IR 05000266/2014403: Difference between revisions
StriderTol (talk | contribs) (Created page by program invented by StriderTol) |
StriderTol (talk | contribs) (Created page by program invented by StriderTol) |
||
| Line 3: | Line 3: | ||
| issue date = 10/23/2014 | | issue date = 10/23/2014 | ||
| title = Temporary Instruction 2201/004, Inspection of Implementation of Interim Cyber Security Milestones 1 - 7 Inspection Report 05000266/2014403; 05000301/2014403 - Cover Letter | | title = Temporary Instruction 2201/004, Inspection of Implementation of Interim Cyber Security Milestones 1 - 7 Inspection Report 05000266/2014403; 05000301/2014403 - Cover Letter | ||
| author name = Daley R | | author name = Daley R | ||
| author affiliation = NRC/RGN-III/DRS/EB3 | | author affiliation = NRC/RGN-III/DRS/EB3 | ||
| addressee name = | | addressee name = Mccartney E | ||
| addressee affiliation = NextEra Energy Point Beach, LLC | | addressee affiliation = NextEra Energy Point Beach, LLC | ||
| docket = 05000266, 05000301 | | docket = 05000266, 05000301 | ||
| Line 18: | Line 18: | ||
=Text= | =Text= | ||
{{#Wiki_filter:UNITED STATES NUCLEAR REGULATORY COMMISSION REGION III 2443 WARRENVILLE RD. SUIT E 210 LISLE, IL 60532 | {{#Wiki_filter:UNITED STATES NUCLEAR REGULATORY COMMISSION REGION III 2443 WARRENVILLE RD. SUIT E 210 LISLE, IL 60532-4352 October 23, 2014 | ||
-4352 October 23, 2014 | |||
Mr. Eric McCartney Site Vice President NextEra Energy Point Beach, LLC 6610 Nuclear Road Two Rivers, WI 54241 SUBJECT: POINT BEACH NUCLEAR PLANT, UNITS 1 AND 2 TEMPORARY INSTRUCTION 2201/004, "INSPECTION OF IMPLEMENTATION OF INTERIM CYBER SECURITY MILESTONES 1 - 7" INSPECTION REPORT 05000266/2014403; 05000301/2014403 | Mr. Eric McCartney Site Vice President NextEra Energy Point Beach, LLC 6610 Nuclear Road Two Rivers, WI 54241 SUBJECT: POINT BEACH NUCLEAR PLANT, UNITS 1 AND 2 TEMPORARY INSTRUCTION 2201/004, "INSPECTION OF IMPLEMENTATION OF INTERIM CYBER SECURITY MILESTONES 1 - 7" INSPECTION REPORT 05000266/2014403; 05000301/2014403 | ||
| Line 26: | Line 25: | ||
On October 6, 2014, the U.S. Nuclear Regulatory Commission (NRC) completed an inspection at your Point Beach Nuclear Plant, Units 1 and 2. The inspection covered the interim cyber security Milestones 1 - 7 of the security cornerstone. The enclosed inspection report documents the inspection results, which were discussed on October 6, 2014, with you and other members of your staff. The inspection examined activities conducted under your license as they relate to cyber security and compliance with the Commission's rules and regulations and with the conditions of your license. The inspectors reviewed selected procedures and records, observed activities, and interviewed personnel. | On October 6, 2014, the U.S. Nuclear Regulatory Commission (NRC) completed an inspection at your Point Beach Nuclear Plant, Units 1 and 2. The inspection covered the interim cyber security Milestones 1 - 7 of the security cornerstone. The enclosed inspection report documents the inspection results, which were discussed on October 6, 2014, with you and other members of your staff. The inspection examined activities conducted under your license as they relate to cyber security and compliance with the Commission's rules and regulations and with the conditions of your license. The inspectors reviewed selected procedures and records, observed activities, and interviewed personnel. | ||
No NRC-identified or self | No NRC-identified or self-revealing findings were identified during this inspection. However, one licensee-identified violation that was determined to be of very low significance (Green) is listed in Section 4OA7 of this report. The NRC is treating this violation as a Non-Cited Violation (NCV) consistent with Section 2.3.2 of the Enforcement Policy. | ||
-revealing findings were identified during this inspection. However, one licensee-identified violation that was determined to be of very low significance (Green) is listed in Section 4OA7 of this report. The NRC is treating this violation as a Non | |||
-Cited Violation (NCV) consistent with Section 2.3.2 of the Enforcement Policy. | |||
However, i n accordance with the Security Issues Forum (SIF) | However, i n accordance with the Security Issues Forum (SIF) | ||
Charter, the NRC may exercise enforcement discretion during inspection of the interim cyber security measures for licensees who demonstrate a "good | Charter, the NRC may exercise enforcement discretion during inspection of the interim cyber security measures for licensees who demonstrate a "good-faith interpretation and attempt to implement" Milestones 1 - 7. This discretion applies to licensees who have tried to implement the new requirements, but failed to be in full compliance. Before discretion is considered or granted for any issue, licensees must accept the finding, put the finding into their Corrective Action Program (CAP), and take appropriate corrective action once identified. | ||
-faith interpretation and attempt to implement" Milestones 1 - 7. This discretion applies to licensees who have tried to implement the new requirements, but failed to be in full compliance. Before discretion is considered or granted for any issue, licensees must accept the finding, put the finding into their Corrective Action Program (CAP), and take appropriate corrective action once identified. | |||
These issues were discussed and reviewed during the SIF Meeting conducted on October 1, 201 4. The results of the SIF Panel review concluded that although this issue constituted a violation of your facility operating license (FOL) and Title 10, Code of Federal Regulations (CFR), Part 73, Section 54, "Protection of Digital Computer and Communication Systems and Networks," the NRC is exercising enforcement discretion. The NRC is not taking enforcement action for these violations because they meet the criteria established in an NRC memorandum fromEnclosure contains Sensitive Unclassified Non | These issues were discussed and reviewed during the SIF Meeting conducted on October 1, 201 4. The results of the SIF Panel review concluded that although this issue constituted a violation of your facility operating license (FOL) and Title 10, Code of Federal Regulations (CFR), Part 73, Section 54, "Protection of Digital Computer and Communication Systems and Networks," the NRC is exercising enforcement discretion. The NRC is not taking enforcement action for these violations because they meet the criteria established in an NRC memorandum fromEnclosure contains Sensitive Unclassified Non-Safeguards Information. When separated from enclosure, this transmittal document is decontrolled. Barry C. Westreich, Director, Cyber Security Directorate, Office of Nuclear Security and Incident Response, to each regional office and Director, Division of Reactor Safety, Subject: | ||
-Safeguards Information. When separated from enclosure, this transmittal document is decontrolled. Barry C. Westreich, Director, Cyber Security Directorate, Office of Nuclear Security and Incident Response, to each regional office and Director, Division of Reactor Safety, Subject: | Enhanced Guidance for Licensee N ear-Term Corrective Actions to Address Cyber Security Inspection Findings and Licensee Eligibility for "Good-Faith" Attempt Discretion dated July 1, 2013, (ADAMS Accession Number ML13178A203). Consistent with the NRC Memorandum, upon completion of all corrective actions, you are requested to provide written notification to the NRC's regional office as to the method and date of closure for the identified issue(s). | ||
Enhanced Guidance for Licensee N ear-Term Corrective Actions to Address Cyber Security Inspection Findings and Licensee Eligibility for "Good | |||
-Faith" Attempt Discretion dated July 1, 2013, (ADAMS Accession Number ML13178A203). Consistent with the NRC Memorandum, upon completion of all corrective actions, you are requested to provide written notification to the NRC's regional office as to the method and date of closure for the identified issue(s). | |||
In accordance with Title 10, Code of Federal Regulations (CFR) "Rules of Practice," a copy of this letter will be available electronically for public inspection in the NRC Public Document Room or from the Publicly Available Records System (PARS) component of NRC's Agencywide Documents Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading | In accordance with Title 10, Code of Federal Regulations (CFR) "Rules of Practice," a copy of this letter will be available electronically for public inspection in the NRC Public Document Room or from the Publicly Available Records System (PARS) component of NRC's Agencywide Documents Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading-rm/adams.html (the Public Electronic Reading Room). However, the material enclosed herewith contains Security-Related Information in accordance with 10 CFR 2.390(d)(1) and its disclosure to unauthorized individuals could present a security vulnerability. Therefore, the material in the enclosure will not be made available electronically for public inspection in the NRC Public Document Room or from the PARS component of NRC's ADAMS. If you choose to provide a response and Security-Related Information is necessary to provide an acceptable response, please mark your entire response "Security-Related Information | ||
-rm/adams.html (the Public Electronic Reading Room). However, the material enclosed herewith contains Security | |||
-Related Information in accordance with 10 CFR 2.390(d)(1) and its disclosure to unauthorized individuals could present a security vulnerability. Therefore, the material in the enclosure will not be made available electronically for public inspection in the NRC Public Document Room or from the PARS component of NRC's ADAMS. If you choose to provide a response and Security | |||
-Related Information is necessary to provide an acceptable response, please mark your entire response "Security | |||
-Related Information | |||
- Withhold Under 10 CFR 2.390" in accordance with 10 CFR 2.390(d)(1) and follow the instructions for withholding in 10 CFR 2.390(b)(1). In accordance with 10 CFR 2.390(b)(1)(ii), the NRC is waiving the affidavit requirements for your response. | - Withhold Under 10 CFR 2.390" in accordance with 10 CFR 2.390(d)(1) and follow the instructions for withholding in 10 CFR 2.390(b)(1). In accordance with 10 CFR 2.390(b)(1)(ii), the NRC is waiving the affidavit requirements for your response. | ||
Sincerely, | Sincerely, | ||
/RA/ | /RA/ | ||
Robert C. Daley, Chief Engineering Branch 3 Division of Reactor Safety Docket Nos. 50 | Robert C. Daley, Chief Engineering Branch 3 Division of Reactor Safety Docket Nos. 50-266; 50-301 License Nos. DPR-24; DPR-27 Nonpublic Enclosure: | ||
-266; 50-301 License Nos. DPR | |||
-24; DPR-27 Nonpublic Enclosure: | |||
==Inspection Report== | ==Inspection Report== | ||
Revision as of 22:01, 18 August 2019
| ML14297A487 | |
| Person / Time | |
|---|---|
| Site: | Point Beach |
| Issue date: | 10/23/2014 |
| From: | Robert Daley Engineering Branch 3 |
| To: | Mccartney E Point Beach |
| Gregory Hansen | |
| References | |
| IR 2014403 | |
| Download: ML14297A487 (4) | |
Text
UNITED STATES NUCLEAR REGULATORY COMMISSION REGION III 2443 WARRENVILLE RD. SUIT E 210 LISLE, IL 60532-4352 October 23, 2014
Mr. Eric McCartney Site Vice President NextEra Energy Point Beach, LLC 6610 Nuclear Road Two Rivers, WI 54241 SUBJECT: POINT BEACH NUCLEAR PLANT, UNITS 1 AND 2 TEMPORARY INSTRUCTION 2201/004, "INSPECTION OF IMPLEMENTATION OF INTERIM CYBER SECURITY MILESTONES 1 - 7" INSPECTION REPORT 05000266/2014403; 05000301/2014403
Dear Mr. McCartney:
On October 6, 2014, the U.S. Nuclear Regulatory Commission (NRC) completed an inspection at your Point Beach Nuclear Plant, Units 1 and 2. The inspection covered the interim cyber security Milestones 1 - 7 of the security cornerstone. The enclosed inspection report documents the inspection results, which were discussed on October 6, 2014, with you and other members of your staff. The inspection examined activities conducted under your license as they relate to cyber security and compliance with the Commission's rules and regulations and with the conditions of your license. The inspectors reviewed selected procedures and records, observed activities, and interviewed personnel.
No NRC-identified or self-revealing findings were identified during this inspection. However, one licensee-identified violation that was determined to be of very low significance (Green) is listed in Section 4OA7 of this report. The NRC is treating this violation as a Non-Cited Violation (NCV) consistent with Section 2.3.2 of the Enforcement Policy.
However, i n accordance with the Security Issues Forum (SIF)
Charter, the NRC may exercise enforcement discretion during inspection of the interim cyber security measures for licensees who demonstrate a "good-faith interpretation and attempt to implement" Milestones 1 - 7. This discretion applies to licensees who have tried to implement the new requirements, but failed to be in full compliance. Before discretion is considered or granted for any issue, licensees must accept the finding, put the finding into their Corrective Action Program (CAP), and take appropriate corrective action once identified.
These issues were discussed and reviewed during the SIF Meeting conducted on October 1, 201 4. The results of the SIF Panel review concluded that although this issue constituted a violation of your facility operating license (FOL) and Title 10, Code of Federal Regulations (CFR), Part 73, Section 54, "Protection of Digital Computer and Communication Systems and Networks," the NRC is exercising enforcement discretion. The NRC is not taking enforcement action for these violations because they meet the criteria established in an NRC memorandum fromEnclosure contains Sensitive Unclassified Non-Safeguards Information. When separated from enclosure, this transmittal document is decontrolled. Barry C. Westreich, Director, Cyber Security Directorate, Office of Nuclear Security and Incident Response, to each regional office and Director, Division of Reactor Safety, Subject:
Enhanced Guidance for Licensee N ear-Term Corrective Actions to Address Cyber Security Inspection Findings and Licensee Eligibility for "Good-Faith" Attempt Discretion dated July 1, 2013, (ADAMS Accession Number ML13178A203). Consistent with the NRC Memorandum, upon completion of all corrective actions, you are requested to provide written notification to the NRC's regional office as to the method and date of closure for the identified issue(s).
In accordance with Title 10, Code of Federal Regulations (CFR) "Rules of Practice," a copy of this letter will be available electronically for public inspection in the NRC Public Document Room or from the Publicly Available Records System (PARS) component of NRC's Agencywide Documents Access and Management System (ADAMS). ADAMS is accessible from the NRC Web site at http://www.nrc.gov/reading-rm/adams.html (the Public Electronic Reading Room). However, the material enclosed herewith contains Security-Related Information in accordance with 10 CFR 2.390(d)(1) and its disclosure to unauthorized individuals could present a security vulnerability. Therefore, the material in the enclosure will not be made available electronically for public inspection in the NRC Public Document Room or from the PARS component of NRC's ADAMS. If you choose to provide a response and Security-Related Information is necessary to provide an acceptable response, please mark your entire response "Security-Related Information
- Withhold Under 10 CFR 2.390" in accordance with 10 CFR 2.390(d)(1) and follow the instructions for withholding in 10 CFR 2.390(b)(1). In accordance with 10 CFR 2.390(b)(1)(ii), the NRC is waiving the affidavit requirements for your response.
Sincerely,
/RA/
Robert C. Daley, Chief Engineering Branch 3 Division of Reactor Safety Docket Nos. 50-266; 50-301 License Nos. DPR-24; DPR-27 Nonpublic Enclosure:
Inspection Report
05000266/2014403; 05000301/2014403 w/Attachment: Supplemental Information cc w/encl:
B. Kopetsky, Point Beach Nuclear Plant Security Manager B. Westreich, NSIR R. Felts, NSIR S. Coker, NSIR J. Rogge, RI S. Shaeffer, RII J. Dixon, RIV N. Coleman, OE M. Millen, Licensing Manager M. Nazar, Executive Vice President, Nuclear Division and Chief Nuclear Officer cc w/o encl: Distribution via LISTSERV