International Workshop on Conducting Computer Security Exercises for Nuclear Security
Computer security exercises are a key assurance activity supportive of nuclear security. Nuclear Security Fundamentals recognizes that routinely performing computer security assurance activities is an essential element of nuclear security. Exercises can provide unique insight in the state of preparedness of computer security. They can also be the basis for continued improvement programmes for all organizations within the State’s nuclear security regime. The IAEA has been supporting Members States on conducting well organized, professionally conducted computer security that focus on constructive evaluation for capability improvement. This event will be based on the IAEA guidance and training material (Asherah Nuclear Power Plant, Shapash Nuclear Research Institute and Gula General Hospital ), and on the lessons learned from the IAEA’s support to the Brazilian Cyber Guardian Exercise (2018-2023), from the Slovenia KIVA Exercise (2022),from the Regional Training Course on Conducting a Computer Security Exercise conducted in Argentina (2023), and from the Regional Workshop on Conducting a Computer Security Exercise (France, 2024). Besides its objective, this event will provide information for participants to adapt the IAEA material to their national context, organization and procedures, in order to develop a future training or awareness activities more realistic to their national context.The objective of this event is to raise participants' awareness of the threat of cyber-attacks, and their potential impact on nuclear security by conducting a computer security exercise for a simulated adversary cyber-attack. Additionally, the scenario-based exercise will help participants to become familiar with techniques for conducting such exercises. The participants will address the effectiveness of the computer security systems and measures that provide protection to the facility and learn how to evaluate the ability to respond to computer security incidents.This event is designed for nuclear security professionals that have responsibilities for computer security. It will involve awareness and hands-on exercises and would be beneficial if participants have computer or digital system experience.