Audit of the U.S. Nuclear Regulatory Commission’s (NRC) Cybersecurity Inspection Program for Operating Nuclear Power Plants
Report Information
Recommendations
The OIG recommends that the Executive Director for Operations train staff on the correct Cost Activity Codes for reporting fee-billable and non-billable cybersecurity inspection activities within the Human Capital Management Cloud System.
Therefore, the staff considers Recommendation 4.1 to be complete.<br />
Target date for completion: Completed June 11, 2026<br />
OIG Analysis: The OIG will close this recommendation after the agency provides documentation confirming that cybersecurity inspectors were trained on the proper CAC and EPID combinations to be used for cybersecurity inspections. This<br />
recommendation remains open and resolved.
The OIG recommends that the Executive Director for Operations finalize the Cyber Security Issues Forum Draft Charter to include the Cost Activity Codes used by staff members when participating in or observing meetings.
complete.<br />
Target date for completion: Completed June 11, 2026.<br />
OIG Analysis: The OIG acknowledges that the Cyber SIF Charter is not an appropriate place to identify CACs for use in support of meetings. The OIG will close this recommendation after the agency provides documentation confirming that the cybersecurity inspectors were trained on the proper CAC and EPID combinations to be used for cybersecurity inspections. This recommendation remains open and resolved.
The OIG recommends that the Executive Director for Operations develop clear guidance on the appropriate use of security oversight Cost Activity Codes.
complete. Target date for completion: Completed June 11, 2026.<br />
OIG Analysis: The OIG will close this recommendation after the agency provides documentation confirming that cybersecurity inspectors were trained on the proper CAC and EPID combinations to be used for cybersecurity inspections. This<br />
recommendation remains open and resolved.
The OIG recommends that the Executive Director for Operations develop and implement Enterprise Project Identifier codes for inspection oversight activities to improve tracking of safety and security related oversight activities.
complete. Target date for completion: Completed June 11, 2026.<br />
OIG Analysis: The OIG will close this recommendation after the agency provides documentation confirming that the proper CACEPID combinations were established for cybersecurity inspection oversight activities. This recommendation<br />
remains open and resolved.