K05 assurance architecture
Control Mapping Register
Direct answer
K05 maps controls to external frameworks only where a bounded relationship is documented. Every mapping states its relationship and applicability limits; none is a universal compliance determination.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
No compliance shortcut. These records identify a documented relationship. They do not determine whether a framework applies to a named facility, whether a control fully implements a requirement, whether the control operates effectively, or whether a competent authority accepts the evidence.
DoD Directive 3000.09
| Control | Relationship | Reference | Applicability boundary |
|---|---|---|---|
| AUT-01 — Bounded autonomous action tiering | APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM | Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior | The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems. |
| PHY-01 — Multi-sensor disagreement management | APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM | Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior | The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems. |
| PHY-02 — Non-destructive delay and access denial | APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM | Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior | The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems. |
| PHY-03 — Counter-UAS authority separation | APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM | Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior | The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems. |
| EVD-01 — Tamper-evident decision receipts | APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM | Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior | The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems. |
INL Consequence-driven Cyber-informed Engineering
| Control | Relationship | Reference | Applicability boundary |
|---|---|---|---|
| GOV-01 — Authority and mission register | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| GOV-02 — Site-tailoring and applicability record | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| GOV-03 — Hazard and assurance-defeater register | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| ARC-01 — Critical-function decomposition | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| ARC-02 — Deterministic safety separation | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| ARC-03 — Trust-zone microsegmentation | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| ID-01 — Non-human workload identity | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| ID-02 — Privileged session control | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| SUP-01 — SBOM and component provenance | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| SUP-02 — Signed update and rollback | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| MGT-01 — BMC isolation and attestation | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| MGT-02 — Hardware-rooted attestation | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| OT-01 — Passive OT asset and dependency discovery | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| OT-02 — Physics-informed detection | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| OT-03 — Independent safe-state path | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| PWR-01 — Load-rejection and islanding assurance | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| CLG-01 — Cooling independent protection | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| TIM-01 — Assured time and holdover | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| AUT-01 — Bounded autonomous action tiering | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| AUT-02 — Causal response guard | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| AUT-03 — Multi-agent trust boundaries | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| AUT-04 — Model and data provenance and drift | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| PHY-01 — Multi-sensor disagreement management | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| PHY-02 — Non-destructive delay and access denial | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| PHY-03 — Counter-UAS authority separation | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| EM-01 — Electromagnetic resilience | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| REC-01 — Clean-room restoration | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| REC-02 — Critical-function recovery objectives | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| EVD-01 — Tamper-evident decision receipts | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| EVD-02 — Independent verification and replay | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| EVD-03 — Readiness downgrade on evidence failure | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
| OPS-01 — Incident command and deconfliction | INFORMS | Consequence prioritization and critical-function assurance | Useful for high-consequence pathway analysis; not a regulatory certification. |
NERC CIP
| Control | Relationship | Reference | Applicability boundary |
|---|---|---|---|
| GOV-01 — Authority and mission register | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| GOV-02 — Site-tailoring and applicability record | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| GOV-03 — Hazard and assurance-defeater register | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| PWR-01 — Load-rejection and islanding assurance | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| CLG-01 — Cooling independent protection | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| EVD-01 — Tamper-evident decision receipts | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| EVD-02 — Independent verification and replay | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| EVD-03 — Readiness downgrade on evidence failure | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
| OPS-01 — Incident command and deconfliction | MAY IMPLEMENT OR SUPPORT | Current applicable CIP standards and implementation plans | Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis. |
NIST SP 800-207
| Control | Relationship | Reference | Applicability boundary |
|---|---|---|---|
| GOV-01 — Authority and mission register | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| GOV-02 — Site-tailoring and applicability record | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| GOV-03 — Hazard and assurance-defeater register | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| ARC-01 — Critical-function decomposition | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| ARC-02 — Deterministic safety separation | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| ARC-03 — Trust-zone microsegmentation | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| ID-01 — Non-human workload identity | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| ID-02 — Privileged session control | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| SUP-01 — SBOM and component provenance | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| SUP-02 — Signed update and rollback | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| MGT-01 — BMC isolation and attestation | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| MGT-02 — Hardware-rooted attestation | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| OT-01 — Passive OT asset and dependency discovery | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| OT-02 — Physics-informed detection | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| OT-03 — Independent safe-state path | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| PWR-01 — Load-rejection and islanding assurance | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| CLG-01 — Cooling independent protection | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| TIM-01 — Assured time and holdover | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| AUT-01 — Bounded autonomous action tiering | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| AUT-02 — Causal response guard | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| AUT-03 — Multi-agent trust boundaries | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| AUT-04 — Model and data provenance and drift | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| PHY-01 — Multi-sensor disagreement management | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| PHY-02 — Non-destructive delay and access denial | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| PHY-03 — Counter-UAS authority separation | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| EM-01 — Electromagnetic resilience | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| REC-01 — Clean-room restoration | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| REC-02 — Critical-function recovery objectives | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| EVD-01 — Tamper-evident decision receipts | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| EVD-02 — Independent verification and replay | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| EVD-03 — Readiness downgrade on evidence failure | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
| OPS-01 — Incident command and deconfliction | INFORMS | Zero Trust Architecture principles | Applies to identity- and resource-centric access design; does not replace OT safety analysis. |
NIST SP 800-82 Rev. 3
| Control | Relationship | Reference | Applicability boundary |
|---|---|---|---|
| GOV-01 — Authority and mission register | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| GOV-02 — Site-tailoring and applicability record | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| GOV-03 — Hazard and assurance-defeater register | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| ARC-01 — Critical-function decomposition | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| ARC-02 — Deterministic safety separation | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| ARC-03 — Trust-zone microsegmentation | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| ID-01 — Non-human workload identity | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| ID-02 — Privileged session control | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| SUP-01 — SBOM and component provenance | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| SUP-02 — Signed update and rollback | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| MGT-01 — BMC isolation and attestation | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| MGT-02 — Hardware-rooted attestation | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| OT-01 — Passive OT asset and dependency discovery | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| OT-02 — Physics-informed detection | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| OT-03 — Independent safe-state path | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| PWR-01 — Load-rejection and islanding assurance | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| CLG-01 — Cooling independent protection | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| TIM-01 — Assured time and holdover | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| AUT-01 — Bounded autonomous action tiering | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| AUT-02 — Causal response guard | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| AUT-03 — Multi-agent trust boundaries | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| AUT-04 — Model and data provenance and drift | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| PHY-01 — Multi-sensor disagreement management | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| PHY-02 — Non-destructive delay and access denial | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| PHY-03 — Counter-UAS authority separation | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| EM-01 — Electromagnetic resilience | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| REC-01 — Clean-room restoration | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| REC-02 — Critical-function recovery objectives | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| EVD-01 — Tamper-evident decision receipts | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| EVD-02 — Independent verification and replay | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| EVD-03 — Readiness downgrade on evidence failure | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
| OPS-01 — Incident command and deconfliction | INFORMS | OT security program, architecture, risk, and control guidance | Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development. |
NRC 10 CFR Part 73
| Control | Relationship | Reference | Applicability boundary |
|---|---|---|---|
| GOV-01 — Authority and mission register | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| GOV-02 — Site-tailoring and applicability record | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| GOV-03 — Hazard and assurance-defeater register | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| ARC-01 — Critical-function decomposition | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| ARC-02 — Deterministic safety separation | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| ARC-03 — Trust-zone microsegmentation | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| OT-01 — Passive OT asset and dependency discovery | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| OT-02 — Physics-informed detection | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| OT-03 — Independent safe-state path | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| PWR-01 — Load-rejection and islanding assurance | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| CLG-01 — Cooling independent protection | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| PHY-01 — Multi-sensor disagreement management | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| PHY-02 — Non-destructive delay and access denial | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| PHY-03 — Counter-UAS authority separation | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| EM-01 — Electromagnetic resilience | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |
| OPS-01 — Incident command and deconfliction | MAY IMPLEMENT OR SUPPORT | 73.54/73.55 or 73.100/73.110/73.120 as selected and applicable | Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls. |