Power Reactor Security Requirements

Federal RegisterMar 27, 2009

Ask Donna

What actually matters in this document.

Text

NUCLEAR REGULATORY COMMISSION

10 CFR Parts 50, 52, 72, and 73

[NRC-2008-0019]

RIN 3150-AG63

Power Reactor Security Requirements

AGENCY:

Nuclear Regulatory Commission.

ACTION:

Final rule.

SUMMARY:

The Nuclear Regulatory Commission (NRC) is amending its security regulations and adding new security requirements pertaining to nuclear power reactors. This rulemaking establishes and updates generically applicable security requirements similar to those previously imposed by Commission orders issued after the terrorist attacks of September 11, 2001. Additionally, this rulemaking adds several new requirements not derived directly from the security order requirements but developed as a result of insights gained from implementation of the security orders, review of site security plans, implementation of the enhanced baseline inspection program, and NRC evaluation of force-on-force exercises. This rulemaking also updates the NRC's security regulatory framework for the licensing of new nuclear power plants. Finally, it resolves three petitions for rulemaking (PRM) that were considered during the development of the final rule.

DATES:

Effective Date:

This final rule is effective on May 26, 2009.

Compliance Date:

Compliance with this final rule is required by March 31, 2010, for licensees currently licensed to operate under 10 CFR Part 50.

ADDRESSES:

You can access publicly available documents related to this document using the following methods:

Federal e-Rulemaking Portal:

Go to

http://www.regulations.gov

and search for documents filed under Docket ID [NRC-2008-0019]. Address questions about NRC Dockets to Carol Gallagher at 301-492-3668; e-mail

Carol.Gallagher@nrc.gov.

NRC's Public Document Room (PDR):

The public may examine and have copied for a fee publicly available documents at the NRC's PDR, Public File Area O1 F21, One White Flint North, 11555 Rockville Pike, Rockville, Maryland.

NRC's Agency Wide Documents Access and Management System (ADAMS):

Publicly available documents created or received at the NRC are available electronically at the NRC's Electronic Reading Room at

http://www.nrc.gov/reading-rm/adams.html.

From this page, the public can gain entry into ADAMS, which provides text and image files of the NRC's public documents. If you do not have access to ADAMS or if there are problems in accessing the documents located in ADAMS, contact the NRC's PDR reference staff at 1-800-397-4209, 301-415-4737 or by e-mail to

pdr.resource@nrc.gov.

FOR FURTHER INFORMATION CONTACT:

Ms. Bonnie Schnetzler, Office of Nuclear Security and Incident Response, U.S. Nuclear Regulatory Commission, Washington, DC 20555-0001; telephone 301-415-7883; e-mail:

Bonnie.Schnetzler@nrc.gov,

or Mr. Timothy Reed, Office of Nuclear Reactor Regulation, U.S. Nuclear Regulatory Commission, Washington, DC 20555-0001; telephone 301-415-1462; e-mail:

Timothy.Reed@nrc.gov.

SUPPLEMENTARY INFORMATION:

I. Background

II. Petitions for Rulemaking

III. Discussion of Substantive Changes and Responses to Significant Comments

IV. Section-by-Section Analysis

V. Guidance

VI. Criminal Penalties

VII. Availability of Documents

VIII. Voluntary Consensus Standards

IX. Finding of No Significant Environmental Impact

X. Paperwork Reduction Act Statement

XI. Regulatory Analysis

XII. Regulatory Flexibility Certification

XIII. Backfit Analysis

XIV. Congressional Review Act

I. Background

A. Historical Background and Overview

Following the terrorist attacks on September 11, 2001, the Commission issued a series of orders to ensure that nuclear power plants and other licensed facilities continued to have effective security measures in place given the changing threat environment. Through these orders, the Commission supplemented the design basis threat (DBT) as well as mandated specific training enhancements, access authorization enhancements, and enhancements to defensive strategies, mitigative measures, and integrated response. Additionally, through generic communications, the Commission specified expectations for enhanced notifications to the NRC for certain security events or suspicious activities. The four following security orders were issued to licensees:

• EA-02-026, “Interim Compensatory Measures (ICM) Order,” issued February 25, 2002 (March 4, 2002; 67 FR 9792);

• EA-02-261, “Access Authorization Order,” issued January 7, 2003 (January 13, 2003; 68 FR 1643);

• EA-03-039, “Security Personnel Training and Qualification Requirements (Training) Order,” issued April 29, 2003, (May 7, 2003; 68 FR 24514); and

• EA-03-086, “Revised Design Basis Threat Order,” issued April 29, 2003, (May 7, 2003; 68 FR 24517).

Nuclear power plant licensees revised their physical security plans, access authorization programs, training and qualification plans, and safeguards contingency plans in response to these orders. The Commission completed its review and approval of the revised security plans on October 29, 2004. These plans incorporated the enhancements required by the orders. While the specifics of these enhancements are protected as Safeguards Information consistent with 10 CFR 73.21, the enhancements resulted in measures such as increased patrols; augmented security forces and capabilities; additional security posts; additional physical barriers; vehicle checks at greater standoff distances; enhanced coordination with law enforcement authorities; augmented security and emergency response training, equipment, and communication; and more restrictive site access controls for personnel including expanded, expedited, and more thorough employee background investigations.

The Energy Policy Act of 2005 (EPAct 2005), signed into law on August 8, 2005, contained several provisions relevant to security at nuclear power plants. Section 653, for instance, added Section 161A. to the Atomic Energy Act of 1954, as amended (AEA). This provision allows the Commission to authorize certain licensees to use, as part of their protective strategies, an expanded arsenal of weapons including machine guns and semi-automatic assault weapons. Section 653 also requires certain security personnel to undergo a background check that includes fingerprinting and a check against the Federal Bureau of Investigation's (FBI) National Instant Criminal Background Check System (NICS) database. Section 161A, however, is not effective until guidelines are completed by the Commission and approved by the Attorney General. More information on the NRC's implementation of Section 161A can be found below.

B. The Proposed Rule

As noted to recipients of the post-September 11, 2001, orders, it was

always the Commission's intent to complete a thorough review of the existing physical protection program requirements and undertake a rulemaking that would codify generically-applicable security requirements. This rulemaking would be informed by the requirements previously issued by orders and includes an update of existing power reactor security requirements, which had not been significantly revised for nearly 30 years. To that end, on October 26, 2006, the Commission issued the proposed Power Reactor Security rulemaking (71 FR 62663). The proposed rule was originally published for a 75-day public comment period. In response to several requests for extension, the comment period was extended on two separate occasions (January 5, 2005; 72 FR 480; and February 28, 2007; 72 FR 8951), eventually closing on March 26, 2007. The Commission received 48 comment letters. In addition, the Commission held two public meetings to solicit public comment in Rockville, MD on November 15, 2006, and Las Vegas, NV on November 29, 2006. The Commission held a third public meeting in Rockville, MD, on March 9, 2007, to facilitate stakeholder understanding of the proposed requirements, and thereby result in more informed comments on the proposed rule provisions.

In addition to proposing requirements that were similar to those that had previously been imposed by the various orders, the proposed rule also contained several new provisions that the Commission determined would provide additional assurance of licensee capabilities to protect against the DBT. These new provisions were identified by the Commission during implementation of the security orders while reviewing the revised site security plans that had been submitted by licensees for Commission review and approval, while conducting the enhanced baseline inspection program, and through evaluation of the results of force-on-force exercises. As identified in the proposed rule, these new provisions included such measures as cyber security requirements, safety/security interface reviews, functional equivalency of the central and secondary alarm stations, uninterruptable backup power for detection and assessment equipment, and video image recording equipment (See 71 FR 62666-62667; October 26, 2006).

The Commission also published a supplemental proposed rule on April 10, 2008, (73 FR 19443) seeking additional stakeholder comment on two provisions of the rule for which the Commission had decided to provide additional detail. The supplemental proposed rule also proposed to move these requirements from appendix C to part 73 in the proposed rule to § 50.54 in the final rule. More detail on those provisions and the comments received is provided in section III of this document.

Three petitions for rulemaking (PRM) (PRM-50-80, PRM-73-11, PRM-73-13) were also considered as part of this rulemaking. Consideration of these petitions is discussed in detail in section II of this document.

C. Significant New Requirements in the Final Rule

This final rulemaking amends the security requirements for power reactors. The following existing sections and appendices in 10 CFR Part 73 have been revised as a result:

• 10 CFR 73.55, Requirements for physical protection of licensed activities in nuclear power reactors against radiological sabotage.

• 10 CFR 73.56, Personnel access authorization requirements for nuclear power plants.

• 10 CFR Part 73, appendix B, section VI, Nuclear Power Reactor Training and Qualification Plan for Personnel Performing Security Program Duties.

• 10 CFR Part 73, appendix C, Licensee Safeguards Contingency Plans.

The amendments also add two new sections to part 73 and a new paragraph to 10 CFR Part 50:

• 10 CFR 73.54, Protection of digital computer and communication systems and networks (

i.e.

, cyber security requirements).

• 10 CFR 73.58, Safety/security interface requirements for nuclear power reactors.

• 10 CFR 50.54(hh), Mitigative strategies and response procedures for potential or actual aircraft attacks.

Specifically, this rulemaking contains a number of significant new requirements listed as follows:

Safety/Security Interface Requirements.

These requirements are located in new § 73.58. The safety/security interface requirements explicitly require licensees to manage and assess the potential conflicts between security activities and other plant activities that could compromise either plant security or plant safety. The requirements direct licensees to assess and manage these interactions so that neither safety nor security is compromised. These requirements address, in part, PRM-50-80, which requested the establishment of regulations governing proposed changes to the facilities which could adversely affect the protection against radiological sabotage.

Mixed-Oxide (MOX) Fuel Requirements.

These requirements are codified into new § 73.55(l) for reactor licensees who propose to use MOX fuel in concentrations of 20 percent or less. These requirements provide enhancements to the normal radiological sabotage-based physical security requirements by adding the requirement that the MOX fuel be protected from theft or diversion. These requirements reflect the Commission's view that the application of security requirements for the protection of formula quantities of strategic special nuclear material set forth in Part 73, which would otherwise apply because of the MOX fuel's plutonium content, is, in part, unnecessary to provide adequate protection for this material because of the weight and size of the MOX fuel assemblies. The MOX fuel security requirements are consistent with the approach implemented at Catawba Nuclear Station through the MOX lead test assembly effort in 2004-2005.

Cyber Security Requirements.

These requirements are codified as new § 73.54 and designed to provide high assurance that digital computer and communication systems and networks are adequately protected against cyber attacks up to and including the design basis threat as established by § 73.1(a)(1)(v). These requirements are substantial improvements upon the requirements imposed by the February 25, 2002 order. In addition to requiring that all new applications for an operating or combined license include a cyber security plan, the rule will also require currently operating licensees to submit a cyber security plan to the Commission for review and approval by way of license amendment pursuant to § 50.90 within 180 days of the effective date of this final rule. In addition, applicants who have submitted an application for an operating license or combined license currently under review by the Commission must amend their applications to include a cyber security plan. For both current and new licensees, the cyber security plan will become part of the licensee's licensing basis in the same manner as other security plans.

Mitigative Strategies and Response Procedures for Potential or Actual Aircraft Attacks.

These requirements appear in new § 50.54(hh). Section 50.54(hh)(1) establishes the necessary regulatory framework to facilitate consistent application of Commission requirements for preparatory actions to be taken in the event of a potential or

actual aircraft attack and mitigation strategies for loss of large areas due to fire and explosions. Section 50.54(hh)(2) requires licensees to develop guidance and strategies for addressing the loss of large areas of the plant due to explosions or fires from a beyond-design basis event through the use of readily available resources and identification of potential practicable areas for the use of beyond-readily-available resources. Requirements similar to these were previously imposed under section B.5 of the February 25, 2002, ICM order; specifically, the “B.5.a” and the “B.5.b” provisions.

Access Authorization Enhancements.

Section 73.56 has been substantially revised to incorporate lessons learned from the Commission's implementation of the January 7, 2003 order requirements and to improve the integration of the access authorization and security program requirements. The final rule includes an increase in the rigor for many elements of the pre-existing access authorization program requirements. In addition, the access authorization requirements include new requirements for individuals who have electronic means to adversely impact facility safety, security, or emergency preparedness; enhancements to the psychological assessments requirements; requires information sharing between reactor licensees; expanded behavioral observation requirements; requirements for reinvestigations of criminal and credit history records for all individuals with unescorted access; and 5-year psychological reassessments for certain critical job functions.

Training and Qualification Enhancements.

These requirements are set forth in appendix B to part 73 and include modifications to training and qualification program requirements based on insights gained from implementation of the security orders, Commission reviews of site security plans, implementation of the enhanced baseline inspection program, and insights gained from evaluations of force-on-force exercises. These new requirements include additional requirements for unarmed security personnel to assure these personnel meet minimum physical requirements commensurate with their duties. The new requirements also include a minimum age requirement of 18 years for unarmed security officers, enhanced minimal qualification scores for testing required by the training and qualification plan, enhanced qualification requirements for security trainers, armorer certification requirements, program requirements for on-the-job training, and qualification requirements for drill and exercise controllers.

Physical Security Enhancements.

The rule imposes new physical security enhancements in the revised § 73.55 that were identified by the Commission during implementation of the security orders, reviews of site security plans, implementation of the enhanced baseline inspection program, and NRC evaluations of force-on-force exercises. Significant new requirements in § 73.55 include a requirement that the central alarm station (CAS) and secondary alarm station (SAS) have functionally equivalent capabilities so that no single act in accordance with the design basis threat of radiological sabotage could disable the key functions of both CAS and SAS. Additions also include requirements for new reactor licensees to locate the SAS within a site's protected area, ensure that the SAS is bullet resistant, and limit visibility into the SAS from the perimeter of the protected area. Revisions to § 73.55 also include requiring uninterruptible backup power supplies for detection and assessment equipment, video image recording capability, and new requirements for protection of the facility against waterborne vehicles.

D. Significant Changes in the Final Rule

A number of significant changes were made to the proposed rule as a result of public comments, and they are now reflected in the final rule. Those changes are outlined as follows:

Separation of Enhanced Weapons and Firearms Background Check Requirements.

As noted previously, Section 161A of the AEA permits the Commission to authorize the use of certain enhanced weapons in the protective strategies of certain designated licensees once guidelines are developed by the Commission and approved by the Attorney General. In anticipation of the completion of those guidelines and the Attorney General's approval, the Commission had included in the proposed rule several provisions that would implement its proposed requirements concerning application for and approval of the use of enhanced weapons and firearms background checks. However, because the guidelines had not yet received the approval of the Attorney General as the final rule was submitted to the Commission, the Commission decided to address that portion of the proposed rule in a separate rulemaking. Once the final guidelines are approved by the Attorney General and published in the

Federal Register

, the Commission will take appropriate action to codify the Section 161A. authorities.

Cyber Security Requirements.

Another change to this final rulemaking is the relocation of cyber security requirements. Cyber security requirements had been located in the proposed rule in § 73.55(m). These requirements are now placed in new § 73.54 as a separate section within part 73. These requirements were placed in a stand-alone section to enable the cyber security requirements to be made applicable to other types of facilities and applications through future rulemakings.

Establishing these requirements as a stand-alone section also necessitated creating accompanying licensing requirements. Because the cyber security requirements were originally proposed as part of the physical security program and thus the physical security plan, a licensee's cyber security plan under the proposed rule would have been part of the license through that licensing document. Once these requirements were separated from proposed § 73.55, the Commission identified the need to establish separate licensing requirements for the licensee's cyber security plan that would require the plan to be part of a new application for a license issued under part 50 or part 52, as well as continue to be a condition of either type of license. Conforming changes were therefore made to sections §§ 50.34, 50.54, 52.79, and 52.80 to address this consideration. As noted previously and in § 73.54, for current reactor licensees, the rule requires the submission of a new cyber security plan to the Commission for review and approval within 180 days of the effective date of the final rule. Current licensees are required to submit their cyber security plans by way of a license amendment pursuant to 10 CFR § 50.90. In addition, applicants for an operating license or combined license who have submitted their applications to the Commission prior to the effective date of the rule are required to amend their applications to the extent necessary to address the requirements of § 73.54.

Performance Evaluation Program Requirements.

The Performance Evaluation Program requirements that were in proposed appendix C to part 73, are moved in their entirety to appendix B to part 73 as these requirements describe the development and implementation of a training program for training the security force in the response to contingency events.

Mitigative Strategies and Response Procedures for Potential or Actual Aircraft Attacks.

Another significant change to this rulemaking is the

relocation of and the addition of clarifying rule language to the beyond-design basis mitigative measures and potential aircraft threat notification requirements that were previously located in proposed part 73, appendix C. Those requirements are now set forth in 10 CFR 50.54(hh). This change was made, in part, in response to stakeholder comments that part 73, appendix C, was not the appropriate location for these requirements because the requirements were not specific to the licensee's security organization. The Commission agreed and relocated the requirements accordingly and provided more details to the final rule language to ensure that the intent of these requirements is clear. As noted previously, the Commission issued a supplemental proposed rule seeking additional stakeholder comment on these proposed changes to the rule. More detail on this provision is provided in Section III of this document.

Section 73.71 and Appendix G to Part 73.

The proposed power reactor security rulemaking contained proposed requirements for § 73.71 and appendix G to part 73. Based on public comments, the Commission intended to make few changes to these regulations. However, these provisions are not contained in this final rulemaking. Because the enhanced weapons rulemaking (discussed previously) will include potential changes to § 73.71 and appendix G to part 73, the Commission decided that revisions to these regulations were better suited for that rulemaking.

Security Plan Submittal Requirements.

The proposed rule would have required current licensees to revise their physical security plan, training and qualification plans, and safeguards contingency plan to incorporate the new requirements and to submit these security plans for Commission review and approval. The final rule no longer requires these security plans (with the exception of the cyber security plan as discussed previously) to be submitted for prior Commission review and approval and instead allows licensees to make changes in accordance with existing licensing provisions such as § 50.54(p) or § 50.90, as applicable. The Commission determined that this was an acceptable approach because most of the requirements established by this rule are substantially similar to the requirements that had been imposed by the security orders and because all licensee security plans were recently reviewed and approved by the Commission in 2004 following issuance of those orders. Additionally, many of the additional requirements in the final rule are already current practices that were implemented following an industry-developed, generic, security plan template that was reviewed and approved by the Commission. For the requirements that go beyond current practices, the Commission does not expect that changes required by this rule would result in a decrease of effectiveness in a licensee's security plan. For implementation of those new requirements, licensees should, therefore, consider whether their plans could be revised in accordance with the procedures described in § 50.54(p). However, if a licensee believes that a plan change may reduce the effectiveness of a security plan or if the licensee desires Commission review and approval of the plan change, then the proposed plan revision should be submitted to the NRC for review and approval as a license amendment per § 50.90.

With respect to applicants who have already submitted an application to the Commission for an operating license or combined license as of the effective date of this rule, those applicants are required by this rule to amend their applications to the extent necessary to address the requirements of the new rule.

Implementation of the Final Rule.

The final rule is effective 30 days following date of publication. This permits applicability of the rule's requirements to new reactor applicants at the earliest possible date. Current licensees are required to be in compliance with the rule requirements by March 31, 2010.

Definitions.

The proposed rule contained a number of definitions, primarily related to the proposed enhanced weapons requirements. As noted previously, the enhanced weapons provisions and firearms backgrounds checks have been separated into a separate rulemaking so codifying those definitions is no longer appropriate in this rulemaking. Regarding the other proposed rule definitions of safety/security interface, security officer, and target sets, these terms are addressed in guidance, and accordingly the final rule does not contain these definitions.

EPAct 2005 Provisions.

As noted above, the proposed rule contained a number of proposed requirements that were designed to address security-related provisions of the EPAct 2005. With respect to Section 653 of the EPAct 2005, enhanced weapons and firearms background check requirements have been moved to a separate rulemaking. The only other provisions of the EPAct 2005 that the Commission had considered during this rulemaking were in Section 651, which concerns matters related to the triennial Commission-evaluated, force-on-force exercises, the NRC's mitigation of potential conflicts of interest in the conduct of such exercises, and the submission of annual reports by the NRC to Congress. Because the statute requires the NRC to be directly responsible for implementation of those requirements, the Commission has determined that there is no need for them to be specifically reflected in the NRC's regulations. The NRC has fully complied with all of the requirements of Section 651 in its conduct of force-on-force evaluations since the EPAct 2005, and has submitted three annual reports to Congress during that time. Further discussion of and the Commission's response to a comment on this issue are provided below in Section III.

E. Conforming and Corrective Changes

Conforming changes to the requirements listed below are made to ensure that cross-referencing between the various security regulations in part 73 is preserved, implement cyber security plan submittal requirements, and preserve requirements for licensees who are not within the scope of this final rule. The following requirements contain conforming changes:

• Section 50.34, “Contents of construction permit and operating license applications; technical information,” is revised to align the application requirements with appendix B to 10 CFR part 73, the addition of § 73.54 to part 73, and the addition of § 50.54(hh) to part 50.

• Section 50.54, “Conditions of licenses,” is revised to conform with the revisions to sections in appendix C to 10 CFR Part 73. In accordance with the introductory text to § 50.54, revisions to this section are also made applicable to combined licenses issued under part 52.

• Section 52.79, “Contents of applications; technical information in the final safety analysis report,” is revised to align the application requirements with the revisions to appendix C to 10 CFR Part 73 and the addition of § 73.54 to Part 73.

• Section 52.80, “Contents of applications; additional technical information,” is revised to add the application requirements for § 50.54(hh) to part 50.

• Section 72.212, “Conditions of general license issued under § 72.210,” is revised to reference the appropriate revised paragraph designations in § 73.55.

• Section 73.8, “Information collection requirements: OMB approval,” is revised to add the new

requirements (§§ 73.54 and 73.58) to the list of sections with Office of Management and Budget (OMB) information collection requirements. A corrective revision to § 73.8 is made to reflect OMB approval of existing information collection requirements for NRC Form 366 under existing § 73.71.

• Section 73.70, “Records,” is revised to reference the appropriate revised paragraph designations in § 73.55 regarding the need to retain a record of the registry of visitors.

Additionally, § 73.81, “Criminal penalties,” which sets forth the sections within part 73 that are not subject to criminal sanctions under the AEA, remains unchanged because willful violations of the new §§ 73.54 and 73.58 may be subject to criminal sanctions.

Appendix B to part 73 and appendix C to part 73 require special treatment in this final rule to preserve, with a minimum of conforming changes, the current requirements for licensees and applicants who are not within the scope of this final rule, such as Category I strategic special nuclear material licensees and research and test reactor licensees. Accordingly, Sections I through V of appendix B to part 73 remain unchanged to preserve the current training and qualification requirements for all applicants, licensees, and certificate holders who are not within the scope of this final rule, and the new language for power reactor security training and qualification (revised in this final rule) is added as Section VI. Part 73, appendix C, is divided into two sections, with Section I maintaining all current requirements for licensees and applicants not within the scope of this final rule, and Section II containing all new requirements related to power reactor contingency response.

II. Petitions for Rulemaking

Three petitions for rulemaking were considered during the development of the final rule requirements consistent with previous petition resolution and closure process for these petitions (

i.e.

, PRM-50-80, PRM-73-11, and PRM-73-13). All three petitions are closed, and the discussion that follows provides the Commission's consideration of the issues raised in each petition as part of the development of the final power reactor security requirements.

A. PRM-50-80

PRM-50-80, submitted by the Union of Concerned Scientists (UCS) and the San Luis Obispo Mothers for Peace (SLOMFP), was published for public comment on June 16, 2003, (68 FR 35568). The petition requested that the Commission take two actions. The first action was to amend 10 CFR 50.54(p), “Conditions of licenses,” and 10 CFR 50.59, “Changes, tests, and experiments,” to require licensees to evaluate whether proposed changes, tests, or experiments cause protection against radiological sabotage to be decreased and, if so, to conduct such actions only with prior Commission approval. The second action requested that the Commission amend 10 CFR Part 50 to require licensees to evaluate their facilities against specified aerial hazards and make necessary changes to provide reasonable assurance that the ability of the facility to reach and maintain safe shutdown would not be compromised by an accidental or intentional aerial assault. The second action (regarding aerial hazards) was previously considered and resolved as part of the final design basis threat (DBT) (§ 73.1) rulemaking (March 19, 2007; 72 FR 12705). On November 17, 2005, (70 FR 69690), the Commission decided to consider the petitioner's first request for rulemaking (

i.e.

, evaluation of proposed changes, tests, or experiments to determine whether radiological sabotage protection is decreased). Proposed language addressing the issues raised in the petition was published as proposed § 73.58, “Safety/security interface requirements for nuclear power reactors.” This section remains in the final rule. Refer to the section-by-section analysis in this document, supporting § 73.58 for further discussion of the safety/security interface requirements.

B. PRM-73-11

PRM-73-11, submitted by Scott Portzline, Three Mile Island Alert, was published for public comment on November 2, 2001 (66 FR 55603). The comment period closed on January 16, 2002. Eleven comment letters were received. Of the 11 comments filed, 7 were from governmental organizations, 2 were from individuals, and 2 were from industry organizations. The majority of the comments support the petitioner's recommendation.

The petitioner requested that the NRC regulations governing physical protection of plants and materials be amended to require NRC licensees to post at least one armed guard at each entrance to the “owner controlled areas” (OCA) surrounding all U.S. nuclear power plants. The petitioner stated that this should be accomplished by requiring the addition of armed site protection officers (SPO) to the total number of SPOs—not by simply shifting SPOs from their protected area (PA) posts to the OCA entrances. The petitioner believes that the proposed amendment would provide an additional layer of security that would complement existing measures against radiological sabotage and would be consistent with the long-standing principle of defense-in-depth.

In a

Federal Register

Notice published December 27, 2006 (72 FR 481), the Commission informed the public that PRM-73-11 and the public comments filed on the petition would be considered in this final rule. Consideration of PRM-73-11 and the associated comments was undertaken as part of the effort to finalize the requirements governing security in the OCA.

The Commission has concluded that prescriptively requiring armed security personnel in the OCA is not necessary. Instead, the final physical security requirements in § 73.55(k) allows licensees the flexibility to determine the need for armed security personnel in the OCA, as a function of site-specific considerations, such that the licensee can defend against the DBT with high assurance. In reaching this determination, the Commission recognized that the requirements governing protective strategies must be more performance-based to enable licensees to adjust their strategies to address the site-specific circumstances and that a prescriptive requirement for armed security personnel in the owner controlled area may not always be the most effective approach for every licensee in defending against the DBT. The Commission constructed the final physical security requirements, recognizing the range of site-specific circumstances that exist, to put in place the performance objectives that must be met, and where possible, provided flexibility to licensees to construct strategies that meet the objectives.

C. PRM-73-13

PRM-73-13, submitted by David Lochbaum, Union of Concerned Scientists, was published for public comment on April 9, 2007 (72 FR 17440) and the comment period closed June 25, 2007.

The petitioner requested that the Commission amend part 73 to require that licensees implement procedures to ensure that, when information becomes known to a licensee about an individual seeking access to the protected area that would prevent that individual from gaining unescorted access to the protected area of a nuclear power plant, the licensee will implement measures to ensure the individual does not enter the protected area, whether escorted or not. Further, the petitioner requested that the NRC's regulations be amended to

require that, when sufficient information is not available to a licensee about an individual seeking access to the protected area to determine whether the criteria for unescorted access are satisfied, the licensee will implement measures to allow that individual to enter the protected area only when escorted at all times by an armed member of the security force who maintains communication with security supervision.

The Commission determined that the issues raised in PRM-73-13 were appropriate for consideration and were in fact issues already being considered in the Power Reactor Security Requirements rulemaking. Accordingly, the issues raised by PRM-73-13 and the public comments received were considered as part of the effort to finalize the requirements that govern escort and access within the protected area (refer to requirements in § 73.55(g) and § 73.56(h) for the specific final rule requirements).

The Nuclear Energy Institute (NEI) commented on PRM-73-13, with 11 other industry organizations agreeing (hereafter referred to collectively as commenters). The commenters agreed that the petitioner's first request (with regard to preventing an individual to have access to the protected area when derogatory information becomes known) should be issued as a notice of proposed rulemaking. Neither NEI nor any of the other commenters commented on any of the specific language proposed by the petitioner. With regard to the second provision proposed by the petitioner (requiring armed escorts for certain visitors), the commenters did not agree with the proposal. The commenters argued that the use of trained individuals, though not necessarily armed, in conjunction with search equipment and techniques as well as the limitation placed on visitors (

i.e.

, that visitors must have a “work-related need” for entry into the PA) have resulted in no incidents that warrant imposing this new requirement.

The Commission has decided not to adopt either proposal. Regarding the petitioner's second proposal, the Commission agrees with the commenters that the current protective measures for escorted personnel are sufficient to protect against the scenario presented by the petitioner. Licensee escorted access programs have been in place for years without incident, and the petitioner has not provided a basis that raises questions about their sufficiency.

With respect to the petitioner's first proposal, the Commission does not agree that the NRC's unescorted access requirements described in § 73.56 and § 73.57 need to contain prescriptive disqualifiers for access. Licensees are required by § 73.56(h) in this final rule to consider all of the information obtained in the background investigation for determining whether an individual is trustworthy and reliable before granting unescorted access. With the exception of individuals who have been denied access to another facility, the regulation does not specify types of information obtained during a background investigation that would automatically disqualify an individual from access. The final rule § 73.55(g)(7), however, does have several restrictions on escorted access (visitors) including verification of identity, verification of reason for business inside the protected area, and collection of information (visitor control register) pertaining to the visitor. In addition, there are several conditions that individuals who escort the visitor must adhere to including continuous monitoring of the visitor while inside the protected area, having a means of timely communication with security, and having received training on escort duties. Lastly, licensees may not allow any individual who is currently denied access at any other facility to be a visitor.

Furthermore, the petitioner's suggested language that a licensee must act to deny escorted access when such information “becomes known to the licensee” is unworkable from a regulatory perspective. It is unclear what the NRC could impose on licensees as an enforceable standard for such a scenario. In order to avoid potential enforcement action, a licensee would be put in a position to conduct a full background investigation on a visitor each time access is requested, which would undermine the entire purpose behind having the ability to escort visitors on site, or, in accordance with the petitioner's second suggestion, assign an armed security officer to escort that individual. The Commission does not have a basis to impose either measure, and the petitioners have not provided a basis in support of it. Section 73.55(g), however, does not allow individuals currently denied access at other facilities to be a visitor.

III. Discussion of Substantive Changes and Responses to Significant Comments

A. Introduction

A detailed discussion of the public comments submitted on the proposed power reactor security rule and supplemental proposed rule as well as the Commission's responses are contained in a separate document (see Section VII, “Availability of Documents,” of this document). This section discusses the more significant comments submitted on the proposed power reactor security provisions and the substantive changes made to develop the final power reactor security requirements.

The changes made to the power reactor security requirements are discussed by part, with changes to part 50 requirements being discussed first, followed by the changes to part 73 requirements, and proceeding in numerical order according to the section number. General topics are discussed first, followed by discussion of changes to individual sections as necessary. In addition to the substantive changes, rule language was revised to make conforming administrative changes, correct typographic errors, adopt consistent terminology, correct grammar, and adopt plain English. These changes are not discussed further.

Note that some of the final rule requirements were relocated. An example is the cyber security requirements that were issued as proposed § 73.55(m) and now reside in § 73.54.

Comments on the three PRMs are not explicitly addressed in the detailed comments response document, beyond those discussed earlier in Section II of this document, as this document addresses only the comments submitted on the proposed rule. However, the petitioner's comments were considered as part of the Commission's decision-making process and final determination of the rule requirements for each of the areas of concern.

Comments on the supporting regulatory analysis of the proposed rule are also contained in the detailed comment response document. Revisions to the final rule regulatory analysis were made consistent with the comment responses and these comments are not addressed further in this section.

The Commission solicited public comment on a number of specific issues but received input on only one of these specific issues. Specifically, the Commission requested stakeholders to provide insights and estimates on the feasibility, costs, and time necessary to implement the proposed rule changes to existing alarm stations, supporting systems, video systems, and cyber security. A commenter stated that the feasibility of establishing a cyber security program for industrial control systems has been demonstrated by various electric utilities, chemical plants, refineries, and other facilities with systems similar, if not identical, to those used in the balance-of-plant in commercial nuclear plants. The

commenter stated that the time and cost necessary to implement a cyber security program is dependent on the scope and discussed the technologies and programmatic approaches that can be pursued to augment current industry-proposed generic recommendations. The Commission focused significant attention on the cyber requirements and supporting guidance during development of the final cyber security requirements in § 73.54 as discussed below.

In general, there was a range of stakeholder views concerning this rulemaking, some supporting the rulemaking, others opposing the rulemaking. Some stakeholders viewed this rulemaking as an effort to codify the insufficient status quo while others described the new requirements as going well beyond the post-September 11, 2001, order requirements. The Commission believes that commenters who suggested that the Commission had no basis to go beyond the requirements that were imposed by the security orders misunderstood the relationship of those orders and the rulemaking. The security orders were issued based on the specific knowledge and threat information available to the Commission at the time the orders were issued. The Commission advised licensees who received those orders that the requirements were interim and that the Commission would eventually undertake a more comprehensive re-evaluation of current safeguards and security programs. As noted in the proposed rule, there were a number of objectives for the rulemaking beyond simply making generically applicable security requirements similar to those that were imposed by Commission orders. The Commission intended to implement several new requirements that resulted from insights it gained from implementation of the security orders, review of site security plans, implementation of the enhanced baseline inspection program, and evaluation of force-on-force exercises. These insights were obviously not available to the Commission when it issued the original security orders in 2002 and 2003.

In addition, another key objective of this rulemaking was to update the regulatory framework in preparation for receiving license applications for new reactors. The current security regulations in part 73 have not been substantially revised for nearly 30 years. Before September 11, 2001, the NRC staff had already undertaken an effort to revise these dated requirements, but that effort was delayed (See SECY-01-0101, June 4, 2001). Thus, this rulemaking addresses a broader context of security issues than the focus of the security orders of 2002 and 2003. One significant issue in particular was the need for clearly articulated security requirements and a logical regulatory framework for new reactor applicants. The revisions to part 73 were also intended to provide it with needed longevity and predictability for current and future licensees with a measured attempt to anticipate future developments or needs in physical protection.

B. Section 50.54(hh), Mitigative Strategies and Response Procedures for Potential or Actual Aircraft Attacks

As noted previously, a significant change to this final rule is the relocation of and provision of more detailed requirements for the beyond-design basis mitigative measures and potential aircraft attack notification requirements from proposed part 73, appendix C, to 10 CFR 50.54(hh). The Commission received several stakeholder comments that the proposed part 73, appendix C, was not the appropriate location for these requirements. During consideration of these comments, the Commission also decided to add additional detail to the aircraft attack notification portion of the requirements now located in § 50.54(hh)(1). In response, the Commission issued a supplemental proposed rule seeking additional stakeholder comment on these proposed revisions on April 10, 2008, (73 FR 19443) for a 30 day comment period. The Commission received six sets of comments on the supplemental proposed rule. The responses to those comments are discussed as follows.

The Commission revised the final rule language for § 50.54(hh)(1)(ii) in response to comments that the final rule should only require periodic updates to applicable entities or that communications should be maintained “as necessary and as resources allow.” The Commission intended the continuous communication requirement to apply to licensees only with respect to aircraft threat notification sources and not to all offsite response or government organizations. The Federal Aviation Administration (FAA) local, regional, or national offices; North American Aerospace Defense Command (NORAD); law enforcement organizations; and the NRC Headquarters Operations Center are examples of threat notification sources with which licensees would be required to maintain a continuous communication capability. If a licensee encounters a situation in which multiple threat notification sources(

e.g.

, FAA, NORAD, and NRC Headquarters Operations Center) are providing the same threat information, the licensee would only be required to maintain continuous communication with the NRC Headquarters Operations Center. Because licensees need to be aware when they can cease or must accelerate mitigative actions, it is important that licensees do not lose contact with aircraft threat notification sources. Periodic updates to entities other than threat notification sources are permitted by this final rule.

In response to comments that §§ 50.54(hh)(1)(iii), 50.54(hh)(1)(iv), and 50.54(hh)(1)(vi) requirements were redundant to those found in the NRC's existing emergency preparedness rules, the Commission revised the final rule language for each of those paragraphs to clarify the Agency's intent and to eliminate the appearance of redundant requirements vis-à-vis the emergency preparedness rules, which are also currently being revised. The intent of § 50.54(hh)(1)(iii) is to ensure that licensees contact offsite response organizations as soon as possible after receiving aircraft threat notifications. There is no expectation that licensees will complete and disseminate notification forms as the previous rule text implied. Section 50.54(hh)(1)(iv) pertains to operational actions that licensees can take to mitigate the consequences of an aircraft impact; the Commission did not intend this requirement to include emergency preparedness-related protective actions. In § 50.54(hh)(1)(vi), the Commission intended to require licensees to disperse essential personnel and equipment to pre-identified locations after receiving aircraft threat notifications, but before actual aircraft impacts, when possible. Also, the requirement for licensees to facilitate rapid entry into their protected areas applies only to those onsite personnel and offsite responders who are necessary to mitigate the event and not to everyone who was initially evacuated from the protected areas.

The Commission revised the statements of consideration for § 50.54(hh)(1)(vi) in response to a comment that meeting the rule might require licensees to suspend security measures under 10 CFR 50.54(x). The Commission elaborated on the specific intent of the protected area evacuation timeline assessment and validation, which is to require licensees to establish a decision-making tool for use by shift operations personnel to assist them in determining the appropriate onsite protective action for site personnel for various warning times and site population conditions. The Commission

expects that licensees will incorporate this tool into applicable site procedures to reduce the need to make improvised decisions that would necessitate a suspension of safeguards measures during the pre-event notification period. However, the Commission wishes to make clear that the suspension of security measures to protect the health and safety of security force personnel during emergencies is now governed by § 73.55(p)(1)(i) as codified in this final rule. Previously, there was no specific provision in the Commission's regulations that would have permitted such a departure, because under § 50.54(x), licensees are only permitted to suspend security measures if the health and safety of the public was at risk. Note that, in a § 50.54(hh) scenario, either §§ 50.54(x) or 73.55(p) could be applicable depending on the circumstances.

The Commission revised the final rule requirements in § 50.54(hh) in response to a comment that the final rule should include an applicability statement that removes the requirements of § 50.54(hh) from reactor facilities currently in decommissioning and for which the certifications required under § 50.82(a)(1) have been submitted. The commenter indicated that it is inappropriate that § 50.54(hh) should apply to a permanently shutdown and defueled reactor where the fuel was removed from the site or moved to an independent spent fuel storage installation (ISFSI). The NRC agrees with this comment and revised the final requirements in § 50.54(hh) so they do not apply to facilities for which certifications have been filed under § 50.82(a)(1) or § 52.110(a)(1). The Commission notes that § 50.54(hh) does not apply to any current decommissioning reactor facilities that have already satisfied the § 50.82(a) requirements.

The Commission requested stakeholder feedback on two questions in the supplemental proposed rule. Regarding the first question in the supplemental proposed rule notice where the Commission requested input on whether there should be additional language added to the proposed § 50.54(hh) requirements that would limit the scope of the regulation (

i.e.

, language that would constrain the requirements to a subset of beyond-design basis events such as beyond-design basis security events), commenters indicated that the Commission should constrain the requirements to a subset of beyond-design basis events; namely beyond design basis security events. The feedback suggested that, by limiting the rule requirements to strategies that address a generic set of beyond-design basis security events, the strategies could then be developed and proceduralized to focus on the restoration capabilities needed to mitigate the effects from these events. After careful consideration, the Commission decided to maintain the language from the supplemental proposed rule that recognizes that the mitigative strategies can address losses of large areas of a plant and the related losses of plant equipment from a variety of causes including aircraft impacts and beyond-design basis security events. The Commission also requested comments on whether applicants should include, as part of a combined license or operating license application, the § 50.54(hh) procedures, guidance, and strategies. Commenters indicated that this information will not be needed until fuel load, when an aircraft threat would be present. The most appropriate and efficient process for the Commission is to review these procedures as part of the review of operations procedures and beyond-design basis guidelines. The Commission views the mitigative strategies as similar to those operational programs for which a description of the program is provided and reviewed by the Commission as part of the combined license application and subsequently the more detailed procedures are implemented by the applicant and inspected by the NRC before plant operation. Because the Commission finds that the most effective approach is for the mitigative strategies, at least at the programmatic level, to be developed before construction and reviewed and approved during licensing, a requirement for information has been added to § 52.80, “Contents of applications; additional technical information,” and § 50.34, “Contents of construction permit and operating license applications; technical information.”

C. Section 73.2, Definitions

The proposed rule contained a number of definitions, primarily related to the proposed enhanced weapons requirements. As noted earlier, the enhanced weapons provisions and firearms backgrounds checks have been separated into a separate rulemaking, so codifying those definitions is no longer appropriate here. Regarding the other definitions of safety/security interface, security officer, and target sets; the Commission has determined that those terms are better defined through guidance.

D. Section 73.54, Protection of Digital Computer and Communication Systems and Networks

General Comments.

Proposed § 73.55(m) is relocated in the final rule to a stand-alone section (10 CFR 73.54). The Commission received several comments that the inclusion of a cyber security program within the proposed § 73.55(m) is not appropriate because cyber security is not implemented by physical security personnel. The Commission agrees that the cyber security program would not necessarily be implemented by security personnel and recognizes that a uniquely independent technical expertise and knowledge is required to effectively implement the cyber security program. Additionally, these requirements were placed into a stand alone section to enable the cyber security requirements to be made applicable to other types of facilities and applications through future rulemakings. The rule now requires that these requirements apply to nuclear power plant licensees in the same manner as the access authorization program required by § 73.56; the cyber security plan is subject to the same licensing requirements as the licensee's physical security, training and qualification, and safeguards contingency plans. In relocating these requirements, the Commission concluded that certain administrative requirements, otherwise applied by inclusion in § 73.55, must be brought forward for consistency. As a result, conforming changes were made to the pre-existing §§ 50.34(c) and 50.34(e) to establish the appropriate regulatory framework for Commission review and approval of the cyber security plan required by § 73.54(e). These conforming changes require nuclear power reactor applicants to provide a cyber security plan as part of the security plans currently required by §§ 50.34(c) or 52.79(a)(36), as applicable. Additionally, conforming changes were made to § 50.54(p), applicable to both operating and combined licensees, to require a cyber security plan as a condition of the license. Conforming changes were also made to §§ 50.34(e) and 52.79(a)(36) to require applicants to review this plan against the criteria for Safeguards Information established in § 73.21. Consistent with § 73.54(b)(3), the cyber security program is a part of the physical protection program subject to the same review and approval mechanisms as the physical security plan, training and qualification plan, and safeguards contingency plan.

The Commission has also added three (3) administrative requirements to the final rule (§§ 73.54(f), 73.54(g), and 73.54(h)) to require written policies and procedures, program review, and records retention, respectively.

In addition to the previously mentioned conforming changes, the Commission added an undesignated paragraph at the beginning of this section to require current licensees subject to § 73.54 to submit a cyber security plan and implementation schedule for Commission review and approval. The licensee's cyber security plan must be submitted by way of a license amendment pursuant to 10 CFR 50.90.

Section 73.54(a), Protection.

The Commission received a comment suggesting that the term “emergency preparedness,” as it appears in the proposed § 73.55(m)(1), should be replaced with the term “emergency response.” In the final rule, the term “emergency preparedness” is replaced with the more generic term “emergency preparedness functions.” The equipment embodied within these preparedness functions as described in 10 CFR Part 50, appendix E, usually includes a wide variety of plant monitoring systems, protection systems, and the onsite and offsite emergency communications systems used during an emergency event.

The term “emergency response” suggested by the commenter is used more specifically to refer only to the “emergency response data system” or ERDS, which provides a data link that transmits key plant parameters. Therefore, using the term “emergency preparedness functions” is considered the most appropriate term as it holistically addresses the equipment used during an emergency.

The Commission revised the proposed § 73.55(m)(1) which is renumbered in the final rule as § 73.54(a). This paragraph has been expanded to provide a more detailed list of the types of systems and networks that are intended to be included consistent with the proposed rule. The language in § 73.54(a)(1)(ii) is revised to clarify that “digital computer and communications systems and networks” must be considered for protection. It is important to note that the Commission does

not

intend that CAS or SAS operators be responsible for cyber security detection and response but rather that this function will be performed by technically trained and qualified personnel.

Section 73.54(b), Analysis of Digital Computer and Communication Systems and Networks.

The requirement to document a site-specific analysis that identifies site-specific conditions has been brought forward from § 73.55(b)(4). The rule is clarified to require that each licensee analyze the digital computer and communication systems and networks in use at their facility to identify those assets that require protection against the design basis threat.

The proposed § 73.55(m)(1) requirement to establish, implement, and maintain a cyber security program is renumbered in the final rule as § 73.54(b)(2). The rule requires that the cyber security program will include measures for the adequate protection of the digital computer and communication systems and networks identified by the licensee through the required site-specific analysis stated in § 73.54(b)(1).

The proposed § 73.55(m)(1)(ii) is renumbered in the final rule as § 73.54(b)(3). The Commission received several comments that the cyber security program is not appropriate for incorporation into the physical security program and, therefore, should not be implemented through the security organization. The Commission agrees in part. Cyber security, like physical security, focuses on the protection of equipment and systems against attacks by those individuals or organizations that would seek to cause harm, damage, or adversely affect the functions performed by such systems and networks. Cyber security and physical security programs are intrinsically linked and must be integrated to satisfy the physical protection program design criteria of § 73.55(b). The Commission recognizes that a uniquely independent technical expertise and knowledge is required to implement the cyber security program effectively, and therefore, the specific training and qualification requirements for the program must focus on ensuring that the personnel are trained, qualified, and equipped to perform their unique duties and responsibilities.

Section 73.54(c), Cyber Security Program.

The proposed § 73.55(m)(1)(iii) is renumbered in the final rule as § 73.54(c) and (c)(1), and is revised to clarify appropriate design requirements for the cyber security program. The cyber security program must be designed to implement security controls to protect the digital assets identified by the paragraph (b)(1) analysis. To accomplish this, the final rule § 73.54(c)(2), (3), and (4) are added to clarify the performance criteria to be met through implementation of the cyber security program.

The Commission received a comment that the term “protected computer system” in the proposed § 73.55(m)(1)(iii) is not defined and urged a more specific description. The Commission has deleted the term “protected computer system” from the final rule and provided a more detailed description of digital computer and communication systems and networks in § 73.54(a)(1).

The Commission received a comment that the high assurance requirement of the proposed § 73.55(m)(1) does not allow a licensee to implement measures designed to ensure continued functionality. Section 73.54(c)(4) has been revised to require the cyber security program to be designed to ensure that the intended function of the assets identified by § 73.54(b)(1) are maintained.

The proposed § 73.55(m)(5) is renumbered in the final rule as § 73.54(c)(2). The Commission received a comment to the proposed § 73.55(m)(5) that questioned whether the phrase “defense-in-depth” in computer terminology was intended to include real-time backup data. The Commission concluded that defense-in-depth for digital computer and communication systems and networks includes technical and administrative controls that are integrated and used to mitigate threats from identified risks. The need to back-up data as part of a defense-in-depth program is dependent upon the nature of the data relative to its use within the facility or system.

Defense-in-depth is achieved when (1) a layered defensive model exists that allows for detection and containment of non-authorized activities occurring within each layer, (2) each defensive layer is protected from adjacent layers, (3) protection mechanisms used for isolation between layers employ diverse technologies to mitigate common cause failures, (4) the design and configuration of the security architecture and associated countermeasures creates the capability to sufficiently delay the advance of an adversary in order for preplanned response actions to occur, (5) no single points of failure exist within the security strategy or design that would render the entire security solution invalid or ineffective, and (6) effective disaster recovery capabilities exist for protected assets.

The commenter also questioned how this requirement impacts the video image recording system, which is a computer system required by § 73.55(e)(7)(i)(C). Based upon the licensee's site-specific analysis, the video image recording system may be subject to this requirement if it meets

the criteria stipulated in § 73.54(a)(2), but it is not required to be included by the final rule.

Section 73.54(d), Cyber-Related Training, Risk, and Modification Management.

The Commission has consolidated the proposed requirements from §§ 73.55(m)(2), (m)(6), and (m)(7) into one paragraph of the § 73.54(d) to require the development, implementation, and maintenance of supporting programs within the cyber security program. The Commission has moved proposed § 73.54(m)(6) to § 73.54(d)(3) and clarified it to require that an evaluation be performed prior to modifications to protected digital assets to ensure that the cyber performance objectives of § 73.54 are maintained.

The Commission received a comment to the proposed rule § 73.55(m)(2) requesting clarification of what is meant by “assessment.” The term “assessment” has been removed from the final rule. To ensure that the measures used to protect digital computer and communication systems and networks remain effective and continue to meet high assurance expectations, the cyber security program must evaluate and manage cyber risks. Licensees must evaluate changes to systems and networks when (1) modifications are proposed for previously analyzed systems and (2) new technology-related vulnerabilities, not previously analyzed in the original analysis, that would act to reduce the cyber security environment of the system are identified.

Section 73.54(e), Cyber Security Plan.

The proposed § 73.55(m)(1)(i) is renumbered in the final rule as § 73.54(e). The Commission added a new § 73.54(e)(1) generically addressing the content of the cyber security plan. The plan must describe and account for any site-specific conditions that affect how Commission requirements are implemented.

The proposed § 73.55(m)(4)(ii) is deleted from the final rule. Consistent with the removal of this section from the proposed § 73.55(m), the Commission concluded that it is appropriate to address the cyber security incident response and recovery plan in the cyber security plan required by this section. The rule requires that the cyber security incident response and recovery plan will be part of the cyber security plan which in turn will be a component of the physical security program.

The proposed §§ 73.55(m)(4)(i) and (m)(4)(iii) are combined and renumbered to the final rule § 73.54(e)(2). The Commission received a comment to the proposed § 73.54(m)(4)(i) that there should be a rule requirement prescribing the timeframe in which a licensee must determine that a cyber attack is occurring or has occurred and suggested that it be within minutes of the attack. The Commission agrees with the commenter's concerns. The proposed § 3.54(m)(4)(iii) is renumbered in the final rule as § 73.54(e)(2)(i) and is revised to require a description in the cyber plan of how the licensee will maintain the capability for timely detection and response to cyber attacks. Licensees are required to develop, implement, and maintain a methodology for detecting cyber attacks; however, they are not required to meet deterministic time limits for discovery of a cyber attack. The cyber security program must be designed to ensure that cyber attacks are detected and an appropriate response is initiated to prevent the attack from adversely affecting the systems and networks that must be protected. The Commission has concluded that the § 73.54 performance-criteria and requirements ensure that detection and response are appropriate.

Section 73.54(f), Policies and Procedures.

The proposed § 73.55(m)(3) is renumbered in the final rule as § 73.54(f). The Commission added § 73.54(f) to clarify that policies, implementing procedures, site-specific analysis, and other supporting technical information used by the licensee need not be submitted for Commission review and approval as part of the cyber security plan. However, this information must be made available upon request by an authorized representative of the Commission.

Section 73.54(g), Reviews.

The Commission added the final rule § 73.54(g). The requirement for the review of the cyber security program is subject to the same processes stipulated in § 73.55(m), “Security program reviews.”

Section 73.54(h), Records.

The Commission added the final rule § 73.54(h). Consistent with establishing § 73.54 as a stand-alone 10 CFR section, this requirement for the retention of the cyber security program records is brought forward from the final rule § 73.55(q), “Records.” The expectation is that each licensee will maintain the technical information associated with the assets identified by the final rule § 73.54(b)(1) that is pertinent to compliance with § 73.54.

E. Section 73.55, Requirements for Physical Protection of Licensed Activities in Nuclear Power Reactors Against Radiological Sabotage

General Comments.

The Commission received several general comments which stated that the proposed § 73.55 does not include requirements for protection against aircraft attacks. As the Commission recently stated in the final design basis threat rulemaking (72 FR 12705; March 19, 2007), the protection of NRC-regulated facilities against aircraft attacks is beyond the scope of a licensee's obligations. Accordingly, requiring specific measures for the protection against aircraft attacks is beyond the scope of the requirements presented in this section and, therefore, is not addressed. The Commission nevertheless notes that there are requirements in this rulemaking that address licensee actions that are required to minimize the potential consequences of an aircraft impact on a nuclear power plant. As noted previously, those requirements are now located in § 50.54(hh) as conditions of license.

Section 73.55(a), Introduction.

The proposed § 73.55(a) would have required each licensee to submit, in their entirety, a revised physical security plan, training and qualification plan, and safeguards contingency plan for NRC review and approval within 180 days after the effective date of the final rule. The Commission received several comments stating that 180 days is not sufficient time to review and understand the modifications that may be required for compliance with the amended rule and to revise and submit amended security plans. In response to the comments, the Commission determined that, with the exception of the cyber security plan required by the new § 73.54, the majority of plan changes needed for compliance with the amended requirements of this section are likely to be minimal and are not anticipated to decrease the effectiveness of any particular licensee's current security plan. Because the current NRC-approved security plans already address the Commission's orders and pre-existing 10 CFR requirements, the greatest impact of this final rule will be focused primarily on those changes to plans and procedures needed to satisfy the requirements that are identified as “new.” The rule requires that by March 31, 2010, each currently operating reactor licensee must evaluate, on a site-specific basis, what security plan changes are needed to comply with the amended requirements of the rule. Those changes must be incorporated

into their security plans, as necessary, by March 31, 2010. In doing so, licensees are expected to follow the appropriate change processes described currently in §§ 50.54(p), 50.90, or 73.5. The Commission acknowledges that based on site-specific conditions, a limited number of plan changes may require Commission review and approval before implementation and must be made through a license amendment pursuant to 10 CFR § 50.90 or a request for an exemption per 10 CFR 73.5.

The Commission deleted the proposed requirements in § 73.55(a)(2) and (a)(3) for consistency with the determination that revised plans need not be submitted to the Commission for review and approval.

The Commission added a requirement in § 73.55(a)(2) that licensees must identify, describe, and account for site-specific conditions that affect the licensee's ability to satisfy the requirements of this section in the NRC-approved security plans. This requirement is added for consistency with revisions made to § 73.55(b)(4) which requires each licensee to conduct a site-specific analysis to identify such conditions.

The proposed § 73.55(a)(4) is renumbered in the final rule as § 73.55(a)(3) with minor revision to delete reference to Commission orders. One commenter asked the NRC to clarify its position with respect to the “legally-controlling document” once it approves a licensee security plan. Once a licensee has an approved security plan, both the licensee's security plan and the Commission's regulations are legally controlling. Regulations are legally controlling to the extent that they set forth the regulatory framework and general performance objectives of a licensee's security plan. The NRC-approved security plan, in contrast, describes a licensee's method of complying with those regulations including exemptions and approved alternatives. However, that the NRC specifically approved a licensee's security plan does not relieve the licensee from compliance with regulations.

To the extent that there are differences in a licensee's security plan and the regulatory requirements, the Commission expects that those differences would be specifically approved by the NRC, either in the form of an NRC-granted exemption, or an NRC-approved “alternative measure” as set forth in § 73.55(r). The NRC recognizes that generic regulations cannot always account for site-specific conditions. Some degree of regulatory flexibility is necessary to ensure that each licensee is capable of meeting the general performance objective of § 73.55(b)(1) to provide “high assurance” of public health and safety and common defense and security despite site specific conditions or situations that may interfere with or prevent the effective implementation of a given NRC requirement. Therefore, these regulations provide several mechanisms through which the NRC may approve a licensee's plan to implement alternative measures or exempt a licensee from compliance with any one or more NRC requirements, provided the licensee documents and submits sufficient justification. Once those exemptions or alternative measures are specifically reviewed and approved by the NRC and are incorporated into the licensee's security plan, they then become legally binding through the licensee's security plan required as a condition of its license.

In the rare situation in which a licensee's security plan conflicts with NRC regulations and the NRC has not reviewed and approved the conflicting measures, the Commission expects that the staff would work with the licensee to ensure that the security plan is revised to comply with the regulatory requirement. That the security plan may have been approved with a deficiency does not excuse the licensee from compliance with the Commission's regulations.

Section 73.55(a)(4) establishes when an applicant's physical protection program must be implemented. The Commission concluded that the receipt of special nuclear material (SNM) in the form of fuel assemblies onsite,

i.e.

in the licensee's protected area, is the event that subjects a licensee to the requirements of § 73.55. It is the responsibility of the applicant/licensee to implement an effective physical protection program before SNM in the form of fuel assemblies is received in the protected area.

The Commission has added a new requirement in § 73.55(a)(5) to address the Tennessee Valley Authority (TVA) facility at Watts Bar. TVA is in possession of a current construction permit for Watts Bar Nuclear Plant, Unit 2, and is treated as a current licensee for purposes of satisfying the requirements of this rule. These requirements reflect Commission support of a licensing review approach for Watts Bar Nuclear Plant, Unit 2, that employs the current licensing basis for Unit 1 as the reference basis for review and licensing of Unit 2, as stated in a July 25, 2007, Staff Requirements Memorandum (ML072060688).

The Commission has revised the final rule § 73.55(a)(6) to clarify that certain requirements in this section apply only to applicants for an operating license under the provisions of 10 CFR part 50 of this chapter, or holders of a combined license under the provisions of 10 CFR part 52 of this chapter. Specifically, the requirements to design, construct, and equip both the CAS and SAS to the same standards are addressed in the final rule as § 73.55(i)(4)(iii). The Commission views this as a prudent safety enhancement for future nuclear power plants but not an enhancement that is necessary for the adequate protection of pre-existing operating reactors. Unless otherwise specifically approved by the Commission, pre-existing power reactor licensees choosing to construct a new reactor inside an existing protected area are subject to the new CAS/SAS requirements in § 73.55(i)(4)(iii).

Section 73.55(b), General Performance Objective and Requirements.

The Commission received several comments requesting that the term “radiological sabotage” be used in lieu of the phrase “significant core damage” and “spent fuel sabotage” because the term “radiological sabotage” is defined in § 73.2. The Commission agrees in part and has revised the final rule in § 73.55(b)(2) to clearly retain, without modification, the pre-existing requirement for licensees to provide protection against the design basis threat of radiological sabotage and has revised § 73.55(b)(3) to clarify that the design of the physical protection program must ensure the capability to prevent “significant core damage” and “spent fuel sabotage.” It was not the Commission's intent in the proposed rule to delete the requirement for protection against radiological sabotage but rather to establish the prevention of significant core damage and spent fuel sabotage as the criteria to measure a licensee's performance to protect against “radiological sabotage.” The final rule has been revised to reflect this intent. The achievement of “significant core damage” and “spent fuel sabotage” can be measured by the licensee through accepted engineering standards, and the use of these terms provides measurable performance criteria that are essential to understanding the definition of radiological sabotage. Additionally, the Commission believes that continued use of the terms “significant core damage” and “spent fuel sabotage” to enhance the understanding of radiological sabotage is warranted because these terms are now well established and have been used consistently by the

Commission and industry relative to force-on-force testing before and after September 11, 2001.

The Commission received several comments regarding the proposed rule § 73.55(b)(2), the introduction of six performance-criteria: detect, assess, intercept, challenge, delay, and neutralize. Upon consideration, the Commission concluded that the four terms, “detect, assess, interdict, and neutralize,” more concisely represent the intended performance-criteria and this change has been made throughout the final rule. The terms “intercept, challenge, and delay” are subsumed in the term “interdict.”

The Commission received a comment that the proposed rule § 73.55(b)(3) delineation of requirements for the design of the physical protection program should be clarified. The Commission agrees and § 73.55(b)(3) has been revised to clarify Commission expectations. The requirement for the protection of personnel, equipment, and systems against the design basis threat vehicle bomb assault is addressed in the § 73.55(e)(10)(i)(A). The requirement for protection against a single act, within the capabilities of the design basis threat of radiological sabotage, is based upon the pre-existing § 73.55(e) and is addressed in the final rule § 73.55(i)(4)(i). Section 73.55(i)(4)(i) requires licensees to protect either the CAS or SAS against a single act by ensuring the survival of at least one alarm station in order to maintain the ability to perform required functions.

Section 73.55(b)(4) is renumbered in the final rule as § 73.55(b)(3)(ii). The Commission received a comment that the scope of the proposed § 73.55(b)(4) regarding the term “defense-in-depth” was not clearly understood. Section 73.55(b)(3)(ii) is revised to clarify that defense-in-depth is accomplished through the integration of systems, technologies, programs, equipment, supporting processes, and implementing procedures as needed to ensure the overall effectiveness of the physical protection program.

Section 73.55(b)(4) is added to specifically require that each licensee perform a site-specific analysis for the purpose of identifying and analyzing site-specific conditions that affect the design of the onsite physical protection program. Commission regulations are generic and cannot in all instances account for site-specific conditions, and therefore, it is the licensee's responsibility to identify and account for site-specific conditions relative to meeting Commission requirements, subject to NRC inspection.

Section 73.55(b)(8) is added to require the development and maintenance of a cyber security program that meets the performance objectives of the new § 73.54. Section 73.54 incorporates the proposed § 73.55(m) in its entirety, and the associated public comments were addressed previously within the new § 73.54.

Section 73.55(b)(10) is revised to clarify the Commission's expectation that each licensee will enter physical protection program findings and deficiencies into the site corrective action program so that they can be tracked, trended, corrected, and prevented from recurring.

Section 73.55(b)(11) is repeated from the pre-existing appendix C to part 73, “Introduction,” to delineate the Commission's expectation that security plans and implementing procedures must be complementary to other site plans and procedures.

Section 73.55(c), Security Plans.

The Commission received several comments stating that the requirements in § 73.55(c) are redundant to the requirements in § 50.34(c) and (d). The Commission disagrees. While these requirements appear to be redundant, conforming changes have been made to § 50.34(c) and (e) to include cyber security plans and training and qualification plans. In addition, § 73.55 establishes a paragraph dedicated to security plans to consolidate the regulatory framework for each plan, describe the general content of each plan, and clarify the relationship between Commission regulations, NRC-approved security plans, and site-specific implementing procedures. The primary focus of the security plans is to describe how the licensee will satisfy Commission requirements including how site-specific conditions affect the measures needed at each site to ensure that the physical protection program is effective.

The Commission received a comment that the proposed § 73.55(c)(2) appeared to require that all security plans be protected as Safeguards Information (SGI). The Commission disagrees with the comment. Licensees are required by § 73.55(c)(2) only to review the information contained in the security plans against the criteria contained in § 73.21 to determine the existence of SGI and to protect that information appropriately.

The Commission has added a conforming requirement to §§ 73.55(c)(6) and 50.34(c) for licensees to provide a cyber security plan in accordance with the new § 73.54 for Commission review and approval.

The proposed §§ 73.55(c)(3)(ii), 73.55(c)(4)(ii), and 73.55(c)(5)(ii) are deleted from the final rule. The Commission's expectation is that each licensee will address Commission requirements in their approved plans and implementing procedures and, where the Commission requires a specific detail to be included in the plans, that requirement is stated in applicable paragraphs of the final rule.

Section 73.55(d), Security Organization.

The Commission received several comments that the proposed requirement of § 73.55(d)(1) to provide “early detection, assessment, and response to unauthorized activities within any area of the facility” was too broad and could result in unnecessary regulatory burden. The Commission agrees with the comment and has deleted these terms and revised the language to clarify the primary responsibility of the security organization. The intent is that the security organization will focus upon the effective implementation of the physical protection program which in turn is designed to protect the facility from the design basis threat of radiological sabotage with high assurance.

The Commission received a comment that proposed § 73.55(d)(3) was not clearly understood as it appeared this requirement may pertain to any individual within the security organization. The Commission agrees, and the final rule text in § 73.55(d)(3) is revised to clarify that individuals assigned to perform physical protection and/or contingency response duties must be trained, equipped, and qualified in accordance with appendix B to part 73 to perform those assigned duties and responsibilities whether that individual is a member of the security organization or not. This clarification is made to account for those instances where the licensee uses facility personnel other than members of the security organization to perform duties within the physical protection program, such as a vehicle escort or warehouse personnel inspecting/searching deliveries. The rule requires that facility personnel who are not members of the security organization will be trained and qualified for the specific physical protection duties that they are assigned, which includes possessing the knowledge, skills, abilities, and the minimum physical qualifications such as sight, hearing, and the general health needed to perform the assigned duties effectively.

The proposed § 73.55(d)(4) is deleted from the final rule because the reference to meeting the requirements of § 73.56

(Access authorization program) is redundant.

The Commission received several comments indicating that the requirements in the proposed § 73.55(d)(5) pertaining to contracted security forces were redundant to other requirements addressed in the proposed rule. The Commission agrees. These requirements were retained from pre-existing requirements for the licensee to explicitly include these requirements as written statements in contracts between the licensee and a contract security force. Upon review, the Commission has determined that specifying these requirements in written contracts is unnecessary. The enforceability of NRC regulatory requirements is not dependent on whether they are implemented by the licensee or by a licensee contractor; therefore, specifically requiring the contract between these parties to contain these requirements is unnecessary. The Commission has, however, retained the requirement in the final rule § 73.55(q)(3), “Records,” (formally described in proposed § 73.55(d)(5)) that a copy of the contract be retained by the licensee. Additionally, the requirement in the proposed § 73.55(d)(5)(vi) that “any license for possession and ownership of enhanced weapons will reside with the licensee” has been deleted from this section. The Commission intends, however, that this requirement will be reflected in its regulations codifying requirements related to the use of enhanced weapons. The Commission's plan for that rulemaking was stated previously in this document. The remaining proposed requirements of § 73.55(d)(5) are deleted from this paragraph and are retained in other paragraphs of the final rule.

Section 73.55(e), Physical Barriers.

The Commission received several comments that the proposed § 73.55(e) would result in unnecessary regulatory burden by expanding protected area physical barrier requirements into the owner controlled area (OCA). The Commission agrees in part and § 73.55(e) is revised to clarify the generic and specific requirements for the design, construction, placement, and function of each physical barrier. Section 73.55(e)(6) specifically addresses requirements for physical barriers in the OCA. Physical barriers can be used to fulfill many functions within the physical protection program, and therefore, each physical barrier must be designed and constructed to serve its predetermined function within the physical protection program. Consistent with § 73.55(b) for design of the physical protection program, the rule requires that each licensee will analyze site-specific conditions to determine the specific use, type, function, construction, and placement of physical barriers needed for the implementation of the physical protection program.

The Commission received comments on the proposed § 73.55(e)(3)(i), which would have required the delineation of the boundaries of areas for which the physical barrier provides protection, requesting that this provision be deleted because it lacked performance criteria. The Commission agrees, and the requirement is deleted from the final rule because it is more appropriate to be specified in regulatory guidance.

The proposed § 73.55(e)(3)(ii) is renumbered in the final rule as § 73.55(e)(3)(i) and is broken into subparagraphs § 73.55(e)(3)(i)(A) through (C). The Commission received a comment to clarify the proposed rule statements of consideration pertaining to the performance criteria for physical barriers. The Commission agrees in part. The pre-existing § 73.55(c)(8) introduced design goals relative to the use of vehicle barriers but did not address other physical barriers. The statements of consideration in the proposed rule attempted to incorporate other physical barriers and explain that the generic performance-criteria for physical barriers are not limited to vehicle barriers. The criterion for physical barriers is that

“each barrier be designed to satisfy the function it is intended to perform.”

The Commission agrees with the comment stating that the performance of all three functions (

i.e.

, visual deterrence, delay, and support access control measures) is not always required of each barrier, and the final rule addresses the barrier design requirements generically in § 73.55(e)(3)(i)(A) through (C).

The Commission received several comments requesting clarification of the proposed rule § 73.55(e)(4) for physical protection measures in the OCA. The proposed § 73.55(e) attempted to establish a generic requirement for the design, construction, placement, and function of physical barriers based on a site specific analysis. This generic requirement was misunderstood to mean that PA barriers were now required in the OCA. As such, the Commission revised the proposed § 73.55(e) and (e)(6) to clarify the scope and intent of this requirement. Consistent with the final rule § 73.55(b)(4), it is the responsibility of each licensee to identify, analyze, and account for site-specific conditions in the design and implementation of its physical protection program. Section 73.55(e)(6) is revised to clarify that the application of physical barriers in the OCA is determined by each licensee through site-specific analysis and must satisfy the physical protection program design requirements of § 73.55(b). The rule requires that the licensee will design and construct appropriate barriers in those areas to meet the identified site-specific need.

The Commission received comments requesting clarification of the term “unobstructed observation” as used in § 73.55(e)(5)(i)(A). The Commission agrees that this term can be misunderstood, and therefore, § 73.55(e)(7)(i)(A) is revised to delete the term “unobstructed.” This term was used to emphasize that a clear field of observation be provided in the isolation zone. However, the Commission's expectation is not the complete elimination of obstruction but that the licensee implement measures needed to negate the effects of any obstructions such as the relocation of non-permanent objects or the strategic placement of cameras to enable observation around an obstruction.

The Commission received several comments to clarify the proposed § 73.55(e)(5)(ii) pertaining to the performance of isolation zone assessment equipment and agrees that clarification is necessary. The proposed § 73.55(e)(5)(ii) is renumbered in the final rule as § 73.55(e)(7)(i)(C) and provides a performance-based description for specific isolation zone assessment equipment. The Commission has concluded that the requirement for this equipment is consistent with current licensee practices, therefore, it is an appropriate update for this final rule.

The proposed § 73.55(e)(5)(iii) is renumbered in the final rule as § 73.55(e)(7)(ii). The Commission received a comment that this requirement would preclude the use of areas inside the protected area as equipment lay-down/staging areas. The Commission agrees in part. The final rule does not preclude the use of lay-down areas/staging areas. However, this requirement does explicitly preclude such activities where the action constitutes an obstruction that prevents observation on either side of the protected area perimeter. This rule requires the licensee to take appropriate actions to negate any adverse effects that lay-down/staging areas may have to prevent observation on either side of the protected area perimeter.

The Commission received several comments to clarify the proposed requirement in § 73.55(e)(6)(i) to secure penetrations through the protected area barrier. The Commission agrees that

clarification is necessary. The proposed requirement is separated and renumbered as § 73.55(e)(8)(ii). Section 73.55(e)(8)(ii) is revised to clarify that penetrations must be secured and monitored to prevent exploitation. Where the size of an opening in any barrier is large enough to be exploited or otherwise defeat the intended function of that barrier, then such openings must be secured and monitored to prevent or detect attempted or actual exploitation.

The proposed § 73.55(e)(6)(v) is renumbered to § 73.55(e)(5). The Commission received several comments to clarify the term “bullet-resisting.” The Commission agrees in part that additional clarification is needed but does not believe that such clarification is necessary in the rule text. The Commission has determined that it is not appropriate to publicly reference site specific bullet-resisting standards in the rule because such specificity may lead to the identification of specific vulnerabilities. Specific bullet resisting standards that meet the requirements in § 73.55(e)(5) are described in regulatory guidance and would be further reflected in a licensee's NRC-approved security plans. The Commission acknowledges, however, that in addition to manufactured bullet-resisting materials, a level of bullet-resistance that meets the intent of this regulation might be provided by distances and angles combined with standard construction materials and designs.

The proposed § 73.55(e)(6)(vi) is renumbered in the final rule as § 73.55(e)(8)(v). The Commission received several comments requesting that the NRC delete the word “all” with respect to its modification of the term “exterior areas.” The Commission agrees that clarification is necessary. Section 73.55(e)(8)(v) retains and updates the pre-existing requirement in § 73.55(c)(4) to periodically check

all

exterior areas within the protected area but has revised the requirement to clarify that some areas may be excepted from this requirement where safety concerns prevent the licensee from physically checking that area. The Commission's expectation is that licensee procedures will account for these areas by another means that ensures the safety of personnel while assuring the integrity of the area and the requirement is met.

Section § 73.55(e)(9)(v)(D) is added to include the SAS among the types of areas and equipment that must be afforded protection as a vital area/equipment the same as the CAS, only for

applicants

for new reactor licenses. Current licensees are not subject to this requirement as they have been found to provide adequate protection within current configurations. The requirement to treat SAS as a vital area is an enhancement that provides equivalency and redundancy for the alarm stations.

The Commission received a comment that proposed § 73.55(e)(7)(iii), renumbered to the final rule as § 73.55(e)(9)(vi)(A), expands the requirement for secondary power systems from just “alarm annunciator equipment” to all “intrusion detection and assessment equipment” and that this is a significant expansion that is not explained or supported by NRC force-on-force inspections. The Commission agrees that the scope of the proposed paragraph appears to have been expanded to require all intrusion detection and assessment equipment employed by the licensee to be connected to a secondary power supply and for all secondary power supplies to be treated as vital areas. Section 73.55(e)(9)(vi)(A) is revised to retain the pre-existing § 73.55(e)(1) to locate the secondary power supply for alarm annunciation equipment in a vital area. The Commission has added § 73.55(i)(3)(vii) to address uninterruptible power supplies for intrusion detection and assessment equipment at the protected area perimeter. The uninterruptible power supply discussed in § 73.55(i)(3)(vii) is not required to be located in a vital area because it is a short-term measure utilized to provide service until secondary power sources are operable and the Commission recognizes that uninterruptible power supplies are physically dispersed across the site. Making each uninterruptable power supply a vital area is considered a safety enhancement and implementation would be an unnecessary regulatory burden on the licensee based on the level of protection that would be provided versus the cost.

The Commission has determined that the proposed § 73.55(e)(7)(iv) was redundant to § 73.58 and has deleted this requirement from the final rule to avoid unintended duplication and impact beyond current requirements.

The Commission received multiple comments stating that the proposed § 73.55(e)(8) significantly expands the requirements for controlling vehicles inside the OCA. The pre-existing § 73.55(c)(7) requires the licensee to provide vehicle control measures, including vehicle barrier systems, to protect against use of a land vehicle as a means of transportation to gain unauthorized proximity to vital areas. The Commission's intent is not to expand the requirements for controlling vehicles in the OCA and has revised and consolidated the proposed rule § 73.55(e)(8) to clarify scope and intent of this requirement. The proposed § 73.55(e)(8) is renumbered in the final rule as § 73.55(e)(10) and provides general vehicle control requirements. In addition, the rule requires that licensees implement security measures to prevent unauthorized access to the protected area by rail.

The Commission received several comments on proposed § 73.55(e)(8)(ii) that to control vehicle approach routes is broader in scope than protecting against vehicle bomb attacks and preventing vehicle use as a means of adversary transportation as was stated in the proposed rule. In lieu of a specific requirement to control vehicle approach routes, § 73.55(e)(10) provides general vehicle control requirements. The Commission acknowledges that the control of vehicle approach routes is generally accomplished through the establishment of vehicle control measures such as a vehicle barrier system designed for protection against vehicle bomb assaults or a protected area barrier that prevents unauthorized personnel from gaining proximity to protected areas or vital areas.

The proposed § 73.55(e)(8)(iii) is modified and renumbered as § 73.55(e)(10)(i)(A). The Commission received several comments to clarify protection requirements against land vehicle bombs and the protection of personnel, systems, and equipment. The Commission agrees, and § 73.55(e)(10)(i)(A) is revised to clarify the protection of personnel, systems, and equipment relative to land vehicle bomb assaults rather than the design basis threat in its entirety. This requirement does not include an obligation to protect all plant personnel from such an attack but rather focuses on the protection of those personnel whose job functions make them necessary to prevent significant core damage and spent fuel sabotage through the implementation of the protective strategy.

The proposed § 73.55(e)(8)(v) is renumbered as § 73.55(e)(10)(i)(B). The Commission received a comment to clarify whether loss of power testing is subject to this requirement. The Commission concluded that specific testing criteria and periodicity are site-specific and must be addressed in procedures. The rule requires that each licensee will develop and implement procedures that will ensure that active vehicle barriers can be electronically, manually, or mechanically placed in the denial position to perform their intended function for protection against

the vehicle bomb in the event of a power failure.

The proposed § 73.55(e)(8)(vi) is renumbered as § 73.55(e)(10)(i)(C). The Commission received several comments that if the proposed § 73.55(e)(8)(vi) is intended to address tampering then the term “tampering” should be used. The Commission agrees and § 73.55(e)(10)(i)(C) is revised to remove the term “integrity,” and clarified to require that the licensee implement measures to identify indications of tampering with vehicle barriers and barrier systems and to ensure that barriers are not degraded. The rule requires that the licensee will implement appropriate surveillance and observation measures for vehicle barriers, barrier systems, and railway barriers.

Section 73.55(e)(10)(i)(D) was specifically added, based on a comment, to address vehicle control measures for sites that have rail access to the protected area.

The proposed § 73.55(e)(9) is renumbered as § 73.55(e)(10)(ii). Section 73.55(e)(10)(ii)(B) is revised to require licensees to provide periodic surveillance and observation of waterway approaches and adjacent areas. Section 73.55(e)(10)(ii) is also revised to delete reference to early detection, assessment, and response, consistent with revisions made to the proposed § 73.55(d)(1).

The proposed § 73.55(e)(10) is deleted. The Commission received several comments that this provision is inconsistent with the existing regulations and associated regulatory guidance for openings in the protected or vital areas. The Commission agrees and furthermore determined that “Unattended Openings” are adequately addressed in regulatory guidance and, therefore, need only be addressed through a more generic requirement within this rulemaking. Section 73.55(e)(8)(ii) and § 73.55(i)(5)(iii) generically address penetrations through the PA barrier and unattended openings that intersect a security boundary. The rule requires that such penetrations and unattended openings will be secured and monitored consistent with the intended function of the barrier to ensure the penetration or unattended opening can not be exploited.

Section 73.55(f), Target Sets.

The Commission received multiple comments that the NRC should require licensees to identify certain bridges as “targets.” The commenter stated in part, that certain bridges, if lost, would adversely affect or even negate the offsite responders' capabilities and because numerous emergency scenarios rely upon offsite responder's capability to cross these bridges to gain access to the facility during an emergency. The Commission disagrees. The requirements of this section focus on the physical protection of target set equipment against the design basis threat of radiological sabotage. Target sets include, in part, the combination of equipment or operator actions which, if all are prevented from performing their intended safety function or prevented from being accomplished, would likely result in significant core damage barring extraordinary action by plant operators. Clearly, geographical features such as bridges or other ingress or egress routes are not included in this concept of target set equipment. Further, a licensee's ability to defend against the design basis threat of radiological sabotage is not dependent on the availability of offsite responders.

The Commission received a comment that proposed § 73.55(f)(1) which would have required licensees to document their target set development process in “site procedures” is not appropriate because other site documents (

e.g.

, engineering calculations) are used to document this process. The Commission agrees and final rule § 73.55(f)(1) is revised to generically require that this information be documented, rather than written into site procedures, to provide the necessary regulatory flexibility. The word “maintain” is added to ensure availability of this information upon request by an authorized representative of the NRC. The specific information needed to satisfy this requirement may be contained in engineering records or other documents.

The Commission received two comments pertaining to the proposed requirement § 73.55(f)(2) which stated that the requirement for licensees to consider the effects of cyber attacks on target sets is not appropriate. The Commission disagrees, concluding that § 73.55(f)(2) is appropriate and consistent with Commission requirements for protection against the design basis threat of radiological sabotage stated in § 73.1 and the cyber security requirements stated in the new § 73.54.

The Commission received a comment that the proposed § 73.55(f)(3) requirement to list target set equipment or elements that are not within a protected or vital area in the approved security plan is an unnecessary regulatory burden that could require plan changes whenever site-conditions change. The Commission agrees that targets sets must be adjusted consistent with changes to site-specific conditions, and therefore, § 73.55(f)(3) is revised to require that target set elements not contained in a protected or vital area be identified through the documentation required in § 73.55(f)(1) rather than security plans to ensure that they can be appropriately updated and modified to account for changes to site-specific conditions without prior Commission approval.

The Commission received comments that the proposed § 73.55(f)(4), which would have required implementation of a program to ensure that changes to the configuration of equipment that was identified as target set equipment in the licensee's security plan, was not appropriate due to the increased burden of oversight identified by the requirement. The Commission agrees in part. Section 73.55(f)(4) is revised to clarify the Commission's expectation that each licensee implement a process for the oversight of target set equipment, systems, and configurations using existing processes. This requirement ensures that changes made to the configuration of target set equipment and modes of operation are considered in the licensee's protective strategy. Reference to “significant core damage and spent fuel sabotage” is deleted to clarify that the focus of this requirement is on the licensee's process to identify changes made to such equipment that could potentially affect the implementation of the protective strategy. The licensee is expected to periodically review target sets for completeness and continued applicability consistent with the requirements in the final rule § 73.55(m), “Security program reviews.” The Commission has determined that such reviews are needed to ensure target sets are complete and accurate at all times.

Section 73.55(g), Access Controls.

The Commission received a comment that the proposed § 73.55(g) does not close a dangerous loophole in current search requirements for law enforcement personnel and security officers which allows bona fide Federal, State, and local law enforcement personnel on official duty and licensee security personnel who have exited the protected area (PA) to reenter the PA without being searched for firearms. The commenter argued that such exceptions could provide insiders or corrupt law enforcement personnel collaborating with adversaries with significant opportunities to introduce contraband, silencers, ammunition, or other unauthorized equipment that could be used in an attack. The commenter stated that this practice should be explicitly forbidden in the rules except under

extraordinary circumstances. The Commission disagrees with this comment. On-duty law enforcement personnel may be granted access by licensees when there is a need for such access and are escorted while inside the PA. With respect to licensee security personnel, they are searched for firearms, explosives, and incendiary devices upon reporting for duty and are under the observation of other security personnel who are subject to the licensee's continuous behavioral observation program when performing duties. Upon assuming their duties, armed security officers must continue to be subject to the search criteria for explosives and incendiary devices upon re-entry to the PA. Both law enforcement personnel and licensee armed security personnel have been determined, through rigorous background investigations, to be trustworthy and reliable before being issued a firearm as part of their assigned duties. The Commission concluded that this exception to the required search criteria is necessary and appropriate to avoid unnecessary regulatory burden associated with these operating conditions.

The proposed rule attempted to address all access controls equally without addressing specific implementing differences for access to the owner controlled area, PA, or vital areas (VA). The Commission received several comments to clarify these differences in access controls for each area regarding processing of materials, personnel, and vehicles. The Commission agrees and the final rule is revised to address access control requirements for each area. The Commission also revised § 73.55(g)(1)(ii), (A), (B), and (C) to clarify generic control measures for controlling vehicle access through a vehicle barrier. Section 73.55(g)(2) is revised to specifically address PA access controls, and § 73.55(g)(4) is revised to specifically address VA access controls.

The proposed § 73.55(g)(1)(iv) to monitor and ensure the integrity of the licensee's access control systems is deleted from the final rule because it is sufficiently addressed by §§ 73.55(n)(1)(i) and (g)(1)(i)(C). The rule requires that the licensee will ensure that all access controls are working as intended and have not been compromised such that a person, vehicle, or material is able to gain unauthorized access beyond a barrier.

The proposed § 73.55(g)(5) is renumbered as § 73.55(g)(3). The Commission received a comment that the proposed § 73.55(g)(3)(ii) would have relaxed the requirement for armed security escorts for all vehicles inside a nuclear power plant's PA or VAs, unless the vehicle was specifically designated for use in such areas. The commenter further stated that the provision provides no explanation for the proposed change to this requirement, particularly given that there appears to have been no change in the threat environment that might warrant this change in security.

The Commission disagrees that requirements for control of vehicles inside the PA are relaxed by this requirement. The pre-existing requirement § 73.55(d)(4) did not require an armed escort for all vehicles but rather required only that the escort be a member of the security organization who may have been an unarmed watchman. The requirement has been revised, however, to permit the use of non-security-organization personnel as escorts for vehicles except that armed security personnel must escort vehicles containing hazardous materials and unsearched bulk items. Vehicle escorts, however, must be trained in accordance with the licensee's training and qualification plan as required by § 73.55(g)(8)(iii).

The pre-existing requirement for licensees to designate certain vehicles for use inside the PA has been deleted from the final rule. The Commission concluded that simply designating a vehicle for use inside the PA is an unnecessary regulatory burden and, therefore, is not necessary. Section 73.55(g)(3)(iii) requires that vehicle use inside the PA must be limited to plant functions or emergencies and that keys must be removed or the vehicle otherwise disabled when not in use. All vehicles and personnel must be searched before entering the PA. Vehicles operated by individuals who are authorized unescorted access to the PA are not required to be escorted.

The proposed § 73.55(g)(4)(ii)(C), which would have required licensees to implement procedures during an emergency to ensure that the licensee's capability to prevent significant core damage and spent fuel sabotage was maintained, is deleted because it is sufficiently addressed by § 73.55(b)(3).

The proposed § 73.55(g)(4)(iii) is subsumed by §§ 73.55(g)(5)(ii) and 73.55(b)(11). These provisions require that consideration be given to how access to and egress from the site will be controlled during an emergency, which is a function assigned to the security organization consistent with site emergency procedures.

The Commission received comments that passwords are not access control devices and, therefore, are not appropriate for the requirements of the proposed § 73.55(g)(6). The Commission disagrees. The Commission has determined that in physical security, passwords are a form of access control device because they are used to control access to security computer or electronic systems and may be used to control access to secured areas. The rule requires that the licensee will control passwords/passcodes used for security computers, electronic systems, or secured areas.

Section 73.55(g)(7)(i)(F) is added to require the licensee to deny access (escorted or unescorted) to any individual for whom access is currently denied at another NRC-licensed nuclear power reactor facility.

The Commission received several comments that the requirements described in proposed § 73.55(g)(7)(ii) regarding the specific information to be included on photo-identification badges issued to non-employee personnel who require frequent or extended unescorted access to a facility are an unnecessary regulatory burden. The Commission agrees in part, and § 73.55(g)(7)(ii) is revised to retain only the requirement for badges to visually reflect that the individual is a non-employee and that no escort is required. The proposed §§ 73.55(g)(7)(ii)(B) through (D) are deleted. The Commission's expectation is for licensees to electronically record the individual's access level, period of unescorted access, and employer within security databases. The Commission concluded that current badge technology is predicated upon computerized access control methodologies that store much of this information electronically on badges or keycards and in associated databases. Therefore, the need to visually display such information on badges is unnecessary. The proposed § 73.55(g)(7)(ii)(E) requirement for the designation of assigned assembly areas on badges is also deleted as it is determined to be an unnecessary regulatory burden.

The Commission received a comment to clarify the proposed § 73.55(g)(8) relative to the training of personnel assigned to perform escort duties. The rule requires that all escorts will be trained to perform escort duties and that this training may be accomplished through existing processes such as the General Employee Training (personnel escort) and/or the security Training and Qualification Plan (vehicle escorts). This training requirement ensures that any individual assigned to escort duties understands their responsibilities and the activities the person(s) to be escorted are authorized to perform. For

those instances where the licensee uses facility personnel other than a member of the security organization to perform escort duties within the physical protection program, such as a vehicle escort, these individuals must be trained, equipped, and qualified in accordance with the security Training and Qualification Plan to perform this specific duty. The rule requires that facility personnel who are not members of the security organization will be trained and qualified for the specific physical protection duties that they are assigned which includes possessing the knowledge, skills, abilities, and the minimum physical qualifications such as sight, hearing, and their general health needed to perform the assigned duties effectively.

The Commission received another comment that the proposed § 73.55(g)(8) allows escorts to take multiple visitors with no background checks into PAs and VAs, but does not require that the escorts meet even minimal physical and visual capabilities. The commenter stated that, unlike the proposed new requirement in Part 73, appendix B, paragraph B.2.a(2) that unarmed members of the security organization meet specified physical capabilities, the proposed regulations in § 73.55(g)(8) would not prevent licensees from assigning blind, deaf, and mute persons as escorts. The commenter urged that the regulation define minimally acceptable physical attributes for escorts. The Commission disagrees with this comment. The final rule does not require personnel escorts to be subjected to medical qualifications to perform escort duties but does require escorts to meet the requirements of § 73.55(g)(8), which establishes training and qualification requirements for personnel escorts. Further, personnel escorts are required to be capable of performing the assigned duty and maintain communication with the security organization when performing escort duties to summon assistance if needed. The NRC has never imposed minimum physical qualifications on licensee personnel escorts and the commenter has supplied no basis to impose such requirements now.

Section § 73.55(g)(8)(i) through (v) updates pre-existing requirements consistent with Commission expectations and current licensee practices for performing escort duties. The Commission received several comments that the proposed § 73.55(g)(8)(ii), which would have required that individuals assigned escort duties be provided a means of “timely communication,” was without basis because current communications capabilities at facilities are sufficient for escorts to make notifications or requests for assistance. Therefore, the commenter asserted that the NRC should delete this provision from the final rule. The Commission disagrees. The rule requires that escorts be able to call for assistance when needed. The “timely communication” language in the final rule does not require a specific form of communication media. It is the responsibility of each licensee to determine the appropriate communication media for their site which may or may not include the use of hand-held radios, public address systems, intercoms, etc. The Commission has concluded that timely communication capability is an appropriate update to pre-existing requirements and current licensee practices. Therefore, the Commission retains this requirement in § 73.55(g)(8)(ii).

The Commission received several comments that the proposed § 73.55(g)(8)(iii) for continuous communication is a new requirement without basis. The Commission disagrees. Section 73.55(g)(8)(iii) is an appropriate update to the pre-existing requirement described in § 73.55(f)(1), which required security personnel to maintain

continuous

communication capability with the central and secondary alarm stations and the pre-existing § 73.55(d)(4) which required vehicles to be escorted by security personnel while inside the PA. Section 73.55(g)(3)(ii) relieves the licensee from the pre-existing § 73.55(d)(4) and allowed non-security personnel, who are trained and qualified in accordance with the security Training and Qualification Plan, to escort vehicles inside the PA. In providing this relief, the Commission concluded that it is prudent to “retain” the pre-existing § 73.55(f)(1) requirement for vehicle escorts to maintain a continuous communication capability that was otherwise present through the use of security personnel escorting vehicles. It is also important to note that § 73.55(g)(8)(iii) is revised to permit vehicle escorts to directly contact members of the security organization other than the CAS or SAS for assistance. The proposed requirement would have limited this communication to only the CAS or SAS.

The Commission received a comment that the proposed § 73.55(g)(8)(iv) phrase “knowledgeable of those activities that are authorized to be performed within the areas” is broad and impracticable and that escorts should only be responsible for observing obvious indications of inappropriate behavior. The Commission agrees in part and revised § 73.55(g)(8)(iv) to clarify that the level of knowledge required is general and that general knowledge of authorized activities is a fundamental requirement for an effective escort.

The Commission received comments that proposed § 73.55(g)(8)(v), which described minimum visitor to escort ratios in protected and vital areas, would not have provided sufficient protection against the possibility that visitors could attempt to commit or facilitate acts of radiological sabotage. The Commission disagrees that the requirements reflected in the proposed rule are not sufficient to ensure that visitor activities are adequately controlled, and they are, therefore, reflected in the final rule. The rule requires each licensee to implement visitor observation and control measures that are consistent with the physical protection program design requirements in § 73.55(b) including specific requirements for searches of personnel, escorting of personnel, and escort communications. The Commission has concluded that the visitor control measures required by this paragraph provide an appropriate level of protection and prescribing specific visitor-to-escort ratios is unnecessary. Visitor-to-escort ratios should be specific to each site and visitor based on site conditions and the rationale for the visit. Therefore, § 73.55(g)(8)(v) is revised to delete the proposed visitor-to-escort ratios (10 to 1 in the PA and 5 to 1 in VAs) as these ratios are addressed in regulatory guidance and required to be delineated in the licensee's NRC-approved security plans.

Section 73.55(h), Search Programs.

The Commission received several comments that search requirements should be addressed according to facility area (

i.e.

, owner controlled area (OCA) and PA). The Commission agrees, and § 73.55(h) has been revised to address search requirements by area. This revision is necessary to clarify the differences of search requirements and implementation for owner controlled and protected areas.

The Commission received several comments to clarify the proposed § 73.55(h)(1) and (1)(i) regarding searches and that searches should be conducted at each physical barrier only for those items that must be excluded beyond the barrier. The Commission agrees that clarification is warranted and has combined and renumbered the proposed § 73.55(h)(1) and (h)(1)(i) as § 73.55(h)(1). Consistent with § 73.55(b)(4), each licensee must analyze their site-specific conditions to

determine what personnel, vehicles, and materials must be prevented from gaining access to specific areas of the facility and will search the personnel, vehicles, and materials to satisfy the design requirements of § 73.55(b).

The proposed § 73.55(h)(5) is renumbered as § 73.55(h)(2)(iii). Section 73.55(h)(2)(iii) is revised to specify implementing details for the conduct of vehicle searches within the OCA including to the number of personnel required and the duties to be performed by each. The search process applied in the OCA must be performed by two personnel at least one of which must be armed and positioned to observe the search to provide an immediate response if needed. The rule requirement for searches conducted at vehicle checkpoints within the OCA is that one individual will conduct the search function, a second armed individual will be physically located at the checkpoint to provide an immediate armed response if needed, and a third individual, in accordance with § 73.55 (h)(2)(v), will monitor the search function via video equipment at a location from which that individual can initiate an additional response.

The proposed § 73.55(h)(8) through (h)(8)(iii) are renumbered as § 73.55(h)(3)(v) through (h)(3)(viii). The Commission received a comment that Commission approval of exceptions to search requirements through licensee security plans is unreasonable and unnecessary. The Commission agrees in part, and § 73.55(h)(3)(v) is revised to clarify the rule requirement that a general description of the types of exceptions must be stated in the licensee security plans rather than a specific listing of individual exceptions which must be captured in procedures.

The proposed § 73.55(h)(8)(i) is renumbered as § 73.55(h)(3)(vii). The Commission received a comment that the requirement for an armed escort is not applicable in all cases. The Commission agrees in part and has revised § 73.55(h)(3)(vii). The rule requires that bulk items excepted from the search required for access into the PA will be escorted by an armed member of the security organization to ensure that unsearched bulk items are controlled until they can be offloaded and the absence of contraband can be verified to the extent practicable.

The proposed § 73.55(h)(1)(iii) is subsumed in the final rule in appendix B of part 73.

The proposed §§ 73.55(h)(2)(i) and 73.55(h)(2)(ii) regarding clearly identifying items during a search are subsumed as §§ 73.55(h)(2)(iv) and 73.55(h)(3)(i).

Section 73.55(i), Detection and Assessment Systems.

Several requirements from proposed §§ 73.55(i)(7) and 73.55(i)(10) have been consolidated, revised, relocated, and/or deleted to eliminate redundancy and provide clarification for alarm annunciation and video assessment equipment in both alarm stations and have been designated as § 73.55(i)(2) and (3).

The proposed §§ 73.55(i)(4), 73.55(i)(4)(i), and 73.55(b)(3) are combined and renumbered as § 73.55(i)(4)(i). The Commission received a comment that the requirements set forth in the proposed § 73.55(i)(4) were significant high-impact requirements that exceed the existing requirements without basis and whose exact scope and impact could not be assessed with the current language. The Commission agrees that further clarification of the intent and scope of these requirements is necessary. In the final rule, the pre-existing requirement in § 73.55(e)(1) for protection of at least one alarm station against a single act is retained. Section 73.55(i)(4)(i) of the final rule clarifies the functions that must survive from a single act by requiring licensees to ensure the survivability of either alarm station to maintain the ability to perform the following four functions: Detection and assessment of alarms, initiation and coordination of an adequate response to alarms, summoning offsite assistance, and providing effective command and control. The proposed § 73.55(b)(3), which generally addressed the protection of personnel, systems, and equipment from a single act bounded by the design basis threat, is now reflected as § 73.55(e)(10)(i)(A), which generally describes licensee measures for protection against the design basis threat land vehicle bomb assault. A single act does not refer to the number of acts committed during a security contingency event; rather it pertains to any one act that alone could remove the licensee's capability to retain at least one alarm station and/or its functions as required. An example of a single act against which this regulation requires protection would be destruction of security equipment not specifically accounted for in the licensee protective strategy that is accessible from the PA perimeter and that its destruction would remove the capability to retain one alarm station and/or its required functions.

The proposed § 73.55(i)(4)(ii) is renumbered as § 73.55(i)(3)(vii). The Commission received several comments that proposed § 73.55(i)(4)(ii), which would have required uninterruptable backup power for all alarm station functions, would be a significant high-impact requirement that would exceed the existing requirements without a basis and that the exact scope and impact of the requirement cannot be assessed with the current language. The Commission agrees in part, and has revised § 73.55(i)(3)(vii) to clarify the scope of equipment to which this requirement applies. The Commission recognizes that because the transfer to secondary power is not an instantaneous event, the maintenance of continuous power to some equipment essential to the initiation of licensees' protective strategies may not be possible and could result in a period of degraded performance. In light of this potential vulnerability, the rule requires uninterrupted power supplies for detection and assessment equipment at the PA perimeter to ensure continued operability in the event of the loss of normal power during the transition between normal power and initiation of secondary power. The Commission determined that a licensee's capability to detect and assess a threat at the PA perimeter is an essential function for all sites, and as such, the equipment needed to satisfy the requirement in § 73.55(i)(1) must remain operable through an uninterruptible power supply. Based on each licensee's site specific considerations, detection and assessment equipment subject to this requirement may, for example, include alarm annunciators and sensors, lighting, closed circuit televisions, and video image recording necessary to provide detection and assessment at the protected area perimeter. However, under this rule, each license must identify which detection and assessment equipment it relies on to initiate its protective strategy. This requirement is based on the pre-existing § 73.55(e)(1), the evaluation of information gained through enhanced baseline inspections and force-on-force exercises.

Section 73.55(i)(4)(ii)(E) is added to ensure that licensees address events (

e.g.

, trespassing) that may not require a response in accordance with the protective strategy but may require the employment of elements within the licensee's force continuum and legal authority as permitted under applicable State law.

Section § 73.55(i)(4)(ii)(G) is added for consistency with § 73.55(i)(4)(ii)(F) to ensure that operators in both alarm stations are knowledgeable of the final disposition of all alarms, thus minimizing the possibility of assessment errors.

The proposed §§ 73.55(a)(6), 73.55(a)(6)(i), and 73.55(a)(6)(ii) are consolidated and re-numbered as § 73.55(i)(4)(iii). The Commission received several comments to clarify the applicability and scope of the proposed § 73.55(a)(6) and to relocate this requirement to § 73.55(i). The Commission agrees that additional clarity is needed but declines to relocate the applicability language in § 73.55(a)(6). Sections 73.55(a)(6) and 73.55(i)(4)(iii) specify that the requirement to construct, locate, protect, and equip both the central and secondary alarm stations (CAS and SAS) is applicable to only applicants for an operating license under the provision of part 50 or holders of a combined license under the provisions of part 52 that is issued after the effective date of this rule. The rule requires that both alarm stations for new reactors will be equal and redundant and will meet construction standards previously applied only to the CAS. Specifically, the Commission has deleted the pre-existing provision that otherwise permitted the SAS to be located offsite. Operating power reactors licensed before the effective date of this final rule and the Tennessee Valley Authority's Watts Bar Nuclear Plant need not renovate their existing alarm stations to meet this requirement. Applicants for a new operating license or combined license for a reactor that would be constructed inside an existing PA must construct both the CAS and SAS to the requirements of § 73.55 for CAS, unless otherwise exempted through established licensing processes.

The proposed §§ 73.55(i)(5), (i)(6), and (i)(7)(i) related to detection and assessment capabilities are deleted because they are subsumed as § 73.55(i)(1) which provides a general description of detection and assessment requirements.

The proposed §§ 73.55(i)(9)(ii), (ii)(A), and (ii)(B) are combined and renumbered as § 73.55(i)(5)(ii). The Commission received a comment that the NRC should delineate the requirements of each of the three areas (OCA, PA, and VA) in the final rule and clarify what is meant by the proposed “integrity of physical barriers or other components.” The Commission agrees and the final rule is revised to clarify that this requirement applies to the OCA. The term “integrity” is retained and is meant to refer to the ability of the barrier to perform its function and that it has not been tampered with.

The proposed § 73.55(i)(9)(iv) is renumbered as § 73.55(i)(5)(iii). The Commission received several comments to clarify the proposed § 73.55(i)(9)(iv), which concerned licensee obligations for observation of unattended unmonitored openings. The Commission agrees that clarification is needed, and § 73.55(i)(5)(iii) is revised to clarify that this requirement focuses on monitoring unattended openings, such as underground pathways, that can be exploited to circumvent the intent of a barrier or otherwise defeat its required function.

The proposed § 73.55(i)(9)(iii)(B) has been divided and renumbered as § 73.55(i)(5)(v) and (vi). The Commission received a request for clarification of the intent of the proposed requirement specific to “random intervals.” The Commission agrees and § 73.55(i)(5)(vi) is revised to clarify the scope of patrols relative to PAs, VAs, and target sets. The term “random” as used in the final rule is not intended to describe the periodicity of the patrols but to describe the manner in which the patrol is conducted to prevent predictability.

The proposed § 73.55(i)(9)(iii)(C) is renumbered as § 73.55(i)(5)(vii). The Commission received several comments to add the word “obvious” before the word tampering because security personnel generally do not possess the level of specific knowledge that might be necessary to detect the types of tampering that could have been included within the scope of the rule. These commenters noted that other licensee operations personnel who possess detailed engineering knowledge also provide observation of target set equipment and additional assurances that tampering would be identified. The Commission agrees and § 73.55(i)(5)(vii) is revised to include the term “obvious” consistent with the level of knowledge that security personnel possess regarding plant operations based on training that is provided to them.

The proposed §§ 73.55(i)(10) and (i)(10)(i) are deleted from the final rule because this proposed requirement to maintain video equipment in operable condition is redundant to §§ 73.55(b)(3) and 73.55(n)(1)(i).

The proposed § 73.55(i)(10)(iii) is deleted from the final rule. The NRC received a comment that ensuring personnel assigned to monitor video equipment are alert and able to perform their assigned duties is a licensee management responsibility. The Commission agrees. Fitness-for-duty, fatigue, and work-hour controls are covered in 10 CFR part 26.

The proposed § 73.55(i)(11)(i) is renumbered as § 73.55(i)(6). The Commission received several comments to clarify this lighting requirement. The Commission agrees and § 73.55(i)(6) is revised to clarify the lighting requirements and identify acceptable alternatives. The reference to the OCA is removed from this paragraph as it is duplicative to the reference in § 73.55(b).

The proposed § 73.55(i)(11)(ii) is renumbered as § 73.55(i)(6)(ii). The Commission received several comments to clarify the pre-existing requirement for 0.2-foot-candle illumination and the application of low-light technology. Consistent with the proposed rule, the current 0.2-foot-candle illumination requirement is explicitly retained as the minimum standard for illumination levels at nuclear power reactor facilities. However, § 73.55(i)(6)(ii) is revised to clarify and introduce the use of low-light technology to supplement the facility lighting scheme and to provide the flexibility needed for licensees to use low-light technology. The rule requires that licensees will ensure that lighting levels either meet the 0.2-foot-candle requirement, or employ low-light technology to ensure the protective strategy can be implemented effectively.

Section 73.55(j), Communication Requirements.

The Commission has made no significant changes to § 73.55(j). The Commission received a comment that proposed § 73.55(j)(1), which would require the maintenance of continuous communication with offsite resources, was without a basis. The commenter argued that the ability to maintain such communication is beyond the ability of licensees. The Commission disagrees. This requirement is retained from the pre-existing § 73.55(f)(3) and remains unchanged. The rule requires that each licensee security organization maintains continuous communication with local law enforcement authorities and onsite personnel.

The Commission received a comment that proposed § 73.55(j)(4)(iii), regarding the licensee's communication system, is not appropriate for escorts. The Commission agrees and § 73.55(j) is revised to address the specific communication requirements of personnel or entities requiring communications and communication systems to be employed to meet the requirement. The rule requires that vehicle escorts are provided by the licensee with the appropriate means to call for assistance when needed. The final rule does not require a specific form of communication media, and therefore, it is the responsibility of each licensee to determine the appropriate communication media for their site which may or may not include the use of hand-held radios, public address systems, intercoms, etc.

The Commission received a comment that proposed § 73.55(j)(6), which would have required the licensee to identify and establish alternative communication methods for areas of its facility where communication could be interrupted or not maintained, was without a basis, and would be virtually impossible to implement given a power plant's reinforced concrete construction and trip sensitive equipment. The Commission disagrees and believes that the commenter misinterpreted the Commission's intent. A condition as described in the rule, if present at a site, must be identified and accounted for to satisfy the pre-existing § 73.55(f)(1) requirement for continuous communication. However, the Commission does not intend to require that such conditions be “fixed” but rather that the licensee compensate for this condition as needed and appropriate for their site-specific considerations.

Section 73.55(k), Response Requirements.

The proposed §§ 73.55(k)(1)(ii) and (iii), regarding the training and qualification of armed responders and the availability of certain equipment, are deleted from the final rule. These requirements are sufficiently addressed in the final rule in appendix B to part 73 and appendix C to part 73 and, therefore, are redundant.

The proposed § 73.55(k)(1)(iv), regarding training for assigned weapons, is renumbered as § 73.55(k)(2). The Commission determined that the proposed § 73.55(k)(3)(iv) is redundant to this requirement and has revised § 73.55(k)(2) to clarify performance criteria.

The proposed requirement in § 73.55(k)(1)(v) regarding weapons training and qualification of armed responders is deleted from the final rule because it is redundant to the requirements set forth in appendix B to part 73.

The proposed § 73.55(k)(3) is renumbered as § 73.55(k)(4). The final rule § 73.55(k)(4) is clarified to delineate the duties of armed responders and armed security officers. Section 73.55(k)(5) is added to retain the pre-existing requirement, described in former § 73.55(h)(3), for the minimum number of armed responders required to be immediately available at the facility to fulfill response requirements. The rule requires that each licensee will determine the specific minimum number of armed responders needed to protect their facility and that under no circumstances will that minimum number be less than 10 inside the PA and available at all times.

The proposed § 73.55(k)(3)(iii) and (iv) are deleted from the final rule. The Commission concluded that these proposed requirements are redundant to the final rule appendix B to part 73 and § 73.55(n)(1)(i), respectively.

The proposed § 73.55(k)(6) regarding licensee personnel being trained to understand their roles during security incidents, is deleted from the final rule. The Commission has determined that this requirement is more appropriate for site procedures and has deleted it from the final rule.

The proposed § 73.55(k)(7)(iv) is renumbered as § 73.55(k)(8)(iii). The Commission received a comment that it does not have a basis to require licensee notification of offsite agencies other than local law enforcement upon receipt of an alarm or other threat notification. The Commission generally agrees that the requirement is not necessary. Section 73.55(k)(8)(iii) is revised to specify that licensees must notify local law enforcement only in accordance with their site procedures. However, as noted below, some licensees have established liaison with non-local law enforcement agencies including State or Federal. To the extent that these arrangements are noted in those licensees' site procedures, the rule would require their notification.

The proposed § 73.55(k)(8) is renumbered as § 73.55(k)(9). The Commission received a comment that it does not have a basis to require licensees to obtain liaison agreements with agencies other than local law enforcement. The Commission disagrees with this comment but has clarified the rule. In some instances, licensees have arrangements with agencies not considered “local law enforcement” such as Federal or State law enforcement agencies. It is, therefore, an appropriate update to the regulatory framework to include the possibility of State and Federal law enforcement agencies as well as local law enforcement to account for sites whose local law enforcement are State or Federal agencies. However, such agreements are not required by the rule. Further, the Commission acknowledges that in some cases a local, State, or Federal law enforcement agency cannot or will not enter into a written agreement with a licensee, and in such cases the Commission's expectation is that the licensee will make a reasonable effort to pursue liaison with these agencies to the extent practicable and that this liaison is documented.

The proposed appendix C to part 73, section II, paragraph (k), “Threat Warning System,” paragraph (k)(1), (k)(2), and (k)(3) are moved and renumbered as § 73.55(k)(10), paragraph (k)(10)(i), and paragraph (k)(10)(ii). The Commission concluded that these requirements are better presented in the regulatory framework for the physical protection program. The rule requires that the licensee will pre-plan specific enhancements to their physical protection program to be taken upon notification by the NRC of a heightened threat environment.

Section 73.55(l),

Facilities Using Mixed-Oxide (MOX) Fuel Assemblies Containing up to 20 Weight Percent Plutonium Dioxide (PuO

2

).

The Commission received a comment that through this proposed rulemaking, the NRC is ignoring the Atomic Safety and Licensing Board's (ASLB) decision in the Catawba case. The commenter stated that, in that case, the ASLB added security conditions to Duke Energy's proposed security plan at Catawba and that one of the ASLB's conditions is not in the proposed rule. The Commission disagrees with this assertion. In fact, the Commission specifically rejected the ASLB's imposition of additional license conditions for the use of MOX fuel and affirmed the staff's conclusion that the additional security measures provided by the licensee would provide reasonable assurance of the protection of public health and safety in light of the theft risk presented by the use of MOX fuel (

Duke Energy Corp.

(Catawba Nuclear Stations, Units 1 and 2), CLI-05-14, 61 NRC 359 (2005)). The Catawba license amendments were issued on March 3, 2005 (70 FR 11711; March 9, 2005). The requirements described in § 73.55(l) are consistent with the physical protection program enhancements that were applied to the Catawba facility. Section 73.55(l) is revised to clarify that those licensees choosing to use MOX fuel assemblies must implement additional measures designed to prevent theft or diversion of un-irradiated MOX fuel assemblies in addition to protecting the power reactor facility against the design basis threat of radiological sabotage.

The Commission received a comment that the NRC did not define MOX fuel in the proposed rule (with regard to concentration, weight, or any other physical property), and suggested that this is necessary. The Commission agrees, and § 73.55(l) is revised to specify the maximum percent weight of plutonium dioxide allowed within a MOX fuel assembly and that the use of MOX fuel assemblies with percent weights greater than 20 weight percent plutonium dioxide require unique and separate approval from the Commission. In such cases, licensees would be required to submit a license amendment

request, and the Commission would consider additional security measures as necessary. Section 73.55(l)(3)(v)(B) is also revised to clarify the number of physical barriers required for protection of un-irradiated MOX fuel assemblies. Physical protection of un-irradiated MOX fuel assemblies requires three physical barriers of which the water contained within the spent fuel pool is the third barrier.

Finally, the commenter disagreed with the fact that the proposed rule language did not make a distinction between the security applied to a small number of MOX lead test assemblies and the security applied to a large number of assemblies. The Commission disagrees that such a distinction is necessary in the rule. Because the Commission considers only one part of one assembly to be the goal quantity of a theft scenario and because theft of only a portion of the fuel in one assembly would be considered failure, no additional protection would be added by distinguishing between multiple additional assemblies. The physical protection program requirements specified in § 73.55(l) are appropriate for any quantity of unirradiated MOX fuel assemblies that are less than or equal to 20 weight percent plutonium dioxide and may be on-site at any time.

Section 73.55(m), Security Program Reviews

. The proposed § 73.55(m) for “Digital computer and communication systems and networks” is relocated to a stand-alone section (10 CFR 73.54). The Commission has determined that these requirements are best addressed as a stand-alone section similar to the requirements for an access authorization program.

The proposed § 73.55(n) is renumbered as § 73.55(m) to account for the renumbering of the proposed § 73.55(m) as 10 CFR 73.54.

The proposed §§ 73.55(n)(1) and (n)(1)(ii) are combined and renumbered as § 73.55(m)(1). The Commission received a comment to clarify the periodicity of audits and reviews required by proposed § 73.55(n)(1). Section 73.55(m)(1) is revised to clarify periodicity. The rule requires that each licensee will review their physical protection program to determine if the programmatic requirements established are being implemented. The rule also requires that each licensee will review the physical protection program to determine if the physical protection program effectively meets Commission requirements. The licensee must ensure that all components or elements of the physical protection program are reviewed at intervals no less than every 24 months. However, the Commission has concluded that licensees must also review individual components or elements of the physical protection program no later than 12 months following a significant change to site-specific conditions, equipment, personnel, or other performance indicators.

The proposed §§ 73.55(n)(3) and (4) are deleted because these requirements are redundant to the requirement to review the physical protection program at intervals not to exceed 24 months.

The proposed § 73.55(n)(5) is deleted because it is redundant to the final rule Part 73, appendix B, Section VI, for the performance evaluation program.

The proposed § 73.55(n)(8) is deleted because the requirements for the site corrective action program as stated in § 73.55(b)(10) address all issues, not just findings from reviews, audits, etc. as stated in the proposed rule.

The proposed § 73.55(n)(9) is deleted because this provision does not apply to reviews and audits addressed herein and is limited to only the conduct of training program requirements addressed in part 73, appendix B, Section VI.

Section 73.55(n), Maintenance, Testing, and Calibration.

The proposed § 73.55(o) is renumbered as § 73.55(n) to account for the renumbering of the proposed § 73.55(m) to a stand-alone section (10 CFR 73.54).

The proposed § 73.55(o)(1)(i) is renumbered as § 73.55(n)(1)(i). The Commission received a comment asking who determines the “predetermined intervals” in which testing and maintenance are required. The predetermined intervals for maintenance, calibration, and performance testing of equipment are specified by manufacturer specifications and the NRC. The Commission has concluded that specific, pre-determined intervals for operability testing are required to ensure that certain equipment is capable of performing its intended function.

Section 73.55(o), Compensatory Measures.

The proposed § 73.55(p) is renumbered as § 73.55(o) to account for the renumbering of proposed § 73.55(m) for cyber security requirements to a stand-alone § 73.54.

Section 73.55(p), Suspension of Security Measures.

The proposed § 73.55(q) is renumbered as § 73.55(p) to account for the renumbering of proposed § 73.55(m) for cyber security requirements to a stand-alone § 73.54.

The Commission received a comment that proposed § 73.55(q)(1)(ii) requires that a licensed senior operator approve the suspension of safeguards measures. The commenter suggested that approval from a licensed senior operator was excessive and that the rule should be revised to permit approval by the “on shift operations manager.” The Commission disagrees and finds that approval by a licensed senior operator is appropriate for all suspensions of security measures pursuant to § 73.55(p). The allowance for suspensions of security measures for severe weather conditions is based on the pre-existing §§ 50.54(x) and (y) which explicitly requires, at a minimum, approval by a licensed senior operator. Under this provision, the security supervisor recommends when security measures must be suspended; and, consistent with the pre-existing §§ 50.54(x) and (y), a licensed senior operator must, at minimum, approve that decision to ensure that other operational and safety concerns have been fully considered and that there will be no adverse affects or undue risk to the public health and safety as a result of the suspension. Refer to NRC Regulatory Issue Summary 2008-26 “Clarified Requirements of Title 10 of the Code of Federal Regulations (10 CFR) Section 50.54(y) When Implementing 10 CFR Section 50.54(x) to Depart from a License Condition or Technical Specification,” dated October 29, 2008 (ML080590124), for further discussion of the requirements associated with which licensee personnel may approve licensee departures from license conditions or technical specifications.

The proposed § 73.55(q)(4) is deleted because the requirement to report the suspension of safeguards measures is redundant to § 73.71 and is sufficiently addressed in § 73.55(p)(3).

Section 73.55(q), Records

. The proposed § 73.55(r) is renumbered as § 73.55(q) to account for the renumber of proposed § 73.55(m) for cyber security requirements to a stand-alone section (10 CFR 73.54). The proposed § 73.55(d)(5) is renumbered as § 73.55(q)(3) to retain the requirement for retention of security force contracts as a record for the duration of the contract and retention of superseded portions for three years following changes to that contract.

Section 73.55(r), Alternative Measures.

The proposed § 73.55(s) is deleted because it is redundant to § 73.58. The Commission has determined that safety/security interface is a stand-alone section, the applicability of which is adequately addressed in § 73.58 and need not be referenced in § 73.55 to ensure clarity or applicability.

The proposed § 73.55(t) is renumbered as § 73.55(r) to account for the renumbering of the proposed § 73.55(m) for cyber security requirements to a stand-alone section (10 CFR 73.54) and the deletion of proposed § 73.55(s) “Safety/security interface.” Section 73.55(r) represents the same set of requirements that were described in former § 73.55(a), which stated, in part, “the Commission may authorize an applicant or licensee to provide measures for protection against radiological sabotage other than those required by this section * * *.” That provision had been known as the “alternative measures” provision although that specific phrase did not appear in the rule text. The final rule codifies that phrase as it relates to this process, but the requirements of seeking and obtaining approval for an “alternative measure” essentially remains as it had been set forth in the existing rule.

F. Section 73.56, Personnel Access Authorization Requirements for Nuclear Power Plants

General Comments.

Section 10 CFR 73.56, the Commission has revised the proposed rule text and associated statement of considerations to (1) address over 180 pages of the comments received on the proposed rule, (2) provide additional clarifications and specifications, and (3) correct errors. The following provides a brief explanation of the significant changes to the proposed rule and the Commission's responses to the comments.

The Commission received numerous comments on the proposed rule as a result of unclear descriptions or inconsistent use of the roles and responsibilities of licensees, applicants, and contractors or vendors and the phrases “grant unescorted access” and “authorize unescorted access authorization.”

In response to the comments received and suggestions implicit in the comments received on various provisions in the proposed rule, the Commission improved the clarity and precision of the final rule by providing the following clarification in the statement of consideration for § 73.56(a). First, the Commission replaced the phrases “unescorted access authorization” and “access authorization” with the phrases “unescorted access” and/or “unescorted access authorization” to correct misuse and misinterpretation of the rule. Second, the Commission replaced the term “grant” associated with “unescorted access authorization” and “access authorization” with the terms “grant” and/or “certify.” Finally, the Commission made several revisions in order to provide clarification and/or specifications on the roles and responsibilities of licensees, applicants, and contractors or vendors.

Additionally, the Commission revised paragraphs (a)(4) and deleted (a)(5) in the final rule to define and to provide clarification and specification on the roles and responsibilities of licensees, applicants, and contractors or vendors. Throughout the final rule, the Commission revised the proposed rule text to reflect the above clarifications and specifications.

Throughout the proposed rule text, the Commission received comments that some of its statements in the proposed rule regarding the accessibilities and capabilities of the information-sharing mechanism that the industry is currently using to comply with the Commission's requirements were incorrect. Specifically, commenters noted that the information-sharing mechanism used by the industry does not contain records, but rather it contains data representative of the records that are accessed and controlled by licensees, applicants, and certain contractors or vendors. The Commission agrees with the received comments and revised the final rule to clarify that use of an information-sharing mechanism is not a requirement; rather it is the sharing of specific access authorization information with the other licensees subject to this section that is required in accordance with § 73.56(o)(6).

Section 73.56(a), Introduction

. The Commission deleted proposed paragraphs (a)(2) and (a)(3) pertaining to the submission of access authorization program amendments for Commission approval and the continued implementation of the access authorization program under current requirements in the final rule as those requirements have been incorporated in § 73.56(a)(1).

Section 73.56(b), Individuals Subject to the Access Authorization Program

. Commenters stated that proposed paragraph (b)(1)(ii) does not contain a necessary provision that allows for short-term escorted digital access and addresses access authorization requirements for an individual accessing emergency response components that include commercial facilities that are not subject to access authorization requirements. The Commission disagrees with the recommended rule requirements. The Commission find

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.

Power Reactor Security Requirements · 74 FR 13926 | Frix