Skip to main content

Partnerships and Information Sharing in President Obama's Executive Order on Cyber Security

President Obama at 2013 SOTU
Yesterday President Obama signed an Executive Order aimed at helping nation harden its critical infrastructure against cyber attacks, and introduced it to the nation as part of his State of the Union address.

The Order states, "We can achieve these goals through a partnership with the owners and operators of critical infrastructure to improve cybersecurity information sharing and collaboratively develop and implement risk-based standards."

The partnership model has a history of success, and it is prudent to continue and support this model.

The nuclear power industry has an active partnership with the U.S. Department of Homeland Security specifically geared toward enhancing the security of commercial users of nuclear materials.

Under HSPD-7, the industry established the Nuclear Sector Coordinating Council (NSCC), and the government established the Government Coordinating Council (GCC).  These groups meet quarterly under the Critical Infrastructure Partnership Advisory Council (CIPAC) framework.

The NSCC/GCC provides an instrumental forum for organizations engaging in civilian uses of nuclear materials in the U.S. to discuss security issues and work together with our federal partners to enhance security and resilience.

The order also discusses the importance of information sharing. I could not agree more. The nuclear power industry in the U.S. has a proven record of responding in a timely manner to identified threats to the safe operations of our facilities.


Information sharing is integral to establishing a robust cyber security program. As I discussed in a previous blog post on nuclear power plant cybersecurity, our plants have been actively addressing the cyber threat for over 10 years.

The first questions that must be answered when establishing a security program are:
  1. What must be protected?
  2. What must it be protected from?
Information sharing has been instrumental in helping us stay on top of what we must be prepared to defend against.

Under the NSCC/GCC framework, the nuclear sector receives quarterly threat briefings at the SECRET level. The DHS also conducts monthly sector-specific unclassified threat briefings.

So, at a high level, the EO is moving in the right direction. But we cannot lose sight of good work already done.

This new emphasis on the adoption of cyber security practices must consider the existing regulatory frameworks and voluntary initiatives that are already in place.Complexity is the enemy of security. Streamlining and minimizing burden on private entities ensures that resources remain available to respond to real threats.

Ensuring that any new cyber security guidance, practices, or policies does not overlap or duplicate existing practices is essential. For addition details, please consult the NEI backgrounder on Cyber Security.

POSTSCRIPT: The Nuclear Energy Institute’s chief nuclear officer and senior vice president, Anthony R. (Tony) Pietrangelo, made the following comment about the cyber security executive order signed Tuesday by President Obama.

Tony Pietrangelo
“Commercial nuclear energy facilities are well protected from possible cyber threats. The nuclear energy industry has been implementing and improving cyber security controls since 2002, and the federal agency that oversees the nation’s nuclear energy facilities—the Nuclear Regulatory Commission—has established regulations that thoroughly monitor and inspect cyber security at all U.S. reactors.

“To ensure our constant readiness, the industry participates with government agencies to be aware of and assess its readiness for emerging cyber threats. Our facilities are essentially cyber islands, in that safety and control systems are not connected to business networks or the Internet. Unlike industries for which two-way data flow is critical, nuclear power plants do not require incoming data flow.

“Nuclear plants also are protected from grid instability, with multiple backup power supplies that provide for safe shutdown of a reactor in the event of a power blackout. Given that the NRC appropriately exercises authority over the protection of nuclear plant systems from potential cyber threats, it would be counterproductive to have dual oversight of these facilities.”

Comments

Popular posts from this blog

How Nanomaterials Can Make Nuclear Reactors Safer and More Efficient

The following is a guest post from Matt Wald, senior communications advisor at NEI. Follow Matt on Twitter at @MattLWald.

From the batteries in our cell phones to the clothes on our backs, "nanomaterials" that are designed molecule by molecule are working their way into our economy and our lives. Now there’s some promising work on new materials for nuclear reactors.

Reactors are a tough environment. The sub atomic particles that sustain the chain reaction, neutrons, are great for splitting additional uranium atoms, but not all of them hit a uranium atom; some of them end up in various metal components of the reactor. The metal is usually a crystalline structure, meaning it is as orderly as a ladder or a sheet of graph paper, but the neutrons rearrange the atoms, leaving some infinitesimal voids in the structure and some areas of extra density. The components literally grow, getting longer and thicker. The phenomenon is well understood and designers compensate for it with a …

Why America Needs the MOX Facility

If Isaiah had been a nuclear engineer, he’d have loved this project. And the Trump Administration should too, despite the proposal to eliminate it in the FY 2018 budget.

The project is a massive factory near Aiken, S.C., that will take plutonium from the government’s arsenal and turn it into fuel for civilian power reactors. The plutonium, made by the United States during the Cold War in a competition with the Soviet Union, is now surplus, and the United States and the Russian Federation jointly agreed to reduce their stocks, to reduce the chance of its use in weapons. Over two thousand construction workers, technicians and engineers are at work to enable the transformation.

Carrying Isaiah’s “swords into plowshares” vision into the nuclear field did not originate with plutonium. In 1993, the United States and Russia began a 20-year program to take weapons-grade uranium out of the Russian inventory, dilute it to levels appropriate for civilian power plants, and then use it to produce…

Nuclear Is a Long-Term Investment for Ohio that Will Pay Big

With 50 different state legislative calendars, more than half of them adjourn by June, and those still in session throughout the year usually take a recess in the summer. So springtime is prime time for state legislative activity. In the next few weeks, legislatures are hosting hearings and calling for votes on bills that have been battered back and forth in the capital halls.

On Tuesday, The Ohio Public Utilities Committee hosted its third round of hearings on the Zero Emissions Nuclear Resources Program, House Bill 178, and NEI’s Maria Korsnick testified before a jam-packed room of legislators.


Washingtonians parachuting into state debates can be a tricky platform, but in this case, Maria’s remarks provided national perspective that put the Ohio conundrum into context. At the heart of this debate is the impact nuclear plants have on local jobs and the local economy, and that nuclear assets should be viewed as “long-term investments” for the state. Of course, clean air and electrons …