IR 05000341/2014403

From kanterella
Revision as of 16:42, 14 July 2019 by StriderTol (talk | contribs) (Created page by program invented by StriderTol)
Jump to navigation Jump to search
Temporary Instruction 2201/004, Inspection of Implementation of Interim Cyber Security Milestones 1-7, IR 05000341/2014403, Cover Letter Only
ML15016A396
Person / Time
Site: Fermi DTE Energy icon.png
Issue date: 01/15/2015
From: Robert Daley
Engineering Branch 3
To: Fessler P
DTE Electric Company
Stuart Sheldon
References
IR 2014403
Download: ML15016A396 (4)


Text

UNITED STATES NUCLEAR REGULATORY COMMISSION REGION III 2443 WARRENVILLE RD. SUIT E 210 LISLE, IL 60532-4352 January 15, 2015 Mr. Paul Fessler Chief Nuclear Officer DTE Electric Company Fermi 2 - 210 NOC 6400 North Dixie Highway Newport, MI 48166 SUBJECT: FERMI POWER PLANT, UNIT 2 TEMPORARY INSTRUCTION 2201/004, "INSPECTION OF IMPLEMENTATION OF INTERIM CYBER SECURITY MILESTONES 1

- 7" INSPECTION REPORT 050003 41/2 014403

Dear Mr. Fessler:

On December 5, 2014, the U.S. Nuclear Regulatory Commission (NRC) completed an inspection at your Fermi Power Plant, Unit 2. The inspection covered the interim cyber security Milestones 1

- 7 of the security cornerstone. The enclosed report documents the results of this inspection, which were discussed on December 5, 2014

, with you and other members of your staff. The inspection examined activities conducted under your license as they relate to cyber security and compliance with the Commission's rules and regulations and with the conditions of your license. The inspectors reviewed selected procedures and records, observed activities, and interviewed personnel.

Four NRC-identified finding s of very low significance (Green) were identified during this inspection. The findings were determined to involve violations of NRC requirements. The NRC is treating these violations as Non-Cited Violations (NCVs) consistent with Section 2.3.2 of the Enforcement Policy.

However, in accordance with the Security Issues Forum (SIF) Charter, the NRC may exercise enforcement discretion during inspection of the interim cyber security measures for licensees who demonstrate a "good-faith interpretation and attempt to implement" Milestones 1

- 7. This discretion applies to licensees who have tried to implement the new requirements, but failed to be in full compliance. Before discretion is considered or granted for any issue, licensees must accept the finding, put the finding into their Corrective Action Program (CAP), and take appropriate corrective action once identified.

These issues were discussed and reviewed during the SIF Meeting conducted on December 17 , 2014. The results of the SIF Panel review concluded that although these issue s constituted violations of your facility operating license (FOL) and Title 10, Code of Federal Regulations (CFR), Part 73, Section 54, "Protection of Digital Computer and Communication Systems and Networks," the NRC is not pursuing enforcement action because of your "good-faith" attempt to interpret and implement Milestones 1

- 7 and because of your prompt Enclosure contains Sensitive Unclassified Non-Safeguards Information. When separated from enclosure, this transmittal document is decontrolled. corrective actions to enter these issues into your CAP. Upon completion of all corrective actions, you are requested to provide written notification to the NRC's regional office as to the method and date of closure for the identified issue(s).

In accordance with Title 10 of the Code of Federal Regulations (10 CFR) 2.390, "Public Inspections, Exemptions, Requests for Withholding," of the NRC's

"Rules of Practice," a copy of this letter will be available electronically for public inspection in the NRC's Public Document Room or from the Publicly Available Records (PARS) component of the NRC's Agencywide Documents Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading-rm/adams.html (the Public Electronic Reading Room).

However, the material enclosed herewith contains Security-Related Information in accordance with 10 CFR 2.390(d)(1) and its disclosure to unauthorized individuals could present a security vulnerability. Therefore, the material in the enclosure will not be made available electronically for public inspection in the NRC Public Document Room or from the PARS component of NRC's ADAMS. If you choose to provide a response and Security-Related Information is necessary to provide an acceptable response, please mark your entire response "Security-Related Information - Withhold from public disclosure under 10 CFR 2.390" in accordance with 10 CFR 2.390(d)(1) and follow the instructions for withholding in 10 CFR 2.390(b)(1). In accordance with 10 CFR 2.390(b)(1)(ii), the NRC is waiving the affidavit requirements for your response.

Sincerely,

/RA Jasmine Gilliam Acting for/

Robert C. Daley, Chief Engineering Branch 3 Division of Reactor Safety Docket No.

50-3 41 License No.

NPF-43 Nonpublic Enclosure:

Inspection Report 05000341/2014403 w/Attachment: Supplemental Information cc w/encl: H. Torberg, Security Manager C. Pederson, RIII RA D. Roberts, RIII Deputy RA B. Westreich, NSIR R. Felts, NSIR S. Coker, NSIR J. Rogge, NSIR S. Shaeffer, RII N. Coleman, OE K. Yale, State Liaison Officer, State of Michigan cc w/o encl: Distribution via LISTSERV