2.6.
A standard approach to protect systems in a structured way according to a graded approach is to use the concepts of computer security levels and computer security zones. The computer security level assigned to a computer security zone is based on the highest degree of security protection required by any facility function performed by a system within that zone. The same computer security level is assigned to all systems within that zone. Typically, a nuclear facility zone model consists of many different zones, and several zones may have the same computer security level assigned.
2.7.
A facility function is a coordinated set of actions and processes that need to be performed at a nuclear facility. Facility functions include functions that are important or related to nuclear security and functions that are important or related to nuclear safety (i.e. safety functions).2 Facility functions are assigned to systems3, each of which performs one or more of these functions.
2.8.
A computer security level is a designation that indicates the degree of security protection required for a facility function and consequently for the system that performs that function. Each computer security level is associated with a set of requirements imposed by the operator to ensure that the appropriate level of protection is provided to digital assets assigned to that level using a graded approach. Each computer security level will need different sets of computer security measures to satisfy the computer security requirements for that level.
2.9.
A computer security zone is a logical and/or physical grouping of digital assets that are assigned to the same computer security level and that share common computer security requirements owing to inherent properties of the systems or their connections to other systems (and, if necessary, additional criteria). The use of computer security zones is intended to simplify the administration, communication and application of computer security measures.4
2.10.
Additional criteria for defining computer security zones may include the following:
Organizational responsibilities, for example different computer security zones for systems that are the responsibility of different departments;
The need to maintain separation, for example different computer security zones for redundant systems at the same computer security level performing the same facility function;
Zones already defined for other purposes, for example a computer security zone defined for simplicity to be the same as a zone already established for administrative or communication purposes.
2.11.
The idealized relationships between the concepts of facility function(s), computer security level(s), system(s) and computer security zone(s) are illustrated in Fig. 1.
2.12.
Each of the idealized relationships is labelled in Fig. 1, and the labelled text below describes each relationship:
Each facility function is assigned to a single computer security level.
Each computer security level may be applied to one or more facility functions.
Each facility function is ideally assigned to one system, where possible.5
Each system ideally performs one facility function, where possible.6
Each computer security level may be applied to one or more security zones.
Each computer security zone is assigned a single computer security level.
Each system is placed within a single computer security zone, where possible.7
Each computer security zone may consist of one or more systems.