IR 05000333/2015405: Difference between revisions

From kanterella
Jump to navigation Jump to search
(Created page by program invented by StriderTol)
(Created page by program invented by StriderTol)
 
(2 intermediate revisions by the same user not shown)
Line 3: Line 3:
| issue date = 04/08/2015
| issue date = 04/08/2015
| title = NRC Temporary Instruction 22011004, Inspection of Implementation of Interim Cyber Security Milestones 1 to 7, Report 05000333/2015405 (Letter Only)
| title = NRC Temporary Instruction 22011004, Inspection of Implementation of Interim Cyber Security Milestones 1 to 7, Report 05000333/2015405 (Letter Only)
| author name = Rogge J F
| author name = Rogge J
| author affiliation = NRC/RGN-I/DRS/EB3
| author affiliation = NRC/RGN-I/DRS/EB3
| addressee name = Sullivan B
| addressee name = Sullivan B
Line 18: Line 18:


=Text=
=Text=
{{#Wiki_filter:OFFICIA L USE ONLY UNITED STATES NUCLEAR REGULATORY COMMISSION REGION I 2100 RENAISSANCE BLVD., SUITE 100 KING OF PRUSSIA, PA 19406
{{#Wiki_filter:ril 8, 2015
-2713 April 8, 2015 Mr. Brian Sullivan Site Vice President Entergy Nuclear Northeast James A. FitzPatrick Nuclear Power Plant P. O. Box 110 Lycoming, NY SUBJECT: JAMES A. FITZPATRICK NUCLEAR POWER PLANT
 
- NRC TEMPORARY INSTRUCTION 2201/004, "INSPECTION OF IMPLEMENTATION OF INTERIM CYBER SECURITY MILESTONES 1
==SUBJECT:==
-7," REPORT 05000 333/201 540 5
JAMES A. FITZPATRICK NUCLEAR POWER PLANT - NRC TEMPORARY INSTRUCTION 2201/004, "INSPECTION OF IMPLEMENTATION OF INTERIM CYBER SECURITY MILESTONES 1-7," REPORT 05000333/2015405


==Dear Mr. Sullivan:==
==Dear Mr. Sullivan:==
On March 19, 2015, the U.S. Nuclear Regulatory Commission (NRC) completed a security temporary instruction inspection at your James A. FitzPatrick Nuclear Power Plant.
On March 19, 2015, the U.S. Nuclear Regulatory Commission (NRC) completed a security temporary instruction inspection at your James A. FitzPatrick Nuclear Power Plant. The inspection covered the implementation of interim milestones associated with your cyber security program, as outlined in your approved cyber security plan (CSP) and described in Temporary Instruction (TI) 2201/004, "Inspection of Implementation of Interim Cyber Security Milestones 1-7." The enclosed inspection report documents the inspection results, which were discussed on March 19, 2015, with Mr. Steve Vercelli and other members of your staff.


The inspection covered the implementation of interim milestones associated with your cyber security program, as outlined in your approved cyber security plan (CSP) and described in Temporary Instruction (TI) 2201/004, "Inspection of Implementation of Interim Cyber Security Milestones 1-7." The enclosed inspection report documents the inspection results, which were discuss ed on March 19, 2015, with Mr. Steve Vercelli and other members of your staff.
The inspection examined activities conducted under your license as they relate to safety and compliance with the Commissions rules and regulations and with the conditions of your license related to the implementation of interim cyber security milestones. The inspection was conducted in accordance with NRC TI 2201/004. The team reviewed selected procedures and records, observed activities, and interviewed personnel.


The inspection examined activities conducted under your license as they relate to safety and compliance with the Commission's rules and regulations and with the conditions of your license related to the implementation of interim cyber security milestones. The inspection was conducted in accordance with NRC TI 2201/004. The team reviewed selected procedures and records, observed activities, and interviewed personnel.
The report documents one violation for which the NRC is exercising enforcement discretion.


The report documents one violation for which the NRC is exercising enforcement discretion. The NRC is not taking enforcement action for th is violation because it meet s the criteria established in a n NRC Memorandum from Barry C. Westreich, Director, Cyber Security Directorate, Office of Nuclear Security and Incident Response, to each regional office and Director, Division of Reactor Safety, Subject: Enhanced Guidance for Licensee Near
The NRC is not taking enforcement action for this violation because it meets the criteria established in an NRC Memorandum from Barry C. Westreich, Director, Cyber Security Directorate, Office of Nuclear Security and Incident Response, to each regional office and Director, Division of Reactor Safety, Subject: Enhanced Guidance for Licensee Near-Term Corrective Actions to Address Cyber Security Inspection Findings and Licensee Eligibility for
-Term Corrective Actions to Address Cyber Security Inspection Findings and Licensee Eligibility for "Good-Faith" Attempt Discretion, dated July 1, 2013 (ADAMS Accession Number ML13178A203). Consistent with the NRC Memorandum, upon completion of all corrective actions, you are requested to provide written notification to the NRC's regional office as to the date of closure for the identified issues.
"Good-Faith" Attempt Discretion, dated July 1, 2013 (ADAMS Accession Number ML13178A203). Consistent with the NRC Memorandum, upon completion of all corrective actions, you are requested to provide written notification to the NRC's regional office as to the date of closure for the identified issues.


Enclosure contains Sensitive Unclassified Non-Safeguards Information. When separated from enclosure, the transmittal document is decontrolled. In accordance with Title 10 of the Code of Federal Regulation s (10 CFR) 2.390 of the NRC's  
Enclosure contains Sensitive Unclassified Non-Safeguards Information. When separated from enclosure, the transmittal document is decontrolled. In accordance with Title 10 of the Code of Federal Regulations (10 CFR) 2.390 of the NRC's
"Rules of Practice," a copy of this letter will be available electronically for public inspection in the NRC Public Document Room or from the Publicly Available Records (PARS) component of NRC's Agencywide Document Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading
"Rules of Practice," a copy of this letter will be available electronically for public inspection in the NRC Public Document Room or from the Publicly Available Records (PARS) component of NRC's Agencywide Document Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading-rm/adams.html (the Public Electronic Reading Room). However, the material enclosed herewith contains Security-Related Information in accordance with 10 CFR 2.390(d)(1) and its disclosure to unauthorized individuals could present a security vulnerability. Therefore, the material in the enclosure will not be made available electronically for public inspection in the NRC Public Document Room or from the PARS component of NRC's ADAMS. If you choose to provide a response and Security-Related Information is necessary to provide an acceptable response, please mark your entire response "Security-Related Information - Withhold From Public Disclosure Under 10 CFR 2.390" in accordance with 10 CFR 2.390(d)(1) and follow the instructions for withholding in 10 CFR 2.390 (b)(1). In accordance with 10 CFR 2.390(b)(1)(ii), the NRC is waiving the affidavit requirements for your response.
-rm/adams.html (the Public Electronic Reading Room). However, the material enclosed herewith contains Security
-Related Information in accordance with 10 CFR 2.390(d)(1) and its disclosure to unauthorized individuals could present a security vulnerability. Therefore, the material in the enclosure will not be made available electronically for public inspection in the NRC Public Document Room or from the PARS component of NRC's ADAMS. If you choose to provide a response and Security-Related Information is necessary to provide an acceptable response, please mark your entire response "Security-Related Information  
- Withhold From Public Disclosure Under 10 CFR 2.390" in accordance with 10 CFR 2.390(d)(1) and follow the instructions for withholding in 10 CFR 2.390 (b)(1). In accordance with 10 CFR 2.390(b)(1)(ii), the NRC is waiving the affidavit requirements for your response.


Sincerely,
Sincerely,
/RA/ John F. Rogge, Chief Engineering Branch 3 Division of Reactor Safety Docket No:
/RA/
50-333 License No:
John F. Rogge, Chief Engineering Branch 3 Division of Reactor Safety Docket No: 50-333 License No: DPR-59 Enclosure:
DPR-59 Enclosure:
Inspection Report 05000333/2015405 w/Attachment: Supplemental Information cc w/o encl: Distribution via ListServ cc w/encl; w/OUO-SRI T. Redfearn, Site Security Manager A. Peterson, State Liaison Office Designee, NY State Energy, Research and Development Authority ML15099A533(Cover letter)
 
==Inspection Report==
05000 333/201540 5 w/Attachment: Supplemental Information cc w/o encl: Distribution via ListServ
 
cc w/encl; w/OUO
-SRI T. Redfearn, Site Security Manager A. Peterson, State Liaison Office Designee, NY State Energy, Research and Development Authority  
 
ML15099A533(Cover letter)
ADAMS ACCESSION NUMBER: ML15099A536(Cover letter w/enclosure)
ADAMS ACCESSION NUMBER: ML15099A536(Cover letter w/enclosure)
Non-Public Designation Category: MD 3.4 Non
Non-Public Designation Category: MD 3.4 Non-Public A.3 Cover Letter   X Non-Sensitive   X Publicly Available SUNSI Review  Sensitive  Non-Publicly Available Cover Letter w/Enclosure Non-Sensitive   Publicly Available SUNSI Review  X Sensitive   X Non-Publicly Available OFFICE  RI/DRS RI/DRS NAME DOrr JRogge DATE 04/7/15 04/8/15 3 Distribution w/o encl; w/o OUO-SRI:
-Public A.3 Cover Letter SUNSI Review X Non-Sensitive Sensitive X Publicly Available Non-Publicly Available Cover Letter w/Enclosure SUNSI Review Non-Sensitive X Sensitive Publicly Available X Non-Publicly Available OFFIC E RI/DRS R I/DRS NAME DOrr JRogge DATE 0 4/7/1 5 0 4/8/1 5 3 Distribution w/o encl; w/o OUO
D. Dorman, RA (R1ORAMAIL RESOURCE)
-SRI: D. Dorman, RA (R1ORAMAIL RESOURCE)
D. Lew, DRA (R1ORAMAIL RESOURCE)
D. Lew, DRA (R1ORAMAIL RESOURCE)
H. Nieh, DRP (R1DRPMAIL RESOURCE)
H. Nieh, DRP (R1DRPMAIL RESOURCE)
M. Scott, DRP (R1DRPMAIL RESOURCE) R. Lorson, DRS (R1DRSMAIL RESOURCE) J. Trapp, DRS (R1DRSMAIL RESOURCE)
M. Scott, DRP (R1DRPMAIL RESOURCE)
A. Burritt, DRP T. Setzer, DRP J. Petch, DRP J. Schussler, DRP E. Knutson, DRP, SRI B. Sienel, DRP, RI M. Paulus, DRP, AA K. MorganButler, RI OEDO RidsNrrPMFitzPatrick Resource RidsNrrDorlLpl1
R. Lorson, DRS (R1DRSMAIL RESOURCE)
-1 Resource ROPreports Resource Distribution w/encl; w/OUO
J. Trapp, DRS (R1DRSMAIL RESOURCE)
-SRI: J. Willis, NSIR N. Simonian, NSIR E. Wharton, NSIR S. Shaeffer, DRS, RII R. Daley, DRS, RIII G. Werner, DRS, RIV A. Burritt, DRP E. Knutson, DRP, SRI
A. Burritt, DRP T. Setzer, DRP J. Petch, DRP J. Schussler, DRP E. Knutson, DRP, SRI B. Sienel, DRP, RI M. Paulus, DRP, AA K. MorganButler, RI OEDO RidsNrrPMFitzPatrick Resource RidsNrrDorlLpl1-1 Resource ROPreports Resource Distribution w/encl; w/OUO-SRI:
J. Willis, NSIR N. Simonian, NSIR E. Wharton, NSIR S. Shaeffer, DRS, RII R. Daley, DRS, RIII G. Werner, DRS, RIV A. Burritt, DRP E. Knutson, DRP, SRI
}}
}}

Latest revision as of 14:12, 31 October 2019

NRC Temporary Instruction 22011004, Inspection of Implementation of Interim Cyber Security Milestones 1 to 7, Report 05000333/2015405 (Letter Only)
ML15099A536
Person / Time
Site: FitzPatrick Constellation icon.png
Issue date: 04/08/2015
From: Rogge J
Engineering Region 1 Branch 3
To: Brian Sullivan
Entergy Nuclear Northeast
References
IR 2015405
Download: ML15099A536 (4)


Text

ril 8, 2015

SUBJECT:

JAMES A. FITZPATRICK NUCLEAR POWER PLANT - NRC TEMPORARY INSTRUCTION 2201/004, "INSPECTION OF IMPLEMENTATION OF INTERIM CYBER SECURITY MILESTONES 1-7," REPORT 05000333/2015405

Dear Mr. Sullivan:

On March 19, 2015, the U.S. Nuclear Regulatory Commission (NRC) completed a security temporary instruction inspection at your James A. FitzPatrick Nuclear Power Plant. The inspection covered the implementation of interim milestones associated with your cyber security program, as outlined in your approved cyber security plan (CSP) and described in Temporary Instruction (TI) 2201/004, "Inspection of Implementation of Interim Cyber Security Milestones 1-7." The enclosed inspection report documents the inspection results, which were discussed on March 19, 2015, with Mr. Steve Vercelli and other members of your staff.

The inspection examined activities conducted under your license as they relate to safety and compliance with the Commissions rules and regulations and with the conditions of your license related to the implementation of interim cyber security milestones. The inspection was conducted in accordance with NRC TI 2201/004. The team reviewed selected procedures and records, observed activities, and interviewed personnel.

The report documents one violation for which the NRC is exercising enforcement discretion.

The NRC is not taking enforcement action for this violation because it meets the criteria established in an NRC Memorandum from Barry C. Westreich, Director, Cyber Security Directorate, Office of Nuclear Security and Incident Response, to each regional office and Director, Division of Reactor Safety, Subject: Enhanced Guidance for Licensee Near-Term Corrective Actions to Address Cyber Security Inspection Findings and Licensee Eligibility for

"Good-Faith" Attempt Discretion, dated July 1, 2013 (ADAMS Accession Number ML13178A203). Consistent with the NRC Memorandum, upon completion of all corrective actions, you are requested to provide written notification to the NRC's regional office as to the date of closure for the identified issues.

Enclosure contains Sensitive Unclassified Non-Safeguards Information. When separated from enclosure, the transmittal document is decontrolled. In accordance with Title 10 of the Code of Federal Regulations (10 CFR) 2.390 of the NRC's

"Rules of Practice," a copy of this letter will be available electronically for public inspection in the NRC Public Document Room or from the Publicly Available Records (PARS) component of NRC's Agencywide Document Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading-rm/adams.html (the Public Electronic Reading Room). However, the material enclosed herewith contains Security-Related Information in accordance with 10 CFR 2.390(d)(1) and its disclosure to unauthorized individuals could present a security vulnerability. Therefore, the material in the enclosure will not be made available electronically for public inspection in the NRC Public Document Room or from the PARS component of NRC's ADAMS. If you choose to provide a response and Security-Related Information is necessary to provide an acceptable response, please mark your entire response "Security-Related Information - Withhold From Public Disclosure Under 10 CFR 2.390" in accordance with 10 CFR 2.390(d)(1) and follow the instructions for withholding in 10 CFR 2.390 (b)(1). In accordance with 10 CFR 2.390(b)(1)(ii), the NRC is waiving the affidavit requirements for your response.

Sincerely,

/RA/

John F. Rogge, Chief Engineering Branch 3 Division of Reactor Safety Docket No: 50-333 License No: DPR-59 Enclosure:

Inspection Report 05000333/2015405 w/Attachment: Supplemental Information cc w/o encl: Distribution via ListServ cc w/encl; w/OUO-SRI T. Redfearn, Site Security Manager A. Peterson, State Liaison Office Designee, NY State Energy, Research and Development Authority ML15099A533(Cover letter)

ADAMS ACCESSION NUMBER: ML15099A536(Cover letter w/enclosure)

Non-Public Designation Category: MD 3.4 Non-Public A.3 Cover Letter X Non-Sensitive X Publicly Available SUNSI Review Sensitive Non-Publicly Available Cover Letter w/Enclosure Non-Sensitive Publicly Available SUNSI Review X Sensitive X Non-Publicly Available OFFICE RI/DRS RI/DRS NAME DOrr JRogge DATE 04/7/15 04/8/15 3 Distribution w/o encl; w/o OUO-SRI:

D. Dorman, RA (R1ORAMAIL RESOURCE)

D. Lew, DRA (R1ORAMAIL RESOURCE)

H. Nieh, DRP (R1DRPMAIL RESOURCE)

M. Scott, DRP (R1DRPMAIL RESOURCE)

R. Lorson, DRS (R1DRSMAIL RESOURCE)

J. Trapp, DRS (R1DRSMAIL RESOURCE)

A. Burritt, DRP T. Setzer, DRP J. Petch, DRP J. Schussler, DRP E. Knutson, DRP, SRI B. Sienel, DRP, RI M. Paulus, DRP, AA K. MorganButler, RI OEDO RidsNrrPMFitzPatrick Resource RidsNrrDorlLpl1-1 Resource ROPreports Resource Distribution w/encl; w/OUO-SRI:

J. Willis, NSIR N. Simonian, NSIR E. Wharton, NSIR S. Shaeffer, DRS, RII R. Daley, DRS, RIII G. Werner, DRS, RIV A. Burritt, DRP E. Knutson, DRP, SRI