EXCEL’s Critical Infrastructure Protection Services team is organized to support clients and reduce operating and maintenance costs in the physical, cyber, and information security areas. EXCEL provides immediate access to a dynamic team of subject-matter experts with extensive nuclear industry and regulatory experience.
The cost of maintaining a physical security program at a licensed nuclear power plant has grown over the years. With increasing requirements, more aggressive performance testing by NRC, and post-9/11 actions, the security budget has grown enough to get the attention of decision makers at the corporate level. EXCEL has had tremendous success in recent years assisting plants by reviewing the security protective strategy and making independent recommendations on changes that can be accomplished under 10 CFR 50.54(p), with additional reviews of changes possible under 10 CFR 50.90. EXCEL has also been successful in providing on-demand licensing and regulatory assistance to clients. This assistance includes inspection support, preparing for interactions with the regulator, developing and/or reviewing licensing or change packages, and assisting and mentoring staff.
EXCEL’s team has assisted clients and the nuclear industry in preparing for NRC cyber security full implementation inspections, establishing appropriate safeguards to protect the digital assets and systems from unauthorized use, writing guidance documents, and recommending innovative solutions for addressing potential areas of weakness. During readiness assessments for the NRC full implementation inspection, EXCEL conducts a review of the client’s Cyber Security Plan (CSP) and program implementing procedures and activities being conducted to be in full compliance with the CSP. This includes walkdowns of critical digit assets (CDAs); CDA assessment reviews; and review of portable media and mobile device (PMMD) controls, and Kiosk controls and processes.
Some of the recent nuclear security projects have included assisting clients in the design, inspection, and validation of information protection programs, including Classified Information, Safeguards Information, Sensitive Security-Related Information, and other categories of information which, if improperly stored and protected, could result in a threat to the facility and the public health and safety.