Comment on FR Doc # 2026-12989, NRC-2025-1303-0001, from Muhammad Ali Zeghum
Muhammad Ali ZeghumSupportBusiness
Summary: Muhammad Ali Zeghum, Head of Security at Masdar Clean Energy, supports the NRC's shift toward a performance-based physical-security framework. He suggests strengthening the rule by requiring evidence of program-level maturity across seven domains, codifying a Global Security Operations Centre (GSOC) architecture, and aligning requirements with operational-technology security standards.
Public Comment
RE: Anchoring the Performance-Based Physical-Security Framework in Enterprise Programme
Docket ID: NRC-2025-1303 | 91 FR 38928 | U.S. Nuclear Regulatory Commission | Notice of Proposed Rulemaking, 26 June 2026
To the U.S. Nuclear Regulatory Commission:
I am Muhammad Ali Zeghum, ASIS-International Certified Protection Professional and Head of Security at a sovereign clean-energy organisation whose portfolio spans more than fifty international project sites. I write in personal capacity, as a practitioner in enterprise physical-security programme architecture, on the Commission's proposed shift from prescriptive, decades-old physical-security requirements to a performance-based, risk-informed framework. The direction of travel is correct. I offer three observations to strengthen the final rule.
First, a performance-based framework should require licensees to demonstrate programme-level maturity, not merely technology deployment. Modern enterprise physical-security programmes at sovereign-energy and critical-infrastructure organisations organise the discipline into seven anchored domains: governance and risk; threat and vulnerability assessment; physical asset protection design; operations doctrine; personnel and training; incident management and business continuity; and compliance and assurance. The final rule would be materially strengthened by treating maturity across these seven domains as the risk-informed evidence base. This moves the assessment beyond the technology layer to the programme-architecture layer, where the largest gaps between installed capability and delivered security posture actually live.
Second, the framework should expressly recognise the Global Security Operations Centre as the integration point that turns fragmented multi-vendor installations into a coherent operational picture. In production deployments across sovereign clean-energy, government-healthcare, port, financial, and pharmaceutical-logistics environments, a three-layer GSOC architecture (field and site systems; Physical Security Information Management correlation; enterprise command and governance) consistently delivers subsystem uptime above 95 percent, sub-three-minute alarm response on validated events, alarm accuracy in the mid-90 percent range, and full regulatory-compliance coverage across applied frameworks. Codifying the GSOC reference architecture as part of the performance-based rule would give licensees a defensible target model rather than leaving each licensee to reinvent the design.
Third, modernised physical-security requirements should be aligned with the operational-technology security posture. A compromised access-control panel is a cyber intrusion path; a physical intrusion is a network access path. Explicit alignment with NIST Special Publication 800-82 Revision 3 (Guide to Operational Technology Security) and the CISA Cross-Sector Cybersecurity Performance Goals at the physical-cyber convergence layer would eliminate the gap between two parallel compliance regimes that today lives at the interface.
I offer these observations grounded in sixteen years of enterprise physical-security practice across sovereign clean-energy, government-healthcare, port, financial, pharmaceutical logistics, and multi-sector commercial-security portfolios. My detailed methodology, including the seven-domain reference model and the GSOC layered architecture, is documented in the whitepaper "Physical Security Programme Architecture for Clean Energy and Critical Infrastructure" (Zenodo, DOI 10.5281/zenodo.21278346). I remain available for direct engagement with Commission staff on any of the observations above.
Respectfully submitted,
Muhammad Ali Zeghum, CPP
Head of Security, Masdar Clean Energy — Abu Dhabi Future Energy Company (ADFEC)
Email: muhammadalizeghum1616@gmail.com
LinkedIn: linkedin.com/in/muhammad-ali-zeghum-cpp-3aab8069