Regulation on Cybersecurity in Nuclear Facilities
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
This regulation sets cybersecurity rules for nuclear facilities in Turkey. Operators must protect all digital assets linked to safety, security, and nuclear safeguards, assign a responsible cybersecurity manager, maintain an information security management system, and build cybersecurity into facility design and operations. It requires operators to classify digital assets by risk, keep inventories of critical assets, run regular risk assessments, manage vulnerabilities, control suppliers, keep access and system logs for at least two years, maintain backups, prepare incident response plans, report serious cyber incidents immediately, and submit incident reports within five business days. Existing licensed applicants and operators must submit a compliance action plan within six months, with a possible extension to one year if approved.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- Nuclear facility operators must create and maintain cybersecurity plans, incident response plans, and information security management systems.
- Operators must identify, classify, inventory, monitor, and protect all digital assets, with stronger controls for critical digital assets.
- Cyber incidents that may affect safety, security, or nuclear safeguards must be reported immediately, followed by a formal report within five business days.
Obligations
What this law requires
Operators must appoint a manager responsible for cybersecurity of all digital assets in the nuclear facility and include this role in the organizational structure.
Operators must establish, implement, maintain, and evaluate an information security management system that includes a cybersecurity policy and complies with current national and international standards.
Operators must identify all digital assets, determine their safety, security, and nuclear safeguards functions, assign criticality ratings, determine cybersecurity levels, and maintain a current inventory of critical digital assets including name, type, location, backup information, criticality rating, and asset owner.
Operators must conduct planned cybersecurity risk assessments at least annually for facilities containing reactors and at least every three years for other nuclear facilities, and must promptly conduct additional assessments when critical digital assets, threat information, or vulnerabilities change.
Operators must record all access, transactions, movements, and system events for digital assets completely, prevent unauthorized access to or alteration of those records, and retain all records for at least two years.