Complete written NRC cyber-event follow-up after telephonic notification

Use 10 CFR 73.77 - Cyber security event notifications to review this narrow operational decision without extending the source beyond its stated scope.

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defensePlaybook · 3 min read
Executive summary

What you need to know

Use 10 CFR 73.77 - Cyber security event notifications to review this narrow operational decision without extending the source beyond its stated scope.

Potentially affected

Teams, systems, services, or facilities within the stated scope of 10 CFR 73.77 - Cyber security event notifications

DSE recommendation

Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.

Keep this document to one review outcome: Complete written NRC cyber-event follow-up after telephonic notification. Only the official source and traced locations below supply facts. Confirm applicability before acting.

Source fact:

The official 10 CFR 73.77 – Cyber security event notifications from U.S. Nuclear Regulatory Commission via eCFR supports the following bounded statements:

  • Under 10 CFR 73, if the licensee subsequently retracts a telephonic notification made under this section as not meeting the threshold of a reportable event after it has submitted a written security follow-up report required by this paragraph, then the licensee must submit a revised written security follow-up report in accordance with this paragraph. The research record locates this support at 10 CFR 73.77(d)(10) (eCFR anchor p-73.77(d)(10)).
  • Under 10 CFR 73, each licensee making an initial telephonic notification of security events to the NRC according to the provisions of paragraphs (a)(1), (a)(2)(i), and (a)(2)(ii) of this section must also submit a written security follow-up report to the NRC within 60 days of the telephonic notification in accordance with section 73.4. The research record locates this support at 10 CFR 73.77(d) (eCFR anchor p-73.77(d)).

Keep the evidence boundary at these traced claims. They support a review of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths; they do not support conclusions outside the source’s stated conditions.

What the source does not establish

NRC regulation for covered licensees and event categories; classification, timing, protected details, parallel reporting, records, and current NRC guidance require qualified review. It does not establish a deployment’s current state, authorize a production change, prove compliance, or show that identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel are healthy. Documented options are review inputs, not universal mandates.

Applicability questions

  • For source statement 1 at 10 CFR 73.77(d)(10) (eCFR anchor p-73.77(d)(10)), which observable configuration, record, or test can confirm applicability here?
  • For source statement 2 at 10 CFR 73.77(d) (eCFR anchor p-73.77(d)), which observable configuration, record, or test can confirm applicability here?
  • Which owner can attest to the recorded state of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths, including exceptions?
  • What baseline for identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel must accompany the source-specific observation?
  • Which success, stop, and escalation criteria are written before testing begins?

DSE recommendation:

DSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths, observed and expected states, owner, and reason for deviation.

Do not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel. Handle credentials, keys, recovery data, and personal information through approved secure channels.

Verification and evidence

Evidence should let another reviewer reproduce this decision. Retain observations beside the traced locations 10 CFR 73.77(d)(10) (eCFR anchor p-73.77(d)(10)); 10 CFR 73.77(d) (eCFR anchor p-73.77(d)). Favor asset and firmware inventories, configuration exports, event tests, inspections, alarm response records, and maintenance findings, linked to stable identifiers, time, and operator.

Record the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.

Official references

Primary reference

Review the official source

10 CFR 73.77 - Cyber security event notifications · Verified August 26, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE