Abstract:
We will discuss in this paper the regulation which specifies the minimum cyber security requirements across the public institutions [1], which includes as well civil NR operators. We will reflect the current state of cyber security in the nuclear and radiological domain from the legislative and technical perspective. We believe the approval of these requirements will lead to an increased level of cyber security at a national level, as well as will facilitate the NR regulation process in terms of cyber security aspects. The minimum cyber security requirements will also provide clear technical guidance for all entities, including the ones from the nuclear and radiological domain, in order to apply these controls within their infrastructure. In addition, the document contains requirements for security testing, design basis threat and inclusion of cyber security requirements in all processes in the organization. We will also refer to the approved Regulation on Physical Security on Nuclear and Radiological Activity [2], which takes into account the increasing cyber security role upon designing, maintenance, inspection and authorization processes of a physical security system for the NR operators.