What is the IAEA Nuclear Security Series NSS-17-T Rev course about?
Implementation-grade readiness for computer security at nuclear facilities under the IAEA standard Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the IAEA Nuclear Security Series NSS-17-T Rev for?
High-assurance environments face recurring delays when assembling compliance artefacts for inspector review, especially due to misaligned technical controls, inconsistent documentation, and late-stage input chasing across IT, OT, and physical security functions.
Who is the IAEA Nuclear Security Series NSS-17-T Rev course for?
Compliance lead, security architect, or operations manager responsible for implementing and demonstrating cyber protections at nuclear or dual-use facilities subject to IAEA oversight.
What do you take away from the IAEA Nuclear Security Series NSS-17-T Rev course?
Produce a complete, inspection-ready NSS-17-T compliance package in one coordinated cycle Standardize control mapping between technical systems and IAEA requirements Reduce rework by aligning IT, OT, and security teams before audit onset Build reusable templates for control validation logs, access reviews, and incident response integration Gain clarity on which artefacts inspectors prioritize during site visits.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the IAEA Nuclear Security Series NSS-17-T Rev cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 90 minutes per module, designed for completion over six weeks with practical application between sessions.
How does this compare to the alternatives?
Unlike generic cybersecurity courses, this program focuses exclusively on IAEA NSS-17-T Rev 1 implementation challenges in nuclear environments, offering field-tested approaches not available in public guidance documents.
What does the IAEA Nuclear Security Series NSS-17-T Rev cover on frequently asked?
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
Mastering IAEA Nuclear Security Series NSS-17-T Rev 1 for Critical Infrastructure Teams
Implementation-grade readiness for computer security at nuclear facilities under the IAEA standard
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
High-assurance environments face recurring delays when assembling compliance artefacts for inspector review, especially due to misaligned technical controls, inconsistent documentation, and late-stage input chasing across IT, OT, and physical security functions.
Who this is for
Compliance lead, security architect, or operations manager responsible for implementing and demonstrating cyber protections at nuclear or dual-use facilities subject to IAEA oversight
Who this is not for
Entry-level auditors, general IT staff without nuclear sector exposure, or consultants focused solely on non-critical infrastructure frameworks
What you walk away with
- Produce a complete, inspection-ready NSS-17-T compliance package in one coordinated cycle
- Standardize control mapping between technical systems and IAEA requirements
- Reduce rework by aligning IT, OT, and security teams before audit onset
- Build reusable templates for control validation logs, access reviews, and incident response integration
- Gain clarity on which artefacts inspectors prioritize during site visits
The 12 modules (with all 144 chapters)
- Overview of IAEA Nuclear Security Series structure and purpose
- Key definitions: computer security, nuclear facility, safety vs security
- Scope determination for multi-system environments
- Differentiating between safety-related and security-sensitive systems
- Application to new builds versus legacy installations
- Handling dual-use technologies under NSS-17-T
- Mapping facility zones to digital asset categories
- Identifying systems subject to external connectivity rules
- Exclusions for purely analog or mechanical components
- Clarifying overlap with IEC 62645 and other standards
- Use of risk assessments to refine scope boundaries
- Documenting scope decisions for auditor review
- Defining the Computer Security Management System (CSMS)
- Role of senior management in policy approval
- Designating the Computer Security Officer (CSO)
- Responsibilities of system owners and custodians
- Interface between CSMS and existing safety management
- Integrating with national regulatory reporting obligations
- Internal audit function independence requirements
- Escalation paths for identified vulnerabilities
- Coordination with physical protection system leads
- Maintaining organizational charts for inspector access
- Updating role assignments after personnel changes
- Documenting delegation authority during absences
- Adapting ISO/IEC 27005 for nuclear context
- Threat actor profiling: insider, outsider, state-sponsored
- Vulnerability identification in OT and embedded systems
- Impact analysis tied to radiological consequences
- Likelihood estimation using historical event databases
- Risk tolerance thresholds set by facility operators
- Use of scenario modeling for cascading failures
- Incorporating lessons from past incidents like Stuxnet
- Third-party involvement in independent validation
- Linking risk findings to specific NSS-17-T controls
- Updating assessments after major system changes
- Presenting risk register to technical steering group
- Zone and conduit model application in nuclear plants
- Segmentation between business IT and process control networks
- Air-gapped system justification and monitoring
- Secure remote access mechanisms for vendors
- Physical isolation of critical controllers
- Use of unidirectional gateways for data export
- Hardening guidelines for Windows-based engineering stations
- Network intrusion detection tailored to low-bandwidth OT
- Wireless communication restrictions and approvals
- Secure configuration baselines for industrial devices
- Monitoring encrypted traffic without disrupting operations
- Response procedures for detected network anomalies
- Principle of least privilege in operator workstations
- Multi-factor authentication for administrative accounts
- Biometric use limitations in secure areas
- Session timeout policies for human-machine interfaces
- Privileged access management for vendor support
- Role-based access control design patterns
- Logging of all user login and command activities
- Periodic review of active accounts and permissions
- Integration with physical access control systems
- Handling emergency override credentials securely
- Revocation procedures during employee termination
- Demonstrating access control effectiveness to inspectors
- Security specifications in vendor contracts
- Evaluation of supplier cybersecurity practices
- Secure software development lifecycle adaptation
- Use of trusted components and open source vetting
- Configuration management for firmware updates
- Delivery media integrity checks
- Onsite acceptance testing protocols
- Documentation requirements for as-built systems
- Secure handover from construction to operations
- Penetration testing before commissioning
- Handling known vulnerabilities in purchased systems
- Maintaining bill of materials for future audits
- Daily log review responsibilities for shift supervisors
- Change management process for system modifications
- Patch management balancing security and availability
- Malware protection in air-gapped environments
- Media handling rules for USB drives and laptops
- Backup frequency and offline storage requirements
- Incident reporting pathways during normal operations
- Scheduled vulnerability scanning without disruption
- Clock synchronization across distributed systems
- Secure disposal of retired digital equipment
- Operator training refresh intervals
- Shift turnover checklist inclusion of cyber status
- Event classification schema based on impact potential
- Initial detection indicators in control system behavior
- Containment strategies without triggering safety systems
- Forensic data collection preserving chain of custody
- Coordination with national computer emergency response teams
- Notification timelines for regulators and IAEA
- Communication protocols during ongoing incidents
- Recovery procedures validated against backup integrity
- Post-event root cause analysis methods
- Updating risk assessments after real events
- Lessons learned integration into training programs
- Inspector access to incident records during reviews
- Vendor prequalification questionnaires
- Remote maintenance session monitoring
- Temporary access provisioning with expiry
- Secure file transfer mechanisms for diagnostics
- Contractual liability clauses for cyber breaches
- Validation of third-party patch authenticity
- Tracking service provider compliance status
- Onsite contractor workstation rules
- Use of demilitarized zones for external connections
- Auditing subcontractor adherence to requirements
- Managing end-of-life support transitions
- Reporting third-party issues to internal CSO
- Required documents listed in NSS-17-T Annex B
- Version control for policy and procedure files
- Storage location requirements for audit access
- Retention periods aligned with licensing conditions
- Formatting standards for inspector readability
- Indexing control mappings for rapid lookup
- Evidence collection schedule before inspections
- Cross-referencing technical logs to control claims
- Preparing facility walkthrough narratives
- Compiling organizational charts and contact lists
- Updating documentation after corrective actions
- Demonstrating continuous compliance between reviews
- Defining audience segments: operators, engineers, managers
- Annual training requirement fulfillment
- Content specificity for different job functions
- Hands-on exercises simulating cyber events
- Testing knowledge retention post-training
- Awareness campaigns for phishing and social engineering
- Incorporating lessons from industry incidents
- Recordkeeping for attendance and completion
- Evaluating program effectiveness annually
- Refresher training after system upgrades
- Tailoring messages for non-technical staff
- Linking training outcomes to performance metrics
- Scheduling coordination with national authorities
- Pre-inspection internal readiness checks
- Designating primary and alternate points of contact
- Facility tour route planning including control rooms
- Providing read-only access to digital repositories
- Handling document requests efficiently
- Responding to clarification questions promptly
- Recording inspector observations accurately
- Developing action plans for identified gaps
- Tracking corrective measures to closure
- Submitting follow-up reports on time
- Archiving inspection records for future reference
How this maps to your situation
- Scope definition and governance setup
- Risk-informed control selection
- Technical implementation across IT/OT
- Operational sustainability and inspection readiness
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 90 minutes per module, designed for completion over six weeks with practical application between sessions.
How this compares to the alternatives
Unlike generic cybersecurity courses, this program focuses exclusively on IAEA NSS-17-T Rev 1 implementation challenges in nuclear environments, offering field-tested approaches not available in public guidance documents.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.