Why emergency preparedness assets deserve a different lens.
As the landscape has matured within the nuclear (power generation) cybersecurity programs since full implementation (Milestone 8), there has been a shift in the approach of what “good” may look like. This has caused the industry’s focus to go beyond simply identifying Critical Digital Assets (CDAs) and setting up a compliant program, and instead look into refining a more risk informed manner. With our new industry OE, revised guidance documentation, and an approach that is leaning towards risk as opposed to the previous, exhaustive checklist, we are seeing a rebirth in some of the age-old mindsets in how our cyber programs begin to take shape. Today, one of the more nuanced challenges is determining when an Emergency Preparedness (EP) Digital Asset should remain in scope, or when an evaluation properly demonstrates whether or not it can be appropriately de-scoped. This distinction has become increasingly important as plants continue refining their processes under NEI 10-04, Revision 3.
While many utilities/fleets have an established CDA/EP grouping, program owners are now revisiting legacy determinations with a greater emphasis not only on technical capability and network connectivity, but more on regulatory intent and operational necessity. The key question is no longer simply, “Is this asset used by Emergency Preparedness?” Instead, it has become more a question of, “If this digital asset were unavailable or maliciously compromised during a declared emergency, could the Emergency Response Organization still perform its required function without adversely impacting compliance with 10 CFR 50.47(b)?” This subtle difference in approach fundamentally changes how assets should be evaluated.
-Emergency preparedness Is more than emergency response.
One of the most common misconceptions during CDA determination is favoring treating every Emergency Preparedness asset as inherently critical. Emergency Preparedness encompasses far more than activities performed during an actual event. These programs include planning, training, qualification management, documentation, corrective actions, drills, scheduling, and numerous administrative processes that enable readiness throughout the year.
Many of these systems certainly support the Emergency Preparedness program, but they may not be required to solely execute emergency response functions if an event actually occurs. We have seen similar approaches across the industry with many sites utilization of NEI 13-10 based on sole indication relevancy and primary versus secondary points of failure for necessary information. One example being most utilities’ allocation of the Plant Process Computer to an Indirect, Level 3 system following the Indirect allowance. Recognizing this particular distinction is often where sound digital and regulatory judgment begins.
-Start with the planning standards.
The sixteen Planning Standards contained in 10 CFR 50.47(b) establish the functional requirements every operating nuclear power plant must satisfy for emergency preparedness. These standards cover responsibilities such as:
- Emergency classification
- Notifications
- Communications
- Dose assessment
- Protective actions
- Emergency facilities
- Recovery planning
- Training
- Exercises
- Program maintenance
Rather than beginning with the technology itself, the system owners should first determine which Planning Standard(s), if any, the asset actually supports. If the answer is “none”, the asset is frequently administrative in nature and may warrant further evaluation as a potential candidate for descoping. If the answer is one or more standards, then the evaluation continues, not automatically toward retaining CDA status, but toward understanding how that asset contributes to the required function.
-The importance of functional dependency.
Not every system supporting an Emergency Preparedness function is indispensable. For example, an electronic training database may maintain qualification records for Emergency Response Organization (ERO) personnel. While important for program administration, losing access to that database during an emergency does not necessarily prevent qualified personnel from responding IF alternate methods already exist.
Conversely, systems supporting:
- Emergency classification
- Emergency notifications
- Dose assessment
- Protective Action Recommendation (PAR) generation
- Emergency communications
- Personnel accountability
are often much more difficult to justify for descoping because they DIRECTLY support emergency response activities. The evaluation process therefore becomes one of operational dependency, not organizational ownership.
-Secondary/alternate methods are key.
One of the strongest themes throughout NEI 10-04 Revision 3 is resiliency. A digital asset should rarely be viewed in isolation. Instead, one should ask whether the required Emergency Preparedness function can still be completed using an adequately independent secondary or alternate method.
Examples may include:
- Established manual procedures
- Administrative processes
- Analog equipment
- Independent digital systems
- Paper documentation
- Alternate communications methods
Just as importantly, these alternate methods cannot simply exist on paper.
They should be:
- Formally documented
- Incorporated into approved procedures
- Routinely maintained
- Supported through personnel training
Without these elements, an alternate method becomes difficult to defend during both cybersecurity reviews and NRC inspections.
-Cybersecurity is about consequence.
The increased focus across modern regulation is consequence and risk-based evaluation. For Emergency Preparedness assets, the question is not whether compromise is possible, as that is a forever-present threat. The question is, “what operational consequence results if compromise occurs?”. An evaluation should demonstrate that compromise of the digital asset does not prevent the licensee from satisfying required Emergency Preparedness functions found in the previously mentioned 10 CFR 50.47(b). Similarly, it necessitates verification that the asset cannot provide an exploitable cyber pathway into safety, security, or other in-scope Critical Digital Assets. This systems-level perspective is often what differentiates a well-supported engineering evaluation from a simple checklist exercise.
-Administrative does not mean automatic.
Many organizations maintain long lists of systems that appear to be administrative in nature:
- Training records
- Scheduling software
- SharePoint sites
- Exercise planning
- Budget tracking
- Document repositories
- Personnel databases
- Historical archives
While these frequently become strong descoping candidates, administrative ownership alone should never determine scope.
Each asset still deserves an evaluation that considers:
- Operational use
- Interconnectivity
- Alternate methodology
- Cyber pathways
- Detection capability
- Emergency Response Dependency
Only then can a technically defensible decision be reached.
A practical rule of thumb.
Perhaps the simplest question SMEs could ask during an Emergency Preparedness asset review is, “If this digital asset became unavailable during a declared emergency, could trained responders successfully perform the required Emergency Preparedness function using documented, independent alternate methods without reducing the required compliance”?
1. If the answer is yes—and supporting engineering evidence exists—the asset may be an appropriate descoping candidate.
2. If the answer is no, the asset likely remains integral to Emergency Preparedness capability and should continue through CDA evaluation.
-Final thoughts.
As nuclear cybersecurity programs continue to mature, successful CDA evaluations increasingly depend less on checklists and more on disciplined judgment. Emergency Preparedness systems represent one of the best examples of this evolution. Determining scope requires understanding regulatory intent, operational dependency, cyber architecture, alternate methods, and emergency response capability, NOT simply identifying whether a system belongs to Emergency Preparedness department.
Organizations that consistently apply this consequence-based approach will not only strengthen the technical quality of their engineering evaluations but also improve consistency during inspections, reduce unnecessary regulatory burden, and better align their cybersecurity programs with the underlying intent of NEI 10-04 Revision 3. In today’s regulatory environment, rationale that can withstand scrutiny is every bit as important as technical implementation, and nowhere is that more evident than in Emergency Preparedness cybersecurity evaluations.
-Daniel Pope
Manager of Operations at Cyber Realm Solutions