Comment on FR Doc # 2026-12989, NRC-2025-1303-0001, from Anonymous
Anonymous AnonymousOpposeIndividual
Summary: The commenter opposes the proposed requirement to use NIST SP 800-171 as the cybersecurity baseline for Safeguards Information (SGI). They argue that SGI requires a risk-based approach commensurate with its high security impact, rather than a fixed minimum baseline designed for less sensitive Controlled Unclassified Information (CUI).
I appreciate the Nuclear Regulatory Commission’s efforts to modernize the handling of Safeguards Information (SGI) by permitting secure networked architectures such as thin clients and virtual desktop infrastructure. These technologies can improve both security and operational efficiency when properly implemented.
However, I respectfully recommend that the Commission reconsider the proposed requirement in paragraph (g)(2)(iii) that systems “shall be protected by the cybersecurity controls described in an active and approved version of NIST Special Publication 800-171.”
NIST Special Publication 800-171 was developed to establish minimum security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. Its purpose is to provide a standardized baseline for a broad range of CUI types whose sensitivity and consequences of compromise vary considerably. The publication was not developed as a security framework for information whose unauthorized disclosure could facilitate radiological sabotage or other threats to national security.
Safeguards Information occupies a unique position within the CUI program. Although designated as CUI, SGI is protected under the Atomic Energy Act because unauthorized disclosure could reasonably be expected to increase the risk of radiological sabotage or theft of strategic nuclear material. These consequences are fundamentally different from those associated with most categories of CUI. As such, SGI warrants security requirements that are derived from the potential impact of compromise rather than from its administrative designation as CUI.
Unlike the federal Risk Management Framework, NIST SP 800-171 does not require organizations to categorize systems based on impact, select controls commensurate with those impacts, perform independent security assessments, or maintain an ongoing authorization decision based on organizational risk acceptance. Rather, it establishes a fixed minimum baseline intended for contractor systems handling CUI. While appropriate for many CUI applications, it does not provide a risk-based approach capable of scaling protections to the unique consequences associated with SGI.
The proposed rule would therefore establish the same cybersecurity baseline for systems storing SGI as would apply to systems processing substantially less sensitive categories of CUI. This approach does not adequately distinguish between information whose compromise may result primarily in economic or privacy harms and information whose compromise could directly affect the physical protection of nuclear facilities and materials.
A more appropriate regulatory approach would require security controls commensurate with the impact of unauthorized disclosure. The Commission could accomplish this by:
* requiring implementation of security controls derived from NIST SP 800-53 at a baseline appropriate to the assessed impact of compromise;
* requiring organizations to perform a documented system categorization and risk assessment to justify the selected control baseline; or
* specifying an enhanced control set that supplements NIST SP 800-171 with additional requirements for identification and authentication, boundary protection, continuous monitoring, audit logging, vulnerability management, incident response, and independent security assessment.
Any of these approaches would better align cybersecurity requirements with the unique sensitivity of SGI while remaining consistent with established NIST risk management principles.