Search NASA⌕ Search

SEARCH · Search NASA

Results for “SECURITY MANAGEMENT”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

1. Physical Security Engineering by Design for Nuclear Facilities; 2. Nuclear Power Plant Site Security Management – A Security Strategy; 3. The UAE Women in Nuclear Energy Security

1. Security by design, or SeBD, is a comprehensive approach that integrates the physical protection system of a nuclear plant into every stage of its existence. This includes planning, designing, constructing, commissioning, and operating the facility, using a combination of analytical, physical, technological, and procedural measures. Essentially, SeBD involves intentionally applying and incorporating security into all aspects of design and operation throughout the entire lifecycle of a facility. By implementing this methodology throughout various phases such as program development, process implementation, staff training and procedures management in conjunction with plant equipment, facilities can be optimized to minimize security risks without compromising functional design requirements. This ultimately improves the overall security posture of the site and reduces the need for costly modifications or additional security resources post-design. 2. A site security strategy is a living document that is revised on a periodic or event-driven basis, ensuring that site security operations and corresponding procedures provide long-term, effective protection for the entire nuclear power plant (NPP) site. A site security strategy aims to mitigate threats across the entire NPP site via in-depth defense approaches and mutual support; therefore, if a layer is omitted or altered, then the effect across all layers must be re-evaluated. Therefore, the aim of the site security strategy is to provide an appropriate, scalable security regime that deters, denies, delays, and detects incidents and, equally importantly, reassures legitimate users and the regulator that due diligence and regulatory compliance have been achieved, ensuring that the site is safe and secure. Robust access control for vehicles and pedestrians is at the heart of the strategy. Vehicle and pedestrian searching and screening are seen as the strongest mitigation methods against vehicle- and pedestrian-borne attacks. The security strategy must also be supported through comprehensive staff training and the development of robust processes, procedures, and planning. If all these measures are to be effective, then training must be implemented during each phase of construction, partial operation/commissioning, and full operation. No single element of site security is completely isolated from the influence of other elements. Ideally, consideration of all key elements will result in a security strategy that is integrated and proportional to the threat and that does not over specify individual security solutions through the application of isolated measures but rather applies a holistic, all-encompassing approach. 3. When women enter the labor force, numerous positive outcomes emerge, including increased GDP, educational gains, and decreased maternal mortality. Despite these benefits, women's employment rates and equality vary significantly worldwide as does support for women in the workforce. This paper will explore the multifaceted benefits of women's employment, the factors influencing labor force participation rates, and the urgency to achieve gender equality as outlined in the 2015 United Nations Sustainable Development Goals (SDGs). It will then examine the emerging presence of women in the traditionally male-dominated nuclear field, specifically within the United Arab Emirates (UAE) as a testament to their resilience and determination to break social norms and advance gender equality.

Zineddin, Dr. Z.↗

Federal Facility Agreement and Consent Order Nevada National Security Site Use Restriction Management Plan

This Use Restriction Management Plan (URMP) provides the information needed to create, modify, and manage use restrictions (URs) for sites on the Nevada National Security Site (NNSS), and sites accessed through the NNSS main gate, that were closed using the corrective action alternative (CAA) of closure in place under the Federal Facility Agreement and Consent Order (FFACO) (1996, as amended).

54 ENVIRONMENTAL SCIENCES↗

Federal Facility Agreement and Consent Order: Nevada National Security Site Use Restriction Management Plan with ROTC 1

This Use Restriction Management Plan (URMP) provides the information needed to create, modify, and manage use restrictions (URs) for sites on the Nevada National Security Site (NNSS), and sites accessed through the NNSS main gate, that were closed using the corrective action alternative (CAA) of closure in place under the Federal Facility Agreement and Consent Order (FFACO) (1996, as amended). (Note: This pertains to those FFACO sites not managed by the U.S. Department of Energy [DOE], Legacy Management.) The closure in place alternative is used for sites closed with residual contamination at levels requiring corrective action as determined using the FFACO process. The URs contain and control all requirements for long-term monitoring. This URMP also serves as the single repository of the URs implemented under the FFACO that identify use restricted areas and contain the current requirements for inspections, maintenance, and monitoring of the UR. The requirements in these URs replace all requirements listed in previous documentation. This consolidates post-closure monitoring requirements into a single source that ensures completeness and consistency of UR requirements and information. Standardized UR forms were developed to clearly document post-closure requirements that are consistent with current protocols and to ensure consistent information is contained in the URs. Standard notification, summary, and site controls statements were developed for all URs with provisions to insert site-specific options in the text. Current protocols for Industrial Sites and Soils URs are defined in this document and in the Soils Risk-Based Corrective Action (RBCA) Evaluation Process (DOE/EMNV, 2018). The standardized UR forms that have been approved to date are listed in Appendix A. Additional UR forms will be added once the review and approval process has been completed.

54 ENVIRONMENTAL SCIENCES↗

Federal Facility Agreement and Consent Order Nevada National Security Site Use Restriction Management Plan, Revision 2

This Use Restriction Management Plan (URMP) provides the information needed to create, modify, and manage use restrictions (URs) for sites on the Nevada National Security Site (NNSS), and sites accessed through the NNSS main gate, that were closed using the corrective action alternative (CAA) of closure in place under the Federal Facility Agreement and Consent Order (FFACO). It addresses URs established under the FFACO for releases related to the development, testing, and production of nuclear weapons that are located on the NNSS and that are accessed through the NNSS main gate. FFACO URs are established at sites where contamination remains at levels exceeding final action levels (FALs) or is forecasted to exceed Safe Drinking Water Act (SDWA) maximum contaminant levels (CFR, 2025a) over the next 1,000 years following completion of corrective actions. Administrative URs are established at Industrial Sites and Soils sites where contamination remains at levels exceeding industrial action levels as defined in the Soils RBCA document. All URs stipulate restrictions sufficient to ensure the protection of human health, safety, and the environment.

54 ENVIRONMENTAL SCIENCES↗

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Managed Tokens Service for Securely Keeping and Distributing Grid Tokens

Fermilab is transitioning authentication and authorization for grid operations to using bearer tokens based on the WLCG Common JWT (JSON Web Token) Profile. One of the functionalities that Fermilab experimenters rely on is the ability to automate batch job submission, which in turn depends on the ability to securely refresh and distribute the necessary credentials to experiment job submit points. Thus, with the transition to using tokens for grid operations, we needed to create a service that would obtain, refresh, and distribute tokens for experimenters' use. This service would avoid the need for experimenters to be experts in obtaining their own tokens and would better protect the most sensitive long-lived credentials. Further, the service needed to be widely scalable, as Fermilab hosts many experiments, each of which would need their own credentials. To address these issues, we created and deployed a Managed Tokens Service. The service is written in Go, taking advantage of that language's native concurrency primitives to easily be able to scale operations as we onboard experiments. The service uses as its first credentials a set of kerberos keytabs, stored on the same secure machine that the Managed Tokens service runs on. These kerberos credentials allow the service to use htgettoken via condor_vault_storer to store vault tokens in the HTCondor credential managers (credds) that run on the batch system scheduler machines (HTCondor schedds); as well as downloading a local, shorter-lived copy of the vault token. The kerberos credentials are then also used to distribute copies of the locally-stored vault tokens to experiment submit points.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

A Managed Tokens Service for Securely Keeping and Distributing Grid Tokens

Fermilab is transitioning authentication and authorization for grid operations to using bearer tokens based on the WLCG Common JWT (JSON Web Token) Profile. One of the functionalities that Fermilab experimenters rely on is the ability to automate batch job submission, which in turn depends on the ability to securely refresh and distribute the necessary credentials to experiment job submit points. Thus, with the transition to using tokens for grid operations, we needed to create a service that would obtain, refresh, and distribute tokens for experimenters’ use. This service would avoid the need for experimenters to be experts in obtaining their own tokens and would better protect the most sensitive long-lived credentials. Further, the service needed to be widely scalable, as we are currently keeping credentials active for approximately 15 experiments, each with 1-3 different credentials, and distributing those credentials to 2-20 submit points per experiment, with those numbers steadily increasing. To address these issues, we created and deployed a Managed Tokens service. The service is written in Go, taking advantage of that language’s native concurrency primitives to easily be able to scale operations as we onboard experiments. The service uses as its first credentials a set of kerberos keytabs, stored on the same secure machine that the Managed Tokens service runs on. These kerberos credentials allow the service to use htgettoken via condor_vault_storer to store vault tokens in the HTCondor credential managers (credds) that run on the batch system scheduler machines (HTCondor schedds); as well as downloading a local, shorter-lived copy of the vault token. The kerberos credentials are then also used to distribute copies of the locally-stored vault tokens to experiment submit points. When experimenters schedule jobs to be submitted, these distributed vault tokens are used to access a Hashicorp Vault instance (run separately from the Managed Tokens service), and previously-stored refresh tokens there are used to obtain the bearer token that is submitted with the job. We will discuss here the design of the Managed Tokens service, including elaborating on certain choices we made with regards to concurrent operations, configuration, monitoring, and deployment.

Bhat, Shreyas↗