Skip to main content
Image coming soon

SEC9883 Mastering IAEA Nuclear Security Series NSS-17-T Rev 1 for Critical Infrastructure Teams

$198.00
Adding to cart… The item has been added

What is the IAEA Nuclear Security Series NSS-17-T Rev course about?

Implementation-grade readiness for computer security at nuclear facilities under the IAEA standard Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

What situation is the IAEA Nuclear Security Series NSS-17-T Rev for?

High-assurance environments face recurring delays when assembling compliance artefacts for inspector review, especially due to misaligned technical controls, inconsistent documentation, and late-stage input chasing across IT, OT, and physical security functions.

Who is the IAEA Nuclear Security Series NSS-17-T Rev course for?

Compliance lead, security architect, or operations manager responsible for implementing and demonstrating cyber protections at nuclear or dual-use facilities subject to IAEA oversight.

What do you take away from the IAEA Nuclear Security Series NSS-17-T Rev course?

Produce a complete, inspection-ready NSS-17-T compliance package in one coordinated cycle Standardize control mapping between technical systems and IAEA requirements Reduce rework by aligning IT, OT, and security teams before audit onset Build reusable templates for control validation logs, access reviews, and incident response integration Gain clarity on which artefacts inspectors prioritize during site visits.

What's included with your purchase?

12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.

What does the IAEA Nuclear Security Series NSS-17-T Rev cover on delivery and format?

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 90 minutes per module, designed for completion over six weeks with practical application between sessions.

How does this compare to the alternatives?

Unlike generic cybersecurity courses, this program focuses exclusively on IAEA NSS-17-T Rev 1 implementation challenges in nuclear environments, offering field-tested approaches not available in public guidance documents.

What does the IAEA Nuclear Security Series NSS-17-T Rev cover on frequently asked?

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

More answers: what you get with every course, refund policy, all help answers.

A tailored course, built for your situation

Mastering IAEA Nuclear Security Series NSS-17-T Rev 1 for Critical Infrastructure Teams

Implementation-grade readiness for computer security at nuclear facilities under the IAEA standard

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Audit readiness packages requiring last-minute evidence coordination across teams

The situation this course is for

High-assurance environments face recurring delays when assembling compliance artefacts for inspector review, especially due to misaligned technical controls, inconsistent documentation, and late-stage input chasing across IT, OT, and physical security functions.

Who this is for

Compliance lead, security architect, or operations manager responsible for implementing and demonstrating cyber protections at nuclear or dual-use facilities subject to IAEA oversight

Who this is not for

Entry-level auditors, general IT staff without nuclear sector exposure, or consultants focused solely on non-critical infrastructure frameworks

What you walk away with

  • Produce a complete, inspection-ready NSS-17-T compliance package in one coordinated cycle
  • Standardize control mapping between technical systems and IAEA requirements
  • Reduce rework by aligning IT, OT, and security teams before audit onset
  • Build reusable templates for control validation logs, access reviews, and incident response integration
  • Gain clarity on which artefacts inspectors prioritize during site visits

The 12 modules (with all 144 chapters)

Module 1. Understanding NSS-17-T Rev 1 Scope and Application Boundaries
Define where the standard applies within nuclear facilities and identify excluded systems.
12 chapters in this module
  1. Overview of IAEA Nuclear Security Series structure and purpose
  2. Key definitions: computer security, nuclear facility, safety vs security
  3. Scope determination for multi-system environments
  4. Differentiating between safety-related and security-sensitive systems
  5. Application to new builds versus legacy installations
  6. Handling dual-use technologies under NSS-17-T
  7. Mapping facility zones to digital asset categories
  8. Identifying systems subject to external connectivity rules
  9. Exclusions for purely analog or mechanical components
  10. Clarifying overlap with IEC 62645 and other standards
  11. Use of risk assessments to refine scope boundaries
  12. Documenting scope decisions for auditor review
Module 2. Establishing Governance and Responsibility Frameworks
Assign clear roles and accountability for computer security implementation.
12 chapters in this module
  1. Defining the Computer Security Management System (CSMS)
  2. Role of senior management in policy approval
  3. Designating the Computer Security Officer (CSO)
  4. Responsibilities of system owners and custodians
  5. Interface between CSMS and existing safety management
  6. Integrating with national regulatory reporting obligations
  7. Internal audit function independence requirements
  8. Escalation paths for identified vulnerabilities
  9. Coordination with physical protection system leads
  10. Maintaining organizational charts for inspector access
  11. Updating role assignments after personnel changes
  12. Documenting delegation authority during absences
Module 3. Conducting Facility-Specific Risk Assessments
Apply structured methodology to identify and prioritize cyber threats.
12 chapters in this module
  1. Adapting ISO/IEC 27005 for nuclear context
  2. Threat actor profiling: insider, outsider, state-sponsored
  3. Vulnerability identification in OT and embedded systems
  4. Impact analysis tied to radiological consequences
  5. Likelihood estimation using historical event databases
  6. Risk tolerance thresholds set by facility operators
  7. Use of scenario modeling for cascading failures
  8. Incorporating lessons from past incidents like Stuxnet
  9. Third-party involvement in independent validation
  10. Linking risk findings to specific NSS-17-T controls
  11. Updating assessments after major system changes
  12. Presenting risk register to technical steering group
Module 4. Designing Defense-in-Depth Architectures
Implement layered protection strategies across digital domains.
12 chapters in this module
  1. Zone and conduit model application in nuclear plants
  2. Segmentation between business IT and process control networks
  3. Air-gapped system justification and monitoring
  4. Secure remote access mechanisms for vendors
  5. Physical isolation of critical controllers
  6. Use of unidirectional gateways for data export
  7. Hardening guidelines for Windows-based engineering stations
  8. Network intrusion detection tailored to low-bandwidth OT
  9. Wireless communication restrictions and approvals
  10. Secure configuration baselines for industrial devices
  11. Monitoring encrypted traffic without disrupting operations
  12. Response procedures for detected network anomalies
Module 5. Managing Access Control and Identity Verification
Ensure only authorized individuals interact with sensitive systems.
12 chapters in this module
  1. Principle of least privilege in operator workstations
  2. Multi-factor authentication for administrative accounts
  3. Biometric use limitations in secure areas
  4. Session timeout policies for human-machine interfaces
  5. Privileged access management for vendor support
  6. Role-based access control design patterns
  7. Logging of all user login and command activities
  8. Periodic review of active accounts and permissions
  9. Integration with physical access control systems
  10. Handling emergency override credentials securely
  11. Revocation procedures during employee termination
  12. Demonstrating access control effectiveness to inspectors
Module 6. Protecting Systems During Development and Procurement
Embed security requirements into acquisition and build processes.
12 chapters in this module
  1. Security specifications in vendor contracts
  2. Evaluation of supplier cybersecurity practices
  3. Secure software development lifecycle adaptation
  4. Use of trusted components and open source vetting
  5. Configuration management for firmware updates
  6. Delivery media integrity checks
  7. Onsite acceptance testing protocols
  8. Documentation requirements for as-built systems
  9. Secure handover from construction to operations
  10. Penetration testing before commissioning
  11. Handling known vulnerabilities in purchased systems
  12. Maintaining bill of materials for future audits
Module 7. Operating Securely Through Daily Procedures
Maintain protection through routine operational discipline.
12 chapters in this module
  1. Daily log review responsibilities for shift supervisors
  2. Change management process for system modifications
  3. Patch management balancing security and availability
  4. Malware protection in air-gapped environments
  5. Media handling rules for USB drives and laptops
  6. Backup frequency and offline storage requirements
  7. Incident reporting pathways during normal operations
  8. Scheduled vulnerability scanning without disruption
  9. Clock synchronization across distributed systems
  10. Secure disposal of retired digital equipment
  11. Operator training refresh intervals
  12. Shift turnover checklist inclusion of cyber status
Module 8. Detecting and Responding to Cybersecurity Events
Prepare for and manage actual or suspected intrusions.
12 chapters in this module
  1. Event classification schema based on impact potential
  2. Initial detection indicators in control system behavior
  3. Containment strategies without triggering safety systems
  4. Forensic data collection preserving chain of custody
  5. Coordination with national computer emergency response teams
  6. Notification timelines for regulators and IAEA
  7. Communication protocols during ongoing incidents
  8. Recovery procedures validated against backup integrity
  9. Post-event root cause analysis methods
  10. Updating risk assessments after real events
  11. Lessons learned integration into training programs
  12. Inspector access to incident records during reviews
Module 9. Ensuring Supply Chain and Third-Party Controls
Extend security expectations beyond organizational boundaries.
12 chapters in this module
  1. Vendor prequalification questionnaires
  2. Remote maintenance session monitoring
  3. Temporary access provisioning with expiry
  4. Secure file transfer mechanisms for diagnostics
  5. Contractual liability clauses for cyber breaches
  6. Validation of third-party patch authenticity
  7. Tracking service provider compliance status
  8. Onsite contractor workstation rules
  9. Use of demilitarized zones for external connections
  10. Auditing subcontractor adherence to requirements
  11. Managing end-of-life support transitions
  12. Reporting third-party issues to internal CSO
Module 10. Maintaining Documentation and Audit Readiness
Produce consistent, accessible records for inspection cycles.
12 chapters in this module
  1. Required documents listed in NSS-17-T Annex B
  2. Version control for policy and procedure files
  3. Storage location requirements for audit access
  4. Retention periods aligned with licensing conditions
  5. Formatting standards for inspector readability
  6. Indexing control mappings for rapid lookup
  7. Evidence collection schedule before inspections
  8. Cross-referencing technical logs to control claims
  9. Preparing facility walkthrough narratives
  10. Compiling organizational charts and contact lists
  11. Updating documentation after corrective actions
  12. Demonstrating continuous compliance between reviews
Module 11. Training and Awareness Program Design
Build organizational competence through structured learning.
12 chapters in this module
  1. Defining audience segments: operators, engineers, managers
  2. Annual training requirement fulfillment
  3. Content specificity for different job functions
  4. Hands-on exercises simulating cyber events
  5. Testing knowledge retention post-training
  6. Awareness campaigns for phishing and social engineering
  7. Incorporating lessons from industry incidents
  8. Recordkeeping for attendance and completion
  9. Evaluating program effectiveness annually
  10. Refresher training after system upgrades
  11. Tailoring messages for non-technical staff
  12. Linking training outcomes to performance metrics
Module 12. Preparing for Inspector Engagement and Follow-Up
Enable smooth, confident interactions during official reviews.
12 chapters in this module
  1. Scheduling coordination with national authorities
  2. Pre-inspection internal readiness checks
  3. Designating primary and alternate points of contact
  4. Facility tour route planning including control rooms
  5. Providing read-only access to digital repositories
  6. Handling document requests efficiently
  7. Responding to clarification questions promptly
  8. Recording inspector observations accurately
  9. Developing action plans for identified gaps
  10. Tracking corrective measures to closure
  11. Submitting follow-up reports on time
  12. Archiving inspection records for future reference

How this maps to your situation

  • Scope definition and governance setup
  • Risk-informed control selection
  • Technical implementation across IT/OT
  • Operational sustainability and inspection readiness

Before vs. after

Before
Fragmented understanding of NSS-17-T requirements, inconsistent control application, reactive evidence gathering
After
Unified implementation approach, standardized documentation, proactive audit preparation

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per module, designed for completion over six weeks with practical application between sessions.

If nothing changes
Without structured implementation, organizations face delayed approvals, repeated findings during inspections, and increased scrutiny from national regulators and the IAEA.

How this compares to the alternatives

Unlike generic cybersecurity courses, this program focuses exclusively on IAEA NSS-17-T Rev 1 implementation challenges in nuclear environments, offering field-tested approaches not available in public guidance documents.

Frequently asked

Is this course aligned with the latest version of NSS-17-T?
Yes, the course covers NSS-17-T Rev 1 in full, published right now.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Who typically enrolls in this course?
Security architects, compliance leads, and operations managers working at nuclear or dual-use facilities subject to IAEA oversight.
$199 one-time. Approximately 90 minutes per module, designed for completion over six weeks with practical application between sessions..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee·144 chapters·Hand-built playbook included· Account access within 24 hours