will be conducted in compliance with the Commission's regulations, and (3) the issuance of the amendment will not be inimical to the common defense and security or to the health and safety of the public. Principal Contributor:

J. Rycyna Date: December 10, 2014 Vice President, Operations Entergy Operations, Inc. December 10, 2014 Waterford Steam Electric Station, Unit 3 17265 River Road Killona, LA 70057-3093

SUBJECT:

WATERFORD STEAM ELECTRIC STATION, UNIT 3-ISSUANCE OF AMENDMENT RE: MILESTONE 8 OF THE CYBER SECURITY PLAN (TAC NO. MF4675)

Dear Sir or Madam:

The Commission has issued the enclosed Amendment No. 241 to Facility Operating License No. NPF-38 for the Waterford Steam Electric Station, Unit 3 (WF3). This amendment consists of changes to the facility operating license in response to your application dated August 4, 2014. The amendment approves a change to the WF3 facility operating license to revise the date for implementation of Milestone 8 of the Cyber Security Plan (CSP) Implementation Schedule and the existing license conditions in the facility operating license. Milestone 8 of the CSP implementation schedule concerns the full implementation of the CSP. A copy of our related Safety Evaluation is also enclosed.

The Notice of Issuance will be included in the Commission's next biweekly Federal Register notice. Docket No. 50-382

Enclosures:

Sincerely, IRA/ Michael D Orenak, Project Manager Plant Licensing IV-2 and Decommissioning Transition Branch Division of Operating Reactor Licensing Office of Nuclear Reactor Regulation

1. Amendment No. 241 to NPF-38 2. Safety Evaluation cc w/encls: Distribution via Listserv DISTRIBUTION:

PUBLIC LPL4-2 r/f RidsAcrsAcnw_MaiiCTR Resource RidsNrrLAJBurkhardt Resource RidsNrrDorllpl4-2 Resource RidsNrrDoriDpr Resource RidsNrrPMWaterford Resource JRycyna, NSIR RidsRgn4MaiiCenter Resource RidsNrrLAPBiechman Resource RidsNsirOd Resource ADAMS Accession No ML 14321A713

  • via email OFFICE NRR/DORULPL4-2/PM NRR/DORLILPL4-2/PM NRR/DORULPL4-2/LA NRR/DORLILPL4-2/LA NAME MOrenak A Wang PBiechman JBurkhardt DATE 12/1/2014 12/1/2014 11/19/2014 11/21/2014 OFFICE NSIR/CSD/DD*

OGC NRR/DORLILPL4-2/BC N RR/DORL/LPL4-2/PM NAME RFelts SCiark-NLO* DBroaddus MOrenak DATE 11/5/2014 12/9/2014 12/10/2014 12/10/2014 OFFICIAL RECORD COPY