{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"description":"Ideas here will be raw and unpolished, but I hope they spark meaningful thought.","feed_url":"https://blog.mitcdh.au/feed.json","home_page_url":"https://blog.mitcdh.au/","items":[{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eThere is a scene in \u003cem\u003eMad Men\u003c/em\u003e where Don Draper pitches Kodak\u0026rsquo;s circular slide projector, \u0026ldquo;The Carousel\u0026rdquo;. He barely talks about the technology. Instead, he talks about what it allows people to feel, the ability to travel backwards and return to a place and a time where they still ache to be.\u003c/p\u003e\n\u003cp\u003eWhen my dad passed away, I found myself going through thousands of slides from my grandfather\u0026rsquo;s collection. Many showed my dad growing up with his family. I saw the father I knew as a child, a brother, and a son, living through years that had previously existed for me only as stories.\u003c/p\u003e\n\u003cp\u003eEach photograph was contained in a small square of mounted film. Held in your hand, it could be difficult to make out. Pass a light through it, though, and for that moment an entire memory returned.\u003c/p\u003e\n\u003cp\u003eGoing through those slides made me think not only about what photographs preserve, but about how they used to be shared, a family ritual. Someone chose them, arranged them, and loaded them into a tray. People gathered in the same room. The lights went down. The projector clicked, the next image appeared, and, for a little while, a memory held everyone\u0026rsquo;s attention at once\u0026hellip; usually accompanied by an overly confident uncle volunteering all the embarrassing stories.\u003c/p\u003e\n\u003cp\u003eThe slideshow turned displaying pictures into a shared moment. I was never quite sure why, but I kept thinking about it. Eventually, I built \u003ca href=\"https://carousel.mitcdh.au\"\u003emy own Carousel\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/carousel-before-the-feed_01.webp\" width=\"2015\" height=\"1418\" alt=\"A fullscreen photograph displayed in Flickr Carousel with visible navigation controls.\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eMy little Flickr Carousel in use.\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"before-photographs-became-content\"\u003eBefore photographs became content\u003c/h2\u003e\n\u003cp\u003ePhotographs were once treasured objects through which memories were shared. For most of my childhood, my mum kept an emergency bag by the door in case of fire. It held no important documents or valuables, only the photographs that meant something to her.\u003c/p\u003e\n\u003cp\u003eIn sharing these treasures a family might send a few prints to relatives, assemble an album, or invite people over to look through slides. The audience was smaller and the process slower, but the act of sharing was deliberate. People talked over the images. Someone explained who was standing at the edge of the frame. A photograph usually arrived with a story attached. Only the best made it into the annual Christmas card.\u003c/p\u003e\n\u003cp\u003eSocial media removed almost all of the friction from that process. I can take a photograph and show it to hundreds of people within seconds.\u003c/p\u003e\n\u003cp\u003eThat convenience is extraordinary, but it has also changed the photograph itself. Online, a picture becomes one more item in a feed: briefly visible between everything that came before it and whatever the almighty algorithm has decided should come next.\u003c/p\u003e\n\u003cp\u003eThe interface asks us to react, like, swipe and continue. It rarely asks us simply to pause and look. Modern album tools may allow a caption, but they rarely make description or context central. It is just another set of pixels.\u003c/p\u003e\n\u003cp\u003eWorse still, sharing photographs online presents an uncomfortable choice. I can send them privately to a few friends, or upload them to a large social platform. Either way, they often disappear from meaningful view while remaining available to the companies and systems that host, index, and analyse them.\u003c/p\u003e\n\u003cp\u003eThat access may arise through my own account, through a copy uploaded to a friend\u0026rsquo;s gallery, or even through the email or messaging service carrying the photograph between us. The precise terms vary, but these services generally receive broad permissions to store, process, reproduce, distribute, and even sell what we share.\u003c/p\u003e\n\u003cp\u003eI may retain the copyright, but I lose much of the practical agency that copyright is supposed to provide. The platform gains extensive rights to use the photograph, while the public gains no corresponding right to access, preserve, or reuse it. That is not publishing on terms I have chosen, and it is not contributing to a common good. It is private extraction disguised and sold as a personal convenience.\u003c/p\u003e\n\u003ch2 id=\"why-i-still-use-flickr\"\u003eWhy I still use Flickr\u003c/h2\u003e\n\u003cp\u003eI\u0026rsquo;m often asked why I still use \u003ca href=\"https://www.flickr.com/people/mitcdh/\"\u003eFlickr\u003c/a\u003e, most people have forgotten about it as a relic of the Yahoo days. But for me, Flickr still offers something closer to real sharing and real agency.\u003c/p\u003e\n\u003cp\u003eI can make a photograph genuinely available beyond a closed friend list. I can give it a title and description, organise it into albums, and link directly to it—to the actual image file not just a hosted page on the platform. Most importantly, I can choose the licence under which I am sharing it.\u003c/p\u003e\n\u003cp\u003eThe licence tells people what they are allowed to do with the photograph. It lets me decide whether an image can be reused, adapted or redistributed, rather than leaving \u0026ldquo;sharing\u0026rdquo; to mean whatever a platform\u0026rsquo;s terms happen to permit.\u003c/p\u003e\n\u003cp\u003eA public licence also changes who benefits from that sharing. The platform may still receive permissions under its terms of service, but it is no longer the only party able to make use of the photograph. By applying the right licence, I can contribute the image to the commons allowing anyone to exercise the same rights I am otherwise implicitly signing away to a large corporation. Those rights do not remain locked inside a private agreement, they can be openly granted to the public, under terms I have chosen.\u003c/p\u003e\n\u003cp\u003eFlickr is still a commercial platform, of course. What distinguishes it is that photographs retain their titles, descriptions, licences, albums, direct links, and, most importantly, images can be publicly catalogued without an algorithm. It also has an API. That turns an archive in any other tools into something I can build with. Flickr can remain the place where I organise and describe my photographs while another application presents them in an entirely different way.\u003c/p\u003e\n\u003cp\u003eSo with this in mind I built \u003ca href=\"https://github.com/mitcdh/flickr-carousel\"\u003eFlickr Carousel\u003c/a\u003e: a fullscreen slideshow that takes an album from Flickr and presents it with some of the rhythm and atmosphere of an old slide projector.\u003c/p\u003e\n\u003ch2 id=\"building-the-carousel\"\u003eBuilding the Carousel\u003c/h2\u003e\n\u003cp\u003eA small Cloudflare Worker requests the photographs from a Flickr album and returns them to the browser. This keeps the Flickr API key out of the client-side JavaScript and avoids maintaining a separate database. Flickr remains the source of the photographs and their metadata.\u003c/p\u003e\n\u003cp\u003eThe browser then handles the presentation. It chooses an appropriate image size for the screen, preloads the next photograph and moves through the collection automatically or under the viewer\u0026rsquo;s control.\u003c/p\u003e\n\u003cp\u003eThe slide projector effect is made from several restrained details:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ea short mechanical movement between frames;\u003c/li\u003e\n\u003cli\u003ea brief shutter blackout;\u003c/li\u003e\n\u003cli\u003ea warm flare as the next photograph appears;\u003c/li\u003e\n\u003cli\u003esubtle grain and vignetting; and\u003c/li\u003e\n\u003cli\u003ea recording of a real automatic slide advance.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe sound is muted by default because a website unexpectedly making projector noises is less nostalgic than it is just plain annoying.\u003c/p\u003e\n\u003cp\u003eThe controls are modern even if the rhythm is old. The Carousel supports arrow keys, touch gestures, pause and resume, fullscreen mode, and a choice between fitting the entire photograph or filling the display. Titles and descriptions are available without permanently covering the image, and each photograph links back to Flickr, where its context and licence remain visible.\u003c/p\u003e\n\u003cp\u003eI wanted to recover the character of an old projector without recreating its limitations. The rhythm and atmosphere could remain, while keyboard controls, accessibility labels, and other modern conveniences made it easier to use.\u003c/p\u003e\n\u003ch2 id=\"a-finite-tray-rather-than-an-infinite-feed\"\u003eA finite tray rather than an infinite feed\u003c/h2\u003e\n\u003cp\u003eOne of the things I like most about a physical slide projector is that it has a boundary.\u003c/p\u003e\n\u003cp\u003eA tray contains a finite number of slides. It begins somewhere, moves through them, and eventually returns to the start. Even if the order is shuffled, the collection itself has a shape and a finality.\u003c/p\u003e\n\u003cp\u003eAn infinite feed is designed around the opposite idea. There must always be something else below the current image. Reaching the end is treated as a failure of engagement, or an unhealthy addiction, rather than a natural place to stop.\u003c/p\u003e\n\u003cp\u003eI did not want likes, recommendations, or an endless supply of adjacent advertising material. I wanted one photograph at a time, with just enough information to understand what was being shown.\u003c/p\u003e\n\u003cp\u003eIn a feed, the interface is constantly suggesting what you should do next. With a projector, the interface can almost disappear. The photograph gets the screen, and you decide when it is time to move on.\u003c/p\u003e\n\u003ch2 id=\"the-simpler-thing-i-was-trying-to-recover\"\u003eThe simpler thing I was trying to recover\u003c/h2\u003e\n\u003cp\u003eI know the past was not actually simple. A box of family slides is itself a carefully edited record. It preserves some moments and omits others, sometimes by choice and sometimes by accident. Nostalgia has a habit of smoothing the edges of whatever it touches.\u003c/p\u003e\n\u003cp\u003eBut the ritual of the slide projector asked something simpler of us. Load the tray. Dim the lights. Show one picture. Tell the story that belongs to it. Move to the next.\u003c/p\u003e\n\u003cp\u003eThe projector did not ask anyone to like the photograph, repost it or remain engaged. It gave the image to the room and allowed the few people in that room, with shared memories and relationships, to reflect on why it mattered.\u003c/p\u003e\n\u003cp\u003eThat is what I wanted my little Carousel to recover: a slower and more deliberate way of looking, without pretending that everything was better before the internet.\u003c/p\u003e\n\u003cp\u003eThe source code for the project is freely available on GitHub at \u003ca href=\"https://github.com/mitcdh/flickr-carousel\"\u003emitcdh/flickr-carousel\u003c/a\u003e. Like the photographs I share on Flickr, I hope someone else might find a use for it, adapt it into a Carousel of their own, or be inspired to make something entirely new.\u003c/p\u003e\n\u003cp\u003eFor me, though, my Carousel will always bring me back to my dad and the thousands of small memories my grandfather had once captured, curated, and proudly shown.\u003c/p\u003e\n\u003cp\u003eNot an infinite feed. A rotating tray, a full room, and one photograph at a time.\u003c/p\u003e\n","content_text":"There is a scene in Mad Men where Don Draper pitches Kodak’s circular slide projector, “The Carousel”. He barely talks about the technology. Instead, he talks about what it allows people to feel, the ability to travel backwards and return to a place and a time where they still ache to be.\nWhen my dad passed away, I found myself going through thousands of slides from my grandfather’s collection. Many showed my dad growing up with his family. I saw the father I knew as a child, a brother, and a son, living through years that had previously existed for me only as stories.\nEach photograph was contained in a small square of mounted film. Held in your hand, it could be difficult to make out. Pass a light through it, though, and for that moment an entire memory returned.\nGoing through those slides made me think not only about what photographs preserve, but about how they used to be shared, a family ritual. Someone chose them, arranged them, and loaded them into a tray. People gathered in the same room. The lights went down. The projector clicked, the next image appeared, and, for a little while, a memory held everyone’s attention at once… usually accompanied by an overly confident uncle volunteering all the embarrassing stories.\nThe slideshow turned displaying pictures into a shared moment. I was never quite sure why, but I kept thinking about it. Eventually, I built my own Carousel.\nMy little Flickr Carousel in use.\nBefore photographs became content Photographs were once treasured objects through which memories were shared. For most of my childhood, my mum kept an emergency bag by the door in case of fire. It held no important documents or valuables, only the photographs that meant something to her.\nIn sharing these treasures a family might send a few prints to relatives, assemble an album, or invite people over to look through slides. The audience was smaller and the process slower, but the act of sharing was deliberate. People talked over the images. Someone explained who was standing at the edge of the frame. A photograph usually arrived with a story attached. Only the best made it into the annual Christmas card.\nSocial media removed almost all of the friction from that process. I can take a photograph and show it to hundreds of people within seconds.\nThat convenience is extraordinary, but it has also changed the photograph itself. Online, a picture becomes one more item in a feed: briefly visible between everything that came before it and whatever the almighty algorithm has decided should come next.\nThe interface asks us to react, like, swipe and continue. It rarely asks us simply to pause and look. Modern album tools may allow a caption, but they rarely make description or context central. It is just another set of pixels.\nWorse still, sharing photographs online presents an uncomfortable choice. I can send them privately to a few friends, or upload them to a large social platform. Either way, they often disappear from meaningful view while remaining available to the companies and systems that host, index, and analyse them.\nThat access may arise through my own account, through a copy uploaded to a friend’s gallery, or even through the email or messaging service carrying the photograph between us. The precise terms vary, but these services generally receive broad permissions to store, process, reproduce, distribute, and even sell what we share.\nI may retain the copyright, but I lose much of the practical agency that copyright is supposed to provide. The platform gains extensive rights to use the photograph, while the public gains no corresponding right to access, preserve, or reuse it. That is not publishing on terms I have chosen, and it is not contributing to a common good. It is private extraction disguised and sold as a personal convenience.\nWhy I still use Flickr I’m often asked why I still use Flickr, most people have forgotten about it as a relic of the Yahoo days. But for me, Flickr still offers something closer to real sharing and real agency.\nI can make a photograph genuinely available beyond a closed friend list. I can give it a title and description, organise it into albums, and link directly to it—to the actual image file not just a hosted page on the platform. Most importantly, I can choose the licence under which I am sharing it.\nThe licence tells people what they are allowed to do with the photograph. It lets me decide whether an image can be reused, adapted or redistributed, rather than leaving “sharing” to mean whatever a platform’s terms happen to permit.\nA public licence also changes who benefits from that sharing. The platform may still receive permissions under its terms of service, but it is no longer the only party able to make use of the photograph. By applying the right licence, I can contribute the image to the commons allowing anyone to exercise the same rights I am otherwise implicitly signing away to a large corporation. Those rights do not remain locked inside a private agreement, they can be openly granted to the public, under terms I have chosen.\nFlickr is still a commercial platform, of course. What distinguishes it is that photographs retain their titles, descriptions, licences, albums, direct links, and, most importantly, images can be publicly catalogued without an algorithm. It also has an API. That turns an archive in any other tools into something I can build with. Flickr can remain the place where I organise and describe my photographs while another application presents them in an entirely different way.\nSo with this in mind I built Flickr Carousel: a fullscreen slideshow that takes an album from Flickr and presents it with some of the rhythm and atmosphere of an old slide projector.\nBuilding the Carousel A small Cloudflare Worker requests the photographs from a Flickr album and returns them to the browser. This keeps the Flickr API key out of the client-side JavaScript and avoids maintaining a separate database. Flickr remains the source of the photographs and their metadata.\nThe browser then handles the presentation. It chooses an appropriate image size for the screen, preloads the next photograph and moves through the collection automatically or under the viewer’s control.\nThe slide projector effect is made from several restrained details:\na short mechanical movement between frames; a brief shutter blackout; a warm flare as the next photograph appears; subtle grain and vignetting; and a recording of a real automatic slide advance. The sound is muted by default because a website unexpectedly making projector noises is less nostalgic than it is just plain annoying.\nThe controls are modern even if the rhythm is old. The Carousel supports arrow keys, touch gestures, pause and resume, fullscreen mode, and a choice between fitting the entire photograph or filling the display. Titles and descriptions are available without permanently covering the image, and each photograph links back to Flickr, where its context and licence remain visible.\nI wanted to recover the character of an old projector without recreating its limitations. The rhythm and atmosphere could remain, while keyboard controls, accessibility labels, and other modern conveniences made it easier to use.\nA finite tray rather than an infinite feed One of the things I like most about a physical slide projector is that it has a boundary.\nA tray contains a finite number of slides. It begins somewhere, moves through them, and eventually returns to the start. Even if the order is shuffled, the collection itself has a shape and a finality.\nAn infinite feed is designed around the opposite idea. There must always be something else below the current image. Reaching the end is treated as a failure of engagement, or an unhealthy addiction, rather than a natural place to stop.\nI did not want likes, recommendations, or an endless supply of adjacent advertising material. I wanted one photograph at a time, with just enough information to understand what was being shown.\nIn a feed, the interface is constantly suggesting what you should do next. With a projector, the interface can almost disappear. The photograph gets the screen, and you decide when it is time to move on.\nThe simpler thing I was trying to recover I know the past was not actually simple. A box of family slides is itself a carefully edited record. It preserves some moments and omits others, sometimes by choice and sometimes by accident. Nostalgia has a habit of smoothing the edges of whatever it touches.\nBut the ritual of the slide projector asked something simpler of us. Load the tray. Dim the lights. Show one picture. Tell the story that belongs to it. Move to the next.\nThe projector did not ask anyone to like the photograph, repost it or remain engaged. It gave the image to the room and allowed the few people in that room, with shared memories and relationships, to reflect on why it mattered.\nThat is what I wanted my little Carousel to recover: a slower and more deliberate way of looking, without pretending that everything was better before the internet.\nThe source code for the project is freely available on GitHub at mitcdh/flickr-carousel. Like the photographs I share on Flickr, I hope someone else might find a use for it, adapt it into a Carousel of their own, or be inspired to make something entirely new.\nFor me, though, my Carousel will always bring me back to my dad and the thousands of small memories my grandfather had once captured, curated, and proudly shown.\nNot an infinite feed. A rotating tray, a full room, and one photograph at a time.\n","date_published":"2026-07-19T14:30:00+10:00","id":"https://blog.mitcdh.au/posts/carousel-before-the-feed/","image":"https://blog.mitcdh.au/images/carousel-before-the-feed.webp","summary":"What the ritual of the slide projector can teach us about sharing photographs more deliberately online.","tags":["Writing","Photography","Technology","Code"],"title":"The Carousel Before the Feed","url":"https://blog.mitcdh.au/posts/carousel-before-the-feed/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eThe idea for this experiment came from a few conversations at CyberCon26. I spoke with people who had asked LLMs questions about IAEA safety and nuclear security guidance and come away with an understanding that the publications did not support. The answers were not always obvious hallucinations. Some quoted genuine passages but lost the distinctions that tell an experienced reader what those passages mean and how much weight to give them.\u003c/p\u003e\n\u003cp\u003eThat made me suspect the prompt was not the main problem. The model was being given the words without enough of the document around them, so I began looking for a better way to represent the source material. I had done something related during the Committee Draft stage of IEC 63096, when I built a deterministic parser for SC45 WGA9 that generated Annex A from the structured content in the body of the draft. It seemed worth testing the same general approach here.\u003c/p\u003e\n\u003cp\u003eIt is easy to upload a folder of PDFs. The difficult part is getting answers that remain useful and defensible once document structure begins to matter. A seemingly simple question can depend on much more than finding the right words. Is the passage a requirement, a recommendation, an example in an annex, or a qualification in a footnote? Does it come from the publication being discussed or from a contents page that repeats the same heading? Is it paragraph 4.32, a table row that happens to begin with \u003ccode\u003e4.32\u003c/code\u003e, or a page number that has wandered into the extracted text?\u003c/p\u003e\n\u003cp\u003eThese distinctions are routine for someone used to working with IAEA guidance. Once a PDF is flattened into a stream of text, many of them disappear.\u003c/p\u003e\n\u003cp\u003eI built the \u003ca href=\"https://github.com/mitcdh/iaea-guidance-parser\"\u003eIAEA Guidance Parser\u003c/a\u003e to preserve them. It turns local folders of IAEA publications into structured, searchable knowledge files for an LLM. I wanted each retrieved passage to arrive with the context a reader would normally have around it i.e. which publication it came from, where it appeared, and what status it carried.\u003c/p\u003e\n\u003cp\u003eThe problem also mattered to me because I had previously worked as a scientific secretary for publications in the NSS. I saw how much work goes into choosing a term, placing a paragraph, and resolving the torrent of comments on any draft text. A paragraph is more than a convenient container for sentences. Its location, its relationship to other publications and its status within the document all affect how it should be read and applied. Those distinctions may appear almost invisible once the final PDF is published but they remain part of the substance created and upheld through the international consensus process.\u003c/p\u003e\n\u003ch2 id=\"search-was-not-the-hard-part\"\u003eSearch was not the hard part\u003c/h2\u003e\n\u003cp\u003eMy first approach was the obvious one: upload either the extracted text or the raw PDFs to NotebookLM or a Custom GPT. That preserves the words but not necessarily the document. A chapter heading may be separated from the paragraphs it governs. A footnote explaining an exception may be retrieved without the sentence it qualifies. A contents entry may look indistinguishable from the real heading later in the publication.\u003c/p\u003e\n\u003cp\u003ePDFs make this particularly difficult. A PDF is often closer to a set of instructions for how a page should look than a structured representation of paragraphs, headings and footnotes. The page can appear perfectly ordered to a person while its text layer contains lines in an inconvenient or misleading reading order. Many of the semantic relationships are only expressed visually rather than encoded explicitly.\u003c/p\u003e\n\u003cp\u003eWithout those visual signals, retrieval may find a relevant sentence and still support a misleading answer.\u003c/p\u003e\n\u003ch2 id=\"what-the-parser-actually-does\"\u003eWhat the parser actually does\u003c/h2\u003e\n\u003cp\u003eThe parser itself is a deterministic Python program. It reads the PDF text layer, applies explicit recognition and repair rules, maintains state while moving through the publication and emits typed records. The LLM enters the process later, after those records have been exported and uploaded as knowledge.\u003c/p\u003e\n\u003cp\u003eThat boundary is deliberate. I did not want a model to guess whether a sentence \u003cem\u003esounds\u003c/em\u003e like a requirement or whether a block \u003cem\u003elooks\u003c/em\u003e like an annex. Those decisions can be made more consistently from the publication\u0026rsquo;s structure, so the parser, rather than the model, decides where paragraphs, annexes, tables, and requirements begin and end.\u003c/p\u003e\n\u003cp\u003eIdeally, this structure would be checked by a person or exported directly from the IAEA\u0026rsquo;s publishing system. As neither option was available\u0026mdash;the IAEA\u0026rsquo;s system or my spare time\u0026mdash;the parser reconstructs as much as it can from the published PDFs, largely through trial and error. When I found specific problems, I used an LLM (oh, the irony) to understand the PDF syntax, explore solutions and build regression tests so they would not reappear. This was far from ideal, and I eventually had to turn to my vibe coding LLM friend to restructure the repository before it became a single file containing an endless collection of regular expressions.\u003c/p\u003e\n\u003ch3 id=\"1-extracting-text-from-a-format-that-was-not-designed-for-it\"\u003e1. Extracting text from a format that was not designed for it\u003c/h3\u003e\n\u003cp\u003eThe parser opens each PDF and extracts its text page by page. For every page, it retains the physical PDF page number and, where it can identify one safely, the printed page number shown in the publication.\u003c/p\u003e\n\u003cp\u003eIt then performs conservative clean-up. It normalises whitespace, removes recognised page-mastering artefacts, joins lines that appear to be artificial PDF wraps and repairs ordinary words split by end-of-line hyphenation. Dashes used in publication identifiers and annex paragraph numbers are preserved because changing them could alter the identifier.\u003c/p\u003e\n\u003cp\u003eThe clean-up is deliberately a light touch. It reverses some of the artefacts introduced when a visually mastered page is converted back into a sequence of text lines, without changing the publication\u0026rsquo;s wording.\u003c/p\u003e\n\u003cp\u003eThe current version reads the PDF\u0026rsquo;s existing text layer and does not perform OCR. If an older PDF contains damaged font mappings, or a scanned page has no usable text layer, the parser cannot reconstruct the intended characters. It can flag suspicious output, but the source still requires review or a separate OCR process.\u003c/p\u003e\n\u003ch3 id=\"2-rebuilding-structure-with-a-small-state-machine\"\u003e2. Rebuilding structure with a small state machine\u003c/h3\u003e\n\u003cp\u003eAfter extraction, the parser walks through the cleaned lines in order. It keeps track of its current position in the publication, including:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe current region, such as front matter, body, appendix, annex or references;\u003c/li\u003e\n\u003cli\u003ethe current major heading and subheading;\u003c/li\u003e\n\u003cli\u003ewhether it is still inside the contents pages;\u003c/li\u003e\n\u003cli\u003ethe active paragraph or other prose block; and\u003c/li\u003e\n\u003cli\u003ewhether a table is open across one or more pages.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe order in which it tests each line matters. Tables are considered before ordinary paragraphs because a table cell can begin with something that looks exactly like a paragraph number. Region transitions are handled before prose so that an \u003ccode\u003eAnnex\u003c/code\u003e heading changes the classification of everything that follows. Requirement headings are separated before a preceding paragraph can absorb them.\u003c/p\u003e\n\u003cp\u003eFootnotes are extracted without automatically ending the paragraph they interrupt. In many PDFs, the main sentence continues after the footnote, sometimes on the next page.\u003c/p\u003e\n\u003cp\u003eI had thought that with \u003ca href=\"https://nucleus.iaea.org/sites/committees/Policy%20Documents/SPESS%20documents/SPESS%20C%20Guidance%20for%20Drafters.doc?Web=1\"\u003eSPESS C guidance for drafters\u003c/a\u003e and a single template in use within the IAEA there would be a pretty consistent use of formatting across both series. However that\u0026rsquo;s not always the case. I\u0026rsquo;ve had to debug the parser until it was capable of recognising numbering patterns used across different generations of the series, including forms such as:\u003c/p\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eConvention\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eExample\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eDocuments in which it occurs\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eNotes\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eBody paragraph\u003c/strong\u003e\u003c/br\u003eHierarchical decimal number with terminal full stop\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e1.1.\u003c/code\u003e; \u003ccode\u003e2.4.1.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAll 179 documents except \u003ccode\u003eSSR-6-REV2\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eNormal body-paragraph convention.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eBody paragraph (alternate)\u003c/strong\u003e\u003c/br\u003eThree-digit number with terminal full stop\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e101.\u003c/code\u003e; \u003ccode\u003e701.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSR-6-REV2\u003c/code\u003e; \u003ccode\u003eSSG-78\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eIn \u003ccode\u003eSSR-6-REV2\u003c/code\u003e, these are used as the normal body paragraphs. In \u003ccode\u003eSSG-78\u003c/code\u003e, numbers such as \u003ccode\u003e100.\u003c/code\u003e are used to number checklist questions within an Annex without an Annex prefix.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAdvisory subparagraph (alternate)\u003c/strong\u003e\u003c/br\u003eThree-digit parent plus decimal suffix\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e101.1.\u003c/code\u003e; \u003ccode\u003e701.4.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-26-REV1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAdvisory paragraphs expanding on the corresponding three-digit \u003ccode\u003eSSR-6\u003c/code\u003e paragraph.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eBody paragraph (alternate)\u003c/strong\u003e\u003c/br\u003eLetter-suffixed three-digit number\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e220A.\u003c/code\u003e; \u003ccode\u003e229B.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSR-6-REV2\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eParagraphs throughout the document that appear to expand on the proceeding numbered paragraph without the letter suffix.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAdvisory subparagraph (alternate)\u003c/strong\u003e\u003c/br\u003eLetter-suffixed three-digit parent plus decimal suffix\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e220A.1.\u003c/code\u003e; \u003ccode\u003e613A.6.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-26-REV1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAdvisory paragraphs extending or ranging over the corresponding three-digit \u003ccode\u003eSSR-6\u003c/code\u003e paragraph, e.g.: \u003ccode\u003e220A.1–220A.7\u003c/code\u003e, \u003ccode\u003e524A.1\u003c/code\u003e, \u003ccode\u003e536A.1\u003c/code\u003e, \u003ccode\u003e613A.1–613A.6\u003c/code\u003e, \u003ccode\u003e827A.1\u003c/code\u003e.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAppendix paragraph\u003c/strong\u003e\u003c/br\u003eSingle-letter identifier, dot-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eA.1.\u003c/code\u003e; \u003ccode\u003eA.64.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSG-1\u003c/code\u003e, \u003ccode\u003eGSG-10\u003c/code\u003e, \u003ccode\u003eGSG-11\u003c/code\u003e, \u003ccode\u003eGSG-14\u003c/code\u003e, \u003ccode\u003eGSG-16\u003c/code\u003e, \u003ccode\u003eGSG-18\u003c/code\u003e, \u003ccode\u003eGSG-8\u003c/code\u003e, \u003ccode\u003eNSS-10-G-REV1\u003c/code\u003e, \u003ccode\u003eNSS-17-T-REV1\u003c/code\u003e, \u003ccode\u003eNSS-40-T\u003c/code\u003e, \u003ccode\u003eNSS-42-G\u003c/code\u003e, \u003ccode\u003eNSS-44-T\u003c/code\u003e, \u003ccode\u003eSSG-11\u003c/code\u003e, \u003ccode\u003eSSG-12\u003c/code\u003e, \u003ccode\u003eSSG-20-REV1\u003c/code\u003e, \u003ccode\u003eSSG-28\u003c/code\u003e, \u003ccode\u003eSSG-35\u003c/code\u003e, \u003ccode\u003eSSG-4-REV1\u003c/code\u003e, \u003ccode\u003eSSG-47\u003c/code\u003e, \u003ccode\u003eSSG-50\u003c/code\u003e, \u003ccode\u003eSSG-53\u003c/code\u003e, \u003ccode\u003eSSG-54\u003c/code\u003e, \u003ccode\u003eSSG-79\u003c/code\u003e, \u003ccode\u003eSSG-80\u003c/code\u003e, \u003ccode\u003eSSG-81\u003c/code\u003e, \u003ccode\u003eSSG-89\u003c/code\u003e, \u003ccode\u003eSSG-90\u003c/code\u003e, \u003ccode\u003eSSG-92\u003c/code\u003e, \u003ccode\u003eSSR-4\u003c/code\u003e, \u003ccode\u003eSSR-5\u003c/code\u003e, \u003ccode\u003eTS-G-1-4\u003c/code\u003e, \u003ccode\u003eWS-G-6-1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAppears to be the format preferred for a document with a single Appendix.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAppendix paragraph\u003c/strong\u003e\u003c/br\u003eRoman-numeral identifier, dot-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eI.1.\u003c/code\u003e; \u003ccode\u003eIII.21.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGS-G-2-1\u003c/code\u003e, \u003ccode\u003eGS-G-3-1\u003c/code\u003e, \u003ccode\u003eGS-G-3-5\u003c/code\u003e, \u003ccode\u003eGSG-12\u003c/code\u003e, \u003ccode\u003eGSG-13\u003c/code\u003e, \u003ccode\u003eGSG-15\u003c/code\u003e, \u003ccode\u003eGSG-17\u003c/code\u003e, \u003ccode\u003eGSG-2\u003c/code\u003e, \u003ccode\u003eGSG-6\u003c/code\u003e, \u003ccode\u003eGSG-7\u003c/code\u003e, \u003ccode\u003eGSR-PART-3\u003c/code\u003e, \u003ccode\u003eGSR-PART-7\u003c/code\u003e, \u003ccode\u003eNSS-11-G-REV1\u003c/code\u003e, \u003ccode\u003eNSS-22-G\u003c/code\u003e, \u003ccode\u003eNSS-24-G\u003c/code\u003e, \u003ccode\u003eNSS-26-G\u003c/code\u003e, \u003ccode\u003eNSS-27-G\u003c/code\u003e, \u003ccode\u003eNSS-28-T\u003c/code\u003e, \u003ccode\u003eNSS-29-G\u003c/code\u003e, \u003ccode\u003eNSS-32-T\u003c/code\u003e, \u003ccode\u003eNSS-34-T\u003c/code\u003e, \u003ccode\u003eNSS-4\u003c/code\u003e, \u003ccode\u003eNSS-41-T\u003c/code\u003e, \u003ccode\u003eNSS-5\u003c/code\u003e, \u003ccode\u003eNSS-6\u003c/code\u003e, \u003ccode\u003eNSS-9-G-REV1\u003c/code\u003e, \u003ccode\u003eRS-G-1-9\u003c/code\u003e, \u003ccode\u003eSSG-1-REV1\u003c/code\u003e, \u003ccode\u003eSSG-14\u003c/code\u003e, \u003ccode\u003eSSG-15-REV1\u003c/code\u003e, \u003ccode\u003eSSG-19\u003c/code\u003e, \u003ccode\u003eSSG-21\u003c/code\u003e, \u003ccode\u003eSSG-25\u003c/code\u003e, \u003ccode\u003eSSG-26-REV1\u003c/code\u003e, \u003ccode\u003eSSG-29\u003c/code\u003e, \u003ccode\u003eSSG-40\u003c/code\u003e, \u003ccode\u003eSSG-41\u003c/code\u003e, \u003ccode\u003eSSG-45\u003c/code\u003e, \u003ccode\u003eSSG-46\u003c/code\u003e, \u003ccode\u003eSSG-49\u003c/code\u003e, \u003ccode\u003eSSG-55\u003c/code\u003e, \u003ccode\u003eSSG-60\u003c/code\u003e, \u003ccode\u003eSSG-61\u003c/code\u003e, \u003ccode\u003eSSG-64\u003c/code\u003e, \u003ccode\u003eSSG-65\u003c/code\u003e, \u003ccode\u003eSSG-66\u003c/code\u003e, \u003ccode\u003eSSG-70\u003c/code\u003e, \u003ccode\u003eSSG-71\u003c/code\u003e, \u003ccode\u003eSSG-77\u003c/code\u003e, \u003ccode\u003eSSG-83\u003c/code\u003e, \u003ccode\u003eSSG-91\u003c/code\u003e, \u003ccode\u003eSSR-3\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex paragraph\u003c/strong\u003e\u003c/br\u003eSingle-letter identifier, dash-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eA–1.\u003c/code\u003e; \u003ccode\u003eA–6.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGS-G-2-1\u003c/code\u003e, \u003ccode\u003eGS-G-3-5\u003c/code\u003e, \u003ccode\u003eGSG-12\u003c/code\u003e, \u003ccode\u003eGSG-19\u003c/code\u003e, \u003ccode\u003eGSG-6\u003c/code\u003e, \u003ccode\u003eGSG-7\u003c/code\u003e, \u003ccode\u003eGSG-9\u003c/code\u003e, \u003ccode\u003eGSR-PART-3\u003c/code\u003e, \u003ccode\u003eGSR-PART-5\u003c/code\u003e, \u003ccode\u003eGSR-PART-7\u003c/code\u003e, \u003ccode\u003eSSG-13-REV1\u003c/code\u003e, \u003ccode\u003eSSG-28\u003c/code\u003e, \u003ccode\u003eSSG-37-REV1\u003c/code\u003e, \u003ccode\u003eSSG-50\u003c/code\u003e, \u003ccode\u003eSSG-51\u003c/code\u003e, \u003ccode\u003eSSG-54\u003c/code\u003e, \u003ccode\u003eSSG-63\u003c/code\u003e, \u003ccode\u003eSSG-69\u003c/code\u003e, \u003ccode\u003eSSG-70\u003c/code\u003e, \u003ccode\u003eSSG-72\u003c/code\u003e, \u003ccode\u003eSSG-79\u003c/code\u003e, \u003ccode\u003eSSG-82\u003c/code\u003e, \u003ccode\u003eSSG-89\u003c/code\u003e, \u003ccode\u003eSSG-91\u003c/code\u003e, \u003ccode\u003eSSR-4\u003c/code\u003e, \u003ccode\u003eSSR-5\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAppears to be the format preferred for a document with a single Annex. \u003ccode\u003eSSG-37-REV1\u003c/code\u003e figure uses an ASCII hyphen instead of an en dash.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex paragraph\u003c/strong\u003e\u003c/br\u003eRoman-numeral identifier, dash-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eI–1.\u003c/code\u003e; \u003ccode\u003eIII–21.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGS-G-3-1\u003c/code\u003e, \u003ccode\u003eGSG-1\u003c/code\u003e, \u003ccode\u003eGSG-10\u003c/code\u003e, \u003ccode\u003eGSG-11\u003c/code\u003e, \u003ccode\u003eGSG-14\u003c/code\u003e, \u003ccode\u003eGSG-15\u003c/code\u003e, \u003ccode\u003eGSG-17\u003c/code\u003e, \u003ccode\u003eGSG-18\u003c/code\u003e, \u003ccode\u003eGSG-3\u003c/code\u003e, \u003ccode\u003eGSG-5\u003c/code\u003e, \u003ccode\u003eNSS-12-T-REV1\u003c/code\u003e, \u003ccode\u003eNSS-17-T-REV1\u003c/code\u003e, \u003ccode\u003eNSS-2-G-REV1\u003c/code\u003e, \u003ccode\u003eNSS-22-G\u003c/code\u003e, \u003ccode\u003eNSS-23-G\u003c/code\u003e, \u003ccode\u003eNSS-3\u003c/code\u003e, \u003ccode\u003eNSS-34-T\u003c/code\u003e, \u003ccode\u003eNSS-38-T\u003c/code\u003e, \u003ccode\u003eNSS-39-T\u003c/code\u003e, \u003ccode\u003eNSS-41-T\u003c/code\u003e, \u003ccode\u003eNSS-42-G\u003c/code\u003e, \u003ccode\u003eNSS-43-T\u003c/code\u003e, \u003ccode\u003eNSS-44-T\u003c/code\u003e, \u003ccode\u003eNSS-47-T\u003c/code\u003e, \u003ccode\u003eNSS-9-G-REV1\u003c/code\u003e, \u003ccode\u003eRS-G-1-9\u003c/code\u003e, \u003ccode\u003eSSG-1-REV1\u003c/code\u003e, \u003ccode\u003eSSG-10-REV1\u003c/code\u003e, \u003ccode\u003eSSG-11\u003c/code\u003e, \u003ccode\u003eSSG-15-REV1\u003c/code\u003e, \u003ccode\u003eSSG-17\u003c/code\u003e, \u003ccode\u003eSSG-18\u003c/code\u003e, \u003ccode\u003eSSG-19\u003c/code\u003e, \u003ccode\u003eSSG-2-REV1\u003c/code\u003e, \u003ccode\u003eSSG-20-REV1\u003c/code\u003e, \u003ccode\u003eSSG-21\u003c/code\u003e, \u003ccode\u003eSSG-24-REV1\u003c/code\u003e, \u003ccode\u003eSSG-3-REV1\u003c/code\u003e, \u003ccode\u003eSSG-31\u003c/code\u003e, \u003ccode\u003eSSG-32\u003c/code\u003e, \u003ccode\u003eSSG-34\u003c/code\u003e, \u003ccode\u003eSSG-35\u003c/code\u003e, \u003ccode\u003eSSG-36\u003c/code\u003e, \u003ccode\u003eSSG-39\u003c/code\u003e, \u003ccode\u003eSSG-4-REV1\u003c/code\u003e, \u003ccode\u003eSSG-42-REV1\u003c/code\u003e, \u003ccode\u003eSSG-43-REV1\u003c/code\u003e, \u003ccode\u003eSSG-47\u003c/code\u003e, \u003ccode\u003eSSG-49\u003c/code\u003e, \u003ccode\u003eSSG-5-REV1\u003c/code\u003e, \u003ccode\u003eSSG-52\u003c/code\u003e, \u003ccode\u003eSSG-57\u003c/code\u003e, \u003ccode\u003eSSG-58\u003c/code\u003e, \u003ccode\u003eSSG-59\u003c/code\u003e, \u003ccode\u003eSSG-6-REV1\u003c/code\u003e, \u003ccode\u003eSSG-60\u003c/code\u003e, \u003ccode\u003eSSG-65\u003c/code\u003e, \u003ccode\u003eSSG-66\u003c/code\u003e, \u003ccode\u003eSSG-7-REV1\u003c/code\u003e, \u003ccode\u003eSSG-78\u003c/code\u003e, \u003ccode\u003eSSG-81\u003c/code\u003e, \u003ccode\u003eSSG-84\u003c/code\u003e, \u003ccode\u003eSSG-85\u003c/code\u003e, \u003ccode\u003eSSG-86\u003c/code\u003e, \u003ccode\u003eSSG-87\u003c/code\u003e, \u003ccode\u003eSSG-88\u003c/code\u003e, \u003ccode\u003eSSG-90\u003c/code\u003e, \u003ccode\u003eSSR-3\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMost use an en dash; \u003ccode\u003eRS-G-1-9\u003c/code\u003e and \u003ccode\u003eNSS-43-T\u003c/code\u003e contain ASCII-hyphen variants, and \u003ccode\u003eSSG-47\u003c/code\u003e contains a figure-dash character.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eLocal decimal numbering\u003c/strong\u003e\u003c/br\u003eRepeated identifiers\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e8.1.\u003c/code\u003e–\u003ccode\u003e8.6.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-33-REV1\u003c/code\u003e, \u003ccode\u003eSSG-66\u003c/code\u003e, \u003ccode\u003eTS-G-1-4\u003c/code\u003e, \u003ccode\u003eNSS-9-G-REV1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eThe same identifiers recur in different schedules, templates, appendices, or table sections. The number may not be globally unique within a single document.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eBody or template number\u003c/strong\u003e\u003c/br\u003eNo terminal full stop\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e106.2\u003c/code\u003e; \u003ccode\u003e4.4\u003c/code\u003e; \u003ccode\u003e2.5\u003c/code\u003e; \u003ccode\u003e6.1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-26-REV1\u003c/code\u003e, \u003ccode\u003eNSS-25-G\u003c/code\u003e, \u003ccode\u003eNSS-36-G\u003c/code\u003e, \u003ccode\u003eNSS-29-G\u003c/code\u003e, \u003ccode\u003eNSS-9-G-REV1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eOmitted in \u003ccode\u003eSSG-26-REV1\u003c/code\u003e \u003ccode\u003e106.2\u003c/code\u003e; \u003ccode\u003eNSS-25-G\u003c/code\u003e \u003ccode\u003e4.4\u003c/code\u003e; \u003ccode\u003eNSS-36-G\u003c/code\u003e \u003ccode\u003e2.5\u003c/code\u003e, \u003ccode\u003e2.7\u003c/code\u003e, \u003ccode\u003e2.8\u003c/code\u003e. \u003ccode\u003eNSS-29-G\u003c/code\u003e and \u003ccode\u003eNSS-9-G-REV1\u003c/code\u003e use unpunctuated local template/annex outlines.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eTable-cell cross-reference\u003c/strong\u003e\u003c/br\u003eBare three-digit number\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003e503\u003c/code\u003e; \u003ccode\u003e580\u003c/code\u003e; \u003ccode\u003e581\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-33-REV1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eThese are references to \u003ccode\u003eSSR-6\u003c/code\u003e paragraphs, not new paragraphs.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eRequirement heading\u003c/strong\u003e\u003c/br\u003eColon-terminated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eRequirement 7:\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSR-PART-1-REV1\u003c/code\u003e, \u003ccode\u003eGSR-PART-2\u003c/code\u003e, \u003ccode\u003eGSR-PART-3\u003c/code\u003e, \u003ccode\u003eGSR-PART-4-REV1\u003c/code\u003e, \u003ccode\u003eGSR-PART-5\u003c/code\u003e, \u003ccode\u003eGSR-PART-6\u003c/code\u003e, \u003ccode\u003eGSR-PART-7\u003c/code\u003e, \u003ccode\u003eSSR-1\u003c/code\u003e, \u003ccode\u003eSSR-2-1-REV1\u003c/code\u003e, \u003ccode\u003eSSR-2-2-REV1\u003c/code\u003e, \u003ccode\u003eSSR-3\u003c/code\u003e, \u003ccode\u003eSSR-4\u003c/code\u003e, \u003ccode\u003eSSR-5\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e13 Requirements publications. Capitalisation is normally \u003ccode\u003eRequirement\u003c/code\u003e, although uppercase forms occur in contents/headings.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eTable caption\u003c/strong\u003e\u003c/br\u003eNumeric with terminal full stop\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE 4.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGS-G-2-1\u003c/code\u003e, \u003ccode\u003eGSG-10\u003c/code\u003e, \u003ccode\u003eGSG-11\u003c/code\u003e, \u003ccode\u003eGSG-17\u003c/code\u003e, \u003ccode\u003eGSG-18\u003c/code\u003e, \u003ccode\u003eGSG-19\u003c/code\u003e, \u003ccode\u003eGSG-2\u003c/code\u003e, \u003ccode\u003eGSG-7\u003c/code\u003e, \u003ccode\u003eGSG-8\u003c/code\u003e, \u003ccode\u003eGSR-PART-3\u003c/code\u003e, \u003ccode\u003eGSR-PART-7\u003c/code\u003e, \u003ccode\u003eNSS-10-G-REV1\u003c/code\u003e, \u003ccode\u003eNSS-11-G-REV1\u003c/code\u003e, \u003ccode\u003eNSS-12-T-REV1\u003c/code\u003e, \u003ccode\u003eNSS-2-G-REV1\u003c/code\u003e, \u003ccode\u003eNSS-24-G\u003c/code\u003e, \u003ccode\u003eNSS-27-G\u003c/code\u003e, \u003ccode\u003eNSS-28-T\u003c/code\u003e, \u003ccode\u003eNSS-36-G\u003c/code\u003e, \u003ccode\u003eNSS-37-G\u003c/code\u003e, \u003ccode\u003eNSS-4\u003c/code\u003e, \u003ccode\u003eNSS-40-T\u003c/code\u003e, \u003ccode\u003eNSS-41-T\u003c/code\u003e, \u003ccode\u003eNSS-43-T\u003c/code\u003e, \u003ccode\u003eNSS-46-T\u003c/code\u003e, \u003ccode\u003eNSS-5\u003c/code\u003e, \u003ccode\u003eNSS-6\u003c/code\u003e, \u003ccode\u003eNSS-9-G-REV1\u003c/code\u003e, \u003ccode\u003eRS-G-1-9\u003c/code\u003e, \u003ccode\u003eSSG-1-REV1\u003c/code\u003e, \u003ccode\u003eSSG-10-REV1\u003c/code\u003e, \u003ccode\u003eSSG-14\u003c/code\u003e, \u003ccode\u003eSSG-15-REV1\u003c/code\u003e, \u003ccode\u003eSSG-16-REV1\u003c/code\u003e, \u003ccode\u003eSSG-17\u003c/code\u003e, \u003ccode\u003eSSG-2-REV1\u003c/code\u003e, \u003ccode\u003eSSG-21\u003c/code\u003e, \u003ccode\u003eSSG-25\u003c/code\u003e, \u003ccode\u003eSSG-26-REV1\u003c/code\u003e, \u003ccode\u003eSSG-27-REV1\u003c/code\u003e, \u003ccode\u003eSSG-29\u003c/code\u003e, \u003ccode\u003eSSG-30\u003c/code\u003e, \u003ccode\u003eSSG-32\u003c/code\u003e, \u003ccode\u003eSSG-33-REV1\u003c/code\u003e, \u003ccode\u003eSSG-4-REV1\u003c/code\u003e, \u003ccode\u003eSSG-40\u003c/code\u003e, \u003ccode\u003eSSG-41\u003c/code\u003e, \u003ccode\u003eSSG-45\u003c/code\u003e, \u003ccode\u003eSSG-46\u003c/code\u003e, \u003ccode\u003eSSG-48\u003c/code\u003e, \u003ccode\u003eSSG-52\u003c/code\u003e, \u003ccode\u003eSSG-53\u003c/code\u003e, \u003ccode\u003eSSG-54\u003c/code\u003e, \u003ccode\u003eSSG-57\u003c/code\u003e, \u003ccode\u003eSSG-58\u003c/code\u003e, \u003ccode\u003eSSG-60\u003c/code\u003e, \u003ccode\u003eSSG-61\u003c/code\u003e, \u003ccode\u003eSSG-66\u003c/code\u003e, \u003ccode\u003eSSG-67\u003c/code\u003e, \u003ccode\u003eSSG-79\u003c/code\u003e, \u003ccode\u003eSSG-81\u003c/code\u003e, \u003ccode\u003eSSG-86\u003c/code\u003e, \u003ccode\u003eSSG-88\u003c/code\u003e, \u003ccode\u003eSSG-92\u003c/code\u003e, \u003ccode\u003eSSG-93\u003c/code\u003e, \u003ccode\u003eSSR-6-REV2\u003c/code\u003e, \u003ccode\u003eTS-G-1-4\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eTable formatting appears to be very mixed. These can occur across bodies, appendicies, and annexes.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAppendix table caption\u003c/strong\u003e\u003c/br\u003eSingle-letter identifier, dot-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE A.1.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-11\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAppendix table caption\u003c/strong\u003e\u003c/br\u003eRoman-numeral identifier, dot-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE I.1.\u003c/code\u003e; \u003ccode\u003eTABLE II.3.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSG-15\u003c/code\u003e, \u003ccode\u003eGSR-PART-3\u003c/code\u003e, \u003ccode\u003eGSR-PART-7\u003c/code\u003e, \u003ccode\u003eSSG-26-REV1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex table caption\u003c/strong\u003e\u003c/br\u003eSingle-letter identifier, dash-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE A–1.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSG-12\u003c/code\u003e, \u003ccode\u003eGSG-19\u003c/code\u003e, \u003ccode\u003eGSR-PART-3\u003c/code\u003e, \u003ccode\u003eGSR-PART-7\u003c/code\u003e, \u003ccode\u003eSSG-51\u003c/code\u003e, \u003ccode\u003eSSG-69\u003c/code\u003e, \u003ccode\u003eSSG-79\u003c/code\u003e, \u003ccode\u003eSSG-89\u003c/code\u003e, \u003ccode\u003eSSG-9-REV1\u003c/code\u003e, \u003ccode\u003eSSG-91\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex table caption\u003c/strong\u003e\u003c/br\u003eRoman-numeral identifier, dash-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE II–3.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSG-1\u003c/code\u003e, \u003ccode\u003eGSG-10\u003c/code\u003e, \u003ccode\u003eGSG-11\u003c/code\u003e, \u003ccode\u003eGSG-14\u003c/code\u003e, \u003ccode\u003eGSG-15\u003c/code\u003e, \u003ccode\u003eGSG-17\u003c/code\u003e, \u003ccode\u003eGSG-18\u003c/code\u003e, \u003ccode\u003eGSG-3\u003c/code\u003e, \u003ccode\u003eNSS-17-T-REV1\u003c/code\u003e, \u003ccode\u003eNSS-22-G\u003c/code\u003e, \u003ccode\u003eNSS-23-G\u003c/code\u003e, \u003ccode\u003eNSS-34-T\u003c/code\u003e, \u003ccode\u003eNSS-38-T\u003c/code\u003e, \u003ccode\u003eNSS-39-T\u003c/code\u003e, \u003ccode\u003eNSS-41-T\u003c/code\u003e, \u003ccode\u003eNSS-42-G\u003c/code\u003e, \u003ccode\u003eNSS-43-T\u003c/code\u003e, \u003ccode\u003eNSS-44-T\u003c/code\u003e, \u003ccode\u003eNSS-47-T\u003c/code\u003e, \u003ccode\u003eNSS-9-G-REV1\u003c/code\u003e, \u003ccode\u003eRS-G-1-9\u003c/code\u003e, \u003ccode\u003eSSG-10-REV1\u003c/code\u003e, \u003ccode\u003eSSG-11\u003c/code\u003e, \u003ccode\u003eSSG-15-REV1\u003c/code\u003e, \u003ccode\u003eSSG-17\u003c/code\u003e, \u003ccode\u003eSSG-18\u003c/code\u003e, \u003ccode\u003eSSG-2-REV1\u003c/code\u003e, \u003ccode\u003eSSG-3-REV1\u003c/code\u003e, \u003ccode\u003eSSG-31\u003c/code\u003e, \u003ccode\u003eSSG-32\u003c/code\u003e, \u003ccode\u003eSSG-34\u003c/code\u003e, \u003ccode\u003eSSG-35\u003c/code\u003e, \u003ccode\u003eSSG-36\u003c/code\u003e, \u003ccode\u003eSSG-39\u003c/code\u003e, \u003ccode\u003eSSG-4-REV1\u003c/code\u003e, \u003ccode\u003eSSG-42-REV1\u003c/code\u003e, \u003ccode\u003eSSG-43-REV1\u003c/code\u003e, \u003ccode\u003eSSG-49\u003c/code\u003e, \u003ccode\u003eSSG-5-REV1\u003c/code\u003e, \u003ccode\u003eSSG-52\u003c/code\u003e, \u003ccode\u003eSSG-57\u003c/code\u003e, \u003ccode\u003eSSG-58\u003c/code\u003e, \u003ccode\u003eSSG-6-REV1\u003c/code\u003e, \u003ccode\u003eSSG-60\u003c/code\u003e, \u003ccode\u003eSSG-65\u003c/code\u003e, \u003ccode\u003eSSG-66\u003c/code\u003e, \u003ccode\u003eSSG-7-REV1\u003c/code\u003e, \u003ccode\u003eSSG-81\u003c/code\u003e, \u003ccode\u003eSSG-84\u003c/code\u003e, \u003ccode\u003eSSG-85\u003c/code\u003e, \u003ccode\u003eSSG-87\u003c/code\u003e, \u003ccode\u003eSSG-90\u003c/code\u003e, \u003ccode\u003eSSR-3\u003c/code\u003e, \u003ccode\u003eTS-G-1-4\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eRS-G-1-9\u003c/code\u003e uses an ASCII hyphen.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eTable caption (alternate)\u003c/strong\u003e\u003c/br\u003eColon-terminated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE 1:\u003c/code\u003e; \u003ccode\u003eTABLE I–1:\u003c/code\u003e; \u003ccode\u003eTABLE I.1:\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-26-REV1\u003c/code\u003e, \u003ccode\u003eSSG-45\u003c/code\u003e, \u003ccode\u003eSSG-66\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-45\u003c/code\u003e uses the colon on substantive table captions; \u003ccode\u003eSSG-66\u003c/code\u003e uses it in templates; \u003ccode\u003eSSG-26-REV1\u003c/code\u003e uses it in front-matter table listings.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAppendix table caption (alternate)\u003c/strong\u003e\u003c/br\u003eRoman-numeral identifier with letter-suffixed table number\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE III.1B.\u003c/code\u003e; \u003ccode\u003eTABLE III.2A.\u003c/code\u003e; \u003ccode\u003eTABLE III.2H.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSR-PART-3\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eUppercase suffixes \u003ccode\u003eA–H\u003c/code\u003e occur, \u003ccode\u003eTABLE III.1a.\u003c/code\u003e also contains a lowercase suffix.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex table caption (alternate)\u003c/strong\u003e\u003c/br\u003eRoman numerals in both components\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eTABLE II–I.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSG-1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eUnique occurrence, the second component is a capital Roman \u003ccode\u003eI\u003c/code\u003e, rather than digit \u003ccode\u003e1\u003c/code\u003e.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eFigure caption\u003c/strong\u003e\u003c/br\u003eNumeric with terminal full stop\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eFIG. 4.\u003c/code\u003e; \u003ccode\u003eFig. 4.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAll documents except \u003ccode\u003eNSS-13\u003c/code\u003e, \u003ccode\u003eNSS-14\u003c/code\u003e, \u003ccode\u003eNSS-15\u003c/code\u003e, \u003ccode\u003eNSS-20\u003c/code\u003e, \u003ccode\u003eNSS-23-G\u003c/code\u003e, \u003ccode\u003eNSS-25-G\u003c/code\u003e, \u003ccode\u003eNSS-29-G\u003c/code\u003e, \u003ccode\u003eNSS-30-G\u003c/code\u003e, \u003ccode\u003eNSS-31-G\u003c/code\u003e, \u003ccode\u003eNSS-32-T\u003c/code\u003e, \u003ccode\u003eNSS-33-T\u003c/code\u003e, \u003ccode\u003eNSS-35-G\u003c/code\u003e, \u003ccode\u003eNSS-36-G\u003c/code\u003e, \u003ccode\u003eNSS-38-T\u003c/code\u003e, \u003ccode\u003eNSS-39-T\u003c/code\u003e, \u003ccode\u003eNSS-43-T\u003c/code\u003e, \u003ccode\u003eRS-G-1-9\u003c/code\u003e, \u003ccode\u003eSF-1\u003c/code\u003e, \u003ccode\u003eWS-G-6-1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eNormal body figure caption. Both uppercase \u003ccode\u003eFIG.\u003c/code\u003e and title-case \u003ccode\u003eFig.\u003c/code\u003e occur.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAppendix figure caption\u003c/strong\u003e\u003c/br\u003eRoman-numeral identifier, dot-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eFIG. I.1.\u003c/code\u003e; \u003ccode\u003eFig. II.1.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-26-REV1\u003c/code\u003e, \u003ccode\u003eSSG-71\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eNumbered appendix figure caption.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex figure caption\u003c/strong\u003e\u003c/br\u003eSingle-letter identifier, dash-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eFIG. A–1.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGS-G-3-5\u003c/code\u003e, \u003ccode\u003eGSG-9\u003c/code\u003e, \u003ccode\u003eSSG-13-REV1\u003c/code\u003e, \u003ccode\u003eSSG-37-REV1\u003c/code\u003e, \u003ccode\u003eSSG-70\u003c/code\u003e, \u003ccode\u003eSSR-4\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSingle appendix figure caption. \u003ccode\u003eSSG-37-REV1\u003c/code\u003e contains both en-dash and ASCII-hyphen forms.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex figure caption\u003c/strong\u003e\u003c/br\u003eRoman-numeral identifier, dash-separated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eFIG. III–1.\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSG-1\u003c/code\u003e, \u003ccode\u003eGSG-10\u003c/code\u003e, \u003ccode\u003eGSG-11\u003c/code\u003e, \u003ccode\u003eGSG-14\u003c/code\u003e, \u003ccode\u003eGSG-15\u003c/code\u003e, \u003ccode\u003eGSG-17\u003c/code\u003e, \u003ccode\u003eGSG-18\u003c/code\u003e, \u003ccode\u003eGSG-3\u003c/code\u003e, \u003ccode\u003eNSS-17-T-REV1\u003c/code\u003e, \u003ccode\u003eNSS-18\u003c/code\u003e, \u003ccode\u003eNSS-22-G\u003c/code\u003e, \u003ccode\u003eNSS-34-T\u003c/code\u003e, \u003ccode\u003eNSS-38-T\u003c/code\u003e, \u003ccode\u003eNSS-41-T\u003c/code\u003e, \u003ccode\u003eNSS-43-T\u003c/code\u003e, \u003ccode\u003eNSS-44-T\u003c/code\u003e, \u003ccode\u003eSSG-17\u003c/code\u003e, \u003ccode\u003eSSG-18\u003c/code\u003e, \u003ccode\u003eSSG-19\u003c/code\u003e, \u003ccode\u003eSSG-21\u003c/code\u003e, \u003ccode\u003eSSG-3-REV1\u003c/code\u003e, \u003ccode\u003eSSG-32\u003c/code\u003e, \u003ccode\u003eSSG-34\u003c/code\u003e, \u003ccode\u003eSSG-4-REV1\u003c/code\u003e, \u003ccode\u003eSSG-40\u003c/code\u003e, \u003ccode\u003eSSG-42-REV1\u003c/code\u003e, \u003ccode\u003eSSG-43-REV1\u003c/code\u003e, \u003ccode\u003eSSG-45\u003c/code\u003e, \u003ccode\u003eSSG-5-REV1\u003c/code\u003e, \u003ccode\u003eSSG-6-REV1\u003c/code\u003e, \u003ccode\u003eSSG-65\u003c/code\u003e, \u003ccode\u003eSSG-7-REV1\u003c/code\u003e, \u003ccode\u003eSSG-84\u003c/code\u003e, \u003ccode\u003eSSG-90\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eFigure caption (alternate)\u003c/strong\u003e\u003c/br\u003eNo terminal punctuation\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eFIG. 1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eGSG-16\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eConfirmed visually on PDF page 24.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cstrong\u003eAnnex figure caption (alternate)\u003c/strong\u003e\u003c/br\u003eColon-terminated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eFIG. II-1:\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ccode\u003eSSG-4-REV1\u003c/code\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eUnique substantive caption, using both an ASCII hyphen and a colon; PDF page 178.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003eIt also accepts several visually similar dash characters. The PDFs contain hyphens, non-breaking hyphens, figure dashes, en dashes and em dashes that look almost identical on the page but behave differently in text matching. This was already a publication problem long before anyone began blaming LLMs for their dashes.\u003c/p\u003e\n\u003cp\u003eMulti-line headings are joined before they update the section path. Contents entries are suppressed rather than mistaken for the beginning of the body. Running headers and page numbers are removed before paragraph reconstruction.\u003c/p\u003e\n\u003cp\u003eSome annexes contain curriculum outlines or reporting templates that are visually tables but have no conventional \u003ccode\u003eTABLE N.\u003c/code\u003e caption. For these, the parser can create a synthetic table record so that their outline numbers do not become dozens of false paragraphs.\u003c/p\u003e\n\u003cp\u003eWhen it reaches a structural boundary, the parser finalises the active element and outputs a record. Instead of dividing the text after a fixed number of characters or sentences, it follows the reference units used by the publications: one numbered paragraph, one requirement, one table, one footnote or one heading.\u003c/p\u003e\n\u003ch3 id=\"3-inferring-metadata-conservatively\"\u003e3. Inferring metadata conservatively\u003c/h3\u003e\n\u003cp\u003eThe parser also needs to identify the publication it is reading. It tries to infer the title, series number, document family, category, type, year and other identifiers from the first pages of the PDF. It avoids generic pages that list all categories in a series because those pages can otherwise be mistaken for the identity of the publication itself.\u003c/p\u003e\n\u003cp\u003eWhere the PDF is ambiguous, the parser can fall back to the filename. A YAML configuration can override either source for documents that remain difficult to identify.\u003c/p\u003e\n\u003cp\u003eThe resulting metadata records where each important value came from: configuration, PDF inference, filename or fallback. This makes it possible to distinguish a value read confidently from the publication from one supplied as a practical default.\u003c/p\u003e\n\u003cp\u003eEach source PDF is also hashed. The hash provides source traceability by identifying exactly which file produced each set of records. It makes no claim about the correctness of the publication itself.\u003c/p\u003e\n\u003ch3 id=\"4-self-describing-records\"\u003e4. Self-describing records\u003c/h3\u003e\n\u003cp\u003eEach structural record contains:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edocument identity and type;\u003c/li\u003e\n\u003cli\u003eelement type and number;\u003c/li\u003e\n\u003cli\u003esource region;\u003c/li\u003e\n\u003cli\u003estatus and the reason for that status;\u003c/li\u003e\n\u003cli\u003esection path;\u003c/li\u003e\n\u003cli\u003ephysical and printed page numbers;\u003c/li\u003e\n\u003cli\u003eextracted text;\u003c/li\u003e\n\u003cli\u003eparser confidence;\u003c/li\u003e\n\u003cli\u003ediagnostic notes; and\u003c/li\u003e\n\u003cli\u003erelationships between elements, such as a footnote and its paragraph.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe full machine-readable index is useful for auditing, testing and building other tools. For an LLM, the parser also produces a more compact Markdown export. A record looks roughly like this:\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-1\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003eYAML\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-1-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy YAML to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-1-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-yaml\" data-lang=\"yaml\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nn\"\u003e---\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003edoc\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003eGSR-PART-2\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003erecord\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003eparagraph 4.32\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003estatus\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003eNormative\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003eregion\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003eBody\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003epdf\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"m\"\u003e27\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003esection\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"m\"\u003e4\u003c/span\u003e\u003cspan class=\"l\"\u003e. LEADERSHIP FOR SAFETY\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nn\"\u003e...\u003c/span\u003e\u003cspan class=\"l\"\u003eparagraph text...\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003cp\u003eThe parser repeats the labels beside every record so that a passage retrieved on its own still identifies its source and status.\u003c/p\u003e\n\u003cp\u003eThe compact Markdown does not contain every field from the structural record. Parser confidence, detailed status reasons and diagnostic notes remain available in the complete output and QA reports. The LLM-facing version keeps the information most useful during retrieval and citation.\u003c/p\u003e\n\u003ch2 id=\"status-is-data-not-decoration\"\u003eStatus is data, not decoration\u003c/h2\u003e\n\u003cp\u003eThe most important design decision was to preserve the status of the text. The \u003ca href=\"https://www.iaea.org/resources/nuclear-security-series\"\u003eNuclear Security Series\u003c/a\u003e has a hierarchy of Fundamentals, Recommendations, Implementing Guides and Technical Guidance. The \u003ca href=\"https://www.iaea.org/resources/safety-standards\"\u003eSafety Standards Series\u003c/a\u003e is organised into Safety Fundamentals, Safety Requirements and Safety Guides.\u003c/p\u003e\n\u003cp\u003eDifferent levels of these hierarchies use different forms of language. Requirements use \u0026ldquo;shall\u0026rdquo;, while guides generally use \u0026ldquo;should\u0026rdquo; when describing recommended measures or acceptable alternatives.\u003c/p\u003e\n\u003cp\u003eStatus also varies within a publication. SPESS C explains that an appendix is integral to a publication and carries the same status as its body. Annexes and footnotes provide practical examples, additional information or explanation and are not integral parts of the main text. Section 1 establishes the background, objective, scope and structure rather than carrying the publication\u0026rsquo;s primary requirements, recommendations or guidance.\u003c/p\u003e\n\u003cp\u003eThe parser represents these distinctions using three deliberately simple labels:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNormative\u003c/strong\u003e: substantive body content from Section 2 onwards, together with substantive appendix material;\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInformative\u003c/strong\u003e: substantive annex material and footnotes; and\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInformational\u003c/strong\u003e: front matter, Section 1 context, headings, references, glossary material, publication metadata and back matter.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe classification is derived from structure: where the element appears, what type of element it is and which section or region governs it. The wording of an individual sentence does not determine its status.\u003c/p\u003e\n\u003cp\u003eHere, \u0026ldquo;Normative\u0026rdquo; refers to the passage\u0026rsquo;s status within the IAEA publication as approved by the relevant committee. Whether it is legally binding is a separate question determined by the relevant national and international framework.\u003c/p\u003e\n\u003cp\u003eLLMs are very good at combining related passages into fluent prose, and that fluency can hide the fact that the passages do not have equal status.\u003c/p\u003e\n\u003cp\u003eAn annex example may be useful, but it should not quietly reappear in an answer as a requirement. A footnote may clarify a paragraph, but it should not become a new recommendation. On the other side of that challenge, excluding all supporting material would discard valuable explanation.\u003c/p\u003e\n\u003cp\u003eMy response to this? Including status on every record! It makes it harder for the model to treat an annex example as equivalent to a requirement.\u003c/p\u003e\n\u003ch2 id=\"what-the-llm-does-with-the-records\"\u003eWhat the LLM does with the records\u003c/h2\u003e\n\u003cp\u003eOnce uploaded, the files are indexed by the platform. The details vary, but the model generally receives only a selection of records for each question. That creates two failure modes: the right record may not be retrieved, or the model may misuse a record that was.\u003c/p\u003e\n\u003cp\u003eThe parser cannot control either stage. It can only make records easier to find and harder to misread by keeping identifiers, section paths, status and page references beside the text. Exact identifiers and paragraph numbers also provide useful anchors when semantic retrieval alone is insufficient.\u003c/p\u003e\n\u003cp\u003eI therefore instruct the model to preserve distinctions between requirements, recommendations, guidance and examples, cite the publication and PDF page (so the PDF can be more easily referenced), and say when the uploaded material does not support an answer.\u003c/p\u003e\n\u003ch2 id=\"working-across-the-series\"\u003eWorking across the series\u003c/h2\u003e\n\u003cp\u003eWith the series represented as structured knowledge, a single query can retrieve records from several publications. In my testing, the most useful questions were those that crossed publication boundaries: an overarching requirement, a guide explaining how it might be met, and an annex illustrating one possible application. Each passage retains its document, paragraph, section, page, and status.\u003c/p\u003e\n\u003cp\u003eThis creates practical questions that ordinary document search handles poorly:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWhat do the overarching requirements say about an issue, and how do the relevant guides elaborate on it?\u003c/li\u003e\n\u003cli\u003eWhich publications discuss the same responsibility from the perspectives of the State, regulator, and operator?\u003c/li\u003e\n\u003cli\u003eWhere does a recommendation originate, and which implementing or technical guidance develops it further?\u003c/li\u003e\n\u003cli\u003eDo several publications use a term consistently?\u003c/li\u003e\n\u003cli\u003eWhich passages establish expectations, and which provide examples of implementation?\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eWith the series represented as structured knowledge, one question can retrieve records from several publications. The model can follow a chain from principle to requirement or recommendation and then to detailed guidance while retaining the document, paragraph, section, page and status of each step.\u003c/p\u003e\n\u003cp\u003eThe questions I found most useful were those that crossed publication boundaries. A single query could surface an overarching requirement, a guide explaining how it might be met and an annex illustrating one possible application, and implict uses of the same concept throughout the series while throughout retaining the status and source of each passage. As an example, I loaded the knowledge files into a Custom GPT and asked it to \u0026ldquo;Summarise where documents in the NSS are implictly describing a Sensitive Digital Asset (SDA) without explicitly using the term\u0026rdquo;. This is what it output:\u003c/p\u003e\n\u003cblockquote class=\"long-quote\"\u003e\u003cp\u003eSeveral IAEA Nuclear Security Series publications address the substance of \u003cstrong\u003esensitive digital assets\u003c/strong\u003e without using that specific term. They discuss computer-based systems, sensitive information assets, digital instrumentation and control systems, networks, and other digital systems whose compromise could affect nuclear safety, nuclear security, nuclear material accounting and control, or emergency response. These references identify systems that may warrant SDA-like protection, but they do not automatically classify every system concerned as an SDA; that determination depends on the function supported, system dependencies, and the potential consequences of compromise.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eProtection of important computer-based systems:\u003c/strong\u003e \u003cstrong\u003eNSS-13\u003c/strong\u003e recommends protecting computer-based systems used for physical protection, nuclear safety, and nuclear material accountancy and control against compromise. This is the clearest precursor to the later SDA concept. See \u003cstrong\u003eNSS-13, paras 4.10 and 5.19, PDF pp. 33 and 44\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSensitive information assets:\u003c/strong\u003e \u003cstrong\u003eNSS-20, NSS-23-G, NSS-29-G, and NSS-11-G (Rev. 1)\u003c/strong\u003e address computer systems, networks, communications systems, digital media, and instrumentation and control systems that process, store, control, or transmit sensitive information. They emphasize protection of confidentiality, integrity, and availability, access control, and security throughout the information life cycle. This category is broader than SDAs because it can also include non-digital assets. See \u003cstrong\u003eNSS-23-G, paras 2.9–2.12 and 6.17, PDF pp. 15–16 and 30\u003c/strong\u003e; \u003cstrong\u003eNSS-29-G, paras 4.47–4.52, section “Security of Information,” PDF pp. 36–37\u003c/strong\u003e; and \u003cstrong\u003eNSS-11-G (Rev. 1), paras 3.20–3.21, PDF pp. 24–25\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDigital instrumentation and control systems:\u003c/strong\u003e \u003cstrong\u003eNSS-33-T\u003c/strong\u003e provides computer-security guidance for instrumentation and control systems performing safety, security, or auxiliary functions. Such systems are a major potential SDA class because their compromise could prevent important functions from being performed. See \u003cstrong\u003eNSS-33-T, paras 1.1–1.4, 1.10, and 1.12, sections “Background,” “Objective,” and “Scope,” PDF pp. 11–13\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCyber, blended, and insider attacks:\u003c/strong\u003e \u003cstrong\u003eNSS-10-G (Rev. 1)\u003c/strong\u003e considers cyberattacks against safety, security, nuclear material accounting and control, and emergency-response systems, including supply-chain compromise and combined physical–cyber attacks. \u003cstrong\u003eNSS-8-G (Rev. 1)\u003c/strong\u003e similarly addresses insider compromise, remote connectivity, and the monitoring of sensitive computer assets. See \u003cstrong\u003eNSS-10-G (Rev. 1), paras 2.19–2.20 and 7.12, sections “Potential Adversaries and Their Attributes and Characteristics” and “Developing Attack Scenarios,” PDF pp. 18 and 39\u003c/strong\u003e; and \u003cstrong\u003eNSS-8-G (Rev. 1), paras 3.9–3.10, 4.78, and 4.84, PDF pp. 19 and 35–37\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eApplication in particular operational areas:\u003c/strong\u003e Other publications apply related computer-security concepts to physical-protection computers and networks, computerized nuclear material accounting and control records, border-detection systems, transport tracking and control systems, and contingency response. Examples include \u003cstrong\u003eNSS-27-G, paras 4.140–4.145, PDF pp. 99–100\u003c/strong\u003e; \u003cstrong\u003eNSS-40-T, paras 3.44 and 6.1–6.5, PDF pp. 29 and 136–137\u003c/strong\u003e; \u003cstrong\u003eNSS-25-G, paras 4.57–4.58, PDF pp. 34–35\u003c/strong\u003e; \u003cstrong\u003eNSS-32-T, paras 3.18–3.20, PDF pp. 19–20\u003c/strong\u003e; and relevant passages in \u003cstrong\u003eNSS-44-T, NSS-46-T, and NSS-39-T\u003c/strong\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThese passages identify \u003cstrong\u003epossible SDA populations\u003c/strong\u003e, not automatic SDA designations. Whether a particular system is an SDA still depends on the function it supports, its dependencies, and the consequences that could result from its compromise.\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003ch2 id=\"tables-and-figures-are-where-honesty-matters-most\"\u003eTables and figures are where honesty matters most\u003c/h2\u003e\n\u003cp\u003eTables quickly became the most persistent parsing problem, a table expresses relationships between rows, columns, headings and cells. PDF extraction often preserves the words but loses those relationships. It can return every cell in sequence without reliably indicating which row or column each value belonged to.\u003c/p\u003e\n\u003cp\u003eContinued tables may repeat their headings. Cell labels can resemble paragraph numbers. A paragraph immediately following a table can be absorbed into the table record. Some annexes contain curricula or report outlines that are visibly tabular but have no useful table metadata in the text layer.\u003c/p\u003e\n\u003cp\u003eThe parser handles table boundaries conservatively and recognises several outline-style blocks as synthetic tables. It preserves the raw extracted text and relevant page range, leaving uncertain row and column relationships unresolved.\u003c/p\u003e\n\u003cp\u003eFor a simple table, the extracted text may be enough. Where the relationship between a row and column affects the meaning, the page image must be checked.\u003c/p\u003e\n\u003cp\u003eFor figures, the record contains the identifier, caption and page reference. Interpreting the diagram still requires inspection of the page image. Someone asked why I did not have another LLM interpret the figure. That would have reintroduced exactly the kind of probabilistic judgement I was trying to keep out of the parser 😉\u003c/p\u003e\n\u003ch2 id=\"building-in-reasons-not-to-trust-it\"\u003eBuilding in reasons not to trust it\u003c/h2\u003e\n\u003cp\u003eA tool used for high-consequence material should make its weaknesses visible. Each run produces manifests, source checksums, a parser version, a run identifier and QA reports alongside the knowledge files. Automated checks look for problems such as:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erequirement markers left inside ordinary paragraphs;\u003c/li\u003e\n\u003cli\u003efootnote bodies contaminating substantive text;\u003c/li\u003e\n\u003cli\u003epage headers or footers that leaked into records;\u003c/li\u003e\n\u003cli\u003ewrapped headings that were not rejoined;\u003c/li\u003e\n\u003cli\u003econtents-page entries mistaken for body content;\u003c/li\u003e\n\u003cli\u003etable cells misidentified as paragraphs;\u003c/li\u003e\n\u003cli\u003estatus labels inconsistent with document regions;\u003c/li\u003e\n\u003cli\u003esuspicious encoding or damaged characters;\u003c/li\u003e\n\u003cli\u003eduplicate record identifiers; and\u003c/li\u003e\n\u003cli\u003edisagreement between the records and the series manifest.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThese checks are alarms rather than certifications of perfect parsing. An empty report means only that the deterministic tests found none of the failure patterns they currently recognise.\u003c/p\u003e\n\u003ch2 id=\"what-the-tool-cannot-promise\"\u003eWhat the tool cannot promise\u003c/h2\u003e\n\u003cp\u003eThe parser has limits that I\u0026rsquo;ve already described and there are still a substantial number of parsing failures, particularly in the Safety Standards Series where I have much less experience with the historical formatting conventions (should a Schedule be treated the same as an Appendix?). I mostly built this for my own use across the NSS.\u003c/p\u003e\n\u003cp\u003eUsing the parser output in a Custom GPT or NotebookLM adds another layer of limitations. A structural boundary may be missed. A damaged text layer may alter a symbol whose exact value matters. A complex table may lose the relationship between a heading and a cell. A figure caption cannot substitute for the figure. A low-confidence footnote boundary may require manual review. Metadata inference can also be wrong, which is why the parser supports overrides and records its sources.\u003c/p\u003e\n\u003cp\u003eThe retrieval system may fail to surface a relevant record or may retrieve a passage without enough neighbouring context. The LLM may misunderstand a label, combine passages too aggressively or produce a citation that does not support every part of its sentence.\u003c/p\u003e\n\u003cp\u003eFor important interpretations, decisions or exact quotations, the answer must be checked against the official PDF. The parser and LLM are best used to help readers locate and compare material before they return to the official publication for verification.\u003c/p\u003e\n\u003ch2 id=\"what-i-learned\"\u003eWhat I learned\u003c/h2\u003e\n\u003cp\u003eBuilding the parser changed the question I was asking. I began by wondering how to put a collection of IAEA publications in front of an LLM. The harder problem was deciding how much of the publication I could stop the visual structure of the PDF from throwing away. While I tried to apply what I thought would be a practible solution, in many cases this either needs to evolve to full OCR, human interpretation, or some other output from the IAEA\u0026rsquo;s publishing system.\u003c/p\u003e\n\u003cp\u003eThe closest analogy is a library in which every book has been emptied into one pile of pages. An LLM may be remarkably good at reading those pages, but someone still has to restore the page numbers, chapter dividers, catalogue records and shelf labels.\u003c/p\u003e\n\u003cp\u003eThat is what I was trying to do.\u003c/p\u003e\n","content_text":"The idea for this experiment came from a few conversations at CyberCon26. I spoke with people who had asked LLMs questions about IAEA safety and nuclear security guidance and come away with an understanding that the publications did not support. The answers were not always obvious hallucinations. Some quoted genuine passages but lost the distinctions that tell an experienced reader what those passages mean and how much weight to give them.\nThat made me suspect the prompt was not the main problem. The model was being given the words without enough of the document around them, so I began looking for a better way to represent the source material. I had done something related during the Committee Draft stage of IEC 63096, when I built a deterministic parser for SC45 WGA9 that generated Annex A from the structured content in the body of the draft. It seemed worth testing the same general approach here.\nIt is easy to upload a folder of PDFs. The difficult part is getting answers that remain useful and defensible once document structure begins to matter. A seemingly simple question can depend on much more than finding the right words. Is the passage a requirement, a recommendation, an example in an annex, or a qualification in a footnote? Does it come from the publication being discussed or from a contents page that repeats the same heading? Is it paragraph 4.32, a table row that happens to begin with 4.32, or a page number that has wandered into the extracted text?\nThese distinctions are routine for someone used to working with IAEA guidance. Once a PDF is flattened into a stream of text, many of them disappear.\nI built the IAEA Guidance Parser to preserve them. It turns local folders of IAEA publications into structured, searchable knowledge files for an LLM. I wanted each retrieved passage to arrive with the context a reader would normally have around it i.e. which publication it came from, where it appeared, and what status it carried.\nThe problem also mattered to me because I had previously worked as a scientific secretary for publications in the NSS. I saw how much work goes into choosing a term, placing a paragraph, and resolving the torrent of comments on any draft text. A paragraph is more than a convenient container for sentences. Its location, its relationship to other publications and its status within the document all affect how it should be read and applied. Those distinctions may appear almost invisible once the final PDF is published but they remain part of the substance created and upheld through the international consensus process.\nSearch was not the hard part My first approach was the obvious one: upload either the extracted text or the raw PDFs to NotebookLM or a Custom GPT. That preserves the words but not necessarily the document. A chapter heading may be separated from the paragraphs it governs. A footnote explaining an exception may be retrieved without the sentence it qualifies. A contents entry may look indistinguishable from the real heading later in the publication.\nPDFs make this particularly difficult. A PDF is often closer to a set of instructions for how a page should look than a structured representation of paragraphs, headings and footnotes. The page can appear perfectly ordered to a person while its text layer contains lines in an inconvenient or misleading reading order. Many of the semantic relationships are only expressed visually rather than encoded explicitly.\nWithout those visual signals, retrieval may find a relevant sentence and still support a misleading answer.\nWhat the parser actually does The parser itself is a deterministic Python program. It reads the PDF text layer, applies explicit recognition and repair rules, maintains state while moving through the publication and emits typed records. The LLM enters the process later, after those records have been exported and uploaded as knowledge.\nThat boundary is deliberate. I did not want a model to guess whether a sentence sounds like a requirement or whether a block looks like an annex. Those decisions can be made more consistently from the publication’s structure, so the parser, rather than the model, decides where paragraphs, annexes, tables, and requirements begin and end.\nIdeally, this structure would be checked by a person or exported directly from the IAEA’s publishing system. As neither option was available—the IAEA’s system or my spare time—the parser reconstructs as much as it can from the published PDFs, largely through trial and error. When I found specific problems, I used an LLM (oh, the irony) to understand the PDF syntax, explore solutions and build regression tests so they would not reappear. This was far from ideal, and I eventually had to turn to my vibe coding LLM friend to restructure the repository before it became a single file containing an endless collection of regular expressions.\n1. Extracting text from a format that was not designed for it The parser opens each PDF and extracts its text page by page. For every page, it retains the physical PDF page number and, where it can identify one safely, the printed page number shown in the publication.\nIt then performs conservative clean-up. It normalises whitespace, removes recognised page-mastering artefacts, joins lines that appear to be artificial PDF wraps and repairs ordinary words split by end-of-line hyphenation. Dashes used in publication identifiers and annex paragraph numbers are preserved because changing them could alter the identifier.\nThe clean-up is deliberately a light touch. It reverses some of the artefacts introduced when a visually mastered page is converted back into a sequence of text lines, without changing the publication’s wording.\nThe current version reads the PDF’s existing text layer and does not perform OCR. If an older PDF contains damaged font mappings, or a scanned page has no usable text layer, the parser cannot reconstruct the intended characters. It can flag suspicious output, but the source still requires review or a separate OCR process.\n2. Rebuilding structure with a small state machine After extraction, the parser walks through the cleaned lines in order. It keeps track of its current position in the publication, including:\nthe current region, such as front matter, body, appendix, annex or references; the current major heading and subheading; whether it is still inside the contents pages; the active paragraph or other prose block; and whether a table is open across one or more pages. The order in which it tests each line matters. Tables are considered before ordinary paragraphs because a table cell can begin with something that looks exactly like a paragraph number. Region transitions are handled before prose so that an Annex heading changes the classification of everything that follows. Requirement headings are separated before a preceding paragraph can absorb them.\nFootnotes are extracted without automatically ending the paragraph they interrupt. In many PDFs, the main sentence continues after the footnote, sometimes on the next page.\nI had thought that with SPESS C guidance for drafters and a single template in use within the IAEA there would be a pretty consistent use of formatting across both series. However that’s not always the case. I’ve had to debug the parser until it was capable of recognising numbering patterns used across different generations of the series, including forms such as:\nConvention Example Documents in which it occurs Notes Body paragraphHierarchical decimal number with terminal full stop 1.1.; 2.4.1. All 179 documents except SSR-6-REV2 Normal body-paragraph convention. Body paragraph (alternate)Three-digit number with terminal full stop 101.; 701. SSR-6-REV2; SSG-78 In SSR-6-REV2, these are used as the normal body paragraphs. In SSG-78, numbers such as 100. are used to number checklist questions within an Annex without an Annex prefix. Advisory subparagraph (alternate)Three-digit parent plus decimal suffix 101.1.; 701.4. SSG-26-REV1 Advisory paragraphs expanding on the corresponding three-digit SSR-6 paragraph. Body paragraph (alternate)Letter-suffixed three-digit number 220A.; 229B. SSR-6-REV2 Paragraphs throughout the document that appear to expand on the proceeding numbered paragraph without the letter suffix. Advisory subparagraph (alternate)Letter-suffixed three-digit parent plus decimal suffix 220A.1.; 613A.6. SSG-26-REV1 Advisory paragraphs extending or ranging over the corresponding three-digit SSR-6 paragraph, e.g.: 220A.1–220A.7, 524A.1, 536A.1, 613A.1–613A.6, 827A.1. Appendix paragraphSingle-letter identifier, dot-separated A.1.; A.64. GSG-1, GSG-10, GSG-11, GSG-14, GSG-16, GSG-18, GSG-8, NSS-10-G-REV1, NSS-17-T-REV1, NSS-40-T, NSS-42-G, NSS-44-T, SSG-11, SSG-12, SSG-20-REV1, SSG-28, SSG-35, SSG-4-REV1, SSG-47, SSG-50, SSG-53, SSG-54, SSG-79, SSG-80, SSG-81, SSG-89, SSG-90, SSG-92, SSR-4, SSR-5, TS-G-1-4, WS-G-6-1 Appears to be the format preferred for a document with a single Appendix. Appendix paragraphRoman-numeral identifier, dot-separated I.1.; III.21. GS-G-2-1, GS-G-3-1, GS-G-3-5, GSG-12, GSG-13, GSG-15, GSG-17, GSG-2, GSG-6, GSG-7, GSR-PART-3, GSR-PART-7, NSS-11-G-REV1, NSS-22-G, NSS-24-G, NSS-26-G, NSS-27-G, NSS-28-T, NSS-29-G, NSS-32-T, NSS-34-T, NSS-4, NSS-41-T, NSS-5, NSS-6, NSS-9-G-REV1, RS-G-1-9, SSG-1-REV1, SSG-14, SSG-15-REV1, SSG-19, SSG-21, SSG-25, SSG-26-REV1, SSG-29, SSG-40, SSG-41, SSG-45, SSG-46, SSG-49, SSG-55, SSG-60, SSG-61, SSG-64, SSG-65, SSG-66, SSG-70, SSG-71, SSG-77, SSG-83, SSG-91, SSR-3 Annex paragraphSingle-letter identifier, dash-separated A–1.; A–6. GS-G-2-1, GS-G-3-5, GSG-12, GSG-19, GSG-6, GSG-7, GSG-9, GSR-PART-3, GSR-PART-5, GSR-PART-7, SSG-13-REV1, SSG-28, SSG-37-REV1, SSG-50, SSG-51, SSG-54, SSG-63, SSG-69, SSG-70, SSG-72, SSG-79, SSG-82, SSG-89, SSG-91, SSR-4, SSR-5 Appears to be the format preferred for a document with a single Annex. SSG-37-REV1 figure uses an ASCII hyphen instead of an en dash. Annex paragraphRoman-numeral identifier, dash-separated I–1.; III–21. GS-G-3-1, GSG-1, GSG-10, GSG-11, GSG-14, GSG-15, GSG-17, GSG-18, GSG-3, GSG-5, NSS-12-T-REV1, NSS-17-T-REV1, NSS-2-G-REV1, NSS-22-G, NSS-23-G, NSS-3, NSS-34-T, NSS-38-T, NSS-39-T, NSS-41-T, NSS-42-G, NSS-43-T, NSS-44-T, NSS-47-T, NSS-9-G-REV1, RS-G-1-9, SSG-1-REV1, SSG-10-REV1, SSG-11, SSG-15-REV1, SSG-17, SSG-18, SSG-19, SSG-2-REV1, SSG-20-REV1, SSG-21, SSG-24-REV1, SSG-3-REV1, SSG-31, SSG-32, SSG-34, SSG-35, SSG-36, SSG-39, SSG-4-REV1, SSG-42-REV1, SSG-43-REV1, SSG-47, SSG-49, SSG-5-REV1, SSG-52, SSG-57, SSG-58, SSG-59, SSG-6-REV1, SSG-60, SSG-65, SSG-66, SSG-7-REV1, SSG-78, SSG-81, SSG-84, SSG-85, SSG-86, SSG-87, SSG-88, SSG-90, SSR-3 Most use an en dash; RS-G-1-9 and NSS-43-T contain ASCII-hyphen variants, and SSG-47 contains a figure-dash character. Local decimal numberingRepeated identifiers 8.1.–8.6. SSG-33-REV1, SSG-66, TS-G-1-4, NSS-9-G-REV1 The same identifiers recur in different schedules, templates, appendices, or table sections. The number may not be globally unique within a single document. Body or template numberNo terminal full stop 106.2; 4.4; 2.5; 6.1 SSG-26-REV1, NSS-25-G, NSS-36-G, NSS-29-G, NSS-9-G-REV1 Omitted in SSG-26-REV1 106.2; NSS-25-G 4.4; NSS-36-G 2.5, 2.7, 2.8. NSS-29-G and NSS-9-G-REV1 use unpunctuated local template/annex outlines. Table-cell cross-referenceBare three-digit number 503; 580; 581 SSG-33-REV1 These are references to SSR-6 paragraphs, not new paragraphs. Requirement headingColon-terminated Requirement 7: GSR-PART-1-REV1, GSR-PART-2, GSR-PART-3, GSR-PART-4-REV1, GSR-PART-5, GSR-PART-6, GSR-PART-7, SSR-1, SSR-2-1-REV1, SSR-2-2-REV1, SSR-3, SSR-4, SSR-5 13 Requirements publications. Capitalisation is normally Requirement, although uppercase forms occur in contents/headings. Table captionNumeric with terminal full stop TABLE 4. GS-G-2-1, GSG-10, GSG-11, GSG-17, GSG-18, GSG-19, GSG-2, GSG-7, GSG-8, GSR-PART-3, GSR-PART-7, NSS-10-G-REV1, NSS-11-G-REV1, NSS-12-T-REV1, NSS-2-G-REV1, NSS-24-G, NSS-27-G, NSS-28-T, NSS-36-G, NSS-37-G, NSS-4, NSS-40-T, NSS-41-T, NSS-43-T, NSS-46-T, NSS-5, NSS-6, NSS-9-G-REV1, RS-G-1-9, SSG-1-REV1, SSG-10-REV1, SSG-14, SSG-15-REV1, SSG-16-REV1, SSG-17, SSG-2-REV1, SSG-21, SSG-25, SSG-26-REV1, SSG-27-REV1, SSG-29, SSG-30, SSG-32, SSG-33-REV1, SSG-4-REV1, SSG-40, SSG-41, SSG-45, SSG-46, SSG-48, SSG-52, SSG-53, SSG-54, SSG-57, SSG-58, SSG-60, SSG-61, SSG-66, SSG-67, SSG-79, SSG-81, SSG-86, SSG-88, SSG-92, SSG-93, SSR-6-REV2, TS-G-1-4 Table formatting appears to be very mixed. These can occur across bodies, appendicies, and annexes. Appendix table captionSingle-letter identifier, dot-separated TABLE A.1. SSG-11 Appendix table captionRoman-numeral identifier, dot-separated TABLE I.1.; TABLE II.3. GSG-15, GSR-PART-3, GSR-PART-7, SSG-26-REV1 Annex table captionSingle-letter identifier, dash-separated TABLE A–1. GSG-12, GSG-19, GSR-PART-3, GSR-PART-7, SSG-51, SSG-69, SSG-79, SSG-89, SSG-9-REV1, SSG-91 Annex table captionRoman-numeral identifier, dash-separated TABLE II–3. GSG-1, GSG-10, GSG-11, GSG-14, GSG-15, GSG-17, GSG-18, GSG-3, NSS-17-T-REV1, NSS-22-G, NSS-23-G, NSS-34-T, NSS-38-T, NSS-39-T, NSS-41-T, NSS-42-G, NSS-43-T, NSS-44-T, NSS-47-T, NSS-9-G-REV1, RS-G-1-9, SSG-10-REV1, SSG-11, SSG-15-REV1, SSG-17, SSG-18, SSG-2-REV1, SSG-3-REV1, SSG-31, SSG-32, SSG-34, SSG-35, SSG-36, SSG-39, SSG-4-REV1, SSG-42-REV1, SSG-43-REV1, SSG-49, SSG-5-REV1, SSG-52, SSG-57, SSG-58, SSG-6-REV1, SSG-60, SSG-65, SSG-66, SSG-7-REV1, SSG-81, SSG-84, SSG-85, SSG-87, SSG-90, SSR-3, TS-G-1-4 RS-G-1-9 uses an ASCII hyphen. Table caption (alternate)Colon-terminated TABLE 1:; TABLE I–1:; TABLE I.1: SSG-26-REV1, SSG-45, SSG-66 SSG-45 uses the colon on substantive table captions; SSG-66 uses it in templates; SSG-26-REV1 uses it in front-matter table listings. Appendix table caption (alternate)Roman-numeral identifier with letter-suffixed table number TABLE III.1B.; TABLE III.2A.; TABLE III.2H. GSR-PART-3 Uppercase suffixes A–H occur, TABLE III.1a. also contains a lowercase suffix. Annex table caption (alternate)Roman numerals in both components TABLE II–I. GSG-1 Unique occurrence, the second component is a capital Roman I, rather than digit 1. Figure captionNumeric with terminal full stop FIG. 4.; Fig. 4. All documents except NSS-13, NSS-14, NSS-15, NSS-20, NSS-23-G, NSS-25-G, NSS-29-G, NSS-30-G, NSS-31-G, NSS-32-T, NSS-33-T, NSS-35-G, NSS-36-G, NSS-38-T, NSS-39-T, NSS-43-T, RS-G-1-9, SF-1, WS-G-6-1 Normal body figure caption. Both uppercase FIG. and title-case Fig. occur. Appendix figure captionRoman-numeral identifier, dot-separated FIG. I.1.; Fig. II.1. SSG-26-REV1, SSG-71 Numbered appendix figure caption. Annex figure captionSingle-letter identifier, dash-separated FIG. A–1. GS-G-3-5, GSG-9, SSG-13-REV1, SSG-37-REV1, SSG-70, SSR-4 Single appendix figure caption. SSG-37-REV1 contains both en-dash and ASCII-hyphen forms. Annex figure captionRoman-numeral identifier, dash-separated FIG. III–1. GSG-1, GSG-10, GSG-11, GSG-14, GSG-15, GSG-17, GSG-18, GSG-3, NSS-17-T-REV1, NSS-18, NSS-22-G, NSS-34-T, NSS-38-T, NSS-41-T, NSS-43-T, NSS-44-T, SSG-17, SSG-18, SSG-19, SSG-21, SSG-3-REV1, SSG-32, SSG-34, SSG-4-REV1, SSG-40, SSG-42-REV1, SSG-43-REV1, SSG-45, SSG-5-REV1, SSG-6-REV1, SSG-65, SSG-7-REV1, SSG-84, SSG-90 Figure caption (alternate)No terminal punctuation FIG. 1 GSG-16 Confirmed visually on PDF page 24. Annex figure caption (alternate)Colon-terminated FIG. II-1: SSG-4-REV1 Unique substantive caption, using both an ASCII hyphen and a colon; PDF page 178. It also accepts several visually similar dash characters. The PDFs contain hyphens, non-breaking hyphens, figure dashes, en dashes and em dashes that look almost identical on the page but behave differently in text matching. This was already a publication problem long before anyone began blaming LLMs for their dashes.\nMulti-line headings are joined before they update the section path. Contents entries are suppressed rather than mistaken for the beginning of the body. Running headers and page numbers are removed before paragraph reconstruction.\nSome annexes contain curriculum outlines or reporting templates that are visually tables but have no conventional TABLE N. caption. For these, the parser can create a synthetic table record so that their outline numbers do not become dozens of false paragraphs.\nWhen it reaches a structural boundary, the parser finalises the active element and outputs a record. Instead of dividing the text after a fixed number of characters or sentences, it follows the reference units used by the publications: one numbered paragraph, one requirement, one table, one footnote or one heading.\n3. Inferring metadata conservatively The parser also needs to identify the publication it is reading. It tries to infer the title, series number, document family, category, type, year and other identifiers from the first pages of the PDF. It avoids generic pages that list all categories in a series because those pages can otherwise be mistaken for the identity of the publication itself.\nWhere the PDF is ambiguous, the parser can fall back to the filename. A YAML configuration can override either source for documents that remain difficult to identify.\nThe resulting metadata records where each important value came from: configuration, PDF inference, filename or fallback. This makes it possible to distinguish a value read confidently from the publication from one supplied as a practical default.\nEach source PDF is also hashed. The hash provides source traceability by identifying exactly which file produced each set of records. It makes no claim about the correctness of the publication itself.\n4. Self-describing records Each structural record contains:\ndocument identity and type; element type and number; source region; status and the reason for that status; section path; physical and printed page numbers; extracted text; parser confidence; diagnostic notes; and relationships between elements, such as a footnote and its paragraph. The full machine-readable index is useful for auditing, testing and building other tools. For an LLM, the parser also produces a more compact Markdown export. A record looks roughly like this:\nYAML Wrap Copy --- doc: GSR-PART-2 record: paragraph 4.32 status: Normative region: Body pdf: 27 section: 4. LEADERSHIP FOR SAFETY ...paragraph text... The parser repeats the labels beside every record so that a passage retrieved on its own still identifies its source and status.\nThe compact Markdown does not contain every field from the structural record. Parser confidence, detailed status reasons and diagnostic notes remain available in the complete output and QA reports. The LLM-facing version keeps the information most useful during retrieval and citation.\nStatus is data, not decoration The most important design decision was to preserve the status of the text. The Nuclear Security Series has a hierarchy of Fundamentals, Recommendations, Implementing Guides and Technical Guidance. The Safety Standards Series is organised into Safety Fundamentals, Safety Requirements and Safety Guides.\nDifferent levels of these hierarchies use different forms of language. Requirements use “shall”, while guides generally use “should” when describing recommended measures or acceptable alternatives.\nStatus also varies within a publication. SPESS C explains that an appendix is integral to a publication and carries the same status as its body. Annexes and footnotes provide practical examples, additional information or explanation and are not integral parts of the main text. Section 1 establishes the background, objective, scope and structure rather than carrying the publication’s primary requirements, recommendations or guidance.\nThe parser represents these distinctions using three deliberately simple labels:\nNormative: substantive body content from Section 2 onwards, together with substantive appendix material; Informative: substantive annex material and footnotes; and Informational: front matter, Section 1 context, headings, references, glossary material, publication metadata and back matter. The classification is derived from structure: where the element appears, what type of element it is and which section or region governs it. The wording of an individual sentence does not determine its status.\nHere, “Normative” refers to the passage’s status within the IAEA publication as approved by the relevant committee. Whether it is legally binding is a separate question determined by the relevant national and international framework.\nLLMs are very good at combining related passages into fluent prose, and that fluency can hide the fact that the passages do not have equal status.\nAn annex example may be useful, but it should not quietly reappear in an answer as a requirement. A footnote may clarify a paragraph, but it should not become a new recommendation. On the other side of that challenge, excluding all supporting material would discard valuable explanation.\nMy response to this? Including status on every record! It makes it harder for the model to treat an annex example as equivalent to a requirement.\nWhat the LLM does with the records Once uploaded, the files are indexed by the platform. The details vary, but the model generally receives only a selection of records for each question. That creates two failure modes: the right record may not be retrieved, or the model may misuse a record that was.\nThe parser cannot control either stage. It can only make records easier to find and harder to misread by keeping identifiers, section paths, status and page references beside the text. Exact identifiers and paragraph numbers also provide useful anchors when semantic retrieval alone is insufficient.\nI therefore instruct the model to preserve distinctions between requirements, recommendations, guidance and examples, cite the publication and PDF page (so the PDF can be more easily referenced), and say when the uploaded material does not support an answer.\nWorking across the series With the series represented as structured knowledge, a single query can retrieve records from several publications. In my testing, the most useful questions were those that crossed publication boundaries: an overarching requirement, a guide explaining how it might be met, and an annex illustrating one possible application. Each passage retains its document, paragraph, section, page, and status.\nThis creates practical questions that ordinary document search handles poorly:\nWhat do the overarching requirements say about an issue, and how do the relevant guides elaborate on it? Which publications discuss the same responsibility from the perspectives of the State, regulator, and operator? Where does a recommendation originate, and which implementing or technical guidance develops it further? Do several publications use a term consistently? Which passages establish expectations, and which provide examples of implementation? With the series represented as structured knowledge, one question can retrieve records from several publications. The model can follow a chain from principle to requirement or recommendation and then to detailed guidance while retaining the document, paragraph, section, page and status of each step.\nThe questions I found most useful were those that crossed publication boundaries. A single query could surface an overarching requirement, a guide explaining how it might be met and an annex illustrating one possible application, and implict uses of the same concept throughout the series while throughout retaining the status and source of each passage. As an example, I loaded the knowledge files into a Custom GPT and asked it to “Summarise where documents in the NSS are implictly describing a Sensitive Digital Asset (SDA) without explicitly using the term”. This is what it output:\nSeveral IAEA Nuclear Security Series publications address the substance of sensitive digital assets without using that specific term. They discuss computer-based systems, sensitive information assets, digital instrumentation and control systems, networks, and other digital systems whose compromise could affect nuclear safety, nuclear security, nuclear material accounting and control, or emergency response. These references identify systems that may warrant SDA-like protection, but they do not automatically classify every system concerned as an SDA; that determination depends on the function supported, system dependencies, and the potential consequences of compromise.\nProtection of important computer-based systems: NSS-13 recommends protecting computer-based systems used for physical protection, nuclear safety, and nuclear material accountancy and control against compromise. This is the clearest precursor to the later SDA concept. See NSS-13, paras 4.10 and 5.19, PDF pp. 33 and 44. Sensitive information assets: NSS-20, NSS-23-G, NSS-29-G, and NSS-11-G (Rev. 1) address computer systems, networks, communications systems, digital media, and instrumentation and control systems that process, store, control, or transmit sensitive information. They emphasize protection of confidentiality, integrity, and availability, access control, and security throughout the information life cycle. This category is broader than SDAs because it can also include non-digital assets. See NSS-23-G, paras 2.9–2.12 and 6.17, PDF pp. 15–16 and 30; NSS-29-G, paras 4.47–4.52, section “Security of Information,” PDF pp. 36–37; and NSS-11-G (Rev. 1), paras 3.20–3.21, PDF pp. 24–25. Digital instrumentation and control systems: NSS-33-T provides computer-security guidance for instrumentation and control systems performing safety, security, or auxiliary functions. Such systems are a major potential SDA class because their compromise could prevent important functions from being performed. See NSS-33-T, paras 1.1–1.4, 1.10, and 1.12, sections “Background,” “Objective,” and “Scope,” PDF pp. 11–13. Cyber, blended, and insider attacks: NSS-10-G (Rev. 1) considers cyberattacks against safety, security, nuclear material accounting and control, and emergency-response systems, including supply-chain compromise and combined physical–cyber attacks. NSS-8-G (Rev. 1) similarly addresses insider compromise, remote connectivity, and the monitoring of sensitive computer assets. See NSS-10-G (Rev. 1), paras 2.19–2.20 and 7.12, sections “Potential Adversaries and Their Attributes and Characteristics” and “Developing Attack Scenarios,” PDF pp. 18 and 39; and NSS-8-G (Rev. 1), paras 3.9–3.10, 4.78, and 4.84, PDF pp. 19 and 35–37. Application in particular operational areas: Other publications apply related computer-security concepts to physical-protection computers and networks, computerized nuclear material accounting and control records, border-detection systems, transport tracking and control systems, and contingency response. Examples include NSS-27-G, paras 4.140–4.145, PDF pp. 99–100; NSS-40-T, paras 3.44 and 6.1–6.5, PDF pp. 29 and 136–137; NSS-25-G, paras 4.57–4.58, PDF pp. 34–35; NSS-32-T, paras 3.18–3.20, PDF pp. 19–20; and relevant passages in NSS-44-T, NSS-46-T, and NSS-39-T. These passages identify possible SDA populations, not automatic SDA designations. Whether a particular system is an SDA still depends on the function it supports, its dependencies, and the consequences that could result from its compromise.\nTables and figures are where honesty matters most Tables quickly became the most persistent parsing problem, a table expresses relationships between rows, columns, headings and cells. PDF extraction often preserves the words but loses those relationships. It can return every cell in sequence without reliably indicating which row or column each value belonged to.\nContinued tables may repeat their headings. Cell labels can resemble paragraph numbers. A paragraph immediately following a table can be absorbed into the table record. Some annexes contain curricula or report outlines that are visibly tabular but have no useful table metadata in the text layer.\nThe parser handles table boundaries conservatively and recognises several outline-style blocks as synthetic tables. It preserves the raw extracted text and relevant page range, leaving uncertain row and column relationships unresolved.\nFor a simple table, the extracted text may be enough. Where the relationship between a row and column affects the meaning, the page image must be checked.\nFor figures, the record contains the identifier, caption and page reference. Interpreting the diagram still requires inspection of the page image. Someone asked why I did not have another LLM interpret the figure. That would have reintroduced exactly the kind of probabilistic judgement I was trying to keep out of the parser 😉\nBuilding in reasons not to trust it A tool used for high-consequence material should make its weaknesses visible. Each run produces manifests, source checksums, a parser version, a run identifier and QA reports alongside the knowledge files. Automated checks look for problems such as:\nrequirement markers left inside ordinary paragraphs; footnote bodies contaminating substantive text; page headers or footers that leaked into records; wrapped headings that were not rejoined; contents-page entries mistaken for body content; table cells misidentified as paragraphs; status labels inconsistent with document regions; suspicious encoding or damaged characters; duplicate record identifiers; and disagreement between the records and the series manifest. These checks are alarms rather than certifications of perfect parsing. An empty report means only that the deterministic tests found none of the failure patterns they currently recognise.\nWhat the tool cannot promise The parser has limits that I’ve already described and there are still a substantial number of parsing failures, particularly in the Safety Standards Series where I have much less experience with the historical formatting conventions (should a Schedule be treated the same as an Appendix?). I mostly built this for my own use across the NSS.\nUsing the parser output in a Custom GPT or NotebookLM adds another layer of limitations. A structural boundary may be missed. A damaged text layer may alter a symbol whose exact value matters. A complex table may lose the relationship between a heading and a cell. A figure caption cannot substitute for the figure. A low-confidence footnote boundary may require manual review. Metadata inference can also be wrong, which is why the parser supports overrides and records its sources.\nThe retrieval system may fail to surface a relevant record or may retrieve a passage without enough neighbouring context. The LLM may misunderstand a label, combine passages too aggressively or produce a citation that does not support every part of its sentence.\nFor important interpretations, decisions or exact quotations, the answer must be checked against the official PDF. The parser and LLM are best used to help readers locate and compare material before they return to the official publication for verification.\nWhat I learned Building the parser changed the question I was asking. I began by wondering how to put a collection of IAEA publications in front of an LLM. The harder problem was deciding how much of the publication I could stop the visual structure of the PDF from throwing away. While I tried to apply what I thought would be a practible solution, in many cases this either needs to evolve to full OCR, human interpretation, or some other output from the IAEA’s publishing system.\nThe closest analogy is a library in which every book has been emptied into one pile of pages. An LLM may be remarkably good at reading those pages, but someone still has to restore the page numbers, chapter dividers, catalogue records and shelf labels.\nThat is what I was trying to do.\n","date_published":"2026-07-18T00:00:00+10:00","id":"https://blog.mitcdh.au/posts/parsing-consensus/","image":"https://blog.mitcdh.au/images/parsing-consensus.webp","summary":"Experiments in parsing IAEA guidance into structured knowledge for LLMs","tags":["Writing","Nuclear","Technology","Security","Code"],"title":"Parsing Consensus","url":"https://blog.mitcdh.au/posts/parsing-consensus/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis review may contain spoilers.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eMy uncle once showed me a copy of The Odyssey carried to Australia, allegedly, aboard the First Fleet. It felt like a beautiful object: an ancient story of wandering, endurance, and homecoming transported across the world. The story I grew up with saw Odysseus as a hero tested by monsters, gods and hostile lands as he struggles home from Troy. Nolan’s film makes that much harder to romanticise.\u003c/p\u003e\n\u003cp\u003eOdysseus, his men, and all those who returned from Troy do not arrive as innocent wanderers. They arrive armed, traumatised, and practised in deception. They take what they need (or try to) and leave violence behind. They survived the war, but they also spread it.\u003c/p\u003e\n\u003cp\u003eFrom the ship, they are exhausted men searching for home. From every shore, they are the people who come from the sea.\u003c/p\u003e\n\u003cp\u003eThe turning point in the movie is when we realise that the war had reached Ithaca before Odysseus. His reflection highlights how the suitors, having tormented his household and relentlessly pursued Penelope, were reproducing the same entitlement, deception, and violence that characterised the war. It has travelled inside the men who fought there; its disorder has taken root in the homes to which they had returned.\u003c/p\u003e\n\u003cp\u003eThat shift makes Nolan’s Odyssey fiercely anti-war: a story about how war survives its battlefield, remakes those who endure it and turns one people’s victory into another people’s catastrophe.\u003c/p\u003e\n\u003cp\u003eI now think differently about that copy carried aboard the First Fleet. It did not cross the ocean alone, but with passengers who imagined themselves as voyagers entering a new world. From the shore, the story looked very different.\u003c/p\u003e\n\u003cp\u003eWatching Nolan\u0026rsquo;s interpretation has left me wondering: who are we—the people watching the horizon, or the ones who came from the sea?\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://letterboxd.com/mitcdh/film/the-odyssey-2026/\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"This review may contain spoilers.\nMy uncle once showed me a copy of The Odyssey carried to Australia, allegedly, aboard the First Fleet. It felt like a beautiful object: an ancient story of wandering, endurance, and homecoming transported across the world. The story I grew up with saw Odysseus as a hero tested by monsters, gods and hostile lands as he struggles home from Troy. Nolan’s film makes that much harder to romanticise.\nOdysseus, his men, and all those who returned from Troy do not arrive as innocent wanderers. They arrive armed, traumatised, and practised in deception. They take what they need (or try to) and leave violence behind. They survived the war, but they also spread it.\nFrom the ship, they are exhausted men searching for home. From every shore, they are the people who come from the sea.\nThe turning point in the movie is when we realise that the war had reached Ithaca before Odysseus. His reflection highlights how the suitors, having tormented his household and relentlessly pursued Penelope, were reproducing the same entitlement, deception, and violence that characterised the war. It has travelled inside the men who fought there; its disorder has taken root in the homes to which they had returned.\nThat shift makes Nolan’s Odyssey fiercely anti-war: a story about how war survives its battlefield, remakes those who endure it and turns one people’s victory into another people’s catastrophe.\nI now think differently about that copy carried aboard the First Fleet. It did not cross the ocean alone, but with passengers who imagined themselves as voyagers entering a new world. From the shore, the story looked very different.\nWatching Nolan’s interpretation has left me wondering: who are we—the people watching the horizon, or the ones who came from the sea?\nView this review on Letterboxd\n","date_published":"2026-07-16T12:57:13Z","id":"https://blog.mitcdh.au/posts/the-odyssey-2026-07-16-film-review/","image":"https://blog.mitcdh.au/images/the-odyssey-2026-07-16-film-review.jpg","summary":"Rating: 4.5/5","tags":["Review","Film"],"title":"The Odyssey (2026)","url":"https://blog.mitcdh.au/posts/the-odyssey-2026-07-16-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eOne Battle After Another feels like TEMU Andor: a discount rebellion against a discount empire, both sides morally flattened and dressed in the same disposable plastic sheen. The resistance has vibes, the regime has spectacle, and history has been replaced by a shopping trolley full of product placements (don\u0026rsquo;t drink and drive kids!). Contemporary masterpiece.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://letterboxd.com/mitcdh/film/one-battle-after-another/\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"One Battle After Another feels like TEMU Andor: a discount rebellion against a discount empire, both sides morally flattened and dressed in the same disposable plastic sheen. The resistance has vibes, the regime has spectacle, and history has been replaced by a shopping trolley full of product placements (don’t drink and drive kids!). Contemporary masterpiece.\nView this review on Letterboxd\n","date_published":"2026-06-29T04:24:15Z","id":"https://blog.mitcdh.au/posts/one-battle-after-another-2026-06-29-film-review/","image":"https://blog.mitcdh.au/images/one-battle-after-another-2026-06-29-film-review.jpg","summary":"Rating: 4.0/5","tags":["Review","Film"],"title":"One Battle After Another (2025)","url":"https://blog.mitcdh.au/posts/one-battle-after-another-2026-06-29-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis article has been adapted verbatim from a paper accepted and presented during the \u003ca href=\"https://www.iaea.org/events/cybercon26\"\u003eInternational Conference on Computer Security in the Nuclear World: Securing the Future\u003c/a\u003e titled \u0026lsquo;\u003ca href=\"https://conferences.iaea.org/event/428/contributions/38952/\"\u003eWhy Nuclear Security Needs Information Security: The Promise Of NST070\u003c/a\u003e\u0026rsquo; authored by \u003ca href=\"https://www.linkedin.com/in/mike-stjohn-green-685b6163/\"\u003eMike StJohn-Green\u003c/a\u003e and myself.\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"abstract\"\u003eAbstract\u003c/h2\u003e\n\u003cp\u003eEffective computer security requires information security. Computers, like humans, are actors on information and adversaries target the functions they perform by compromising the confidentiality, integrity, or availability (CIA) of the information itself.\u003c/p\u003e\n\u003cp\u003eModern information is fluid and knowledge-based, capable of being inferred from fragments and moving beyond traditional boundaries. This makes older, containment-based security models that treat information as a simple object appear increasingly obsolete. The value of information is also asymmetric; what seems routine to a defender can reveal critical vulnerabilities to an attacker. Since information\u0026rsquo;s value is derived from its use within a function, any compromise of its CIA can be quantified by the potential impacts to that function\u0026rsquo;s performance.\u003c/p\u003e\n\u003cp\u003eThe IAEA\u0026rsquo;s circulated draft of NST070 describes an integrated, life-cycle approach that protects information\u0026rsquo;s CIA during both its processing and its ultimate use. This model, with its holistic approach, fills gaps legacy systems cannot, resulting in strong security against modern threats and the future of AI. NST070 is set to become an essential security evolution, closing gaps within legacy models to create a truly modern defence. This paper will illustrate how the circulated draft of NST070 delivers this.\u003c/p\u003e\n\u003ch2 id=\"1-introduction\"\u003e1. Introduction\u003c/h2\u003e\n\u003cp\u003eNuclear security guidance has historically evolved from the principles of physical protection, heavily emphasising the containment of physical objects based on an analysis of their static value. This approach proved effective when confidentiality was the predominant concern, particularly against adversaries seeking to collect intelligence. This lineage is evident in legacy information security frameworks, such as IAEA Nuclear Security Series No. 23-G Security of Nuclear Information\u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e (NSS 23-G), which focused on protecting the confidentiality of discrete \u0026ldquo;information objects\u0026rdquo;\u0026mdash;tangible items like hard copy documents and electronic files\u0026mdash;under the assumption that if the object is contained, the information is secure.\u003c/p\u003e\n\u003cp\u003eHowever, the rapid digitalisation of nuclear infrastructure and the use of computer based systems to control physical machines have exposed the limitations of a purely containment-centric posture. Information is no longer merely a physical asset to be locked away; it is both a dynamic component and a functional dependency of the functions we rely on for nuclear safety and security. As a result of this shift while confidentiality remains important, our approaches to the integrity and availability of information have moved to the centre of security discourse. This is increasingly evident as vulnerabilities within industrial control systems become high-profile targets for non-state actors and central to greyzone warfare, where digital interference serves as a potent tool for disruption without triggering conventional conflict\u003csup id=\"fnref:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eApproaches to information security have struggled to keep pace with this change. Much existing analysis and labelling still rely heavily on containment models, such as marking documents as confidential and applying standardised security controls to them, with little analysis of how the information is used, trusted, and how that could be exploited. Modern adversarial tactics render these models increasingly insufficient. Integrity faces escalating threats from new techniques designed to deceive users\u0026mdash;both human and machine\u0026mdash;such as deep-fakes generated by artificial intelligence and sophisticated cyber-attacks. Simultaneously, confidentiality has been disrupted as the global push to embrace artificial intelligence offers adversaries novel ways to aggregate, extract, and reconstruct meaning from scattered, unclassified datasets, reproducing sensitive information and bypassing traditional containment entirely.\u003c/p\u003e\n\u003cp\u003eEffective information security can no longer rely so heavily on a model of containment. Instead, it requires the defender to analyse how information is used to support decision-making by both the legitimate user and the adversary.\u003c/p\u003e\n\u003cp\u003eComputers and humans share a functional similarity: both act within a feedback loop, taking actions to support the correct performance of a function. Whether human or digital, the actor relies on information to form a belief about the facility\u0026rsquo;s state and capabilities to inform their decision-making. In a nuclear facility, these actors ingest information to update this model and determine the necessary actions to maintain nuclear safety, nuclear security, and nuclear material accounting and control.\u003c/p\u003e\n\u003cp\u003eAdversaries do not target information for its own sake. They target the decision-making process to either:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eReveal Performance Limitations\u003c/strong\u003e: By analysing information objects representing logic or configuration data, they uncover the specific boundaries and vulnerabilities of our orientation, allowing them to engineer scenarios that operate exactly within the unanalysed blind spots.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCorrupt the Orientation\u003c/strong\u003e: By compromising the integrity and availability of information objects relied upon within to form an orientation, they deceive the actor into issuing insecure, unsafe, or untimely control actions, turning them into an unwitting agent of the adversaries will.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eRecognising these dynamics was a primary driver for the IAEA\u0026rsquo;s revision of its guidance. NSS 42-G\u003csup id=\"fnref:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e and NSS 17-T Rev. 1\u003csup id=\"fnref:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e had already advanced alongside modern systems thinking theory, framing sensitive information as the active target, the compromise of which would result in mal-operation of the digital assets. In accordance with the Convention on the Physical Protection of Nuclear Material (CPPNM) and its Amendment, computer security was established as a subset of information security. To prevent systemic weaknesses that well-resourced adversaries could exploit, the Secretariat recognised the need to address the doctrinal inconsistencies between NSS 23-G and the more modern computer security guidance.\u003c/p\u003e\n\u003cp\u003eThis paper introduces the revised approach outlined in the IAEA\u0026rsquo;s circulated Step 12 draft of NST070\u003csup id=\"fnref:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e the draft proposed as the next revision of NSS 23-G. NST070 proposes a shift toward a risk-informed, graded approach that prioritises the demonstrable assurance of information relied upon within important functions over its static containment, thereby allowing defenders to both engineer the targeted protections necessary while enabling the secure and risk-informed adoption of AI and other emerging technologies.\u003c/p\u003e\n\u003cp\u003eFurther, mapping this functional assurance to understand how information and its actors make up our orientation within an OODA Loop (Observe, Orient, Decide, Act)\u003csup id=\"fnref:6\"\u003e\u003ca href=\"#fn:6\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e6\u003c/a\u003e\u003c/sup\u003e shifts nuclear security from providing for passive containment to preparing for dynamic engagement.\u003c/p\u003e\n\u003cp\u003eWith this framework, the beliefs we form, and the functions those are executed within, represent the fixed elements of our orientation. Protecting it preserves correct decision-making. If an adversary corrupts our orientation, they effectively hijack our decision cycle. Knowing this, to prevent a nuclear security event, defenders must leverage their deep, asymmetric knowledge of the function and the role of information within it to maintain an accurate perception of reality while denying the same to the adversary.\u003c/p\u003e\n\u003ch2 id=\"2-the-value-propositions-of-nst070\"\u003e2. The Value Propositions of NST070\u003c/h2\u003e\n\u003cp\u003eTo address the widening gap between legacy information security models and modern adversarial capabilities, the IAEA\u0026rsquo;s draft NST070 introduces a series of subtle changes on how sensitive information is classified, managed, and protected throughout its lifecycle. Rather than treating information purely as a static asset requiring containment, the draft provides an approach to information security designed to protect the dynamic operations of modern nuclear facilities.\u003c/p\u003e\n\u003cp\u003eThe following section highlights a series of shifts on how information security is approached described. By contrasting the structural deficiencies of the existing publication of NSS 23-G with the new guidance, we can illustrate how NST070 transitions the discipline toward a model of functional assurance.\u003c/p\u003e\n\u003ch3 id=\"21-information-resists-containment\"\u003e2.1. Information Resists Containment\u003c/h3\u003e\n\u003cp\u003eContainment-centric security models, like NSS 23-G, often treat information exactly like physical nuclear material: identifying a tangible representation as sensitive (e.g., a site security plan), protectively marking it, and placing it within a bounded system, such as a safe. In this linear model, if the physical object remains in the safe, the information is deemed secure; if it is removed, the response triggers a security investigation and, ideally, recovery. But what if it has been copied? There is little structured guidance for interpreting what this disclosure would mean for the overall security posture.\u003c/p\u003e\n\u003cp\u003eApplying the logic of protecting physical assets to information creates a systemic blind spot. Because information is non-tangible, its theft does not require its removal. If a security posture only accounts for the representation, an adversary can simply exploit alternative forms, assembling facts and context until the sensitive information can be reconstructed. The adversary completely bypasses the protected physical object, collapsing the facility\u0026rsquo;s advantage that was reliant on confidentiality without ever gaining access to the \u0026lsquo;safe\u0026rsquo;.\u003c/p\u003e\n\u003cp\u003eFig. 1 demonstrates how NST070 provides the foundations to address this vulnerability by introducing a conceptual model that separates abstract information from its tangible representations (\u0026ldquo;Ceci n\u0026rsquo;est pas une pipe\u0026rdquo;\u0026mdash;or, in this case, the document is not the secret itself). The draft acknowledges information \u0026ldquo;can be represented and communicated by almost any means but becomes meaningful and valuable only when placed within appropriate context\u0026rdquo;\u003csup id=\"fnref1:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_01.webp\" width=\"1280\" height=\"720\" alt=\"NST070 Fig. 2 Conceptual model illustrating the relationship between abstract information, information objects, information assets and the functions performed, with examples\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 1. NST070 Fig. 2 Conceptual model illustrating the relationship between abstract information, information objects, information assets and the functions performed, with examples (produced verbatim from Ref. \u003csup id=\"fnref2:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e).\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis has become an increasingly important concept, as the advent of frontier AI and Large Language Models has demonstrated the ability to infer missing context to find sensitive information; for example, by rapidly aggregating and synthesising vast quantities of disparate, publicly available data to make novel inferences about a nuclear facility\u0026rsquo;s operations or physical layout\u003csup id=\"fnref:7\"\u003e\u003ca href=\"#fn:7\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e7\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eRecognising that \u0026ldquo;conventional information security measures can generally only be applied to information objects, information assets and individuals\u0026rdquo;\u003csup id=\"fnref3:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e, NST070 instructs that \u0026ldquo;Information security measures should be designed to protect information as comprehensively as practicable in both its tangible and abstract forms\u0026rdquo;. To address the response to a compromise of information, the guidance further establishes that a facility\u0026rsquo;s incident response plan should \u0026ldquo;Outline methods to\u0026hellip; otherwise mitigate the related consequences, ensuring that functions can continue to be performed within the defined levels of risk tolerance\u0026rdquo;\u003csup id=\"fnref4:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eBy separating abstract information from tangible objects, the draft promotes the development of a graded approach that orients nuclear security to preserve the utility of the information rather than just protecting an individual representation.\u003c/p\u003e\n\u003ch3 id=\"22-automation-amplifies-vulnerability\"\u003e2.2. Automation Amplifies Vulnerability\u003c/h3\u003e\n\u003cp\u003eThe current NSS 23-G primarily considered human actors: a person reads a secret and acts on it therefore those secrets should not be disclosed to adversaries. Today, information directly leads to the performance of a function as can be exhibited through instrumentation and control systems, physical access controllers, safety actuation systems, and even video monitoring systems. Information as the basis for action is foundational to considering both computer security as well as mitigation of unwitting insiders, and information is considered to exist throughout the State and taking on many forms as depicted in Fig. 2.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_02.webp\" width=\"1280\" height=\"720\" alt=\"NST070 FIG. 3. Relationship between the information and computer based systems in the State and in the nuclear security regime\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 2. NST070 FIG. 3. Relationship between the information and computer based systems in the State and in the nuclear security regime (produced verbatim from Ref.  \u003csup id=\"fnref5:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e).\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eIf an adversary alters the information relied on by any of these actors without stealing it, the actor may make incorrect and potentially catastrophic decisions based on that falsified data. The consequence of such a compromise is not just a leaked secret; it is a valve opening, an alarm disabling, or the failure to actuate a safety system. In each of these examples, the actions taken or deferred will likely have a direct impact on defence-in-depth.\u003c/p\u003e\n\u003cp\u003eWhile second order effects of this are not directly addressed in NST070, as the level of detail would exceed that of an Implementing Guide, the Systems Theoretic Accident Modelling Process\u003csup id=\"fnref:8\"\u003e\u003ca href=\"#fn:8\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e8\u003c/a\u003e\u003c/sup\u003e provides the basis for a useful categorisation of the impact of the subversion of these actions:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eA control action required for safety/security is not provided:\u003c/strong\u003e A loss of Availability prevents a critical safety actuation or security response.\n\u003cul\u003e\n\u003cli\u003eExample: An adversary suppresses the high radiation signal to a safety actuation system. The system, lacking the necessary observation, fails to close a containment valve.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAn unsafe control action is provided:\u003c/strong\u003e A loss of Integrity induces a malicious or incorrect command, tricking the system into an unintended state.\n\u003cul\u003e\n\u003cli\u003eExample: An adversary spoofing digital sensor readings leads an operator to believe a cooling pump has failed. The operator, following standard operating procedures, issues a command to activate a backup system that, in the current actual state, over-pressurises the circuit.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eA potentially safe control action is provided too late, too early, or out of sequence:\u003c/strong\u003e Latency or timing manipulation of when information is available disrupts the synchronisation of actions necessary for effective defence-in-depth.\n\u003cul\u003e\n\u003cli\u003eExample: An adversary generates spectrum noise to affect the delivery speed of messages between a central alarm station and a wirelessly connected truck stopper, causing a delay that allows the adversary to transit the barrier before the actuation command is registered.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eA continuous safe control action is stopped too soon or applied too long:\u003c/strong\u003e A disruption causes an incomplete or over-extended execution of an action, potentially leading to impairment of the function.\n\u003cul\u003e\n\u003cli\u003eExample: An adversary intercepts the digital feedback from a Spent Fuel Pool\u0026rsquo;s level sensors, feeding the pump controller a constant \u0026ldquo;Low\u0026rdquo; signal during a makeup operation. The controller, relying on this observation, applies the pumping action for too long, causing a pool overflow that floods the spent fuel pool hall.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eNST070, however, aims to correct this imbalance, noting that \u0026ldquo;loss of integrity or of availability can also have negative consequences for nuclear security and nuclear safety\u0026rdquo;\u003csup id=\"fnref6:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. The draft emphasises that attacks \u0026ldquo;could include attacks that are specifically designed and executed to mislead human or machine based decision making\u0026rdquo;\u003csup id=\"fnref7:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. If sensitive information is modified in a way that \u0026ldquo;misleads individuals or information assets\u0026rdquo;, it can prevent them \u0026ldquo;from correctly performing their functions and potentially lead to a nuclear security event or a nuclear accident\u0026rdquo;\u003csup id=\"fnref8:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_03.webp\" width=\"1280\" height=\"720\" alt=\"NST070 FIG. 5. Example common scale of impact and a graded approach to protecting sensitive Information\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 3. NST070 FIG. 5. Example common scale of impact and a graded approach to protecting sensitive Information (produced verbatim from Ref. \u003csup id=\"fnref9:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e).\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eFig. 3 illustrates the practical application of this, it outlines a consequence-based, graded approach, moving away from classification tied to unauthorised disclosure and concluding that \u0026ldquo;the protection of integrity and availability should be prioritised over confidentiality if the potential consequences to nuclear security and nuclear safety are greater\u0026rdquo;\u003csup id=\"fnref10:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003ch3 id=\"23-information-security-is-a-unifying-foundation\"\u003e2.3. Information Security is a Unifying Foundation\u003c/h3\u003e\n\u003cp\u003eIn many instances NSS 23-G, and the resulting guidance structure built up within NSS 42-G and NSS 17-T Rev. 1, could be interpreted in a way that conflated information with its actors, treating them as a single administrative unit. This ambiguity would lead to security posture that heavily prioritised hardening the sensitive digital assets (i.e. computer security) while failing to validate the integrity, origin, or broader lifecycle of the sensitive information itself (i.e. information security) leading to many lost opportunities for a more efficient security solution. In a systems security engineering context, this is a problematic functional decomposition, as it assumes that protecting the actor inherently guarantees the validity and safety of the basis for its action.\u003c/p\u003e\n\u003cp\u003eNST070 delineates this relationship, defining Information Security (and the Information Security Management System) as the superset that governs information objects in any form while Computer Security manages the specific subset of computer based information assets (i.e. digital assets) that facilitate their use. Highlighting that \u0026ldquo;decisions made and actions taken by individuals, on the basis of information in whatever form, can have some significance for the functions performed relevant to nuclear security\u0026rdquo;\u003csup id=\"fnref11:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e, it provides the stable foundations for a broader information security framework that goes beyond computer security.\u003c/p\u003e\n\u003cp\u003eFor instance, it counters disinformation by presenting the need to validate integrity before it influences human decision-making or is acted upon by an asset. Similarly, it supports the development of insider risk mitigation strategies against the risk of unwitting insiders who, despite operating within highly well-defined procedures, might be manipulated into taking adverse actions by acting on falsified information.\u003c/p\u003e\n\u003ch3 id=\"24-information-has-an-asymmetric-value\"\u003e2.4. Information has an Asymmetric Value\u003c/h3\u003e\n\u003cp\u003eWithout specific guidance standard information security risk assessments typically measure the value of information based on its criticality to an organisation\u0026rsquo;s business continuity or routine operational needs. This overlooks a malicious perspective: an adversary does not use this information to operate the facility, but rather to target, bypass, or degrade physical protection and nuclear safety. They want to use it within a malicious act, resulting in a different, or asymmetric, value placed on that information.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_04.webp\" width=\"1150\" height=\"644\" alt=\"NST070 FIG. 4. The relationship between the State and entities relevant to the nuclear security regime for the purposes of information security\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 4 NST070 FIG. 4. The relationship between the State and entities relevant to the nuclear security regime for the purposes of information security (produced verbatim from Ref. \u003csup id=\"fnref12:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e).\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis asymmetry is further complicated by the fact that information may have different value throughout the nuclear security regime, often residing in, or being sensitive to other regulated entities or third parties. For example, an operator might discover and mitigate a specific equipment vulnerability, subsequently treating the technical details of that flaw as historical data with low sensitivity. However, if that same equipment design is utilised by other facilities within the regime, an adversary may view those details as a highly valuable blueprint for undertaking a malicious act elsewhere.\u003c/p\u003e\n\u003cp\u003eNST070 addresses this asymmetry, explaining that \u0026ldquo;each entity or organization could have a different use\u0026hellip; and perception of the value of information\u0026rdquo;\u003csup id=\"fnref13:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. For instance, detailed configuration data for a safety control system might be considered by the operator \u0026ldquo;to be of little value\u0026rdquo;. However, to an adversary, such information \u0026ldquo;might be of high value as it could reveal a weakness or vulnerability that could be exploited in the context of a criminal or intentional unauthorized act\u0026rdquo;\u003csup id=\"fnref14:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e and \u0026ldquo;should therefore be protected consistent with the highest impact and consequence\u0026rdquo;\u003csup id=\"fnref15:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003ch3 id=\"25-aggregation-and-inference-are-increasingly-important\"\u003e2.5. Aggregation and Inference Are Increasingly Important\u003c/h3\u003e\n\u003cp\u003eWhile aggregation (i.e. gathering many pieces of information) is a recognised threat it was not structurally addressed within the original publication of NSS 23-G. Nor was inference, the cognitive leap an adversary makes to construct a model from that fragmented information.\u003c/p\u003e\n\u003cp\u003eAn organisation might successfully contain a classified document. However, if an adversary observes related unclassified details, they may infer the context and logic of the document. Many information security frameworks struggle to acknowledge this emergent risk where the relationship between non-sensitive information generates new, sensitive knowledge that bypasses traditional containment.\u003c/p\u003e\n\u003cp\u003eNST070 provides a basis for addressing both aggregation and inference, \u0026ldquo;consideration should also be given to the potential for aggregated information to warrant a higher classification, even if individual components are less sensitive\u0026rdquo;\u003csup id=\"fnref16:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. It treats the relationship between data points as a protectable aspect, \u0026ldquo;collections of non-sensitive information objects could become sensitive information objects if the relationship between the non-sensitive information objects provides additional context for an adversary\u0026rdquo;\u003csup id=\"fnref17:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e, shifting defence from protecting static object to a calibrated management of the adversary\u0026rsquo;s orientation leading into a malicious act.\u003c/p\u003e\n\u003ch3 id=\"26-transient-sensitivity-needs-flexibility\"\u003e2.6. Transient Sensitivity Needs Flexibility\u003c/h3\u003e\n\u003cp\u003eNSS 23-G was largely built for static or persistently sensitive data (e.g., plans, system designs, threat and vulnerability modelling). It lacked agile mechanisms for information whose value decays rapidly, such as real-time transport logistics or temporary operational variables within an I\u0026amp;C system. Applying dogmatic and heavy-handed controls in these fast-paced environments can severely hinder safety or security functions.\u003c/p\u003e\n\u003cp\u003eNST070 recognises that \u0026ldquo;traditional information security measures can be impractical for enabling the use of information whose sensitivity has a brief lifespan, for example during the transport of nuclear and other radioactive material\u0026rdquo;\u003csup id=\"fnref18:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. It allows for agile adaptations, such as \u0026ldquo;employing code words (including gestures or signs)\u0026rdquo; \u003csup id=\"fnref19:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. However, it cautions that \u0026ldquo;meaning can be quickly inferred on the basis of context\u0026rdquo;. Therefore, \u0026ldquo;the context of these code words\u0026rdquo;\u003csup id=\"fnref20:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e must be treated as sensitive information itself, and this approach must be \u0026ldquo;strictly controlled and limited to scenarios in which the information\u0026rsquo;s sensitive nature is transient\u0026rdquo;\u003csup id=\"fnref21:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003ch3 id=\"27-realigning-the-lifecycle-and-control-structures-to-preserving-functions\"\u003e2.7. Realigning the Lifecycle and Control Structures to Preserving Functions\u003c/h3\u003e\n\u003cp\u003eMany information security lifecycles, including those in NSS 23-G, are depicted as a series of administrative procedures that mirror those used for records management. This approach treats these lifecycle stages as an end unto themselves, creating a disconnect between the State\u0026rsquo;s overarching objectives for nuclear security and the functional execution, potentially even extending beyond the mandate of nuclear security.\u003c/p\u003e\n\u003cp\u003eWithout a cohesive bridge between the lifecycle phases and the objective of nuclear security, policies have remained static and failed to address emerging threats, as, following records management, they formalised a process that prioritised the custody of the object over the contribution to the function.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_05.webp\" width=\"1280\" height=\"720\" alt=\"NST070 FIG. 6. The four stages in a generic information life cycle and the relationships between them\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 5. NST070 FIG. 6. The four stages in a generic information life cycle and the relationships between them (produced verbatim from Ref. \u003csup id=\"fnref22:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e).\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eIn Fig. 5 NST070 redefines the generic lifecycle and reduces it to a series of stages that can be directly related to functional outcomes\u003csup id=\"fnref23:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eCreating\u003c/strong\u003e: Actions performed to identify or assemble an information object from abstract information or other information objects, provide context, and asses its sensitivity.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProcessing\u003c/strong\u003e: Actions performed on information/information objects that could affect its C/I/A.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUsing\u003c/strong\u003e: Actions performed using information/information objects, reliant on its C/I/A.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDisposing\u003c/strong\u003e: Actions performed to archive or destroy information/information objects ensuring they can no longer impair the performance of a function through a loss of C/I/A.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eTo govern this lifecycle, NST070 introduces a layered control structure, dictating that a \u0026ldquo;State\u0026rsquo;s legislative, regulatory and policy frameworks\u0026hellip; and the information security management system of a regulated entity\u0026hellip; should together form information security governance structures\u0026rdquo;\u003csup id=\"fnref24:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e demonstrating this hierarchy of controls in Fig. 6.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_06.webp\" width=\"1280\" height=\"720\" alt=\"NST070 FIG. 6. NST070 FIG. 1. Relationship between the State’s nuclear security objectives, information security governance structures and the confidentiality, integrity and availability of information\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 6. NST070 FIG. 1. Relationship between the State\u0026rsquo;s nuclear security objectives, information security governance structures and the confidentiality, integrity and availability of information (produced verbatim from Ref.  \u003csup id=\"fnref25:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e).\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis hierarchy ensures the information security management system implemented and maintained by organisations within the nuclear security regime encompasses procedures \u0026ldquo;designed to provide for the security of sensitive information, sensitive information objects and sensitive information assets\u0026rdquo;\u003csup id=\"fnref26:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e to ultimately \u0026ldquo;preserve satisfactory performance of a regulated entity\u0026rsquo;s functions using sensitive information\u0026rdquo;\u003csup id=\"fnref27:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e while maintaining alignment with the objectives of nuclear security.\u003c/p\u003e\n\u003ch2 id=\"3-ooda-and-information-security-during-a-nuclear-security-event\"\u003e3. OODA and Information Security during a nuclear security event\u003c/h2\u003e\n\u003cp\u003eTo move away from static containment and operationalise the functional assurance proposed in NST070, we must examine how information actively drives decision-making in the lead-up to and within a nuclear security event. Modern nuclear facilities are among the most robustly regulated examples of critical infrastructure in existence. IAEA guidance has established a series of assurance principles as international norms, such as Defence-in-Depth, the Graded Approach, and the Single Failure Criterion, creating a dense fabric of redundant, parallel safety and security systems designed to deliver important functions even in the face of localised losses (component failure or an emergent vulnerability within the PPS)\u003csup id=\"fnref:9\"\u003e\u003ca href=\"#fn:9\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e9\u003c/a\u003e\u003c/sup\u003e\u003csup id=\"fnref:10\"\u003e\u003ca href=\"#fn:10\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e10\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eHowever, a nuclear facility and its safety and security systems cannot be protected as though they are a static collection of assets. They are complex, dynamic environments comprised of interacting processes designed to maintain these functions. An attack on a single system, a simple \u0026lsquo;hack\u0026rsquo;, should, by design, not result in an unacceptable loss. A true nuclear security event will emerge from a dynamic encounter within this environment, where an adversary exploits crafted control actions, disrupts feedback loops, or leverages flawed assumptions to force the facility into an unanalysed, hazardous state.\u003c/p\u003e\n\u003cp\u003eIn such an encounter, the effectiveness of the facility\u0026rsquo;s defences depends entirely on the performance of its functions. However, actors performing safety and security functions, whether human or computer, rarely observe physical reality directly. Instead, their operational reality is governed by an orientation. These actors base their decisions and subsequent actions entirely on this orientation. Therefore, if an adversary can manipulate the sensitive information feeding this, they can trick the actor into issuing a damaging action, effectively turning the facility\u0026rsquo;s own processes against it, bypassing active Defence-in-Depth, and setting the scene for a nuclear security event.\u003c/p\u003e\n\u003cp\u003eVisualising how this orientation is formed requires looking at how the conceptual model described in Fig. 1 can be practically applied. It occurs through a layered convergence of information; for any given action, there are typically at least three distinct types of information that mechanically influence the orientation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInformation forms the baseline capability of the actor, such as the compiled firmware of a digital controller or the specialised training of the guard force;\u003c/li\u003e\n\u003cli\u003eThe actor is instructed by predefined logical rules, such as process logic for a PLC or written standard operating procedures for a guard; and\u003c/li\u003e\n\u003cli\u003eThe actor receives observations, interpreting them against their capability and the logical rules to execute actions within the performance a function.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThese three elements of orientation can be mapped to the NST070 information lifecycle using a model derived from a Input-Control-Output-Mechanism (ICOM) Integration Definition for Process Modelling (IDEF0) \u003csup id=\"fnref:11\"\u003e\u003ca href=\"#fn:11\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e11\u003c/a\u003e\u003c/sup\u003e function block:\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_07.webp\" width=\"1280\" height=\"720\" alt=\"A set of sensitive information related to the performance of a function illustrating a re-entrant application of Fig. 1 depicted in an ICOM-like structure\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 7. A set of sensitive information related to the performance of a function illustrating a re-entrant application of Fig. 1 depicted in an ICOM-like structure.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eFeeding this function are information objects that collectively form the system\u0026rsquo;s orientation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eInput (I):\u003c/strong\u003e This is the raw observation of the physical world. It provides the situational context (e.g., Temperature is 300°C).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eControl (C):\u003c/strong\u003e These are the task specific instructions. They represent the application logic, safety constraints, or work orders/instructions (e.g., If Temp \u0026gt; 280°C, open valve).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMechanism (M):\u003c/strong\u003e This is the base capability of the actor itself. Additionally, it holds the Knowledge or System Programming required to interpret the inputs against the controls to produce an output.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor an \u003cstrong\u003eOutput (O)\u003c/strong\u003e to be generated the mechanism (and therefore the actor) must resolved the interaction of the three variables above to form a prediction, decide on a course of action, and then act to execute it. By defining the orientation in this way, we see that any compromise to the integrity of the Control or Mechanism, or the availability and integrity of the Input, results in a flawed orientation, forcing the actor to base their decisions upon a reality that does not exist.\u003c/p\u003e\n\u003cp\u003eThis can be demonstrated through mapping the internal architecture of the OODA loop\u0026rsquo;s Orient and Decide phases to the Using phase of the information lifecycle.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/nuclear-needs-information-security_08.webp\" width=\"907\" height=\"372\" alt=\"The ICOM-like structure in Fig. 7 applied to demonstrate the formulation of orientation within an OODA loop\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFig. 8. The ICOM-like structure in Fig. 7 applied to demonstrate the formulation of orientation within an OODA loop\u003csup id=\"fnref1:6\"\u003e\u003ca href=\"#fn:6\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e6\u003c/a\u003e\u003c/sup\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003ch3 id=\"31-the-vulnerability-of-the-fixed-orientation\"\u003e3.1. The Vulnerability of the Fixed Orientation\u003c/h3\u003e\n\u003cp\u003eBecause of their highly regulated nature, nuclear facilities largely operate with a fixed orientation. To ensure deterministic and verifiable responses, the operational logic and mechanisms are rigorously baselined. While this provides stability against anticipated losses (e.g. random component failures), it creates a strategic vulnerability: the defender\u0026rsquo;s Decide and Act phases can be discovered through reconnaissance.\u003c/p\u003e\n\u003cp\u003eArmed with this knowledge, an adversary does not need to outpace the defender\u0026rsquo;s OODA loop, they simply decouple it from reality. By manipulating the Input or poisoning the Control, such as through maliciously altering ladder logic or a guard\u0026rsquo;s orders, the attacker forces the actor to perform its function perfectly against a false orientation. For example, if a sensor\u0026rsquo;s integrity is compromised to report a normal state during an actual excursion, the safety system\u0026rsquo;s decision to remain idle is technically correct according to its logic yet may be functionally damaging.\u003c/p\u003e\n\u003cp\u003eWhen malicious information is successfully injected into the orientation this way, the actor maintains total confidence in their orientation, unwittingly executing the adversary\u0026rsquo;s intent. The defender is no longer reacting to an external threat; they have been rendered an agent of the attacker. This corruption may bypass redundancy provided by the single failure criterion as well as all active layers of defence-in-depth, including physical, computer, and information security barriers entirely, as the system executes the action under the assumption that it is a legitimate operational requirement.\u003c/p\u003e\n\u003ch2 id=\"conclusion-reclaiming-the-orientation\"\u003eConclusion: Reclaiming the Orientation\u003c/h2\u003e\n\u003cp\u003eAdversaries intent on violating the core objectives of nuclear security (preventing theft and sabotage) will not merely seek to extract information. Because defence-in-depth within most nuclear facilities is so thoroughly established, brute-force physical bypass is exceptionally difficult.\u003c/p\u003e\n\u003cp\u003eInstead, the lowest-cost path for an adversary is increasingly being demonstrated as an attack the orientation itself. This targeted attack path relies on a specific sequence:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRevealing Limitations:\u003c/strong\u003e By uncovering the logic the adversary maps the system\u0026rsquo;s fixed orientation. If the function lacks architectural diversity, compromising the confidentiality of one system reveals the blind spots of all systems. This collapses the adversary\u0026rsquo;s required effort, turning what should be independence into a single, shared attack path.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCorrupting Orientation:\u003c/strong\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDenying Observation:\u003c/strong\u003e By blocking or severing the input data, the adversary blinds the orientation.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAttacking Integrity:\u003c/strong\u003e By subtly altering the inputs, logic, or mechanisms, the adversary corrupts the system\u0026rsquo;s orientation, forcing it to act on a false reality.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOur advantage will not come from the static defences established by containment-based information security. Frameworks like the original NSS 23-G focused almost exclusively on the physical containment of tangible information objects, a posture that is entirely blind to an adversary manipulating abstract information flows. By applying the functional, lifecycle-based protections of the draft NST070, we shift away from this limited perception of value.\u003c/p\u003e\n\u003cp\u003eInstead, NST070 provides a basis against which to assess the value of information functionally, through the eyes of other stakeholders in the nuclear security regime, and the adversary. Because the adversary\u0026rsquo;s attack path requires them to map our limitations and manipulate our orientation, their success is dependent on exploiting sensitive information. By shifting our priority from strict confidentiality to ensuring the integrity and availability of the basis for action within our functions, we enforce the modern principles of trustworthiness\u003csup id=\"fnref:12\"\u003e\u003ca href=\"#fn:12\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e12\u003c/a\u003e\u003c/sup\u003e. We protect the exact information an adversary would value most, starving them of the prerequisites for success and turning their reconnaissance and manipulation attempts into detectable anomalies.\u003c/p\u003e\n\u003cp\u003eThese early indicators provide us with the opportunity for active defence. Because the facility inherently possesses the master operational picture, understanding our reliance on sensitive information allows us to dynamically re-calibrate our orientation: validating inputs, shifting control logic, or isolating compromised actors. With a well-established understanding of our own orientation we can do this long before the adversary can achieve their goal.\u003c/p\u003e\n\u003cp\u003eBy securing this sensitive information relative to its uses and preparing for a dynamic encounter, we force the adversary to fight through exponentially compounding layers of uncertainty, introducing crippling friction into their decision cycle. We shift from a posture of passive containment to consistently operating inside the adversary\u0026rsquo;s OODA loop, ensuring the facility acts on a validated and resilient orientation\u003csup id=\"fnref:13\"\u003e\u003ca href=\"#fn:13\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e13\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eThe circulated draft of NST070 aligns directly with this systems theory view. It recognises that in a modern nuclear environment, security is not merely about locking away the data but preserving the orientation so it can be safely relied upon during an emerging nuclear security event. By shifting to a model that re-evaluates information through its functional consequence, the new guidance changes how risk is calculated. Security measures are no longer graded simply by the administrative sensitivity of a static document, but by how severely a system\u0026rsquo;s orientation would diverge from reality if that information were corrupted, and what the consequences of that divergence would be.\u003c/p\u003e\n\u003cp\u003eUltimately, NST070 modernises the foundations of information security to address the rapidly developing capabilities of digital technology, including the use of AI by both operators and adversaries. It provides the framework necessary to counter sophisticated, information-centric threats. It ensures that when an actor executes a safety or security function, it acts not as an unwitting agent of the adversary, but based on an assured, trustworthy orientation that accurately reflects the true orientation of the facility.\u003c/p\u003e\n\u003ch2 id=\"references\"\u003eReferences\u003c/h2\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 23-G, \u0026ldquo;Security of Nuclear Information,\u0026rdquo; Vienna, Austria, 2015.  \u003ca href=\"https://www.iaea.org/publications\"\u003ehttps://www.iaea.org/publications\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:2\"\u003e\n\u003cp\u003eA. Crowe, \u0026ldquo;Mass Insider Threats: Civilians, Cyberoperations, Critical Infrastructure, and the Erosion of Sovereignty in the Grey-Zone,\u0026rdquo; in Oxford Intersections: Borders, ed. Alexander Diener and Joshua Hagen, Oxford University Press, 2026.\u0026#160;\u003ca href=\"#fnref:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:3\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 42-G, \u0026ldquo;Computer Security for Nuclear Security,\u0026rdquo; Vienna, Austria, July 2021.  \u003ca href=\"https://www.iaea.org/publications\"\u003ehttps://www.iaea.org/publications\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:4\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 17-T (Rev. 1), \u0026ldquo;Computer Security Techniques for Nuclear Facilities,\u0026rdquo; Vienna, Austria, September 2021.  \u003ca href=\"https://www.iaea.org/publications\"\u003ehttps://www.iaea.org/publications\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:5\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency (IAEA) Draft Implementing Guide NST070 Step 12, \u0026ldquo;Information Security for Nuclear Security,\u0026rdquo; Vienna, Austria, 2025.\u0026#160;\u003ca href=\"#fnref:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref2:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref3:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref4:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref5:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref6:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref7:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref8:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref9:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref10:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref11:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref12:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref13:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref14:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref15:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref16:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref17:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref18:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref19:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref20:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref21:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref22:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref23:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref24:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref25:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref26:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref27:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:6\"\u003e\n\u003cp\u003eJ. R. Boyd, \u0026ldquo;The Essence of Winning and Losing,\u0026rdquo; Unpublished briefing slides, June 1995..\u0026#160;\u003ca href=\"#fnref:6\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:6\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:7\"\u003e\n\u003cp\u003eS. C. Lackner and Z. Kara, \u0026ldquo;Artificial Intelligence and Nuclear Security Governance: Addressing the Risks of Frontier AI,\u0026rdquo; Vienna Center for Disarmament and Non-Proliferation, 2025\u0026#160;\u003ca href=\"#fnref:7\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:8\"\u003e\n\u003cp\u003eN. G. Leveson, \u0026ldquo;Engineering a Safer World: Systems Thinking Applied to Safety,\u0026rdquo; The MIT Press, 2012.  \u003ca href=\"https://doi.org/10.7551/mitpress/8179.001.0001\"\u003ehttps://doi.org/10.7551/mitpress/8179.001.0001\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:8\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:9\"\u003e\n\u003cp\u003eINTERNATIONAL ATOMIC ENERGY AGENCY, Nuclear Security Recommendations on Physical Protection of Nuclear Material and Nuclear Facilities (INFCIRC/225/ Revision 5), IAEA Nuclear Security Series No. 13, IAEA, Vienna (2011).\u0026#160;\u003ca href=\"#fnref:9\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:10\"\u003e\n\u003cp\u003eINTERNATIONAL ATOMIC ENERGY AGENCY, Safety of Nuclear Power Plants: Design, IAEA Safety Standards Series No. SSR-2/1 (Rev. 1), IAEA, Vienna (2016).\u0026#160;\u003ca href=\"#fnref:10\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:11\"\u003e\n\u003cp\u003eNational Institute of Standards and Technology (NIST) Federal Information Processing Standards Publication (FIPS PUB) 183, \u0026ldquo;Integration Definition for Function Modeling (IDEF0),\u0026rdquo; Gaithersburg, MD, December 1993. \u003ca href=\"https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub183.pdf\"\u003ehttps://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub183.pdf\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:11\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:12\"\u003e\n\u003cp\u003eNational Institute of Standards and Technology (NIST) Special Publication 800-160 Volume 1 Revision 1, \u0026ldquo;Engineering Trustworthy Secure Systems,\u0026rdquo; Gaithersburg, MD, November 2022. \u003ca href=\"https://doi.org/10.6028/NIST.SP.800-160v1r1\"\u003ehttps://doi.org/10.6028/NIST.SP.800-160v1r1\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:12\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:13\"\u003e\n\u003cp\u003eRick Dove, \u0026ldquo;Embedding Agile Security in System Architecture,\u0026rdquo; Insight 12 (2): 14-17, International Council on Systems Engineering, July 2009.\u0026#160;\u003ca href=\"#fnref:13\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This article has been adapted verbatim from a paper accepted and presented during the International Conference on Computer Security in the Nuclear World: Securing the Future titled ‘Why Nuclear Security Needs Information Security: The Promise Of NST070’ authored by Mike StJohn-Green and myself.\nAbstract Effective computer security requires information security. Computers, like humans, are actors on information and adversaries target the functions they perform by compromising the confidentiality, integrity, or availability (CIA) of the information itself.\nModern information is fluid and knowledge-based, capable of being inferred from fragments and moving beyond traditional boundaries. This makes older, containment-based security models that treat information as a simple object appear increasingly obsolete. The value of information is also asymmetric; what seems routine to a defender can reveal critical vulnerabilities to an attacker. Since information’s value is derived from its use within a function, any compromise of its CIA can be quantified by the potential impacts to that function’s performance.\nThe IAEA’s circulated draft of NST070 describes an integrated, life-cycle approach that protects information’s CIA during both its processing and its ultimate use. This model, with its holistic approach, fills gaps legacy systems cannot, resulting in strong security against modern threats and the future of AI. NST070 is set to become an essential security evolution, closing gaps within legacy models to create a truly modern defence. This paper will illustrate how the circulated draft of NST070 delivers this.\n1. Introduction Nuclear security guidance has historically evolved from the principles of physical protection, heavily emphasising the containment of physical objects based on an analysis of their static value. This approach proved effective when confidentiality was the predominant concern, particularly against adversaries seeking to collect intelligence. This lineage is evident in legacy information security frameworks, such as IAEA Nuclear Security Series No. 23-G Security of Nuclear Information1 (NSS 23-G), which focused on protecting the confidentiality of discrete “information objects”—tangible items like hard copy documents and electronic files—under the assumption that if the object is contained, the information is secure.\nHowever, the rapid digitalisation of nuclear infrastructure and the use of computer based systems to control physical machines have exposed the limitations of a purely containment-centric posture. Information is no longer merely a physical asset to be locked away; it is both a dynamic component and a functional dependency of the functions we rely on for nuclear safety and security. As a result of this shift while confidentiality remains important, our approaches to the integrity and availability of information have moved to the centre of security discourse. This is increasingly evident as vulnerabilities within industrial control systems become high-profile targets for non-state actors and central to greyzone warfare, where digital interference serves as a potent tool for disruption without triggering conventional conflict2.\nApproaches to information security have struggled to keep pace with this change. Much existing analysis and labelling still rely heavily on containment models, such as marking documents as confidential and applying standardised security controls to them, with little analysis of how the information is used, trusted, and how that could be exploited. Modern adversarial tactics render these models increasingly insufficient. Integrity faces escalating threats from new techniques designed to deceive users—both human and machine—such as deep-fakes generated by artificial intelligence and sophisticated cyber-attacks. Simultaneously, confidentiality has been disrupted as the global push to embrace artificial intelligence offers adversaries novel ways to aggregate, extract, and reconstruct meaning from scattered, unclassified datasets, reproducing sensitive information and bypassing traditional containment entirely.\nEffective information security can no longer rely so heavily on a model of containment. Instead, it requires the defender to analyse how information is used to support decision-making by both the legitimate user and the adversary.\nComputers and humans share a functional similarity: both act within a feedback loop, taking actions to support the correct performance of a function. Whether human or digital, the actor relies on information to form a belief about the facility’s state and capabilities to inform their decision-making. In a nuclear facility, these actors ingest information to update this model and determine the necessary actions to maintain nuclear safety, nuclear security, and nuclear material accounting and control.\nAdversaries do not target information for its own sake. They target the decision-making process to either:\nReveal Performance Limitations: By analysing information objects representing logic or configuration data, they uncover the specific boundaries and vulnerabilities of our orientation, allowing them to engineer scenarios that operate exactly within the unanalysed blind spots. Corrupt the Orientation: By compromising the integrity and availability of information objects relied upon within to form an orientation, they deceive the actor into issuing insecure, unsafe, or untimely control actions, turning them into an unwitting agent of the adversaries will. Recognising these dynamics was a primary driver for the IAEA’s revision of its guidance. NSS 42-G3 and NSS 17-T Rev. 14 had already advanced alongside modern systems thinking theory, framing sensitive information as the active target, the compromise of which would result in mal-operation of the digital assets. In accordance with the Convention on the Physical Protection of Nuclear Material (CPPNM) and its Amendment, computer security was established as a subset of information security. To prevent systemic weaknesses that well-resourced adversaries could exploit, the Secretariat recognised the need to address the doctrinal inconsistencies between NSS 23-G and the more modern computer security guidance.\nThis paper introduces the revised approach outlined in the IAEA’s circulated Step 12 draft of NST0705 the draft proposed as the next revision of NSS 23-G. NST070 proposes a shift toward a risk-informed, graded approach that prioritises the demonstrable assurance of information relied upon within important functions over its static containment, thereby allowing defenders to both engineer the targeted protections necessary while enabling the secure and risk-informed adoption of AI and other emerging technologies.\nFurther, mapping this functional assurance to understand how information and its actors make up our orientation within an OODA Loop (Observe, Orient, Decide, Act)6 shifts nuclear security from providing for passive containment to preparing for dynamic engagement.\nWith this framework, the beliefs we form, and the functions those are executed within, represent the fixed elements of our orientation. Protecting it preserves correct decision-making. If an adversary corrupts our orientation, they effectively hijack our decision cycle. Knowing this, to prevent a nuclear security event, defenders must leverage their deep, asymmetric knowledge of the function and the role of information within it to maintain an accurate perception of reality while denying the same to the adversary.\n2. The Value Propositions of NST070 To address the widening gap between legacy information security models and modern adversarial capabilities, the IAEA’s draft NST070 introduces a series of subtle changes on how sensitive information is classified, managed, and protected throughout its lifecycle. Rather than treating information purely as a static asset requiring containment, the draft provides an approach to information security designed to protect the dynamic operations of modern nuclear facilities.\nThe following section highlights a series of shifts on how information security is approached described. By contrasting the structural deficiencies of the existing publication of NSS 23-G with the new guidance, we can illustrate how NST070 transitions the discipline toward a model of functional assurance.\n2.1. Information Resists Containment Containment-centric security models, like NSS 23-G, often treat information exactly like physical nuclear material: identifying a tangible representation as sensitive (e.g., a site security plan), protectively marking it, and placing it within a bounded system, such as a safe. In this linear model, if the physical object remains in the safe, the information is deemed secure; if it is removed, the response triggers a security investigation and, ideally, recovery. But what if it has been copied? There is little structured guidance for interpreting what this disclosure would mean for the overall security posture.\nApplying the logic of protecting physical assets to information creates a systemic blind spot. Because information is non-tangible, its theft does not require its removal. If a security posture only accounts for the representation, an adversary can simply exploit alternative forms, assembling facts and context until the sensitive information can be reconstructed. The adversary completely bypasses the protected physical object, collapsing the facility’s advantage that was reliant on confidentiality without ever gaining access to the ‘safe’.\nFig. 1 demonstrates how NST070 provides the foundations to address this vulnerability by introducing a conceptual model that separates abstract information from its tangible representations (“Ceci n’est pas une pipe”—or, in this case, the document is not the secret itself). The draft acknowledges information “can be represented and communicated by almost any means but becomes meaningful and valuable only when placed within appropriate context”5.\nFig. 1. NST070 Fig. 2 Conceptual model illustrating the relationship between abstract information, information objects, information assets and the functions performed, with examples (produced verbatim from Ref. 5).\nThis has become an increasingly important concept, as the advent of frontier AI and Large Language Models has demonstrated the ability to infer missing context to find sensitive information; for example, by rapidly aggregating and synthesising vast quantities of disparate, publicly available data to make novel inferences about a nuclear facility’s operations or physical layout7.\nRecognising that “conventional information security measures can generally only be applied to information objects, information assets and individuals”5, NST070 instructs that “Information security measures should be designed to protect information as comprehensively as practicable in both its tangible and abstract forms”. To address the response to a compromise of information, the guidance further establishes that a facility’s incident response plan should “Outline methods to… otherwise mitigate the related consequences, ensuring that functions can continue to be performed within the defined levels of risk tolerance”5.\nBy separating abstract information from tangible objects, the draft promotes the development of a graded approach that orients nuclear security to preserve the utility of the information rather than just protecting an individual representation.\n2.2. Automation Amplifies Vulnerability The current NSS 23-G primarily considered human actors: a person reads a secret and acts on it therefore those secrets should not be disclosed to adversaries. Today, information directly leads to the performance of a function as can be exhibited through instrumentation and control systems, physical access controllers, safety actuation systems, and even video monitoring systems. Information as the basis for action is foundational to considering both computer security as well as mitigation of unwitting insiders, and information is considered to exist throughout the State and taking on many forms as depicted in Fig. 2.\nFig. 2. NST070 FIG. 3. Relationship between the information and computer based systems in the State and in the nuclear security regime (produced verbatim from Ref. 5).\nIf an adversary alters the information relied on by any of these actors without stealing it, the actor may make incorrect and potentially catastrophic decisions based on that falsified data. The consequence of such a compromise is not just a leaked secret; it is a valve opening, an alarm disabling, or the failure to actuate a safety system. In each of these examples, the actions taken or deferred will likely have a direct impact on defence-in-depth.\nWhile second order effects of this are not directly addressed in NST070, as the level of detail would exceed that of an Implementing Guide, the Systems Theoretic Accident Modelling Process8 provides the basis for a useful categorisation of the impact of the subversion of these actions:\nA control action required for safety/security is not provided: A loss of Availability prevents a critical safety actuation or security response. Example: An adversary suppresses the high radiation signal to a safety actuation system. The system, lacking the necessary observation, fails to close a containment valve. An unsafe control action is provided: A loss of Integrity induces a malicious or incorrect command, tricking the system into an unintended state. Example: An adversary spoofing digital sensor readings leads an operator to believe a cooling pump has failed. The operator, following standard operating procedures, issues a command to activate a backup system that, in the current actual state, over-pressurises the circuit. A potentially safe control action is provided too late, too early, or out of sequence: Latency or timing manipulation of when information is available disrupts the synchronisation of actions necessary for effective defence-in-depth. Example: An adversary generates spectrum noise to affect the delivery speed of messages between a central alarm station and a wirelessly connected truck stopper, causing a delay that allows the adversary to transit the barrier before the actuation command is registered. A continuous safe control action is stopped too soon or applied too long: A disruption causes an incomplete or over-extended execution of an action, potentially leading to impairment of the function. Example: An adversary intercepts the digital feedback from a Spent Fuel Pool’s level sensors, feeding the pump controller a constant “Low” signal during a makeup operation. The controller, relying on this observation, applies the pumping action for too long, causing a pool overflow that floods the spent fuel pool hall. NST070, however, aims to correct this imbalance, noting that “loss of integrity or of availability can also have negative consequences for nuclear security and nuclear safety”5. The draft emphasises that attacks “could include attacks that are specifically designed and executed to mislead human or machine based decision making”5. If sensitive information is modified in a way that “misleads individuals or information assets”, it can prevent them “from correctly performing their functions and potentially lead to a nuclear security event or a nuclear accident”5.\nFig. 3. NST070 FIG. 5. Example common scale of impact and a graded approach to protecting sensitive Information (produced verbatim from Ref. 5).\nFig. 3 illustrates the practical application of this, it outlines a consequence-based, graded approach, moving away from classification tied to unauthorised disclosure and concluding that “the protection of integrity and availability should be prioritised over confidentiality if the potential consequences to nuclear security and nuclear safety are greater”5.\n2.3. Information Security is a Unifying Foundation In many instances NSS 23-G, and the resulting guidance structure built up within NSS 42-G and NSS 17-T Rev. 1, could be interpreted in a way that conflated information with its actors, treating them as a single administrative unit. This ambiguity would lead to security posture that heavily prioritised hardening the sensitive digital assets (i.e. computer security) while failing to validate the integrity, origin, or broader lifecycle of the sensitive information itself (i.e. information security) leading to many lost opportunities for a more efficient security solution. In a systems security engineering context, this is a problematic functional decomposition, as it assumes that protecting the actor inherently guarantees the validity and safety of the basis for its action.\nNST070 delineates this relationship, defining Information Security (and the Information Security Management System) as the superset that governs information objects in any form while Computer Security manages the specific subset of computer based information assets (i.e. digital assets) that facilitate their use. Highlighting that “decisions made and actions taken by individuals, on the basis of information in whatever form, can have some significance for the functions performed relevant to nuclear security”5, it provides the stable foundations for a broader information security framework that goes beyond computer security.\nFor instance, it counters disinformation by presenting the need to validate integrity before it influences human decision-making or is acted upon by an asset. Similarly, it supports the development of insider risk mitigation strategies against the risk of unwitting insiders who, despite operating within highly well-defined procedures, might be manipulated into taking adverse actions by acting on falsified information.\n2.4. Information has an Asymmetric Value Without specific guidance standard information security risk assessments typically measure the value of information based on its criticality to an organisation’s business continuity or routine operational needs. This overlooks a malicious perspective: an adversary does not use this information to operate the facility, but rather to target, bypass, or degrade physical protection and nuclear safety. They want to use it within a malicious act, resulting in a different, or asymmetric, value placed on that information.\nFig. 4 NST070 FIG. 4. The relationship between the State and entities relevant to the nuclear security regime for the purposes of information security (produced verbatim from Ref. 5).\nThis asymmetry is further complicated by the fact that information may have different value throughout the nuclear security regime, often residing in, or being sensitive to other regulated entities or third parties. For example, an operator might discover and mitigate a specific equipment vulnerability, subsequently treating the technical details of that flaw as historical data with low sensitivity. However, if that same equipment design is utilised by other facilities within the regime, an adversary may view those details as a highly valuable blueprint for undertaking a malicious act elsewhere.\nNST070 addresses this asymmetry, explaining that “each entity or organization could have a different use… and perception of the value of information”5. For instance, detailed configuration data for a safety control system might be considered by the operator “to be of little value”. However, to an adversary, such information “might be of high value as it could reveal a weakness or vulnerability that could be exploited in the context of a criminal or intentional unauthorized act”5 and “should therefore be protected consistent with the highest impact and consequence”5.\n2.5. Aggregation and Inference Are Increasingly Important While aggregation (i.e. gathering many pieces of information) is a recognised threat it was not structurally addressed within the original publication of NSS 23-G. Nor was inference, the cognitive leap an adversary makes to construct a model from that fragmented information.\nAn organisation might successfully contain a classified document. However, if an adversary observes related unclassified details, they may infer the context and logic of the document. Many information security frameworks struggle to acknowledge this emergent risk where the relationship between non-sensitive information generates new, sensitive knowledge that bypasses traditional containment.\nNST070 provides a basis for addressing both aggregation and inference, “consideration should also be given to the potential for aggregated information to warrant a higher classification, even if individual components are less sensitive”5. It treats the relationship between data points as a protectable aspect, “collections of non-sensitive information objects could become sensitive information objects if the relationship between the non-sensitive information objects provides additional context for an adversary”5, shifting defence from protecting static object to a calibrated management of the adversary’s orientation leading into a malicious act.\n2.6. Transient Sensitivity Needs Flexibility NSS 23-G was largely built for static or persistently sensitive data (e.g., plans, system designs, threat and vulnerability modelling). It lacked agile mechanisms for information whose value decays rapidly, such as real-time transport logistics or temporary operational variables within an I\u0026C system. Applying dogmatic and heavy-handed controls in these fast-paced environments can severely hinder safety or security functions.\nNST070 recognises that “traditional information security measures can be impractical for enabling the use of information whose sensitivity has a brief lifespan, for example during the transport of nuclear and other radioactive material”5. It allows for agile adaptations, such as “employing code words (including gestures or signs)” 5. However, it cautions that “meaning can be quickly inferred on the basis of context”. Therefore, “the context of these code words”5 must be treated as sensitive information itself, and this approach must be “strictly controlled and limited to scenarios in which the information’s sensitive nature is transient”5.\n2.7. Realigning the Lifecycle and Control Structures to Preserving Functions Many information security lifecycles, including those in NSS 23-G, are depicted as a series of administrative procedures that mirror those used for records management. This approach treats these lifecycle stages as an end unto themselves, creating a disconnect between the State’s overarching objectives for nuclear security and the functional execution, potentially even extending beyond the mandate of nuclear security.\nWithout a cohesive bridge between the lifecycle phases and the objective of nuclear security, policies have remained static and failed to address emerging threats, as, following records management, they formalised a process that prioritised the custody of the object over the contribution to the function.\nFig. 5. NST070 FIG. 6. The four stages in a generic information life cycle and the relationships between them (produced verbatim from Ref. 5).\nIn Fig. 5 NST070 redefines the generic lifecycle and reduces it to a series of stages that can be directly related to functional outcomes5:\nCreating: Actions performed to identify or assemble an information object from abstract information or other information objects, provide context, and asses its sensitivity. Processing: Actions performed on information/information objects that could affect its C/I/A. Using: Actions performed using information/information objects, reliant on its C/I/A. Disposing: Actions performed to archive or destroy information/information objects ensuring they can no longer impair the performance of a function through a loss of C/I/A. To govern this lifecycle, NST070 introduces a layered control structure, dictating that a “State’s legislative, regulatory and policy frameworks… and the information security management system of a regulated entity… should together form information security governance structures”5 demonstrating this hierarchy of controls in Fig. 6.\nFig. 6. NST070 FIG. 1. Relationship between the State’s nuclear security objectives, information security governance structures and the confidentiality, integrity and availability of information (produced verbatim from Ref. 5).\nThis hierarchy ensures the information security management system implemented and maintained by organisations within the nuclear security regime encompasses procedures “designed to provide for the security of sensitive information, sensitive information objects and sensitive information assets”5 to ultimately “preserve satisfactory performance of a regulated entity’s functions using sensitive information”5 while maintaining alignment with the objectives of nuclear security.\n3. OODA and Information Security during a nuclear security event To move away from static containment and operationalise the functional assurance proposed in NST070, we must examine how information actively drives decision-making in the lead-up to and within a nuclear security event. Modern nuclear facilities are among the most robustly regulated examples of critical infrastructure in existence. IAEA guidance has established a series of assurance principles as international norms, such as Defence-in-Depth, the Graded Approach, and the Single Failure Criterion, creating a dense fabric of redundant, parallel safety and security systems designed to deliver important functions even in the face of localised losses (component failure or an emergent vulnerability within the PPS)910.\nHowever, a nuclear facility and its safety and security systems cannot be protected as though they are a static collection of assets. They are complex, dynamic environments comprised of interacting processes designed to maintain these functions. An attack on a single system, a simple ‘hack’, should, by design, not result in an unacceptable loss. A true nuclear security event will emerge from a dynamic encounter within this environment, where an adversary exploits crafted control actions, disrupts feedback loops, or leverages flawed assumptions to force the facility into an unanalysed, hazardous state.\nIn such an encounter, the effectiveness of the facility’s defences depends entirely on the performance of its functions. However, actors performing safety and security functions, whether human or computer, rarely observe physical reality directly. Instead, their operational reality is governed by an orientation. These actors base their decisions and subsequent actions entirely on this orientation. Therefore, if an adversary can manipulate the sensitive information feeding this, they can trick the actor into issuing a damaging action, effectively turning the facility’s own processes against it, bypassing active Defence-in-Depth, and setting the scene for a nuclear security event.\nVisualising how this orientation is formed requires looking at how the conceptual model described in Fig. 1 can be practically applied. It occurs through a layered convergence of information; for any given action, there are typically at least three distinct types of information that mechanically influence the orientation:\nInformation forms the baseline capability of the actor, such as the compiled firmware of a digital controller or the specialised training of the guard force; The actor is instructed by predefined logical rules, such as process logic for a PLC or written standard operating procedures for a guard; and The actor receives observations, interpreting them against their capability and the logical rules to execute actions within the performance a function. These three elements of orientation can be mapped to the NST070 information lifecycle using a model derived from a Input-Control-Output-Mechanism (ICOM) Integration Definition for Process Modelling (IDEF0) 11 function block:\nFig. 7. A set of sensitive information related to the performance of a function illustrating a re-entrant application of Fig. 1 depicted in an ICOM-like structure.\nFeeding this function are information objects that collectively form the system’s orientation:\nInput (I): This is the raw observation of the physical world. It provides the situational context (e.g., Temperature is 300°C). Control (C): These are the task specific instructions. They represent the application logic, safety constraints, or work orders/instructions (e.g., If Temp \u003e 280°C, open valve). Mechanism (M): This is the base capability of the actor itself. Additionally, it holds the Knowledge or System Programming required to interpret the inputs against the controls to produce an output. For an Output (O) to be generated the mechanism (and therefore the actor) must resolved the interaction of the three variables above to form a prediction, decide on a course of action, and then act to execute it. By defining the orientation in this way, we see that any compromise to the integrity of the Control or Mechanism, or the availability and integrity of the Input, results in a flawed orientation, forcing the actor to base their decisions upon a reality that does not exist.\nThis can be demonstrated through mapping the internal architecture of the OODA loop’s Orient and Decide phases to the Using phase of the information lifecycle.\nFig. 8. The ICOM-like structure in Fig. 7 applied to demonstrate the formulation of orientation within an OODA loop6.\n3.1. The Vulnerability of the Fixed Orientation Because of their highly regulated nature, nuclear facilities largely operate with a fixed orientation. To ensure deterministic and verifiable responses, the operational logic and mechanisms are rigorously baselined. While this provides stability against anticipated losses (e.g. random component failures), it creates a strategic vulnerability: the defender’s Decide and Act phases can be discovered through reconnaissance.\nArmed with this knowledge, an adversary does not need to outpace the defender’s OODA loop, they simply decouple it from reality. By manipulating the Input or poisoning the Control, such as through maliciously altering ladder logic or a guard’s orders, the attacker forces the actor to perform its function perfectly against a false orientation. For example, if a sensor’s integrity is compromised to report a normal state during an actual excursion, the safety system’s decision to remain idle is technically correct according to its logic yet may be functionally damaging.\nWhen malicious information is successfully injected into the orientation this way, the actor maintains total confidence in their orientation, unwittingly executing the adversary’s intent. The defender is no longer reacting to an external threat; they have been rendered an agent of the attacker. This corruption may bypass redundancy provided by the single failure criterion as well as all active layers of defence-in-depth, including physical, computer, and information security barriers entirely, as the system executes the action under the assumption that it is a legitimate operational requirement.\nConclusion: Reclaiming the Orientation Adversaries intent on violating the core objectives of nuclear security (preventing theft and sabotage) will not merely seek to extract information. Because defence-in-depth within most nuclear facilities is so thoroughly established, brute-force physical bypass is exceptionally difficult.\nInstead, the lowest-cost path for an adversary is increasingly being demonstrated as an attack the orientation itself. This targeted attack path relies on a specific sequence:\nRevealing Limitations: By uncovering the logic the adversary maps the system’s fixed orientation. If the function lacks architectural diversity, compromising the confidentiality of one system reveals the blind spots of all systems. This collapses the adversary’s required effort, turning what should be independence into a single, shared attack path. Corrupting Orientation: Denying Observation: By blocking or severing the input data, the adversary blinds the orientation. Attacking Integrity: By subtly altering the inputs, logic, or mechanisms, the adversary corrupts the system’s orientation, forcing it to act on a false reality. Our advantage will not come from the static defences established by containment-based information security. Frameworks like the original NSS 23-G focused almost exclusively on the physical containment of tangible information objects, a posture that is entirely blind to an adversary manipulating abstract information flows. By applying the functional, lifecycle-based protections of the draft NST070, we shift away from this limited perception of value.\nInstead, NST070 provides a basis against which to assess the value of information functionally, through the eyes of other stakeholders in the nuclear security regime, and the adversary. Because the adversary’s attack path requires them to map our limitations and manipulate our orientation, their success is dependent on exploiting sensitive information. By shifting our priority from strict confidentiality to ensuring the integrity and availability of the basis for action within our functions, we enforce the modern principles of trustworthiness12. We protect the exact information an adversary would value most, starving them of the prerequisites for success and turning their reconnaissance and manipulation attempts into detectable anomalies.\nThese early indicators provide us with the opportunity for active defence. Because the facility inherently possesses the master operational picture, understanding our reliance on sensitive information allows us to dynamically re-calibrate our orientation: validating inputs, shifting control logic, or isolating compromised actors. With a well-established understanding of our own orientation we can do this long before the adversary can achieve their goal.\nBy securing this sensitive information relative to its uses and preparing for a dynamic encounter, we force the adversary to fight through exponentially compounding layers of uncertainty, introducing crippling friction into their decision cycle. We shift from a posture of passive containment to consistently operating inside the adversary’s OODA loop, ensuring the facility acts on a validated and resilient orientation13.\nThe circulated draft of NST070 aligns directly with this systems theory view. It recognises that in a modern nuclear environment, security is not merely about locking away the data but preserving the orientation so it can be safely relied upon during an emerging nuclear security event. By shifting to a model that re-evaluates information through its functional consequence, the new guidance changes how risk is calculated. Security measures are no longer graded simply by the administrative sensitivity of a static document, but by how severely a system’s orientation would diverge from reality if that information were corrupted, and what the consequences of that divergence would be.\nUltimately, NST070 modernises the foundations of information security to address the rapidly developing capabilities of digital technology, including the use of AI by both operators and adversaries. It provides the framework necessary to counter sophisticated, information-centric threats. It ensures that when an actor executes a safety or security function, it acts not as an unwitting agent of the adversary, but based on an assured, trustworthy orientation that accurately reflects the true orientation of the facility.\nReferences International Atomic Energy Agency (IAEA) Nuclear Security Series No. 23-G, “Security of Nuclear Information,” Vienna, Austria, 2015. https://www.iaea.org/publications ↩︎\nA. Crowe, “Mass Insider Threats: Civilians, Cyberoperations, Critical Infrastructure, and the Erosion of Sovereignty in the Grey-Zone,” in Oxford Intersections: Borders, ed. Alexander Diener and Joshua Hagen, Oxford University Press, 2026. ↩︎\nInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 42-G, “Computer Security for Nuclear Security,” Vienna, Austria, July 2021. https://www.iaea.org/publications ↩︎\nInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 17-T (Rev. 1), “Computer Security Techniques for Nuclear Facilities,” Vienna, Austria, September 2021. https://www.iaea.org/publications ↩︎\nInternational Atomic Energy Agency (IAEA) Draft Implementing Guide NST070 Step 12, “Information Security for Nuclear Security,” Vienna, Austria, 2025. ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\nJ. R. Boyd, “The Essence of Winning and Losing,” Unpublished briefing slides, June 1995.. ↩︎ ↩︎\nS. C. Lackner and Z. Kara, “Artificial Intelligence and Nuclear Security Governance: Addressing the Risks of Frontier AI,” Vienna Center for Disarmament and Non-Proliferation, 2025 ↩︎\nN. G. Leveson, “Engineering a Safer World: Systems Thinking Applied to Safety,” The MIT Press, 2012. https://doi.org/10.7551/mitpress/8179.001.0001 ↩︎\nINTERNATIONAL ATOMIC ENERGY AGENCY, Nuclear Security Recommendations on Physical Protection of Nuclear Material and Nuclear Facilities (INFCIRC/225/ Revision 5), IAEA Nuclear Security Series No. 13, IAEA, Vienna (2011). ↩︎\nINTERNATIONAL ATOMIC ENERGY AGENCY, Safety of Nuclear Power Plants: Design, IAEA Safety Standards Series No. SSR-2/1 (Rev. 1), IAEA, Vienna (2016). ↩︎\nNational Institute of Standards and Technology (NIST) Federal Information Processing Standards Publication (FIPS PUB) 183, “Integration Definition for Function Modeling (IDEF0),” Gaithersburg, MD, December 1993. https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub183.pdf ↩︎\nNational Institute of Standards and Technology (NIST) Special Publication 800-160 Volume 1 Revision 1, “Engineering Trustworthy Secure Systems,” Gaithersburg, MD, November 2022. https://doi.org/10.6028/NIST.SP.800-160v1r1 ↩︎\nRick Dove, “Embedding Agile Security in System Architecture,” Insight 12 (2): 14-17, International Council on Systems Engineering, July 2009. ↩︎\n","date_published":"2026-05-28T19:00:00+03:00","id":"https://blog.mitcdh.au/posts/nuclear-needs-information-security/","image":"https://blog.mitcdh.au/images/nuclear-needs-information-security.webp","summary":"The Promise Of NST070","tags":["Writing","Nuclear","Technology","Security","Safety"],"title":"Why Nuclear Security Needs Information Security","url":"https://blog.mitcdh.au/posts/nuclear-needs-information-security/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis article has been adapted verbatim from a paper accepted and presented during the \u003ca href=\"https://www.iaea.org/events/cybercon26\"\u003eInternational Conference on Computer Security in the Nuclear World: Securing the Future\u003c/a\u003e titled \u0026lsquo;\u003ca href=\"https://conferences.iaea.org/event/428/contributions/39258/\"\u003eWhere To Start — The System Or The Function? How The V-Model Clarifies Effective Computer Security\u003c/a\u003e\u0026rsquo; authored by \u003ca href=\"https://www.linkedin.com/in/mike-stjohn-green-685b6163/\"\u003eMike StJohn-Green\u003c/a\u003e and myself.\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"abstract\"\u003eAbstract\u003c/h2\u003e\n\u003cp\u003eIAEA guidance on computer security calls for two levels of risk management, initially a function-based analysis followed by a systems-based analysis. This concept of multiple levels of risk analysis is also present in other computer security standards (IEC 62443, IEC 62645, NRC), although they differ on the details of whether a graded approach should consider impact, adversarial-skill, or likelihood. However, the most significant practical challenge in implementing this guidance is bridging the functions-systems analyses, resulting in a struggle to translate between impacts, risks, and vulnerabilities.\u003c/p\u003e\n\u003cp\u003eIntegrating this analysis directly into the engineering lifecycle, however, enables Secure-by-Design. This method resolves the issues preventing designs that are merely compliant on paper from remaining vulnerable in practice. It highlights the need to prepare for and perform risk management throughout the operational lifetime of the plant.\u003c/p\u003e\n\u003cp\u003eThis paper directly addresses the transition from an analysis of functions with risks to an analysis of systems with vulnerabilities, a topic that current publications do not explore in detail. It will present an engineering lifecycle view that fosters holistic security by design, is consistent with the major publications, and harnesses complementary physical and personnel security measures that work coherently to achieve safety and security objectives. This perspective on the engineering lifecycle offers a practical interpretation of the function-based concept for those seeking to implement IAEA and other guidance.\u003c/p\u003e\n\u003ch2 id=\"1-introduction\"\u003e1. Introduction\u003c/h2\u003e\n\u003cp\u003eA security risk can be described in terms of the capability, motivation and opportunity of a threat actor to act on a combination of vulnerabilities to cause an adverse outcome. To fully understand what adverse outcomes are possible in a nuclear power plant calls requires a top-down function-based understanding of the entire plant. However, the threat actor has to exploit vulnerabilities, to create credible attack scenarios in order to be successful in their malicious intent. It would be disproportionate to defend against an attack that is genuinely inconceivable. For computer security, this analysis calls for very detailed knowledge of how the digital technology in a nuclear power plant works, suggesting a bottom-up approach.\u003c/p\u003e\n\u003cp\u003eEffective security requires both high-level strategy and a granular defence. A purely top-down functional analysis will ignore detailed vulnerabilities, while a strictly bottom-up asset-by-asset analysis without understanding their functional contribution and significance will lead to a disproportionate and flawed defensive architecture. Neither will deliver a graded approach on their own, as called for in IAEA guidance \u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e. Therefore, whether designers are starting with a blank sheet of paper and a requirement to design a nuclear power plant or working in an operational plant, with computer-based control systems that need upgrading, it is necessary to analyse both the higher-level functional design and the lower-level system design. The need for multiple levels of risk management is reflected in IAEA guidance and in some international standards but there is a lack of consistency and consensus about how this might work in practice.\u003c/p\u003e\n\u003cp\u003eFurther, computer security requirements need to be considered early in the design process, alongside those for safety, physical security and safeguards in order to achieve coherence and complementarity in the manner in which they are delivered, and achieve security-by-design.\u003c/p\u003e\n\u003cp\u003eThis paper describes the relationship between the two levels of risk management and how they collectively fit into the mainstream engineering design activities of a nuclear power plant, with its multiple opportunities to reduce the consequences and risks of malicious action. This also allows for non-security risks to be managed with the same process. It suggests a closer working relationship between all the disciplines.\u003c/p\u003e\n\u003ch2 id=\"2-current-computer-security-guidance\"\u003e2. Current Computer Security Guidance\u003c/h2\u003e\n\u003cp\u003eIAEA guidance in NSS 17-T (Rev 1) \u003csup id=\"fnref:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e divides the risk-based approach into Facility Computer Security Risk Management (FCSRM), focused on functions, and System Computer Security Risk Management (SCSRM), focused on the implementation of those functions using computer-based systems. In Figure 1 \u003csup id=\"fnref1:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e, the system level is shown embedded within the functional level and there is evidence of the iterative nature between the different stages. The Computer Security Programme (CSP) and the Defensive Computer Security Architecture (DCSA) are two of the enduring artefacts that provide continuity between the different stages.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/where-to-start-system-or-function_01.webp\" width=\"1079\" height=\"762\" alt=\"IAEA NSS 17-T (Rev 1) Figure 6, Overview of the computer security risk management process\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 1 \u0026ndash; IAEA NSS 17-T (Rev 1) Figure 6, Overview of the computer security risk management process \u003csup id=\"fnref2:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eIAEA guidance \u003csup id=\"fnref1:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref3:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e recommends that the graded approach defined at the higher functional level should be based on the consequences of the adverse outcome. This involves identifying and seeking to reduce the inherent risk of the project or plant design through the establishment of barriers at an architectural level. At the system level, the defender considers the combination of the threat actor\u0026rsquo;s capability, motivation and intent to cause the adverse outcome with an understanding of the vulnerabilities in the target.\u003c/p\u003e\n\u003cp\u003eIt is worth noting the operator\u0026rsquo;s perspective on the management of risk will have a much wider scope of adverse outcomes than the protection of nuclear security. For example, the operator must also manage risks to the provision of essential critical infrastructure services and business risks of profitability.\u003c/p\u003e\n\u003cp\u003eAn important internationally-recognised pan-industry standard for the computer security / cybersecurity of Industrial Control Systems, IEC 62443-3-2 \u003csup id=\"fnref:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e, also describes a two-level approach, see Figure 2. The language in IEC 62443-3-2 differs from IAEA guidance in that there is no mention of functions in Figure 2 but the initial cyber security risk assessment (ZCR 2 in Figure 2) based on severity of (functional) consequences leads to the partitioning into security zones. This aligns well with the output of FCSRM (i.e. the functional level) in the IAEA guidance. The detailed risk assessment (ZCR 5 in Figure 2) then seeks to reduce the residual risk for each zone to an acceptable level. This equates to SCSRM in the IAEA approach (i.e. the system level) though IEC 62443-3-2 here refers to zones that contain systems. There are other important differences in the treatment of likelihood of a successful attack when determining what strength of security measures are proportionate, and the resulting nature of the graded approach. The differences reinforce the point that there isn\u0026rsquo;t yet a consensus of guidance, but the similarity in the need for multiple levels of management of risk through a graded approach is nevertheless evident.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/where-to-start-system-or-function_02.webp\" width=\"795\" height=\"1077\" alt=\"IEC 62443-3-2, Flow diagram for Security Risk Assessment for Design\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 2 \u0026ndash; IEC 62443-3-2, Flow diagram for Security Risk Assessment for Design \u003csup id=\"fnref1:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eIt is worth noting that the outputs of Process Hazards Analysis (PHA) are an input to the initial risk assessment shown in Figure 2. Similarly, the Facility Safety Report appears in Figure 1 from the IAEA. This illustrates how safety-related work informs the security risk assessment, to ensure that the output of computer security risk management supports the needs of safety. This paper argues that the relationship between the two disciplines should be close.\u003c/p\u003e\n\u003ch2 id=\"3-the-argument-for-a-single-coherent-design-activity\"\u003e3. The Argument For A Single, Coherent Design Activity\u003c/h2\u003e\n\u003cp\u003eIt has now widely quoted that for a computer-based system \u0026ldquo;If it\u0026rsquo;s not secure, it\u0026rsquo;s not safe.\u0026rdquo;  \u003csup id=\"fnref:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e, a position supported by this paper. This means that the safety case of a system, such as the control system for a nuclear reactor, cannot be deemed valid without adequate assurance that the control system is protected from malicious action. This paper asserts that analysis of how malicious action may undermine safety must be part of the design activity. Therefore, security should be designed to support safety and both should also be designed in a coherent and mutually-reinforcing manner.\u003c/p\u003e\n\u003cp\u003eThis need for complementarity also applies to physical security (e.g. tampering with sensors that have a role in safety), personnel security (e.g. the insider) and computer security (e.g. interfering with digital technology).\u003c/p\u003e\n\u003cp\u003eComputer security relies on adequate, complementary physical security and personnel security measures. For example, if an adversary can gain unconstrained and undetected access to the computer hardware or networks, a wide range of possible attacks become possible. Additionally, physical security and personnel security rely heavily on computer-based systems. For example, digital surveillance cameras connected to a network can be spoofed to mislead the Central Alarm Station staff, and delay physical security response, if computer security is inadequate. Identity and Access Management relies on the security of the information to underpin the control of personnel access for many purposes. All forms of security have a relationship with information security because trusting the confidentiality, integrity and availability of information is both a necessary foundation for and outcome of the other forms of security. This paper argues, therefore, that the means to deliver the different forms of security should therefore be designed in a coherent and mutually-reinforcing manner.\u003c/p\u003e\n\u003cp\u003eAs the resilience of energy generation becomes a prominent national security issue and must be considered alongside traditional nuclear security, this argument for holistic design process extends still further, into the mainstream operational design activities.\u003c/p\u003e\n\u003cp\u003eCost-effective construction and operation of nuclear systems also demands a coherent, holistic design that combines security requirements with other requirements as part of the options analysis. Consider, for example, the incentives on designers to use Wi-Fi in advanced reactor designs, to reduce the cost of wiring. The total savings should be offset as part of the initial design analysis by the cost of protecting the Wi-Fi from malicious action, to provide designers with an informed choice.\u003c/p\u003e\n\u003cp\u003eWhat is being described in this paper is a traditional engineering design process that considers the different functional, e.g. energy generation, and non-functional, e.g. safety and security, requirements together. This is not a new concept to systems engineers but is not universally recognised by security engineers, who are often taught to see security activities through their own largely independent security lifecycle \u003csup id=\"fnref4:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref2:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e. However, this paper is not unique its message that \u0026ldquo;\u0026hellip; security \u0026hellip; must be fundamental to systems engineering, not just a specialty discipline. Security concepts must be fundamental to (an) engineering education, and security proficiency must be fundamental in development teams.\u0026rdquo; \u003csup id=\"fnref:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref:6\"\u003e\u003ca href=\"#fn:6\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e6\u003c/a\u003e\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/where-to-start-system-or-function_03.webp\" width=\"2176\" height=\"1560\" alt=\"Where security risk is primarily managed in a simplified engineering lifecycle model\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 3 – Where security risk is primarily managed in a simplified engineering lifecycle model\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"4-the-engineering-lifecycle\"\u003e4. The Engineering Lifecycle\u003c/h2\u003e\n\u003cp\u003eFigure 3 is an interpretation of a classic engineering lifecycle, often described as a \u0026lsquo;V Diagram\u0026rsquo;, that has been amended for this paper to emphasise the activities of computer security risk management in that lifecycle. Figure 3 was inspired by a diagram in nuclear safety guidance \u003csup id=\"fnref:7\"\u003e\u003ca href=\"#fn:7\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e7\u003c/a\u003e\u003c/sup\u003e, and derived from a more complex diagram at Annex 1. The following subsections step through Figure 3 to describe in more detail how computer security risk management can engage in the engineering lifecycle. This can represent an entire plant or a small project.\u003c/p\u003e\n\u003ch3 id=\"41-project-definition\"\u003e4.1. Project Definition\u003c/h3\u003e\n\u003cp\u003eInitially, in the engineering design process, security is very much a reaction to the conceptual requirements \u0026ndash; if you want to use nuclear material, you will need some protections. The high-level, functional design can only be practically achieved at a high level of abstraction, before refining requirements with increasing levels of detail in the design and implementation, which will likely later identify the need for and use of computer-based systems.\u003c/p\u003e\n\u003cp\u003eSecurity involvement should be focussed on reducing or eliminating the potential consequences of malicious action, such as by reducing the inventory of nuclear material. Because these design factors are determined by the initial concept and then reflected in the functional specification of the plant (or project), early security involvement is critical. Furthermore, the manner in which security will support safety and other organisational objectives and how the different aspects of security will work together need establishing.\u003c/p\u003e\n\u003cp\u003eBy failing to address security at this stage, there are some obvious consequences: the organisation misses cost-effective opportunities to the possible consequences of malicious action and thus reduce inherent risk; and because the analysis of risk starts too late, it loses its relationship to the top-level requirements for the plant/project. Ultimately, this delay prevents security from integrating coherently with other disciplines.\u003c/p\u003e\n\u003ch3 id=\"42-functional-design\"\u003e4.2. Functional Design\u003c/h3\u003e\n\u003cp\u003eDuring the functional design, the represented design teams are making choices about the plant and its control systems at a high level of abstraction. At this point, the requirements describe a set of functions and may still be entirely agnostic of the type of technology that will be used, though some constraints may already have been introduced to reduce inherent risk. Once the combined functional design has been completed, a high-level block-diagram design will be defined, with candidate systems nominated to deliver the functional requirements.\u003c/p\u003e\n\u003cp\u003eWithin this phase there should be further opportunities to reduce the inherent risk, such as by reducing the quantity of sensitive information that will be exposed, by design. This focus on inherent risk and then residual and is reflected in the US NRC pre-decisional publication on Tiered Cybersecurity Analysis \u003csup id=\"fnref:8\"\u003e\u003ca href=\"#fn:8\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e8\u003c/a\u003e\u003c/sup\u003e.  \u003c/p\u003e\n\u003cp\u003eAt this point, the designers should be developing scenarios on how adversaries might cause adverse security outcomes, developing a big picture view of major consequences and identifying barriers that further reduce the inherent risk. The designers don\u0026rsquo;t yet know why a barrier might fail, just that it should exist. Failing to reduce the risk at this point means there will be a higher level of inherent risk to be managed later with a greatly reduced control set and, again, there may be a loss of relationship in the risk analysis to the top-level requirements and the missed opportunity to achieve coherence with other disciplines, to resolve contradictions and trade-offs\u003csup id=\"fnref:9\"\u003e\u003ca href=\"#fn:9\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e9\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003ch3 id=\"43-system-design-and-iteration\"\u003e4.3. System Design And Iteration\u003c/h3\u003e\n\u003cp\u003eDesign activities then continue with requirements derived, disaggregated and assigned to be delivered by individual systems. The system level addresses the design and implementation of functional requirements and should seek to reduce the risk to those functions to an acceptable level, through the identification of requirements for security measures. Note that some of these security measures will require the addition of security devices, such as firewalls, but many will place requirements on the way the control systems are designed, built and operated, such as software assurance and supply chain provenance, requiring close engagement with their designers.\u003c/p\u003e\n\u003cp\u003eInitially, there may errors in design assumptions, conflicting requirements, misplaced trust and other latent vulnerabilities introduced through imperfect specifications \u003csup id=\"fnref:10\"\u003e\u003ca href=\"#fn:10\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e10\u003c/a\u003e\u003c/sup\u003e. The more complex the combination of systems, the more likely there will be unpredictable emergent properties. Also, the system level design may identify better ways to assign functions to systems. The system and function design activities therefore need to be iterative.\u003c/p\u003e\n\u003cp\u003eIn the IAEA guidance, the Defensive Computer Security Architecture is a central artefact in the design activities for computer security. It is created at a high level of abstraction during functional design and becomes more detailed in the system level \u003csup id=\"fnref5:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e. The DCSA provides designers with a common view of the design, its requirements and constraints. Some interpretations of the DCSA describe a network diagram (see Figure 2 of NSS 17-T \u003csup id=\"fnref6:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e). Other industries have identified Model Based Systems Engineering (MBSE) as providing this common design view, with a set of models or views that are gradually elaborated through iterative design activities \u003csup id=\"fnref1:10\"\u003e\u003ca href=\"#fn:10\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e10\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eMost computer security vulnerabilities will only be identified when candidate technologies and candidate control system designs are scrutinised in detail. Consider, for example, a very high consequence safety function has requirements for security, to provide resilience and reliability in the face of malicious action. At this point in the design activity, candidate controls may be selected from catalogues of security measures. Many computer security standards offer such lists and, in some regulatory environments, there may be a set of minimum requirements or a suite of minimum controls. In the risk-based approach described in IAEA guidance and in the IEC 62443 family of standards, the designer must now assess which security measures will defend against possible adversary action to exploit known vulnerabilities. Crucially, the designer may find those requirements so stringent or so expensive that they cannot easily be met by systems using networked programmable digital technology, especially if its supply chain provenance cannot be adequately proven. This is a practical illustration that the relationship between the high-level functional design and lower-level system design must allow for iteration.\u003c/p\u003e\n\u003ch3 id=\"44-implement-components-systems-functions\"\u003e4.4. Implement Components, Systems, Functions\u003c/h3\u003e\n\u003cp\u003eThe step to implementation may in many projects be via a contract interface, with a detailed system requirement being implemented as a separate activity by another organisation. In general, it can reduce project risk if managers can disaggregate project activities into separate distinct tasks with well-defined scopes. Most standards reflect this natural desire to operate in this way. However, this can also often mean that the physical security, computer security design and safety design activities take place independently.\u003c/p\u003e\n\u003cp\u003eRisks can be introduced at this point due to weaknesses in requirements, in component assurance, implementation, or interface coordination, but the right-hand side of the V Diagram shown in Figure 3 relies upon conventional engineering practice to perform design acceptance, which should maintain the residual risk profile against the original design intent. Component assurance includes adequate testing and supply chain provenance to form a trusted foundation to maintain the accepted residual risk profile against the original design intent.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/where-to-start-system-or-function_04.webp\" width=\"867\" height=\"668\" alt=\"IAEA NSS 17-T (Rev 1) Figure 7 showing verification and validation in Computer Security Risk Management on the Engineering V Diagram\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 4 – IAEA NSS 17-T (Rev 1) Figure 7 showing verification and validation in Computer Security Risk Management on the Engineering V Diagram \u003csup id=\"fnref1:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eAs components become systems and they in turn are commissioned to implement functions, the functional acceptance criteria and commissioning should include validation against the original attack scenarios, as a further check against errors that may occur in the entire design disaggregation down the left-hand side and the implementation up the right-hand side. Figure 4 is also from NSS 17-T (Rev 1) \u003csup id=\"fnref7:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e, illustrating how validation checks the various levels of implementation against the original intent. It is also significant that this figure uses a very similar form of Engineering V Diagram, reflecting the 2 levels of risk assessment in NSS 17-T (Rev 1).\u003c/p\u003e\n\u003ch3 id=\"45-operations\"\u003e4.5. Operations\u003c/h3\u003e\n\u003cp\u003eReturning to Figure 3, once the system has become operational, the defender has to identify new vulnerabilities in computer-based systems before the adversary. This requires understanding the plant-level consequences in order to prioritise remediations, for example applying patches, thinking like an adversary only better and quicker, to manage the risk throughout the plant/project operating lifetime. The defender must know which computer-based systems support which high-level functions, and which system failures lead to adverse physical outcomes, to be able to act faster than the adversary in order to close new attack paths before the adversary can exploit them. The design of computer-based systems, and their associated commercial contracts, must acknowledge this whole-life management of risk by staff, with the necessary deep knowledge of the digital technology. This places additional demands on traditional maintenance and illustrates the need for close working between security and engineering teams.\u003c/p\u003e\n\u003ch2 id=\"5-anticipating-some-questions\"\u003e5. Anticipating Some Questions  \u003c/h2\u003e\n\u003ch3 id=\"51-can-computer-security-risk-ever-be-managed-in-a-single-step-process\"\u003e5.1. Can Computer Security Risk Ever Be Managed In A Single Step Process?\u003c/h3\u003e\n\u003cp\u003eYes, but only if a system is so simple that its role in delivering high level functions can be determined in the same activity as understanding the detail of vulnerabilities that the adversary can exploit. For a trivially simple industrial activity, this may be the case. For something as complex as a nuclear power plant, this is highly unlikely to be practical and the multidisciplinary reduction in inherent risk followed by prudent management of residual risk as described earlier will deliver a more effective solution.\u003c/p\u003e\n\u003ch3 id=\"52-can-the-process-start-with-a-list-of-computer-based-assets-and-work-from-there\"\u003e5.2. Can The Process Start With A List Of Computer-Based Assets And Work From There?\u003c/h3\u003e\n\u003cp\u003eYes, a project may have as its focus an existing computer-based system, e.g. to perform a limited upgrade on its constituent assets.  In this case, the functional significance of the computer-based system will already be very well documented. If the project is making a greater change to the functionality, e.g. changing system boundaries and relationships, there may need to be a reassessment of the functional analysis. The crucial point is that the risk assessment at the level of the computer-based system can only be performed with knowledge of its functional context, so at some point there needs to be an understanding of the high-level functional design \u003csup id=\"fnref:11\"\u003e\u003ca href=\"#fn:11\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e11\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eHowever, if there is too much emphasis on analysis at a system level and a failure to understand the functional level, defences will not be truly proportionate to the exposure to risk and there is an increased chance of a flawed defensive architecture, as Young and Leveson observe \u003csup id=\"fnref2:10\"\u003e\u003ca href=\"#fn:10\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e10\u003c/a\u003e\u003c/sup\u003e. There is also a greater chance of rework. For example, to apply security zones to an existing Instrumentation and Control (I\u0026amp;C) design may require extensive changes to data-flows and trust relationships, probably requiring expensive rework. This also applies to the inclusion of safeguards requirements as part of the design activity, to avoid for example the need to make holes and run wires in unhelpful places to fit unanticipated sensors.\u003c/p\u003e\n\u003ch3 id=\"53-why-doesnt-computer-security-for-it-follow-this-approach\"\u003e5.3. Why Doesn\u0026rsquo;t Computer Security For It Follow This Approach?\u003c/h3\u003e\n\u003cp\u003eComputer security developed as a reaction to the use of computer-based systems to process information, referred to as information technology (IT), and computer security focused almost entirely on protecting the confidentiality of information in proportion to its perceived value. The assessment of computer security risk generally started with an existing landscape of sensitive information that needed identifying, assessing and protecting. Operational Technology (OT, may also be known as SCADA or Instrumentation and Control), in contrast with IT, addresses risks to cyber-physical systems, often with risks to assets, life, and to the environment, and consequently has a close relationship with safety.\u003c/p\u003e\n\u003ch2 id=\"6-conclusion\"\u003e6. Conclusion\u003c/h2\u003e\n\u003cp\u003eTo protect nuclear facilities in the current threat environment requirements for computer security for nuclear security must be integrated with those for safety and physical protection, with those responsible for the design and operation of the plant, under a systems engineering umbrella.\u003c/p\u003e\n\u003cp\u003eThis paper argues that managing the risks arising from computer-based systems should include the reduction of exposure to malicious action in the concept phase and the subsequent reduction of inherent risk in the functional design. A closer interdisciplinary relationship may be needed in some projects in the early stages of design to achieve this and thereby achieve security-by-design, and to avoid security being additive. This paper describes how this can be achieved by including computer security activities at appropriate points in the engineering lifecycle, from the earliest opportunity.\u003c/p\u003e\n\u003cp\u003eAs computer-based systems are used ever more extensively, and the complexity of their designs increases, it is no longer viable to design computer security to defend the individual assets in an additive manner, independent of the overall plant design \u003csup id=\"fnref3:10\"\u003e\u003ca href=\"#fn:10\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e10\u003c/a\u003e\u003c/sup\u003e. Even were that not the case, additive security will more likely lead to expensive rework, and missed opportunities for cost-savings for design controls that will be more effective than the additive computer security measures.\u003c/p\u003e\n\u003cp\u003eThis paper also argues that some existing standards and guidance can be easily mapped onto this lifecycle, but not all standards are yet describing the whole picture. The content of this paper is written to be consistent with current IAEA publications in the NSS series and may help fill in some gaps.\u003c/p\u003e\n\u003ch2 id=\"annex-1--a-more-detailed-v-model-for-computer-security\"\u003eAnnex 1 \u0026ndash; A more detailed V Model for computer security\u003c/h2\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/where-to-start-system-or-function_05.webp\" width=\"2317\" height=\"1399\" alt=\"A more detailed V Model for computer security\" loading=\"lazy\" decoding=\"async\"\u003e\n\u003c/p\u003e\n\u003ch2 id=\"references\"\u003eReferences\u003c/h2\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 42-G, \u0026ldquo;Computer Security for Nuclear Security,\u0026rdquo; Vienna, Austria, July 2021. \u003ca href=\"https://www.iaea.org/publications\"\u003ehttps://www.iaea.org/publications\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:2\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 17-T (Rev. 1), \u0026ldquo;Computer Security Techniques for Nuclear Facilities,\u0026rdquo; Vienna, Austria, September 2021. \u003ca href=\"https://www.iaea.org/publications\"\u003ehttps://www.iaea.org/publications\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref2:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref3:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref4:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref5:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref6:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref7:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:3\"\u003e\n\u003cp\u003eInternational Electrotechnical Commission, Geneva, IEC 62443-3-2  \u003ca href=\"https://webstore.iec.ch/\"\u003ehttps://webstore.iec.ch/\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref2:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:4\"\u003e\n\u003cp\u003eBLOOMFIELD, PROF, R, STROUD R., Sep 2013, Security-Informed Safety \u0026ldquo;If it\u0026rsquo;s not secure, it\u0026rsquo;s not safe\u0026rdquo;, MarcOlivier Killijian. Safecomp 2013 FastAbstract, Toulouse, France. pp.NC, 2013.\u0026#160;\u003ca href=\"#fnref:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:5\"\u003e\n\u003cp\u003eSecurity in the Future of Systems Engineering (FuSE), a Roadmap of Foundational Concepts, INCOSE International Symposium, July 2021.\u0026#160;\u003ca href=\"#fnref:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:6\"\u003e\n\u003cp\u003eUnited States National Institute of Science and Technology, November 2022, Engineering Trustworthy Secure Systems, NIST Special Publication NIST SP 800-160v1r1. \u003ca href=\"https://doi.org/10.6028/NIST.SP.800-160v1r1\"\u003ehttps://doi.org/10.6028/NIST.SP.800-160v1r1\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:6\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:7\"\u003e\n\u003cp\u003eOffice of Nuclear Regulation, May 2025, ONR Technical Assessment Guide, Categorisation of safety functions and classification of structures, systems and components (SSCs), NS-TAST-GD-094.  \u003ca href=\"https://www.onr.org.uk/publications/regulatory-guidance/\"\u003ehttps://www.onr.org.uk/publications/regulatory-guidance/\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:7\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:8\"\u003e\n\u003cp\u003eUnited States Nuclear Regulatory Commission, pre-decisional of 13 October 2023, proposed new regulatory guide under NRC 10 CFR Part 53, DG-5075, \u003ca href=\"https://www.nrc.gov/docs/ML2328/ML23286A278.pdf\"\u003ehttps://www.nrc.gov/docs/ML2328/ML23286A278.pdf\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:8\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:9\"\u003e\n\u003cp\u003eYOUNG, W.E., LEVESON, PROF N., IT, Cambridge, MA, December 2013, Systems thinking for safety and security, ACSAC \u0026lsquo;13 Proceedings of the 29th Annual Computer Security Applications Conference.\u0026#160;\u003ca href=\"#fnref:9\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:10\"\u003e\n\u003cp\u003eJAPS, ANACKER, DUMITRESCU, 31st CIRP Design Conference, 2021, SAVE: Security \u0026amp; safety by model-based systems engineering on the example of automotive. Available online at \u003ca href=\"http://www.sciencedirect.com/\"\u003ewww.sciencedirect.com\u003c/a\u003e  \u0026#160;\u003ca href=\"#fnref:10\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:10\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref2:10\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref3:10\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:11\"\u003e\n\u003cp\u003eIdaho National Laboratory, Cyber Informed Engineering Implementation Guide, August 2023, INL/RPT-23-74072, \u003ca href=\"https://inldigitallibrary.inl.gov/sites/sti/sti/Sort_67122.pdf\"\u003ehttps://inldigitallibrary.inl.gov/sites/sti/sti/Sort_67122.pdf\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:11\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This article has been adapted verbatim from a paper accepted and presented during the International Conference on Computer Security in the Nuclear World: Securing the Future titled ‘Where To Start — The System Or The Function? How The V-Model Clarifies Effective Computer Security’ authored by Mike StJohn-Green and myself.\nAbstract IAEA guidance on computer security calls for two levels of risk management, initially a function-based analysis followed by a systems-based analysis. This concept of multiple levels of risk analysis is also present in other computer security standards (IEC 62443, IEC 62645, NRC), although they differ on the details of whether a graded approach should consider impact, adversarial-skill, or likelihood. However, the most significant practical challenge in implementing this guidance is bridging the functions-systems analyses, resulting in a struggle to translate between impacts, risks, and vulnerabilities.\nIntegrating this analysis directly into the engineering lifecycle, however, enables Secure-by-Design. This method resolves the issues preventing designs that are merely compliant on paper from remaining vulnerable in practice. It highlights the need to prepare for and perform risk management throughout the operational lifetime of the plant.\nThis paper directly addresses the transition from an analysis of functions with risks to an analysis of systems with vulnerabilities, a topic that current publications do not explore in detail. It will present an engineering lifecycle view that fosters holistic security by design, is consistent with the major publications, and harnesses complementary physical and personnel security measures that work coherently to achieve safety and security objectives. This perspective on the engineering lifecycle offers a practical interpretation of the function-based concept for those seeking to implement IAEA and other guidance.\n1. Introduction A security risk can be described in terms of the capability, motivation and opportunity of a threat actor to act on a combination of vulnerabilities to cause an adverse outcome. To fully understand what adverse outcomes are possible in a nuclear power plant calls requires a top-down function-based understanding of the entire plant. However, the threat actor has to exploit vulnerabilities, to create credible attack scenarios in order to be successful in their malicious intent. It would be disproportionate to defend against an attack that is genuinely inconceivable. For computer security, this analysis calls for very detailed knowledge of how the digital technology in a nuclear power plant works, suggesting a bottom-up approach.\nEffective security requires both high-level strategy and a granular defence. A purely top-down functional analysis will ignore detailed vulnerabilities, while a strictly bottom-up asset-by-asset analysis without understanding their functional contribution and significance will lead to a disproportionate and flawed defensive architecture. Neither will deliver a graded approach on their own, as called for in IAEA guidance 1. Therefore, whether designers are starting with a blank sheet of paper and a requirement to design a nuclear power plant or working in an operational plant, with computer-based control systems that need upgrading, it is necessary to analyse both the higher-level functional design and the lower-level system design. The need for multiple levels of risk management is reflected in IAEA guidance and in some international standards but there is a lack of consistency and consensus about how this might work in practice.\nFurther, computer security requirements need to be considered early in the design process, alongside those for safety, physical security and safeguards in order to achieve coherence and complementarity in the manner in which they are delivered, and achieve security-by-design.\nThis paper describes the relationship between the two levels of risk management and how they collectively fit into the mainstream engineering design activities of a nuclear power plant, with its multiple opportunities to reduce the consequences and risks of malicious action. This also allows for non-security risks to be managed with the same process. It suggests a closer working relationship between all the disciplines.\n2. Current Computer Security Guidance IAEA guidance in NSS 17-T (Rev 1) 2 divides the risk-based approach into Facility Computer Security Risk Management (FCSRM), focused on functions, and System Computer Security Risk Management (SCSRM), focused on the implementation of those functions using computer-based systems. In Figure 1 2, the system level is shown embedded within the functional level and there is evidence of the iterative nature between the different stages. The Computer Security Programme (CSP) and the Defensive Computer Security Architecture (DCSA) are two of the enduring artefacts that provide continuity between the different stages.\nFigure 1 – IAEA NSS 17-T (Rev 1) Figure 6, Overview of the computer security risk management process 2\nIAEA guidance 1 2 recommends that the graded approach defined at the higher functional level should be based on the consequences of the adverse outcome. This involves identifying and seeking to reduce the inherent risk of the project or plant design through the establishment of barriers at an architectural level. At the system level, the defender considers the combination of the threat actor’s capability, motivation and intent to cause the adverse outcome with an understanding of the vulnerabilities in the target.\nIt is worth noting the operator’s perspective on the management of risk will have a much wider scope of adverse outcomes than the protection of nuclear security. For example, the operator must also manage risks to the provision of essential critical infrastructure services and business risks of profitability.\nAn important internationally-recognised pan-industry standard for the computer security / cybersecurity of Industrial Control Systems, IEC 62443-3-2 3, also describes a two-level approach, see Figure 2. The language in IEC 62443-3-2 differs from IAEA guidance in that there is no mention of functions in Figure 2 but the initial cyber security risk assessment (ZCR 2 in Figure 2) based on severity of (functional) consequences leads to the partitioning into security zones. This aligns well with the output of FCSRM (i.e. the functional level) in the IAEA guidance. The detailed risk assessment (ZCR 5 in Figure 2) then seeks to reduce the residual risk for each zone to an acceptable level. This equates to SCSRM in the IAEA approach (i.e. the system level) though IEC 62443-3-2 here refers to zones that contain systems. There are other important differences in the treatment of likelihood of a successful attack when determining what strength of security measures are proportionate, and the resulting nature of the graded approach. The differences reinforce the point that there isn’t yet a consensus of guidance, but the similarity in the need for multiple levels of management of risk through a graded approach is nevertheless evident.\nFigure 2 – IEC 62443-3-2, Flow diagram for Security Risk Assessment for Design 3\nIt is worth noting that the outputs of Process Hazards Analysis (PHA) are an input to the initial risk assessment shown in Figure 2. Similarly, the Facility Safety Report appears in Figure 1 from the IAEA. This illustrates how safety-related work informs the security risk assessment, to ensure that the output of computer security risk management supports the needs of safety. This paper argues that the relationship between the two disciplines should be close.\n3. The Argument For A Single, Coherent Design Activity It has now widely quoted that for a computer-based system “If it’s not secure, it’s not safe.” 4, a position supported by this paper. This means that the safety case of a system, such as the control system for a nuclear reactor, cannot be deemed valid without adequate assurance that the control system is protected from malicious action. This paper asserts that analysis of how malicious action may undermine safety must be part of the design activity. Therefore, security should be designed to support safety and both should also be designed in a coherent and mutually-reinforcing manner.\nThis need for complementarity also applies to physical security (e.g. tampering with sensors that have a role in safety), personnel security (e.g. the insider) and computer security (e.g. interfering with digital technology).\nComputer security relies on adequate, complementary physical security and personnel security measures. For example, if an adversary can gain unconstrained and undetected access to the computer hardware or networks, a wide range of possible attacks become possible. Additionally, physical security and personnel security rely heavily on computer-based systems. For example, digital surveillance cameras connected to a network can be spoofed to mislead the Central Alarm Station staff, and delay physical security response, if computer security is inadequate. Identity and Access Management relies on the security of the information to underpin the control of personnel access for many purposes. All forms of security have a relationship with information security because trusting the confidentiality, integrity and availability of information is both a necessary foundation for and outcome of the other forms of security. This paper argues, therefore, that the means to deliver the different forms of security should therefore be designed in a coherent and mutually-reinforcing manner.\nAs the resilience of energy generation becomes a prominent national security issue and must be considered alongside traditional nuclear security, this argument for holistic design process extends still further, into the mainstream operational design activities.\nCost-effective construction and operation of nuclear systems also demands a coherent, holistic design that combines security requirements with other requirements as part of the options analysis. Consider, for example, the incentives on designers to use Wi-Fi in advanced reactor designs, to reduce the cost of wiring. The total savings should be offset as part of the initial design analysis by the cost of protecting the Wi-Fi from malicious action, to provide designers with an informed choice.\nWhat is being described in this paper is a traditional engineering design process that considers the different functional, e.g. energy generation, and non-functional, e.g. safety and security, requirements together. This is not a new concept to systems engineers but is not universally recognised by security engineers, who are often taught to see security activities through their own largely independent security lifecycle 2 3. However, this paper is not unique its message that “… security … must be fundamental to systems engineering, not just a specialty discipline. Security concepts must be fundamental to (an) engineering education, and security proficiency must be fundamental in development teams.” 5 6\nFigure 3 – Where security risk is primarily managed in a simplified engineering lifecycle model\n4. The Engineering Lifecycle Figure 3 is an interpretation of a classic engineering lifecycle, often described as a ‘V Diagram’, that has been amended for this paper to emphasise the activities of computer security risk management in that lifecycle. Figure 3 was inspired by a diagram in nuclear safety guidance 7, and derived from a more complex diagram at Annex 1. The following subsections step through Figure 3 to describe in more detail how computer security risk management can engage in the engineering lifecycle. This can represent an entire plant or a small project.\n4.1. Project Definition Initially, in the engineering design process, security is very much a reaction to the conceptual requirements – if you want to use nuclear material, you will need some protections. The high-level, functional design can only be practically achieved at a high level of abstraction, before refining requirements with increasing levels of detail in the design and implementation, which will likely later identify the need for and use of computer-based systems.\nSecurity involvement should be focussed on reducing or eliminating the potential consequences of malicious action, such as by reducing the inventory of nuclear material. Because these design factors are determined by the initial concept and then reflected in the functional specification of the plant (or project), early security involvement is critical. Furthermore, the manner in which security will support safety and other organisational objectives and how the different aspects of security will work together need establishing.\nBy failing to address security at this stage, there are some obvious consequences: the organisation misses cost-effective opportunities to the possible consequences of malicious action and thus reduce inherent risk; and because the analysis of risk starts too late, it loses its relationship to the top-level requirements for the plant/project. Ultimately, this delay prevents security from integrating coherently with other disciplines.\n4.2. Functional Design During the functional design, the represented design teams are making choices about the plant and its control systems at a high level of abstraction. At this point, the requirements describe a set of functions and may still be entirely agnostic of the type of technology that will be used, though some constraints may already have been introduced to reduce inherent risk. Once the combined functional design has been completed, a high-level block-diagram design will be defined, with candidate systems nominated to deliver the functional requirements.\nWithin this phase there should be further opportunities to reduce the inherent risk, such as by reducing the quantity of sensitive information that will be exposed, by design. This focus on inherent risk and then residual and is reflected in the US NRC pre-decisional publication on Tiered Cybersecurity Analysis 8. At this point, the designers should be developing scenarios on how adversaries might cause adverse security outcomes, developing a big picture view of major consequences and identifying barriers that further reduce the inherent risk. The designers don’t yet know why a barrier might fail, just that it should exist. Failing to reduce the risk at this point means there will be a higher level of inherent risk to be managed later with a greatly reduced control set and, again, there may be a loss of relationship in the risk analysis to the top-level requirements and the missed opportunity to achieve coherence with other disciplines, to resolve contradictions and trade-offs9.\n4.3. System Design And Iteration Design activities then continue with requirements derived, disaggregated and assigned to be delivered by individual systems. The system level addresses the design and implementation of functional requirements and should seek to reduce the risk to those functions to an acceptable level, through the identification of requirements for security measures. Note that some of these security measures will require the addition of security devices, such as firewalls, but many will place requirements on the way the control systems are designed, built and operated, such as software assurance and supply chain provenance, requiring close engagement with their designers.\nInitially, there may errors in design assumptions, conflicting requirements, misplaced trust and other latent vulnerabilities introduced through imperfect specifications 10. The more complex the combination of systems, the more likely there will be unpredictable emergent properties. Also, the system level design may identify better ways to assign functions to systems. The system and function design activities therefore need to be iterative.\nIn the IAEA guidance, the Defensive Computer Security Architecture is a central artefact in the design activities for computer security. It is created at a high level of abstraction during functional design and becomes more detailed in the system level 2. The DCSA provides designers with a common view of the design, its requirements and constraints. Some interpretations of the DCSA describe a network diagram (see Figure 2 of NSS 17-T 2). Other industries have identified Model Based Systems Engineering (MBSE) as providing this common design view, with a set of models or views that are gradually elaborated through iterative design activities 10.\nMost computer security vulnerabilities will only be identified when candidate technologies and candidate control system designs are scrutinised in detail. Consider, for example, a very high consequence safety function has requirements for security, to provide resilience and reliability in the face of malicious action. At this point in the design activity, candidate controls may be selected from catalogues of security measures. Many computer security standards offer such lists and, in some regulatory environments, there may be a set of minimum requirements or a suite of minimum controls. In the risk-based approach described in IAEA guidance and in the IEC 62443 family of standards, the designer must now assess which security measures will defend against possible adversary action to exploit known vulnerabilities. Crucially, the designer may find those requirements so stringent or so expensive that they cannot easily be met by systems using networked programmable digital technology, especially if its supply chain provenance cannot be adequately proven. This is a practical illustration that the relationship between the high-level functional design and lower-level system design must allow for iteration.\n4.4. Implement Components, Systems, Functions The step to implementation may in many projects be via a contract interface, with a detailed system requirement being implemented as a separate activity by another organisation. In general, it can reduce project risk if managers can disaggregate project activities into separate distinct tasks with well-defined scopes. Most standards reflect this natural desire to operate in this way. However, this can also often mean that the physical security, computer security design and safety design activities take place independently.\nRisks can be introduced at this point due to weaknesses in requirements, in component assurance, implementation, or interface coordination, but the right-hand side of the V Diagram shown in Figure 3 relies upon conventional engineering practice to perform design acceptance, which should maintain the residual risk profile against the original design intent. Component assurance includes adequate testing and supply chain provenance to form a trusted foundation to maintain the accepted residual risk profile against the original design intent.\nFigure 4 – IAEA NSS 17-T (Rev 1) Figure 7 showing verification and validation in Computer Security Risk Management on the Engineering V Diagram 4\nAs components become systems and they in turn are commissioned to implement functions, the functional acceptance criteria and commissioning should include validation against the original attack scenarios, as a further check against errors that may occur in the entire design disaggregation down the left-hand side and the implementation up the right-hand side. Figure 4 is also from NSS 17-T (Rev 1) 2, illustrating how validation checks the various levels of implementation against the original intent. It is also significant that this figure uses a very similar form of Engineering V Diagram, reflecting the 2 levels of risk assessment in NSS 17-T (Rev 1).\n4.5. Operations Returning to Figure 3, once the system has become operational, the defender has to identify new vulnerabilities in computer-based systems before the adversary. This requires understanding the plant-level consequences in order to prioritise remediations, for example applying patches, thinking like an adversary only better and quicker, to manage the risk throughout the plant/project operating lifetime. The defender must know which computer-based systems support which high-level functions, and which system failures lead to adverse physical outcomes, to be able to act faster than the adversary in order to close new attack paths before the adversary can exploit them. The design of computer-based systems, and their associated commercial contracts, must acknowledge this whole-life management of risk by staff, with the necessary deep knowledge of the digital technology. This places additional demands on traditional maintenance and illustrates the need for close working between security and engineering teams.\n5. Anticipating Some Questions 5.1. Can Computer Security Risk Ever Be Managed In A Single Step Process? Yes, but only if a system is so simple that its role in delivering high level functions can be determined in the same activity as understanding the detail of vulnerabilities that the adversary can exploit. For a trivially simple industrial activity, this may be the case. For something as complex as a nuclear power plant, this is highly unlikely to be practical and the multidisciplinary reduction in inherent risk followed by prudent management of residual risk as described earlier will deliver a more effective solution.\n5.2. Can The Process Start With A List Of Computer-Based Assets And Work From There? Yes, a project may have as its focus an existing computer-based system, e.g. to perform a limited upgrade on its constituent assets. In this case, the functional significance of the computer-based system will already be very well documented. If the project is making a greater change to the functionality, e.g. changing system boundaries and relationships, there may need to be a reassessment of the functional analysis. The crucial point is that the risk assessment at the level of the computer-based system can only be performed with knowledge of its functional context, so at some point there needs to be an understanding of the high-level functional design 11.\nHowever, if there is too much emphasis on analysis at a system level and a failure to understand the functional level, defences will not be truly proportionate to the exposure to risk and there is an increased chance of a flawed defensive architecture, as Young and Leveson observe 10. There is also a greater chance of rework. For example, to apply security zones to an existing Instrumentation and Control (I\u0026C) design may require extensive changes to data-flows and trust relationships, probably requiring expensive rework. This also applies to the inclusion of safeguards requirements as part of the design activity, to avoid for example the need to make holes and run wires in unhelpful places to fit unanticipated sensors.\n5.3. Why Doesn’t Computer Security For It Follow This Approach? Computer security developed as a reaction to the use of computer-based systems to process information, referred to as information technology (IT), and computer security focused almost entirely on protecting the confidentiality of information in proportion to its perceived value. The assessment of computer security risk generally started with an existing landscape of sensitive information that needed identifying, assessing and protecting. Operational Technology (OT, may also be known as SCADA or Instrumentation and Control), in contrast with IT, addresses risks to cyber-physical systems, often with risks to assets, life, and to the environment, and consequently has a close relationship with safety.\n6. Conclusion To protect nuclear facilities in the current threat environment requirements for computer security for nuclear security must be integrated with those for safety and physical protection, with those responsible for the design and operation of the plant, under a systems engineering umbrella.\nThis paper argues that managing the risks arising from computer-based systems should include the reduction of exposure to malicious action in the concept phase and the subsequent reduction of inherent risk in the functional design. A closer interdisciplinary relationship may be needed in some projects in the early stages of design to achieve this and thereby achieve security-by-design, and to avoid security being additive. This paper describes how this can be achieved by including computer security activities at appropriate points in the engineering lifecycle, from the earliest opportunity.\nAs computer-based systems are used ever more extensively, and the complexity of their designs increases, it is no longer viable to design computer security to defend the individual assets in an additive manner, independent of the overall plant design 10. Even were that not the case, additive security will more likely lead to expensive rework, and missed opportunities for cost-savings for design controls that will be more effective than the additive computer security measures.\nThis paper also argues that some existing standards and guidance can be easily mapped onto this lifecycle, but not all standards are yet describing the whole picture. The content of this paper is written to be consistent with current IAEA publications in the NSS series and may help fill in some gaps.\nAnnex 1 – A more detailed V Model for computer security References International Atomic Energy Agency (IAEA) Nuclear Security Series No. 42-G, “Computer Security for Nuclear Security,” Vienna, Austria, July 2021. https://www.iaea.org/publications ↩︎ ↩︎\nInternational Atomic Energy Agency (IAEA) Nuclear Security Series No. 17-T (Rev. 1), “Computer Security Techniques for Nuclear Facilities,” Vienna, Austria, September 2021. https://www.iaea.org/publications ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎\nInternational Electrotechnical Commission, Geneva, IEC 62443-3-2 https://webstore.iec.ch/ ↩︎ ↩︎ ↩︎\nBLOOMFIELD, PROF, R, STROUD R., Sep 2013, Security-Informed Safety “If it’s not secure, it’s not safe”, MarcOlivier Killijian. Safecomp 2013 FastAbstract, Toulouse, France. pp.NC, 2013. ↩︎ ↩︎\nSecurity in the Future of Systems Engineering (FuSE), a Roadmap of Foundational Concepts, INCOSE International Symposium, July 2021. ↩︎\nUnited States National Institute of Science and Technology, November 2022, Engineering Trustworthy Secure Systems, NIST Special Publication NIST SP 800-160v1r1. https://doi.org/10.6028/NIST.SP.800-160v1r1 ↩︎\nOffice of Nuclear Regulation, May 2025, ONR Technical Assessment Guide, Categorisation of safety functions and classification of structures, systems and components (SSCs), NS-TAST-GD-094. https://www.onr.org.uk/publications/regulatory-guidance/ ↩︎\nUnited States Nuclear Regulatory Commission, pre-decisional of 13 October 2023, proposed new regulatory guide under NRC 10 CFR Part 53, DG-5075, https://www.nrc.gov/docs/ML2328/ML23286A278.pdf ↩︎\nYOUNG, W.E., LEVESON, PROF N., IT, Cambridge, MA, December 2013, Systems thinking for safety and security, ACSAC ‘13 Proceedings of the 29th Annual Computer Security Applications Conference. ↩︎\nJAPS, ANACKER, DUMITRESCU, 31st CIRP Design Conference, 2021, SAVE: Security \u0026 safety by model-based systems engineering on the example of automotive. Available online at www.sciencedirect.com  ↩︎ ↩︎ ↩︎ ↩︎\nIdaho National Laboratory, Cyber Informed Engineering Implementation Guide, August 2023, INL/RPT-23-74072, https://inldigitallibrary.inl.gov/sites/sti/sti/Sort_67122.pdf ↩︎\n","date_published":"2026-05-28T18:00:00+03:00","id":"https://blog.mitcdh.au/posts/where-to-start-system-or-function/","image":"https://blog.mitcdh.au/images/where-to-start-system-or-function.webp","summary":"How the V-model Clarifies Effective Computer Security","tags":["Writing","Nuclear","Technology","Security","Safety"],"title":"Where to Start — the System or the Function?","url":"https://blog.mitcdh.au/posts/where-to-start-system-or-function/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eI didn\u0026rsquo;t expect to like this as much as I did. Underneath the sci-fi spectacle, the survival of humanity actually hinges on a brilliant, quiet critique of English as the universal lingua franca along with a powerful push for genuine inter-cultural exchange.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://letterboxd.com/mitcdh/film/project-hail-mary/\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"I didn’t expect to like this as much as I did. Underneath the sci-fi spectacle, the survival of humanity actually hinges on a brilliant, quiet critique of English as the universal lingua franca along with a powerful push for genuine inter-cultural exchange.\nView this review on Letterboxd\n","date_published":"2026-04-08T05:28:17Z","id":"https://blog.mitcdh.au/posts/project-hail-mary-2026-04-08-film-review/","image":"https://blog.mitcdh.au/images/project-hail-mary-2026-04-08-film-review.jpg","summary":"Rating: 4.0/5","tags":["Review","Film"],"title":"Project Hail Mary (2026)","url":"https://blog.mitcdh.au/posts/project-hail-mary-2026-04-08-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eHalfway through the book I preordered the two sequels. By the end I was hollowed out, staring at the ceiling, trying to process what I just read. The last time I felt like this was Deadhouse Gates. A brilliant, devastating debut. Read the trigger warnings, and then read the book.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://hardcover.app/books/dreams-of-the-dying\"\u003eView this review on Hardcover\u003c/a\u003e\u003c/p\u003e\n","content_text":"Halfway through the book I preordered the two sequels. By the end I was hollowed out, staring at the ceiling, trying to process what I just read. The last time I felt like this was Deadhouse Gates. A brilliant, devastating debut. Read the trigger warnings, and then read the book.\nView this review on Hardcover\n","date_published":"2026-03-02T00:00:00Z","id":"https://blog.mitcdh.au/posts/dreams-of-the-dying-2026-03-02-book-review/","image":"https://blog.mitcdh.au/images/dreams-of-the-dying-2026-03-02-book-review.jpg","summary":"Rating: 4.5/5","tags":["Review","Book"],"title":"Dreams of the Dying","url":"https://blog.mitcdh.au/posts/dreams-of-the-dying-2026-03-02-book-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2026-02-01T16:10:40Z","id":"https://blog.mitcdh.au/posts/taronga-zoo-sydney-australia/","image":"https://blog.mitcdh.au/images/taronga-zoo-sydney-australia.jpg","summary":"There's nothing quite like the unique mix of native Australian wildlife and exotic animals set against the spectacular backdrop of the Sydney Opera House and the Harbour Bridge.","tags":["Album"],"title":"Taronga Zoo Sydney, Australia","url":"https://blog.mitcdh.au/posts/taronga-zoo-sydney-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eFor two movies, Avatar sold us the myth that Pandora was a utopia where nature always equals goodness. This film burns that idea to the ground becoming a genuine tragedy about the loss of innocence. It’s the darker, dirtier turn that proves Pandora isn\u0026rsquo;t a fairytale, but a real place capable of both the same destruction as Earth and finding the desperate necessity of coming together to prevent it.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://letterboxd.com/mitcdh/film/avatar-fire-and-ash/\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"For two movies, Avatar sold us the myth that Pandora was a utopia where nature always equals goodness. This film burns that idea to the ground becoming a genuine tragedy about the loss of innocence. It’s the darker, dirtier turn that proves Pandora isn’t a fairytale, but a real place capable of both the same destruction as Earth and finding the desperate necessity of coming together to prevent it.\nView this review on Letterboxd\n","date_published":"2026-01-31T11:53:47Z","id":"https://blog.mitcdh.au/posts/avatar-fire-and-ash-2026-01-31-film-review/","image":"https://blog.mitcdh.au/images/avatar-fire-and-ash-2026-01-31-film-review.jpg","summary":"Rating: 4.0/5","tags":["Review","Film"],"title":"Avatar: Fire and Ash (2025)","url":"https://blog.mitcdh.au/posts/avatar-fire-and-ash-2026-01-31-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eNeo-Tokyo isn\u0026rsquo;t just a backdrop; it is a character representing a society in late-stage decay. Akira captures the chaotic energy of student protests, religious zealotry, and a government that has lost its legitimacy. Beneath the stunning animation and the tragic friendship of Kaneda and Tetsuo lies a deeper warning: what happens to humanity when technology outpaces our ability to govern it.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://letterboxd.com/mitcdh/film/akira/\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"Neo-Tokyo isn’t just a backdrop; it is a character representing a society in late-stage decay. Akira captures the chaotic energy of student protests, religious zealotry, and a government that has lost its legitimacy. Beneath the stunning animation and the tragic friendship of Kaneda and Tetsuo lies a deeper warning: what happens to humanity when technology outpaces our ability to govern it.\nView this review on Letterboxd\n","date_published":"2026-01-30T11:49:07Z","id":"https://blog.mitcdh.au/posts/akira-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/akira-2026-01-30-film-review.jpg","summary":"Rating: 5.0/5","tags":["Review","Film"],"title":"Akira (1988)","url":"https://blog.mitcdh.au/posts/akira-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003ePeople talk about the first ten minutes of this movie like it’s a sad short film. It isn’t. It’s a documentary on what it feels like to be left behind. Watching Carl drag that house across the world to keep a promise\u0026hellip; watching him carry memory forward while shouldering the burden of loss. It’s a comforting reminder that time is just an illusion, you have to focus on the here and now, but equally nothing will take away from you what you had back then.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://boxd.it/cTU7qN\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"People talk about the first ten minutes of this movie like it’s a sad short film. It isn’t. It’s a documentary on what it feels like to be left behind. Watching Carl drag that house across the world to keep a promise… watching him carry memory forward while shouldering the burden of loss. It’s a comforting reminder that time is just an illusion, you have to focus on the here and now, but equally nothing will take away from you what you had back then.\nView this review on Letterboxd\n","date_published":"2026-01-30T00:00:00Z","id":"https://blog.mitcdh.au/posts/up-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/up-2026-01-30-film-review.jpg","summary":"Rating: 5/5","tags":["Review","Film"],"title":"Up (2009)","url":"https://blog.mitcdh.au/posts/up-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eChristopher Nolan’s Gotham isn’t just a city, it’s a complex society pushed to its breaking point. While most blockbusters deal in simple good vs. evil, this is a heavy-duty deconstruction of the fragility of social architectures that we have come to take for granted.\u003c/p\u003e\n\u003cp\u003eThe Joker is the ultimate disruptor. He doesn\u0026rsquo;t just want to \u0026lsquo;watch the world burn\u0026rsquo;, he wants to prove that our collective sense of order is a brittle model that is only loosely held together. He identifies the systems of a corrupt society and short-circuits them, forcing Batman to confront the agonising limits of stewardship in an era of insecurity.\u003c/p\u003e\n\u003cp\u003eThe tragedy of Harvey Dent is the film\u0026rsquo;s most visceral lesson in systemic failure: what happens when a person built on humanist logic, a belief in \u0026lsquo;good\u0026rsquo;, is shattered by a world that is inherently chaotic.\u003c/p\u003e\n\u003cp\u003eIt’s a haunting look at the right kind of wrong and the heavy cost of trying to save a world that is constantly becoming something else. A masterpiece of tension, agency (inc. how quickly it can be lost), and the terrifying realisation that we may all be just one bad day away from the world Nolan has created.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://boxd.it/cTU70F\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"Christopher Nolan’s Gotham isn’t just a city, it’s a complex society pushed to its breaking point. While most blockbusters deal in simple good vs. evil, this is a heavy-duty deconstruction of the fragility of social architectures that we have come to take for granted.\nThe Joker is the ultimate disruptor. He doesn’t just want to ‘watch the world burn’, he wants to prove that our collective sense of order is a brittle model that is only loosely held together. He identifies the systems of a corrupt society and short-circuits them, forcing Batman to confront the agonising limits of stewardship in an era of insecurity.\nThe tragedy of Harvey Dent is the film’s most visceral lesson in systemic failure: what happens when a person built on humanist logic, a belief in ‘good’, is shattered by a world that is inherently chaotic.\nIt’s a haunting look at the right kind of wrong and the heavy cost of trying to save a world that is constantly becoming something else. A masterpiece of tension, agency (inc. how quickly it can be lost), and the terrifying realisation that we may all be just one bad day away from the world Nolan has created.\nView this review on Letterboxd\n","date_published":"2026-01-30T00:00:00Z","id":"https://blog.mitcdh.au/posts/the-dark-knight-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/the-dark-knight-2026-01-30-film-review.jpg","summary":"Rating: 5/5","tags":["Review","Film"],"title":"The Dark Knight (2008)","url":"https://blog.mitcdh.au/posts/the-dark-knight-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eA terrifying look at what happens when you spend so much time trying to build your life that you forget to actually live it.\u003c/p\u003e\n\u003cp\u003eWatching Caden build his massive, impossible set is heartbreaking because it shows the flawed belief that if we just analyse things enough, or build a perfect enough model, we can control the outcome. However, life is beautiful precisely because it defies scripting. We watch Caden miss this again and again.\u003c/p\u003e\n\u003cp\u003eIt’s dense and difficult, and it deals heavily with decay and time slipping away. It’s not an easy watch, but it feels honest about the fact that we\u0026rsquo;re all just improvising until the lights go out.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://boxd.it/cT6dn1\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"A terrifying look at what happens when you spend so much time trying to build your life that you forget to actually live it.\nWatching Caden build his massive, impossible set is heartbreaking because it shows the flawed belief that if we just analyse things enough, or build a perfect enough model, we can control the outcome. However, life is beautiful precisely because it defies scripting. We watch Caden miss this again and again.\nIt’s dense and difficult, and it deals heavily with decay and time slipping away. It’s not an easy watch, but it feels honest about the fact that we’re all just improvising until the lights go out.\nView this review on Letterboxd\n","date_published":"2026-01-30T00:00:00Z","id":"https://blog.mitcdh.au/posts/synecdoche-new-york-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/synecdoche-new-york-2026-01-30-film-review.jpg","summary":"Rating: 5/5","tags":["Review","Film"],"title":"Synecdoche, New York (2008)","url":"https://blog.mitcdh.au/posts/synecdoche-new-york-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eIt’s a gothic industrial rock opera about debt, legacy, and organ harvesting committing to that premise 100%. It’s messy, campy, and completely unashamed of itself.\u003c/p\u003e\n\u003cp\u003eAmongst this it manages to be a serious critique of control, creating a parallel between corporate paternalism and parenting: both claim to know what\u0026rsquo;s best for you while stripping away your autonomy. A bloody, chaotic reminder that we often have to break our parent\u0026rsquo;s rules to survive their mistakes.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://boxd.it/cT6QW5\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"It’s a gothic industrial rock opera about debt, legacy, and organ harvesting committing to that premise 100%. It’s messy, campy, and completely unashamed of itself.\nAmongst this it manages to be a serious critique of control, creating a parallel between corporate paternalism and parenting: both claim to know what’s best for you while stripping away your autonomy. A bloody, chaotic reminder that we often have to break our parent’s rules to survive their mistakes.\nView this review on Letterboxd\n","date_published":"2026-01-30T00:00:00Z","id":"https://blog.mitcdh.au/posts/repo-the-genetic-opera-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/repo-the-genetic-opera-2026-01-30-film-review.jpg","summary":"Rating: 4/5","tags":["Review","Film"],"title":"Repo! The Genetic Opera (2008)","url":"https://blog.mitcdh.au/posts/repo-the-genetic-opera-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eIf an adrenaline shot to the heart was a colour palette, it would look exactly like this. This isn\u0026rsquo;t just a chase, it\u0026rsquo;s an opera of rust and fire where the engines scream out louder than the plot: \u0026lsquo;Max. My name is Max. That’s my name\u0026rsquo;. For what it sets out to be, and the world we live in now, the new Max is perfect.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://boxd.it/cTU7At\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"If an adrenaline shot to the heart was a colour palette, it would look exactly like this. This isn’t just a chase, it’s an opera of rust and fire where the engines scream out louder than the plot: ‘Max. My name is Max. That’s my name’. For what it sets out to be, and the world we live in now, the new Max is perfect.\nView this review on Letterboxd\n","date_published":"2026-01-30T00:00:00Z","id":"https://blog.mitcdh.au/posts/mad-max-fury-road-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/mad-max-fury-road-2026-01-30-film-review.jpg","summary":"Rating: 5/5","tags":["Review","Film"],"title":"Mad Max: Fury Road (2015)","url":"https://blog.mitcdh.au/posts/mad-max-fury-road-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eIf you could visualise a decision tree exploding, this is what it would look like. It \u003ci\u003efeels\u003c/i\u003e like chaos, but really it’s a study in radical connectivity.\u003c/p\u003e\n\u003cp\u003eThe bagel is the ultimate logical conclusion of nihilism: if nothing matters, the system collapses.\u003c/p\u003e\n\u003cp\u003eWaymond’s counter-strategy isn\u0026rsquo;t to fight the entropy, but to inject a new data point, kindness, into the system until it stabilises. Precisely because nothing matters, the only thing that holds weight is how we treat each other.\u003c/p\u003e\n\u003cp\u003eWe could all stand to learn from that.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://boxd.it/cT6tFF\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"If you could visualise a decision tree exploding, this is what it would look like. It feels like chaos, but really it’s a study in radical connectivity.\nThe bagel is the ultimate logical conclusion of nihilism: if nothing matters, the system collapses.\nWaymond’s counter-strategy isn’t to fight the entropy, but to inject a new data point, kindness, into the system until it stabilises. Precisely because nothing matters, the only thing that holds weight is how we treat each other.\nWe could all stand to learn from that.\nView this review on Letterboxd\n","date_published":"2026-01-30T00:00:00Z","id":"https://blog.mitcdh.au/posts/everything-everywhere-all-at-once-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/everything-everywhere-all-at-once-2026-01-30-film-review.jpg","summary":"Rating: 5/5","tags":["Review","Film"],"title":"Everything Everywhere All at Once (2022)","url":"https://blog.mitcdh.au/posts/everything-everywhere-all-at-once-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eChildren of Men offers a masterclass in show, don\u0026rsquo;t tell world-building, depicting a society in the advanced stages of a long-burn collapse after it has lost its future. Uniquely, rather than relying on exposition, the film forces you to observe the degradation of infrastructure and the normalisation of deviance in the background: the cages on the streets, the militarised borders, and the quiet despair of a population with no long-termism left. It delivers a haunting exploration of how quickly the social contract dissolves when the dream of a better future is lost.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://boxd.it/cTU7nf\"\u003eView this review on Letterboxd\u003c/a\u003e\u003c/p\u003e\n","content_text":"Children of Men offers a masterclass in show, don’t tell world-building, depicting a society in the advanced stages of a long-burn collapse after it has lost its future. Uniquely, rather than relying on exposition, the film forces you to observe the degradation of infrastructure and the normalisation of deviance in the background: the cages on the streets, the militarised borders, and the quiet despair of a population with no long-termism left. It delivers a haunting exploration of how quickly the social contract dissolves when the dream of a better future is lost.\nView this review on Letterboxd\n","date_published":"2026-01-30T00:00:00Z","id":"https://blog.mitcdh.au/posts/children-of-men-2026-01-30-film-review/","image":"https://blog.mitcdh.au/images/children-of-men-2026-01-30-film-review.jpg","summary":"Rating: 5/5","tags":["Review","Film"],"title":"Children of Men (2006)","url":"https://blog.mitcdh.au/posts/children-of-men-2026-01-30-film-review/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-24T20:11:04Z","id":"https://blog.mitcdh.au/posts/an-end-in-the-barossa-valley-australia/","image":"https://blog.mitcdh.au/images/an-end-in-the-barossa-valley-australia.jpg","summary":"We traded the wind and the broken jetties for the stillness of the valley. Ending the journey here, among the ancient vines and stone cottages, feels like a soft landing after the rugged coast. The air is warmer, the light is golden, and the only crashing waves are those stirred willingly in a glass of Shiraz.","tags":["Album"],"title":"An End in the Barossa Valley, Australia","url":"https://blog.mitcdh.au/posts/an-end-in-the-barossa-valley-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-23T14:36:28Z","id":"https://blog.mitcdh.au/posts/stormy-fleurieu-peninsula-australia/","image":"https://blog.mitcdh.au/images/stormy-fleurieu-peninsula-australia.jpg","summary":"The wind hits different here on the Fleurieu. It whips across the gulf, bending the scrub and battering the coastline. The last time I stood on this coast 30 years ago, these jetties still reached out into the water. Returning now, they have been reclaimed by the sea, reduced to skeletal pylons by the relentless waves.","tags":["Album"],"title":"Stormy Fleurieu Peninsula, Australia","url":"https://blog.mitcdh.au/posts/stormy-fleurieu-peninsula-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-20T18:45:58Z","id":"https://blog.mitcdh.au/posts/mouth-of-the-murray-australia/","image":"https://blog.mitcdh.au/images/mouth-of-the-murray-australia.jpg","summary":"The silence of the Coorong and the flow of the Murray River both die here. At this strange, significant convergence, the Southern Ocean at the end of the world finally swallows the fresh water that brings bounty to the interior and the endless shore of the Coorong.","tags":["Album"],"title":"Mouth of the Murray, Australia","url":"https://blog.mitcdh.au/posts/mouth-of-the-murray-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-20T18:22:07Z","id":"https://blog.mitcdh.au/posts/inland-through-langhorne-creek-australia/","image":"https://blog.mitcdh.au/images/inland-through-langhorne-creek-australia.jpg","summary":"Turning the wheel away from the coast, we headed inland. The salt spray was replaced by the dusty greens of Langhorne Creek, a landscape of river red gums amongst the vineyards. But this was just a quiet pause before the final push towards the end of the Coorong.","tags":["Album"],"title":"Inland Through Langhorne Creek, Australia","url":"https://blog.mitcdh.au/posts/inland-through-langhorne-creek-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-19T20:04:15Z","id":"https://blog.mitcdh.au/posts/endless-coorong-australia/","image":"https://blog.mitcdh.au/images/endless-coorong-australia.jpg","summary":"Leaving the vertical drama of the cliffs behind, the world suddenly flattened out. There is raw isolation here. The Coorong is a stretch of South Australia that refuses to be tamed. Nearly 200km of scrub and saltwater lagoons separating the highway from the ocean, creating a landscape that feels infinite and untouched. It’s just the wind, the birds, and the endless road ahead.","tags":["Album"],"title":"Endless Coorong, Australia","url":"https://blog.mitcdh.au/posts/endless-coorong-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-18T21:14:31Z","id":"https://blog.mitcdh.au/posts/broken-coast-at-the-end-of-the-world-australia/","image":"https://blog.mitcdh.au/images/broken-coast-at-the-end-of-the-world-australia.jpg","summary":"We arrived at the limestone edge where the continent crumbles into the Southern Ocean. Standing before the (less-than) 12 Apostles, the separation between land and ocean feels absolute. A hard-boiled wonderland of jagged cliffs meeting quiet solitude at the end of the world among lost shadows and relentless tides.","tags":["Album"],"title":"Broken Coast at the End of the World, Australia","url":"https://blog.mitcdh.au/posts/broken-coast-at-the-end-of-the-world-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-18T11:21:21Z","id":"https://blog.mitcdh.au/posts/sheltering-at-maits-rest-australia/","image":"https://blog.mitcdh.au/images/sheltering-at-maits-rest-australia.jpg","summary":"We needed a break from the sun, so we stopped at Maits Rest to escape the heat. It feels like a different world down here—quiet, green, and wonderfully cool. The path loops through some massive trees that have been here for centuries.","tags":["Album"],"title":"Sheltering at Maits Rest, Australia","url":"https://blog.mitcdh.au/posts/sheltering-at-maits-rest-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-17T19:23:47Z","id":"https://blog.mitcdh.au/posts/starting-the-way-at-apollo-bay-australia/","image":"https://blog.mitcdh.au/images/starting-the-way-at-apollo-bay-australia.jpg","summary":"Starting the drive along the Great Ocean Road, on our way to Adelaide. The winding cliffs and wildlife set the tone for a lovely ride, leading us to our first stop for the night at Apollo Bay.","tags":["Album"],"title":"Starting The Way at Apollo Bay, Australia","url":"https://blog.mitcdh.au/posts/starting-the-way-at-apollo-bay-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-17T10:38:00Z","id":"https://blog.mitcdh.au/posts/rounding-the-twist-to-aireys-inlet-australia/","image":"https://blog.mitcdh.au/images/rounding-the-twist-to-aireys-inlet-australia.jpg","summary":"You walk up to the lighthouse trying to act like a responsible adult. But, deep down, you are absolutely terrified that if you touch the wrong railing you’re going to be forced to finish the trip without your pants... Have you ever, ever felt like this?","tags":["Album"],"title":"Rounding the Twist to Aireys Inlet, Australia","url":"https://blog.mitcdh.au/posts/rounding-the-twist-to-aireys-inlet-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-12-14T03:04:30Z","id":"https://blog.mitcdh.au/posts/picnic-at-hanging-rock-australia/","image":"https://blog.mitcdh.au/images/picnic-at-hanging-rock-australia.jpg","summary":"Nothing could ever ruin a picnic at Hanging Rock, right?","tags":["Album"],"title":"Picnic at Hanging Rock, Australia","url":"https://blog.mitcdh.au/posts/picnic-at-hanging-rock-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-07-17T20:13:30Z","id":"https://blog.mitcdh.au/posts/last-time-on-the-boat-greece/","image":"https://blog.mitcdh.au/images/last-time-on-the-boat-greece.jpg","summary":"","tags":["Album"],"title":"Last Time on the Boat, Greece","url":"https://blog.mitcdh.au/posts/last-time-on-the-boat-greece/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-07-05T19:34:21Z","id":"https://blog.mitcdh.au/posts/abbey-of-melk-austria/","image":"https://blog.mitcdh.au/images/abbey-of-melk-austria.jpg","summary":"","tags":["Album"],"title":"Abbey of Melk, Austria","url":"https://blog.mitcdh.au/posts/abbey-of-melk-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-06-01T21:00:36Z","id":"https://blog.mitcdh.au/posts/hiking-the-south-coast-iceland/","image":"https://blog.mitcdh.au/images/hiking-the-south-coast-iceland.jpg","summary":"Hiking Iceland's surprisingly green South Coast and sympathising with poor Flóki, who clearly had the worst possible winter before dramatically naming this place.","tags":["Album"],"title":"Hiking the South Coast, Iceland","url":"https://blog.mitcdh.au/posts/hiking-the-south-coast-iceland/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-05-18T17:07:39Z","id":"https://blog.mitcdh.au/posts/visiting-london-united-kingdom/","image":"https://blog.mitcdh.au/images/visiting-london-united-kingdom.jpg","summary":"The fourth city, before the bats notice it's unattended.","tags":["Album"],"title":"Visiting London, United Kingdom","url":"https://blog.mitcdh.au/posts/visiting-london-united-kingdom/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-05-09T14:55:38Z","id":"https://blog.mitcdh.au/posts/adventures-on-the-reef/","image":"https://blog.mitcdh.au/images/adventures-on-the-reef.jpg","summary":"There are some places we are not made to be—entire worlds where we will only ever be visitors, dancing to unknown rhythms that will go on without us—Ciao fishies, until our paths cross again 🤿👋🐠🪸","tags":["Video"],"title":"Adventures on the Reef","url":"https://blog.mitcdh.au/posts/adventures-on-the-reef/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-05-09T14:55:18Z","id":"https://blog.mitcdh.au/posts/flying-to-a-coral-island/","image":"https://blog.mitcdh.au/images/flying-to-a-coral-island.jpg","summary":"From up high coral spawn drifts like dreams in pink and orange clouds painting the turquoise waters. Time to see what grows 🤿","tags":["Video"],"title":"Flying to a Coral Island","url":"https://blog.mitcdh.au/posts/flying-to-a-coral-island/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-04-18T16:29:02Z","id":"https://blog.mitcdh.au/posts/the-colours-of-portofino-italy/","image":"https://blog.mitcdh.au/images/the-colours-of-portofino-italy.jpg","summary":"Where azure waters embrace a harbor dotted with colorful boats and pastel cottages nestled against lush hillsides. Your only worries here are the prices and the queue for the bus!","tags":["Album"],"title":"The Colours of Portofino, Italy","url":"https://blog.mitcdh.au/posts/the-colours-of-portofino-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-04-15T14:30:13Z","id":"https://blog.mitcdh.au/posts/getting-vertical-in-bergamo-italy/","image":"https://blog.mitcdh.au/images/getting-vertical-in-bergamo-italy.jpg","summary":"Rising dramatically between the plains and the hills, Bergamo’s layered cityscape is defined by its striking verticality, where ancient streets and sweeping views are linked by steel wires pulling cars that rise into the clouds through lush gardens and ancient walls.","tags":["Album"],"title":"Getting Vertical in Bergamo, Italy","url":"https://blog.mitcdh.au/posts/getting-vertical-in-bergamo-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-04-09T20:35:52Z","id":"https://blog.mitcdh.au/posts/camera-click-at-wienerblick-austria/","image":"https://blog.mitcdh.au/images/camera-click-at-wienerblick-austria.jpg","summary":"Featuring the memories of a short stroll through Lainzer Tiergarten and Hermesvilla on the way to the Weinerblick photo spot.","tags":["Album"],"title":"Camera Click at Wienerblick, Austria","url":"https://blog.mitcdh.au/posts/camera-click-at-wienerblick-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-03-22T15:24:00Z","id":"https://blog.mitcdh.au/posts/kunst-on-the-streets-of-tokyo-japan/","image":"https://blog.mitcdh.au/images/kunst-on-the-streets-of-tokyo-japan.jpg","summary":"Wander through the streets of Tokyo and discover an urban landscape that blurs the line between city and art.","tags":["Album"],"title":"Kunst on the Streets of Tokyo, Japan","url":"https://blog.mitcdh.au/posts/kunst-on-the-streets-of-tokyo-japan/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-02-15T21:29:14Z","id":"https://blog.mitcdh.au/posts/a-grand-cabaret-for-the-iaea-in-vienna-austria/","image":"https://blog.mitcdh.au/images/a-grand-cabaret-for-the-iaea-in-vienna-austria.jpg","summary":"Where safeguards shimmer brighter than sequins.","tags":["Album"],"title":"A Grand Cabaret for the IAEA in Vienna, Austria","url":"https://blog.mitcdh.au/posts/a-grand-cabaret-for-the-iaea-in-vienna-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2025-02-09T13:46:38Z","id":"https://blog.mitcdh.au/posts/ice-skating-on-weissensee-austria/","image":"https://blog.mitcdh.au/images/ice-skating-on-weissensee-austria.jpg","summary":"A dance of boots and blades. Some more graceful than others.","tags":["Album"],"title":"Ice Skating on Weissensee, Austria","url":"https://blog.mitcdh.au/posts/ice-skating-on-weissensee-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-12-29T13:01:33Z","id":"https://blog.mitcdh.au/posts/visiting-spadbarn-in-helsinki-finland/","image":"https://blog.mitcdh.au/images/visiting-spadbarn-in-helsinki-finland.jpg","summary":"Barren branches pierce the mist like tiny ghostly fingers grasping at infinity. December's secrets whisper through Helsinki's grey veil to new life's warmth.","tags":["Album"],"title":"Visiting Spädbarn in Helsinki, Finland","url":"https://blog.mitcdh.au/posts/visiting-spadbarn-in-helsinki-finland/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-12-25T17:21:08Z","id":"https://blog.mitcdh.au/posts/fresh-christmas-by-the-sea-italy/","image":"https://blog.mitcdh.au/images/fresh-christmas-by-the-sea-italy.jpg","summary":"Liguria’s salty whispers – where the cliffs meet markets piled with fresh produce that reminds me of home.","tags":["Album"],"title":"Fresh Christmas by the Sea, Italy","url":"https://blog.mitcdh.au/posts/fresh-christmas-by-the-sea-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-11-13T11:50:27Z","id":"https://blog.mitcdh.au/posts/back-to-sydney-australia/","image":"https://blog.mitcdh.au/images/back-to-sydney-australia.jpg","summary":"Every return to Sydney's sparkling harbour reminds me that home isn't just about the iconic Opera House sails or coastal walks... but here's some pictures of those!","tags":["Album"],"title":"Back to Sydney, Australia","url":"https://blog.mitcdh.au/posts/back-to-sydney-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-11-08T10:51:33Z","id":"https://blog.mitcdh.au/posts/soaring-around-lady-elliot-island-australia/","image":"https://blog.mitcdh.au/images/soaring-around-lady-elliot-island-australia.jpg","summary":"Where the Great Barrier Reef meets azure skies over Lady Elliot Island. A November dance with nature's masterpiece, where seabirds glide and coral dreams come alive.","tags":["Album"],"title":"Soaring Around Lady Elliot Island, Australia","url":"https://blog.mitcdh.au/posts/soaring-around-lady-elliot-island-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-11-03T21:40:05Z","id":"https://blog.mitcdh.au/posts/speedrun-of-melbourne-australia/","image":"https://blog.mitcdh.au/images/speedrun-of-melbourne-australia.jpg","summary":"Racing through Melbourne's vibrant lane ways and iconic streets, a whirlwind adventure in just a few precious hours. Proving that sometimes the best explorations are the ones where time is of the essence.","tags":["Album"],"title":"Speedrun of Melbourne, Australia","url":"https://blog.mitcdh.au/posts/speedrun-of-melbourne-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-11-02T14:42:14Z","id":"https://blog.mitcdh.au/posts/swagging-in-the-red-centre-australia/","image":"https://blog.mitcdh.au/images/swagging-in-the-red-centre-australia.jpg","summary":"Under a blanket of stars in Australia's Red Centre, embracing the raw beauty of the outback while sleeping in swags.","tags":["Album"],"title":"Swagging in the Red Centre, Australia","url":"https://blog.mitcdh.au/posts/swagging-in-the-red-centre-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-10-29T18:46:16Z","id":"https://blog.mitcdh.au/posts/getting-to-know-sydney-australia/","image":"https://blog.mitcdh.au/images/getting-to-know-sydney-australia.jpg","summary":"Sydney revealed its many faces, a city that seamlessly blends beach culture with urban sophistication while making this bustling metropolis feel surprisingly like home.","tags":["Album"],"title":"Getting to Know Sydney, Australia","url":"https://blog.mitcdh.au/posts/getting-to-know-sydney-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-10-28T18:16:56Z","id":"https://blog.mitcdh.au/posts/meeting-the-fam-in-symbio-wildlife-park-australia/","image":"https://blog.mitcdh.au/images/meeting-the-fam-in-symbio-wildlife-park-australia.jpg","summary":"Surrounded by Australia's most charming locals - from bouncing kangaroos to cuddly koalas - made Symbio feel less like a park and more like a heartwarming reunion with some of nature's most endearing characters.","tags":["Album"],"title":"Meeting the Fam in Symbio Wildlife Park, Australia","url":"https://blog.mitcdh.au/posts/meeting-the-fam-in-symbio-wildlife-park-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-10-27T18:54:56Z","id":"https://blog.mitcdh.au/posts/cruising-through-the-illawarra-australia/","image":"https://blog.mitcdh.au/images/cruising-through-the-illawarra-australia.jpg","summary":"Winding along the Grand Pacific Drive where pristine beaches meet a lush rainforest escarpment, and charming seaside towns like reveal their laid-back charm.","tags":["Album"],"title":"Cruising Through the Illawarra, Australia","url":"https://blog.mitcdh.au/posts/cruising-through-the-illawarra-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-10-24T20:09:24Z","id":"https://blog.mitcdh.au/posts/back-in-daejeon-south-korea/","image":"https://blog.mitcdh.au/images/back-in-daejeon-south-korea.jpg","summary":"Returning to the familiar streets of Daejeon felt like stepping into a cherished memory, with the warm embrace of Korean hospitality and the comforting aroma of deliciously spicy street food.","tags":["Album"],"title":"Back in Daejeon, South Korea","url":"https://blog.mitcdh.au/posts/back-in-daejeon-south-korea/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis article has been adapted verbatim from a paper accepted and presented during the \u003ca href=\"https://www.iaea.org/events/smr2024\"\u003eInternational Conference on Small Modular Reactors and their Applications\u003c/a\u003e titled \u0026lsquo;\u003ca href=\"https://conferences.iaea.org/event/374/contributions/31393/\"\u003eAchieving Resilience Through the Preservation of Functions: Safety and Security Working Together\u003c/a\u003e\u0026rsquo; authored by \u003ca href=\"https://www.linkedin.com/in/mike-stjohn-green-685b6163/\"\u003eMike StJohn-Green\u003c/a\u003e and myself.\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"abstract\"\u003eAbstract\u003c/h2\u003e\n\u003cp\u003eAdvanced nuclear reactors, including Small Modular Reactors, promise enhanced safety and efficiency by harnessing complex digital technologies. However, these innovations also introduce risk management challenges regarding the computer security vulnerability of complex digital components to malicious action, faults and failures. Current nuclear industry approaches to safety and security operate with system-centric views, focusing on individual system robustness and redundancy. This approach does not explicitly address functional interdependencies, potentially causing gaps in understanding and addressing threats and vulnerabilities, resulting in a less efficient approach and less resilient result.\u003c/p\u003e\n\u003cp\u003eThis position paper advocates a paradigm shift towards unified risk management whereby safety, security, and operational integrity are complementary aspects of achieving resilience through the preservation of functions. Although applying such a model poses analytical and complexity challenges, it provides a path towards more resilient nuclear infrastructure.\u003c/p\u003e\n\u003cp\u003eRecognising that safety and security fundamentally aim to uphold functional integrity facilitates collaboration between these domains. With the development of advanced nuclear reactors, the industry has a rare opportunity to develop new tools, techniques and working methods that foster cross-domain partnerships from the design phase onward. Ultimately, this integrated perspective on technological and organisational risk management will enable nuclear designers, regulators and operators to leverage the benefits of new and complex digital systems while ensuring robust safety and security.\u003c/p\u003e\n\u003ch2 id=\"1-introduction\"\u003e1. Introduction\u003c/h2\u003e\n\u003cp\u003eThis paper will use some examples of functions that are important to the nuclear security regime and consider how the design and construction of the digital technology to deliver those functions can be made resilient to malicious action, faults and failures by using a systems engineering approach. This approach produces systems that are secure by design, alongside being safe by design. This delivers a more effective and more efficient result than attempting to apply security in an additive manner to the digital assets, without adequate consideration of the functions they perform.\u003c/p\u003e\n\u003ch2 id=\"2-what-are-we-securing\"\u003e2. What Are We Securing?\u003c/h2\u003e\n\u003cp\u003eConventional approaches to information security and computer security have often focused on, or have been interpreted as, securing individual systems, digital assets and the information they process through a set of discrete measures rather than defining and then meeting overarching security objectives to defend critical functions, such as reactor protection in a reactor \u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e. This paper will illustrate how a system-centric view can lead to a fragmented and ineffective security posture, as it fails to consider the broader context in which these systems operate, the complex interdependencies between them, and the interweaving with other objectives such as nuclear safety. By prioritising the security of individual components through requiring compliance with a set of discrete measures without considering the larger picture, organisations may overlook critical vulnerabilities and fail to allocate resources effectively to mitigate the most significant risks.\u003c/p\u003e\n\u003cp\u003eIn contrast, developing security objectives offers a robust framework for identifying and prioritising the preservation of critical functions. Safety and security objectives should be developed in tandem as the two are inherently linked - security must support safety and some safety objectives need reconciling with security objectives. For example, accident conditions could stem from violating a security objective, such as a malicious act against a system important to nuclear safety. The manner in which such a system is made both safe and secure may involve some systems engineering and architectural reconciliation to achieve both sets of objectives. Nuclear safety has a long-established culture of demonstrating adherence to a set of top-level objectives. Nuclear security should develop the equivalent approach.\u003c/p\u003e\n\u003cp\u003eSecurity objectives are materially different from the existing conventions established in safety, of protecting against faults, failures or accidents. Security needs to protect against intelligent acts delivered with malicious intent. Security is a continuously evolving struggle against knowledgeable adversaries who actively exploit vulnerabilities and launch targeted attacks to undermine critical functions, aiming to cause maximum disruption, at a time of the adversary\u0026rsquo;s choice. Many attacks will exploit weaknesses in the way assets and systems are assembled, compromising multiple layers of redundancy within a single attack, rather than in the individual assets alone. This requires that computer security is oriented to preserve the functions delivered by the combination, not just of the individual assets.\u003c/p\u003e\n\u003cp\u003eOrganisations require continuous effort to maintain their security objectives and consequently security controls will not be static, in a manner that is similar to ongoing maintenance, required to protect against equipment failure. By framing security as a set of objectives, organisations can define the engineering activities necessary to achieve and sustain a desired level of trust in the reliability of their systems and functions they deliver against malicious acts. This focus on the design functions and on security objectives alongside safety objectives can also ensure designers consider initiating events that can fall between conventional security and safety analysis, such as errors by legitimate users that enable malicious action to undermine safety.\u003c/p\u003e\n\u003cp\u003eIn the case of small modular reactors, many planned designs are expected to employ a much larger degree of digital technology than conventional reactors. The more widespread adoption of digital instrumentation, control systems, and human-system interfaces is expected to enable features like remote monitoring and maintenance, centralised control of multiple reactor modules, potentially remote operation, and even fully autonomous operation all requiring widespread integration of digital technology. For conventional reactors, most of the Instrumentation \u0026amp; Control (I\u0026amp;C) engineering has already occurred, and in many fundamental systems, structures, and components have been qualified and validated against safety objectives without consideration of supporting alignment with security objectives. However, due to a lesser prevalence and interconnection of digital technology, these systems can be demonstrated to be secured through only the sets of discrete security measures. For SMRs, this costly but fundamental engineering work is largely yet to be completed. Integrating security objectives from the outset, alongside safety objectives, will be essential to realising the benefits from the efficiencies offered by new digital I\u0026amp;C technology, while managing the risks arising from the increased prevalence and interconnectivity at an acceptable level and demonstrating regulatory compliance. This approach requires that security is viewed not as a post-design activity but as integral to the design and maintained throughout the lifecycle to ensure dependable, reliable, and trustworthy operations.\u003c/p\u003e\n\u003cp\u003eThe following sections will review existing approaches to safety and security and advocate for a systems engineering approach to combine and resolve these two sets of objectives alongside the mainstream engineering objectives to enable designers, engineers, operators and regulators to see a unified approach to delivering efficient and effective safety and security in nuclear reactors.\u003c/p\u003e\n\u003ch2 id=\"3-current-approaches-to-safety-and-security-in-engineering\"\u003e3. Current Approaches to Safety and Security in Engineering\u003c/h2\u003e\n\u003cp\u003eThis paper asserts that safety and security are often too disconnected in the engineering activities, specifically related to digital assets and that a paradigm shift is required towards unified risk management, within a systems engineering approach, where safety, security, and operational integrity are complementary aspects of achieving resilience through the preservation of functions. There is a wide range of ways this can happen, involving various disciplines that often work in isolation until (or after) final integration, leading to inevitable conflicts. This section describes some of the ways that this disconnect manifests itself. Consider the example of a digital instrumentation and control system that is designed to deliver against design function. Current approaches often use safety analysis to develop the design to the point that the safety case is acceptable. The analysis of failure paths, e.g. with a Bow Tie technique, identifies the need for barriers to maintain safety.\u003c/p\u003e\n\u003cp\u003eWhere those barriers use digital technology, these digital assets become important to safety, attracting computer security requirements. The computer security team is then tasked to defend those assets against malicious action. The security measures are often assumed to be additive and applied around those digital assets without altering their safety critical functionality. With complex digital systems, this is at best inefficient and at worst impossible. Further, the adequacy of the security measures can too easily be judged against criteria associated with the correct operation of the digital technology rather than the correct performance of all the critical functions. The following simplified examples will illustrate some of the ways this can happen, and the suboptimal result for computer security and for safety.\u003c/p\u003e\n\u003ch3 id=\"31-example-1-reactor-protection\"\u003e3.1. Example 1, Reactor Protection\u003c/h3\u003e\n\u003cp\u003eConsider the Reactor Protection Function in a conventional Nuclear Power Plant (NPP), which intervenes to stop the reactor operating outside its design basis, to protect the reactor from damage. This may be implemented using a combination of mechanical and simple electrical systems. For the purposes of this paper, this function is delivered using digital technology, implemented in the form of two independent Reactor Protection Systems (RPS). There is a safety requirement that the RPS have a high degree of independent operation and will very likely demand separate digital hardware, separate power supplies, etc. Note that this NPP-related example is chosen because it should be widely understood, not because it is directly relevant to an SMR. The principles it illustrates are widely applicable, including to SMRs.\u003c/p\u003e\n\u003cp\u003eThe security analysis will identify these two Reactor Protection Systems as being of the same criticality, because they perform the same function, and therefore they attract the same computer security requirements. Often, the computer security analysis will be focused on defending those digital assets against assumed scenarios of malicious action. Based solely on the need to defend the digital assets comprising the RPS, it would be logical to put the two RPS into the same network security zone, protected by common security devices. This simplistic approach to security would fail to defend the reactor protection function adequately because, if an adversary could compromise the common security device, the adversary would have access to both RPS. Example 1 illustrates how the computer security measures to defend the individual assets could be inadequate because they would create a single point of failure that fails to adequately support the safety requirements for the critical function.\u003c/p\u003e\n\u003ch3 id=\"32-example-2-safety-critical-cooling\"\u003e3.2. Example 2, Safety-critical cooling\u003c/h3\u003e\n\u003cp\u003eConsider a safety-critical cooling function, such as to provide heating, ventilation and air-conditioning or to keep spent fuel rods cool. Let us imagine that the safety analysis determines the need for a separate layer of protection, independent from the process control. In this example, a designer proposes that the cooling function will be implemented using digital technology, with a SIL-rated Safety Instrumented System providing the required layer of protection independent of the Basic Process Control System (BPCS), in order to meet the required performance to meet the safety requirements for the cooling function. The designer implements this using a safety controller that is certified as capable of delivering to the necessary Safety Integrity Level (SIL). The safety controller sits in a card frame that provides it with power and communications. The BPCS is implemented in similar technology, in an identical card frame. The designer identifies options to save money, by having the SIS and BPCS share the same card frame and share some sensors, accepting the vendor\u0026rsquo;s assurances and proofs of independence to protect safety requirements, but without demanding corresponding assurances about the effects of adversarial action.\u003c/p\u003e\n\u003cp\u003eThe safety analysis may consider this to be acceptable because the SIS card is built to be capable of operating to the necessary SIL level, irrespective of what else is in the card frame. However, this reasoning is flawed, as SIL-compliant devices do not automatically create a SIL-compliant system when wired together. Security analysis may simply demand that the combined card frame is protected to the higher security level, appropriate to protect the SIS. The vendor or designer may choose to demonstrate sufficient independence for safety, in light of reasonably assumed attack scenarios, but there is no guarantee this analysis will take place. The problem is only revealed if the security analysis (or systems engineers) go back to the original functional requirements and the assumptions made in the safety analysis, and check that there are adequate security measures to defend those assumptions of independence. If there is inadequate security analysis, the card frame may allow data-flows and trust relationships between the SIS and BPCS to be established by adversarial action. Example 2 illustrates how security measures could again fail to defend the assumed separation of digital technology, again violating the safety assumptions, because the security analysis was limited to the asset rather than the critical functions.\u003c/p\u003e\n\u003ch3 id=\"33-example-3-safety-bow-tie-identifies-the-barriers-for-security-to-defend\"\u003e3.3. Example 3, Safety Bow-Tie identifies the barriers for security to defend\u003c/h3\u003e\n\u003cp\u003eConventional safety analysis methods, such as fault trees or bow-tie techniques, have inherent limitations when applied to complex digital systems. Returning to the topic of Bow-Tie analysis, this is an example of what can go wrong with current safety and security approaches and illustrates the need to adopt a function-centric approach. Consider in this example the conventional safety analysis methods of failure analysis using fault trees or bow-tie methods. It is implicit in the way these methods are generally used that the paths are independent and can be analysed separately. Each barrier is assumed to be acting independently to stop failures causing a specific adverse outcome \u0026ndash; the Top Event in bow-tie terminology. The barriers are not expected to be activated simultaneously.\u003c/p\u003e\n\u003cp\u003eIn this example, the traditional security procedures call for security activity to be tasked to defend each barrier. However, a more comprehensive security analysis should consider an adversary that creates a coordinated attack that is designed to overcome multiple, parallel safety barriers in order to cause the failure of the function - the Top Event. Further, the security analysis should consider that the adversary can add functionality to the system, e.g. by covertly adding malicious code or hardware. This alters the system being defended and would warrant changes to the original bow-tie or fault tree analysis, if there were sufficient coordination between the security and safety teams. Therefore, more sophisticated security analysis may identify previously unidentified paths to cause the Top Event that should be fed back into the safety analysis. New adversary paths may also be created as a result of assembling the individual systems into systems-of-systems, which exhibit emergent properties. As digital control systems become more complex, there will be greater scope for emergent properties and consequently adversary paths that are created by combination of the systems.\u003c/p\u003e\n\u003ch2 id=\"4-development-of-a-function-centric-approach-to-csrm\"\u003e4. Development of a Function-Centric Approach to CSRM\u003c/h2\u003e\n\u003cp\u003eAn evolution enabling this systems engineering approach can be seen in the introduction of a function-centric approach to computer security risk management (CSRM) in the first revision of the IAEA\u0026rsquo;s Nuclear Security Series publication, NSS 17-T Computer Security Techniques for Nuclear Facilities \u003csup id=\"fnref:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eThe original publication of NSS 17 focused on a system-centric approach to security, prioritising developing security requirements for individual digital assets without fully considering the larger picture, the interdependencies between systems and the properties that emerge from their combination. Implementations would see a standard set of computer security measures created at various levels of consequence within the facility. While the approach at the time was common practice within the nuclear industry, it led to an incomplete and inefficient delivery of security, with controls that were additive and targeted at protecting individual systems against compromise. The controls were not easily and demonstrably traceable to meeting security and safety objectives to protect critical functions.\u003c/p\u003e\n\u003cp\u003eThe introduction of NSS 17-T Rev. 1 adopts a function-centric approach so that security measures defend the critical functions and, in this way, better support safety requirements. For example, the consideration of the critical function that a system contributes to would ensure that two systems on a common approach to defence in depth are separated into different computer security zones. This tailored defensive computer security architecture is designed to preserve existing approaches to safety defence in depth, providing a more effective and efficient security strategy.\u003c/p\u003e\n\u003cp\u003eThe revised approach in NSS 17-T Rev. 1, while not describing the creation or interpretation of security objectives, provides a framework that recognises the interdependence between security and safety objectives, allowing the harmonisation of a computer security programme with the organisation\u0026rsquo;s overarching mission and existing management frameworks. Doing so offers a more streamlined strategy for interpreting and implementing a mature and targeted approach to the security of functions compared to the original system-centric approach of NSS 17. Furthermore, it promotes a unified set of safety and security requirements, facilitating a consolidated requirements derivation process as part of an integrated approach to systems engineering.\u003c/p\u003e\n\u003cp\u003eThere are others identifying the need to improve the manner in which security engages with the engineering process. For example, many organisations and States have Secure by Design initiatives, which call for security requirements to be considered as an integral part of the engineering lifecycle. The IAEA Technical Meeting on Instrumentation and Control and Computer Security for Small Modular Reactors and Microreactors (SMR/MRs) called for a One Team approach that would bring safety and security teams much closer in a systems engineering approach to resolve the issues described in the event \u003csup id=\"fnref:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e. Some such initiatives recognise the strong association with systems engineering and the need to consider functions, but, in comparison to the IAEA NSS, they retain a more system-centric approach, starting with the digital asset or system definition rather than having a strong function-centric starting point. \u003csup id=\"fnref:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e Some initiatives focus on the consequences of malicious action rather than on the critical design functions themselves. This is a subtle distinction, perhaps best considered security-centric rather than systems engineering-centric \u003csup id=\"fnref:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eThe central argument of this paper is consistent with the Secure by Design initiatives but goes further than many in calling for a function-centric approach. All these parallel initiatives can be seen as recognising aspects of the problem described in this paper and offering similar and often overlapping proposals to solve it. However, there is not yet an industry consensus on what this should look like. This paper argues that the true solution requires combining a function-centric analysis and harmonising security and safety objectives within a systems engineering processes from the outset.\u003c/p\u003e\n\u003ch2 id=\"5-preserving-security-in-the-engineering-process\"\u003e5. Preserving Security in the Engineering Process\u003c/h2\u003e\n\u003cp\u003eThe paper will now return to the three examples and describe how a systems engineering based approach that defends the functions would have addressed the adverse results described earlier.\u003c/p\u003e\n\u003ch3 id=\"54-example-1-reactor-protection\"\u003e5.4. Example 1, Reactor Protection\u003c/h3\u003e\n\u003cp\u003eThe requirements for independence of the two digital technology systems would be derived from the high-level requirements for the reliability and availability of the reactor protection function. These high-level requirements would flow to the security design team in parallel with the safety design team and the engineering design team. Those teams may not even be teams but a single, multi-disciplinary team. The architecture for the digital systems performing the reactor protection function would be tested against all the requirements, including those for integrity and availability of the function. The network architecture would be designed to maintain a high degree of separation between the two RPS and this would extend to using different maintenance laptops and other forms of diversity. This analysis would drive the security architecture.\u003c/p\u003e\n\u003ch3 id=\"55-example-2-safety-critical-cooling\"\u003e5.5. Example 2, safety-critical cooling:\u003c/h3\u003e\n\u003cp\u003eThis example also identifies the need for independence between the digital technology that is required to achieve a specified level of safety performance. A systems engineering approach would cause all the relevant requirements, including those for safety, to be correctly identified, to be flowed down from the designer and system integrator to the vendor. The vendor would have to demonstrate that the shared card frame offers sufficient separation between the SIS and the BCPS cards. This would overcome the problem whereby the vendor delivers a card frame, as an isolated system whose architecture meets a stated security level, without considering how to meet all the non-security requirements for resilience of the critical function that the system delivers.\u003c/p\u003e\n\u003ch3 id=\"56-example-3-safety-bow-tie-identifies-all-the-safety-barriers\"\u003e5.6. Example 3, Safety Bow-Tie identifies all the safety barriers\u003c/h3\u003e\n\u003cp\u003eThe challenge with this example is that the attack scenario assumes that the adversary changes the system, therefore any safety analysis must be reviewed in light of those assumed changes. This is unlikely to happen, given the current level of interaction between the safety and security processes. Moreover, there may be additional adversary paths made possible by the properties that emerge, such as by the additional functionality introduced by the adversary. A systems engineering approach, incorporating Secure-by-Design, will consider the effects of the assumed attack scenarios on the initial design of the digital system. Where those scenarios assume modifications to the system, such as by introducing malicious code or hardware, the final design should demonstrate how the security functionality will Protect-Detect-Respond quickly enough to maintain the Safety Case or alarm to inform the operator that the system has lost integrity due to a suspected cyber-attack. Note that this functionality includes not just preventative controls, under Protect, but the means to Detect and the full range of business processes to Respond, such as returning a digital asset to a \u0026lsquo;known good state\u0026rsquo;, following detection of malicious activity. These requirements may demand fundamental changes to the control system design.\u003c/p\u003e\n\u003ch2 id=\"6-implications-for-designers-regulators-and-operators-of-smrs\"\u003e6. Implications for Designers, Regulators, and Operators of SMRs\u003c/h2\u003e\n\u003cp\u003eAs digital technology becomes more complex, such as anticipated with SMRs, the historic approach of additive security becomes less and less efficient and effective. This is because computer security measures will increasingly demand changes to the digital architecture itself. To avoid this, safety and security requirements should feed into the systems engineering processes and those requirements be maintained throughout the system lifecycle.\u003c/p\u003e\n\u003cp\u003eThese requirements should be traceable back to the functions that the system delivers, in order to assure that the function has sufficient resilience against all kinds of faults, failures and malicious action, throughout the system\u0026rsquo;s entire lifecycle. This requires a different mind-set, particularly for the security team, to work within a systems engineering regime, using a functional basis for managing requirements. It may also call for a different approach from the safety team, recognising that security cannot be additive, designed and applied as a layer around an existing design.\u003c/p\u003e\n\u003cp\u003eThis means that the design teams for new nuclear plants, such as SMRs, must now include sufficient skills and knowledge to derive and maintain security requirements, alongside safety and engineering requirements. This may involve secondments of specialist computer security expertise into the design teams.\u003c/p\u003e\n\u003cp\u003eMaintaining the resilience of the functions during the operational phase, with engineering, safety and security working together, will prompt different relationships between the operational staff and incident response staff. Consider Example 1, Reactor Protection System for a nuclear power plant. It uses digital technology and at some point, the dual-redundant RPS then declares a fault because the two channels are in different states. This may be an operator error, an equipment fault condition or a malicious attack. Which team has the knowledge and skills to diagnose, manage and remediate this problem? Options include: the I\u0026amp;C maintenance team, the physical security central alarm station, the IT Security Operations Centre, somewhere else. The requirement for suitable alarms and alerts from the system should be designed in from the outset. There will be a requirement for suitably skilled teams to be created or adapted from today\u0026rsquo;s teams, organisational policies and procedures, authority hierarchies, and communications structures for incident responders.\u003c/p\u003e\n\u003cp\u003eVendors will have their own part to play in this new approach. The developer of component digital assets and systems integrators who assemble assets into systems should become accustomed to seeing safety and security requirements in a more coherent and coordinated form, traceable back to requirements about the resilience of the function of that system or asset. The vendor is likely to have its own design team and the assets or systems will have their own lifecycles. Standards already exist for the certification of individual assets, e.g. within \u003csup id=\"fnref:6\"\u003e\u003ca href=\"#fn:6\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e6\u003c/a\u003e\u003c/sup\u003e and the other members of that family of standards.\u003c/p\u003e\n\u003cp\u003eThe functions of those systems and assets should be assured in the face of faults, failures and malicious action by the system designers, system integrators and operators, as part of a system engineering approach. There are publications \u003csup id=\"fnref1:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e and \u003csup id=\"fnref1:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e that make relevant recommendations but there is as yet no consensus on the way to deliver the function-based approach called for in this paper.\u003c/p\u003e\n\u003cp\u003eRegulators frequently separate safety and security into different parts of their organisations, so there can be weak interaction between them, based on the premise that safety and security can be dealt with separately. Developing the coordination between the safety and security teams may be a challenge, but one that definitely needs to be overcome.\u003c/p\u003e\n\u003cp\u003eThose separations between the engineering, safety and security disciplines seen across industry can also be seen in the way IAEA guidance is developed.\u003c/p\u003e\n\u003ch2 id=\"7-conclusion\"\u003e7. Conclusion\u003c/h2\u003e\n\u003cp\u003eThis position paper advocates a paradigm shift towards unified risk management, within a systems engineering approach, where safety, security, and operational integrity are complementary aspects of achieving resilience through the preservation of functions. Although applying such a model poses analytical and complexity challenges, it provides a path towards more resilient nuclear infrastructure. Recognising that safety and security fundamentally aim to uphold functional integrity facilitates collaboration between safety teams, security teams and engineering teams. If the arguments presented in this position paper are accepted, changes are likely to be needed to existing safety and security standards.\u003c/p\u003e\n\u003cp\u003eThis approach has applicability to conventional NPPs but there is greater urgency to develop this thinking for SMRs, due to the likely reliance on new I\u0026amp;C technologies that have previously not been used in the nuclear sector. Others identify the need to improve the way security is achieved, with Secure by Design and other initiatives but there is not yet a consensus about what this looks like. With the development of advanced nuclear reactors, the industry has a rare opportunity to develop new tools, techniques and collaborative working methods. Once developed and established, this integrated approach will enable nuclear designers, regulators and operators to leverage the benefits of new and more complex digital technology while demonstrating traceable, robust safety and security.\u003c/p\u003e\n\u003ch2 id=\"acknowledgements\"\u003eAcknowledgements\u003c/h2\u003e\n\u003cp\u003eThe authors wish to thank Dr. Steve Essery (Method Cyber Security Ltd, UK), Mr. Jon Wiggins (1981 Consultants, UK), and Mr. Joe Mahanes (INL, USA) for their insightful feedback on the methodology, helpful challenges and suggestions. Any errors or omissions in the paper are solely the responsibility of the authors.\u003c/p\u003e\n\u003ch2 id=\"references\"\u003eReferences\u003c/h2\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eINTERNATIONAL STANDARDS ORGANISATION, ISO/IEC 27000 Information technology \u0026ndash; Security techniques \u0026ndash; Information security management systems \u0026ndash; Overview and vocabulary,  Edition 5, Geneva (2018)\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:2\"\u003e\n\u003cp\u003eINTERNATIONAL ATOMIC ENERGY AGENCY, Computer Security Techniques for Nuclear Facilities, IAEA Nuclear Security Series No. 17-T (Rev. 1), IAEA, Vienna (2021)\u0026#160;\u003ca href=\"#fnref:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:3\"\u003e\n\u003cp\u003eINTERNATIONAL ATOMIC ENERGY AGENCY, Technical Meeting on Instrumentation and Control and Computer Security for Small Modular Reactors and Microreactors, \u003ca href=\"https://www.iaea.org/events/evt2100684\"\u003ehttps://www.iaea.org/events/evt2100684\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:4\"\u003e\n\u003cp\u003eWright, V.L., Meng, J.P., Anderson, R.S., Gellner, J.R., Barnes, L.B., Chanoski, S.D., Edsall, R.M., Holtz, M.R., Jones, J.M., Le Blanc, K.L., Mahanes, J.C., McJunkin, T.R., Robinson, J., Rucinski, D.J., Shannon, G.E., Welch, J.J., Ayala, M., Atkins, V., Baker, K.A., Castillo, K., Cox, J., Gale, T., Graham, R., Groves, D., Johnson, S., Kishter, L., Macwan, R., Loo, S.M., McFly, S., Martin, M., Morris, M., Ohrt, A., Sachs, M., Venkataramanan, V., Waligoske, E., and Williams, G., \u0026ldquo;Cyber-informed engineering implementation guide\u0026rdquo;, 2023.\u0026#160;\u003ca href=\"#fnref:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:5\"\u003e\n\u003cp\u003eFreeman, S.G., St Michel, C., Smith, R., and Assante, M., \u0026ldquo;Consequence-driven cyber-informed engineering (CCE)\u0026rdquo;. United States: N. p., 2016. Web. doi:10.2172/1341416.\u0026#160;\u003ca href=\"#fnref:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref1:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:6\"\u003e\n\u003cp\u003eINTERNATIONAL ELECTROTECHNICAL COMMISSION, Security for Industrial Automation and Control Systems - Part 4-2: Technical Security Requirements for IACS Components, IEC 62443-4-2:2019, IEC, Geneva (2019)\u0026#160;\u003ca href=\"#fnref:6\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This article has been adapted verbatim from a paper accepted and presented during the International Conference on Small Modular Reactors and their Applications titled ‘Achieving Resilience Through the Preservation of Functions: Safety and Security Working Together’ authored by Mike StJohn-Green and myself.\nAbstract Advanced nuclear reactors, including Small Modular Reactors, promise enhanced safety and efficiency by harnessing complex digital technologies. However, these innovations also introduce risk management challenges regarding the computer security vulnerability of complex digital components to malicious action, faults and failures. Current nuclear industry approaches to safety and security operate with system-centric views, focusing on individual system robustness and redundancy. This approach does not explicitly address functional interdependencies, potentially causing gaps in understanding and addressing threats and vulnerabilities, resulting in a less efficient approach and less resilient result.\nThis position paper advocates a paradigm shift towards unified risk management whereby safety, security, and operational integrity are complementary aspects of achieving resilience through the preservation of functions. Although applying such a model poses analytical and complexity challenges, it provides a path towards more resilient nuclear infrastructure.\nRecognising that safety and security fundamentally aim to uphold functional integrity facilitates collaboration between these domains. With the development of advanced nuclear reactors, the industry has a rare opportunity to develop new tools, techniques and working methods that foster cross-domain partnerships from the design phase onward. Ultimately, this integrated perspective on technological and organisational risk management will enable nuclear designers, regulators and operators to leverage the benefits of new and complex digital systems while ensuring robust safety and security.\n1. Introduction This paper will use some examples of functions that are important to the nuclear security regime and consider how the design and construction of the digital technology to deliver those functions can be made resilient to malicious action, faults and failures by using a systems engineering approach. This approach produces systems that are secure by design, alongside being safe by design. This delivers a more effective and more efficient result than attempting to apply security in an additive manner to the digital assets, without adequate consideration of the functions they perform.\n2. What Are We Securing? Conventional approaches to information security and computer security have often focused on, or have been interpreted as, securing individual systems, digital assets and the information they process through a set of discrete measures rather than defining and then meeting overarching security objectives to defend critical functions, such as reactor protection in a reactor 1. This paper will illustrate how a system-centric view can lead to a fragmented and ineffective security posture, as it fails to consider the broader context in which these systems operate, the complex interdependencies between them, and the interweaving with other objectives such as nuclear safety. By prioritising the security of individual components through requiring compliance with a set of discrete measures without considering the larger picture, organisations may overlook critical vulnerabilities and fail to allocate resources effectively to mitigate the most significant risks.\nIn contrast, developing security objectives offers a robust framework for identifying and prioritising the preservation of critical functions. Safety and security objectives should be developed in tandem as the two are inherently linked - security must support safety and some safety objectives need reconciling with security objectives. For example, accident conditions could stem from violating a security objective, such as a malicious act against a system important to nuclear safety. The manner in which such a system is made both safe and secure may involve some systems engineering and architectural reconciliation to achieve both sets of objectives. Nuclear safety has a long-established culture of demonstrating adherence to a set of top-level objectives. Nuclear security should develop the equivalent approach.\nSecurity objectives are materially different from the existing conventions established in safety, of protecting against faults, failures or accidents. Security needs to protect against intelligent acts delivered with malicious intent. Security is a continuously evolving struggle against knowledgeable adversaries who actively exploit vulnerabilities and launch targeted attacks to undermine critical functions, aiming to cause maximum disruption, at a time of the adversary’s choice. Many attacks will exploit weaknesses in the way assets and systems are assembled, compromising multiple layers of redundancy within a single attack, rather than in the individual assets alone. This requires that computer security is oriented to preserve the functions delivered by the combination, not just of the individual assets.\nOrganisations require continuous effort to maintain their security objectives and consequently security controls will not be static, in a manner that is similar to ongoing maintenance, required to protect against equipment failure. By framing security as a set of objectives, organisations can define the engineering activities necessary to achieve and sustain a desired level of trust in the reliability of their systems and functions they deliver against malicious acts. This focus on the design functions and on security objectives alongside safety objectives can also ensure designers consider initiating events that can fall between conventional security and safety analysis, such as errors by legitimate users that enable malicious action to undermine safety.\nIn the case of small modular reactors, many planned designs are expected to employ a much larger degree of digital technology than conventional reactors. The more widespread adoption of digital instrumentation, control systems, and human-system interfaces is expected to enable features like remote monitoring and maintenance, centralised control of multiple reactor modules, potentially remote operation, and even fully autonomous operation all requiring widespread integration of digital technology. For conventional reactors, most of the Instrumentation \u0026 Control (I\u0026C) engineering has already occurred, and in many fundamental systems, structures, and components have been qualified and validated against safety objectives without consideration of supporting alignment with security objectives. However, due to a lesser prevalence and interconnection of digital technology, these systems can be demonstrated to be secured through only the sets of discrete security measures. For SMRs, this costly but fundamental engineering work is largely yet to be completed. Integrating security objectives from the outset, alongside safety objectives, will be essential to realising the benefits from the efficiencies offered by new digital I\u0026C technology, while managing the risks arising from the increased prevalence and interconnectivity at an acceptable level and demonstrating regulatory compliance. This approach requires that security is viewed not as a post-design activity but as integral to the design and maintained throughout the lifecycle to ensure dependable, reliable, and trustworthy operations.\nThe following sections will review existing approaches to safety and security and advocate for a systems engineering approach to combine and resolve these two sets of objectives alongside the mainstream engineering objectives to enable designers, engineers, operators and regulators to see a unified approach to delivering efficient and effective safety and security in nuclear reactors.\n3. Current Approaches to Safety and Security in Engineering This paper asserts that safety and security are often too disconnected in the engineering activities, specifically related to digital assets and that a paradigm shift is required towards unified risk management, within a systems engineering approach, where safety, security, and operational integrity are complementary aspects of achieving resilience through the preservation of functions. There is a wide range of ways this can happen, involving various disciplines that often work in isolation until (or after) final integration, leading to inevitable conflicts. This section describes some of the ways that this disconnect manifests itself. Consider the example of a digital instrumentation and control system that is designed to deliver against design function. Current approaches often use safety analysis to develop the design to the point that the safety case is acceptable. The analysis of failure paths, e.g. with a Bow Tie technique, identifies the need for barriers to maintain safety.\nWhere those barriers use digital technology, these digital assets become important to safety, attracting computer security requirements. The computer security team is then tasked to defend those assets against malicious action. The security measures are often assumed to be additive and applied around those digital assets without altering their safety critical functionality. With complex digital systems, this is at best inefficient and at worst impossible. Further, the adequacy of the security measures can too easily be judged against criteria associated with the correct operation of the digital technology rather than the correct performance of all the critical functions. The following simplified examples will illustrate some of the ways this can happen, and the suboptimal result for computer security and for safety.\n3.1. Example 1, Reactor Protection Consider the Reactor Protection Function in a conventional Nuclear Power Plant (NPP), which intervenes to stop the reactor operating outside its design basis, to protect the reactor from damage. This may be implemented using a combination of mechanical and simple electrical systems. For the purposes of this paper, this function is delivered using digital technology, implemented in the form of two independent Reactor Protection Systems (RPS). There is a safety requirement that the RPS have a high degree of independent operation and will very likely demand separate digital hardware, separate power supplies, etc. Note that this NPP-related example is chosen because it should be widely understood, not because it is directly relevant to an SMR. The principles it illustrates are widely applicable, including to SMRs.\nThe security analysis will identify these two Reactor Protection Systems as being of the same criticality, because they perform the same function, and therefore they attract the same computer security requirements. Often, the computer security analysis will be focused on defending those digital assets against assumed scenarios of malicious action. Based solely on the need to defend the digital assets comprising the RPS, it would be logical to put the two RPS into the same network security zone, protected by common security devices. This simplistic approach to security would fail to defend the reactor protection function adequately because, if an adversary could compromise the common security device, the adversary would have access to both RPS. Example 1 illustrates how the computer security measures to defend the individual assets could be inadequate because they would create a single point of failure that fails to adequately support the safety requirements for the critical function.\n3.2. Example 2, Safety-critical cooling Consider a safety-critical cooling function, such as to provide heating, ventilation and air-conditioning or to keep spent fuel rods cool. Let us imagine that the safety analysis determines the need for a separate layer of protection, independent from the process control. In this example, a designer proposes that the cooling function will be implemented using digital technology, with a SIL-rated Safety Instrumented System providing the required layer of protection independent of the Basic Process Control System (BPCS), in order to meet the required performance to meet the safety requirements for the cooling function. The designer implements this using a safety controller that is certified as capable of delivering to the necessary Safety Integrity Level (SIL). The safety controller sits in a card frame that provides it with power and communications. The BPCS is implemented in similar technology, in an identical card frame. The designer identifies options to save money, by having the SIS and BPCS share the same card frame and share some sensors, accepting the vendor’s assurances and proofs of independence to protect safety requirements, but without demanding corresponding assurances about the effects of adversarial action.\nThe safety analysis may consider this to be acceptable because the SIS card is built to be capable of operating to the necessary SIL level, irrespective of what else is in the card frame. However, this reasoning is flawed, as SIL-compliant devices do not automatically create a SIL-compliant system when wired together. Security analysis may simply demand that the combined card frame is protected to the higher security level, appropriate to protect the SIS. The vendor or designer may choose to demonstrate sufficient independence for safety, in light of reasonably assumed attack scenarios, but there is no guarantee this analysis will take place. The problem is only revealed if the security analysis (or systems engineers) go back to the original functional requirements and the assumptions made in the safety analysis, and check that there are adequate security measures to defend those assumptions of independence. If there is inadequate security analysis, the card frame may allow data-flows and trust relationships between the SIS and BPCS to be established by adversarial action. Example 2 illustrates how security measures could again fail to defend the assumed separation of digital technology, again violating the safety assumptions, because the security analysis was limited to the asset rather than the critical functions.\n3.3. Example 3, Safety Bow-Tie identifies the barriers for security to defend Conventional safety analysis methods, such as fault trees or bow-tie techniques, have inherent limitations when applied to complex digital systems. Returning to the topic of Bow-Tie analysis, this is an example of what can go wrong with current safety and security approaches and illustrates the need to adopt a function-centric approach. Consider in this example the conventional safety analysis methods of failure analysis using fault trees or bow-tie methods. It is implicit in the way these methods are generally used that the paths are independent and can be analysed separately. Each barrier is assumed to be acting independently to stop failures causing a specific adverse outcome – the Top Event in bow-tie terminology. The barriers are not expected to be activated simultaneously.\nIn this example, the traditional security procedures call for security activity to be tasked to defend each barrier. However, a more comprehensive security analysis should consider an adversary that creates a coordinated attack that is designed to overcome multiple, parallel safety barriers in order to cause the failure of the function - the Top Event. Further, the security analysis should consider that the adversary can add functionality to the system, e.g. by covertly adding malicious code or hardware. This alters the system being defended and would warrant changes to the original bow-tie or fault tree analysis, if there were sufficient coordination between the security and safety teams. Therefore, more sophisticated security analysis may identify previously unidentified paths to cause the Top Event that should be fed back into the safety analysis. New adversary paths may also be created as a result of assembling the individual systems into systems-of-systems, which exhibit emergent properties. As digital control systems become more complex, there will be greater scope for emergent properties and consequently adversary paths that are created by combination of the systems.\n4. Development of a Function-Centric Approach to CSRM An evolution enabling this systems engineering approach can be seen in the introduction of a function-centric approach to computer security risk management (CSRM) in the first revision of the IAEA’s Nuclear Security Series publication, NSS 17-T Computer Security Techniques for Nuclear Facilities 2.\nThe original publication of NSS 17 focused on a system-centric approach to security, prioritising developing security requirements for individual digital assets without fully considering the larger picture, the interdependencies between systems and the properties that emerge from their combination. Implementations would see a standard set of computer security measures created at various levels of consequence within the facility. While the approach at the time was common practice within the nuclear industry, it led to an incomplete and inefficient delivery of security, with controls that were additive and targeted at protecting individual systems against compromise. The controls were not easily and demonstrably traceable to meeting security and safety objectives to protect critical functions.\nThe introduction of NSS 17-T Rev. 1 adopts a function-centric approach so that security measures defend the critical functions and, in this way, better support safety requirements. For example, the consideration of the critical function that a system contributes to would ensure that two systems on a common approach to defence in depth are separated into different computer security zones. This tailored defensive computer security architecture is designed to preserve existing approaches to safety defence in depth, providing a more effective and efficient security strategy.\nThe revised approach in NSS 17-T Rev. 1, while not describing the creation or interpretation of security objectives, provides a framework that recognises the interdependence between security and safety objectives, allowing the harmonisation of a computer security programme with the organisation’s overarching mission and existing management frameworks. Doing so offers a more streamlined strategy for interpreting and implementing a mature and targeted approach to the security of functions compared to the original system-centric approach of NSS 17. Furthermore, it promotes a unified set of safety and security requirements, facilitating a consolidated requirements derivation process as part of an integrated approach to systems engineering.\nThere are others identifying the need to improve the manner in which security engages with the engineering process. For example, many organisations and States have Secure by Design initiatives, which call for security requirements to be considered as an integral part of the engineering lifecycle. The IAEA Technical Meeting on Instrumentation and Control and Computer Security for Small Modular Reactors and Microreactors (SMR/MRs) called for a One Team approach that would bring safety and security teams much closer in a systems engineering approach to resolve the issues described in the event 3. Some such initiatives recognise the strong association with systems engineering and the need to consider functions, but, in comparison to the IAEA NSS, they retain a more system-centric approach, starting with the digital asset or system definition rather than having a strong function-centric starting point. 4 Some initiatives focus on the consequences of malicious action rather than on the critical design functions themselves. This is a subtle distinction, perhaps best considered security-centric rather than systems engineering-centric 5.\nThe central argument of this paper is consistent with the Secure by Design initiatives but goes further than many in calling for a function-centric approach. All these parallel initiatives can be seen as recognising aspects of the problem described in this paper and offering similar and often overlapping proposals to solve it. However, there is not yet an industry consensus on what this should look like. This paper argues that the true solution requires combining a function-centric analysis and harmonising security and safety objectives within a systems engineering processes from the outset.\n5. Preserving Security in the Engineering Process The paper will now return to the three examples and describe how a systems engineering based approach that defends the functions would have addressed the adverse results described earlier.\n5.4. Example 1, Reactor Protection The requirements for independence of the two digital technology systems would be derived from the high-level requirements for the reliability and availability of the reactor protection function. These high-level requirements would flow to the security design team in parallel with the safety design team and the engineering design team. Those teams may not even be teams but a single, multi-disciplinary team. The architecture for the digital systems performing the reactor protection function would be tested against all the requirements, including those for integrity and availability of the function. The network architecture would be designed to maintain a high degree of separation between the two RPS and this would extend to using different maintenance laptops and other forms of diversity. This analysis would drive the security architecture.\n5.5. Example 2, safety-critical cooling: This example also identifies the need for independence between the digital technology that is required to achieve a specified level of safety performance. A systems engineering approach would cause all the relevant requirements, including those for safety, to be correctly identified, to be flowed down from the designer and system integrator to the vendor. The vendor would have to demonstrate that the shared card frame offers sufficient separation between the SIS and the BCPS cards. This would overcome the problem whereby the vendor delivers a card frame, as an isolated system whose architecture meets a stated security level, without considering how to meet all the non-security requirements for resilience of the critical function that the system delivers.\n5.6. Example 3, Safety Bow-Tie identifies all the safety barriers The challenge with this example is that the attack scenario assumes that the adversary changes the system, therefore any safety analysis must be reviewed in light of those assumed changes. This is unlikely to happen, given the current level of interaction between the safety and security processes. Moreover, there may be additional adversary paths made possible by the properties that emerge, such as by the additional functionality introduced by the adversary. A systems engineering approach, incorporating Secure-by-Design, will consider the effects of the assumed attack scenarios on the initial design of the digital system. Where those scenarios assume modifications to the system, such as by introducing malicious code or hardware, the final design should demonstrate how the security functionality will Protect-Detect-Respond quickly enough to maintain the Safety Case or alarm to inform the operator that the system has lost integrity due to a suspected cyber-attack. Note that this functionality includes not just preventative controls, under Protect, but the means to Detect and the full range of business processes to Respond, such as returning a digital asset to a ‘known good state’, following detection of malicious activity. These requirements may demand fundamental changes to the control system design.\n6. Implications for Designers, Regulators, and Operators of SMRs As digital technology becomes more complex, such as anticipated with SMRs, the historic approach of additive security becomes less and less efficient and effective. This is because computer security measures will increasingly demand changes to the digital architecture itself. To avoid this, safety and security requirements should feed into the systems engineering processes and those requirements be maintained throughout the system lifecycle.\nThese requirements should be traceable back to the functions that the system delivers, in order to assure that the function has sufficient resilience against all kinds of faults, failures and malicious action, throughout the system’s entire lifecycle. This requires a different mind-set, particularly for the security team, to work within a systems engineering regime, using a functional basis for managing requirements. It may also call for a different approach from the safety team, recognising that security cannot be additive, designed and applied as a layer around an existing design.\nThis means that the design teams for new nuclear plants, such as SMRs, must now include sufficient skills and knowledge to derive and maintain security requirements, alongside safety and engineering requirements. This may involve secondments of specialist computer security expertise into the design teams.\nMaintaining the resilience of the functions during the operational phase, with engineering, safety and security working together, will prompt different relationships between the operational staff and incident response staff. Consider Example 1, Reactor Protection System for a nuclear power plant. It uses digital technology and at some point, the dual-redundant RPS then declares a fault because the two channels are in different states. This may be an operator error, an equipment fault condition or a malicious attack. Which team has the knowledge and skills to diagnose, manage and remediate this problem? Options include: the I\u0026C maintenance team, the physical security central alarm station, the IT Security Operations Centre, somewhere else. The requirement for suitable alarms and alerts from the system should be designed in from the outset. There will be a requirement for suitably skilled teams to be created or adapted from today’s teams, organisational policies and procedures, authority hierarchies, and communications structures for incident responders.\nVendors will have their own part to play in this new approach. The developer of component digital assets and systems integrators who assemble assets into systems should become accustomed to seeing safety and security requirements in a more coherent and coordinated form, traceable back to requirements about the resilience of the function of that system or asset. The vendor is likely to have its own design team and the assets or systems will have their own lifecycles. Standards already exist for the certification of individual assets, e.g. within 6 and the other members of that family of standards.\nThe functions of those systems and assets should be assured in the face of faults, failures and malicious action by the system designers, system integrators and operators, as part of a system engineering approach. There are publications 4 and 5 that make relevant recommendations but there is as yet no consensus on the way to deliver the function-based approach called for in this paper.\nRegulators frequently separate safety and security into different parts of their organisations, so there can be weak interaction between them, based on the premise that safety and security can be dealt with separately. Developing the coordination between the safety and security teams may be a challenge, but one that definitely needs to be overcome.\nThose separations between the engineering, safety and security disciplines seen across industry can also be seen in the way IAEA guidance is developed.\n7. Conclusion This position paper advocates a paradigm shift towards unified risk management, within a systems engineering approach, where safety, security, and operational integrity are complementary aspects of achieving resilience through the preservation of functions. Although applying such a model poses analytical and complexity challenges, it provides a path towards more resilient nuclear infrastructure. Recognising that safety and security fundamentally aim to uphold functional integrity facilitates collaboration between safety teams, security teams and engineering teams. If the arguments presented in this position paper are accepted, changes are likely to be needed to existing safety and security standards.\nThis approach has applicability to conventional NPPs but there is greater urgency to develop this thinking for SMRs, due to the likely reliance on new I\u0026C technologies that have previously not been used in the nuclear sector. Others identify the need to improve the way security is achieved, with Secure by Design and other initiatives but there is not yet a consensus about what this looks like. With the development of advanced nuclear reactors, the industry has a rare opportunity to develop new tools, techniques and collaborative working methods. Once developed and established, this integrated approach will enable nuclear designers, regulators and operators to leverage the benefits of new and more complex digital technology while demonstrating traceable, robust safety and security.\nAcknowledgements The authors wish to thank Dr. Steve Essery (Method Cyber Security Ltd, UK), Mr. Jon Wiggins (1981 Consultants, UK), and Mr. Joe Mahanes (INL, USA) for their insightful feedback on the methodology, helpful challenges and suggestions. Any errors or omissions in the paper are solely the responsibility of the authors.\nReferences INTERNATIONAL STANDARDS ORGANISATION, ISO/IEC 27000 Information technology – Security techniques – Information security management systems – Overview and vocabulary, Edition 5, Geneva (2018) ↩︎\nINTERNATIONAL ATOMIC ENERGY AGENCY, Computer Security Techniques for Nuclear Facilities, IAEA Nuclear Security Series No. 17-T (Rev. 1), IAEA, Vienna (2021) ↩︎\nINTERNATIONAL ATOMIC ENERGY AGENCY, Technical Meeting on Instrumentation and Control and Computer Security for Small Modular Reactors and Microreactors, https://www.iaea.org/events/evt2100684 ↩︎\nWright, V.L., Meng, J.P., Anderson, R.S., Gellner, J.R., Barnes, L.B., Chanoski, S.D., Edsall, R.M., Holtz, M.R., Jones, J.M., Le Blanc, K.L., Mahanes, J.C., McJunkin, T.R., Robinson, J., Rucinski, D.J., Shannon, G.E., Welch, J.J., Ayala, M., Atkins, V., Baker, K.A., Castillo, K., Cox, J., Gale, T., Graham, R., Groves, D., Johnson, S., Kishter, L., Macwan, R., Loo, S.M., McFly, S., Martin, M., Morris, M., Ohrt, A., Sachs, M., Venkataramanan, V., Waligoske, E., and Williams, G., “Cyber-informed engineering implementation guide”, 2023. ↩︎ ↩︎\nFreeman, S.G., St Michel, C., Smith, R., and Assante, M., “Consequence-driven cyber-informed engineering (CCE)”. United States: N. p., 2016. Web. doi:10.2172/1341416. ↩︎ ↩︎\nINTERNATIONAL ELECTROTECHNICAL COMMISSION, Security for Industrial Automation and Control Systems - Part 4-2: Technical Security Requirements for IACS Components, IEC 62443-4-2:2019, IEC, Geneva (2019) ↩︎\n","date_published":"2024-10-23T18:00:00+03:00","id":"https://blog.mitcdh.au/posts/preserving-functions/","image":"https://blog.mitcdh.au/images/preserving-functions.webp","summary":"Safety and Security Working Together","tags":["Writing","Nuclear","Technology","Security","Safety"],"title":"Achieving Resilience Through the Preservation of Functions","url":"https://blog.mitcdh.au/posts/preserving-functions/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis article has been adapted verbatim from a paper accepted and presented during the \u003ca href=\"https://www.iaea.org/events/smr2024\"\u003eInternational Conference on Small Modular Reactors and their Applications\u003c/a\u003e titled \u0026lsquo;\u003ca href=\"https://conferences.iaea.org/event/374/contributions/31390/\"\u003eApproaches for Comprehensive Safety and Digital Risk Management for Advanced Nuclear Technology and Small Modular Reactors\u003c/a\u003e\u0026rsquo; authored by \u003ca href=\"https://www.linkedin.com/in/joseph-mahanes-a2940b57/\"\u003eJoseph Mahanes\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/bob-anderson-414a2834/\"\u003eBob Anderson\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/shannoneggers/\"\u003eShannon Eggers\u003c/a\u003e,  \u003ca href=\"https://www.linkedin.com/in/mike-stjohn-green-685b6163/\"\u003eMike StJohn-Green\u003c/a\u003e and myself.\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"abstract\"\u003eAbstract\u003c/h1\u003e\n\u003cp\u003eSmall Modular Reactor (SMR) designs are likely to rely on complex digital technology novel to nuclear industry applications while also leveraging passive systems and safety design simplification. The result of current approaches may lead to a safety-driven system design that lacks demonstrated robustness in the event of cyber-attacks against its digital equipment. Information and computer security should be an integral part of engineering and operational processes. Current safety and security thinking does not encourage sufficient interaction. Teams are often separate and management structures reinforce this separation. This paper provides a case for cybersecurity related safety and digital engineering security requirements to be considered together throughout design, licensing, and operation. Safety envelope boundaries may be expressed using many variables and suitably defined system theoretic models can be used to alert whether due to faults, failures, or malicious action. This provides a unifying \u0026ldquo;top down\u0026rdquo; framework for digital systems and approaches supporting and implementing safety and security requirements. This paper will identify existing work supporting this closer relationship. However, new tools, techniques, and ways of working need developing to enable SMR designers, regulators and operators to employ complex digital technology in a way that remains both safe and secure.\u003c/p\u003e\n\u003ch1 id=\"1-introduction\"\u003e1. Introduction\u003c/h1\u003e\n\u003cp\u003eTraditional approaches to safety, security, and information security within the nuclear industry operate in silos, with distinct teams and management structures that do not sufficiently encourage a holistic approach to risk management. This segregation leads to a fragmented understanding of threats, vulnerabilities, and responsibilities potentially overlooking the interdependencies between safety and security objectives. Risk is the common language through which these and other different engineering disciplines and stakeholders evaluate design decisions, as well as how potentially conflicting priorities are arbitrated. Digital risk encompasses both adversarial threats such as a cyber attacker and non-adversarial threats such as human performance errors and equipment failure or misconfiguration. A comprehensive consideration of the possible risks posed by maloperation of digital equipment bridges the typically threat-focused risk mitigation in security engineering, and the phenomena driven risk mitigation of safety engineering. Digital innovations introduce nuanced challenges in risk management, particularly regarding the use of new and emerging digital systems and technologies that will play integral roles in operations, safety, and security, while potentially revealing gaps in current approaches that may lead to a system design that lacks demonstrated robustness to cyber-attacks.\u003c/p\u003e\n\u003cp\u003eA barrier to the successful deployment of SMRs is risk communication and regulatory acceptance. Many SMRs leverage mature and existing nuclear reactor design aspects to reduce the overall potential negative consequence of safety and security scenarios. These practices more effectively treat risk early in the engineering process where certain choices can eliminate or significantly reduce potential failures or attack pathways and can reduce the high operational costs associated with \u0026ldquo;bolt-on\u0026rdquo; security practices. Significant improvements in ensuring the critical functions of preserving radiological barriers, safe shutdown and continued safe shutdown,, and heat removal through advanced fuels, such as used in gas-cooled SMRs, and inherent safety features in light water cooled reactors (LWRs) with extensive natural circulation cooling capabilities. As SMR technology progress into licensing and operation, the question remains whether these designs have sufficiently demonstrated to licensing entities the due diligence, enabling a smaller safety systems footprint, physical protection guard force scaled from traditional large multi-reactor sites, and advancing the safe and secure adoption of digital technologies in ways previously not considered in the nuclear industry.\u003c/p\u003e\n\u003cp\u003eTraditional safety analysis draws a bounding envelope of operation through a series of analyses enumerating normal operation modes and expected challenges, which is then accepted by a regulatory body. These analyses utilize physics-based codes to model and understand the potential energy sources which must be contained, such as kinetic energy from high mass objects, chemical potential energy, criticality of nuclear material, radiation from radiological material, highly pressurized systems, high temperature systems and other energy sources. The challenge of the safety and security intersection can be expressed similarly as the potential for digital systems to interact adversely with these same high potential energy systems. One concern with the design and construction of new SMRs/MRs is that design teams will not address digital risk management or cybersecurity early enough in the systems engineering lifecycle. Another concern is that large, multi-teamed design projects will not bring in cybersecurity and digital risk as a separate discipline which can lead to conflicts with requirements, potentially leading to functional, safety, reliability, or security issues. Model Based Systems Engineering (MBSE) helps to bridge that gap, by bringing all disciplines together and addressing digital risk management starting early in the systems engineering lifecycle.\u003c/p\u003e\n\u003ch1 id=\"2-breaking-down-the-safety-silo\"\u003e2. Breaking Down the Safety Silo\u003c/h1\u003e\n\u003cp\u003eGood safety design has independently arrived at many of the same conclusions for best practice as cybersecurity, such as favouring reliance on passive systems, design simplification, layered defences and more. The result is a safety-driven system design that while often offering limited incidental robustness in event of cyber-attacks, lacks any approach to protecting the digital systems responsible for managing high energy and high potential impact consequences resulting from intentional maloperation. The ultimate reliability objective of a system for cybersecurity is the preservation of the correct performance of a vital function, even in the face of malicious compromise of one or more digital systems contributing to the performance of that function. For example, preserving a cooling loop\u0026rsquo;s ability to remove heat from a system may be reliably maintained through combinations of non-digital alternative operation means, fail-safe process design, and capability to redeploy a known good configuration in an isolated mode. In this example, even if an adversary were to gain control of the system, no combination of actions can push the process outside of its safety envelope. This result requires not just a good understanding of the process and governing physics, but also the entire range of capability of the responsible control systems, and the capability of maloperation.\u003c/p\u003e\n\u003cp\u003eOne such example of integrating security and engineering is Cyber-Informed Engineering (CIE), a US Department of Energy national strategy that encourages \u0026ldquo;secure-by-design\u0026rdquo; concepts to include the engineering of cyber-physical systems. This approach creates opportunities for engineering teams to secure digital systems using physics and mechanics of engineering controls \u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e. This methodology to integrate security has been applied to projects across critical infrastructure sectors. Benefits have primarily been building communication pathways between different engineering teams, and incorporating cybersecurity as not only a major contributor within the entire systems engineering team, but also the awareness that cybersecurity is necessary as a major engineering discipline during conceptual, requirements, and detailed design phases that allow for an \u0026ldquo;engineered\u0026rdquo; approach to cyber risk reduction. More importantly, projects have eliminated potential attack pathways and reduce consequence of compromise. Successful integration of cybersecurity requirements and design considerations have been applied to advanced reactor projects and ongoing research and development in support of nuclear SMRs. One example is the implementation of data encryption in OT systems. Often, encryption can be a challenge as a perceived complication in the availability of digital assets. By integrating cybersecurity into the requirements and design phase, one potential option for cryptography clearly best satisfied both functional and cybersecurity requirements. This potentially mitigated costly revisions or less effective options that would require additional controls. This example demonstrated to the safety engineers that securing digital equipment was much more efficient if security was core to the design. Other benefits of this approach include encouraging \u0026ldquo;outside the box\u0026rdquo; thinking about how an adversary could use potential digital assets in a manner not thought of for malicious goals. A standalone wireless gas supply system located outside the facility was identified as a potential jump point into the plant with or without insider help. Typically, safety does not think adversarial, however, the inclusion of security during the design process helped reduce the need for last minute bolt-on controls especially when bolt-on controls may not be possible.\u003c/p\u003e\n\u003cp\u003eThe entire goal of CIE and \u0026ldquo;security-by-design\u0026rdquo; is to include all engineering disciplines, including historically siloed disciplines such as safety, to identify and design the most robust, functionally secure systems that can anticipate, as much as possible, adversarial threat tactics, techniques, and procedures (TTP). Ideally, incorporating security-by-design into the engineering process will extend the longevity of a design to, at a maximum, prevent the continuously adaptive adversary TTP\u0026rsquo;s ability to overtake a system and, at a minimum, alert operators before a security event or incident compromises nuclear security.\u003c/p\u003e\n\u003cp\u003eAdditionally, recent TTPs have increasingly expanded to leverage \u0026ldquo;Living-off-the-land\u0026rdquo; (LOTL) practices, which utilize the same legitimate tools and capabilities of compromised systems to achieve adverse outcomes. While many classes of cyber-attack are utilizing specially crafted malware, LOTL techniques are highly targeted, well-informed attacks that can be difficult to detect. In this way, latent capability and intended functionality of a system can be used as a weapon that is particularly difficult to defend against. Systems engineered utilizing CIE principles or other cybersecurity design tools are best prepared to reduce both the attack surface and the potential consequence of compromise.\u003c/p\u003e\n\u003ch1 id=\"3-breaking-down-the-security-silo\"\u003e3. Breaking Down the Security Silo\u003c/h1\u003e\n\u003cp\u003eHistorically, nuclear security has been applied after the safety analysis has identified systems depended on to ensure protection from theft, radiological release, and other high consequence events. Cybersecurity is applied in a graded approach dependent on the criticality of a digital system or asset, that is, its role and potential for negative consequence if compromised. Security measures are then applied to protect the identified asset. This approach can be illustrated by imagining a series of safety barriers, such as may be identified on a bow tie diagram. Consider that those safety barriers rely on the trusted operation of digital technology, e.g. to detect over-temperature or over-pressure and actuate a valve in response. It would appear to be reasonable to task the computer security team to protect that digital technology in such a way that it can be trusted to operate. However, in practice, this kind of protection cannot be easily applied to the control system without considering its engineering design. The computer security team would be limited to applying a selection of computer security measures to protect individual computer based systems, in a node-by-node approach, from rudimentary attacks. Instead, the control system needs to be designed to make attacks more intrinsically difficult, supporting the preservation of the function it\u0026rsquo;s performing and the role it contributes to in defence in depth, while maintaining its legitimate capabilities. This security-by-design approach involves a close collaboration between those designing the control system and those who understand adversarial capabilities.\u003c/p\u003e\n\u003cp\u003eFurther, this node-by-node approach is insufficient because there may be multi-node attacks in which the adversary misuses the legitimate capabilities of the control system, simultaneously across multiple nodes, to create modes of operation that were never considered; for example, dynamic physical phenomena resulting from the control system opening and closing valves as fast as possible in an orchestrated way. Multiple nodes may be induced to fail simultaneously in other ways. Digital technology is often built from commodity components, such as commonly used integrated circuits, and commodity software, such as commonly used low-level library functions. These can lead to common modes of failure but may also contain common but undiscovered security vulnerabilities. Once these are discovered by an adversary, they can create a loss of diversity or defence-in-depth, such as in independent reactor protection systems that have an unrecognised common security vulnerability.\u003c/p\u003e\n\u003cp\u003eOrganisations can foster a more integrated and resilient approach to risk management by framing security measures as mechanisms to preserve these functions against malicious action. This is a profoundly different approach for many conventional cyber security teams, who are taught to defend the digital assets against recognized forms of adversary action, hunting threats, looking for indicators of compromise, etc. Arguably, in the mode prevalent understanding of cyber security, the team does not adapt their focus to be on the specific purpose, (e.g., the function of the digital technology), but rather unknowingly adopts the more widespread industry focus of securing the confidentiality, integrity, and availability of information. In a more integrated approach, the cyber security teams must help design the control systems to maintain the design function and keep the system within its design basis, given what they know about adversarial means and motives. Whereas safety analysis is concerned with the physics of interaction energy, the challenge for security-by-design engineering lies in focusing on the much wider question of \u0026ldquo;what is credible malicious intent and capability, given what I know about the design basis of the system?\u0026rdquo;\u003c/p\u003e\n\u003ch2 id=\"31-demystifying-cybersecurity-for-engineering-and-operation\"\u003e3.1. Demystifying Cybersecurity for Engineering and Operation\u003c/h2\u003e\n\u003cp\u003eEarly operational technology (OT) security had significant challenge of raising cybersecurity awareness and dispelling myths such as the \u0026ldquo;air gap\u0026rdquo; isolation and \u0026ldquo;security through obscurity\u0026rdquo;. As cyber-attacks become more prevalent, rising in both frequency and severity, digital security has emerged as a high priority in both design and operation. The rapidly evolving pace of both system software functionality and threat capability often places cybersecurity risk mitigation in a reactionary state, or a position where it can be difficult to allocate resources towards the risk reduction of legacy systems while addressing emerging threat and newly discovered vulnerability.\u003c/p\u003e\n\u003cp\u003eIn the design of new advanced and SMR reactors, security-by-design is a driving paradigm in the process of adoption into industry best practice and regulatory requirements. Again, throughout the design process, good general cyber awareness has reinforced many good engineering practices such as limiting reliance on active systems. However, good engineering practice without cybersecurity expertise can and has led to reliance on ill-informed assumptions or poor implementation of security measures. Use of weak or improper encryption, high-impact vulnerabilities in a device\u0026rsquo;s physical security such as maintenance ports, vulnerability in the storage and protection of critical firmware, or misconfiguration in isolation implementation all represent just a few subtle digital risks that may evade due diligence while credited towards defence-in-depth by safety engineering analysis and design. Strong communication links between both safety and engineering can ensure the highest potential consequence events and critical facility functions are identified, and the selected security controls and design requirements are best tailored to mitigate those risks. Early successful efforts in this space have leveraged cybersecurity subject matter expertise within system design reviews, establishing functional requirements, and preliminary vulnerability assessment. Towards the long-term solution, greater incorporation of digital control system with engineering curricula lay a foundational skillset for engineering modern digital systems. Ongoing research and development includes enhancing the capability of commonly used engineering analysis to include modelling maloperation effects, such as improper actuation of physical equipment, including pumps, valves, or motors.\u003c/p\u003e\n\u003ch2 id=\"32-digital-twins-and-machine-learning-applications\"\u003e3.2. Digital Twins and Machine Learning Applications\u003c/h2\u003e\n\u003cp\u003eIt has been stated that some SMR designs and operating methodologies will only be financially viable if they can use more advanced digital technology than has been used in previous reactor control systems. These include greater use of sensors, in both number and granularity of the information collected, to allow the inference of physical parameters that cannot be measured directly. Machine learning algorithms may be used to accomplish these tasks. More advanced algorithms that use digital twins with machine learning may offer improved efficiencies in reactor operation, more accurate predictive maintenance, lower demands on human operators, etc. However, design teams must consider the new opportunities for the adversary to cause loss of visibility or loss of control of physical phenomena by maliciously manipulating these algorithms. This example illustrates how far effective cyber security needs to move from simply defending the digital technology assets that support safety barriers.\u003c/p\u003e\n\u003cp\u003eWhile digital twins provide a valuable simulation environment, it is worth noting that without robust model training using facility-specific datasets, these may fail at capturing emergent transient behaviour. Typical training sets rely on recorded data from the real operation of nuclear power plants from sensors distributed throughout the process, or by simplified physics models coupled with powerful numerical solvers. In the case of the observed data, sufficiently off-normal conditions may push the model outside of the training data set, or even slight variations in input data might greatly reduce the likelihood the model will provide the desired capability close to the bounds established in its original training conditions. In the case of the interactive physics model, inevitably some critical boundary conditions and assumptions will be incorporated which may cause the failure to predict certain rare phenomena.\u003c/p\u003e\n\u003ch2 id=\"33-model-based-system-engineering\"\u003e3.3. Model Based System Engineering\u003c/h2\u003e\n\u003cp\u003eMany vendors use model-based systems engineering (MBSE) tools to manage the design and construction of advanced reactors. MBSE utilizes models as a central tool for designing and implementing complex systems throughout the systems engineering lifecycle, from conceptual design to decommissioning or disposal. Formal MBSE tools merge a model, systems thinking, and systems engineering to graphically represent the boundaries, context, and behaviour of interconnected systems to enable successful design, development, and use of engineered systems throughout the lifecycle.\u003c/p\u003e\n\u003cp\u003eThe model represents the entire system or system of systems to provide a visual representation of requirements, structure, behaviour, and more. It can be used to integrate simulation and analysis techniques (e.g., multi-physics, computational fluid dynamics, finite element analysis, digital twins), computer-aided design (CAD), piping and instrumentation drawings (P\u0026amp;ID), trade-off analyses, performance testing, verification and validation, configuration management/version control, requirements management, and other project management capabilities. MBSE provides a common language for communication between all stakeholders in the development process; all disciplines involved in the project can view the complex relationships in a system to better make informed decisions. The ability to provide a holistic view of individual components as well as their interactions and dependencies enables better communication of complex ideas across diverse teams and disciplines. These tools, however, often are focused on functionality, performance, and safety and do not incorporate additional concerns introduced by use of OT.\u003c/p\u003e\n\u003cp\u003eMost, if not all, MBSE tools have the capability to add digital risk and cybersecurity requirements as additional requirements into the tool. However, it was shown through a survey of advanced reactor vendors performed by the authors that they do not currently do so or know how to do so. With the existing U.S. nuclear fleet, cybersecurity controls were \u0026lsquo;bolt-on\u0026rsquo; NRC requirements after 9-11. However, we have seen with CIE and security-by-design approaches that eliminating digital risk concerns (both adversarial and non-adversarial) or designing in digital risk controls/mitigations can lead to a better security posture against adversarial threats and reduce impacts from non-adversarial threats, such as human performance errors, common cause failures, equipment degradation, and environmental issues.\u003c/p\u003e\n\u003ch1 id=\"4-conclusions\"\u003e4. Conclusions\u003c/h1\u003e\n\u003cp\u003eDesign Basis Threat, scenario development, threat hunting, and \u0026ldquo;active\u0026rdquo; cybersecurity techniques will continue to remain important components of overall security posture. However, as modern SMR design looks to deliver assurance of digitally enabled critical functions, improvement in the interface between safety and security engineering is vitally important to reduce costly and ineffective duplication of analysis, and most effectively reduce overall risk early. This shift in perspective necessitates revaluation of current practices to provide for the development of new tools, techniques, and ways of working that encourage collaboration across traditionally separate domains to enable SMR designers, regulators, and operators to fully leverage the potential of complex digital technologies while ensuing both safety and security. The integration of digital risk management and cybersecurity-by-design capabilities into these tools will provide an improved process for ensuring reactors are built with safety and security in mind. The adoption of a security inclusive approach to nuclear digital engineering projects will support the integrated requirements, design, analysis, verification, and validation necessary to integrate safety, security, and resilience from unintentional digital incidents into the overall functional design.\u003c/p\u003e\n\u003ch1 id=\"5-references\"\u003e5. References\u003c/h1\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eCIE Implementation Guide, August 2023, INL/RPT-23-74072, US Department of Energy, Office of Cybersecurity, Energy, Security, and Emergency Response.\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This article has been adapted verbatim from a paper accepted and presented during the International Conference on Small Modular Reactors and their Applications titled ‘Approaches for Comprehensive Safety and Digital Risk Management for Advanced Nuclear Technology and Small Modular Reactors’ authored by Joseph Mahanes, Bob Anderson, Shannon Eggers, Mike StJohn-Green and myself.\nAbstract Small Modular Reactor (SMR) designs are likely to rely on complex digital technology novel to nuclear industry applications while also leveraging passive systems and safety design simplification. The result of current approaches may lead to a safety-driven system design that lacks demonstrated robustness in the event of cyber-attacks against its digital equipment. Information and computer security should be an integral part of engineering and operational processes. Current safety and security thinking does not encourage sufficient interaction. Teams are often separate and management structures reinforce this separation. This paper provides a case for cybersecurity related safety and digital engineering security requirements to be considered together throughout design, licensing, and operation. Safety envelope boundaries may be expressed using many variables and suitably defined system theoretic models can be used to alert whether due to faults, failures, or malicious action. This provides a unifying “top down” framework for digital systems and approaches supporting and implementing safety and security requirements. This paper will identify existing work supporting this closer relationship. However, new tools, techniques, and ways of working need developing to enable SMR designers, regulators and operators to employ complex digital technology in a way that remains both safe and secure.\n1. Introduction Traditional approaches to safety, security, and information security within the nuclear industry operate in silos, with distinct teams and management structures that do not sufficiently encourage a holistic approach to risk management. This segregation leads to a fragmented understanding of threats, vulnerabilities, and responsibilities potentially overlooking the interdependencies between safety and security objectives. Risk is the common language through which these and other different engineering disciplines and stakeholders evaluate design decisions, as well as how potentially conflicting priorities are arbitrated. Digital risk encompasses both adversarial threats such as a cyber attacker and non-adversarial threats such as human performance errors and equipment failure or misconfiguration. A comprehensive consideration of the possible risks posed by maloperation of digital equipment bridges the typically threat-focused risk mitigation in security engineering, and the phenomena driven risk mitigation of safety engineering. Digital innovations introduce nuanced challenges in risk management, particularly regarding the use of new and emerging digital systems and technologies that will play integral roles in operations, safety, and security, while potentially revealing gaps in current approaches that may lead to a system design that lacks demonstrated robustness to cyber-attacks.\nA barrier to the successful deployment of SMRs is risk communication and regulatory acceptance. Many SMRs leverage mature and existing nuclear reactor design aspects to reduce the overall potential negative consequence of safety and security scenarios. These practices more effectively treat risk early in the engineering process where certain choices can eliminate or significantly reduce potential failures or attack pathways and can reduce the high operational costs associated with “bolt-on” security practices. Significant improvements in ensuring the critical functions of preserving radiological barriers, safe shutdown and continued safe shutdown,, and heat removal through advanced fuels, such as used in gas-cooled SMRs, and inherent safety features in light water cooled reactors (LWRs) with extensive natural circulation cooling capabilities. As SMR technology progress into licensing and operation, the question remains whether these designs have sufficiently demonstrated to licensing entities the due diligence, enabling a smaller safety systems footprint, physical protection guard force scaled from traditional large multi-reactor sites, and advancing the safe and secure adoption of digital technologies in ways previously not considered in the nuclear industry.\nTraditional safety analysis draws a bounding envelope of operation through a series of analyses enumerating normal operation modes and expected challenges, which is then accepted by a regulatory body. These analyses utilize physics-based codes to model and understand the potential energy sources which must be contained, such as kinetic energy from high mass objects, chemical potential energy, criticality of nuclear material, radiation from radiological material, highly pressurized systems, high temperature systems and other energy sources. The challenge of the safety and security intersection can be expressed similarly as the potential for digital systems to interact adversely with these same high potential energy systems. One concern with the design and construction of new SMRs/MRs is that design teams will not address digital risk management or cybersecurity early enough in the systems engineering lifecycle. Another concern is that large, multi-teamed design projects will not bring in cybersecurity and digital risk as a separate discipline which can lead to conflicts with requirements, potentially leading to functional, safety, reliability, or security issues. Model Based Systems Engineering (MBSE) helps to bridge that gap, by bringing all disciplines together and addressing digital risk management starting early in the systems engineering lifecycle.\n2. Breaking Down the Safety Silo Good safety design has independently arrived at many of the same conclusions for best practice as cybersecurity, such as favouring reliance on passive systems, design simplification, layered defences and more. The result is a safety-driven system design that while often offering limited incidental robustness in event of cyber-attacks, lacks any approach to protecting the digital systems responsible for managing high energy and high potential impact consequences resulting from intentional maloperation. The ultimate reliability objective of a system for cybersecurity is the preservation of the correct performance of a vital function, even in the face of malicious compromise of one or more digital systems contributing to the performance of that function. For example, preserving a cooling loop’s ability to remove heat from a system may be reliably maintained through combinations of non-digital alternative operation means, fail-safe process design, and capability to redeploy a known good configuration in an isolated mode. In this example, even if an adversary were to gain control of the system, no combination of actions can push the process outside of its safety envelope. This result requires not just a good understanding of the process and governing physics, but also the entire range of capability of the responsible control systems, and the capability of maloperation.\nOne such example of integrating security and engineering is Cyber-Informed Engineering (CIE), a US Department of Energy national strategy that encourages “secure-by-design” concepts to include the engineering of cyber-physical systems. This approach creates opportunities for engineering teams to secure digital systems using physics and mechanics of engineering controls 1. This methodology to integrate security has been applied to projects across critical infrastructure sectors. Benefits have primarily been building communication pathways between different engineering teams, and incorporating cybersecurity as not only a major contributor within the entire systems engineering team, but also the awareness that cybersecurity is necessary as a major engineering discipline during conceptual, requirements, and detailed design phases that allow for an “engineered” approach to cyber risk reduction. More importantly, projects have eliminated potential attack pathways and reduce consequence of compromise. Successful integration of cybersecurity requirements and design considerations have been applied to advanced reactor projects and ongoing research and development in support of nuclear SMRs. One example is the implementation of data encryption in OT systems. Often, encryption can be a challenge as a perceived complication in the availability of digital assets. By integrating cybersecurity into the requirements and design phase, one potential option for cryptography clearly best satisfied both functional and cybersecurity requirements. This potentially mitigated costly revisions or less effective options that would require additional controls. This example demonstrated to the safety engineers that securing digital equipment was much more efficient if security was core to the design. Other benefits of this approach include encouraging “outside the box” thinking about how an adversary could use potential digital assets in a manner not thought of for malicious goals. A standalone wireless gas supply system located outside the facility was identified as a potential jump point into the plant with or without insider help. Typically, safety does not think adversarial, however, the inclusion of security during the design process helped reduce the need for last minute bolt-on controls especially when bolt-on controls may not be possible.\nThe entire goal of CIE and “security-by-design” is to include all engineering disciplines, including historically siloed disciplines such as safety, to identify and design the most robust, functionally secure systems that can anticipate, as much as possible, adversarial threat tactics, techniques, and procedures (TTP). Ideally, incorporating security-by-design into the engineering process will extend the longevity of a design to, at a maximum, prevent the continuously adaptive adversary TTP’s ability to overtake a system and, at a minimum, alert operators before a security event or incident compromises nuclear security.\nAdditionally, recent TTPs have increasingly expanded to leverage “Living-off-the-land” (LOTL) practices, which utilize the same legitimate tools and capabilities of compromised systems to achieve adverse outcomes. While many classes of cyber-attack are utilizing specially crafted malware, LOTL techniques are highly targeted, well-informed attacks that can be difficult to detect. In this way, latent capability and intended functionality of a system can be used as a weapon that is particularly difficult to defend against. Systems engineered utilizing CIE principles or other cybersecurity design tools are best prepared to reduce both the attack surface and the potential consequence of compromise.\n3. Breaking Down the Security Silo Historically, nuclear security has been applied after the safety analysis has identified systems depended on to ensure protection from theft, radiological release, and other high consequence events. Cybersecurity is applied in a graded approach dependent on the criticality of a digital system or asset, that is, its role and potential for negative consequence if compromised. Security measures are then applied to protect the identified asset. This approach can be illustrated by imagining a series of safety barriers, such as may be identified on a bow tie diagram. Consider that those safety barriers rely on the trusted operation of digital technology, e.g. to detect over-temperature or over-pressure and actuate a valve in response. It would appear to be reasonable to task the computer security team to protect that digital technology in such a way that it can be trusted to operate. However, in practice, this kind of protection cannot be easily applied to the control system without considering its engineering design. The computer security team would be limited to applying a selection of computer security measures to protect individual computer based systems, in a node-by-node approach, from rudimentary attacks. Instead, the control system needs to be designed to make attacks more intrinsically difficult, supporting the preservation of the function it’s performing and the role it contributes to in defence in depth, while maintaining its legitimate capabilities. This security-by-design approach involves a close collaboration between those designing the control system and those who understand adversarial capabilities.\nFurther, this node-by-node approach is insufficient because there may be multi-node attacks in which the adversary misuses the legitimate capabilities of the control system, simultaneously across multiple nodes, to create modes of operation that were never considered; for example, dynamic physical phenomena resulting from the control system opening and closing valves as fast as possible in an orchestrated way. Multiple nodes may be induced to fail simultaneously in other ways. Digital technology is often built from commodity components, such as commonly used integrated circuits, and commodity software, such as commonly used low-level library functions. These can lead to common modes of failure but may also contain common but undiscovered security vulnerabilities. Once these are discovered by an adversary, they can create a loss of diversity or defence-in-depth, such as in independent reactor protection systems that have an unrecognised common security vulnerability.\nOrganisations can foster a more integrated and resilient approach to risk management by framing security measures as mechanisms to preserve these functions against malicious action. This is a profoundly different approach for many conventional cyber security teams, who are taught to defend the digital assets against recognized forms of adversary action, hunting threats, looking for indicators of compromise, etc. Arguably, in the mode prevalent understanding of cyber security, the team does not adapt their focus to be on the specific purpose, (e.g., the function of the digital technology), but rather unknowingly adopts the more widespread industry focus of securing the confidentiality, integrity, and availability of information. In a more integrated approach, the cyber security teams must help design the control systems to maintain the design function and keep the system within its design basis, given what they know about adversarial means and motives. Whereas safety analysis is concerned with the physics of interaction energy, the challenge for security-by-design engineering lies in focusing on the much wider question of “what is credible malicious intent and capability, given what I know about the design basis of the system?”\n3.1. Demystifying Cybersecurity for Engineering and Operation Early operational technology (OT) security had significant challenge of raising cybersecurity awareness and dispelling myths such as the “air gap” isolation and “security through obscurity”. As cyber-attacks become more prevalent, rising in both frequency and severity, digital security has emerged as a high priority in both design and operation. The rapidly evolving pace of both system software functionality and threat capability often places cybersecurity risk mitigation in a reactionary state, or a position where it can be difficult to allocate resources towards the risk reduction of legacy systems while addressing emerging threat and newly discovered vulnerability.\nIn the design of new advanced and SMR reactors, security-by-design is a driving paradigm in the process of adoption into industry best practice and regulatory requirements. Again, throughout the design process, good general cyber awareness has reinforced many good engineering practices such as limiting reliance on active systems. However, good engineering practice without cybersecurity expertise can and has led to reliance on ill-informed assumptions or poor implementation of security measures. Use of weak or improper encryption, high-impact vulnerabilities in a device’s physical security such as maintenance ports, vulnerability in the storage and protection of critical firmware, or misconfiguration in isolation implementation all represent just a few subtle digital risks that may evade due diligence while credited towards defence-in-depth by safety engineering analysis and design. Strong communication links between both safety and engineering can ensure the highest potential consequence events and critical facility functions are identified, and the selected security controls and design requirements are best tailored to mitigate those risks. Early successful efforts in this space have leveraged cybersecurity subject matter expertise within system design reviews, establishing functional requirements, and preliminary vulnerability assessment. Towards the long-term solution, greater incorporation of digital control system with engineering curricula lay a foundational skillset for engineering modern digital systems. Ongoing research and development includes enhancing the capability of commonly used engineering analysis to include modelling maloperation effects, such as improper actuation of physical equipment, including pumps, valves, or motors.\n3.2. Digital Twins and Machine Learning Applications It has been stated that some SMR designs and operating methodologies will only be financially viable if they can use more advanced digital technology than has been used in previous reactor control systems. These include greater use of sensors, in both number and granularity of the information collected, to allow the inference of physical parameters that cannot be measured directly. Machine learning algorithms may be used to accomplish these tasks. More advanced algorithms that use digital twins with machine learning may offer improved efficiencies in reactor operation, more accurate predictive maintenance, lower demands on human operators, etc. However, design teams must consider the new opportunities for the adversary to cause loss of visibility or loss of control of physical phenomena by maliciously manipulating these algorithms. This example illustrates how far effective cyber security needs to move from simply defending the digital technology assets that support safety barriers.\nWhile digital twins provide a valuable simulation environment, it is worth noting that without robust model training using facility-specific datasets, these may fail at capturing emergent transient behaviour. Typical training sets rely on recorded data from the real operation of nuclear power plants from sensors distributed throughout the process, or by simplified physics models coupled with powerful numerical solvers. In the case of the observed data, sufficiently off-normal conditions may push the model outside of the training data set, or even slight variations in input data might greatly reduce the likelihood the model will provide the desired capability close to the bounds established in its original training conditions. In the case of the interactive physics model, inevitably some critical boundary conditions and assumptions will be incorporated which may cause the failure to predict certain rare phenomena.\n3.3. Model Based System Engineering Many vendors use model-based systems engineering (MBSE) tools to manage the design and construction of advanced reactors. MBSE utilizes models as a central tool for designing and implementing complex systems throughout the systems engineering lifecycle, from conceptual design to decommissioning or disposal. Formal MBSE tools merge a model, systems thinking, and systems engineering to graphically represent the boundaries, context, and behaviour of interconnected systems to enable successful design, development, and use of engineered systems throughout the lifecycle.\nThe model represents the entire system or system of systems to provide a visual representation of requirements, structure, behaviour, and more. It can be used to integrate simulation and analysis techniques (e.g., multi-physics, computational fluid dynamics, finite element analysis, digital twins), computer-aided design (CAD), piping and instrumentation drawings (P\u0026ID), trade-off analyses, performance testing, verification and validation, configuration management/version control, requirements management, and other project management capabilities. MBSE provides a common language for communication between all stakeholders in the development process; all disciplines involved in the project can view the complex relationships in a system to better make informed decisions. The ability to provide a holistic view of individual components as well as their interactions and dependencies enables better communication of complex ideas across diverse teams and disciplines. These tools, however, often are focused on functionality, performance, and safety and do not incorporate additional concerns introduced by use of OT.\nMost, if not all, MBSE tools have the capability to add digital risk and cybersecurity requirements as additional requirements into the tool. However, it was shown through a survey of advanced reactor vendors performed by the authors that they do not currently do so or know how to do so. With the existing U.S. nuclear fleet, cybersecurity controls were ‘bolt-on’ NRC requirements after 9-11. However, we have seen with CIE and security-by-design approaches that eliminating digital risk concerns (both adversarial and non-adversarial) or designing in digital risk controls/mitigations can lead to a better security posture against adversarial threats and reduce impacts from non-adversarial threats, such as human performance errors, common cause failures, equipment degradation, and environmental issues.\n4. Conclusions Design Basis Threat, scenario development, threat hunting, and “active” cybersecurity techniques will continue to remain important components of overall security posture. However, as modern SMR design looks to deliver assurance of digitally enabled critical functions, improvement in the interface between safety and security engineering is vitally important to reduce costly and ineffective duplication of analysis, and most effectively reduce overall risk early. This shift in perspective necessitates revaluation of current practices to provide for the development of new tools, techniques, and ways of working that encourage collaboration across traditionally separate domains to enable SMR designers, regulators, and operators to fully leverage the potential of complex digital technologies while ensuing both safety and security. The integration of digital risk management and cybersecurity-by-design capabilities into these tools will provide an improved process for ensuring reactors are built with safety and security in mind. The adoption of a security inclusive approach to nuclear digital engineering projects will support the integrated requirements, design, analysis, verification, and validation necessary to integrate safety, security, and resilience from unintentional digital incidents into the overall functional design.\n5. References CIE Implementation Guide, August 2023, INL/RPT-23-74072, US Department of Energy, Office of Cybersecurity, Energy, Security, and Emergency Response. ↩︎\n","date_published":"2024-10-23T17:00:00+03:00","id":"https://blog.mitcdh.au/posts/advanced-nuclear-digital-risk-management/","image":"https://blog.mitcdh.au/images/advanced-nuclear-digital-risk-management.webp","summary":"For Advanced Nuclear Technology and Small Modular Reactors","tags":["Writing","Nuclear","Technology","Security","Safety"],"title":"Approaches for Comprehensive Safety and Digital Risk Management","url":"https://blog.mitcdh.au/posts/advanced-nuclear-digital-risk-management/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-10-20T05:24:00Z","id":"https://blog.mitcdh.au/posts/seoul-gangnam-style-south-korea/","image":"https://blog.mitcdh.au/images/seoul-gangnam-style-south-korea.jpg","summary":"...Boombayah!","tags":["Album"],"title":"Seoul Gangnam Style, South Korea","url":"https://blog.mitcdh.au/posts/seoul-gangnam-style-south-korea/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-10-12T17:31:16Z","id":"https://blog.mitcdh.au/posts/kaiserwiesngeburstagsfest-ii/","image":"https://blog.mitcdh.au/images/kaiserwiesngeburstagsfest-ii.jpg","summary":"We came for the Bier, and stayed for the Bier!","tags":["Album"],"title":"Kaiserwiesngeburstagsfest II","url":"https://blog.mitcdh.au/posts/kaiserwiesngeburstagsfest-ii/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-10-06T17:37:56Z","id":"https://blog.mitcdh.au/posts/schlossing-around-in-laxenburg-austria/","image":"https://blog.mitcdh.au/images/schlossing-around-in-laxenburg-austria.jpg","summary":"Who needs a castle in the clouds when you can have one on a lake? Schlosspark Laxenburg has you covered!","tags":["Album"],"title":"Schlossing Around in Laxenburg, Austria","url":"https://blog.mitcdh.au/posts/schlossing-around-in-laxenburg-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-09-22T18:40:16Z","id":"https://blog.mitcdh.au/posts/a-day-at-the-tiergarten-in-vienna-austria/","image":"https://blog.mitcdh.au/images/a-day-at-the-tiergarten-in-vienna-austria.jpg","summary":"Quick Sunday evening stroll through the palace gardens and Schönbrunn Zoo.","tags":["Album"],"title":"A Day at the Tiergarten in Vienna, Austria","url":"https://blog.mitcdh.au/posts/a-day-at-the-tiergarten-in-vienna-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-09-17T17:04:37Z","id":"https://blog.mitcdh.au/posts/prunksaal-der-osterreichischen-nationalbibliothek-in-vienna-austria/","image":"https://blog.mitcdh.au/images/prunksaal-der-osterreichischen-nationalbibliothek-in-vienna-austria.jpg","summary":"Towering walnut shelves stretch towards the gilded ceiling, their ornate carvings alive with imperial heraldry. Tomes of questionable age line these shelves, leather-bound spines adorned with titles in languages both familiar and antique. The scent mingles with the acrid tang of ink and the sweet decay of paper, enticing even the most disciplined minds to sway to the siren song of knowledge.","tags":["Album"],"title":"Prunksaal der Österreichischen Nationalbibliothek in Vienna, Austria","url":"https://blog.mitcdh.au/posts/prunksaal-der-osterreichischen-nationalbibliothek-in-vienna-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-09-16T10:55:35Z","id":"https://blog.mitcdh.au/posts/iaea-general-conference-in-vienna-austria/","image":"https://blog.mitcdh.au/images/iaea-general-conference-in-vienna-austria.jpg","summary":"","tags":["Album"],"title":"IAEA General Conference in Vienna, Austria","url":"https://blog.mitcdh.au/posts/iaea-general-conference-in-vienna-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-09-14T17:45:31Z","id":"https://blog.mitcdh.au/posts/naturhistorisches-museum-in-vienna-austria/","image":"https://blog.mitcdh.au/images/naturhistorisches-museum-in-vienna-austria.jpg","summary":"Crossing the threshold of Vienna's Naturhistorisches Museum, you're enveloped by shadows of bygone eras, where time-worn cabinets whisper secrets of ancient worlds. In this labyrinth of forgotten lore, each display case is a window to primordial realms, beckoning you to lose yourself in the depths of our mysterious past.","tags":["Album"],"title":"Naturhistorisches Museum in Vienna, Austria","url":"https://blog.mitcdh.au/posts/naturhistorisches-museum-in-vienna-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-09-08T16:54:01Z","id":"https://blog.mitcdh.au/posts/hiking-weekend-in-oberosterreich-austria/","image":"https://blog.mitcdh.au/images/hiking-weekend-in-oberosterreich-austria.jpg","summary":"Conquering peaks crowned with Gipfelkreuze, climbing through narrow Klamms carved by glacial streams, and savouring breathtaking views of the glistening alpine lakes nestled below.","tags":["Album"],"title":"Hiking Weekend in Oberösterreich, Austria","url":"https://blog.mitcdh.au/posts/hiking-weekend-in-oberosterreich-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-09-05T19:44:30Z","id":"https://blog.mitcdh.au/posts/summer-in-vienna-austria/","image":"https://blog.mitcdh.au/images/summer-in-vienna-austria.jpg","summary":"Work less and enjoy the sun, winter is coming!","tags":["Album"],"title":"Summer in Vienna, Austria","url":"https://blog.mitcdh.au/posts/summer-in-vienna-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-08-20T13:26:49Z","id":"https://blog.mitcdh.au/posts/hebdon-bridge-and-halifax-england/","image":"https://blog.mitcdh.au/images/hebdon-bridge-and-halifax-england.jpg","summary":"From the hills of Halifax to the mills of Hebden Bridge. Where the rugged beauty of the Pennines meets the industrial heritage of the North.","tags":["Album"],"title":"Hebdon Bridge and Halifax, England","url":"https://blog.mitcdh.au/posts/hebdon-bridge-and-halifax-england/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-08-19T17:38:01Z","id":"https://blog.mitcdh.au/posts/day-trip-to-york-england/","image":"https://blog.mitcdh.au/images/day-trip-to-york-england.jpg","summary":"Old york, old york, it's a hell of a town. The shambles look like they're about to fall down!","tags":["Album"],"title":"Day Trip to York, England","url":"https://blog.mitcdh.au/posts/day-trip-to-york-england/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-08-18T18:04:54Z","id":"https://blog.mitcdh.au/posts/ale-trail-from-halifax-to-sowerby-bridge-england/","image":"https://blog.mitcdh.au/images/ale-trail-from-halifax-to-sowerby-bridge-england.jpg","summary":"Cheers mate!","tags":["Album"],"title":"Ale Trail from Halifax to Sowerby Bridge, England","url":"https://blog.mitcdh.au/posts/ale-trail-from-halifax-to-sowerby-bridge-england/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-07-19T20:15:56Z","id":"https://blog.mitcdh.au/posts/sailing-on-hulya-esmerelda-greece/","image":"https://blog.mitcdh.au/images/sailing-on-hulya-esmerelda-greece.jpg","summary":"Don't mix up the sunscreen and tzatziki!","tags":["Album"],"title":"Sailing on Hülya Esmerelda, Greece","url":"https://blog.mitcdh.au/posts/sailing-on-hulya-esmerelda-greece/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-06-17T03:40:46Z","id":"https://blog.mitcdh.au/posts/snake-river-and-tetons-usa/","image":"https://blog.mitcdh.au/images/snake-river-and-tetons-usa.jpg","summary":"Keep your hands and children inside the boat. Or not!","tags":["Album"],"title":"Snake River and Tetons, USA","url":"https://blog.mitcdh.au/posts/snake-river-and-tetons-usa/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-06-16T05:00:45Z","id":"https://blog.mitcdh.au/posts/yellowstone-national-park-usa/","image":"https://blog.mitcdh.au/images/yellowstone-national-park-usa.jpg","summary":"The only national park where you don't ride the bison; the bison ride you.","tags":["Album"],"title":"Yellowstone National Park, USA","url":"https://blog.mitcdh.au/posts/yellowstone-national-park-usa/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-06-02T10:49:32Z","id":"https://blog.mitcdh.au/posts/summersplash-in-steiermark-austria/","image":"https://blog.mitcdh.au/images/summersplash-in-steiermark-austria.jpg","summary":"Servas Hawara","tags":["Album"],"title":"Summersplash in Steiermark, Austria","url":"https://blog.mitcdh.au/posts/summersplash-in-steiermark-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-05-16T14:32:03Z","id":"https://blog.mitcdh.au/posts/bringing-ic-together-in-budapest-hungary/","image":"https://blog.mitcdh.au/images/bringing-ic-together-in-budapest-hungary.jpg","summary":"Unicum. What more needs to be said?","tags":["Album"],"title":"Bringing I\u0026C Together in Budapest, Hungary","url":"https://blog.mitcdh.au/posts/bringing-ic-together-in-budapest-hungary/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-05-04T19:07:13Z","id":"https://blog.mitcdh.au/posts/romance-in-rome-italy/","image":"https://blog.mitcdh.au/images/romance-in-rome-italy.jpg","summary":"Sodalitas·Romae·Inventa","tags":["Album"],"title":"Romance in Rome, Italy","url":"https://blog.mitcdh.au/posts/romance-in-rome-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-04-13T14:12:14Z","id":"https://blog.mitcdh.au/posts/getaway-to-valletta-malta/","image":"https://blog.mitcdh.au/images/getaway-to-valletta-malta.jpg","summary":"Nothing teases like Malteasers!","tags":["Album"],"title":"Getaway to Valletta, Malta","url":"https://blog.mitcdh.au/posts/getaway-to-valletta-malta/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-03-19T18:11:56Z","id":"https://blog.mitcdh.au/posts/the-baths-of-gymea-bay-australia/","image":"https://blog.mitcdh.au/images/the-baths-of-gymea-bay-australia.jpg","summary":"I learnt how to swim here... and also avoid stingrays. 'Straya.","tags":["Album"],"title":"The Baths of Gymea Bay, Australia","url":"https://blog.mitcdh.au/posts/the-baths-of-gymea-bay-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-03-19T14:29:02Z","id":"https://blog.mitcdh.au/posts/under-the-sydney-harbour-bridge-australia/","image":"https://blog.mitcdh.au/images/under-the-sydney-harbour-bridge-australia.jpg","summary":"Why are there no trolls under the Sydney Harbour Bridge? The bridge tolls were too high in Sydney!","tags":["Album"],"title":"Under the Sydney Harbour Bridge, Australia","url":"https://blog.mitcdh.au/posts/under-the-sydney-harbour-bridge-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-03-17T16:48:10Z","id":"https://blog.mitcdh.au/posts/backyard-birds-of-gymea-bay-australia/","image":"https://blog.mitcdh.au/images/backyard-birds-of-gymea-bay-australia.jpg","summary":"Amidst the vibrant beauty of an Australian backyard, a kaleidoscope of colourful parrots delight with their lively presence as they gracefully swoop in for their daily afternoon cuppa.","tags":["Album"],"title":"Backyard Birds of Gymea Bay, Australia","url":"https://blog.mitcdh.au/posts/backyard-birds-of-gymea-bay-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-03-17T14:39:14Z","id":"https://blog.mitcdh.au/posts/exploring-nan-tien-temple-in-wollongong-australia/","image":"https://blog.mitcdh.au/images/exploring-nan-tien-temple-in-wollongong-australia.jpg","summary":"Seeking solace and connection, I embarked on a pilgrimage to the serene Buddhist temple that once provided my father a sanctuary of peace and helped to heal his grieving heart.","tags":["Album"],"title":"Exploring Nan Tien Temple in Wollongong, Australia","url":"https://blog.mitcdh.au/posts/exploring-nan-tien-temple-in-wollongong-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eMy father was a good man and I thought he would live forever, but on Monday, he passed away while I held his hand. I had flown to Australia to take him on a holiday next week and build in him the confidence to persevere as he began chemo. I had five precious days in Sydney by his side—where he was in good health, mobile, and unburdened by sickness. The end began in the morning with an ambulance, and I, along with his family and friends, spent those final hours with him as he fought to live for himself, to survive for us, and ultimately, to hold on long enough for everyone to arrive.\u003c/p\u003e\n\u003cp\u003eOne day, I will write about him and what he meant to me, but today is not that day.\u003c/p\u003e\n\u003cp\u003ePeople have been asking me what they can do to help, and I\u0026rsquo;ve had to reflect. I remembered how he, with newfound comfort from Buddhism and despite his fear of flying, travelled around the world to light candles for my sister who had tragically passed away, hoping to guide her back to him.\u003c/p\u003e\n\u003cp\u003eI don\u0026rsquo;t wish for my father to return to me; I had my chance to make my peace with him in these last days. But they never shared that chance. My only desire would be for him to find her, as he had always wanted from the minute she was taken from us.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/candles-for-dave_02.webp\" width=\"1750\" height=\"1167\" alt=\"My father holding my sister in his arms.\" loading=\"lazy\" decoding=\"async\"\u003e\n\u003c/p\u003e\n\u003cp\u003eSo I have asked everyone who has approached me to hold this second picture in their hearts—the image of her in his arms—and to light a flame, a beacon to illuminate his path. Though I am not a person of faith, this act would have held a deep meaning for him, and so it holds meaning for me as well.\u003c/p\u003e\n\u003cp\u003eAstonishingly, lights now shine on every continent, even Antarctica—a profound testament to the far-reaching impact of his life and what he inspired. Unburdened his path is clear, the way is lit by the collective love he demonstrated, a love taken, amplified, and shared around the globe.\u003c/p\u003e\n\u003cp\u003eIf you are reading this now or in the future and you could join this tribute, or share it, it would mean the world to me. Let the light burn brighter, as radiant as he lived, reflecting back to him the love he showed. He would be so happy with this outpouring of light guiding him through the darkness, leading him to where she awaits his arms once more.\u003c/p\u003e\n\u003cp\u003eCya boy 👍👍\u003c/p\u003e\n\u003cdiv class=\"gallery-box\"\u003e\r\n  \u003cdiv class=\"gallery\"\u003e\r\n    \u003cimg src=\"/images/candles-for-dave_04.webp\" width=\"720\" height=\"958\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_05.webp\" width=\"1200\" height=\"1600\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_06.webp\" width=\"1200\" height=\"1600\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_07.webp\" width=\"1280\" height=\"960\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_08.webp\" width=\"1125\" height=\"1500\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_09.webp\" width=\"1500\" height=\"2000\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_10.webp\" width=\"1403\" height=\"2048\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_11.webp\" width=\"1200\" height=\"1600\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n    \u003cimg src=\"/images/candles-for-dave_12.webp\" width=\"2048\" height=\"1536\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\r\n  \u003c/div\u003e\r\n\u003c/div\u003e\r\n\u003ch2 id=\"eulogy\"\u003eEulogy\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003eThis eulogy was delivered in memory of my father during his memorial service on March 21st, 2024, which coincided with what would have been his 66th birthday.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eI remember the day Dad set out to buy milk and returned three hours later carrying two slices of cake. A new family had moved into our local corner store, and upon learning that they had never tasted a cake before, he gathered all the necessary ingredients from the shelves and proceeded to bake a cake for them right then and there. This story encapsulates the essence of my father—a man who was not just always ready but wouldn\u0026rsquo;t even think twice about going above and beyond for others. When he helped someone, he never accepted money; instead, he asked them to pay it forward and help the next person they saw in need.\u003c/p\u003e\n\u003cp\u003eDad was multifaceted, playing different roles for each person he encountered while remaining uniquely his best self. He even liked that this could evoke strong emotions and opinions. Despite his challenges, Dad\u0026rsquo;s capacity for love and compassion knew no bounds.\u003c/p\u003e\n\u003cp\u003eWhen my sister Jodie passed away in a tragic accident, he went on a literal and figurative walk, searching for her wherever he could, seeking anything that could bring him back to her. It was a difficult time for our family, and I spent years feeling the distance between us. But even then, I knew he was always there for me—it took me time and personal growth to realise he was there for everyone.\u003c/p\u003e\n\u003cp\u003eHe spoke openly and proudly of anyone he met, treating you all like family. It didn\u0026rsquo;t matter if you were related by blood or if he had just met you sitting on a bench. He saw no distinction between us. Without hesitation, he was there for anyone who needed him, and these bonds are now irreducible. You are my family.\u003c/p\u003e\n\u003cp\u003eAs we gather here today, I want you to remember how you first met my Dad. Was it before his first \u0026ldquo;this could be it\u0026rdquo; skin cancer diagnosis 25 years ago? Or before Jodie\u0026rsquo;s passing 22 years ago? Reflect on your interactions with him since then, and realise everyone here has a similar story.\u003c/p\u003e\n\u003cp\u003eFor Dad, the small things mattered:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSmiling to improve someone\u0026rsquo;s day.\u003c/li\u003e\n\u003cli\u003eBeing there without question or expectation when you needed it.\u003c/li\u003e\n\u003cli\u003eEveryday waking up to put two thumbs up because he had one more day to spend with us all.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eHis legacy is one of breaking down barriers, not building them. He showed us the power of kindness, generosity, and unwavering love, even in the face of his own struggles. He made it all look so easy that anything less is now inconceivable. I spent five days with my Dad, still healthy, sharing this love with those around us. In the hospital, I held his hand while he struggled, not for himself, but so that everyone had the chance to arrive and say goodbye.\u003c/p\u003e\n\u003cp\u003eRemember this. Remember my father. While he goes on his long journey of the soul to be reunited with my sister, take a minute out of your life to be kind to someone, stop to help rather than walk by when someone is in need, and sincerely ask how they\u0026rsquo;re doing, then stay to listen, and strive to break down barriers, not build them. In this way, he would be proud, the world would be a better place, and maybe, in a way, my father would live forever.\u003c/p\u003e\n\u003cp\u003eI miss you. I know you thought you hurt me, but you didn\u0026rsquo;t. Your love and the person you were are the most consequential aspects of my life that have shaped me into who I am today. I won\u0026rsquo;t forget you. I\u0026rsquo;ll carry your mantra forward in all that I do. Thank you for being not just my father but for sharing that same care with so many others. You may be gone, but who you were will continue to burn brightly through all of us, lighting your way back to her once more—Cya boy.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/candles-for-dave_03.webp\" width=\"5728\" height=\"3824\" alt=\"Dad and I on his birthday.\" loading=\"lazy\" decoding=\"async\"\u003e\n\u003c/p\u003e\n\u003cdiv class=\"post-video\"\u003e\n\t\t\t\u003ciframe allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen\" loading=\"eager\" referrerpolicy=\"strict-origin-when-cross-origin\" src=\"https://www.youtube.com/embed/65WLaIXy6Ps?si=ZOJ9QL1bFtamihar?autoplay=0\u0026amp;controls=1\u0026amp;end=0\u0026amp;loop=0\u0026amp;mute=0\u0026amp;start=0\" title=\"YouTube video\"\u003e\u003c/iframe\u003e\n\t\t\u003c/div\u003e\n\n","content_text":"My father was a good man and I thought he would live forever, but on Monday, he passed away while I held his hand. I had flown to Australia to take him on a holiday next week and build in him the confidence to persevere as he began chemo. I had five precious days in Sydney by his side—where he was in good health, mobile, and unburdened by sickness. The end began in the morning with an ambulance, and I, along with his family and friends, spent those final hours with him as he fought to live for himself, to survive for us, and ultimately, to hold on long enough for everyone to arrive.\nOne day, I will write about him and what he meant to me, but today is not that day.\nPeople have been asking me what they can do to help, and I’ve had to reflect. I remembered how he, with newfound comfort from Buddhism and despite his fear of flying, travelled around the world to light candles for my sister who had tragically passed away, hoping to guide her back to him.\nI don’t wish for my father to return to me; I had my chance to make my peace with him in these last days. But they never shared that chance. My only desire would be for him to find her, as he had always wanted from the minute she was taken from us.\nSo I have asked everyone who has approached me to hold this second picture in their hearts—the image of her in his arms—and to light a flame, a beacon to illuminate his path. Though I am not a person of faith, this act would have held a deep meaning for him, and so it holds meaning for me as well.\nAstonishingly, lights now shine on every continent, even Antarctica—a profound testament to the far-reaching impact of his life and what he inspired. Unburdened his path is clear, the way is lit by the collective love he demonstrated, a love taken, amplified, and shared around the globe.\nIf you are reading this now or in the future and you could join this tribute, or share it, it would mean the world to me. Let the light burn brighter, as radiant as he lived, reflecting back to him the love he showed. He would be so happy with this outpouring of light guiding him through the darkness, leading him to where she awaits his arms once more.\nCya boy 👍👍\nEulogy This eulogy was delivered in memory of my father during his memorial service on March 21st, 2024, which coincided with what would have been his 66th birthday.\nI remember the day Dad set out to buy milk and returned three hours later carrying two slices of cake. A new family had moved into our local corner store, and upon learning that they had never tasted a cake before, he gathered all the necessary ingredients from the shelves and proceeded to bake a cake for them right then and there. This story encapsulates the essence of my father—a man who was not just always ready but wouldn’t even think twice about going above and beyond for others. When he helped someone, he never accepted money; instead, he asked them to pay it forward and help the next person they saw in need.\nDad was multifaceted, playing different roles for each person he encountered while remaining uniquely his best self. He even liked that this could evoke strong emotions and opinions. Despite his challenges, Dad’s capacity for love and compassion knew no bounds.\nWhen my sister Jodie passed away in a tragic accident, he went on a literal and figurative walk, searching for her wherever he could, seeking anything that could bring him back to her. It was a difficult time for our family, and I spent years feeling the distance between us. But even then, I knew he was always there for me—it took me time and personal growth to realise he was there for everyone.\nHe spoke openly and proudly of anyone he met, treating you all like family. It didn’t matter if you were related by blood or if he had just met you sitting on a bench. He saw no distinction between us. Without hesitation, he was there for anyone who needed him, and these bonds are now irreducible. You are my family.\nAs we gather here today, I want you to remember how you first met my Dad. Was it before his first “this could be it” skin cancer diagnosis 25 years ago? Or before Jodie’s passing 22 years ago? Reflect on your interactions with him since then, and realise everyone here has a similar story.\nFor Dad, the small things mattered:\nSmiling to improve someone’s day. Being there without question or expectation when you needed it. Everyday waking up to put two thumbs up because he had one more day to spend with us all. His legacy is one of breaking down barriers, not building them. He showed us the power of kindness, generosity, and unwavering love, even in the face of his own struggles. He made it all look so easy that anything less is now inconceivable. I spent five days with my Dad, still healthy, sharing this love with those around us. In the hospital, I held his hand while he struggled, not for himself, but so that everyone had the chance to arrive and say goodbye.\nRemember this. Remember my father. While he goes on his long journey of the soul to be reunited with my sister, take a minute out of your life to be kind to someone, stop to help rather than walk by when someone is in need, and sincerely ask how they’re doing, then stay to listen, and strive to break down barriers, not build them. In this way, he would be proud, the world would be a better place, and maybe, in a way, my father would live forever.\nI miss you. I know you thought you hurt me, but you didn’t. Your love and the person you were are the most consequential aspects of my life that have shaped me into who I am today. I won’t forget you. I’ll carry your mantra forward in all that I do. Thank you for being not just my father but for sharing that same care with so many others. You may be gone, but who you were will continue to burn brightly through all of us, lighting your way back to her once more—Cya boy.\n","date_published":"2024-03-13T14:05:55+11:00","id":"https://blog.mitcdh.au/posts/candles-for-dave/","image":"https://blog.mitcdh.au/images/candles-for-dave_01.webp","summary":"Please, lend him and I your light.","tags":["Writing","Musings"],"title":"Lighting the Way for My Father","url":"https://blog.mitcdh.au/posts/candles-for-dave/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-03-12T12:48:14Z","id":"https://blog.mitcdh.au/posts/sydney-trip-with-dave-australia/","image":"https://blog.mitcdh.au/images/sydney-trip-with-dave-australia.jpg","summary":"Exploring the vibrant streets of Sydney side-by-side, father and son.","tags":["Album"],"title":"Sydney Trip with Dave, Australia","url":"https://blog.mitcdh.au/posts/sydney-trip-with-dave-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-03-09T12:49:37Z","id":"https://blog.mitcdh.au/posts/afternoons-in-the-shire-australia/","image":"https://blog.mitcdh.au/images/afternoons-in-the-shire-australia.jpg","summary":"Basking under the Sydney sun, the waves whispering secrets to the shore, here I find relaxation and laughter with friends and family, a serene escape from the international hustle.","tags":["Album"],"title":"Afternoons in the Shire, Australia","url":"https://blog.mitcdh.au/posts/afternoons-in-the-shire-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-03-03T09:39:31Z","id":"https://blog.mitcdh.au/posts/philosophising-in-athens-greece/","image":"https://blog.mitcdh.au/images/philosophising-in-athens-greece.jpg","summary":"We came, we saw, we contemplated!","tags":["Album"],"title":"Philosophising in Athens, Greece","url":"https://blog.mitcdh.au/posts/philosophising-in-athens-greece/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eI\u0026rsquo;m excited to share an inside view of a newly released open-source training tool, which has become a significant part of our approach to advancing information and computer security training for nuclear security. Developed as a collaboration between the \u003ca href=\"https://iaea.org\"\u003eInternational Atomic Energy Agency (IAEA)\u003c/a\u003e and the \u003ca href=\"https://www.ait.ac.at/\"\u003eAustrian Institute of Technology (AIT)\u003c/a\u003e, \u0026lsquo;Learners\u0026rsquo; addresses specific education challenges in information and computer security.\u003c/p\u003e\n\u003cp\u003eYou can obtain a copy freely here: \u003ca href=\"https://github.com/iaeaorg/learners\"\u003ehttps://github.com/iaeaorg/learners\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/introducing-learners_02.webp\" width=\"1920\" height=\"1200\" alt=\"Screenshot of the Learners interface\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eThe Learners interface, focus is on the content rather than the platform.\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"history-of-the-project\"\u003eHistory of the Project\u003c/h1\u003e\n\u003cp\u003eThe beginning of the Learners project is rooted in the challenges brought forth by the COVID-19 pandemic. As the world grappled with unprecedented disruptions, we recognised a need for a resilient and flexible approach to computer security training to ensure our programme could continue to deliver capacity-building outcomes. Traditional in-person sessions where participants would travel internationally for regional or international courses were not viable due to the travel restrictions and quarantine requirements.\u003c/p\u003e\n\u003cp\u003eWhile many information and computer security training providers went to virtual delivery during this same time, the cost of these courses was prohibitive to many of the beneficiaries of our training, and there were no available tools to support efficiently deploying a platform for the remote delivery of existing courses. Ultimately, rather than sending participants to courses run by third parties, we needed the ability to train in a hands-on format the concepts within the Nuclear Security Series guidance.\u003c/p\u003e\n\u003cp\u003eThe response was to build on the results of \u003ca href=\"https://www.iaea.org/projects/crp/j02008\"\u003eCRP J02008\u003c/a\u003e and initiate a new project specifically designed to facilitate hands-on technical training in a virtual environment. This project, for which I was the IAEA project lead, quickly evolved to be more than just a reaction to a temporary crisis: it was a step forward to build efficiencies into the development and delivery of our courses, being able to normalise an approach to enable sharing and remixing of training material across collaborators, and adapting to and innovating on more modern training approaches to make educational resources more accessible globally.\u003c/p\u003e\n\u003ch1 id=\"overview-of-learners-features\"\u003eOverview of Learners Features\u003c/h1\u003e\n\u003cp\u003eThe aim was to create a platform that is both practical and easy to navigate, reflecting our core approach. Here is a brief overview of how some of the design criteria were achieved:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eOpen Training Materials\u003c/strong\u003e: Technologies like \u003ca href=\"https://www.markdownguide.org/\"\u003eMarkdown\u003c/a\u003e, \u003ca href=\"https://gohugo.io/\"\u003eHugo\u003c/a\u003e, and \u003ca href=\"https://diagrams.net\"\u003ediagrams.net\u003c/a\u003e are used to create course material. As the Markdown syntax was limited, we reviewed our existing training material library and created Hugo shortcodes that allowed all of the advanced layouts we\u0026rsquo;d previously used in Word document drafted course materials.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMultilingual Capability\u003c/strong\u003e: Multilingual support was integrated to make our training accessible across different linguistic groups. Content files can be prepared in multiple languages using common resources (like images and forms), and the participants can toggle between them.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIntegration with Cyber Range Environments:\u003c/strong\u003e The ability to assign users to HTML5 VNC sessions has been embedded, with authentication tokens being proxied from the platform to facilitate practical, hands-on experience in a controlled, simulated environment.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSelf-Paced Learning and Feedback:\u003c/strong\u003e Learners generates HTML forms from training materials, and allows participants to have their responses validated upon submission. Enhanced with Venjix, the system can interrogate devices in the cyber range environment and confirm that participants have completed assigned tasks.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReal-Time Progress Monitoring:\u003c/strong\u003e Instructors can dynamically observe participant progress through a specialised admin dashboard. This feature aids in providing immediate support and intervention when necessary boosting engagement and responsiveness.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTailored Learning Experience:\u003c/strong\u003e A workbook customised to the individual\u0026rsquo;s role can be provided to each participant. This approach is convenient for training delivered in an exercise format, where each participant in a group is assigned different tasks based on their background. Instructor notes can also be integrated into the same source file, streamlining content management and ensuring consistency across materials\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eComplete Offline Functionality\u003c/strong\u003e: All tools are engineered to operate fully offline, ensuring that sensitive tools crucial for hands-on computer security training, such as those included in Kali Linux, can be utilised without the risk of exposure to public networks.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch1 id=\"the-learners-approach\"\u003eThe Learners Approach\u003c/h1\u003e\n\u003ch2 id=\"accessibility-and-scalability\"\u003eAccessibility and Scalability\u003c/h2\u003e\n\u003cp\u003ePreviously, in developing training material, many potential in-kind contributors needed Microsoft Office or Visio licenses to work on some more technical exercises. The platform was designed to operate with minimal infrastructure requirements and eliminated the need for associated software costs. This strategic approach significantly broadens the tool\u0026rsquo;s dissemination potential, ensuring that training packages are easily distributed and remixed.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/introducing-learners_03.webp\" width=\"949\" height=\"906\" alt=\"A drawio exercise in Learners\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eA drawio exercise in Learners. Participants can edit the diagram and the preview will update with their modifications.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eStatic files are at the heart of our design philosophy with Learners, emphasising plain text to maintain simplicity while allowing for modern version control. We consciously minimised complex database dependencies. The only data stored in a database are participant responses, streamlining the creation of training material. This design choice means that updating or swapping training materials is as straightforward as copying and pasting a folder, greatly simplifying content management, allowing modern version control systems to be used, and enhancing the ease and flexibility of sharing and iterating on training materials which we affectionately called \u0026ldquo;copy-paste-remix\u0026rdquo;.\u003c/p\u003e\n\u003ch2 id=\"pedagogic-considerations\"\u003ePedagogic Considerations\u003c/h2\u003e\n\u003cp\u003eIn our endeavour to preserve and enhance the educational effectiveness of our existing training courses, we focused on developing an environment that is both engaging and interactive. Our objective was to create a learning atmosphere that not only disseminates knowledge but also captivates and retains participants\u0026rsquo; interest, so we considered several ways to ensure they feel integral to the course:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eExercise Submissions\u003c/strong\u003e: Participants need the flexibility to manage their training pace and receive immediate feedback, critical factors in adult learning. We evolved the concept of a personal workbook into a more collaborative format. Submissions are not just personal records on paper but can be automatically validated, are accessible for review and presentation, promoting an environment of shared learning and collective improvement.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInteractive \u0026ldquo;Clicker\u0026rdquo;-Style Questions\u003c/strong\u003e: Multiple-choice quiz questions can be integrated directly into presentation pages. This approach not only fosters active participation and immediate feedback but delivering it through Learners, which can run entirely offline, allows maintaining this capability for environments lacking internet access or those where tools are available that should remain offline for security reasons, with no need to take a pelican case of physical clickers anymore.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIntegrated Feedback Mechanism\u003c/strong\u003e: We have implemented a system where participants can provide feedback for each exercise and presentation. This feedback is then accessible to instructors, ensuring that participants have a continuous voice throughout the course and allowing instructors to tailor their approach to their needs and responses in real-time.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEmbedding Tools and Multimedia Elements\u003c/strong\u003e: Learners can be extended with almost any web-based technology. In our courses, we\u0026rsquo;ve embedded tools like \u003ca href=\"https://mitre-attack.github.io/attack-navigator/\"\u003eMITRE\u0026rsquo;s ATT\u0026amp;CK Navigator\u003c/a\u003e, simulations like \u003ca href=\"https://elearning.iaea.org/m2/course/view.php?id=787\"\u003eAsherah\u003c/a\u003e for hypothetical scenarios, and created simulated websites for fictional organisations to add to the immersion. These elements enrich the learning experience, providing realistic and practical contextual insights.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/introducing-learners_04.webp\" width=\"892\" height=\"976\" alt=\"A Clicker question in Learners.\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eClicker questions can be sent to participants during presentations driving strong engagement.\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"technical-design\"\u003eTechnical Design\u003c/h2\u003e\n\u003cp\u003eFrom a technical perspective, the Learners framework comprises three main components:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eLearners Application\u003c/strong\u003e: This is the heart of the framework and combines the created content, handles authentication, and provides users with their specific view and feature set while supporting submissions and acting as an interface to other tools.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLearners Theme\u003c/strong\u003e: The Learners theme built for Hugo is used to style the exercise content and provide the mentioned shortcodes, but it is also the interface for communication with the Learners application. Rather than running the whole Learners stack, exercises can be generated and previewed directly from Hugo using the theme.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCourse Content\u003c/strong\u003e: The exercise information, presentations, and documentation are written as Markdown files for Hugo. Various shortcodes are available to extend its functionality and improve its rendered output. Presentations are typically embedded in Learners as PDFs, which can be generated from any source.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis modular design enhances the flexibility and maintainability of the system. We ensured Learners could run on major platforms and provided a flexible \u003ca href=\"https://www.docker.com/\"\u003eDockerised\u003c/a\u003e approach for quickly deploying the environment.\u003c/p\u003e\n\u003ch1 id=\"reflecting-on-the-development\"\u003eReflecting on The Development\u003c/h1\u003e\n\u003cp\u003eThe development of Learners has been guided by a commitment to strike a balance between technological innovation, pedagogic soundness, and accessibility, particularly in relation to existing training offerings. Personally, I believe it addresses a significant gap in information and computer security education, particularly to the benefit of areas with fewer available training offerings that meet their required levels of specificity.\u003c/p\u003e\n\u003cp\u003eFurthermore, this initiative responds to the need to broaden the availability of training in nuclear security, placing a strong focus on making access universal across regional, linguistic, and economic barriers. The innovative \u0026lsquo;copy-paste-remix\u0026rsquo; approach to the creation and distribution of training materials significantly reduces the initial costs associated with launching new local training programmes worldwide. I really do look forward to seeing how Learners is used outside of the existing course base.\u003c/p\u003e\n","content_text":"I’m excited to share an inside view of a newly released open-source training tool, which has become a significant part of our approach to advancing information and computer security training for nuclear security. Developed as a collaboration between the International Atomic Energy Agency (IAEA) and the Austrian Institute of Technology (AIT), ‘Learners’ addresses specific education challenges in information and computer security.\nYou can obtain a copy freely here: https://github.com/iaeaorg/learners\nThe Learners interface, focus is on the content rather than the platform.\nHistory of the Project The beginning of the Learners project is rooted in the challenges brought forth by the COVID-19 pandemic. As the world grappled with unprecedented disruptions, we recognised a need for a resilient and flexible approach to computer security training to ensure our programme could continue to deliver capacity-building outcomes. Traditional in-person sessions where participants would travel internationally for regional or international courses were not viable due to the travel restrictions and quarantine requirements.\nWhile many information and computer security training providers went to virtual delivery during this same time, the cost of these courses was prohibitive to many of the beneficiaries of our training, and there were no available tools to support efficiently deploying a platform for the remote delivery of existing courses. Ultimately, rather than sending participants to courses run by third parties, we needed the ability to train in a hands-on format the concepts within the Nuclear Security Series guidance.\nThe response was to build on the results of CRP J02008 and initiate a new project specifically designed to facilitate hands-on technical training in a virtual environment. This project, for which I was the IAEA project lead, quickly evolved to be more than just a reaction to a temporary crisis: it was a step forward to build efficiencies into the development and delivery of our courses, being able to normalise an approach to enable sharing and remixing of training material across collaborators, and adapting to and innovating on more modern training approaches to make educational resources more accessible globally.\nOverview of Learners Features The aim was to create a platform that is both practical and easy to navigate, reflecting our core approach. Here is a brief overview of how some of the design criteria were achieved:\nOpen Training Materials: Technologies like Markdown, Hugo, and diagrams.net are used to create course material. As the Markdown syntax was limited, we reviewed our existing training material library and created Hugo shortcodes that allowed all of the advanced layouts we’d previously used in Word document drafted course materials. Multilingual Capability: Multilingual support was integrated to make our training accessible across different linguistic groups. Content files can be prepared in multiple languages using common resources (like images and forms), and the participants can toggle between them. Integration with Cyber Range Environments: The ability to assign users to HTML5 VNC sessions has been embedded, with authentication tokens being proxied from the platform to facilitate practical, hands-on experience in a controlled, simulated environment. Self-Paced Learning and Feedback: Learners generates HTML forms from training materials, and allows participants to have their responses validated upon submission. Enhanced with Venjix, the system can interrogate devices in the cyber range environment and confirm that participants have completed assigned tasks. Real-Time Progress Monitoring: Instructors can dynamically observe participant progress through a specialised admin dashboard. This feature aids in providing immediate support and intervention when necessary boosting engagement and responsiveness. Tailored Learning Experience: A workbook customised to the individual’s role can be provided to each participant. This approach is convenient for training delivered in an exercise format, where each participant in a group is assigned different tasks based on their background. Instructor notes can also be integrated into the same source file, streamlining content management and ensuring consistency across materials Complete Offline Functionality: All tools are engineered to operate fully offline, ensuring that sensitive tools crucial for hands-on computer security training, such as those included in Kali Linux, can be utilised without the risk of exposure to public networks. The Learners Approach Accessibility and Scalability Previously, in developing training material, many potential in-kind contributors needed Microsoft Office or Visio licenses to work on some more technical exercises. The platform was designed to operate with minimal infrastructure requirements and eliminated the need for associated software costs. This strategic approach significantly broadens the tool’s dissemination potential, ensuring that training packages are easily distributed and remixed.\nA drawio exercise in Learners. Participants can edit the diagram and the preview will update with their modifications.\nStatic files are at the heart of our design philosophy with Learners, emphasising plain text to maintain simplicity while allowing for modern version control. We consciously minimised complex database dependencies. The only data stored in a database are participant responses, streamlining the creation of training material. This design choice means that updating or swapping training materials is as straightforward as copying and pasting a folder, greatly simplifying content management, allowing modern version control systems to be used, and enhancing the ease and flexibility of sharing and iterating on training materials which we affectionately called “copy-paste-remix”.\nPedagogic Considerations In our endeavour to preserve and enhance the educational effectiveness of our existing training courses, we focused on developing an environment that is both engaging and interactive. Our objective was to create a learning atmosphere that not only disseminates knowledge but also captivates and retains participants’ interest, so we considered several ways to ensure they feel integral to the course:\nExercise Submissions: Participants need the flexibility to manage their training pace and receive immediate feedback, critical factors in adult learning. We evolved the concept of a personal workbook into a more collaborative format. Submissions are not just personal records on paper but can be automatically validated, are accessible for review and presentation, promoting an environment of shared learning and collective improvement. Interactive “Clicker”-Style Questions: Multiple-choice quiz questions can be integrated directly into presentation pages. This approach not only fosters active participation and immediate feedback but delivering it through Learners, which can run entirely offline, allows maintaining this capability for environments lacking internet access or those where tools are available that should remain offline for security reasons, with no need to take a pelican case of physical clickers anymore. Integrated Feedback Mechanism: We have implemented a system where participants can provide feedback for each exercise and presentation. This feedback is then accessible to instructors, ensuring that participants have a continuous voice throughout the course and allowing instructors to tailor their approach to their needs and responses in real-time. Embedding Tools and Multimedia Elements: Learners can be extended with almost any web-based technology. In our courses, we’ve embedded tools like MITRE’s ATT\u0026CK Navigator, simulations like Asherah for hypothetical scenarios, and created simulated websites for fictional organisations to add to the immersion. These elements enrich the learning experience, providing realistic and practical contextual insights. Clicker questions can be sent to participants during presentations driving strong engagement.\nTechnical Design From a technical perspective, the Learners framework comprises three main components:\nLearners Application: This is the heart of the framework and combines the created content, handles authentication, and provides users with their specific view and feature set while supporting submissions and acting as an interface to other tools. Learners Theme: The Learners theme built for Hugo is used to style the exercise content and provide the mentioned shortcodes, but it is also the interface for communication with the Learners application. Rather than running the whole Learners stack, exercises can be generated and previewed directly from Hugo using the theme. Course Content: The exercise information, presentations, and documentation are written as Markdown files for Hugo. Various shortcodes are available to extend its functionality and improve its rendered output. Presentations are typically embedded in Learners as PDFs, which can be generated from any source. This modular design enhances the flexibility and maintainability of the system. We ensured Learners could run on major platforms and provided a flexible Dockerised approach for quickly deploying the environment.\nReflecting on The Development The development of Learners has been guided by a commitment to strike a balance between technological innovation, pedagogic soundness, and accessibility, particularly in relation to existing training offerings. Personally, I believe it addresses a significant gap in information and computer security education, particularly to the benefit of areas with fewer available training offerings that meet their required levels of specificity.\nFurthermore, this initiative responds to the need to broaden the availability of training in nuclear security, placing a strong focus on making access universal across regional, linguistic, and economic barriers. The innovative ‘copy-paste-remix’ approach to the creation and distribution of training materials significantly reduces the initial costs associated with launching new local training programmes worldwide. I really do look forward to seeing how Learners is used outside of the existing course base.\n","date_published":"2024-02-01T20:05:55+03:00","id":"https://blog.mitcdh.au/posts/introducing-learners/","image":"https://blog.mitcdh.au/images/introducing-learners_01.webp","summary":"An innovative open-source training platform, developed collaboratively by the IAEA and AIT, designed to enhance information and computer security training.","tags":["Writing","Technology","Nuclear","Security","Code"],"title":"Empowering Computer Security Training with 'Learners'","url":"https://blog.mitcdh.au/posts/introducing-learners/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-01-13T13:36:17Z","id":"https://blog.mitcdh.au/posts/november-festivities-vienna/","image":"https://blog.mitcdh.au/images/november-festivities-vienna.jpg","summary":"From the haunting thrills of Halloween to the feasts of American Thanksgiving and straight into the twinkling charm of Vienna's Christmas markets in November – who has time for rest with such a whirlwind?","tags":["Album"],"title":"November Festivities, Vienna","url":"https://blog.mitcdh.au/posts/november-festivities-vienna/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eI enjoy photography. I\u0026rsquo;ve intermittently used \u003ca href=\"https://flickr.com/people/mitcdh/\"\u003eFlickr\u003c/a\u003e to upload pictures I\u0026rsquo;ve captured for a long time, I\u0026rsquo;m a big proponent of sharing my work too so any photos not featuring an obviously identifiable human subject I release under a Creative Commons license, typically CC BY-NC-ND. Having shifted my blog to Hugo, I was bored and thought I could do something creative.\u003c/p\u003e\n\u003cp\u003eThe concept of photo boxes sprang to mind – the sort you order that arrives brimming with pictures which you then splay out at various angles (let\u0026rsquo;s be honest, even with OCD, it\u0026rsquo;s probably impossible to get them straight). Such a tangible experience is deeply satisfying, and I thought, why not replicate this on the internet? Integrating a few services I use, particularly given Flickr\u0026rsquo;s user-friendly API, seemed straightforward.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/photo-box-galleries_01.webp\" width=\"1532\" height=\"1287\" alt=\"Screenshot of the generated page\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eThis page was automatically generated from the example below.\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"hugo-modifications\"\u003eHugo Modifications\u003c/h2\u003e\n\u003ch3 id=\"post-frontmatter\"\u003ePost Frontmatter\u003c/h3\u003e\n\u003cp\u003eAs a lazy coder, I was struck by an idea: what if I could transform entire Hugo posts into mere frontmatter? I could leave the rest to be handled by code after simply linking to one of my Flickr albums.\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-1\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003efreezing-layover-in-zurich-switzerland.md.yaml\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/5f90aedb02c76077c0c666cc248d3e0f#file-freezing-layover-in-zurich-switzerland-md-yaml\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-1-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy freezing-layover-in-zurich-switzerland.md.yaml to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-1-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-yaml\" data-lang=\"yaml\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-1\"\u003e1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nn\"\u003e---\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-2\"\u003e2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003etitle\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003eFreezing Layover in Zurich, Switzerland\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-3\"\u003e3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003edescription\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s2\"\u003e\u0026#34;Grounded in Zürich after some bad weather but my heart\u0026#39;s up in the clouds. Unexpected layovers lead to unexpected friendships—particularly when you\u0026#39;d rather be airborne-shoutout to my new seagull (snowgull?) mates!\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-4\"\u003e4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003edate\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"ld\"\u003e2023-12-03 01:00:00 +0000\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-5\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-5\"\u003e5\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003eflickr_embed\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;https://www.flickr.com/photos/83515912@N03/sets/72177720313855068\u0026#39;\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-6\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-6\"\u003e6\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003eimage\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;/images/freezing-layover-in-zurich-switzerland.jpg\u0026#39;\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-7\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-7\"\u003e7\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003etags\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"p\"\u003e[\u003c/span\u003e\u003cspan class=\"l\"\u003eAlbum]\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-8\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-8\"\u003e8\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nn\"\u003e---\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003ch3 id=\"layouts-and-partials\"\u003eLayouts and Partials\u003c/h3\u003e\n\u003cp\u003eHugo\u0026rsquo;s templating engine is impressively powerful. To avoid cluttering the main layout file and to facilitate more complex requests, I employed layouts and partials. Initially, I embedded the following in \u003ccode\u003elayouts/_default/single.html\u003c/code\u003e.\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-2\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003esingle.html\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/5f90aedb02c76077c0c666cc248d3e0f#file-single-html\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-2-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy single.html to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-2-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-go-html-template\" data-lang=\"go-html-template\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-1\"\u003e1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"c\"\u003e\u0026lt;!-- this should be embedded within single.html at the right place --\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-2\"\u003e2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eif\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.Params.flickr_embed\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-3\"\u003e3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003epartial\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;flickr-embed.html\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.Params.flickr_embed\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-4\"\u003e4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eend\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003cp\u003eThis section calls a partial, akin to a function, that queries the Flickr API and returns links and image embeds for all images in the Flickr album.\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-3\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003eflickr-embed.html\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/5f90aedb02c76077c0c666cc248d3e0f#file-flickr-embed-html\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-3-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy flickr-embed.html to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-3-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-go-html-template\" data-lang=\"go-html-template\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-1\"\u003e 1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$url\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-2\"\u003e 2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$photoset_id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-3\"\u003e 3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$user_id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-4\"\u003e 4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$regex\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e`https:\\/\\/w+?\\.?flickr\\.com\\/photos\\/([a-zA-Z0-9_@]+)\\/(albums|sets|photosets)\\/([0-9]+)\\/?`\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-5\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-5\"\u003e 5\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$matches\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003efindRE\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$regex\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$url\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-6\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-6\"\u003e 6\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-7\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-7\"\u003e 7\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eif\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$matches\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-8\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-8\"\u003e 8\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$user_id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003ereplaceRE\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$regex\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;$1\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$url\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-9\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-9\"\u003e 9\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$photoset_id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003ereplaceRE\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$regex\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;$3\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$url\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-10\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-10\"\u003e10\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eend\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-11\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-11\"\u003e11\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-12\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-12\"\u003e12\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003ewith\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003esite\u003c/span\u003e\u003cspan class=\"na\"\u003e.Params.flickr.flickrApiKey\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-13\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-13\"\u003e13\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$api_key\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-14\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-14\"\u003e14\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$api_url\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eprintf\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;%s%s%s%s%s\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://api.flickr.com/services/rest/?format=json\u0026amp;method=flickr.photosets.getPhotos\u0026amp;photoset_id=\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$photoset_id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;\u0026amp;page=1\u0026amp;api_key=\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$api_key\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;\u0026amp;nojsoncallback=1\u0026#34;\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-15\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-15\"\u003e15\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-16\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-16\"\u003e16\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$flickr\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"o\"\u003e:=\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003egetJSON\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$api_url\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-17\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-17\"\u003e17\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eif\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$flickr\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-18\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-18\"\u003e18\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ediv\u003c/span\u003e \u003cspan class=\"na\"\u003eclass\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;photo-box\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-19\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-19\"\u003e19\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003ewith\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$flickr\u003c/span\u003e\u003cspan class=\"na\"\u003e.photoset\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-20\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-20\"\u003e20\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e          \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003erange\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.photo\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-21\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-21\"\u003e21\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e            \u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/\u003c/span\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"nx\"\u003e$user_id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003cspan class=\"s\"\u003e/\u003c/span\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-22\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-22\"\u003e22\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e              \u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/\u003c/span\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.farm\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003cspan class=\"s\"\u003e/\u003c/span\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.server\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003cspan class=\"s\"\u003e/\u003c/span\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.id\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003cspan class=\"s\"\u003e_\u003c/span\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.secret\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003cspan class=\"s\"\u003e_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;\u003c/span\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"na\"\u003e.title\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-23\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-23\"\u003e23\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e            \u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-24\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-24\"\u003e24\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e          \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eend\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-25\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-25\"\u003e25\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eend\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-26\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-26\"\u003e26\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ediv\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-27\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-27\"\u003e27\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eend\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-28\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-28\"\u003e28\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"cp\"\u003e{{\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"k\"\u003eend\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"cp\"\u003e}}\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003cp\u003eNow let\u0026rsquo;s review what that\u0026rsquo;s doing:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eThe \u003ccode\u003e$url\u003c/code\u003e variable captures the current URL passed as an argument from the partial call in \u003ccode\u003esingle.html\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eA regex pattern extracts the \u003ccode\u003e$photoset_id\u003c/code\u003e and \u003ccode\u003e$user_id\u003c/code\u003e from the Flickr URL.\u003c/li\u003e\n\u003cli\u003eIf the Flickr API key (set in \u003ccode\u003econfig.toml\u003c/code\u003e as \u003ccode\u003eParams.flickr.flickrApiKey\u003c/code\u003e), it constructs a request to list the contents of the album (photoset in Flickr API speak).\u003c/li\u003e\n\u003cli\u003eThe response from the Flickr API is then used to generate HTML, displaying and linking each image (with lazy loading) from the Flickr album in a \u003ccode\u003ephoto-box\u003c/code\u003e div.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eAs an example output:\u003c/p\u003e\n\n\u003cdetails class=\"code-details\"\u003e\n  \u003csummary class=\"code-details__summary\"\u003eShow example HTML output\u003c/summary\u003e\n\u003cfigure class=\"code-block\" id=\"code-4\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003eexample-output.html\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/5f90aedb02c76077c0c666cc248d3e0f#file-example-output-html\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-4-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy example-output.html to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-4-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-1\"\u003e 1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ediv\u003c/span\u003e \u003cspan class=\"na\"\u003eclass\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;photo-box\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-2\"\u003e 2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53444202842\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-3\"\u003e 3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53444202842_2286302d06_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000560\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-4\"\u003e 4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-5\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-5\"\u003e 5\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53444202807\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-6\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-6\"\u003e 6\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53444202807_4f2452d4f7_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000561\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-7\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-7\"\u003e 7\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-8\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-8\"\u003e 8\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53444202782\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-9\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-9\"\u003e 9\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53444202782_41f0b5171f_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000568\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-10\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-10\"\u003e10\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-11\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-11\"\u003e11\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53445263598\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-12\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-12\"\u003e12\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53445263598_89f8870916_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000575\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-13\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-13\"\u003e13\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-14\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-14\"\u003e14\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53445538565\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-15\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-15\"\u003e15\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53445538565_85d6bc6566_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;20231203_153608\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-16\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-16\"\u003e16\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-17\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-17\"\u003e17\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53444202542\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-18\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-18\"\u003e18\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53444202542_97dcc85d1c_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000579\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-19\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-19\"\u003e19\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-20\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-20\"\u003e20\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53444202507\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-21\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-21\"\u003e21\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53444202507_50e6bf7740_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000585\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-22\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-22\"\u003e22\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-23\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-23\"\u003e23\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53445447724\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-24\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-24\"\u003e24\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53445447724_60f74acbd6_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000590\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-25\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-25\"\u003e25\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-26\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-26\"\u003e26\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53445263418\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-27\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-27\"\u003e27\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53445263418_aa59539309_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000593\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-28\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-28\"\u003e28\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-29\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-29\"\u003e29\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53445263428\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-30\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-30\"\u003e30\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53445263428_2d7b2b230e_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000596\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-31\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-31\"\u003e31\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-32\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-32\"\u003e32\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53444202257\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-33\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-33\"\u003e33\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53444202257_2ae198bf86_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000597\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-34\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-34\"\u003e34\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-35\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-35\"\u003e35\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53445538525\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-36\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-36\"\u003e36\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53445538525_1e1b43e44e_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;20231203_164707\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-37\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-37\"\u003e37\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-38\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-38\"\u003e38\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"na\"\u003ehref\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://www.flickr.com/photos/83515912@N03/53445538235\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003etarget\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;_blank\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-39\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-39\"\u003e39\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;\u003c/span\u003e\u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"na\"\u003esrc\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;https://c1.staticflickr.com/66/65535/53445538235_bcd7f6d1a6_b.jpg\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003ealt\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;R0000604\u0026#34;\u003c/span\u003e \u003cspan class=\"na\"\u003eloading\u003c/span\u003e\u003cspan class=\"o\"\u003e=\u003c/span\u003e\u003cspan class=\"s\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-40\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-40\"\u003e40\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ea\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-4-line-41\"\u003e\u003ca class=\"lnlinks\" href=\"#code-4-line-41\"\u003e41\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e\u0026lt;/\u003c/span\u003e\u003cspan class=\"nt\"\u003ediv\u003c/span\u003e\u003cspan class=\"p\"\u003e\u0026gt;\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003c/details\u003e\n\u003ch2 id=\"theming\"\u003eTheming\u003c/h2\u003e\n\u003cp\u003eWhile functionality is crucial, I really did want this photo box vibe. To achieve this, I turned to SCSS for its added flexibility (but mostly because I was already using it).\u003c/p\u003e\n\n\u003cdetails class=\"code-details\"\u003e\n  \u003csummary class=\"code-details__summary\"\u003eShow photo-box SCSS\u003c/summary\u003e\n\u003cfigure class=\"code-block\" id=\"code-5\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003e_photo-box.scss\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/31d6cd6a567d18637820b1b1b5e9419e#file-_photo-box-scss\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-5-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy _photo-box.scss to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-5-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-scss\" data-lang=\"scss\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-1\"\u003e 1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nv\"\u003e$photoRotation\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e4\u003c/span\u003e\u003cspan class=\"kt\"\u003edeg\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e \u003cspan class=\"c1\"\u003e// Allows setting the alternating photo rotation\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-2\"\u003e 2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nv\"\u003e$breakpoints\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"p\"\u003e(\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-3\"\u003e 3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003e1200\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e4\u003c/span\u003e\u003cspan class=\"o\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-4\"\u003e 4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"c1\"\u003e// 4 columns for screens wider than 1200px\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-5\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-5\"\u003e 5\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003e800\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e3\u003c/span\u003e\u003cspan class=\"o\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-6\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-6\"\u003e 6\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"c1\"\u003e// 3 columns for screens wider than 800px\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-7\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-7\"\u003e 7\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003e600\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e2\u003c/span\u003e\u003cspan class=\"o\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-8\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-8\"\u003e 8\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"c1\"\u003e// 2 columns for screens wider than 600px\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-9\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-9\"\u003e 9\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003e400\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e1\u003c/span\u003e \u003cspan class=\"c1\"\u003e// 1 column for screens wider than 400px,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-10\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-10\"\u003e10\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-11\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-11\"\u003e11\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-12\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-12\"\u003e12\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nc\"\u003e.photo-box\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-13\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-13\"\u003e13\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003edisplay\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003eflex\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-14\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-14\"\u003e14\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003eflex-wrap\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003ewrap\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-15\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-15\"\u003e15\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003ejustify-content\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003ecenter\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-16\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-16\"\u003e16\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-17\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-17\"\u003e17\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-18\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-18\"\u003e18\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nc\"\u003e.photo-box\u003c/span\u003e \u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-19\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-19\"\u003e19\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003edisplay\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003einline-block\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-20\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-20\"\u003e20\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003eposition\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003erelative\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-21\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-21\"\u003e21\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003emargin\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e5\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-22\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-22\"\u003e22\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003eflex-basis\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"nf\"\u003ecalc\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"mi\"\u003e25\u003c/span\u003e\u003cspan class=\"kt\"\u003e%\u003c/span\u003e \u003cspan class=\"o\"\u003e-\u003c/span\u003e \u003cspan class=\"mi\"\u003e10\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e \u003cspan class=\"c1\"\u003e// 25% for 4 images in a row, minus margin\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-23\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-23\"\u003e23\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003emax-width\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e25\u003c/span\u003e\u003cspan class=\"kt\"\u003e%\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e \u003cspan class=\"c1\"\u003e// Ensures no more than 4 images per row\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-24\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-24\"\u003e24\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003etext-align\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003ecenter\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-25\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-25\"\u003e25\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003ez-index\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e1\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e \u003cspan class=\"c1\"\u003e// Low z-index for non-hovered items\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-26\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-26\"\u003e26\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"na\"\u003etransform\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"nf\"\u003erotate\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"o\"\u003e-\u003c/span\u003e\u003cspan class=\"nv\"\u003e$photoRotation\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e \u003cspan class=\"c1\"\u003e// Default rotation\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-27\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-27\"\u003e27\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-28\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-28\"\u003e28\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"k\"\u003e\u0026amp;\u003c/span\u003e\u003cspan class=\"nd\"\u003e:nth-child\u003c/span\u003e\u003cspan class=\"o\"\u003e(\u003c/span\u003e\u003cspan class=\"nt\"\u003eeven\u003c/span\u003e\u003cspan class=\"o\"\u003e)\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-29\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-29\"\u003e29\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"na\"\u003etransform\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"nf\"\u003erotate\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"o\"\u003e-\u003c/span\u003e\u003cspan class=\"nv\"\u003e$photoRotation\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e \u003cspan class=\"c1\"\u003e// Subtle left rotation for even items\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-30\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-30\"\u003e30\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-31\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-31\"\u003e31\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"k\"\u003e\u0026amp;\u003c/span\u003e\u003cspan class=\"nd\"\u003e:nth-child\u003c/span\u003e\u003cspan class=\"o\"\u003e(\u003c/span\u003e\u003cspan class=\"nt\"\u003eodd\u003c/span\u003e\u003cspan class=\"o\"\u003e)\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-32\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-32\"\u003e32\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"na\"\u003etransform\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"nf\"\u003erotate\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nv\"\u003e$photoRotation\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e \u003cspan class=\"c1\"\u003e// Subtle right rotation for odd items\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-33\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-33\"\u003e33\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-34\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-34\"\u003e34\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-35\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-35\"\u003e35\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"na\"\u003ewidth\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e100\u003c/span\u003e\u003cspan class=\"kt\"\u003e%\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-36\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-36\"\u003e36\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"na\"\u003eheight\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003eauto\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-37\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-37\"\u003e37\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"na\"\u003etransition\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"ni\"\u003etransform\u003c/span\u003e \u003cspan class=\"mi\"\u003e0\u003c/span\u003e\u003cspan class=\"mf\"\u003e.4\u003c/span\u003e\u003cspan class=\"kt\"\u003es\u003c/span\u003e \u003cspan class=\"ni\"\u003eease-out\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-38\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-38\"\u003e38\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"na\"\u003ebox-shadow\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e1\u003c/span\u003e\u003cspan class=\"mf\"\u003e.5\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e \u003cspan class=\"mi\"\u003e2\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e \u003cspan class=\"mi\"\u003e5\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e \u003cspan class=\"mh\"\u003e#0008\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-39\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-39\"\u003e39\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-40\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-40\"\u003e40\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-41\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-41\"\u003e41\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"k\"\u003e\u0026amp;\u003c/span\u003e\u003cspan class=\"nd\"\u003e:hover\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-42\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-42\"\u003e42\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"na\"\u003ez-index\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e999\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e \u003cspan class=\"c1\"\u003e// High z-index and zoom for hovered items to mimic them being picked up\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-43\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-43\"\u003e43\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-44\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-44\"\u003e44\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003eimg\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-45\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-45\"\u003e45\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"na\"\u003etransform\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"nf\"\u003escale\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"mi\"\u003e2\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-46\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-46\"\u003e46\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"na\"\u003ebox-shadow\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"mi\"\u003e3\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e \u003cspan class=\"mi\"\u003e4\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e \u003cspan class=\"mi\"\u003e10\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e \u003cspan class=\"mh\"\u003e#0006\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-47\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-47\"\u003e47\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-48\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-48\"\u003e48\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-49\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-49\"\u003e49\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-50\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-50\"\u003e50\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-51\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-51\"\u003e51\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"c1\"\u003e// Use the breakpoints map to calculate the correct flex-basis and max-width for each breakpoint\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-52\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-52\"\u003e52\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"k\"\u003e@each\u003c/span\u003e \u003cspan class=\"nv\"\u003e$breakpoint\u003c/span\u003e\u003cspan class=\"o\"\u003e,\u003c/span\u003e \u003cspan class=\"nv\"\u003e$columns\u003c/span\u003e \u003cspan class=\"ow\"\u003ein\u003c/span\u003e \u003cspan class=\"nv\"\u003e$breakpoints\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-53\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-53\"\u003e53\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"k\"\u003e@media\u003c/span\u003e \u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"na\"\u003emax-width\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"si\"\u003e#{\u003c/span\u003e\u003cspan class=\"nv\"\u003e$breakpoint\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e\u003cspan class=\"n\"\u003epx\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-54\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-54\"\u003e54\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nc\"\u003e.photo-box\u003c/span\u003e \u003cspan class=\"nt\"\u003ea\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-55\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-55\"\u003e55\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"na\"\u003eflex-basis\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"nf\"\u003ecalc\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"mi\"\u003e100\u003c/span\u003e\u003cspan class=\"kt\"\u003e%\u003c/span\u003e \u003cspan class=\"o\"\u003e/\u003c/span\u003e\u003cspan class=\"si\"\u003e#{\u003c/span\u003e\u003cspan class=\"nv\"\u003e$columns\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e \u003cspan class=\"o\"\u003e-\u003c/span\u003e \u003cspan class=\"mi\"\u003e10\u003c/span\u003e\u003cspan class=\"kt\"\u003epx\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-56\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-56\"\u003e56\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"na\"\u003emax-width\u003c/span\u003e\u003cspan class=\"o\"\u003e:\u003c/span\u003e \u003cspan class=\"nf\"\u003ecalc\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"mi\"\u003e100\u003c/span\u003e\u003cspan class=\"kt\"\u003e%\u003c/span\u003e \u003cspan class=\"o\"\u003e/\u003c/span\u003e\u003cspan class=\"si\"\u003e#{\u003c/span\u003e\u003cspan class=\"nv\"\u003e$columns\u003c/span\u003e\u003cspan class=\"si\"\u003e}\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-57\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-57\"\u003e57\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-58\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-58\"\u003e58\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-5-line-59\"\u003e\u003ca class=\"lnlinks\" href=\"#code-5-line-59\"\u003e59\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e}\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003c/details\u003e\n\u003cp\u003eThe \u003ccode\u003e.photo-box\u003c/code\u003e class is the main container. It utilizes flexbox to arrange the images neatly and centers them within the container.\u003c/p\u003e\n\u003cp\u003eWithin each image container the anchors (\u003ccode\u003e.photo-box a\u003c/code\u003e) are styled. Even and odd elements are subtly rotated in opposite directions, this gives that spilled photo box look I was aiming for, and there is a zooming effect when you hover over each image. Hovering also changes the z-index to bring the selected image to the forefront as otherwise they\u0026rsquo;d still be clipped behind successive elements (\u0026hellip;I spent 30 minutes trying to figure out why I didn\u0026rsquo;t like it before that).\u003c/p\u003e\n\u003cp\u003eThe individual images (\u003ccode\u003e.photo-box a img\u003c/code\u003e) are styled to include a smooth transition effect when you hover over them. When I was first playing around with it I felt as though it lacked depth so added a subtle box shadow.\u003c/p\u003e\n\u003cp\u003eTo ensure the layout remains responsive, the code incorporates breakpoints using media queries. These breakpoints adjust the number of images displayed in a row based on the screen width (up to a maximum of 4 but this can be configured).\u003c/p\u003e\n\u003cp\u003eThis SCSS approach can be readily adapted to create similar photo grids, or you could embrace the entire concept to automatically generate Hugo albums from Flickr. But for me, I have this nice little photo box asthetic and can now use the best tool for the job (Flickr for album organisation) while still benefiting from it automatically. You can see all of these automatically generated albums here: \u003ca href=\"https://blog.mitcdh.au/tags/album/\"\u003ehttps://blog.mitcdh.au/tags/album/\u003c/a\u003e\u003c/p\u003e\n","content_text":"I enjoy photography. I’ve intermittently used Flickr to upload pictures I’ve captured for a long time, I’m a big proponent of sharing my work too so any photos not featuring an obviously identifiable human subject I release under a Creative Commons license, typically CC BY-NC-ND. Having shifted my blog to Hugo, I was bored and thought I could do something creative.\nThe concept of photo boxes sprang to mind – the sort you order that arrives brimming with pictures which you then splay out at various angles (let’s be honest, even with OCD, it’s probably impossible to get them straight). Such a tangible experience is deeply satisfying, and I thought, why not replicate this on the internet? Integrating a few services I use, particularly given Flickr’s user-friendly API, seemed straightforward.\nThis page was automatically generated from the example below.\nHugo Modifications Post Frontmatter As a lazy coder, I was struck by an idea: what if I could transform entire Hugo posts into mere frontmatter? I could leave the rest to be handled by code after simply linking to one of my Flickr albums.\nfreezing-layover-in-zurich-switzerland.md.yaml Source Wrap Copy 1--- 2title: Freezing Layover in Zurich, Switzerland 3description: \"Grounded in Zürich after some bad weather but my heart's up in the clouds. Unexpected layovers lead to unexpected friendships—particularly when you'd rather be airborne-shoutout to my new seagull (snowgull?) mates!\" 4date: 2023-12-03 01:00:00 +0000 5flickr_embed: 'https://www.flickr.com/photos/83515912@N03/sets/72177720313855068' 6image: '/images/freezing-layover-in-zurich-switzerland.jpg' 7tags: [Album] 8--- Layouts and Partials Hugo’s templating engine is impressively powerful. To avoid cluttering the main layout file and to facilitate more complex requests, I employed layouts and partials. Initially, I embedded the following in layouts/_default/single.html.\nsingle.html Source Wrap Copy 1\u003c!-- this should be embedded within single.html at the right place --\u003e 2{{ if .Params.flickr_embed }} 3 {{ partial \"flickr-embed.html\" .Params.flickr_embed }} 4{{ end }} This section calls a partial, akin to a function, that queries the Flickr API and returns links and image embeds for all images in the Flickr album.\nflickr-embed.html Source Wrap Copy 1{{ $url := . }} 2{{ $photoset_id := \"\" }} 3{{ $user_id := \"\" }} 4{{ $regex := `https:\\/\\/w+?\\.?flickr\\.com\\/photos\\/([a-zA-Z0-9_@]+)\\/(albums|sets|photosets)\\/([0-9]+)\\/?` }} 5{{ $matches := findRE $regex $url }} 6 7{{ if $matches }} 8 {{ $user_id = replaceRE $regex \"$1\" $url }} 9 {{ $photoset_id = replaceRE $regex \"$3\" $url }} 10{{ end }} 11 12{{ with site.Params.flickr.flickrApiKey }} 13 {{ $api_key := . }} 14 {{ $api_url := printf \"%s%s%s%s%s\" \"https://api.flickr.com/services/rest/?format=json\u0026method=flickr.photosets.getPhotos\u0026photoset_id=\" $photoset_id \"\u0026page=1\u0026api_key=\" $api_key \"\u0026nojsoncallback=1\" }} 15 16 {{ $flickr := getJSON $api_url }} 17 {{ if $flickr }} 18 \u003cdiv class=\"photo-box\"\u003e 19 {{ with $flickr.photoset }} 20 {{ range .photo }} 21 \u003ca href=\"https://www.flickr.com/photos/{{ $user_id }}/{{ .id }}\" target=\"_blank\"\u003e 22 \u003cimg src=\"https://c1.staticflickr.com/{{ .farm }}/{{ .server }}/{{ .id }}_{{ .secret }}_b.jpg\" alt=\"{{ .title }}\" loading=\"lazy\"\u003e 23 \u003c/a\u003e 24 {{ end }} 25 {{ end }} 26 \u003c/div\u003e 27 {{ end }} 28{{ end }} Now let’s review what that’s doing:\nThe $url variable captures the current URL passed as an argument from the partial call in single.html. A regex pattern extracts the $photoset_id and $user_id from the Flickr URL. If the Flickr API key (set in config.toml as Params.flickr.flickrApiKey), it constructs a request to list the contents of the album (photoset in Flickr API speak). The response from the Flickr API is then used to generate HTML, displaying and linking each image (with lazy loading) from the Flickr album in a photo-box div. As an example output:\nShow example HTML output example-output.html Source Wrap Copy 1\u003cdiv class=\"photo-box\"\u003e 2\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53444202842\" target=\"_blank\"\u003e 3\u003cimg src=\"https://c1.staticflickr.com/66/65535/53444202842_2286302d06_b.jpg\" alt=\"R0000560\" loading=\"lazy\"\u003e 4\u003c/a\u003e 5\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53444202807\" target=\"_blank\"\u003e 6\u003cimg src=\"https://c1.staticflickr.com/66/65535/53444202807_4f2452d4f7_b.jpg\" alt=\"R0000561\" loading=\"lazy\"\u003e 7\u003c/a\u003e 8\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53444202782\" target=\"_blank\"\u003e 9\u003cimg src=\"https://c1.staticflickr.com/66/65535/53444202782_41f0b5171f_b.jpg\" alt=\"R0000568\" loading=\"lazy\"\u003e 10\u003c/a\u003e 11\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53445263598\" target=\"_blank\"\u003e 12\u003cimg src=\"https://c1.staticflickr.com/66/65535/53445263598_89f8870916_b.jpg\" alt=\"R0000575\" loading=\"lazy\"\u003e 13\u003c/a\u003e 14\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53445538565\" target=\"_blank\"\u003e 15\u003cimg src=\"https://c1.staticflickr.com/66/65535/53445538565_85d6bc6566_b.jpg\" alt=\"20231203_153608\" loading=\"lazy\"\u003e 16\u003c/a\u003e 17\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53444202542\" target=\"_blank\"\u003e 18\u003cimg src=\"https://c1.staticflickr.com/66/65535/53444202542_97dcc85d1c_b.jpg\" alt=\"R0000579\" loading=\"lazy\"\u003e 19\u003c/a\u003e 20\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53444202507\" target=\"_blank\"\u003e 21\u003cimg src=\"https://c1.staticflickr.com/66/65535/53444202507_50e6bf7740_b.jpg\" alt=\"R0000585\" loading=\"lazy\"\u003e 22\u003c/a\u003e 23\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53445447724\" target=\"_blank\"\u003e 24\u003cimg src=\"https://c1.staticflickr.com/66/65535/53445447724_60f74acbd6_b.jpg\" alt=\"R0000590\" loading=\"lazy\"\u003e 25\u003c/a\u003e 26\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53445263418\" target=\"_blank\"\u003e 27\u003cimg src=\"https://c1.staticflickr.com/66/65535/53445263418_aa59539309_b.jpg\" alt=\"R0000593\" loading=\"lazy\"\u003e 28\u003c/a\u003e 29\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53445263428\" target=\"_blank\"\u003e 30\u003cimg src=\"https://c1.staticflickr.com/66/65535/53445263428_2d7b2b230e_b.jpg\" alt=\"R0000596\" loading=\"lazy\"\u003e 31\u003c/a\u003e 32\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53444202257\" target=\"_blank\"\u003e 33\u003cimg src=\"https://c1.staticflickr.com/66/65535/53444202257_2ae198bf86_b.jpg\" alt=\"R0000597\" loading=\"lazy\"\u003e 34\u003c/a\u003e 35\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53445538525\" target=\"_blank\"\u003e 36\u003cimg src=\"https://c1.staticflickr.com/66/65535/53445538525_1e1b43e44e_b.jpg\" alt=\"20231203_164707\" loading=\"lazy\"\u003e 37\u003c/a\u003e 38\u003ca href=\"https://www.flickr.com/photos/83515912@N03/53445538235\" target=\"_blank\"\u003e 39\u003cimg src=\"https://c1.staticflickr.com/66/65535/53445538235_bcd7f6d1a6_b.jpg\" alt=\"R0000604\" loading=\"lazy\"\u003e 40\u003c/a\u003e 41\u003c/div\u003e Theming While functionality is crucial, I really did want this photo box vibe. To achieve this, I turned to SCSS for its added flexibility (but mostly because I was already using it).\nShow photo-box SCSS _photo-box.scss Source Wrap Copy 1$photoRotation: 4deg; // Allows setting the alternating photo rotation 2$breakpoints: ( 3 1200: 4, 4 // 4 columns for screens wider than 1200px 5 800: 3, 6 // 3 columns for screens wider than 800px 7 600: 2, 8 // 2 columns for screens wider than 600px 9 400: 1 // 1 column for screens wider than 400px, 10); 11 12.photo-box { 13 display: flex; 14 flex-wrap: wrap; 15 justify-content: center; 16} 17 18.photo-box a { 19 display: inline-block; 20 position: relative; 21 margin: 5px; 22 flex-basis: calc(25% - 10px); // 25% for 4 images in a row, minus margin 23 max-width: 25%; // Ensures no more than 4 images per row 24 text-align: center; 25 z-index: 1; // Low z-index for non-hovered items 26 transform: rotate(-$photoRotation); // Default rotation 27 28 \u0026:nth-child(even) { 29 transform: rotate(-$photoRotation); // Subtle left rotation for even items 30 } 31 \u0026:nth-child(odd) { 32 transform: rotate($photoRotation); // Subtle right rotation for odd items 33 } 34 img { 35 width: 100%; 36 height: auto; 37 transition: transform 0.4s ease-out; 38 box-shadow: 1.5px 2px 5px #0008; 39 } 40 41 \u0026:hover { 42 z-index: 999; // High z-index and zoom for hovered items to mimic them being picked up 43 44 img { 45 transform: scale(2); 46 box-shadow: 3px 4px 10px #0006; 47 } 48 } 49} 50 51// Use the breakpoints map to calculate the correct flex-basis and max-width for each breakpoint 52@each $breakpoint, $columns in $breakpoints { 53 @media (max-width: #{$breakpoint}px) { 54 .photo-box a { 55 flex-basis: calc(100% /#{$columns} - 10px); 56 max-width: calc(100% /#{$columns}); 57 } 58 } 59} The .photo-box class is the main container. It utilizes flexbox to arrange the images neatly and centers them within the container.\nWithin each image container the anchors (.photo-box a) are styled. Even and odd elements are subtly rotated in opposite directions, this gives that spilled photo box look I was aiming for, and there is a zooming effect when you hover over each image. Hovering also changes the z-index to bring the selected image to the forefront as otherwise they’d still be clipped behind successive elements (…I spent 30 minutes trying to figure out why I didn’t like it before that).\nThe individual images (.photo-box a img) are styled to include a smooth transition effect when you hover over them. When I was first playing around with it I felt as though it lacked depth so added a subtle box shadow.\nTo ensure the layout remains responsive, the code incorporates breakpoints using media queries. These breakpoints adjust the number of images displayed in a row based on the screen width (up to a maximum of 4 but this can be configured).\nThis SCSS approach can be readily adapted to create similar photo grids, or you could embrace the entire concept to automatically generate Hugo albums from Flickr. But for me, I have this nice little photo box asthetic and can now use the best tool for the job (Flickr for album organisation) while still benefiting from it automatically. You can see all of these automatically generated albums here: https://blog.mitcdh.au/tags/album/\n","date_published":"2024-01-11T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/photo-box-galleries/","image":"https://blog.mitcdh.au/images/photo-box-galleries.webp","summary":"Because who doesn't like ordering a box of photos and spilling them all over a table?","tags":["Writing","Technology","Code"],"title":"Automatically Generating Photo Box Galleries in Hugo","url":"https://blog.mitcdh.au/posts/photo-box-galleries/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eSong: Kinissue – Shore\nProvided by Lofi Girl\nWatch: \u003ca href=\"https://www.youtube.com/watch?v=EivZwQlT8SU\"\u003ehttps://www.youtube.com/watch?v=EivZwQlT8SU\u003c/a\u003e\nListen: \u003ca href=\"https://open.spotify.com/album/5R06CgiPgr3hIVD155BIyF\"\u003ehttps://open.spotify.com/album/5R06CgiPgr3hIVD155BIyF\u003c/a\u003e\u003c/p\u003e\n","content_text":"Song: Kinissue – Shore Provided by Lofi Girl Watch: https://www.youtube.com/watch?v=EivZwQlT8SU Listen: https://open.spotify.com/album/5R06CgiPgr3hIVD155BIyF\n","date_published":"2024-01-03T14:07:06Z","id":"https://blog.mitcdh.au/posts/rowing-across-the-sunset/","image":"https://blog.mitcdh.au/images/rowing-across-the-sunset.jpg","summary":"...while relaxing in the evening glow ☀️","tags":["Video"],"title":"Rowing Across the Sunset","url":"https://blog.mitcdh.au/posts/rowing-across-the-sunset/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eSong: Waves by Mount Eminest, Flagé \u0026amp; lofi.dealer\n\u003ca href=\"https://open.spotify.com/track/3iUVeYyobaJ7EBKxma8Pto\"\u003ehttps://open.spotify.com/track/3iUVeYyobaJ7EBKxma8Pto\u003c/a\u003e\u003c/p\u003e\n","content_text":"Song: Waves by Mount Eminest, Flagé \u0026 lofi.dealer https://open.spotify.com/track/3iUVeYyobaJ7EBKxma8Pto\n","date_published":"2024-01-03T11:10:02Z","id":"https://blog.mitcdh.au/posts/swimming-with-dolphins/","image":"https://blog.mitcdh.au/images/swimming-with-dolphins.jpg","summary":"Keep hands and feet inside the boat. Violators will be splashed mercilessly 🐬","tags":["Video"],"title":"Swimming with Dolphins","url":"https://blog.mitcdh.au/posts/swimming-with-dolphins/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eSong: New Beginnings by Kupla\n\u003ca href=\"https://chillhop.bandcamp.com/track/new-beginnings\"\u003ehttps://chillhop.bandcamp.com/track/new-beginnings\u003c/a\u003e\u003c/p\u003e\n","content_text":"Song: New Beginnings by Kupla https://chillhop.bandcamp.com/track/new-beginnings\n","date_published":"2024-01-03T07:55:52Z","id":"https://blog.mitcdh.au/posts/heres-to-you-in-the-next-year/","image":"https://blog.mitcdh.au/images/heres-to-you-in-the-next-year.jpg","summary":"🥂","tags":["Video"],"title":"Here's to You in the Next Year","url":"https://blog.mitcdh.au/posts/heres-to-you-in-the-next-year/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-01-02T21:54:44Z","id":"https://blog.mitcdh.au/posts/chasing-the-sun/","image":"https://blog.mitcdh.au/images/chasing-the-sun.jpg","summary":"No matter how far I chase, I always lose to the sea 🌊☀️🌙","tags":["Video"],"title":"Chasing the Sun","url":"https://blog.mitcdh.au/posts/chasing-the-sun/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-01-02T21:54:06Z","id":"https://blog.mitcdh.au/posts/scenes-from-viennese-balls-of-2023/","image":"https://blog.mitcdh.au/images/scenes-from-viennese-balls-of-2023.jpg","summary":"💃🕺","tags":["Video"],"title":"Scenes from Viennese Balls of 2023","url":"https://blog.mitcdh.au/posts/scenes-from-viennese-balls-of-2023/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-01-02T21:52:17Z","id":"https://blog.mitcdh.au/posts/no-surfboard/","image":"https://blog.mitcdh.au/images/no-surfboard.jpg","summary":"No worries 🏄‍♂️🤙","tags":["Video"],"title":"No surfboard?","url":"https://blog.mitcdh.au/posts/no-surfboard/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2024-01-02T21:51:48Z","id":"https://blog.mitcdh.au/posts/swimming-into-the-depths-of-the-past/","image":"https://blog.mitcdh.au/images/swimming-into-the-depths-of-the-past.jpg","summary":"...one very deep breath at a time 🌊🚢","tags":["Video"],"title":"Swimming into the Depths of the Past","url":"https://blog.mitcdh.au/posts/swimming-into-the-depths-of-the-past/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003e🌌 The sky and I, we have our dialogue,\u003cbr/\u003eIn hues of dawn and dusk, a vibrant monologue.\u003cbr/\u003eFrom east to west, in every latitude,\u003cbr/\u003eWitnessing the night in its quiet solitude.\u003cbr/\u003e\u003cbr/\u003e🌅 As the sun ascends, the sky tells its tale,\u003cbr/\u003eIn palettes of pink, gold, and crimson veil.\u003cbr/\u003eAnd when it sets, a fiery goodbye,\u003cbr/\u003eLeaving strokes of orange across the evening sky.\u003cbr/\u003e\u003cbr/\u003e🌃 But then, the night, oh, the night takes the stage,\u003cbr/\u003eWith stars that shift as I turn life's page.\u003cbr/\u003eConstellations dance in foreign skies,\u003cbr/\u003eWitness timeless stories through celestial eyes.\u003cbr/\u003e\u003cbr/\u003e✨ In each location, the stars rearrange,\u003cbr/\u003eA cosmic show, where quantum forces engage.\u003cbr/\u003eFrom north to south, as patterns transform,\u003cbr/\u003eTheir dance unfolds as mysteries swarm.\u003cbr/\u003e\u003cbr/\u003e🌍 And as the earth spins, night turns to day,\u003cbr/\u003eThe sun and stars in their endless ballet.\u003cbr/\u003eThe sky and I, in our wordless bond,\u003cbr/\u003eGazing upon the world's expanse, so fond.\u003cbr/\u003e\u003cbr/\u003e🌄 In every sunrise, every sunset's glow,\u003cbr/\u003eThe sky reveals secrets only travellers know.\u003cbr/\u003eFor in each journey, under different stars and sun,\u003cbr/\u003eWe find not just new skies, but ourselves, undone.\u003cbr/\u003e\n\u003cdiv class=\"gallery-box\"\u003e\n  \u003cdiv class=\"gallery\"\u003e\n    \u003cimg src=\"/images/celestial-conversations_01.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_02.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_03.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_04.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_05.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_06.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_07.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_08.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/celestial-conversations_09.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n  \u003c/div\u003e\n\u003c/div\u003e","content_text":"🌌 The sky and I, we have our dialogue,In hues of dawn and dusk, a vibrant monologue.From east to west, in every latitude,Witnessing the night in its quiet solitude.🌅 As the sun ascends, the sky tells its tale,In palettes of pink, gold, and crimson veil.And when it sets, a fiery goodbye,Leaving strokes of orange across the evening sky.🌃 But then, the night, oh, the night takes the stage,With stars that shift as I turn life's page.Constellations dance in foreign skies,Witness timeless stories through celestial eyes.✨ In each location, the stars rearrange,A cosmic show, where quantum forces engage.From north to south, as patterns transform,Their dance unfolds as mysteries swarm.🌍 And as the earth spins, night turns to day,The sun and stars in their endless ballet.The sky and I, in our wordless bond,Gazing upon the world's expanse, so fond.🌄 In every sunrise, every sunset's glow,The sky reveals secrets only travellers know.For in each journey, under different stars and sun,We find not just new skies, but ourselves, undone. ","date_published":"2023-12-26T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/celestial-conversations/","image":"https://blog.mitcdh.au/images/celestial-conversations_01.webp","summary":"Wherein I write about a dialogue with the sky.","tags":["Writing","Travel","Poetry","Philosophy"],"title":"Celestial Conversations","url":"https://blog.mitcdh.au/posts/celestial-conversations/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-12-09T16:09:29Z","id":"https://blog.mitcdh.au/posts/a-wild-capybara-appears-in-sao-paulo-brazil/","image":"https://blog.mitcdh.au/images/a-wild-capybara-appears-in-sao-paulo-brazil.jpg","summary":"Forró 4ever.","tags":["Album"],"title":"A Wild Capybara Appears in Sao Paulo, Brazil","url":"https://blog.mitcdh.au/posts/a-wild-capybara-appears-in-sao-paulo-brazil/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-12-09T08:08:32Z","id":"https://blog.mitcdh.au/posts/baltic-ferries-between-sweden-finland-and-estonia/","image":"https://blog.mitcdh.au/images/baltic-ferries-between-sweden-finland-and-estonia.jpg","summary":"So much water. So many lakes.","tags":["Album"],"title":"Baltic Ferries Between Sweden, Finland, and Estonia","url":"https://blog.mitcdh.au/posts/baltic-ferries-between-sweden-finland-and-estonia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-12-03T18:03:41Z","id":"https://blog.mitcdh.au/posts/freezing-layover-in-zurich-switzerland/","image":"https://blog.mitcdh.au/images/freezing-layover-in-zurich-switzerland.jpg","summary":"Grounded in Zürich after some bad weather but my heart's up in the clouds. Unexpected layovers lead to unexpected friendships—particularly when you'd rather be airborne—shoutout to my new seagull (snowgull?) mates!","tags":["Album"],"title":"Freezing Layover in Zurich, Switzerland","url":"https://blog.mitcdh.au/posts/freezing-layover-in-zurich-switzerland/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eComing from the beaches of Sydney 🇦🇺, I remember thinking Melbourne was too cold for me, but little did I know that one day I\u0026rsquo;d find myself living through snowy European winters ☃️ over a holiday season that was before sun and sea to me 🏄🏻‍♂️☀️\u003c/p\u003e\n\u003cp\u003eI saw snowfall for the first time in my life after moving to Vienna 🇦🇹 when I was 27. Now, cold winters are the norm. But I can\u0026rsquo;t help but stop sometimes and think about how far removed this is from where I saw my life before 🤔\u003c/p\u003e\n\u003cp\u003eTo me, it\u0026rsquo;s a lesson to embrace life and its myriad of experiences because you never really know where you might find yourself or who you might be next 🌏✈️\u003c/p\u003e\n","content_text":"Coming from the beaches of Sydney 🇦🇺, I remember thinking Melbourne was too cold for me, but little did I know that one day I’d find myself living through snowy European winters ☃️ over a holiday season that was before sun and sea to me 🏄🏻‍♂️☀️\nI saw snowfall for the first time in my life after moving to Vienna 🇦🇹 when I was 27. Now, cold winters are the norm. But I can’t help but stop sometimes and think about how far removed this is from where I saw my life before 🤔\nTo me, it’s a lesson to embrace life and its myriad of experiences because you never really know where you might find yourself or who you might be next 🌏✈️\n","date_published":"2023-12-02T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/sydney-sands-to-vienna-snows-a-reflection/","image":"https://blog.mitcdh.au/images/sydney-sands-vienna-snow.webp","summary":"Wherein I embrace life's unexpected turns.","tags":["Writing","Musings","Travel"],"title":"A Reflection on Sydney Sands to Vienna Snows","url":"https://blog.mitcdh.au/posts/sydney-sands-to-vienna-snows-a-reflection/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eI work on many projects involving local installations running on environments not connected to the internet, primarily for training purposes. Now, so many times, I\u0026rsquo;ve seen a codebase where someone, somewhere, sometime long ago, generated a self-signed SSL certificate and then left it. It got sucked up into the version control, and then everyone everywhere deploying this tool uses the same certificate. It just makes me crazy.\u003c/p\u003e\n\u003cp\u003eSo I wanted to quickly build something to deal with this: \u003ca href=\"https://github.com/mitcdh/docker-build-certs\"\u003ehttps://github.com/mitcdh/docker-build-certs\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThis is for docker-based workflows but the \u003ccode\u003eentrypoint.sh\u003c/code\u003e script can be repurposed. The container is designed to test for the presence of and generate, when needed, SSL certificates and keys using OpenSSL. It\u0026rsquo;s built on the Alpine Linux image and will create a \u003ccode\u003ecertificate.crt\u003c/code\u003e and \u003ccode\u003ecertificate.key\u003c/code\u003e in the \u003ccode\u003e/certs\u003c/code\u003e volume if they don\u0026rsquo;t already exist.\u003c/p\u003e\n\u003cp\u003eThis allows two things:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUse an existing PKI infrastructure and not accidentally tie it into the repo because of the wonders of \u003ccode\u003e.gitignore\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDistribute code in VCS that will run without bundling hardcoded example certificates/keys.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"customisation\"\u003eCustomisation\u003c/h2\u003e\n\u003cp\u003eThe container supports the following environment variables:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eCA_CN\u003c/code\u003e: Common Name for the Certificate Authority. The default is \u0026ldquo;CertificateCA\u0026rdquo;.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCERTIFICATE_CN\u003c/code\u003e: Common Name for the certificate. The default is \u0026ldquo;certificate\u0026rdquo;.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCERTIFICATE_SAN\u003c/code\u003e: Subject Alternative Names for the certificate. It should be a comma-separated list. The default is \u0026ldquo;certificate\u0026rdquo;.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eDAYS_VALID\u003c/code\u003e: Number of days the certificate is valid. The default is 365.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"usage\"\u003eUsage\u003c/h2\u003e\n\u003cp\u003eThis was primarily written for docker-compose workflows; this example \u003ccode\u003edocker-compose.yml\u003c/code\u003e provides the following:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003ebuild-certs\u003c/code\u003e service is responsible for generating the SSL certificates.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ewebserver\u003c/code\u003e service (using the NGINX image as an example) depends on the \u003ccode\u003ebuild-certs\u003c/code\u003e. It mounts the same volume to read the certificates.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003edepends_on\u003c/code\u003e directive ensures that the \u003ccode\u003ewebserver\u003c/code\u003e service starts only after the \u003ccode\u003ebuild-certs\u003c/code\u003e service has completed its execution.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-1\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003eYAML\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-1-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy YAML to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-1-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-yaml\" data-lang=\"yaml\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003eversion\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;3.8\u0026#39;\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nt\"\u003eservices\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003ebuild-certs\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e\u003cspan class=\"nt\"\u003ebuild\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003e.\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e\u003cspan class=\"nt\"\u003evolumes\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e      \u003c/span\u003e- \u003cspan class=\"l\"\u003e./certs:/certs\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e  \u003c/span\u003e\u003cspan class=\"nt\"\u003ewebserver\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e\u003cspan class=\"nt\"\u003eimage\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e \u003c/span\u003e\u003cspan class=\"l\"\u003enginx\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e\u003cspan class=\"nt\"\u003evolumes\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e      \u003c/span\u003e- \u003cspan class=\"l\"\u003e./certs:/etc/nginx/certs:ro\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e    \u003c/span\u003e\u003cspan class=\"nt\"\u003edepends_on\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e\u003cspan class=\"w\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"w\"\u003e      \u003c/span\u003e- \u003cspan class=\"l\"\u003ebuild-certs\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003ch2 id=\"thoughts\"\u003eThoughts\u003c/h2\u003e\n\u003cp\u003eYes, a service like \u003ca href=\"https://letsencrypt.org/\"\u003eLet\u0026rsquo;s Encrypt\u003c/a\u003e is better for internet-connected applications, but sometimes, you just need something easy to deploy in a short-lived training environment. Generating at runtime is better than a legacy of the same self-signed cert finding its way worldwide.\u003c/p\u003e\n","content_text":"I work on many projects involving local installations running on environments not connected to the internet, primarily for training purposes. Now, so many times, I’ve seen a codebase where someone, somewhere, sometime long ago, generated a self-signed SSL certificate and then left it. It got sucked up into the version control, and then everyone everywhere deploying this tool uses the same certificate. It just makes me crazy.\nSo I wanted to quickly build something to deal with this: https://github.com/mitcdh/docker-build-certs\nThis is for docker-based workflows but the entrypoint.sh script can be repurposed. The container is designed to test for the presence of and generate, when needed, SSL certificates and keys using OpenSSL. It’s built on the Alpine Linux image and will create a certificate.crt and certificate.key in the /certs volume if they don’t already exist.\nThis allows two things:\nUse an existing PKI infrastructure and not accidentally tie it into the repo because of the wonders of .gitignore. Distribute code in VCS that will run without bundling hardcoded example certificates/keys. Customisation The container supports the following environment variables:\nCA_CN: Common Name for the Certificate Authority. The default is “CertificateCA”. CERTIFICATE_CN: Common Name for the certificate. The default is “certificate”. CERTIFICATE_SAN: Subject Alternative Names for the certificate. It should be a comma-separated list. The default is “certificate”. DAYS_VALID: Number of days the certificate is valid. The default is 365. Usage This was primarily written for docker-compose workflows; this example docker-compose.yml provides the following:\nThe build-certs service is responsible for generating the SSL certificates. The webserver service (using the NGINX image as an example) depends on the build-certs. It mounts the same volume to read the certificates. The depends_on directive ensures that the webserver service starts only after the build-certs service has completed its execution. YAML Wrap Copy version: '3.8' services: build-certs: build: . volumes: - ./certs:/certs webserver: image: nginx volumes: - ./certs:/etc/nginx/certs:ro depends_on: - build-certs Thoughts Yes, a service like Let’s Encrypt is better for internet-connected applications, but sometimes, you just need something easy to deploy in a short-lived training environment. Generating at runtime is better than a legacy of the same self-signed cert finding its way worldwide.\n","date_published":"2023-12-01T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/quick-build-for-self-signed-certs/","image":"https://blog.mitcdh.au/images/quick-build-for-self-signed-certs.webp","summary":"Why is SSL like a complicated relationship? Because it's always a struggle to establish trust.","tags":["Writing","Technology","Code"],"title":"Quick Build for Self-signed Certs","url":"https://blog.mitcdh.au/posts/quick-build-for-self-signed-certs/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-11-06T01:09:37Z","id":"https://blog.mitcdh.au/posts/the-greenbelt-of-idaho-falls-united-states/","image":"https://blog.mitcdh.au/images/the-greenbelt-of-idaho-falls-united-states.jpg","summary":"Y'all ready for this?","tags":["Album"],"title":"The Greenbelt of Idaho Falls, United States","url":"https://blog.mitcdh.au/posts/the-greenbelt-of-idaho-falls-united-states/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-10-28T15:21:42Z","id":"https://blog.mitcdh.au/posts/brussels-murals-brighten-dreary-days-belgium/","image":"https://blog.mitcdh.au/images/brussels-murals-brighten-dreary-days-belgium.jpg","summary":"Strolling through Brussels, beneath a weeping sky, where each end is whispered with the wind. Here, amidst the greys, the city's cartoon murals hint at joy—a reminder that even on the dreariest days, colour finds a way to bring a smile.","tags":["Album"],"title":"Brussels Murals Brighten Dreary Days, Belgium","url":"https://blog.mitcdh.au/posts/brussels-murals-brighten-dreary-days-belgium/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-08-25T17:39:16Z","id":"https://blog.mitcdh.au/posts/sunsets-in-tuscany-italy/","image":"https://blog.mitcdh.au/images/sunsets-in-tuscany-italy.jpg","summary":"On so many things, in so many ways, like the sun, fading into its myriad hues, parting in silent eloquence.","tags":["Album"],"title":"Sunsets in Tuscany, Italy","url":"https://blog.mitcdh.au/posts/sunsets-in-tuscany-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e🤔💭 A friend handed me this lamp, saying, \u0026ldquo;You inspire me. You make the world a better place. I want to make magic happen here with you, and this is just a little reminder of that\u0026rdquo;. I\u0026rsquo;ve spent weeks thinking about why that gesture affected me so profoundly, and I now understand.\u003c/p\u003e\n\u003cp\u003eThe universe is a place of balance, of equal and opposite reactions—where energy is neither created nor destroyed but transformed. Yet, when we think about the end of a life, it feels like a violation of this. The thoughts, ideas, experiences, and memories, the unrealised potential to affect the world and others who share it, all contained within a single being, seemingly vanish instantly. It\u0026rsquo;s hard to reconcile.\u003c/p\u003e\n\u003cp\u003eBut what if we shift our perspective? What if we see this not only as an end but also as a transformation? What if, for we who remain, the lost energy, love, and interconnectedness do not just vanish, but we allow ourselves to take them and carry them forward?\u003c/p\u003e\n\u003cp\u003eThat\u0026rsquo;s the power we hold. The ability to channel an infinite loss and create, love, and make a difference is the power to positively affect others and the world around us. That power doesn\u0026rsquo;t simply disappear. It persists, transforms, and continues to make waves if we just let it inspire us and carry it forward to others.\u003c/p\u003e\n\u003cp\u003eSo when my friend handed me this lamp, it reinforced the idea that for me, now, the only possible reaction to loss, the only appropriate response to anyone ever being deprived of realising their potential, is to, in reply, harness mine to the greatest extent while I can. To do good, make a positive impact, and contribute meaningfully to the world and enable others to do the same. To challenge the status quo, break the rules, and push the boundaries of what\u0026rsquo;s possible.\u003c/p\u003e\n\u003cp\u003eBecause, in the scheme of things, we\u0026rsquo;re not just passive observers. We\u0026rsquo;re participants. We\u0026rsquo;re creators and agents of change. The energy we put into the world and the lives around us matters. It reverberates. It endures.\u003c/p\u003e\n\u003cp\u003eLet\u0026rsquo;s make our time matter, strive to leave the world a little better than we found, and maybe make some magic. Because that\u0026rsquo;s the true legacy we leave behind. That\u0026rsquo;s the equilibrium. That\u0026rsquo;s the missing transformation 🌍✨\u003c/p\u003e\n","content_text":"🤔💭 A friend handed me this lamp, saying, “You inspire me. You make the world a better place. I want to make magic happen here with you, and this is just a little reminder of that”. I’ve spent weeks thinking about why that gesture affected me so profoundly, and I now understand.\nThe universe is a place of balance, of equal and opposite reactions—where energy is neither created nor destroyed but transformed. Yet, when we think about the end of a life, it feels like a violation of this. The thoughts, ideas, experiences, and memories, the unrealised potential to affect the world and others who share it, all contained within a single being, seemingly vanish instantly. It’s hard to reconcile.\nBut what if we shift our perspective? What if we see this not only as an end but also as a transformation? What if, for we who remain, the lost energy, love, and interconnectedness do not just vanish, but we allow ourselves to take them and carry them forward?\nThat’s the power we hold. The ability to channel an infinite loss and create, love, and make a difference is the power to positively affect others and the world around us. That power doesn’t simply disappear. It persists, transforms, and continues to make waves if we just let it inspire us and carry it forward to others.\nSo when my friend handed me this lamp, it reinforced the idea that for me, now, the only possible reaction to loss, the only appropriate response to anyone ever being deprived of realising their potential, is to, in reply, harness mine to the greatest extent while I can. To do good, make a positive impact, and contribute meaningfully to the world and enable others to do the same. To challenge the status quo, break the rules, and push the boundaries of what’s possible.\nBecause, in the scheme of things, we’re not just passive observers. We’re participants. We’re creators and agents of change. The energy we put into the world and the lives around us matters. It reverberates. It endures.\nLet’s make our time matter, strive to leave the world a little better than we found, and maybe make some magic. Because that’s the true legacy we leave behind. That’s the equilibrium. That’s the missing transformation 🌍✨\n","date_published":"2023-08-04T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/the-transformative-power-of-loss/","image":"https://blog.mitcdh.au/images/the-transformative-power-of-loss.webp","summary":"Wherein I consider a life's true balance.","tags":["Writing","Musings","Philosophy"],"title":"The Transformative Power of Loss and Love","url":"https://blog.mitcdh.au/posts/the-transformative-power-of-loss/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e📸 Trapped behind my camera lens earlier in the season, I explored Hallstatt like a wide-eyed tourist. The quaint houses, the serene lake, the towering Alps - every shot could be a postcard. But as I looked around, I realised something 🤔💭\u003c/p\u003e\n\u003cp\u003eI wasn\u0026rsquo;t merely a spectator. I have been part of a larger picture of friendship and shared experiences since 2019. Seeing the small Austrian village for the first time, my friends, travelling from across the world like I had before them, caught what matters in focus.\u003c/p\u003e\n\u003cp\u003eI realised that the real magic wasn\u0026rsquo;t just in the landscapes but in the bond and the stories we had shared over time. I once read, \u0026lsquo;We travel not to escape life, but for life not to escape us.\u0026rsquo; On this trip, life didn\u0026rsquo;t escape me.\u003c/p\u003e\n\u003cp\u003eSo here\u0026rsquo;s to Hallstatt, the eyes that rolled while judging us as another group of tourists from faraway lands, and to the friends who make every shot worth capturing. Cheers to my friends for sharing the memories and the pictures (not all of which are mine) 🥂\u003c/p\u003e\n\u003cdiv class=\"gallery-box\"\u003e\n  \u003cdiv class=\"gallery\"\u003e\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_02.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_03.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_04.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_05.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_06.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_07.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_08.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_09.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/hallstatt-adventures-behind-the-lens_10.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n  \u003c/div\u003e\n\u003c/div\u003e","content_text":"📸 Trapped behind my camera lens earlier in the season, I explored Hallstatt like a wide-eyed tourist. The quaint houses, the serene lake, the towering Alps - every shot could be a postcard. But as I looked around, I realised something 🤔💭\nI wasn’t merely a spectator. I have been part of a larger picture of friendship and shared experiences since 2019. Seeing the small Austrian village for the first time, my friends, travelling from across the world like I had before them, caught what matters in focus.\nI realised that the real magic wasn’t just in the landscapes but in the bond and the stories we had shared over time. I once read, ‘We travel not to escape life, but for life not to escape us.’ On this trip, life didn’t escape me.\nSo here’s to Hallstatt, the eyes that rolled while judging us as another group of tourists from faraway lands, and to the friends who make every shot worth capturing. Cheers to my friends for sharing the memories and the pictures (not all of which are mine) 🥂\n","date_published":"2023-07-26T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/hallstatt-adventures-behind-the-lens/","image":"https://blog.mitcdh.au/images/hallstatt-adventures-behind-the-lens_01.webp","summary":"Wherein I find friendship in travel.","tags":["Writing","Musings","Friends"],"title":"Hallstatt Adventures Behind the Lens","url":"https://blog.mitcdh.au/posts/hallstatt-adventures-behind-the-lens/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-07-22T10:08:53Z","id":"https://blog.mitcdh.au/posts/grog-and-pirate-ships-in-turkey-and-greece/","image":"https://blog.mitcdh.au/images/grog-and-pirate-ships-in-turkey-and-greece.jpg","summary":"May contain Kerosene, Propylene Glycol, Artificial Sweeteners, Sulfuric Acid, Rum, Acetone, Battery Acid, red dye#2, SCUMM, Axle grease and/or pepperoni.","tags":["Album"],"title":"Grog and Pirate Ships in Turkey and Greece","url":"https://blog.mitcdh.au/posts/grog-and-pirate-ships-in-turkey-and-greece/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-07-08T13:02:30Z","id":"https://blog.mitcdh.au/posts/hiking-in-vienna-and-lower-austria/","image":"https://blog.mitcdh.au/images/hiking-in-vienna-and-lower-austria.jpg","summary":"What goes up must come down. Even if it does complain the whole way.","tags":["Album"],"title":"Hiking in Vienna and Lower Austria","url":"https://blog.mitcdh.au/posts/hiking-in-vienna-and-lower-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis article was originally published in the \u003ca href=\"https://www.iaea.org/bulletin/64-2\"\u003eJune 2023 IAEA Bulletin\u003c/a\u003e titled Computer Security in a Nuclear World. The only modification has been to replace the cover image.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eArtificial intelligence (AI) and machine learning technologies could potentially revolutionize the world, ushering in unprecedented progress and innovation by transforming how we create, consume and use information. As AI technologies become increasingly sophisticated, they will transform industries, streamline processes and may even impact how we live our lives. The nuclear sector is no exception, and the benefits of AI can be expected in many processes and operations in nuclear and radiological facilities.\u003c/p\u003e\n\u003cp\u003eAt the same time, AI\u0026rsquo;s rapid advancement also brings with it a multitude of risks. Malicious actors may use AI to launch more advanced and targeted attacks or exploit it to compromise the integrity of networks, systems and sensitive information in nuclear and radiological facilities.\u003c/p\u003e\n\u003ch2 id=\"benefits-for-information-and-computer-security\"\u003e\u003cstrong\u003eBenefits for information and computer security\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe IAEA is preparing for the transformations brought about by AI by fostering international cooperation in the area to ensure all countries can benefit from the opportunities while also preparing to mitigate the risks. Through mechanisms such as Technical Meetings and coordinated research projects (CRPs), the IAEA is supporting the development, awareness and application of AI techniques, as well as countermeasures and defence against malicious actors.\u003c/p\u003e\n\u003cp\u003ePerhaps the most significant advantage of AI in information and computer security is the reduced reliance on human analysis and intervention. AI-enabled systems can operate 24/7 to monitor networks and systems for threats. By automating these tasks, nuclear security professionals have the time to focus on more strategic tasks and respond more efficiently to incidents when they occur.\u003c/p\u003e\n\u003cp\u003e\u0026ldquo;The adaptive learning capabilities of AI can be harnessed to enhance information and computer security by swiftly identifying threats and automatically providing human experts with the information they need to coordinate response activities,\u0026rdquo; said Fan Zhang, an assistant professor at the Georgia Institute of Technology in the United States of America, who participated in a CRP to support research in strengthening computer security. \u0026ldquo;It will not replace the workforce, but rather establish resources and insights that will make early detection and response in computer security realistically achievable.\u0026rdquo;\u003c/p\u003e\n\u003cp\u003eBy leveraging advanced machine learning algorithms, AI may also help nuclear and radiological facilities sharpen their defences against cyberattacks by identifying anomalous data in computer systems. AI-supported security systems can continuously monitor and analyse vast amounts of data to determine if any activity is anomalous to the facility\u0026rsquo;s normal operation. Cyberattacks may feed fake data to maliciously mislead the operators of nuclear facilities. In this case, AI-supported systems can be harnessed to alert those running a nuclear power plant to even the slightest variation from normal operations. By offering heightened situational awareness, AI also allows for the early detection of criminal actions and prompts the necessary incident response.\u003c/p\u003e\n\u003ch2 id=\"challenges-to-be-addressed\"\u003e\u003cstrong\u003eChallenges to be addressed\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe benefits offered by AI in nuclear and radiological facilities depend greatly on how the AI system has been trained. AI is only as intelligent as the training data it is working with, and it can be manipulated into giving false readings and results if it does not have the correct inputs. This remains a significant barrier to its use for nuclear security. Even with the recent advancements in AI technology, using it as a replacement for a human is not feasible. Physical protection, material accounting and control and direct measurements \u0026mdash; essential activities for ensuring nuclear security \u0026mdash; require a human input.\u003c/p\u003e\n\u003cp\u003eAn additional challenge with AI with regard to nuclear security is understanding how and why an AI model has made a particular decision or prediction. \u0026ldquo;Transparency and explainability \u0026mdash;where humans can understand the reasoning behind decisions or predictions made by the AI \u0026mdash; are among the most significant problems with AI models. It is often challenging to understand how these models arrive at their conclusions, making it difficult to trust and ensure the integrity of their output,\u0026rdquo; said Scott Purvis, Head of the Information Management Section in the IAEA\u0026rsquo;s Division of Nuclear Security. \u0026ldquo;This becomes particularly problematic when these models replace sensors providing direct measurements and human experience gained with the unique characteristics of each facility. It becomes impractical to place any assurance in the system\u0026rsquo;s integrity unless there is a prior comprehensive advanced understanding of the AI algorithms to recognize how and why decisions are made.\u0026rdquo;\u003c/p\u003e\n\u003cp\u003eThe IAEA\u0026rsquo;s guidance on computer security for nuclear security includes best practices on human checks and balances to guide facilities\u0026rsquo; awareness of which processes can be automated by AI and which should continue to have human oversight, at least until the risks of this rapidly developing technology are known. They also provide an essential resource that can enable countries to put important computer security measures in place to detect, prevent and respond to cyberattacks.\u003c/p\u003e\n\u003cp\u003eAdditionally, a CRP was developed by the IAEA to support research in strengthening computer security. Entitled \u0026ldquo;Enhancing Computer Security Incident Analysis at Nuclear Facilities\u0026rdquo;, the CRP brought together representatives of 13 countries to work on improving computer security capabilities, including AI techniques, at nuclear facilities to detect anomalies indicating targeted cyberattacks.\u003c/p\u003e\n\u003ch2 id=\"the-race-to-adopt-ai-technologies\"\u003e\u003cstrong\u003eThe race to adopt AI technologies\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eAI has shown its potential to benefit people who use nuclear technology for peaceful ends. As its use to enhance processes and operations in nuclear and radiological facilities expands, so too must the awareness of the risks associated with its broader adoption. Organizations must maintain a robust computer security programme to assure nuclear security while benefiting from AI.\u003c/p\u003e\n\u003cp\u003eDoing so requires a fundamental paradigm shift in how trust and sensitivity is viewed. Every potential point of failure in a system must be considered, even those unrelated to its design. Malicious actors can leverage AI to create more sophisticated malware, automate cyberattacks, exploit biases and vulnerabilities within the models, or bypass security measures by mimicking legitimate user behaviour. This \u0026lsquo;arms race\u0026rsquo; between defenders and attackers will require constant innovation and adaptation.\u003c/p\u003e\n\u003cp\u003eGreater use of AI technology to enhance computer security measures at nuclear facilities could offer significant benefits, including enhanced threat detection, proactive security measures, reduced reliance on human intervention and improved incident response. By embracing the benefits of AI while addressing its risks, organizations can significantly enhance their computer security in the face of evolving cyberthreats.\u003c/p\u003e\n","content_text":"This article was originally published in the June 2023 IAEA Bulletin titled Computer Security in a Nuclear World. The only modification has been to replace the cover image.\nArtificial intelligence (AI) and machine learning technologies could potentially revolutionize the world, ushering in unprecedented progress and innovation by transforming how we create, consume and use information. As AI technologies become increasingly sophisticated, they will transform industries, streamline processes and may even impact how we live our lives. The nuclear sector is no exception, and the benefits of AI can be expected in many processes and operations in nuclear and radiological facilities.\nAt the same time, AI’s rapid advancement also brings with it a multitude of risks. Malicious actors may use AI to launch more advanced and targeted attacks or exploit it to compromise the integrity of networks, systems and sensitive information in nuclear and radiological facilities.\nBenefits for information and computer security The IAEA is preparing for the transformations brought about by AI by fostering international cooperation in the area to ensure all countries can benefit from the opportunities while also preparing to mitigate the risks. Through mechanisms such as Technical Meetings and coordinated research projects (CRPs), the IAEA is supporting the development, awareness and application of AI techniques, as well as countermeasures and defence against malicious actors.\nPerhaps the most significant advantage of AI in information and computer security is the reduced reliance on human analysis and intervention. AI-enabled systems can operate 24/7 to monitor networks and systems for threats. By automating these tasks, nuclear security professionals have the time to focus on more strategic tasks and respond more efficiently to incidents when they occur.\n“The adaptive learning capabilities of AI can be harnessed to enhance information and computer security by swiftly identifying threats and automatically providing human experts with the information they need to coordinate response activities,” said Fan Zhang, an assistant professor at the Georgia Institute of Technology in the United States of America, who participated in a CRP to support research in strengthening computer security. “It will not replace the workforce, but rather establish resources and insights that will make early detection and response in computer security realistically achievable.”\nBy leveraging advanced machine learning algorithms, AI may also help nuclear and radiological facilities sharpen their defences against cyberattacks by identifying anomalous data in computer systems. AI-supported security systems can continuously monitor and analyse vast amounts of data to determine if any activity is anomalous to the facility’s normal operation. Cyberattacks may feed fake data to maliciously mislead the operators of nuclear facilities. In this case, AI-supported systems can be harnessed to alert those running a nuclear power plant to even the slightest variation from normal operations. By offering heightened situational awareness, AI also allows for the early detection of criminal actions and prompts the necessary incident response.\nChallenges to be addressed The benefits offered by AI in nuclear and radiological facilities depend greatly on how the AI system has been trained. AI is only as intelligent as the training data it is working with, and it can be manipulated into giving false readings and results if it does not have the correct inputs. This remains a significant barrier to its use for nuclear security. Even with the recent advancements in AI technology, using it as a replacement for a human is not feasible. Physical protection, material accounting and control and direct measurements — essential activities for ensuring nuclear security — require a human input.\nAn additional challenge with AI with regard to nuclear security is understanding how and why an AI model has made a particular decision or prediction. “Transparency and explainability —where humans can understand the reasoning behind decisions or predictions made by the AI — are among the most significant problems with AI models. It is often challenging to understand how these models arrive at their conclusions, making it difficult to trust and ensure the integrity of their output,” said Scott Purvis, Head of the Information Management Section in the IAEA’s Division of Nuclear Security. “This becomes particularly problematic when these models replace sensors providing direct measurements and human experience gained with the unique characteristics of each facility. It becomes impractical to place any assurance in the system’s integrity unless there is a prior comprehensive advanced understanding of the AI algorithms to recognize how and why decisions are made.”\nThe IAEA’s guidance on computer security for nuclear security includes best practices on human checks and balances to guide facilities’ awareness of which processes can be automated by AI and which should continue to have human oversight, at least until the risks of this rapidly developing technology are known. They also provide an essential resource that can enable countries to put important computer security measures in place to detect, prevent and respond to cyberattacks.\nAdditionally, a CRP was developed by the IAEA to support research in strengthening computer security. Entitled “Enhancing Computer Security Incident Analysis at Nuclear Facilities”, the CRP brought together representatives of 13 countries to work on improving computer security capabilities, including AI techniques, at nuclear facilities to detect anomalies indicating targeted cyberattacks.\nThe race to adopt AI technologies AI has shown its potential to benefit people who use nuclear technology for peaceful ends. As its use to enhance processes and operations in nuclear and radiological facilities expands, so too must the awareness of the risks associated with its broader adoption. Organizations must maintain a robust computer security programme to assure nuclear security while benefiting from AI.\nDoing so requires a fundamental paradigm shift in how trust and sensitivity is viewed. Every potential point of failure in a system must be considered, even those unrelated to its design. Malicious actors can leverage AI to create more sophisticated malware, automate cyberattacks, exploit biases and vulnerabilities within the models, or bypass security measures by mimicking legitimate user behaviour. This ‘arms race’ between defenders and attackers will require constant innovation and adaptation.\nGreater use of AI technology to enhance computer security measures at nuclear facilities could offer significant benefits, including enhanced threat detection, proactive security measures, reduced reliance on human intervention and improved incident response. By embracing the benefits of AI while addressing its risks, organizations can significantly enhance their computer security in the face of evolving cyberthreats.\n","date_published":"2023-06-26T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/artificial-intelligence-nuclear-world/","image":"https://blog.mitcdh.au/images/artificial-intelligence-nuclear-world.webp","summary":"Originally written for the Volume 64-2 of the IAEA Bulletin","tags":["Writing","Nuclear","AI","Technology","Security"],"title":"How Artificial Intelligence Will Change Information and Computer Security in the Nuclear World","url":"https://blog.mitcdh.au/posts/artificial-intelligence-nuclear-world/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-06-24T22:06:29Z","id":"https://blog.mitcdh.au/posts/travelling-with-opcia-to-hallstat-austria/","image":"https://blog.mitcdh.au/images/travelling-with-opcia-to-hallstat-austria.jpg","summary":"Adventures behind the lens.","tags":["Album"],"title":"Travelling With OPCIA to Hallstat, Austria","url":"https://blog.mitcdh.au/posts/travelling-with-opcia-to-hallstat-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis article has been adapted with only formatting changes from a paper accepted and presented by \u003ca href=\"https://www.linkedin.com/in/lenhard-reuter-4a170aaa/\"\u003eLenhard Reuter\u003c/a\u003e during CyberCon23 titled \u0026lsquo;Supporting Flexible and Engaging Computer Security Training Courses with the Online Learners Platform and Hands-on Exercises\u0026rsquo; authored by \u003ca href=\"https://www.linkedin.com/in/lenhard-reuter-4a170aaa/\"\u003eLenhard Reuter\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/b3n4kh/\"\u003eBenjamin Akhras\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/david-allison-infosec/\"\u003eDavid Allison\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/agronbajraktari/\"\u003eAgron Bajraktari\u003c/a\u003e, \u003ca href=\"http://www.lac.usp.br/~rpm/english/index.html\"\u003eRicardo Paulino Marques\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/francesca-soro-40601b148/\"\u003eFrancesca Soro\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/paul-smith-2aa618297/\"\u003ePaul Smith\u003c/a\u003e, and myself.\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"abstract\"\u003eAbstract\u003c/h1\u003e\n\u003cp\u003eThe IAEA provides training courses that have the goal of raising awareness of computer security issues that are associated with nuclear facilities and those associated with radioactive materials. As part of this goal, the courses aim to deliver \u003cem\u003eaffective\u003c/em\u003e learning outcomes — in other words, outcomes that motivate the need for computer security and change attitudes toward the topic. To help achieve this, hands-on (practical) exercises are an ingredient of courses, using equipment and systems that are representative of those found in the field and show the functional consequences of cyber-attacks. To support these outcomes, the International Atomic Agency (IAEA) and AIT Austrian Institute of Technology have initiated a joint activity to develop an online learning platform and hands-on exercises that can be hosted on a cyber range — a virtual environment, which can be used to conduct computer security exercises and training. In this paper, we present an overview of this activity and describe the \u003cem\u003eLearners\u003c/em\u003e platform — a learning management system — and give an overview of the cyber range-based hands-on exercises that are being developed.\u003c/p\u003e\n\u003ch1 id=\"1-introduction\"\u003e1. Introduction\u003c/h1\u003e\n\u003cp\u003eThe Covid-19 pandemic has resulted in changes in the way that we conduct business, including more use of online tools to support remote or hybrid activities. Reflecting this situation, and a more general desire to provide flexible, engaging, and sustainable computer security training courses, the IAEA and the AIT started a joint activity to develop an online training platform and accompanying hands-on exercises.\u003c/p\u003e\n\u003cp\u003eThe online training platform — called \u003cem\u003eLearners\u003c/em\u003e — allows participants of a course to complete exercises in the platform, submit their responses, and directly access virtual environments that are representative of those found in facilities. Participants require only a web browser to access Learners and the virtual exercise environments. Instructors can immediately review responses in the platform. The hands-on exercises make use of virtualized representative environments from a nuclear facility — the Asherah Nuclear Power Plant (NPP), which was developed in the IAEA CRP J02008 \u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e — and a facility associated with radioactive materials, a hospital. To this end, virtualized Instrumentation and Control (I\u0026amp;C) systems, along with virtual Physical Protection Systems (PPSs), are being developed.\u003c/p\u003e\n\u003cp\u003eIn this paper, we present some of the details of the Learners platform and the hands-on exercises that are being developed, as part of this joint endeavour. The intention is to raise awareness of this activity to support the development of a community around the platform and engage Member States that would seek to use it for training. The rest of this paper is organized, as follows. In Section 2, we present an overview of cyber ranges and the open-source technologies that are being used to realize the range that is being used in our work. The Learners platform is presented in Section 3, outlining its functionality and implementation. Section 4 presents an overview of the hands-on exercises that are being developed, as part of the joint activity, and the design of the virtual exercise environment.\u003c/p\u003e\n\u003ch1 id=\"2-cyber-range-technology\"\u003e2. Cyber Range Technology\u003c/h1\u003e\n\u003cp\u003eThe virtual exercises that are being developed are intended to be deployed on a \u003cem\u003ecyber range\u003c/em\u003e. A cyber range can be defined as \u003cem\u003e\u0026ldquo;a platform for the development, delivery and use of interactive simulation environments [\u0026hellip;]\u0026rdquo;\u003c/em\u003e \u003csup id=\"fnref:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e. In our case, the cyber range is being used to simulate representative environments that can be found in nuclear facilities and those associated with radioactive materials.\u003c/p\u003e\n\u003cp\u003eIn general, a cyber range architecture can be described using three system modules (i.e., building blocks), which are shown in Figure 1. In this architecture, modules have a distinct purpose and are loosely coupled in order to make changing the underlying technologies or implementation as easy as possible. For example, it should be possible to replace OpenStack — part of the Computing Platform — with solutions from commercial providers such as VMWare vSphere. The intention is that Member States that wish to make use of the hands-on exercises can do so using a cyber range that relies on open-source software.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/online-learning-platform-paper_01.webp\" width=\"329\" height=\"146\" alt=\"Cyber range visualised as building blocks\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 1 An overview of the building blocks of the cyber range\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe implementation of the core open-source modules of the cyber range can be summarized, as follows:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eComputing Platform:\u003c/em\u003e At the core of a cyber range is the ability to simulate and integrate systems to build potentially complex networked infrastructures. To this end, we use OpenStack as the compute engine and the KVM hypervisor technology.\u003c/li\u003e\n\u003cli\u003e\u003cem\u003eInfrastructure Provisioning:\u003c/em\u003e The infrastructure provisioning module is the component that is used to create network configurations and orchestrate them on a computing platform. The range uses an infrastructure-as-code tool, called Terraform, that supports a variety of computing platforms and allows the definition of reusable complex infrastructure modules.\u003c/li\u003e\n\u003cli\u003e\u003cem\u003eSoftware Provisioning:\u003c/em\u003e The software provisioning module is used to add (and configure) functionality to virtual machines on the cyber range. In our case, the software provisioning module is implemented using a configuration management tool, called Ansible. Ansible provides the ability to define software deployments and configurations as program code templates.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe use of these technologies, such as Ansible and Terraform, enables the environments that are developed for hands-on exercises to be shared. The intention is to support knowledge exchange regarding the implementation of the cyber range with IAEA training providers, towards a common set of tools and technologies, enabling reuse of the exercises and scenarios that are developed in the project.\u003c/p\u003e\n\u003ch1 id=\"3-the-learners-platform\"\u003e3. The Learners Platform\u003c/h1\u003e\n\u003cp\u003eThe Learners platform supports relevant stakeholders with each step of an exercise lifecycle. Starting from the development of the content by a creator (e.g., a Subject Matter Expert) to the execution of exercises by course participants, monitoring by instructors during an exercise, and post-processing.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/online-learning-platform-paper_02.webp\" width=\"1437\" height=\"670\" alt=\"Exercise lifecycle presented as multiple screenshots\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 2 Learners exercise lifecycle\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe Learners exercise lifecycle can be summarized, as follows, as depicted in Figure 2:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eContent is created in the freely available Markdown format. To do this any text editor and web interface can be used. Since Markdown is a plain text format, it can be integrated with version control systems, such as Git, and facilitates collaboration across multiple teams.\u003c/li\u003e\n\u003cli\u003eThe Learners platform uses the website framework \u003cem\u003eHugo\u003c/em\u003e to translate the Markdown-formatted exercise descriptions into rendered static web pages. By incorporating a custom Learners theme, styling is adjusted to give the content a cohesive look. In addition, so-called \u003cem\u003eshortcodes\u003c/em\u003e are defined in the theme. These enrich the Markdown format and enable formatting features that are not natively supported. The most important role of the theme is to enable communication between the static content and the Learners backend (e.g., for submitting form data).\u003c/li\u003e\n\u003cli\u003eThe Learners application integration, consisting of a \u003cem\u003eFlask\u003c/em\u003e backend with an \u003cem\u003eSQLite\u003c/em\u003e database and a \u003cem\u003eVUE\u003c/em\u003e frontend, acts as a coordinator between the content relevant to the user. The application is the central access point, requiring only a web browser, thus enabling online or hybrid exercises. This part also handles authentication and user management. The content is controlled via a sidebar and is integrated as full screen iFrames, which allows any content that is accessible via the web. This provides the possibility to integrate additional tools, e.g., for threat analysis (\u003cem\u003eMITRE\u003c/em\u003e \u003cem\u003eATT\u0026amp;CK Navigator\u003c/em\u003e)  and graphics editing (\u003cem\u003edraw.io\u003c/em\u003e), directly into the learning environment and to use them as a part of an exercise. By using noVNC to access clients in the cyber range (see Section 4), interaction with the provisioned exercise environment is also provided directly in a participant\u0026rsquo;s web browser using one of the iFrames.\u003c/li\u003e\n\u003cli\u003eUser management distinguishes between the roles that are assigned to users. Through annotations in the content creation in Step 1, additional information can be rendered to the content pages for instructors. In addition, instructors receive an administration view (5), in which they can monitor the submissions of the participants and see an overview of their progress.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eIn addition to these core building blocks, there are further features that are provided by Learners:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eMultilingual support:\u003c/em\u003e Thanks to the use of Markdown, exercises can be submitted to translators who can perform inline translations and deploy them directly. Users have the possibility to change the displayed language in Learners.\u003c/li\u003e\n\u003cli\u003e\u003cem\u003eTwo exercise types:\u003c/em\u003e Form exercises are textual, wherein participants answer questions and submit their responses; meanwhile, Action-based exercises, wherein the user can perform a self-paced training, e.g., setting configuration changes on the infrastructure and then initializing a check method with a submission to verify that the exercise goal has been achieved.\u003c/li\u003e\n\u003cli\u003e\u003cem\u003eGuided exercises:\u003c/em\u003e Learners offers the possibility to display notifications in the web browser to a course participant, which can provide step-by-step instructions or general assistance.\u003c/li\u003e\n\u003cli\u003e\u003cem\u003eImmediate\u003c/em\u003e \u003cem\u003efeedback:\u003c/em\u003e It can be difficult to get direct feedback from participants about their experiences with an exercise. Learners provides support for this feature via an additional form that can be submitted directly after an exercise has been completed.\u003c/li\u003e\n\u003cli\u003e\u003cem\u003ePresentation integration:\u003c/em\u003e Learners offers the possibility to provide instructor presentations as a viewable PDF document, which can be linked to an interactive questionnaire.\u003c/li\u003e\n\u003cli\u003e\u003cem\u003eMultiscreen support:\u003c/em\u003e Participants have the possibility to open content in a new web browser tab. This allows the user to customize their exercise environment so that it is comfortable for them to perform exercises (e.g., they can show exercise information on a second screen).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1 id=\"4-hands-on-virtual-exercises\"\u003e4. Hands-on Virtual Exercises\u003c/h1\u003e\n\u003cp\u003eImplemented in the Learners platform are twelve hands-on exercises that support several computer security learning objectives. Specifically, they inform participants about concepts that are described in IAEA Nuclear Security Series (NSS) guidance on computer security, including NSS 17-T Rev. 1 \u003csup id=\"fnref:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e and NSS 33-T \u003csup id=\"fnref:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e. The exercises are organized into six thematic areas that support concepts in the targeted NSS guidance documents. The learning objectives of the exercises that are associated with the six thematic areas are summarized in Table 1.\u003c/p\u003e\n\u003cp\u003eTable 1 The hands-on exercises thematic areas and associated learning objectives\u003c/p\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eThematic Area\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eExercise Objectives\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cem\u003eNormal Operations\u003c/em\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eThe objective of these exercises is to enable the participants to develop an appreciation of the types of systems that are associated with nuclear I\u0026amp;C systems and how they can be used to support facility functions.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cem\u003eFunctional Impact\u003c/em\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eThe exercises in this thematic area highlight how cyber-enabled adversaries can impair the function of systems, which could lead to nuclear safety and security consequences.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cem\u003eRisk Informed Approach\u003c/em\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eIAEA NSS computer security guidance advocates taking a risk-informed approach to computer security, which aligns computer security requirements with the consequences of compromise on nuclear security, safety, and emergency preparedness. In this thematic area, there are exercises that explore this approach.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cem\u003eTechnical Vulnerability Management\u003c/em\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eTechnical Vulnerability Management (TVM) is a major undertaking in facilities; this thematic area provides participants with the opportunity to engage in practical TVM activities, such as system hardening, as well as gaining an appreciation of the broader computer security programme aspects of this important activity.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003cem\u003eDefensive Computer Security Architecture\u003c/em\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eThis thematic area informs participants about how risk informed security requirements can be realized via a Defensive Computer Security Architecture (DCSA). Practical activities that are associated with DCSA implementation are performed, such as configuring zone boundary points (e.g., firewalls).\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003eTo support these exercises, a bespoke simulated (or virtual) environment is being built that can be deployed on a cyber range. This environment is depicted in Figure 3 and can be summarized, as follows. The environment is organized into two areas — a management and participant area. The management area consists of systems and services that are needed to implement the exercises; a single instance of this area is deployed per course. Meanwhile, the participants area is instantiated \u003cem\u003eper participant\u003c/em\u003e or participant group and represent systems that can be found in facilities.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/online-learning-platform-paper_03.webp\" width=\"612\" height=\"348\" alt=\"Exercise system and network diagram\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 3 An overview of the virtual exercise environment that will be used to support the hands-on exercises\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eIn the management area, there are several services and systems: participants connect to the environment using a standard Web browser via a reverse proxy, which redirects them to the Leaners platform. In addition to being able to access the exercises via Learners*,* the participants can access via their web browser the systems in the participant network, such as the Security Operations Centre (SOC) client. This is enabled using a noVNC server that is hosted in the management network. The Asherah Webserver is used to host a collection of web pages that are associated with the Asherah NPP. These are used for the OSINT exercise, as discussed in Table 1.\u003c/p\u003e\n\u003cp\u003eThere are two further noteworthy services that are hosted in the management area — \u003cem\u003eVenjix\u003c/em\u003e and the Choreographer. Venjix is used to execute scripts that, for example, perform cyber-attacks against systems in the participant networks. These scripts are invoked from the Learners platform (as part of \u003cem\u003eaction-based exercises\u003c/em\u003e) in response to interactions from participants and provide a way to hide the implementation of attacks from participants. The \u003cem\u003eChoreographer\u003c/em\u003e is a service that interacts with Venjix and the systems in the participant areas, such as door controllers and security cameras, in order to emulate the real-world consequences of interactions with physical protection systems. For example, if a participant successfully completes multi-factor authentication that opens a door, a surveillance camera that is associated with the area where the door is located should show a person going through the door. This logic is implemented in the Choreographer, which invokes interfaces that are exposed on the systems in the participant areas (e.g., to play a video).\u003c/p\u003e\n\u003cp\u003eRegarding the participant networks, there are three sets of zones — those associated with I\u0026amp;C and the management and control of processes in the Asherah NPP; a set of zones that emulate a physical protection system; and computer security operations. In all cases, open-source and free-to-use software is used to implement the systems and services in these zones. For example, the Plant HMI will be implemented using ScadaLTS, the PLC and the software that is used to program it will be implemented using OpenPLC and its Editor software, respectively. Meanwhile, the Asherah Nuclear Simulator (ANS) \u003csup id=\"fnref:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e, which was developed in IAEA CRP J02008, will be used to realize the simulated process. The use of the ANS enables participants to observe facility level consequences of cyber-attacks to I\u0026amp;C systems and is important for the affective learning outcomes that we are targeting. The ANS is available to IAEA Member States, on request. For the physical protection systems, custom program code is being implemented in order to create representative facsimiles of devices and systems.\u003c/p\u003e\n\u003ch1 id=\"5-conclusion\"\u003e5. Conclusion\u003c/h1\u003e\n\u003cp\u003eThe Covid-19 pandemic made it very challenging — if not impossible — to conduct training engagements wherein participants had physical access to representative equipment. Triggered by this challenge and a more general desire to make training courses more sustainable and flexible to execute, the IAEA and AIT engaged in a project to develop the hands-on exercises that are presented in this paper. This initial endeavour will conclude in 2023 and will result thereafter in the exercises and Learners being available to IAEA Member States. Future work will focus on growing a community of users and developers around this initiative to increase its maturity and garner wider interest.\u003c/p\u003e\n\u003ch1 id=\"references\"\u003eReferences\u003c/h1\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency, Enhancing Computer Security Incident Analysis at Nuclear Facilities, Available online: \u003ca href=\"https://www.iaea.org/projects/crp/j02008\"\u003ehttps://www.iaea.org/projects/crp/j02008\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:2\"\u003e\n\u003cp\u003eECSO. Understanding cyber ranges: From hype to reality. Technical report, European Cyber Security Organisation, March 2020.\u0026#160;\u003ca href=\"#fnref:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:3\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency, Computer Security Techniques for Nuclear Facilities, IAEA Nuclear Security Series No. 17-T (Rev. 1), IAEA, Vienna (2021)\u0026#160;\u003ca href=\"#fnref:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:4\"\u003e\n\u003cp\u003eInternational Atomic Energy Agency, Computer Security of Instrumentation and Control Systems at Nuclear Facilities, IAEA Nuclear Security Series No. 33-T, IAEA, Vienna (2018)\u0026#160;\u003ca href=\"#fnref:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:5\"\u003e\n\u003cp\u003eR.A. Busquim e Silva, J.R.C. Piqueira, J.J. Cruz, R.P. Marques, Cybersecurity Assessment Framework for Digital Interface Between Safety and Security at Nuclear Power Plants, International Journal of Critical Infrastructure Protection, Volume 34, 2021, 100453, ISSN 1874-5482, \u003ca href=\"https://doi.org/10.1016/j.ijcip.2021.100453\"\u003ehttps://doi.org/10.1016/j.ijcip.2021.100453\u003c/a\u003e.\u0026#160;\u003ca href=\"#fnref:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This article has been adapted with only formatting changes from a paper accepted and presented by Lenhard Reuter during CyberCon23 titled ‘Supporting Flexible and Engaging Computer Security Training Courses with the Online Learners Platform and Hands-on Exercises’ authored by Lenhard Reuter, Benjamin Akhras, David Allison, Agron Bajraktari, Ricardo Paulino Marques, Francesca Soro, Paul Smith, and myself.\nAbstract The IAEA provides training courses that have the goal of raising awareness of computer security issues that are associated with nuclear facilities and those associated with radioactive materials. As part of this goal, the courses aim to deliver affective learning outcomes — in other words, outcomes that motivate the need for computer security and change attitudes toward the topic. To help achieve this, hands-on (practical) exercises are an ingredient of courses, using equipment and systems that are representative of those found in the field and show the functional consequences of cyber-attacks. To support these outcomes, the International Atomic Agency (IAEA) and AIT Austrian Institute of Technology have initiated a joint activity to develop an online learning platform and hands-on exercises that can be hosted on a cyber range — a virtual environment, which can be used to conduct computer security exercises and training. In this paper, we present an overview of this activity and describe the Learners platform — a learning management system — and give an overview of the cyber range-based hands-on exercises that are being developed.\n1. Introduction The Covid-19 pandemic has resulted in changes in the way that we conduct business, including more use of online tools to support remote or hybrid activities. Reflecting this situation, and a more general desire to provide flexible, engaging, and sustainable computer security training courses, the IAEA and the AIT started a joint activity to develop an online training platform and accompanying hands-on exercises.\nThe online training platform — called Learners — allows participants of a course to complete exercises in the platform, submit their responses, and directly access virtual environments that are representative of those found in facilities. Participants require only a web browser to access Learners and the virtual exercise environments. Instructors can immediately review responses in the platform. The hands-on exercises make use of virtualized representative environments from a nuclear facility — the Asherah Nuclear Power Plant (NPP), which was developed in the IAEA CRP J02008 1 — and a facility associated with radioactive materials, a hospital. To this end, virtualized Instrumentation and Control (I\u0026C) systems, along with virtual Physical Protection Systems (PPSs), are being developed.\nIn this paper, we present some of the details of the Learners platform and the hands-on exercises that are being developed, as part of this joint endeavour. The intention is to raise awareness of this activity to support the development of a community around the platform and engage Member States that would seek to use it for training. The rest of this paper is organized, as follows. In Section 2, we present an overview of cyber ranges and the open-source technologies that are being used to realize the range that is being used in our work. The Learners platform is presented in Section 3, outlining its functionality and implementation. Section 4 presents an overview of the hands-on exercises that are being developed, as part of the joint activity, and the design of the virtual exercise environment.\n2. Cyber Range Technology The virtual exercises that are being developed are intended to be deployed on a cyber range. A cyber range can be defined as “a platform for the development, delivery and use of interactive simulation environments […]” 2. In our case, the cyber range is being used to simulate representative environments that can be found in nuclear facilities and those associated with radioactive materials.\nIn general, a cyber range architecture can be described using three system modules (i.e., building blocks), which are shown in Figure 1. In this architecture, modules have a distinct purpose and are loosely coupled in order to make changing the underlying technologies or implementation as easy as possible. For example, it should be possible to replace OpenStack — part of the Computing Platform — with solutions from commercial providers such as VMWare vSphere. The intention is that Member States that wish to make use of the hands-on exercises can do so using a cyber range that relies on open-source software.\nFigure 1 An overview of the building blocks of the cyber range\nThe implementation of the core open-source modules of the cyber range can be summarized, as follows:\nComputing Platform: At the core of a cyber range is the ability to simulate and integrate systems to build potentially complex networked infrastructures. To this end, we use OpenStack as the compute engine and the KVM hypervisor technology. Infrastructure Provisioning: The infrastructure provisioning module is the component that is used to create network configurations and orchestrate them on a computing platform. The range uses an infrastructure-as-code tool, called Terraform, that supports a variety of computing platforms and allows the definition of reusable complex infrastructure modules. Software Provisioning: The software provisioning module is used to add (and configure) functionality to virtual machines on the cyber range. In our case, the software provisioning module is implemented using a configuration management tool, called Ansible. Ansible provides the ability to define software deployments and configurations as program code templates. The use of these technologies, such as Ansible and Terraform, enables the environments that are developed for hands-on exercises to be shared. The intention is to support knowledge exchange regarding the implementation of the cyber range with IAEA training providers, towards a common set of tools and technologies, enabling reuse of the exercises and scenarios that are developed in the project.\n3. The Learners Platform The Learners platform supports relevant stakeholders with each step of an exercise lifecycle. Starting from the development of the content by a creator (e.g., a Subject Matter Expert) to the execution of exercises by course participants, monitoring by instructors during an exercise, and post-processing.\nFigure 2 Learners exercise lifecycle\nThe Learners exercise lifecycle can be summarized, as follows, as depicted in Figure 2:\nContent is created in the freely available Markdown format. To do this any text editor and web interface can be used. Since Markdown is a plain text format, it can be integrated with version control systems, such as Git, and facilitates collaboration across multiple teams. The Learners platform uses the website framework Hugo to translate the Markdown-formatted exercise descriptions into rendered static web pages. By incorporating a custom Learners theme, styling is adjusted to give the content a cohesive look. In addition, so-called shortcodes are defined in the theme. These enrich the Markdown format and enable formatting features that are not natively supported. The most important role of the theme is to enable communication between the static content and the Learners backend (e.g., for submitting form data). The Learners application integration, consisting of a Flask backend with an SQLite database and a VUE frontend, acts as a coordinator between the content relevant to the user. The application is the central access point, requiring only a web browser, thus enabling online or hybrid exercises. This part also handles authentication and user management. The content is controlled via a sidebar and is integrated as full screen iFrames, which allows any content that is accessible via the web. This provides the possibility to integrate additional tools, e.g., for threat analysis (MITRE ATT\u0026CK Navigator) and graphics editing (draw.io), directly into the learning environment and to use them as a part of an exercise. By using noVNC to access clients in the cyber range (see Section 4), interaction with the provisioned exercise environment is also provided directly in a participant’s web browser using one of the iFrames. User management distinguishes between the roles that are assigned to users. Through annotations in the content creation in Step 1, additional information can be rendered to the content pages for instructors. In addition, instructors receive an administration view (5), in which they can monitor the submissions of the participants and see an overview of their progress. In addition to these core building blocks, there are further features that are provided by Learners:\nMultilingual support: Thanks to the use of Markdown, exercises can be submitted to translators who can perform inline translations and deploy them directly. Users have the possibility to change the displayed language in Learners. Two exercise types: Form exercises are textual, wherein participants answer questions and submit their responses; meanwhile, Action-based exercises, wherein the user can perform a self-paced training, e.g., setting configuration changes on the infrastructure and then initializing a check method with a submission to verify that the exercise goal has been achieved. Guided exercises: Learners offers the possibility to display notifications in the web browser to a course participant, which can provide step-by-step instructions or general assistance. Immediate feedback: It can be difficult to get direct feedback from participants about their experiences with an exercise. Learners provides support for this feature via an additional form that can be submitted directly after an exercise has been completed. Presentation integration: Learners offers the possibility to provide instructor presentations as a viewable PDF document, which can be linked to an interactive questionnaire. Multiscreen support: Participants have the possibility to open content in a new web browser tab. This allows the user to customize their exercise environment so that it is comfortable for them to perform exercises (e.g., they can show exercise information on a second screen). 4. Hands-on Virtual Exercises Implemented in the Learners platform are twelve hands-on exercises that support several computer security learning objectives. Specifically, they inform participants about concepts that are described in IAEA Nuclear Security Series (NSS) guidance on computer security, including NSS 17-T Rev. 1 3 and NSS 33-T 4. The exercises are organized into six thematic areas that support concepts in the targeted NSS guidance documents. The learning objectives of the exercises that are associated with the six thematic areas are summarized in Table 1.\nTable 1 The hands-on exercises thematic areas and associated learning objectives\nThematic Area Exercise Objectives Normal Operations The objective of these exercises is to enable the participants to develop an appreciation of the types of systems that are associated with nuclear I\u0026C systems and how they can be used to support facility functions. Functional Impact The exercises in this thematic area highlight how cyber-enabled adversaries can impair the function of systems, which could lead to nuclear safety and security consequences. Risk Informed Approach IAEA NSS computer security guidance advocates taking a risk-informed approach to computer security, which aligns computer security requirements with the consequences of compromise on nuclear security, safety, and emergency preparedness. In this thematic area, there are exercises that explore this approach. Technical Vulnerability Management Technical Vulnerability Management (TVM) is a major undertaking in facilities; this thematic area provides participants with the opportunity to engage in practical TVM activities, such as system hardening, as well as gaining an appreciation of the broader computer security programme aspects of this important activity. Defensive Computer Security Architecture This thematic area informs participants about how risk informed security requirements can be realized via a Defensive Computer Security Architecture (DCSA). Practical activities that are associated with DCSA implementation are performed, such as configuring zone boundary points (e.g., firewalls). To support these exercises, a bespoke simulated (or virtual) environment is being built that can be deployed on a cyber range. This environment is depicted in Figure 3 and can be summarized, as follows. The environment is organized into two areas — a management and participant area. The management area consists of systems and services that are needed to implement the exercises; a single instance of this area is deployed per course. Meanwhile, the participants area is instantiated per participant or participant group and represent systems that can be found in facilities.\nFigure 3 An overview of the virtual exercise environment that will be used to support the hands-on exercises\nIn the management area, there are several services and systems: participants connect to the environment using a standard Web browser via a reverse proxy, which redirects them to the Leaners platform. In addition to being able to access the exercises via Learners*,* the participants can access via their web browser the systems in the participant network, such as the Security Operations Centre (SOC) client. This is enabled using a noVNC server that is hosted in the management network. The Asherah Webserver is used to host a collection of web pages that are associated with the Asherah NPP. These are used for the OSINT exercise, as discussed in Table 1.\nThere are two further noteworthy services that are hosted in the management area — Venjix and the Choreographer. Venjix is used to execute scripts that, for example, perform cyber-attacks against systems in the participant networks. These scripts are invoked from the Learners platform (as part of action-based exercises) in response to interactions from participants and provide a way to hide the implementation of attacks from participants. The Choreographer is a service that interacts with Venjix and the systems in the participant areas, such as door controllers and security cameras, in order to emulate the real-world consequences of interactions with physical protection systems. For example, if a participant successfully completes multi-factor authentication that opens a door, a surveillance camera that is associated with the area where the door is located should show a person going through the door. This logic is implemented in the Choreographer, which invokes interfaces that are exposed on the systems in the participant areas (e.g., to play a video).\nRegarding the participant networks, there are three sets of zones — those associated with I\u0026C and the management and control of processes in the Asherah NPP; a set of zones that emulate a physical protection system; and computer security operations. In all cases, open-source and free-to-use software is used to implement the systems and services in these zones. For example, the Plant HMI will be implemented using ScadaLTS, the PLC and the software that is used to program it will be implemented using OpenPLC and its Editor software, respectively. Meanwhile, the Asherah Nuclear Simulator (ANS) 5, which was developed in IAEA CRP J02008, will be used to realize the simulated process. The use of the ANS enables participants to observe facility level consequences of cyber-attacks to I\u0026C systems and is important for the affective learning outcomes that we are targeting. The ANS is available to IAEA Member States, on request. For the physical protection systems, custom program code is being implemented in order to create representative facsimiles of devices and systems.\n5. Conclusion The Covid-19 pandemic made it very challenging — if not impossible — to conduct training engagements wherein participants had physical access to representative equipment. Triggered by this challenge and a more general desire to make training courses more sustainable and flexible to execute, the IAEA and AIT engaged in a project to develop the hands-on exercises that are presented in this paper. This initial endeavour will conclude in 2023 and will result thereafter in the exercises and Learners being available to IAEA Member States. Future work will focus on growing a community of users and developers around this initiative to increase its maturity and garner wider interest.\nReferences International Atomic Energy Agency, Enhancing Computer Security Incident Analysis at Nuclear Facilities, Available online: https://www.iaea.org/projects/crp/j02008 ↩︎\nECSO. Understanding cyber ranges: From hype to reality. Technical report, European Cyber Security Organisation, March 2020. ↩︎\nInternational Atomic Energy Agency, Computer Security Techniques for Nuclear Facilities, IAEA Nuclear Security Series No. 17-T (Rev. 1), IAEA, Vienna (2021) ↩︎\nInternational Atomic Energy Agency, Computer Security of Instrumentation and Control Systems at Nuclear Facilities, IAEA Nuclear Security Series No. 33-T, IAEA, Vienna (2018) ↩︎\nR.A. Busquim e Silva, J.R.C. Piqueira, J.J. Cruz, R.P. Marques, Cybersecurity Assessment Framework for Digital Interface Between Safety and Security at Nuclear Power Plants, International Journal of Critical Infrastructure Protection, Volume 34, 2021, 100453, ISSN 1874-5482, https://doi.org/10.1016/j.ijcip.2021.100453. ↩︎\n","date_published":"2023-06-23T18:06:55+03:00","id":"https://blog.mitcdh.au/posts/online-learning-platform-paper/","image":"https://blog.mitcdh.au/images/online-learning-platform-paper.webp","summary":"This article has been adapted with only formatting changes from a paper accepted and presented by Lenhard Reuter during CyberCon23 titled \u0026lsquo;Supporting Flexible and Engaging Computer Security Training Courses with the Online Learners Platform and Hands-on Exercises\u0026rsquo; authored by Lenhard Reuter, Benjamin Akhras, David Allison, Agron Bajraktari, Ricardo Paulino Marques, Francesca Soro, Paul Smith, and myself.\nAbstract The IAEA provides training courses that have the goal of raising awareness of computer security issues that are associated with nuclear facilities and those associated with radioactive materials. As part of this goal, the courses aim to deliver affective learning outcomes — in other words, outcomes that motivate the need for computer security and change attitudes toward the topic. To help achieve this, hands-on (practical) exercises are an ingredient of courses, using equipment and systems that are representative of those found in the field and show the functional consequences of cyber-attacks. To support these outcomes, the International Atomic Agency (IAEA) and AIT Austrian Institute of Technology have initiated a joint activity to develop an online learning platform and hands-on exercises that can be hosted on a cyber range — a virtual environment, which can be used to conduct computer security exercises and training. In this paper, we present an overview of this activity and describe the Learners platform — a learning management system — and give an overview of the cyber range-based hands-on exercises that are being developed.\n","tags":["Writing","Nuclear","Technology","Security"],"title":"Supporting Flexible and Engaging Computer Security Training Courses with the Online Learners Platform and Hands-on Exercises","url":"https://blog.mitcdh.au/posts/online-learning-platform-paper/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis article has been adapted verbatim from a paper accepted and presented during \u003ca href=\"https://www.iaea.org/events/cybercon23\"\u003eCyberCon23\u003c/a\u003e titled \u0026lsquo;Safety versus Security: What’s the difference and why it matters\u0026rsquo; authored by \u003ca href=\"https://www.linkedin.com/in/samuelclements/\"\u003eSamuel Clements\u003c/a\u003e, \u003ca href=\"https://www.linkedin.com/in/mike-stjohn-green-685b6163/\"\u003eMike StJohn-Green\u003c/a\u003e and myself.\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"1-abstract\"\u003e1. Abstract\u003c/h1\u003e\n\u003cp\u003eIn the “Safety-First” culture of the nuclear industry, the nuanced differences between security and safety can be lost. The use of powerful software-programmable digital technology provides the means to transform instrumentation and control systems, but also provides unparalleled opportunity for malicious action by criminals and others.\u003c/p\u003e\n\u003cp\u003eComputer security is therefore increasingly vital to support safety, and safety analysis is important to inform computer security. Superficially, the concepts are so similar that the words are often used interchangeably. This is especially true in languages like Spanish and Russian where the words seguridad and безопасность are used to define both safety and security. However, below the surface, the two disciplines are based on fundamentally different assumptions, so incompatibilities exist. These differences can lead to serious deficiencies in the response of safety systems to failures and of security systems to malicious attack.\u003c/p\u003e\n\u003cp\u003eIn this paper the authors provide examples of these deficiencies, highlight important differences between the two concepts, demonstrate why they matter, and provide the reader with recommendations for how to address this issue.\u003c/p\u003e\n\u003ch1 id=\"2-differences-in-concepts\"\u003e2. Differences in concepts\u003c/h1\u003e\n\u003cp\u003eLack of precision in language leads to misunderstanding. This fallibility is especially true with the concepts of “safety” and “security,” which are related but distinct concepts that feature important differences. This section provides examples of possible misunderstandings and potential consequences. Seguridad vs Seguridad  “Safety” and “Security” are essential concepts of a nuclear programme for which much thought and effort are invested in securing nuclear sites and assuring the safety of nuclear processes. Unfortunately, lack of precision in language leads to many misunderstandings, as illustrated in the following story.\u003c/p\u003e\n\u003cp\u003eA presentation about nuclear security was scheduled to be delivered to senior leaders of nuclear facilities. The presentation’s intent was to inform new leadership of the importance and impact of nuclear security. The leaders had backgrounds in nuclear engineering and safety but were not well versed in the various aspects of a nuclear security programme. The presentation was developed in English and translated to Spanish, the native language of the intended recipients. Thankfully, during the dry run exercise leading up to the presentation someone noticed context that was lost in translation. Spanish only has one word for both safety and security. Additional adjectives or qualifiers must be used to distinguish between them. Lacking this context, the whole purpose of the presentation might have been undermined and intended meanings lost. Unfortunately, Spanish is not alone in the linguistic trap of using a single word for both safety and security. Portuguese (segurança), Russian (безопасность), Swedish (säkerhet), and Danish (sikkerhed) all use a single word to describe both safety and security.\u003c/p\u003e\n\u003cp\u003eA decision-maker might conclude that because the word is the same, the single word covers all the activities required for safety and security. This could lead to some vital activities not happening as needed, such as new security funding lines not being approved because “Seguridad is already funded” elsewhere. Similarly, decision-makers might conclude that, because “seguridad” is in someone’s job title, the entire range of safety and security tasks have been adequately assigned. However, even with two different words, as in English, there is further potential for misunderstanding as noted by PiètreCambacédès, “Dozens of explicit, but distinct, definitions can be found ranging from slightly different to completely incompatible definitions” \u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003ch2 id=\"security-and-safety-are-not-two-perfect-mirror-images-that-fit-together\"\u003eSecurity and safety are not two perfect mirror images that fit together.\u003c/h2\u003e\n\u003cp\u003eIn some organisations, the differences between safety and security are well accepted and different teams are tasked with each. It has been elegantly stated, “Safety: the system must not harm the world. Security: the world must not harm the system” \u003csup id=\"fnref:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e). These two definitions may appear to be mirror images of one another, suggesting that current safety and current security activities are perfectly complementary; that together the two disciplines may appear to perfectly address all relevant risks to “the system” and from “the system”; and finally, that the two disciplines will not conflict. However, none of this is necessarily true unless active coordination, collaboration, and change occur.\u003c/p\u003e\n\u003cp\u003eSafety is defined as reducing the risks of harm arising from dangerous situations, often referred to as “hazards”, to an acceptable level \u003csup id=\"fnref:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e. In general, safety analysis relies on modelling the failure of the components of the system to provide an acceptable level of confidence in the calculation of the residual safety risks.\u003c/p\u003e\n\u003cp\u003eWithin the nuclear sector, Probabilistic Safety Analysis (PSA) and Deterministic Safety Analysis (DSA) are methods used to evaluate the safety of a system or process. PSA uses statistical methods and models to estimate the likelihood of potential accidents and their consequences, considering the nature of known failures and human errors, as well as uncertainties in the behaviour of the system.\u003c/p\u003e\n\u003cp\u003eDSA, on the other hand, uses deterministic methods and models to analyse the behaviour of the system under normal and abnormal conditions. It involves determining the sequences of events that can lead to an accident and the corrective actions that may be undertaken to prevent such an event. The results of a DSA are usually expressed in terms of failure scenarios and the likelihood of their occurrence. However, it is vital to note that malicious action is typically out of scope of such analysis.\u003c/p\u003e\n\u003cp\u003eSecurity is defined as reducing the risks arising from malicious action, stemming ultimately from human motivation and behaviour, which is intrinsically difficult to model and calibrate with any confidence. Any calculation of likelihood or probability related to malicious human behaviour is particularly difficult to justify with any confidence \u003csup id=\"fnref:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. Risks arising from malicious action cannot in general be eliminated, only reduced, leaving an irreducible but hard-to-calibrate residual risk that is relevant to the safety analysis. Further, the malicious actor is very likely to change the system as part of any attack, and those changes will affect the safety analysis. This became evident with the exposure of the Log4j vulnerability \u003csup id=\"fnref:6\"\u003e\u003ca href=\"#fn:6\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e6\u003c/a\u003e\u003c/sup\u003e which is used in logging functions of safety and security related systems.\u003c/p\u003e\n\u003cp\u003eThis argument demonstrates that analyses of safety and security can make potentially incompatible assumptions and approximations. The general basis of the safety analysis is that the system under consideration is fully defined by the design and not subject to uncontrolled change, while security analysis generally makes the assumption that the adversary will change the system and that security measures cannot entirely prevent this, leaving an uncalibrated risk of change to the system.\u003c/p\u003e\n\u003ch2 id=\"single-or-multiple-simultaneous-failures\"\u003eSingle or multiple simultaneous failures\u003c/h2\u003e\n\u003cp\u003eAs introduced above, in both methods of safety analysis (PSA and DSA), the initiating events for the accidents under consideration typically focus on accidental events, such as equipment failure, natural disasters, or human error. Such events are typically analysed on an individual system basis or are bounded by common groupings of systems, structures, and components that fall under well understood criteria (e.g., systems susceptible to seismic risk).\u003c/p\u003e\n\u003cp\u003eIn contrast, a security analysis will typically focus on intentional events, such as malicious acts undertaken by an intelligent human adversary. Such a malicious adversary will be able to intelligently target systems, structures, and components to cause effects considered improbable (e.g., all redundant pumps fail at a coordinated time) or not considered within the design of the system (e.g., an actuation system, after experiencing a malicious modification to its setpoints, performs an action that propagates rather than contains the accident condition).\u003c/p\u003e\n\u003cp\u003eThese examples highlight security events that have the potential to trigger systemic risks, where a localised failure has the possibility to spread and cause a widespread and significant impact on the safety and security of the larger system. Such a systemic risk potentially leads to the failure of multiple interconnected systems. Such risks must be considered and addressed within the context of the overall facility and its operating environment. Today’s safety and security analysis may be deficient in identifying such multi-domain risks.\u003c/p\u003e\n\u003ch1 id=\"3-things-that-are-often-said-but-are-not-general-truths\"\u003e3. Things that are often said but are not general truths\u003c/h1\u003e\n\u003cp\u003eThis section takes some statements that the authors have heard from well-intentioned engineers, who shall remain anonymous. These statements are helpful in revealing some of the prevailing misunderstandings across many industries, including the nuclear sector.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eMy system is designed to be fail-safe so additional security is not necessary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eWhen discussing nuclear security, you may hear “My system is designed to be fail-safe so additional security is not necessary” or “My system is designed for safety, so all this security is not necessary.”  While it is true that nuclear systems are designed to fail-safe and said design specifications do provide some security attributes, they are not enough. A variety of methodologies exist to evaluate system safety; Failure Mode and Effects Analysis and Fault Tree Analysis are two of many. Generally, these methodologies identify random failures in processes or components that will cause the system to fail. Safety instrumented systems (SISs) are designed and integrated into nuclear systems to detect when the system is moving into a dangerous state. When unsafe conditions are detected, the SIS actuates to return the system to a safe state. However, an adversary will seek to cause single or multiple targeted simultaneous failures to cause the system to perform its function(s) improperly. Thus, these standard methodologies are incomplete in this regard.\u003c/p\u003e\n\u003cp\u003eSISs themselves can be the target of the attack to circumvent a layer of safety protection, as illustrated by the Trisis malware \u003csup id=\"fnref:7\"\u003e\u003ca href=\"#fn:7\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e7\u003c/a\u003e\u003c/sup\u003e. As explained above, the security protection for a system and its function(s) can never be absolute; there will always be residual risk, in this case affecting the corresponding safety analysis. Thus, security needs to be an integral part of assuring the safety of a system.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eOK, so I need security measures, but they can be added afterwards.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eOnce it is accepted that security measures are required, it is sometimes claimed, that security measures should be added to the system in such a way that they protect that system from unauthorised change and themselves make no changes to the system. The assumption that any safety assurance certification would remain valid, regardless of which security controls were applied to protect the system is highly attractive. Given the attractiveness of maintaining the safety certification requirement, it is worth exploring in more detail why this in general cannot be achieved.\u003c/p\u003e\n\u003cp\u003eFirst, as already explained, security controls cannot be demonstrated to provide perfect protection because the activities of the adversary cannot be perfectly modelled. Further, with software-based digital technology, there may be vulnerabilities that have not yet been discovered by the designer and operator of the system, but they may have been actively researched and discovered by the adversary—a so-called “Zero Day Vulnerability”.\u003c/p\u003e\n\u003cp\u003eAdditionally, for systems of any complexity, especially those using software-based digital technology, security measures will change the system itself. The simplest example is any change to remedy a vulnerability, such as in an operating system, with a software patch. Similarly, a new method of attack may require a change to the system in order to defeat the attack scenario. In general, to achieve true defence-in-depth with security, the system itself will have to be changed, e.g., to harden it.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eOK, but as a designer, I can still pass this off to the security team.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe belief that security and safety can be independently designed and executed is a flawed approach that results in suboptimal outcomes. This viewpoint, often referred to as \u0026ldquo;stove-piped thinking\u0026rdquo;, results in a narrow and incomplete analysis of both security and safety needs. Safety and security each have their unique strengths that are vital, but each has its own limitations in their current approaches.\u003c/p\u003e\n\u003cp\u003eIn the security discipline, it is not uncommon for the focus to be solely on the security of information (e.g., with the pre-eminence of ISO-27000 \u003csup id=\"fnref:8\"\u003e\u003ca href=\"#fn:8\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e8\u003c/a\u003e\u003c/sup\u003e), thereby neglecting the important role that safety plays in the definition and attainment of security objectives. This can lead to an incomplete assessment of the functions that must be protected by security controls. For example, when using this incomplete approach, one may conclude that only physical protection measures are relevant for the protection of safety-critical functions, systems, structures, and components. This could leave critical safety functions and supporting systems more vulnerable to attack, while other less-consequential functions and systems are afforded a greater share of resources. Such incomplete analysis could lead to a misapplication of the graded approach \u003csup id=\"fnref:9\"\u003e\u003ca href=\"#fn:9\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e9\u003c/a\u003e\u003c/sup\u003e under which resources should be applied in proportion to the severity of the adverse consequences to the function.\u003c/p\u003e\n\u003cp\u003eOn the other hand, safety analysis often lacks adequate consideration of security assumptions. For example, the scenarios may not feature multiple, coordinated failures caused by malicious actors who have a high-level knowledge of the operation and vulnerabilities of multiple systems in the facility. A narrow focus on safety can result in a failure to account for the effects of human adversaries, leaving the system vulnerable to attack.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eSecurity assessments should be scheduled on the calendar, with safety reviews\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eSome want to accommodate security assessments within the existing safety lifecycle and timetable, asserting that security assessments are only necessary periodically. This approach fails to fully recognise the dynamic and constantly evolving nature of security risks.\u003c/p\u003e\n\u003cp\u003eSecurity is a response to the external environment, which is subject to constant change and intelligent, often malicious, human influences. A security review should be triggered by material changes to the underlying assumptions and changes to the risk landscape, e.g., new threat intelligence or new technologies. These changes often occur far beyond the boundaries of nuclear facilities. For example, a novel attack on other industries should be analysed for lessons to be acted upon. The Triton/Hatman/Trisis attack mentioned earlier is one such example that is relevant to most facilities, even if different hardware and software are used. The continuous re-assessment of the security posture requires an ongoing organisational commitment to maintaining awareness of the external environment and its implications for the security of the system.\u003c/p\u003e\n\u003cp\u003eIn contrast, the safety assessment is often viewed as a periodic activity, scheduled as part of the safety lifecycle. While this approach may provide a baseline level of safety, it fails to account for the everchanging security environment and its potential impact on safety if a failure can be exploited to propagate an incident.\u003c/p\u003e\n\u003cp\u003eA comprehensive approach to security and safety therefore requires a holistic understanding of both domains, informed by the interdependence of security and safety needs, that informs the definition of security objectives. This approach recognises that security and safety are not separate, independent activities, but rather interrelated and interdependent. Failing to adopt this approach may result in deficiencies in the results and a heightened susceptibility to systemic risk.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003ePerfect bricks make a perfect house.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eFaulty reasoning is sometimes seen in both the safety and security communities that components that have been tested and assured to a given standard will somehow convey this same standard to the parent system. This can be summarised as “Perfect bricks make a perfect house”. This is self-evidently not true: a bad craftsman can make a very poor building from perfect bricks; similarly, perfect bricks do not compensate for a poor architecture or hostile environmental factors.\u003c/p\u003e\n\u003cp\u003eTranslating this to safety and security, we can reasonably conclude that a perfectly manufactured SIS or network firewall (even if such objects were feasible with software-based digital technology) cannot compensate for errors in their implementation and operation. This observation is especially relevant when using software-based digital technology because the flexible ways in which this technology can be used, which makes it so valuable, also provides multiple ways to make mistakes in its implementation.\u003c/p\u003e\n\u003cp\u003eConsequently, except for the simplest system, the security or safety functionality against which the components are assured is not guaranteed to provide the desired security or security objectives of the system as a whole. The same argument applies for systems that are combined to make a system-ofsystems, which is typical of most facilities.\u003c/p\u003e\n\u003ch1 id=\"4-challenges-and-recommendations\"\u003e4. Challenges and recommendations\u003c/h1\u003e\n\u003cp\u003eIn this final section, the authors offer some practical recommendations for how to avoid the misunderstandings and pitfalls described above.\u003c/p\u003e\n\u003ch2 id=\"ensure-decision-makers-understand-that-safety-and-security-are-not-the-same-thing\"\u003eEnsure decision-makers understand that safety and security are not the same thing.\u003c/h2\u003e\n\u003cp\u003eExtra effort must be applied to clearly define terms, especially in languages in which safety and security are the same word. Use of similar terms, i.e., physical protection, radiological protection, or data confidentiality, will help. When communicating about safety or security, confirm that the reader has understood and is not interpreting content from a different frame of reference. Providing examples also helps clarify and illustrate the differences between the concepts. For example, a security incident event monitor is a security measure, but a backup power supply for emergency pumps is a safety measure.\u003c/p\u003e\n\u003ch2 id=\"be-wary-of-calls-for-safety-to-absorb-security\"\u003eBe wary of calls for safety to absorb security.\u003c/h2\u003e\n\u003cp\u003eSome say that security is part of safety because, when viewed from an enormous distance, they appear to be doing the same thing—protecting the world from undesirable outcomes. However, taking this approach can introduce peril if either safety or security loses its current strengths and distinctive aspects. Key skills in security work include the ability to think like an adversary and to maintain a close eye on current computer security research and hacking trends across the globe. Security must be able to respond to changes in the external environment, which may require modifying the system within days, hours, or even seconds in the event of an attack in progress.\u003c/p\u003e\n\u003cp\u003eThe concepts and best practices from each discipline can inform the other. For example, security behaviours would improve if the safety-first culture also applied to security. Reciprocally, safety might find that the maturity-based approach favoured by some security standards \u003csup id=\"fnref:10\"\u003e\u003ca href=\"#fn:10\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e10\u003c/a\u003e\u003c/sup\u003e provides a route to dealing better with systemic risk. The recommendation is therefore to make sure both are funded and staffed: they are both parts of a greater whole, which some call the One House approach.\u003c/p\u003e\n\u003ch2 id=\"adopt-a-one-house-systems-engineering-approach\"\u003eAdopt a One House systems-engineering approach.\u003c/h2\u003e\n\u003cp\u003eA systems-engineering approach to designing security and safety together recognises the interdependence of security and safety. It takes a universal approach to ensuring that both are effectively integrated into the design of the system and that the integrated approach continues throughout the entire system lifecycle. Such an approach resolves when security and safety requirements are in tension and recognises when they can be implemented in a complementary way \u003csup id=\"fnref:11\"\u003e\u003ca href=\"#fn:11\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e11\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref:12\"\u003e\u003ca href=\"#fn:12\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e12\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eSecurity and safety should be considered from the outset, starting with the functional design, to ensure that the functions of the facility will be performed in a safe and secure manner. As a result, safety and security controls are integrated into the system\u0026rsquo;s architecture, processes, and components. This approach considers the potential for security risks, the consequences of security failures, and the need for safetycritical functions and their supporting systems to be protected from attack within a graded approach.\u003c/p\u003e\n\u003cp\u003eA systems-engineering approach can accommodate the early integration of safety and security requirements into the design and maintain that integration throughout the operation of the system. The close and collaborative work by systems engineers, safety experts, and security experts has been called the One House approach. It can address the risks identified in this paper that might otherwise be unrecognised and neglected.\u003c/p\u003e\n\u003ch2 id=\"beware-of-false-confidence\"\u003eBeware of false confidence.\u003c/h2\u003e\n\u003cp\u003eThe engineering world is at varying stages in understanding and implementing this systems-engineering approach, and emerging guidance on nuclear safety and security is being developed by the International Electrotechnical Commission. Some are still unaware of the need for such an approach, while others may see the value but be unaware of the importance of integrating security and safety into the design process. Other engineers may lack the skills and knowledge to effectively integrate security and safety, having no suitable support, while still others may be consciously competent, recognising the importance of this approach, and working to implement it in their work. Much of this can be addressed by providing further guidance, updating education paradigms, and offering targeted training opportunities.\u003c/p\u003e\n\u003cp\u003eIt is important to note that this systems-engineering approach is not easily applied retroactively. Once a system has been designed and deployed, incorporating security and safety into the design becomes much more difficult.\u003c/p\u003e\n\u003ch2 id=\"final-points--what-should-you-do-about-this\"\u003eFinal points – what should you do about this?\u003c/h2\u003e\n\u003cp\u003eIt depends on who you are, but you could ask yourself questions to prompt informed action. For example, does your staff understand the difference between safety and security? Are the terms clearly defined and built into policy, procedures, and training programmes? Does your documentation clearly differentiate between the two terms, especially with qualifiers and examples for languages for which only one word is used for both terms? Do your risk assessments and other analyses include both safety and security?\u003c/p\u003e\n\u003cp\u003eFinally, every reader should at least think about how security and safety work with each other within their own organisations and relative to their own responsibilities. If the answer is “perfectly”, the authors respectfully suggest that you may not have thought about this question long enough.\u003c/p\u003e\n\u003ch1 id=\"5-references\"\u003e5. References\u003c/h1\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eThe SEMA referential framework: Avoiding ambiguities in the terms “security” and “safety”, Ludovic Piètre-Cambacédès, Claude Chaudet, International Journal of Critical Infrastructure Protection\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:2\"\u003e\n\u003cp\u003eEngineering Safe and Secure Software Systems, p.61, Barry Boehm, Axelrod, W. C., Massachusetts, Artech House, 2013, page 61.\u0026#160;\u003ca href=\"#fnref:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:3\"\u003e\n\u003cp\u003eALARP as low as reasonably practicable. \u003ca href=\"https://www.hse.gov.uk/managing/theory/alarpglance.htm\"\u003ehttps://www.hse.gov.uk/managing/theory/alarpglance.htm\u003c/a\u003e United Kingdom Health and Safety Executive\u0026#160;\u003ca href=\"#fnref:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:4\"\u003e\n\u003cp\u003eWhy process safety risk and cyber security risk differ, Sinclair Koelemij, 23 July 2021. \u003ca href=\"https://otcybersecurity.blog/2021/07/23/why-process-safety-risk-and-cyber-security-risk-differ/\"\u003ehttps://otcybersecurity.blog/2021/07/23/why-process-safety-risk-and-cyber-security-risk-differ/\u003c/a\u003e and\u0026#160;\u003ca href=\"#fnref:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:5\"\u003e\n\u003cp\u003eICS cyber security risk criteria, Sinclair Koelemij, 13 August 2021 \u003ca href=\"https://otcybersecurity.blog/2021/08/13/ics-cyber-security-risk-criteria/\"\u003ehttps://otcybersecurity.blog/2021/08/13/ics-cyber-security-risk-criteria/\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:6\"\u003e\n\u003cp\u003eReview of the December 2021 Log4j Event, US Department of Homeland Security, \u003ca href=\"https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf\"\u003ehttps://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:6\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:7\"\u003e\n\u003cp\u003eTRISIS Malware: Analysis of Safety System Targeted Malware, DRAGOS, \u003ca href=\"https://www.dragos.com/wp-content/uploads/TRISIS-01.pdf\"\u003ehttps://www.dragos.com/wp-content/uploads/TRISIS-01.pdf\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:7\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:8\"\u003e\n\u003cp\u003e27000.org. 2019. ISO 27000 - ISO 27001 and ISO 27002 Standards. Available at: \u003ca href=\"https://www.27000.org\"\u003ehttps://www.27000.org\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:8\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:9\"\u003e\n\u003cp\u003eNuclear Security Recommendations on Physical Protection of Nuclear Material and Nuclear Facilities (INFCIRC/225/Revision 5), IAEA Nuclear Security Series No. 13, IAEA, Vienna (2011)\u0026#160;\u003ca href=\"#fnref:9\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:10\"\u003e\n\u003cp\u003eCybersecurity Capability Maturity Model Version 2.1, US Department of Energy, \u003ca href=\"https://c2m2.doe.gov/\"\u003ehttps://c2m2.doe.gov/\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:10\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:11\"\u003e\n\u003cp\u003e\u0026ldquo;A rule-based approach for safety analysis using STAMP/STPA,\u0026rdquo; D. L. Gurgel, C. M. Hirata and J. De M. Bezerra, 2015 IEEE/AIAA 34th Digital Avionics Systems Conference (DASC), Prague, Czech Republic, 2015, pp. 7B2-1-7B2-8, doi: 10.1109/DASC.2015.7311464./\u0026#160;\u003ca href=\"#fnref:11\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:12\"\u003e\n\u003cp\u003e“Cyber-Informed Engineering, Managing Cyber Risk from Concept to Operation”, Idaho National Laboratory, \u003ca href=\"https://inl.gov/cie/\"\u003ehttps://inl.gov/cie/\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:12\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This article has been adapted verbatim from a paper accepted and presented during CyberCon23 titled ‘Safety versus Security: What’s the difference and why it matters’ authored by Samuel Clements, Mike StJohn-Green and myself.\n1. Abstract In the “Safety-First” culture of the nuclear industry, the nuanced differences between security and safety can be lost. The use of powerful software-programmable digital technology provides the means to transform instrumentation and control systems, but also provides unparalleled opportunity for malicious action by criminals and others.\nComputer security is therefore increasingly vital to support safety, and safety analysis is important to inform computer security. Superficially, the concepts are so similar that the words are often used interchangeably. This is especially true in languages like Spanish and Russian where the words seguridad and безопасность are used to define both safety and security. However, below the surface, the two disciplines are based on fundamentally different assumptions, so incompatibilities exist. These differences can lead to serious deficiencies in the response of safety systems to failures and of security systems to malicious attack.\nIn this paper the authors provide examples of these deficiencies, highlight important differences between the two concepts, demonstrate why they matter, and provide the reader with recommendations for how to address this issue.\n2. Differences in concepts Lack of precision in language leads to misunderstanding. This fallibility is especially true with the concepts of “safety” and “security,” which are related but distinct concepts that feature important differences. This section provides examples of possible misunderstandings and potential consequences. Seguridad vs Seguridad “Safety” and “Security” are essential concepts of a nuclear programme for which much thought and effort are invested in securing nuclear sites and assuring the safety of nuclear processes. Unfortunately, lack of precision in language leads to many misunderstandings, as illustrated in the following story.\nA presentation about nuclear security was scheduled to be delivered to senior leaders of nuclear facilities. The presentation’s intent was to inform new leadership of the importance and impact of nuclear security. The leaders had backgrounds in nuclear engineering and safety but were not well versed in the various aspects of a nuclear security programme. The presentation was developed in English and translated to Spanish, the native language of the intended recipients. Thankfully, during the dry run exercise leading up to the presentation someone noticed context that was lost in translation. Spanish only has one word for both safety and security. Additional adjectives or qualifiers must be used to distinguish between them. Lacking this context, the whole purpose of the presentation might have been undermined and intended meanings lost. Unfortunately, Spanish is not alone in the linguistic trap of using a single word for both safety and security. Portuguese (segurança), Russian (безопасность), Swedish (säkerhet), and Danish (sikkerhed) all use a single word to describe both safety and security.\nA decision-maker might conclude that because the word is the same, the single word covers all the activities required for safety and security. This could lead to some vital activities not happening as needed, such as new security funding lines not being approved because “Seguridad is already funded” elsewhere. Similarly, decision-makers might conclude that, because “seguridad” is in someone’s job title, the entire range of safety and security tasks have been adequately assigned. However, even with two different words, as in English, there is further potential for misunderstanding as noted by PiètreCambacédès, “Dozens of explicit, but distinct, definitions can be found ranging from slightly different to completely incompatible definitions” 1.\nSecurity and safety are not two perfect mirror images that fit together. In some organisations, the differences between safety and security are well accepted and different teams are tasked with each. It has been elegantly stated, “Safety: the system must not harm the world. Security: the world must not harm the system” 2). These two definitions may appear to be mirror images of one another, suggesting that current safety and current security activities are perfectly complementary; that together the two disciplines may appear to perfectly address all relevant risks to “the system” and from “the system”; and finally, that the two disciplines will not conflict. However, none of this is necessarily true unless active coordination, collaboration, and change occur.\nSafety is defined as reducing the risks of harm arising from dangerous situations, often referred to as “hazards”, to an acceptable level 3. In general, safety analysis relies on modelling the failure of the components of the system to provide an acceptable level of confidence in the calculation of the residual safety risks.\nWithin the nuclear sector, Probabilistic Safety Analysis (PSA) and Deterministic Safety Analysis (DSA) are methods used to evaluate the safety of a system or process. PSA uses statistical methods and models to estimate the likelihood of potential accidents and their consequences, considering the nature of known failures and human errors, as well as uncertainties in the behaviour of the system.\nDSA, on the other hand, uses deterministic methods and models to analyse the behaviour of the system under normal and abnormal conditions. It involves determining the sequences of events that can lead to an accident and the corrective actions that may be undertaken to prevent such an event. The results of a DSA are usually expressed in terms of failure scenarios and the likelihood of their occurrence. However, it is vital to note that malicious action is typically out of scope of such analysis.\nSecurity is defined as reducing the risks arising from malicious action, stemming ultimately from human motivation and behaviour, which is intrinsically difficult to model and calibrate with any confidence. Any calculation of likelihood or probability related to malicious human behaviour is particularly difficult to justify with any confidence 4 5. Risks arising from malicious action cannot in general be eliminated, only reduced, leaving an irreducible but hard-to-calibrate residual risk that is relevant to the safety analysis. Further, the malicious actor is very likely to change the system as part of any attack, and those changes will affect the safety analysis. This became evident with the exposure of the Log4j vulnerability 6 which is used in logging functions of safety and security related systems.\nThis argument demonstrates that analyses of safety and security can make potentially incompatible assumptions and approximations. The general basis of the safety analysis is that the system under consideration is fully defined by the design and not subject to uncontrolled change, while security analysis generally makes the assumption that the adversary will change the system and that security measures cannot entirely prevent this, leaving an uncalibrated risk of change to the system.\nSingle or multiple simultaneous failures As introduced above, in both methods of safety analysis (PSA and DSA), the initiating events for the accidents under consideration typically focus on accidental events, such as equipment failure, natural disasters, or human error. Such events are typically analysed on an individual system basis or are bounded by common groupings of systems, structures, and components that fall under well understood criteria (e.g., systems susceptible to seismic risk).\nIn contrast, a security analysis will typically focus on intentional events, such as malicious acts undertaken by an intelligent human adversary. Such a malicious adversary will be able to intelligently target systems, structures, and components to cause effects considered improbable (e.g., all redundant pumps fail at a coordinated time) or not considered within the design of the system (e.g., an actuation system, after experiencing a malicious modification to its setpoints, performs an action that propagates rather than contains the accident condition).\nThese examples highlight security events that have the potential to trigger systemic risks, where a localised failure has the possibility to spread and cause a widespread and significant impact on the safety and security of the larger system. Such a systemic risk potentially leads to the failure of multiple interconnected systems. Such risks must be considered and addressed within the context of the overall facility and its operating environment. Today’s safety and security analysis may be deficient in identifying such multi-domain risks.\n3. Things that are often said but are not general truths This section takes some statements that the authors have heard from well-intentioned engineers, who shall remain anonymous. These statements are helpful in revealing some of the prevailing misunderstandings across many industries, including the nuclear sector.\nMy system is designed to be fail-safe so additional security is not necessary.\nWhen discussing nuclear security, you may hear “My system is designed to be fail-safe so additional security is not necessary” or “My system is designed for safety, so all this security is not necessary.” While it is true that nuclear systems are designed to fail-safe and said design specifications do provide some security attributes, they are not enough. A variety of methodologies exist to evaluate system safety; Failure Mode and Effects Analysis and Fault Tree Analysis are two of many. Generally, these methodologies identify random failures in processes or components that will cause the system to fail. Safety instrumented systems (SISs) are designed and integrated into nuclear systems to detect when the system is moving into a dangerous state. When unsafe conditions are detected, the SIS actuates to return the system to a safe state. However, an adversary will seek to cause single or multiple targeted simultaneous failures to cause the system to perform its function(s) improperly. Thus, these standard methodologies are incomplete in this regard.\nSISs themselves can be the target of the attack to circumvent a layer of safety protection, as illustrated by the Trisis malware 7. As explained above, the security protection for a system and its function(s) can never be absolute; there will always be residual risk, in this case affecting the corresponding safety analysis. Thus, security needs to be an integral part of assuring the safety of a system.\nOK, so I need security measures, but they can be added afterwards.\nOnce it is accepted that security measures are required, it is sometimes claimed, that security measures should be added to the system in such a way that they protect that system from unauthorised change and themselves make no changes to the system. The assumption that any safety assurance certification would remain valid, regardless of which security controls were applied to protect the system is highly attractive. Given the attractiveness of maintaining the safety certification requirement, it is worth exploring in more detail why this in general cannot be achieved.\nFirst, as already explained, security controls cannot be demonstrated to provide perfect protection because the activities of the adversary cannot be perfectly modelled. Further, with software-based digital technology, there may be vulnerabilities that have not yet been discovered by the designer and operator of the system, but they may have been actively researched and discovered by the adversary—a so-called “Zero Day Vulnerability”.\nAdditionally, for systems of any complexity, especially those using software-based digital technology, security measures will change the system itself. The simplest example is any change to remedy a vulnerability, such as in an operating system, with a software patch. Similarly, a new method of attack may require a change to the system in order to defeat the attack scenario. In general, to achieve true defence-in-depth with security, the system itself will have to be changed, e.g., to harden it.\nOK, but as a designer, I can still pass this off to the security team.\nThe belief that security and safety can be independently designed and executed is a flawed approach that results in suboptimal outcomes. This viewpoint, often referred to as “stove-piped thinking”, results in a narrow and incomplete analysis of both security and safety needs. Safety and security each have their unique strengths that are vital, but each has its own limitations in their current approaches.\nIn the security discipline, it is not uncommon for the focus to be solely on the security of information (e.g., with the pre-eminence of ISO-27000 8), thereby neglecting the important role that safety plays in the definition and attainment of security objectives. This can lead to an incomplete assessment of the functions that must be protected by security controls. For example, when using this incomplete approach, one may conclude that only physical protection measures are relevant for the protection of safety-critical functions, systems, structures, and components. This could leave critical safety functions and supporting systems more vulnerable to attack, while other less-consequential functions and systems are afforded a greater share of resources. Such incomplete analysis could lead to a misapplication of the graded approach 9 under which resources should be applied in proportion to the severity of the adverse consequences to the function.\nOn the other hand, safety analysis often lacks adequate consideration of security assumptions. For example, the scenarios may not feature multiple, coordinated failures caused by malicious actors who have a high-level knowledge of the operation and vulnerabilities of multiple systems in the facility. A narrow focus on safety can result in a failure to account for the effects of human adversaries, leaving the system vulnerable to attack.\nSecurity assessments should be scheduled on the calendar, with safety reviews\nSome want to accommodate security assessments within the existing safety lifecycle and timetable, asserting that security assessments are only necessary periodically. This approach fails to fully recognise the dynamic and constantly evolving nature of security risks.\nSecurity is a response to the external environment, which is subject to constant change and intelligent, often malicious, human influences. A security review should be triggered by material changes to the underlying assumptions and changes to the risk landscape, e.g., new threat intelligence or new technologies. These changes often occur far beyond the boundaries of nuclear facilities. For example, a novel attack on other industries should be analysed for lessons to be acted upon. The Triton/Hatman/Trisis attack mentioned earlier is one such example that is relevant to most facilities, even if different hardware and software are used. The continuous re-assessment of the security posture requires an ongoing organisational commitment to maintaining awareness of the external environment and its implications for the security of the system.\nIn contrast, the safety assessment is often viewed as a periodic activity, scheduled as part of the safety lifecycle. While this approach may provide a baseline level of safety, it fails to account for the everchanging security environment and its potential impact on safety if a failure can be exploited to propagate an incident.\nA comprehensive approach to security and safety therefore requires a holistic understanding of both domains, informed by the interdependence of security and safety needs, that informs the definition of security objectives. This approach recognises that security and safety are not separate, independent activities, but rather interrelated and interdependent. Failing to adopt this approach may result in deficiencies in the results and a heightened susceptibility to systemic risk.\nPerfect bricks make a perfect house.\nFaulty reasoning is sometimes seen in both the safety and security communities that components that have been tested and assured to a given standard will somehow convey this same standard to the parent system. This can be summarised as “Perfect bricks make a perfect house”. This is self-evidently not true: a bad craftsman can make a very poor building from perfect bricks; similarly, perfect bricks do not compensate for a poor architecture or hostile environmental factors.\nTranslating this to safety and security, we can reasonably conclude that a perfectly manufactured SIS or network firewall (even if such objects were feasible with software-based digital technology) cannot compensate for errors in their implementation and operation. This observation is especially relevant when using software-based digital technology because the flexible ways in which this technology can be used, which makes it so valuable, also provides multiple ways to make mistakes in its implementation.\nConsequently, except for the simplest system, the security or safety functionality against which the components are assured is not guaranteed to provide the desired security or security objectives of the system as a whole. The same argument applies for systems that are combined to make a system-ofsystems, which is typical of most facilities.\n4. Challenges and recommendations In this final section, the authors offer some practical recommendations for how to avoid the misunderstandings and pitfalls described above.\nEnsure decision-makers understand that safety and security are not the same thing. Extra effort must be applied to clearly define terms, especially in languages in which safety and security are the same word. Use of similar terms, i.e., physical protection, radiological protection, or data confidentiality, will help. When communicating about safety or security, confirm that the reader has understood and is not interpreting content from a different frame of reference. Providing examples also helps clarify and illustrate the differences between the concepts. For example, a security incident event monitor is a security measure, but a backup power supply for emergency pumps is a safety measure.\nBe wary of calls for safety to absorb security. Some say that security is part of safety because, when viewed from an enormous distance, they appear to be doing the same thing—protecting the world from undesirable outcomes. However, taking this approach can introduce peril if either safety or security loses its current strengths and distinctive aspects. Key skills in security work include the ability to think like an adversary and to maintain a close eye on current computer security research and hacking trends across the globe. Security must be able to respond to changes in the external environment, which may require modifying the system within days, hours, or even seconds in the event of an attack in progress.\nThe concepts and best practices from each discipline can inform the other. For example, security behaviours would improve if the safety-first culture also applied to security. Reciprocally, safety might find that the maturity-based approach favoured by some security standards 10 provides a route to dealing better with systemic risk. The recommendation is therefore to make sure both are funded and staffed: they are both parts of a greater whole, which some call the One House approach.\nAdopt a One House systems-engineering approach. A systems-engineering approach to designing security and safety together recognises the interdependence of security and safety. It takes a universal approach to ensuring that both are effectively integrated into the design of the system and that the integrated approach continues throughout the entire system lifecycle. Such an approach resolves when security and safety requirements are in tension and recognises when they can be implemented in a complementary way 11 12.\nSecurity and safety should be considered from the outset, starting with the functional design, to ensure that the functions of the facility will be performed in a safe and secure manner. As a result, safety and security controls are integrated into the system’s architecture, processes, and components. This approach considers the potential for security risks, the consequences of security failures, and the need for safetycritical functions and their supporting systems to be protected from attack within a graded approach.\nA systems-engineering approach can accommodate the early integration of safety and security requirements into the design and maintain that integration throughout the operation of the system. The close and collaborative work by systems engineers, safety experts, and security experts has been called the One House approach. It can address the risks identified in this paper that might otherwise be unrecognised and neglected.\nBeware of false confidence. The engineering world is at varying stages in understanding and implementing this systems-engineering approach, and emerging guidance on nuclear safety and security is being developed by the International Electrotechnical Commission. Some are still unaware of the need for such an approach, while others may see the value but be unaware of the importance of integrating security and safety into the design process. Other engineers may lack the skills and knowledge to effectively integrate security and safety, having no suitable support, while still others may be consciously competent, recognising the importance of this approach, and working to implement it in their work. Much of this can be addressed by providing further guidance, updating education paradigms, and offering targeted training opportunities.\nIt is important to note that this systems-engineering approach is not easily applied retroactively. Once a system has been designed and deployed, incorporating security and safety into the design becomes much more difficult.\nFinal points – what should you do about this? It depends on who you are, but you could ask yourself questions to prompt informed action. For example, does your staff understand the difference between safety and security? Are the terms clearly defined and built into policy, procedures, and training programmes? Does your documentation clearly differentiate between the two terms, especially with qualifiers and examples for languages for which only one word is used for both terms? Do your risk assessments and other analyses include both safety and security?\nFinally, every reader should at least think about how security and safety work with each other within their own organisations and relative to their own responsibilities. If the answer is “perfectly”, the authors respectfully suggest that you may not have thought about this question long enough.\n5. References The SEMA referential framework: Avoiding ambiguities in the terms “security” and “safety”, Ludovic Piètre-Cambacédès, Claude Chaudet, International Journal of Critical Infrastructure Protection ↩︎\nEngineering Safe and Secure Software Systems, p.61, Barry Boehm, Axelrod, W. C., Massachusetts, Artech House, 2013, page 61. ↩︎\nALARP as low as reasonably practicable. https://www.hse.gov.uk/managing/theory/alarpglance.htm United Kingdom Health and Safety Executive ↩︎\nWhy process safety risk and cyber security risk differ, Sinclair Koelemij, 23 July 2021. https://otcybersecurity.blog/2021/07/23/why-process-safety-risk-and-cyber-security-risk-differ/ and ↩︎\nICS cyber security risk criteria, Sinclair Koelemij, 13 August 2021 https://otcybersecurity.blog/2021/08/13/ics-cyber-security-risk-criteria/ ↩︎\nReview of the December 2021 Log4j Event, US Department of Homeland Security, https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf ↩︎\nTRISIS Malware: Analysis of Safety System Targeted Malware, DRAGOS, https://www.dragos.com/wp-content/uploads/TRISIS-01.pdf ↩︎\n27000.org. 2019. ISO 27000 - ISO 27001 and ISO 27002 Standards. Available at: https://www.27000.org ↩︎\nNuclear Security Recommendations on Physical Protection of Nuclear Material and Nuclear Facilities (INFCIRC/225/Revision 5), IAEA Nuclear Security Series No. 13, IAEA, Vienna (2011) ↩︎\nCybersecurity Capability Maturity Model Version 2.1, US Department of Energy, https://c2m2.doe.gov/ ↩︎\n“A rule-based approach for safety analysis using STAMP/STPA,” D. L. Gurgel, C. M. Hirata and J. De M. Bezerra, 2015 IEEE/AIAA 34th Digital Avionics Systems Conference (DASC), Prague, Czech Republic, 2015, pp. 7B2-1-7B2-8, doi: 10.1109/DASC.2015.7311464./ ↩︎\n“Cyber-Informed Engineering, Managing Cyber Risk from Concept to Operation”, Idaho National Laboratory, https://inl.gov/cie/ ↩︎\n","date_published":"2023-06-23T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/safety-vs-security/","image":"https://blog.mitcdh.au/images/safety-vs-security.webp","summary":"What's the Difference and Why It Matters","tags":["Writing","Nuclear","Technology","Security","Safety"],"title":"Safety Versus Security","url":"https://blog.mitcdh.au/posts/safety-vs-security/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-04-25T17:25:55Z","id":"https://blog.mitcdh.au/posts/layovers-in-frankfurt-and-nuremberg-germany/","image":"https://blog.mitcdh.au/images/layovers-in-frankfurt-and-nuremberg-germany.jpg","summary":"Whether it's by plane or train, why not embark on an adventure and explore what's nearby?","tags":["Album"],"title":"Layovers in Frankfurt and Nuremberg, Germany","url":"https://blog.mitcdh.au/posts/layovers-in-frankfurt-and-nuremberg-germany/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-04-08T17:50:59Z","id":"https://blog.mitcdh.au/posts/wandering-the-land-in-tuscany-italy/","image":"https://blog.mitcdh.au/images/wandering-the-land-in-tuscany-italy.jpg","summary":"That log was cursed.","tags":["Album"],"title":"Wandering the Land in Tuscany, Italy","url":"https://blog.mitcdh.au/posts/wandering-the-land-in-tuscany-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-03-26T13:33:54Z","id":"https://blog.mitcdh.au/posts/relaxing-escape-to-prague-czechia/","image":"https://blog.mitcdh.au/images/relaxing-escape-to-prague-czechia.jpg","summary":"“Czech this out” was said endlessly.","tags":["Album"],"title":"Relaxing Escape to Prague, Czechia","url":"https://blog.mitcdh.au/posts/relaxing-escape-to-prague-czechia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003ePut down your tar and pitchforks. The activities connotated with \u0026ldquo;cyber security\u0026rdquo; are vital to avoid the worst consequences of malicious acts that could target computer-based systems. After all, we live in an era where computers are the predominant means we consume information, forming the basis of our knowledge and subsequent actions.\u003c/p\u003e\n\u003cp\u003eI have been fortunate to work on nationally significant critical infrastructure where we developed function-centric approaches to computer security. Leveraging that experience, I have spent much of my career either working in support of or directly for an international organisation on the proposal, establishment, drafting, consensus building, and maintenance of internationally recognised consensus guidance documents on \u0026ldquo;information and computer security\u0026rdquo;.\u003c/p\u003e\n\u003cp\u003eBut why do we use the terms \u0026ldquo;information and computer\u0026rdquo; security rather than \u0026ldquo;cyber security\u0026rdquo;? While, as with all things that make international consensus, there are a number of elements at play, I remain a strong proponent in favour of this decision within my individual capacity because I have come to believe that the term \u0026ldquo;cyber security\u0026rdquo; is harmful, and at least the recognition of that is needed to move forward into a more mature engineering-inclusive approach to security. Let me explain why.\u003c/p\u003e\n\u003ch1 id=\"the-ambiguity-of-cyber\"\u003eThe Ambiguity of \u0026ldquo;Cyber\u0026rdquo;\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003eComputer security is only the desktops, but \u0026ldquo;Cyber\u0026rdquo; includes the Cloud, right?\u003c/p\u003e\n\u003cp\u003e\u003ccite\u003eA Diplomat, 2022\u003c/cite\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cem\u003eComputer security doesn\u0026rsquo;t include the cloud\u0026hellip; but the cloud is made of computers?\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e\u0026ldquo;Cyber\u0026rdquo; is an abstract concept inconsistently encompassing various digital, virtual, computer-based, or internet-related ideas. When discussing \u0026ldquo;cyber security,\u0026rdquo; interpretations can differ significantly among individuals from diverse backgrounds, such as policymakers, regulators, company directors, engineers, security professionals, and average users. This inconsistency poses a challenge when asserting that \u0026ldquo;cyber security is everyone\u0026rsquo;s responsibility.\u0026rdquo;\u003c/p\u003e\n\u003cp\u003eThe ambiguity surrounding \u0026ldquo;cyber\u0026rdquo; can result in confusion or misunderstandings about the scope and focus of \u0026ldquo;cyber security.\u0026rdquo; Consequently, it may be difficult to establish clear security objectives, making the definition of strategy, policy, programme and assurance mechanisms inconsistent and resulting in potential gaps in implementation that attackers could exploit. Securing an abstract concept with no universally agreed-upon definition is challenging. Establishing specific security objectives and successfully adopting a graded approach requires a more precise focus.\u003c/p\u003e\n\u003cp\u003e\u0026ldquo;Computer security\u0026rdquo; offers a more appropriate emphasis on protecting computer-based systems regardless of any biases towards their form or function. In all \u0026ldquo;cyber\u0026rdquo;-relevant technologies, the common element is using computer-based systems, including workstations, servers, networking devices, IoT, cloud computing, information technology, and operational technology. How these systems perform functions is what matters.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/cyber-security-considered-harmful_01.webp\" width=\"2448\" height=\"3264\" alt=\"Foxboro CP60 module with the case removed\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eInside the chassis of a Foxboro CP60 module. Definitely a computer.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eA computer-based system contributes to the performance of a function, this contribution is understandable, and a security programme can be oriented to preserve the contribution towards the performance of the function. This approach actively encompasses any digital device with reprogrammable logic, such as CPUs and Programmable Logic Devices, as the scope of a computer is well-defined at a technical level. It also takes into account the potential consequences of compromise.\u003c/p\u003e\n\u003cp\u003eEngineers know when they use computers. With this perspective, it becomes evident that everyone involved in the system lifecycle has a role in maintaining security rather than assigning the responsibility solely to a \u0026ldquo;cyber\u0026rdquo; expert. Adopting a tangible, measurable approach to security with a more understood scope can help reduce ambiguity and foster a better mutual understanding of the responsibilities of securing digital systems.\u003c/p\u003e\n\u003ch1 id=\"overemphasis-on-specific-technology\"\u003e\u003cstrong\u003eOveremphasis on Specific Technology\u003c/strong\u003e\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003eWe have some clients installing two data diodes operating in opposite directions. The protocol break protects against cyber-attacks.\u003c/p\u003e\n\u003cp\u003e\u003ccite\u003eSecurity Vendor, ~2017\u003c/cite\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe prevailing focus of \u0026ldquo;cyber security\u0026rdquo; governance leans heavily towards securing information-processing systems. This approach influences workforce training, market solutions, and risk assessment. While some practitioners may perceive a broader meaning behind \u0026ldquo;cyber security,\u0026rdquo; the widely accepted understanding remains on information protection. This narrow focus leads to a skewed governance model prioritising safeguarding information and normalising detection, delay, and response strategies aimed at information systems rather than preserving the business functions no matter what systems contribute to their performance.\u003c/p\u003e\n\u003cp\u003e\u0026ldquo;Cyber security\u0026rdquo; overemphasises information security and its technological aspects, often overlooking organisational factors contributing to attaining security objectives such as functions, system design, and existing defence-in-depth and other resiliency measures. This results in a less efficient allocation of security resources. Even when venturing into areas like OT security, the fixation on information-processing technology can overshadow the importance of human factors. Both computers and humans can act on malicious information. Still, the cyber-physical actions of computers often receive more attention than the potential for maliciously misleading human operators into causing unintended consequences (phishing attacks to obtain information are the exception). Without investigation, such incidents may be considered accidents, with the operating organisations and vendors likely having no incentive, or even data, for further investigation when it is attributable to user error.\u003c/p\u003e\n\u003cp\u003eIn my experience, I have seen examples of national critical infrastructure regulations that criminalise attacks on information confidentiality while leaving gaps in addressing breaches of integrity and availability, which may be more consequential in malicious acts. Technical resources are often dedicated to protecting against or gaining visibility into internet protocol-based attacks rather than detecting subversion within engineering networks or business functions.\u003c/p\u003e\n\u003cp\u003eThis approach leads organisations to invest heavily in standalone \u0026ldquo;cyber security\u0026rdquo; measures while neglecting the integration of security principles into engineering processes. Consequently, this may result in suboptimal solutions that fail to address the root causes of vulnerabilities and risks. We must ask ourselves: are we striving to maintain the proper performance of business functions, or are we mistakenly believing our responsibility ends with protecting computer systems?\u003c/p\u003e\n\u003ch1 id=\"clarity-of-roles-and-responsibilities\"\u003e\u003cstrong\u003eClarity of Roles and Responsibilities\u003c/strong\u003e\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003eWe don\u0026rsquo;t have to worry about \u0026ldquo;Cyber Security\u0026rdquo;. We are not connected to the Internet.\u003c/p\u003e\n\u003cp\u003e\u003ccite\u003eReactor Manager, 2018\u003c/cite\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eA respected industry leader once told me that \u0026ldquo;cyber security is a solved problem. You can only be attacked through physical access, wired networks, wireless networks, supply chain, portable media and mobile devices. Once you protect against those, you are secure.\u0026rdquo; But who is doing the work? The engineers or the cyber security professionals? At what point in the engineering lifecycle does it occur? More often than not, \u0026ldquo;cyber security\u0026rdquo; is considered after design and development with minimal emphasis on security by design. Is this viewpoint just more of a reactive approach?\u003c/p\u003e\n\u003cp\u003eThe normalised approach to security and safety certifications has been to front-load costs during the initial design and development, with few economic incentives for ongoing support and maintenance. While this has shifted over time, there is still an issue due to ambiguities around \u0026ldquo;cyber security\u0026rdquo; the full scope of a function-centric systems engineering approach to protecting computer-based systems is not considered part of, or a requirement within, the engineering design process. Information security is the exception, with resources frequently allocated towards protecting sensitive information. All other aspects are relegated to implementing programmes and measures to build a barrier around what are likely fundamentally insecure systems.\u003c/p\u003e\n\u003cp\u003eOver consecutive years I witnessed two sales pitches for modernising an extensive distributed control system from the same vendor: the first presented an architecture without security considered. The second, the \u0026ldquo;high security\u0026rdquo; variant, provided the same architectural diagram, with the same hardware and software, but with logos of cyber security companies such as \u0026ldquo;Splunk, Cisco, Juniper, and McAfee\u0026rdquo; scattered around the periphery of the diagram. It was clear at that point that they didn\u0026rsquo;t see their product as part of a target set, consigning their concerns to the information technology surrounding it. \u003ca href=\"https://www.technologyreview.com/2019/03/05/103328/cybersecurity-critical-infrastructure-triton-malware/\"\u003eMaybe things have changed now\u003c/a\u003e? But where does the boundary exist between the product\u0026rsquo;s security, the software and hardware enabling the function, and the surrounding environment? Who should be responsible? Do we rely on the insertion of insecure trust into our secure boundary? It\u0026rsquo;s not like that hasn\u0026rsquo;t \u003ca href=\"https://en.wikipedia.org/wiki/Havex\"\u003ebeen\u003c/a\u003e \u003ca href=\"https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach#SolarWinds_exploit\"\u003eexploited\u003c/a\u003e \u003ca href=\"https://www.wired.com/story/inside-the-unnerving-supply-chain-attack-that-corrupted-ccleaner/\"\u003ebefore\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eWhat would it be like if we had these clear responsibilities established? We could achieve this by securing \u0026ldquo;computers\u0026rdquo; and their functions, which would be considered another aspect of good engineering consistent with engineering ethics. Such an approach would have further benefits as many \u003ca href=\"https://en.wikipedia.org/wiki/Therac-25\"\u003eincidents related to computer systems\u003c/a\u003e arise from poor engineering practices. A more robust approach to achieving safety and security assurance by design, where there are more specific responsibilities around the engineering of computer systems, could increase general system resilience and robustness, preventing many safety incidents from occurring altogether.\u003c/p\u003e\n\u003ch1 id=\"simplification-of-complex-issues\"\u003e\u003cstrong\u003eSimplification of Complex Issues\u003c/strong\u003e\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003eCan\u0026rsquo;t you just install Anti-virus on the Workstation and call it a day?\u003c/p\u003e\n\u003cp\u003e\u003ccite\u003eI\u0026amp;C Engineer, ~2017\u003c/cite\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u0026ldquo;Cyber security\u0026rdquo; simplifies complex and multifaceted issues that cross disciplines, through ambiguity reducing them to a binary concept of secure versus insecure and further positioning the entire profession to be seen through a lens of commodity measures and professional services. I had this experience, attempting to justify the security of a complex operational technology system within a nuclear reactor against a set of government controls primarily intended for application to information processing computers.\u003c/p\u003e\n\u003cp\u003eThe systems we were looking at securing performed functions and had an existing engineered approach to assuring safety and security defence-in-depth. Multiple systems would perform the same function and thus deserve protection from external threats and measures for delay, detection, and response that orient towards reinforcing their reliability and independence. The mandated oversimplification of security hinders nuanced discussions and the development of comprehensive strategies for preserving the performance of these functions. Instead, we were, at best, incentivised to build a common boundary around all such devices and declare them secure.\u003c/p\u003e\n\u003cp\u003eThese are all \u003ca href=\"https://blog.mitcdh.au/p/rethinking-security-function-based-protection-against-malice-a114bf03b4bb\"\u003ethreat-centric approaches\u003c/a\u003e. Without more \u003ca href=\"https://www.iaea.org/publications/14729/computer-security-techniques-for-nuclear-facilities\"\u003efunction-centric approaches\u003c/a\u003e, encouraging collaboration and cross-involvement between engineering and computer security to address the preservation of the overall engineered function, we will be stuck securing a set of potentially inconsequential computers in manners that may even degrade security.\u003c/p\u003e\n\u003ch1 id=\"fear-driven-market-economics\"\u003e\u003cstrong\u003eFear-driven Market Economics\u003c/strong\u003e\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003eDid you read the article in Wired today? You should be more worried. If we are hacked, I\u0026rsquo;ll cut you loose before they take my head.\u003c/p\u003e\n\u003cp\u003e\u003ccite\u003eIT Manager, ~2017\u003c/cite\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eIncreasing media coverage and public awareness of cyber threats have intensified concerns about the potential consequences of attacks. High-profile incidents, often involving sophisticated and well-resourced threat actors, have spurred organisations to invest in security measures without fully understanding the specific risks they face. This fear-driven demand has led to a proliferation of \u0026ldquo;cyber\u0026rdquo; products and services, with vendors capitalising on the anxiety surrounding cyber threats to promote their solutions as essential and establish long-term vendor lock-in.\u003c/p\u003e\n\u003cp\u003eIn this climate, organisations are influenced by the overdramatisation of \u0026ldquo;cyber\u0026rdquo; to allocate resources based on fear and ambiguities surrounding the term rather than through rational risk assessment and the potential for actual risk reduction. The fear of becoming a victim of a cyber-attack, combined with the limited cross-disciplinary knowledge of many \u0026ldquo;cyber security\u0026rdquo; professionals, can result in a reactive deployment of the latest security technologies or services without considering their effectiveness in addressing the organisation\u0026rsquo;s unique vulnerabilities and threat landscape. Such reactivity can lead to suboptimal resource allocation, fostering a market that thrives on fear instead of developing and implementing effective, tailored strategies for meaningful risk reduction.\u003c/p\u003e\n\u003ch1 id=\"stifling-innovation-in-engineering\"\u003eStifling Innovation in Engineering\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003eIf you don\u0026rsquo;t call it \u0026ldquo;cyber security\u0026rdquo;, I\u0026rsquo;m not funding it. I don\u0026rsquo;t care about good engineering. That\u0026rsquo;s their problem.\u003c/p\u003e\n\u003cp\u003e\u003ccite\u003eIT Manager, ~2016\u003c/cite\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe trinity of \u0026ldquo;Cyber security/cyberthreat/cyber-attack\u0026rdquo; has positioned \u0026ldquo;cyber\u0026rdquo; as a threat-focused discipline distinct from engineering, promoting a reactive mindset where security measures are implemented as an afterthought or in response to specific threats. We prioritise resources to detect malicious activity on computer networks with little thought to addressing defensive strategies within the fundamental engineering designs and resulting response procedures. What happens when a threat is detected? Who responds, the engineering team or the computer security incident response team? Who has authority over the equipment?\u003c/p\u003e\n\u003cp\u003eIf a process-aware anomaly detection system has a high-severity trigger, who will be liable when making the call to bring the process to a safe state? These procedures and interfaces likely do not exist or have yet to be considered. Treating \u0026ldquo;cyber security\u0026rdquo; as different to the engineering disciplines that develop computer-based systems and the operations teams that use them contributes to a lack of interdisciplinary expertise, where professionals narrowly focus on their respective domains. You will see security functions without communication channels and operations with poor visibility due to a reliance on compromisable digital indicators.\u003c/p\u003e\n\u003cp\u003eA cyber-attack is not a special snowflake. Conversations need to occur to establish the mechanisms of delay, detection, and response addressed within the engineering design and shared between operations, engineering, and security. There is a misguided view that cyber security incident responders will have complete authority, but that seldom happens.\u003c/p\u003e\n\u003cp\u003eFor the best outcome, we must recognise that many approaches to \u0026ldquo;cyber security\u0026rdquo; are just band-aids incentivising the industry to stand in the way of progress. There is a need for real innovation in how we engineer and operate computer-based systems. We can only achieve more effective assurance by recognising that \u0026ldquo;cyber security\u0026rdquo; protection is not absolute. Instead, our best approximation will be embedding computer security into the engineering design and building on that to leverage multi-disciplinary approaches to detection, delay, and response.\u003c/p\u003e\n\u003ch1 id=\"conclusion\"\u003eConclusion\u003c/h1\u003e\n\u003cp\u003eThere are misaligned incentives between engineering and \u0026ldquo;cyber security\u0026rdquo;, which I largely attribute to ambiguity in the term \u0026ldquo;cyber\u0026rdquo;. Engineering assurance prioritises functionality and cost from the comfort area of existing assessment methodologies, leaving \u0026ldquo;cyber security\u0026rdquo; as an exercise for operating organisations. Meanwhile, \u0026ldquo;cyber security\u0026rdquo; focuses on defending against cyber threats rather than working to support the assurance of functions those same threats would seek to target.\u003c/p\u003e\n\u003cp\u003eThis misalignment can create tensions and hinder the development of balanced solutions, considering relevant information from both disciplines and meeting engineering needs and security objectives.\u003c/p\u003e\n\u003cp\u003eWorse still, the symbiotic relationship between first-to-market engineering pressures and the false application of \u0026ldquo;cyber security\u0026rdquo;, if oriented to protecting computers rather than preserving functions, will be hugely detrimental to infrastructure security worldwide.\u003c/p\u003e\n\u003cp\u003eThe focus on the robustness and resilience of the performance of functions, understood by both fields and made more tangible with \u0026ldquo;computer security\u0026rdquo; rather than \u0026ldquo;cyber security\u0026rdquo;, would encourage the adoption of a more holistic systems engineering effort that will go a long way to achieving security by design.\u003c/p\u003e\n\u003cp\u003eWhichever word, we must recognise that \u0026ldquo;cyber security\u0026rdquo; is good engineering. It is not different; it is not unique; it is an assurance function that needs to be considered in the engineering design process, just like safety. After all, when faced with the existence of malicious acts, safety cannot be guaranteed without security.\u003c/p\u003e\n","content_text":"Put down your tar and pitchforks. The activities connotated with “cyber security” are vital to avoid the worst consequences of malicious acts that could target computer-based systems. After all, we live in an era where computers are the predominant means we consume information, forming the basis of our knowledge and subsequent actions.\nI have been fortunate to work on nationally significant critical infrastructure where we developed function-centric approaches to computer security. Leveraging that experience, I have spent much of my career either working in support of or directly for an international organisation on the proposal, establishment, drafting, consensus building, and maintenance of internationally recognised consensus guidance documents on “information and computer security”.\nBut why do we use the terms “information and computer” security rather than “cyber security”? While, as with all things that make international consensus, there are a number of elements at play, I remain a strong proponent in favour of this decision within my individual capacity because I have come to believe that the term “cyber security” is harmful, and at least the recognition of that is needed to move forward into a more mature engineering-inclusive approach to security. Let me explain why.\nThe Ambiguity of “Cyber” Computer security is only the desktops, but “Cyber” includes the Cloud, right?\nA Diplomat, 2022\nComputer security doesn’t include the cloud… but the cloud is made of computers?\n“Cyber” is an abstract concept inconsistently encompassing various digital, virtual, computer-based, or internet-related ideas. When discussing “cyber security,” interpretations can differ significantly among individuals from diverse backgrounds, such as policymakers, regulators, company directors, engineers, security professionals, and average users. This inconsistency poses a challenge when asserting that “cyber security is everyone’s responsibility.”\nThe ambiguity surrounding “cyber” can result in confusion or misunderstandings about the scope and focus of “cyber security.” Consequently, it may be difficult to establish clear security objectives, making the definition of strategy, policy, programme and assurance mechanisms inconsistent and resulting in potential gaps in implementation that attackers could exploit. Securing an abstract concept with no universally agreed-upon definition is challenging. Establishing specific security objectives and successfully adopting a graded approach requires a more precise focus.\n“Computer security” offers a more appropriate emphasis on protecting computer-based systems regardless of any biases towards their form or function. In all “cyber”-relevant technologies, the common element is using computer-based systems, including workstations, servers, networking devices, IoT, cloud computing, information technology, and operational technology. How these systems perform functions is what matters.\nInside the chassis of a Foxboro CP60 module. Definitely a computer.\nA computer-based system contributes to the performance of a function, this contribution is understandable, and a security programme can be oriented to preserve the contribution towards the performance of the function. This approach actively encompasses any digital device with reprogrammable logic, such as CPUs and Programmable Logic Devices, as the scope of a computer is well-defined at a technical level. It also takes into account the potential consequences of compromise.\nEngineers know when they use computers. With this perspective, it becomes evident that everyone involved in the system lifecycle has a role in maintaining security rather than assigning the responsibility solely to a “cyber” expert. Adopting a tangible, measurable approach to security with a more understood scope can help reduce ambiguity and foster a better mutual understanding of the responsibilities of securing digital systems.\nOveremphasis on Specific Technology We have some clients installing two data diodes operating in opposite directions. The protocol break protects against cyber-attacks.\nSecurity Vendor, ~2017\nThe prevailing focus of “cyber security” governance leans heavily towards securing information-processing systems. This approach influences workforce training, market solutions, and risk assessment. While some practitioners may perceive a broader meaning behind “cyber security,” the widely accepted understanding remains on information protection. This narrow focus leads to a skewed governance model prioritising safeguarding information and normalising detection, delay, and response strategies aimed at information systems rather than preserving the business functions no matter what systems contribute to their performance.\n“Cyber security” overemphasises information security and its technological aspects, often overlooking organisational factors contributing to attaining security objectives such as functions, system design, and existing defence-in-depth and other resiliency measures. This results in a less efficient allocation of security resources. Even when venturing into areas like OT security, the fixation on information-processing technology can overshadow the importance of human factors. Both computers and humans can act on malicious information. Still, the cyber-physical actions of computers often receive more attention than the potential for maliciously misleading human operators into causing unintended consequences (phishing attacks to obtain information are the exception). Without investigation, such incidents may be considered accidents, with the operating organisations and vendors likely having no incentive, or even data, for further investigation when it is attributable to user error.\nIn my experience, I have seen examples of national critical infrastructure regulations that criminalise attacks on information confidentiality while leaving gaps in addressing breaches of integrity and availability, which may be more consequential in malicious acts. Technical resources are often dedicated to protecting against or gaining visibility into internet protocol-based attacks rather than detecting subversion within engineering networks or business functions.\nThis approach leads organisations to invest heavily in standalone “cyber security” measures while neglecting the integration of security principles into engineering processes. Consequently, this may result in suboptimal solutions that fail to address the root causes of vulnerabilities and risks. We must ask ourselves: are we striving to maintain the proper performance of business functions, or are we mistakenly believing our responsibility ends with protecting computer systems?\nClarity of Roles and Responsibilities We don’t have to worry about “Cyber Security”. We are not connected to the Internet.\nReactor Manager, 2018\nA respected industry leader once told me that “cyber security is a solved problem. You can only be attacked through physical access, wired networks, wireless networks, supply chain, portable media and mobile devices. Once you protect against those, you are secure.” But who is doing the work? The engineers or the cyber security professionals? At what point in the engineering lifecycle does it occur? More often than not, “cyber security” is considered after design and development with minimal emphasis on security by design. Is this viewpoint just more of a reactive approach?\nThe normalised approach to security and safety certifications has been to front-load costs during the initial design and development, with few economic incentives for ongoing support and maintenance. While this has shifted over time, there is still an issue due to ambiguities around “cyber security” the full scope of a function-centric systems engineering approach to protecting computer-based systems is not considered part of, or a requirement within, the engineering design process. Information security is the exception, with resources frequently allocated towards protecting sensitive information. All other aspects are relegated to implementing programmes and measures to build a barrier around what are likely fundamentally insecure systems.\nOver consecutive years I witnessed two sales pitches for modernising an extensive distributed control system from the same vendor: the first presented an architecture without security considered. The second, the “high security” variant, provided the same architectural diagram, with the same hardware and software, but with logos of cyber security companies such as “Splunk, Cisco, Juniper, and McAfee” scattered around the periphery of the diagram. It was clear at that point that they didn’t see their product as part of a target set, consigning their concerns to the information technology surrounding it. Maybe things have changed now? But where does the boundary exist between the product’s security, the software and hardware enabling the function, and the surrounding environment? Who should be responsible? Do we rely on the insertion of insecure trust into our secure boundary? It’s not like that hasn’t been exploited before.\nWhat would it be like if we had these clear responsibilities established? We could achieve this by securing “computers” and their functions, which would be considered another aspect of good engineering consistent with engineering ethics. Such an approach would have further benefits as many incidents related to computer systems arise from poor engineering practices. A more robust approach to achieving safety and security assurance by design, where there are more specific responsibilities around the engineering of computer systems, could increase general system resilience and robustness, preventing many safety incidents from occurring altogether.\nSimplification of Complex Issues Can’t you just install Anti-virus on the Workstation and call it a day?\nI\u0026C Engineer, ~2017\n“Cyber security” simplifies complex and multifaceted issues that cross disciplines, through ambiguity reducing them to a binary concept of secure versus insecure and further positioning the entire profession to be seen through a lens of commodity measures and professional services. I had this experience, attempting to justify the security of a complex operational technology system within a nuclear reactor against a set of government controls primarily intended for application to information processing computers.\nThe systems we were looking at securing performed functions and had an existing engineered approach to assuring safety and security defence-in-depth. Multiple systems would perform the same function and thus deserve protection from external threats and measures for delay, detection, and response that orient towards reinforcing their reliability and independence. The mandated oversimplification of security hinders nuanced discussions and the development of comprehensive strategies for preserving the performance of these functions. Instead, we were, at best, incentivised to build a common boundary around all such devices and declare them secure.\nThese are all threat-centric approaches. Without more function-centric approaches, encouraging collaboration and cross-involvement between engineering and computer security to address the preservation of the overall engineered function, we will be stuck securing a set of potentially inconsequential computers in manners that may even degrade security.\nFear-driven Market Economics Did you read the article in Wired today? You should be more worried. If we are hacked, I’ll cut you loose before they take my head.\nIT Manager, ~2017\nIncreasing media coverage and public awareness of cyber threats have intensified concerns about the potential consequences of attacks. High-profile incidents, often involving sophisticated and well-resourced threat actors, have spurred organisations to invest in security measures without fully understanding the specific risks they face. This fear-driven demand has led to a proliferation of “cyber” products and services, with vendors capitalising on the anxiety surrounding cyber threats to promote their solutions as essential and establish long-term vendor lock-in.\nIn this climate, organisations are influenced by the overdramatisation of “cyber” to allocate resources based on fear and ambiguities surrounding the term rather than through rational risk assessment and the potential for actual risk reduction. The fear of becoming a victim of a cyber-attack, combined with the limited cross-disciplinary knowledge of many “cyber security” professionals, can result in a reactive deployment of the latest security technologies or services without considering their effectiveness in addressing the organisation’s unique vulnerabilities and threat landscape. Such reactivity can lead to suboptimal resource allocation, fostering a market that thrives on fear instead of developing and implementing effective, tailored strategies for meaningful risk reduction.\nStifling Innovation in Engineering If you don’t call it “cyber security”, I’m not funding it. I don’t care about good engineering. That’s their problem.\nIT Manager, ~2016\nThe trinity of “Cyber security/cyberthreat/cyber-attack” has positioned “cyber” as a threat-focused discipline distinct from engineering, promoting a reactive mindset where security measures are implemented as an afterthought or in response to specific threats. We prioritise resources to detect malicious activity on computer networks with little thought to addressing defensive strategies within the fundamental engineering designs and resulting response procedures. What happens when a threat is detected? Who responds, the engineering team or the computer security incident response team? Who has authority over the equipment?\nIf a process-aware anomaly detection system has a high-severity trigger, who will be liable when making the call to bring the process to a safe state? These procedures and interfaces likely do not exist or have yet to be considered. Treating “cyber security” as different to the engineering disciplines that develop computer-based systems and the operations teams that use them contributes to a lack of interdisciplinary expertise, where professionals narrowly focus on their respective domains. You will see security functions without communication channels and operations with poor visibility due to a reliance on compromisable digital indicators.\nA cyber-attack is not a special snowflake. Conversations need to occur to establish the mechanisms of delay, detection, and response addressed within the engineering design and shared between operations, engineering, and security. There is a misguided view that cyber security incident responders will have complete authority, but that seldom happens.\nFor the best outcome, we must recognise that many approaches to “cyber security” are just band-aids incentivising the industry to stand in the way of progress. There is a need for real innovation in how we engineer and operate computer-based systems. We can only achieve more effective assurance by recognising that “cyber security” protection is not absolute. Instead, our best approximation will be embedding computer security into the engineering design and building on that to leverage multi-disciplinary approaches to detection, delay, and response.\nConclusion There are misaligned incentives between engineering and “cyber security”, which I largely attribute to ambiguity in the term “cyber”. Engineering assurance prioritises functionality and cost from the comfort area of existing assessment methodologies, leaving “cyber security” as an exercise for operating organisations. Meanwhile, “cyber security” focuses on defending against cyber threats rather than working to support the assurance of functions those same threats would seek to target.\nThis misalignment can create tensions and hinder the development of balanced solutions, considering relevant information from both disciplines and meeting engineering needs and security objectives.\nWorse still, the symbiotic relationship between first-to-market engineering pressures and the false application of “cyber security”, if oriented to protecting computers rather than preserving functions, will be hugely detrimental to infrastructure security worldwide.\nThe focus on the robustness and resilience of the performance of functions, understood by both fields and made more tangible with “computer security” rather than “cyber security”, would encourage the adoption of a more holistic systems engineering effort that will go a long way to achieving security by design.\nWhichever word, we must recognise that “cyber security” is good engineering. It is not different; it is not unique; it is an assurance function that needs to be considered in the engineering design process, just like safety. After all, when faced with the existence of malicious acts, safety cannot be guaranteed without security.\n","date_published":"2023-03-21T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/cyber-security-considered-harmful/","image":"https://blog.mitcdh.au/images/cyber-security-considered-harmful.webp","summary":"The term “cyber security” has become commonplace. But it brings ambiguities; thus, its use may be doing more harm than we realise.","tags":["Writing","Nuclear","Technology","Security"],"title":"Is “Cyber Security” Harmful?","url":"https://blog.mitcdh.au/posts/cyber-security-considered-harmful/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eI am a big proponent of portability in IT. In that regard, personal custom email domains are great; they let you easily change the backend email provider you use while maintaining a single identity to the rest of the world. You\u0026rsquo;re not tied to Gmail/Yahoo/Hotmail but something uniquely you.\u003c/p\u003e\n\u003cp\u003eBut what happens when someone tries to browse a website associated with your email? Having something to show them is excellent, and it\u0026rsquo;s not that hard. To get started on building a quick landing page, I set out a couple of objectives to hit:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIt should be fast, free, and flexible.\u003c/li\u003e\n\u003cli\u003eIt should show some flair.\u003c/li\u003e\n\u003cli\u003eIt should be uniquely me.\u003c/li\u003e\n\u003cli\u003eIt needs to involve my friends.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSo what I came to can be found publicly on my \u003ca href=\"https://github.com/mitcdh/landing-page\"\u003eGitHub\u003c/a\u003e; it looks a little like this, and what follows is an explanation of how I achieved these objectives and had fun along the way.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/building-a-custom-landing-page_01.webp#wide\" width=\"1348\" height=\"928\" alt=\"Screenshot of the finished page\" loading=\"lazy\" decoding=\"async\"\u003e\n\u003c/p\u003e\n\u003ch1 id=\"fast-free-and-flexible\"\u003eFast, Free, and Flexible\u003c/h1\u003e\n\u003cp\u003eI compared several static website hosting services but, in the end, settled on \u003ca href=\"https://pages.cloudflare.com/\"\u003eCloudflare Pages\u003c/a\u003e because of how easily it integrated into my DNS infrastructure, also based on Cloudflare.\u003c/p\u003e\n\u003ch2 id=\"building-the-site\"\u003eBuilding the Site\u003c/h2\u003e\n\u003cp\u003eThe site itself is static, but I wanted the ability to extend it easily while travelling without worrying about modifying large parts of the codebase. The pages build process tracks the GitHub repository and automatically builds from the main branch. It runs a script within the build command \u0026rsquo;node build/build.js\u0026rsquo; that executes a set of defined build modules. So far, the following two build modules have been defined:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003efetchfonts.js\u003c/strong\u003e: Parses\u0026rsquo; data/greetings.json\u0026rsquo; containing different messages and their associated fonts. It then fetches the required font styles from Google Fonts, optimises them by \u003ca href=\"https://developers.google.com/fonts/docs/getting_started#optimizing_your_font_requests\"\u003eincluding only the unique characters\u003c/a\u003e used in the messages, and combines them into a single file called \u0026lsquo;webfonts.css\u0026rsquo;.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eparsebg.js:\u003c/strong\u003e Parses the \u0026lsquo;bg\u0026rsquo; directory for background images stored with the \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/CSS/background-position\"\u003e\u0026lsquo;background-position\u0026rsquo; CSS property\u003c/a\u003e in their filename. It then builds a \u0026lsquo;data/backgrounds.json\u0026rsquo; file. For \u0026lsquo;js/background.js\u0026rsquo; to work entirely as client-side javascript, it needs this index; this approach makes it trivial to add new backgrounds, as all information is contained in the filename.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"routing-the-page\"\u003eRouting the Page\u003c/h2\u003e\n\u003cp\u003eFor various reasons, I\u0026rsquo;ve accumulated several domains over time, and I wanted to be able to serve this landing page across a number of them efficiently without leaving the Cloudflare platform and having to establish a server to perform the redirection for me.\u003c/p\u003e\n\u003cp\u003eTo maximise functionality and minimise costs, I went with a combination of defining \u003ca href=\"https://developers.cloudflare.com/pages/platform/custom-domains/\"\u003eCustom Domains in Cloudflare Pages\u003c/a\u003e and \u003ca href=\"https://developers.cloudflare.com/workers/\"\u003eWorkers\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/building-a-custom-landing-page_02.webp\" width=\"758\" height=\"581\" alt=\"Cloudflare Pages custom domains configuration.\" loading=\"lazy\" decoding=\"async\"\u003e\n\u003c/p\u003e\n\u003cp\u003eI created a new Worker to intercept requests coming into Cloudflare to hit any of these domains. It then returns a 301 redirect to the canonical URL while preserving the search string:\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-1\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003ecf-worker-redirect.js\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/480fa3187a2fe505df7c4cce84516a8f#file-cf-worker-redirect-js\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-1-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy cf-worker-redirect.js to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-1-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-javascript\" data-lang=\"javascript\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-1\"\u003e 1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"kr\"\u003econst\u003c/span\u003e \u003cspan class=\"nx\"\u003ebase\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"s1\"\u003e\u0026#39;https://mitcdh.au\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-2\"\u003e 2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"kr\"\u003econst\u003c/span\u003e \u003cspan class=\"nx\"\u003estatusCode\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"mi\"\u003e301\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-3\"\u003e 3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-4\"\u003e 4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"nx\"\u003eaddEventListener\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;fetch\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e \u003cspan class=\"nx\"\u003eevent\u003c/span\u003e \u003cspan class=\"p\"\u003e=\u0026gt;\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-5\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-5\"\u003e 5\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"nx\"\u003eevent\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003erespondWith\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003ehandleRequest\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003eevent\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003erequest\u003c/span\u003e\u003cspan class=\"p\"\u003e))\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-6\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-6\"\u003e 6\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e})\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-7\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-7\"\u003e 7\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-8\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-8\"\u003e 8\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"kr\"\u003easync\u003c/span\u003e \u003cspan class=\"kd\"\u003efunction\u003c/span\u003e \u003cspan class=\"nx\"\u003ehandleRequest\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003erequest\u003c/span\u003e\u003cspan class=\"p\"\u003e)\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-9\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-9\"\u003e 9\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"kr\"\u003econst\u003c/span\u003e \u003cspan class=\"nx\"\u003eoriginalUrl\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"k\"\u003enew\u003c/span\u003e \u003cspan class=\"nx\"\u003eURL\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003erequest\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003eurl\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-10\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-10\"\u003e10\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-11\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-11\"\u003e11\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"c1\"\u003e// Bypass redirect for .well-known paths\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-12\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-12\"\u003e12\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"k\"\u003eif\u003c/span\u003e \u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003eoriginalUrl\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003epathname\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003estartsWith\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"s1\"\u003e\u0026#39;/.well-known/\u0026#39;\u003c/span\u003e\u003cspan class=\"p\"\u003e))\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-13\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-13\"\u003e13\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"k\"\u003ereturn\u003c/span\u003e \u003cspan class=\"nx\"\u003efetch\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003erequest\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e \u003cspan class=\"c1\"\u003e// Forward to origin without redirect\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-14\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-14\"\u003e14\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-15\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-15\"\u003e15\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-16\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-16\"\u003e16\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"kr\"\u003econst\u003c/span\u003e \u003cspan class=\"nx\"\u003eredirectUrl\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"nx\"\u003ebase\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-17\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-17\"\u003e17\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"kr\"\u003econst\u003c/span\u003e \u003cspan class=\"nx\"\u003enewUrl\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"k\"\u003enew\u003c/span\u003e \u003cspan class=\"nx\"\u003eURL\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003eredirectUrl\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-18\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-18\"\u003e18\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"nx\"\u003enewUrl\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003epathname\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"nx\"\u003eoriginalUrl\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003epathname\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-19\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-19\"\u003e19\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"nx\"\u003enewUrl\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003esearch\u003c/span\u003e \u003cspan class=\"o\"\u003e=\u003c/span\u003e \u003cspan class=\"nx\"\u003eoriginalUrl\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003esearch\u003c/span\u003e\u003cspan class=\"p\"\u003e;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-20\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-20\"\u003e20\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-21\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-21\"\u003e21\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"k\"\u003ereturn\u003c/span\u003e \u003cspan class=\"nx\"\u003eResponse\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003eredirect\u003c/span\u003e\u003cspan class=\"p\"\u003e(\u003c/span\u003e\u003cspan class=\"nx\"\u003enewUrl\u003c/span\u003e\u003cspan class=\"p\"\u003e.\u003c/span\u003e\u003cspan class=\"nx\"\u003etoString\u003c/span\u003e\u003cspan class=\"p\"\u003e(),\u003c/span\u003e \u003cspan class=\"nx\"\u003estatusCode\u003c/span\u003e\u003cspan class=\"p\"\u003e);\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-22\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-22\"\u003e22\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-23\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-23\"\u003e23\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-1-line-24\"\u003e\u003ca class=\"lnlinks\" href=\"#code-1-line-24\"\u003e24\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"kr\"\u003eexport\u003c/span\u003e \u003cspan class=\"p\"\u003e{\u003c/span\u003e \u003cspan class=\"nx\"\u003ehandleRequest\u003c/span\u003e \u003cspan class=\"p\"\u003e}\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003cp\u003eThen within the \u003ca href=\"https://developers.cloudflare.com/workers/platform/triggers/routes/\"\u003eWorker Triggers\u003c/a\u003e, I configured a unique route for all of the custom domains, specifically with the fail open option set so it will continue to function even when the free plan daily limits have been reached.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/building-a-custom-landing-page_03.webp\" width=\"1105\" height=\"623\" alt=\"Adding a fail-open route to the Cloudflare Worker.\" loading=\"lazy\" decoding=\"async\"\u003e\n\u003c/p\u003e\n\u003cp\u003eThis will allow the Worker to redirect all incoming requests to the Custom Domains configured in the Pages setup to the canonical URL. When the free plan has been exceeded, it will serve the website from the configured Custom Domain rather than redirect.\u003c/p\u003e\n\u003cp\u003eWorkers can also be bound to custom domains; however, in doing this, when the free quota is exceeded, the Worker will no longer run. This combination of Pages Custom Domains and Worker Routes allows the website to be served indefinitely for free.\u003c/p\u003e\n\u003ch2 id=\"content-redirection\"\u003eContent Redirection\u003c/h2\u003e\n\u003cp\u003eOver time, I have had several landing pages, including ones served from GitHub Pages, which will, by default, expose any other page builds as subdirectories. Some of these became valuable tools used by my friends, so I wanted to preserve them as efficiently as possible. I also wanted to establish a redirect for \u0026lsquo;/blog/\u0026rsquo; in case I ever wanted to use it as a subdirectory. Fortunately, Cloudflare Pages support defining server-side redirects in a \u0026lsquo;_redirects\u0026rsquo; file:\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-2\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003e_redirects\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/480fa3187a2fe505df7c4cce84516a8f#file-_redirects\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-2-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy _redirects to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-2-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-text\" data-lang=\"text\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-1\"\u003e1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e/feed/ https://blog.mitcdh.au/index.xml 301\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-2\"\u003e2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e/feed https://blog.mitcdh.au/index.xml 301\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-3\"\u003e3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e/rss/ https://blog.mitcdh.au/index.xml 301\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-4\"\u003e4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e/rss https://blog.mitcdh.au/index.xml 301\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-2-line-5\"\u003e\u003ca class=\"lnlinks\" href=\"#code-2-line-5\"\u003e5\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e/blog/* https://blog.mitcdh.au/:splat 301\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003ch2 id=\"whats-the-cost\"\u003eWhat\u0026rsquo;s the Cost\u003c/h2\u003e\n\u003cp\u003eIn short, thanks to Cloudflare and Github being incredibly generous with what they consider free, this should cost me a grand total of $0, with the only cost being the domain registration.\u003c/p\u003e\n\u003cp\u003ePages within its free tier are limited to 500 builds a month (a build is triggered on every commit) and 100 custom domains which I\u0026rsquo;ll never reach. The route redirection worker will serve 100k requests for free each day, after which it will fail open, leaving everything functioning, just served from each domain rather than redirected to the canonical domain.\u003c/p\u003e\n\u003ch1 id=\"show-some-flair\"\u003eShow Some Flair\u003c/h1\u003e\n\u003cp\u003eWhen I was first crafting this, I noticed several different glitch effects appearing on the internet, probably because at the time \u0026lsquo;Mr. Robot\u0026rsquo; was achieving a lot of well-deserved attention. So I wanted to employ this on the landing page; after a delay, the page would start visibly glitching, leaving people wondering what was happening. At first, I tried to do this with just the \u0026lsquo;clip\u0026rsquo; CSS property and ended up with something that was working but not great.\u003c/p\u003e\n\u003cp\u003eThen I found Codrops\u0026rsquo; \u003ca href=\"https://tympanus.net/codrops/2017/12/21/css-glitch-effect/\"\u003eCSS Glitch Effect\u003c/a\u003e, which used the \u0026lsquo;clip-path\u0026rsquo; property and was implemented in pure CSS. It was almost perfect for what I wanted to build and was relatively easy to integrate with only a few minor customisations.\u003c/p\u003e\n\u003ch1 id=\"uniquely-me\"\u003eUniquely Me\u003c/h1\u003e\n\u003cp\u003eI\u0026rsquo;ve travelled with many people, and we usually all have cameras. I was once told that the best pictures of me are always when I\u0026rsquo;m stopping to look, slow down, take in and appreciate the surroundings. So why not use that as a theme? It turns out \u0026ldquo;back of head\u0026rdquo; is an acceptable search term in Google Photos, so I downloaded all of what I considered the best pictures and assembled them into the \u0026lsquo;/bg\u0026rsquo; directory.\u003c/p\u003e\n\u003cp\u003eHowever, not all pictures are the same; some have me in different positions. To address this, each image is named in the format\u0026rsquo; \u003cem\u003ename.background-position.extension\u0026rsquo;,\u003c/em\u003e allowing both the name and the \u0026lsquo;background-position\u0026rsquo; CSS property to be extracted by the \u0026lsquo;parsebg.js\u0026rsquo; build script.\u003c/p\u003e\n\u003ch1 id=\"involving-my-friends\"\u003eInvolving My Friends\u003c/h1\u003e\n\u003cp\u003eTo have fun, I wrote a script \u003cem\u003ejs/greetings.js\u003c/em\u003e to type out several greetings based on the pluralised \u0026ldquo;Hello Friends\u0026rdquo;. The general way the script works is as follows:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eIt first detects the user\u0026rsquo;s preferred languages from their web browser.\u003c/li\u003e\n\u003cli\u003eIt then fetches a list of greetings in different languages and fonts from a file named \u0026lsquo;data/greetings.json\u0026rsquo;.\u003c/li\u003e\n\u003cli\u003eThe script shuffles the list of greetings so that they appear in a random order.\u003c/li\u003e\n\u003cli\u003eIt then moves the greetings that match the user\u0026rsquo;s preferred languages in \u0026rsquo;navigator.languages\u0026rsquo; to the front of the list, so they are displayed first. It\u0026rsquo;s always nicer to greet someone in a language and script that they\u0026rsquo;re familiar with 😊\u003c/li\u003e\n\u003cli\u003eThe typing animation starts, displaying one greeting at a time. The text appears as if it\u0026rsquo;s being typed and then gets deleted, one character at a time.\u003c/li\u003e\n\u003cli\u003eOnce a greeting is fully displayed, it pauses briefly before deleting the text.\u003c/li\u003e\n\u003cli\u003eAfter deleting the text, it moves on to the following greeting and repeats the process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eThis is all built off the file \u0026lsquo;data/greetings.json\u0026rsquo;, which I gathered from many friends worldwide. I\u0026rsquo;d ask them how you say \u0026ldquo;Hello Friends\u0026rdquo; as a bit of intercultural exchange and talk about how in Australia, we are more prone to say \u0026ldquo;G\u0026rsquo;day Mate(s)\u0026rdquo;. I\u0026rsquo;d then ask them if I could use it, and slowly I\u0026rsquo;m building up a collection:\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-3\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003egreetings.json\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003ca class=\"code-block__source\" href=\"https://gist.github.com/mitcdh/480fa3187a2fe505df7c4cce84516a8f#file-greetings-json\" target=\"_blank\" rel=\"noopener\"\u003eSource\u003c/a\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-3-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy greetings.json to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-3-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-json\" data-lang=\"json\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-1\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-1\"\u003e 1\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e\u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-2\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-2\"\u003e 2\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003e\u0026#34;greetings\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"p\"\u003e[\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-3\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-3\"\u003e 3\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-4\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-4\"\u003e 4\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;G\u0026#39;day Mates\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-5\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-5\"\u003e 5\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;en\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-6\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-6\"\u003e 6\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-7\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-7\"\u003e 7\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-8\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-8\"\u003e 8\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-9\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-9\"\u003e 9\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Ciao Amici\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-10\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-10\"\u003e10\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;it\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-11\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-11\"\u003e11\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-12\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-12\"\u003e12\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-13\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-13\"\u003e13\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-14\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-14\"\u003e14\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Salut les Amis\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-15\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-15\"\u003e15\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;fr\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-16\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-16\"\u003e16\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-17\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-17\"\u003e17\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-18\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-18\"\u003e18\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-19\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-19\"\u003e19\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;¡Hola Amigos!\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-20\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-20\"\u003e20\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;es\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-21\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-21\"\u003e21\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-22\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-22\"\u003e22\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-23\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-23\"\u003e23\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-24\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-24\"\u003e24\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Привет друзья\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-25\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-25\"\u003e25\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;ru\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-26\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-26\"\u003e26\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-27\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-27\"\u003e27\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-28\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-28\"\u003e28\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-29\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-29\"\u003e29\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;大家好\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-30\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-30\"\u003e30\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;zh\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-31\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-31\"\u003e31\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans TC\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-32\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-32\"\u003e32\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-33\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-33\"\u003e33\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-34\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-34\"\u003e34\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;مرحبا اصدقء\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-35\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-35\"\u003e35\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;ar\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-36\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-36\"\u003e36\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans Arabic\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-37\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-37\"\u003e37\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-38\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-38\"\u003e38\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-39\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-39\"\u003e39\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Servus, Liebe Freunde\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-40\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-40\"\u003e40\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;de\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-41\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-41\"\u003e41\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-42\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-42\"\u003e42\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-43\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-43\"\u003e43\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-44\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-44\"\u003e44\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Alô Galera\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-45\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-45\"\u003e45\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;pt\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-46\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-46\"\u003e46\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-47\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-47\"\u003e47\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-48\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-48\"\u003e48\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-49\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-49\"\u003e49\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;안녕하세요 친구\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-50\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-50\"\u003e50\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;ko\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-51\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-51\"\u003e51\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans KR\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-52\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-52\"\u003e52\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-53\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-53\"\u003e53\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-54\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-54\"\u003e54\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;皆さん、こんにちは\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-55\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-55\"\u003e55\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;ja\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-56\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-56\"\u003e56\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans JP\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-57\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-57\"\u003e57\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-58\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-58\"\u003e58\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-59\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-59\"\u003e59\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Hej Mina Vänner\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-60\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-60\"\u003e60\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;sv\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-61\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-61\"\u003e61\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-62\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-62\"\u003e62\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-63\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-63\"\u003e63\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-64\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-64\"\u003e64\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Selam Dostlar\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-65\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-65\"\u003e65\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;tr\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-66\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-66\"\u003e66\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-67\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-67\"\u003e67\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e},\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-68\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-68\"\u003e68\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-69\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-69\"\u003e69\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;message\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Pozdravljeni Prijatelji\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-70\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-70\"\u003e70\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;sl\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-71\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-71\"\u003e71\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e        \u003cspan class=\"nt\"\u003e\u0026#34;font\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Noto Sans\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-72\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-72\"\u003e72\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"p\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-73\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-73\"\u003e73\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"p\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"ln\" id=\"code-3-line-74\"\u003e\u003ca class=\"lnlinks\" href=\"#code-3-line-74\"\u003e74\u003c/a\u003e\u003c/span\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003cp\u003eBut not all writing scripts are included in the default fonts in a web browser; within \u0026lsquo;greetings.json\u0026rsquo;, you can define the font for each message which will be automatically fetched in the \u0026lsquo;fetchfonts.js\u0026rsquo; build script from Google Fonts. In the current build, I\u0026rsquo;m using this to download the \u003ca href=\"https://fonts.google.com/noto\"\u003eNoto Fonts\u003c/a\u003e and cover Latin, Cyrillic and Greek, CJK, and Arabic are covered, and the Webfont versions are stored locally as a backup if the build script isn\u0026rsquo;t called or fails.\u003c/p\u003e\n\u003cp\u003eYou can see the final product at \u003ca href=\"https://mitcdh.au/\"\u003ehttps://mitcdh.au\u003c/a\u003e\u003c/p\u003e\n","content_text":"I am a big proponent of portability in IT. In that regard, personal custom email domains are great; they let you easily change the backend email provider you use while maintaining a single identity to the rest of the world. You’re not tied to Gmail/Yahoo/Hotmail but something uniquely you.\nBut what happens when someone tries to browse a website associated with your email? Having something to show them is excellent, and it’s not that hard. To get started on building a quick landing page, I set out a couple of objectives to hit:\nIt should be fast, free, and flexible. It should show some flair. It should be uniquely me. It needs to involve my friends. So what I came to can be found publicly on my GitHub; it looks a little like this, and what follows is an explanation of how I achieved these objectives and had fun along the way.\nFast, Free, and Flexible I compared several static website hosting services but, in the end, settled on Cloudflare Pages because of how easily it integrated into my DNS infrastructure, also based on Cloudflare.\nBuilding the Site The site itself is static, but I wanted the ability to extend it easily while travelling without worrying about modifying large parts of the codebase. The pages build process tracks the GitHub repository and automatically builds from the main branch. It runs a script within the build command ’node build/build.js’ that executes a set of defined build modules. So far, the following two build modules have been defined:\nfetchfonts.js: Parses’ data/greetings.json’ containing different messages and their associated fonts. It then fetches the required font styles from Google Fonts, optimises them by including only the unique characters used in the messages, and combines them into a single file called ‘webfonts.css’. parsebg.js: Parses the ‘bg’ directory for background images stored with the ‘background-position’ CSS property in their filename. It then builds a ‘data/backgrounds.json’ file. For ‘js/background.js’ to work entirely as client-side javascript, it needs this index; this approach makes it trivial to add new backgrounds, as all information is contained in the filename. Routing the Page For various reasons, I’ve accumulated several domains over time, and I wanted to be able to serve this landing page across a number of them efficiently without leaving the Cloudflare platform and having to establish a server to perform the redirection for me.\nTo maximise functionality and minimise costs, I went with a combination of defining Custom Domains in Cloudflare Pages and Workers.\nI created a new Worker to intercept requests coming into Cloudflare to hit any of these domains. It then returns a 301 redirect to the canonical URL while preserving the search string:\ncf-worker-redirect.js Source Wrap Copy 1const base = 'https://mitcdh.au'; 2const statusCode = 301; 3 4addEventListener('fetch', event =\u003e { 5 event.respondWith(handleRequest(event.request)) 6}) 7 8async function handleRequest(request) { 9 const originalUrl = new URL(request.url); 10 11 // Bypass redirect for .well-known paths 12 if (originalUrl.pathname.startsWith('/.well-known/')) { 13 return fetch(request); // Forward to origin without redirect 14 } 15 16 const redirectUrl = base; 17 const newUrl = new URL(redirectUrl); 18 newUrl.pathname = originalUrl.pathname; 19 newUrl.search = originalUrl.search; 20 21 return Response.redirect(newUrl.toString(), statusCode); 22} 23 24export { handleRequest } Then within the Worker Triggers, I configured a unique route for all of the custom domains, specifically with the fail open option set so it will continue to function even when the free plan daily limits have been reached.\nThis will allow the Worker to redirect all incoming requests to the Custom Domains configured in the Pages setup to the canonical URL. When the free plan has been exceeded, it will serve the website from the configured Custom Domain rather than redirect.\nWorkers can also be bound to custom domains; however, in doing this, when the free quota is exceeded, the Worker will no longer run. This combination of Pages Custom Domains and Worker Routes allows the website to be served indefinitely for free.\nContent Redirection Over time, I have had several landing pages, including ones served from GitHub Pages, which will, by default, expose any other page builds as subdirectories. Some of these became valuable tools used by my friends, so I wanted to preserve them as efficiently as possible. I also wanted to establish a redirect for ‘/blog/’ in case I ever wanted to use it as a subdirectory. Fortunately, Cloudflare Pages support defining server-side redirects in a ‘_redirects’ file:\n_redirects Source Wrap Copy 1/feed/ https://blog.mitcdh.au/index.xml 301 2/feed https://blog.mitcdh.au/index.xml 301 3/rss/ https://blog.mitcdh.au/index.xml 301 4/rss https://blog.mitcdh.au/index.xml 301 5/blog/* https://blog.mitcdh.au/:splat 301 What’s the Cost In short, thanks to Cloudflare and Github being incredibly generous with what they consider free, this should cost me a grand total of $0, with the only cost being the domain registration.\nPages within its free tier are limited to 500 builds a month (a build is triggered on every commit) and 100 custom domains which I’ll never reach. The route redirection worker will serve 100k requests for free each day, after which it will fail open, leaving everything functioning, just served from each domain rather than redirected to the canonical domain.\nShow Some Flair When I was first crafting this, I noticed several different glitch effects appearing on the internet, probably because at the time ‘Mr. Robot’ was achieving a lot of well-deserved attention. So I wanted to employ this on the landing page; after a delay, the page would start visibly glitching, leaving people wondering what was happening. At first, I tried to do this with just the ‘clip’ CSS property and ended up with something that was working but not great.\nThen I found Codrops’ CSS Glitch Effect, which used the ‘clip-path’ property and was implemented in pure CSS. It was almost perfect for what I wanted to build and was relatively easy to integrate with only a few minor customisations.\nUniquely Me I’ve travelled with many people, and we usually all have cameras. I was once told that the best pictures of me are always when I’m stopping to look, slow down, take in and appreciate the surroundings. So why not use that as a theme? It turns out “back of head” is an acceptable search term in Google Photos, so I downloaded all of what I considered the best pictures and assembled them into the ‘/bg’ directory.\nHowever, not all pictures are the same; some have me in different positions. To address this, each image is named in the format’ name.background-position.extension’, allowing both the name and the ‘background-position’ CSS property to be extracted by the ‘parsebg.js’ build script.\nInvolving My Friends To have fun, I wrote a script js/greetings.js to type out several greetings based on the pluralised “Hello Friends”. The general way the script works is as follows:\nIt first detects the user’s preferred languages from their web browser. It then fetches a list of greetings in different languages and fonts from a file named ‘data/greetings.json’. The script shuffles the list of greetings so that they appear in a random order. It then moves the greetings that match the user’s preferred languages in ’navigator.languages’ to the front of the list, so they are displayed first. It’s always nicer to greet someone in a language and script that they’re familiar with 😊 The typing animation starts, displaying one greeting at a time. The text appears as if it’s being typed and then gets deleted, one character at a time. Once a greeting is fully displayed, it pauses briefly before deleting the text. After deleting the text, it moves on to the following greeting and repeats the process. This is all built off the file ‘data/greetings.json’, which I gathered from many friends worldwide. I’d ask them how you say “Hello Friends” as a bit of intercultural exchange and talk about how in Australia, we are more prone to say “G’day Mate(s)”. I’d then ask them if I could use it, and slowly I’m building up a collection:\ngreetings.json Source Wrap Copy 1{ 2 \"greetings\": [ 3 { 4 \"message\": \"G'day Mates\", 5 \"code\": \"en\", 6 \"font\": \"Noto Sans\" 7 }, 8 { 9 \"message\": \"Ciao Amici\", 10 \"code\": \"it\", 11 \"font\": \"Noto Sans\" 12 }, 13 { 14 \"message\": \"Salut les Amis\", 15 \"code\": \"fr\", 16 \"font\": \"Noto Sans\" 17 }, 18 { 19 \"message\": \"¡Hola Amigos!\", 20 \"code\": \"es\", 21 \"font\": \"Noto Sans\" 22 }, 23 { 24 \"message\": \"Привет друзья\", 25 \"code\": \"ru\", 26 \"font\": \"Noto Sans\" 27 }, 28 { 29 \"message\": \"大家好\", 30 \"code\": \"zh\", 31 \"font\": \"Noto Sans TC\" 32 }, 33 { 34 \"message\": \"مرحبا اصدقء\", 35 \"code\": \"ar\", 36 \"font\": \"Noto Sans Arabic\" 37 }, 38 { 39 \"message\": \"Servus, Liebe Freunde\", 40 \"code\": \"de\", 41 \"font\": \"Noto Sans\" 42 }, 43 { 44 \"message\": \"Alô Galera\", 45 \"code\": \"pt\", 46 \"font\": \"Noto Sans\" 47 }, 48 { 49 \"message\": \"안녕하세요 친구\", 50 \"code\": \"ko\", 51 \"font\": \"Noto Sans KR\" 52 }, 53 { 54 \"message\": \"皆さん、こんにちは\", 55 \"code\": \"ja\", 56 \"font\": \"Noto Sans JP\" 57 }, 58 { 59 \"message\": \"Hej Mina Vänner\", 60 \"code\": \"sv\", 61 \"font\": \"Noto Sans\" 62 }, 63 { 64 \"message\": \"Selam Dostlar\", 65 \"code\": \"tr\", 66 \"font\": \"Noto Sans\" 67 }, 68 { 69 \"message\": \"Pozdravljeni Prijatelji\", 70 \"code\": \"sl\", 71 \"font\": \"Noto Sans\" 72 } 73 ] 74 } But not all writing scripts are included in the default fonts in a web browser; within ‘greetings.json’, you can define the font for each message which will be automatically fetched in the ‘fetchfonts.js’ build script from Google Fonts. In the current build, I’m using this to download the Noto Fonts and cover Latin, Cyrillic and Greek, CJK, and Arabic are covered, and the Webfont versions are stored locally as a backup if the build script isn’t called or fails.\nYou can see the final product at https://mitcdh.au\n","date_published":"2023-03-20T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/building-a-custom-landing-page/","image":"https://blog.mitcdh.au/images/building-a-custom-landing-page.webp","summary":"Wherein I save the world from another NXDOMAIN or WIP page.","tags":["Writing","Technology","Code"],"title":"Building a Custom Landing Page","url":"https://blog.mitcdh.au/posts/building-a-custom-landing-page/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eArtificial Intelligence/Machine Learning (AI/ML) models need more transparency and explainability, the lack of which makes it difficult to understand how they arrive at their conclusions and can degrade security. While achieving transparency and explainability can be challenging, failing to do so can require users of the AI/ML models to place blind trust in their output. When such AI/ML models are relied upon without considering how they can be subverted through a malicious act, there is a risk of weakening overall defence-in-depth.\u003c/p\u003e\n\u003cp\u003eDeployment concepts integrating AI/ML into decision-making processes are becoming increasingly common with a push to leverage the technology to reduce costs and increase efficiency. Organisations wishing to receive the most benefit from this will follow through with a reduction in the importance of direct sensing and reliance on human training, intuition, authority, and experience. This would then require more trust in the output of AI/ML models as they are leveraged directly within the performance of critical functions.\u003c/p\u003e\n\u003cp\u003eBefore this happens, we should seek to understand how the models could be compromised \u0026mdash; no matter how unlikely that compromise might seem. This is a non-exhaustive attempt to brainstorm how this might occur across attacks directed towards training data, supporting computer-based infrastructure, the model and its execution, and the acceptance and standardisation process.\u003c/p\u003e\n\u003ch1 id=\"training-data\"\u003eTraining Data\u003c/h1\u003e\n\u003cp\u003eTraining data is a set of examples used to train a machine-learning model. Training data teaches the model to recognise patterns and make predictions or classifications based on the training data set. Malicious actors might target the training data set to compromise the model\u0026rsquo;s decision-making.\u003c/p\u003e\n\u003ch2 id=\"malicious-mislabelling-through-attacks-against-the-data-set-or-labelling-process-for-supervised-models\"\u003eMalicious mislabelling through attacks against the data set or labelling process for supervised models.\u003c/h2\u003e\n\u003cp\u003eIn a supervised AI/ML system, models are trained with labelled data to \u0026ldquo;learn\u0026rdquo; the relationship between inputs and outputs.\u003c/p\u003e\n\u003cp\u003eAn example of such a training data set would be many photos of fruit, each with a description or label noting its type, such as apple or orange. These images and labels would then be loaded into the model and used to compute patterns visible within all photos of a common type. The model learns to recognise patterns in the fruit images during training, associate them with the labelled category, and then use that knowledge to identify new unlabelled fruit images it hasn\u0026rsquo;t seen before.\u003c/p\u003e\n\u003cp\u003eSuppose the training data set or the labelling process is compromised, and these labels can be manipulated. In that case, the model could be trained to return wrong decisions on wide-ranging or specific inputs.\u003c/p\u003e\n\u003ch2 id=\"injection-of-adversarial-examples-into-the-training-dataset\"\u003eInjection of adversarial examples into the training data set.\u003c/h2\u003e\n\u003cp\u003eSimilarly, a malicious actor could intentionally manipulate the training data set by injecting adversarial examples, which may be indistinguishable from regular inputs in review but are designed to mislead the model. This could later be combined with adversarial inputs to increase the reliability in which they can subvert the model once it is deployed.\u003c/p\u003e\n\u003ch2 id=\"undermining-the-statistical-assumptions-of-the-model-by-silently-manipulating-training-datasets\"\u003eUndermining the statistical assumptions of the model by silently manipulating training datasets.\u003c/h2\u003e\n\u003cp\u003eAn AI/ML model is designed to learn from the statistical patterns and trends in the training data set. A malicious actor could manipulate the training data set to undermine the statistical assumptions of the model, resulting in a model that does not accurately represent the data and is not fit for purpose. This may be particularly relevant for models running on limited datasets, for example, a model designed to support the calculation of flow rate at a specific point in an industrial process without a sensor.\u003c/p\u003e\n\u003ch2 id=\"deliberate-manipulation-of-captured-data-to-affect-the-fit-of-the-model-during-retraining\"\u003eDeliberate manipulation of captured data to affect the fit of the model during retraining.\u003c/h2\u003e\n\u003cp\u003eAI/ML models are retrained over time with new data; a malicious actor could manipulate the captured data, combined with one or more of the above techniques, to affect the fit of the model during retraining.\u003c/p\u003e\n\u003ch2 id=\"unauthorised-access-to-retraining-data-compromising-confidentiality\"\u003eUnauthorised access to retraining data compromising confidentiality.\u003c/h2\u003e\n\u003cp\u003eThe training data may be fundamentally sensitive, revealing flaws or limits of performance in a model or the function it is designed to support. A malicious actor may be able to utilise this in preparing an attack against the model or the supported function.\u003c/p\u003e\n\u003ch1 id=\"supporting-computer-based-infrastructure\"\u003eSupporting Computer-based Infrastructure\u003c/h1\u003e\n\u003cp\u003eAI/ML models do not work alone; they are surrounded by supporting infrastructure such as servers, databases, storage systems, networking equipment, and software tools to support the training and execution of the model. Malicious actors may target these to compromise the model\u0026rsquo;s output indirectly.\u003c/p\u003e\n\u003ch2 id=\"compromise-of-supporting-software-in-the-inputoutput-chain-of-themodel\"\u003eCompromise of supporting software in the input/output chain of the model.\u003c/h2\u003e\n\u003cp\u003eIt will likely be uncommon to directly provide input or receive output from the exact process of training or executing the model. Instead, various supporting software may provide web and network services, inter-process communication, and loading input and output data in and out of pre- and post-processing functions.\u003c/p\u003e\n\u003cp\u003eA malicious actor may attempt to compromise any part of this infrastructure to manipulate the integrity of the data loaded into the model, or the output returned (e.g., through a \u003ca href=\"https://en.wikipedia.org/wiki/Man-in-the-middle_attack\"\u003eman-in-the-middle attack\u003c/a\u003e). This can be done in a way undetectable by the system or user of the model, exploiting any implicit trust at play.\u003c/p\u003e\n\u003ch2 id=\"compromise-of-operating-system-functions-leveraged-by-the-model-for-interaction-with-datasets\"\u003eCompromise of operating system functions leveraged by the model for interaction with data sets.\u003c/h2\u003e\n\u003cp\u003eAn AI/ML model may use many features the operating system provides. A malicious actor may seek to exploit vulnerabilities in the operating system\u0026rsquo;s system calls, file handling, shared libraries, and memory management to inject malicious data sets into the model.\u003c/p\u003e\n\u003cp\u003eThis is noteworthy as without explainable models, or within models that are considered proprietary, there is an implicit trust required that may outweigh the authority, intuition, and experience of personnel in a decision-making process, e.g., the AI/ML model is provided by a vendor, the model is accurate, but through such a compromise its decision-making ability is compromised. An operator notices this, but the model will pass all integrity checks. Who would you trust?\u003c/p\u003e\n\u003ch2 id=\"manipulation-of-input-order-through-the-randomiser-function\"\u003eManipulation of input order through the randomiser function.\u003c/h2\u003e\n\u003cp\u003eDuring the training process of AI/ML models, the data is often randomised to reduce biases that might be generated towards a particular subset of data. A malicious actor might seek to compromise the randomiser function used to load the training data into the model, allowing them to manipulate the order of the inputs. This could lead to incorrect relationships between inputs and outputs or be used to magnify the reliability of adversarial examples and inputs.\u003c/p\u003e\n\u003ch2 id=\"manipulation-of-test-inputoutput-through-pre--and-post-processing-functions\"\u003eManipulation of test input/output through pre- and post-processing functions.\u003c/h2\u003e\n\u003cp\u003ePre- and post-processing functions can be used to manipulate training and input data and the resulting outputs from the model. A malicious actor might seek to compromise one of both sets of functions to allow undetected subversion of the model while outputting data that either deceives systems and personnel or holds up to interpretation standards; however, the model has been silently compromised.\u003c/p\u003e\n\u003ch1 id=\"the-model-and-its-execution\"\u003eThe Model and its Execution\u003c/h1\u003e\n\u003cp\u003eAI/ML models are fundamentally computer programs. They are represented in code that is executed by a computer-based system. A malicious actor may seek to compromise either the code itself or its interpretation by computers.\u003c/p\u003e\n\u003ch2 id=\"compromising-the-programming-or-code-of-the-modelitself\"\u003eCompromising the programming or code of the model itself.\u003c/h2\u003e\n\u003cp\u003eA malicious actor may seek to modify or inject malicious code into any processes that form part of the model. This would allow any form of tampering to occur to subvert the model. Such an attack, however, should be readily detected through existing means of integrity checking.\u003c/p\u003e\n\u003ch2 id=\"exposure-of-the-model-code-in-either-source-or-object-codeform\"\u003eExposure of the model code in either source or object code form.\u003c/h2\u003e\n\u003cp\u003eThe source code or compiled version of the model may contain confidential information that, if accessed by a malicious actor, could be used to identify vulnerabilities or extract sensitive information that could support another attack.\u003c/p\u003e\n\u003ch2 id=\"compromise-of-operating-system-functions-leveraged-in-the-execution-of-themodel\"\u003eCompromise of operating system functions leveraged in the execution of the model.\u003c/h2\u003e\n\u003cp\u003eThe object code for an AI/ML model needs to be loaded for execution by the operating system and potentially a series of interpreters. A malicious actor may seek to exploit vulnerabilities in the operating system\u0026rsquo;s system calls, file handling, shared libraries, and memory management to inject malicious code into the execution of the model itself.\u003c/p\u003e\n\u003ch2 id=\"compromise-of-serialisation-functions-or-storage-used-for-persistence-of-modelstate\"\u003eCompromise of serialisation functions or storage used for persistence of model state.\u003c/h2\u003e\n\u003cp\u003eSome AI/ML models use serialisation functions to provide for state persistence. These functions generate a representation of the state of the complex data structures within the model and store it in a form that is easily saved into a file or transmitted. When this data is again loaded (deserialised), the model resumes executing from its previous state. A malicious actor could compromise the functions or the stored serialised form to tamper with the model and subvert its subsequent reload and execution.\u003c/p\u003e\n\u003ch1 id=\"acceptance-and-standardisation\"\u003eAcceptance and Standardisation\u003c/h1\u003e\n\u003cp\u003eAI/ML models will take time and resources to develop. Like with conventional computer modelling codes, some will become more prevalent than others. A malicious actor may exploit this natural filtering.\u003c/p\u003e\n\u003ch2 id=\"deliberate-promotion-of-vulnerable-models-that-can-be-exploited-with-specific-knowledge\"\u003eDeliberate promotion of vulnerable models that can be exploited with specific knowledge.\u003c/h2\u003e\n\u003cp\u003eThere is a risk of deliberately vulnerable AI/ML models being published, which may appear complete but contain weaknesses that can be exploited with specific knowledge. A similar situation would be the allegations that a backdoor allowing an actor with knowledge of the backdoor to decrypt affected communications was crafted into the \u003ca href=\"https://en.wikipedia.org/wiki/Dual_EC_DRBG\"\u003eDual EC DRBG pseudorandom number generator\u003c/a\u003e during the standardisation process.\u003c/p\u003e\n\u003cp\u003eA well-resourced malicious actor may publish a model that achieves a desired goal but embeds an element that can be exploited later. Such an attack can be supported by proxies and unwitting advocates, leading to the widespread adoption of the compromised model. This could be occurring now.\u003c/p\u003e\n\u003ch1 id=\"conclusion\"\u003eConclusion\u003c/h1\u003e\n\u003cp\u003eA malicious actor will constantly attempt new attacks to achieve their intentions and seek to subvert functions and the systems that perform them by intelligently triggering the worst impacts at the most vulnerable moments. We must consider every potential point of failure in a system, even those unrelated to its design. This requires examining every aspect from multiple angles, building an understanding of how it could be exploited, and securing it according to how the technology will be used and the unacceptable consequences of compromise of its misuse. This is a brief attempt to consider how that exploitation might arise for AI/ML.\u003c/p\u003e\n","content_text":"Artificial Intelligence/Machine Learning (AI/ML) models need more transparency and explainability, the lack of which makes it difficult to understand how they arrive at their conclusions and can degrade security. While achieving transparency and explainability can be challenging, failing to do so can require users of the AI/ML models to place blind trust in their output. When such AI/ML models are relied upon without considering how they can be subverted through a malicious act, there is a risk of weakening overall defence-in-depth.\nDeployment concepts integrating AI/ML into decision-making processes are becoming increasingly common with a push to leverage the technology to reduce costs and increase efficiency. Organisations wishing to receive the most benefit from this will follow through with a reduction in the importance of direct sensing and reliance on human training, intuition, authority, and experience. This would then require more trust in the output of AI/ML models as they are leveraged directly within the performance of critical functions.\nBefore this happens, we should seek to understand how the models could be compromised — no matter how unlikely that compromise might seem. This is a non-exhaustive attempt to brainstorm how this might occur across attacks directed towards training data, supporting computer-based infrastructure, the model and its execution, and the acceptance and standardisation process.\nTraining Data Training data is a set of examples used to train a machine-learning model. Training data teaches the model to recognise patterns and make predictions or classifications based on the training data set. Malicious actors might target the training data set to compromise the model’s decision-making.\nMalicious mislabelling through attacks against the data set or labelling process for supervised models. In a supervised AI/ML system, models are trained with labelled data to “learn” the relationship between inputs and outputs.\nAn example of such a training data set would be many photos of fruit, each with a description or label noting its type, such as apple or orange. These images and labels would then be loaded into the model and used to compute patterns visible within all photos of a common type. The model learns to recognise patterns in the fruit images during training, associate them with the labelled category, and then use that knowledge to identify new unlabelled fruit images it hasn’t seen before.\nSuppose the training data set or the labelling process is compromised, and these labels can be manipulated. In that case, the model could be trained to return wrong decisions on wide-ranging or specific inputs.\nInjection of adversarial examples into the training data set. Similarly, a malicious actor could intentionally manipulate the training data set by injecting adversarial examples, which may be indistinguishable from regular inputs in review but are designed to mislead the model. This could later be combined with adversarial inputs to increase the reliability in which they can subvert the model once it is deployed.\nUndermining the statistical assumptions of the model by silently manipulating training datasets. An AI/ML model is designed to learn from the statistical patterns and trends in the training data set. A malicious actor could manipulate the training data set to undermine the statistical assumptions of the model, resulting in a model that does not accurately represent the data and is not fit for purpose. This may be particularly relevant for models running on limited datasets, for example, a model designed to support the calculation of flow rate at a specific point in an industrial process without a sensor.\nDeliberate manipulation of captured data to affect the fit of the model during retraining. AI/ML models are retrained over time with new data; a malicious actor could manipulate the captured data, combined with one or more of the above techniques, to affect the fit of the model during retraining.\nUnauthorised access to retraining data compromising confidentiality. The training data may be fundamentally sensitive, revealing flaws or limits of performance in a model or the function it is designed to support. A malicious actor may be able to utilise this in preparing an attack against the model or the supported function.\nSupporting Computer-based Infrastructure AI/ML models do not work alone; they are surrounded by supporting infrastructure such as servers, databases, storage systems, networking equipment, and software tools to support the training and execution of the model. Malicious actors may target these to compromise the model’s output indirectly.\nCompromise of supporting software in the input/output chain of the model. It will likely be uncommon to directly provide input or receive output from the exact process of training or executing the model. Instead, various supporting software may provide web and network services, inter-process communication, and loading input and output data in and out of pre- and post-processing functions.\nA malicious actor may attempt to compromise any part of this infrastructure to manipulate the integrity of the data loaded into the model, or the output returned (e.g., through a man-in-the-middle attack). This can be done in a way undetectable by the system or user of the model, exploiting any implicit trust at play.\nCompromise of operating system functions leveraged by the model for interaction with data sets. An AI/ML model may use many features the operating system provides. A malicious actor may seek to exploit vulnerabilities in the operating system’s system calls, file handling, shared libraries, and memory management to inject malicious data sets into the model.\nThis is noteworthy as without explainable models, or within models that are considered proprietary, there is an implicit trust required that may outweigh the authority, intuition, and experience of personnel in a decision-making process, e.g., the AI/ML model is provided by a vendor, the model is accurate, but through such a compromise its decision-making ability is compromised. An operator notices this, but the model will pass all integrity checks. Who would you trust?\nManipulation of input order through the randomiser function. During the training process of AI/ML models, the data is often randomised to reduce biases that might be generated towards a particular subset of data. A malicious actor might seek to compromise the randomiser function used to load the training data into the model, allowing them to manipulate the order of the inputs. This could lead to incorrect relationships between inputs and outputs or be used to magnify the reliability of adversarial examples and inputs.\nManipulation of test input/output through pre- and post-processing functions. Pre- and post-processing functions can be used to manipulate training and input data and the resulting outputs from the model. A malicious actor might seek to compromise one of both sets of functions to allow undetected subversion of the model while outputting data that either deceives systems and personnel or holds up to interpretation standards; however, the model has been silently compromised.\nThe Model and its Execution AI/ML models are fundamentally computer programs. They are represented in code that is executed by a computer-based system. A malicious actor may seek to compromise either the code itself or its interpretation by computers.\nCompromising the programming or code of the model itself. A malicious actor may seek to modify or inject malicious code into any processes that form part of the model. This would allow any form of tampering to occur to subvert the model. Such an attack, however, should be readily detected through existing means of integrity checking.\nExposure of the model code in either source or object code form. The source code or compiled version of the model may contain confidential information that, if accessed by a malicious actor, could be used to identify vulnerabilities or extract sensitive information that could support another attack.\nCompromise of operating system functions leveraged in the execution of the model. The object code for an AI/ML model needs to be loaded for execution by the operating system and potentially a series of interpreters. A malicious actor may seek to exploit vulnerabilities in the operating system’s system calls, file handling, shared libraries, and memory management to inject malicious code into the execution of the model itself.\nCompromise of serialisation functions or storage used for persistence of model state. Some AI/ML models use serialisation functions to provide for state persistence. These functions generate a representation of the state of the complex data structures within the model and store it in a form that is easily saved into a file or transmitted. When this data is again loaded (deserialised), the model resumes executing from its previous state. A malicious actor could compromise the functions or the stored serialised form to tamper with the model and subvert its subsequent reload and execution.\nAcceptance and Standardisation AI/ML models will take time and resources to develop. Like with conventional computer modelling codes, some will become more prevalent than others. A malicious actor may exploit this natural filtering.\nDeliberate promotion of vulnerable models that can be exploited with specific knowledge. There is a risk of deliberately vulnerable AI/ML models being published, which may appear complete but contain weaknesses that can be exploited with specific knowledge. A similar situation would be the allegations that a backdoor allowing an actor with knowledge of the backdoor to decrypt affected communications was crafted into the Dual EC DRBG pseudorandom number generator during the standardisation process.\nA well-resourced malicious actor may publish a model that achieves a desired goal but embeds an element that can be exploited later. Such an attack can be supported by proxies and unwitting advocates, leading to the widespread adoption of the compromised model. This could be occurring now.\nConclusion A malicious actor will constantly attempt new attacks to achieve their intentions and seek to subvert functions and the systems that perform them by intelligently triggering the worst impacts at the most vulnerable moments. We must consider every potential point of failure in a system, even those unrelated to its design. This requires examining every aspect from multiple angles, building an understanding of how it could be exploited, and securing it according to how the technology will be used and the unacceptable consequences of compromise of its misuse. This is a brief attempt to consider how that exploitation might arise for AI/ML.\n","date_published":"2023-03-10T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/a-primer-on-subverting-ai-ml/","image":"https://blog.mitcdh.au/images/a-primer-on-subverting-ai-ml.webp","summary":"Before placing implicit trust in AI/ML models for decision-making it is worth considering how they can be compromised. Here are some ideas.","tags":["Writing","AI","Technology","Security"],"title":"A Primer on Subverting AI/ML","url":"https://blog.mitcdh.au/posts/a-primer-on-subverting-ai-ml/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eThe concept of security is highly subjective and varies greatly depending on individual perceptions of the functional space and its known threats; this does not need to be the case. Physical security, personnel security, insider threat mitigation, information and computer security, engineered systems and business process design all contribute to a comprehensive security framework. Experts from each area may unintentionally prioritise the importance of their specific expertise \u0026mdash; protection against known threats will always seem more critical than unknown ones.\u003c/p\u003e\n\u003cp\u003eMy understanding of security was shaped by reading \u003ca href=\"https://www.cl.cam.ac.uk/~rja14/book.html\"\u003eSecurity Engineering by Ross Anderson\u003c/a\u003e. From this book, I took the idea that safety and security combine to protect against the effects of events arising from error, mischance, and malicious action. Safety and security might be the same concept and share the same word in some languages. However, when a distinction is made, it is apparent that error and mischance are addressed by well-established processes in safety, leaving malice, or the protection against the effects of malicious action, as the domain of security.\u003c/p\u003e\n\u003cp\u003eProtecting against malice is incredibly complex. It requires defending against adversaries intending to cause harm and with the cognitive ability to develop or obtain the necessary resources and information to achieve it. The challenge is ongoing as adversaries develop additional capabilities, refine their tactics, techniques, and procedures, gather data to target any possible vulnerability and learn from successive attempts or attacks against similar targets, allowing them to reorient their approach. In the field of cyber security, this challenge is even more apparent due to the instantaneous nature of cyber capabilities, which can be weaponised with just a few lines of code and proliferate rapidly. Unlike the production and use of automatic weapons, which took several decades to spread from military to organised crime, cyber-capable adversaries can almost instantaneously copy and distribute information on vulnerabilities or tools to enable their exploitation.\u003c/p\u003e\n\u003cp\u003eThese factors make applying a threat-centric approach, where it is assumed you have a fully comprehensive understanding of the threat capabilities, increasingly more challenging to achieve if possible. But what do we control? The business functions and the organisational systems that perform them. We can engineer reliability and defence in depth, taking a multidisciplinary approach to anticipate the consequences of compromise before discovering any threat capability.\u003c/p\u003e\n\u003cp\u003eSecurity, particularly information and computer security, should be seen through the lens of the degree of trust one maintains in the dependability of a function to continue to be performed correctly despite a malicious act against any system supporting its performance. This is not a random failure in safety; adversaries will constantly attempt new attacks to achieve their intentions and seek to subvert the targeted function by intelligently triggering the worst impacts at the most vulnerable moments. The only reasonable response is to orient security as a state, representing an objective that allows the specification of an engineering effort to achieve it.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThe degree of trust that given systems will continue to provide a desired function despite a malicious act.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eIf security protects systems and preserves functions, responsible engineers and business processes, owners must also be involved. To achieve this approach, we must identify an organisation or facility\u0026rsquo;s critical functions and the systems delivering them, then collaborate across disciplines to assess the possible means and consequences of compromise. We must perform this analysis thoroughly and across disciplines and recognise that much of this information will not exist within any system design. If that is not the case, we will unknowingly implement a lesser security state. Each represented discipline will offer a unique perspective that contributes to a comprehensive understanding of the potential impacts, allowing for effective and targeted protective measures and approaches to detection and response to be implemented, delivering genuine risk reduction rather than just a simulation of it.\u003c/p\u003e\n\u003cp\u003eDemonstrating absolute or probabilistic protection against malicious acts might not be possible, but reducing the consequences of compromise, and implementing defence in depth to facilitate detection, response, and mitigation of consequences before they can be realised, is within our control. Employing this function-centric multidisciplinary approach is the best approach to maintaining a state of security that is adaptable into the future.\u003c/p\u003e\n","content_text":"The concept of security is highly subjective and varies greatly depending on individual perceptions of the functional space and its known threats; this does not need to be the case. Physical security, personnel security, insider threat mitigation, information and computer security, engineered systems and business process design all contribute to a comprehensive security framework. Experts from each area may unintentionally prioritise the importance of their specific expertise — protection against known threats will always seem more critical than unknown ones.\nMy understanding of security was shaped by reading Security Engineering by Ross Anderson. From this book, I took the idea that safety and security combine to protect against the effects of events arising from error, mischance, and malicious action. Safety and security might be the same concept and share the same word in some languages. However, when a distinction is made, it is apparent that error and mischance are addressed by well-established processes in safety, leaving malice, or the protection against the effects of malicious action, as the domain of security.\nProtecting against malice is incredibly complex. It requires defending against adversaries intending to cause harm and with the cognitive ability to develop or obtain the necessary resources and information to achieve it. The challenge is ongoing as adversaries develop additional capabilities, refine their tactics, techniques, and procedures, gather data to target any possible vulnerability and learn from successive attempts or attacks against similar targets, allowing them to reorient their approach. In the field of cyber security, this challenge is even more apparent due to the instantaneous nature of cyber capabilities, which can be weaponised with just a few lines of code and proliferate rapidly. Unlike the production and use of automatic weapons, which took several decades to spread from military to organised crime, cyber-capable adversaries can almost instantaneously copy and distribute information on vulnerabilities or tools to enable their exploitation.\nThese factors make applying a threat-centric approach, where it is assumed you have a fully comprehensive understanding of the threat capabilities, increasingly more challenging to achieve if possible. But what do we control? The business functions and the organisational systems that perform them. We can engineer reliability and defence in depth, taking a multidisciplinary approach to anticipate the consequences of compromise before discovering any threat capability.\nSecurity, particularly information and computer security, should be seen through the lens of the degree of trust one maintains in the dependability of a function to continue to be performed correctly despite a malicious act against any system supporting its performance. This is not a random failure in safety; adversaries will constantly attempt new attacks to achieve their intentions and seek to subvert the targeted function by intelligently triggering the worst impacts at the most vulnerable moments. The only reasonable response is to orient security as a state, representing an objective that allows the specification of an engineering effort to achieve it.\nThe degree of trust that given systems will continue to provide a desired function despite a malicious act.\nIf security protects systems and preserves functions, responsible engineers and business processes, owners must also be involved. To achieve this approach, we must identify an organisation or facility’s critical functions and the systems delivering them, then collaborate across disciplines to assess the possible means and consequences of compromise. We must perform this analysis thoroughly and across disciplines and recognise that much of this information will not exist within any system design. If that is not the case, we will unknowingly implement a lesser security state. Each represented discipline will offer a unique perspective that contributes to a comprehensive understanding of the potential impacts, allowing for effective and targeted protective measures and approaches to detection and response to be implemented, delivering genuine risk reduction rather than just a simulation of it.\nDemonstrating absolute or probabilistic protection against malicious acts might not be possible, but reducing the consequences of compromise, and implementing defence in depth to facilitate detection, response, and mitigation of consequences before they can be realised, is within our control. Employing this function-centric multidisciplinary approach is the best approach to maintaining a state of security that is adaptable into the future.\n","date_published":"2023-03-08T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/rethinking-security-function-based-protection-against-malice/","image":"https://blog.mitcdh.au/images/rethinking-security-function-based-protection-against-malice.webp","summary":"Protecting against malicious acts is complex. Does the focus need to move from threats to function-based protection against consequences?","tags":["Writing","Technology","Security","Nuclear"],"title":"Rethinking Security: Function-based Protection Against Malice","url":"https://blog.mitcdh.au/posts/rethinking-security-function-based-protection-against-malice/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eWorking for an international organisation, I\u0026rsquo;m constantly in a cycle of forward planning and trying to optimise global impact. There are a number of data sets that can help with this\u0026mdash;for example, all of the countries with certain types of infrastructure\u0026mdash;but they require a degree of piecing together.\u003c/p\u003e\n\u003cp\u003eSome of the problems I\u0026rsquo;ve faced:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThere is no central data repository and a possible resistance to producing one.\u003c/li\u003e\n\u003cli\u003eDifferent databases might use different formats, e.g., country names or ISO codes.\u003c/li\u003e\n\u003cli\u003eSometimes unstructured data is provided, which may reflect the contributor\u0026rsquo;s biases, e.g., alternate or unofficial country names.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis can make effective planning kind of hard. I want maps. I love maps. So why not build a map? I\u0026rsquo;ve created a small tool to do exactly that, which is available here: \u003ca href=\"https://mitcdh.github.io/cb2geochart/\"\u003ehttps://mitcdh.github.io/cb2geochart/\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://github.com/mitcdh/cb2geochart\"\u003ehttps://github.com/mitcdh/cb2geochart\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eLet\u0026rsquo;s run through how it\u0026rsquo;s built.\u003c/p\u003e\n\u003ch2 id=\"building-a-list-of-country-names\"\u003e\u003cstrong\u003eBuilding a List of Country Names\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eSo the first thing is we need to get over the hurdle of everyone using different forms of country names. I found a \u003ca href=\"https://en.wikipedia.org/wiki/List_of_alternative_country_names\"\u003every nice Wikipedia page\u003c/a\u003e listing everything in a single place, so I just needed to extract the information from it. Python to the rescue!\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/mitcdh/country-scraper\"\u003ehttps://github.com/mitcdh/country-scraper\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThe script retrieves the webpage content using an and parses it for any row that contains an ISO 3166-1 alpha-3 country code. This code is then used to look up detailed country information from \u003ca href=\"https://pypi.org/project/pycountry/\"\u003epycountry\u003c/a\u003e which is compiled together with the alternate country names from Wikipedia. It then employs case folding and Unicode Normalization Form Compatibility Decomposition to ensure consistency in the names before outputting it all in a JSON file, let\u0026rsquo;s call it \u003ccode\u003ecountries.json\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eAs an example:\u003c/p\u003e\n\n\u003cfigure class=\"code-block\" id=\"code-1\" data-code-block\u003e\n  \u003cfigcaption class=\"code-block__header\"\u003e\n    \u003cspan class=\"code-block__label\"\u003eJSON\u003c/span\u003e\n    \u003cspan class=\"code-block__actions\"\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-wrap aria-controls=\"code-1-body\" aria-pressed=\"false\" hidden\u003eWrap\u003c/button\u003e\n      \u003cbutton class=\"code-block__control\" type=\"button\" data-code-copy aria-label=\"Copy JSON to clipboard\" hidden\u003eCopy\u003c/button\u003e\n    \u003c/span\u003e\n  \u003c/figcaption\u003e\n  \u003cdiv class=\"code-block__body\" id=\"code-1-body\"\u003e\n    \u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" class=\"chroma\"\u003e\u003ccode class=\"language-json\" data-lang=\"json\"\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003e\u0026#34;name\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;Austria\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003e\u0026#34;alpha_2\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;AT\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003e\u0026#34;alpha_3\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;AUT\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003e\u0026#34;numeric\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"s2\"\u003e\u0026#34;040\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003e\u0026#34;iso_alternate\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"p\"\u003e[\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"s2\"\u003e\u0026#34;republic of austria\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"p\"\u003e],\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"nt\"\u003e\u0026#34;wikipedia_alternate\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e:\u003c/span\u003e \u003cspan class=\"p\"\u003e[\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"s2\"\u003e\u0026#34;republik o\\u0308sterreich\u0026#34;\u003c/span\u003e\u003cspan class=\"p\"\u003e,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e      \u003cspan class=\"s2\"\u003e\u0026#34;o\\u0308sterreich\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e    \u003cspan class=\"p\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan class=\"line\"\u003e\u003cspan class=\"cl\"\u003e  \u003cspan class=\"p\"\u003e}\u003c/span\u003e\u003cspan class=\"err\"\u003e,\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n  \u003c/div\u003e\n  \u003cspan class=\"screen-reader-text\" role=\"status\" aria-live=\"polite\" data-code-status\u003e\u003c/span\u003e\n\u003c/figure\u003e\n\u003ch1 id=\"making-maps\"\u003eMaking Maps\u003c/h1\u003e\n\u003cp\u003eGoogle has a very nice \u0026lsquo;\u003ca href=\"https://developers.google.com/chart/interactive/docs/gallery/geochart\"\u003egeochart\u003c/a\u003e\u0026rsquo; package, a component of Google Charts designed specifically for geographical data representation that accepts an ISO 3166-1 alpha-2 country code as input.\u003c/p\u003e\n\u003cp\u003eNow, we can look for alpha-2 country names using any of the country\u0026rsquo;s official names, alpha-2, alpha-3 code, or its alternate names from ISO or Wikipedia. This best-effort method ensures that the country data is accurately identified regardless of the input format, ensuring that as many entries as possible are plotted on the map.\u003c/p\u003e\n\u003cp\u003eNow, this sounds all boring and technical, but imagine having a magical map that comes to life with just a simple copy-paste. I\u0026rsquo;d previously become very intrigued with the workflow of \u003ca href=\"https://github.com/euangoddard/clipboard2markdown\"\u003eclipboard2markdown\u003c/a\u003e and thought it would be perfect to apply here as well. Picture yourself with a list of countries, trying to normalise their names from your own memory, tediously entering each one by one, removing duplicates, or playing with some obscure Excel addon. Does it sound painful? Now you just copy your list, and voilà \u0026ndash; you paste it into this special area on the webpage, and you get a map.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/harnessing-visualisation-maps_01.webp\" width=\"1920\" height=\"1200\" alt=\"cb2geochart interface\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003ecb2geochart interface\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis isn\u0026rsquo;t just about maps and countries; it\u0026rsquo;s about making things easier and more enjoyable. I built this for myself but wanted to share it, I have no idea who will use it. Whether you\u0026rsquo;re a teacher looking to bring lessons to life, a student on a quest for knowledge, or doing something fancy and professional with global markets (please verify the output, non-matches are logged to \u003ccode\u003econsole.log\u003c/code\u003e), I hope you find some use in it.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/harnessing-visualisation-maps_02.webp\" width=\"1920\" height=\"1200\" alt=\"Example of a generated map\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eExample of a generated map\u003c/em\u003e\u003c/p\u003e\n","content_text":"Working for an international organisation, I’m constantly in a cycle of forward planning and trying to optimise global impact. There are a number of data sets that can help with this—for example, all of the countries with certain types of infrastructure—but they require a degree of piecing together.\nSome of the problems I’ve faced:\nThere is no central data repository and a possible resistance to producing one. Different databases might use different formats, e.g., country names or ISO codes. Sometimes unstructured data is provided, which may reflect the contributor’s biases, e.g., alternate or unofficial country names. This can make effective planning kind of hard. I want maps. I love maps. So why not build a map? I’ve created a small tool to do exactly that, which is available here: https://mitcdh.github.io/cb2geochart/\nSource: https://github.com/mitcdh/cb2geochart\nLet’s run through how it’s built.\nBuilding a List of Country Names So the first thing is we need to get over the hurdle of everyone using different forms of country names. I found a very nice Wikipedia page listing everything in a single place, so I just needed to extract the information from it. Python to the rescue!\nhttps://github.com/mitcdh/country-scraper\nThe script retrieves the webpage content using an and parses it for any row that contains an ISO 3166-1 alpha-3 country code. This code is then used to look up detailed country information from pycountry which is compiled together with the alternate country names from Wikipedia. It then employs case folding and Unicode Normalization Form Compatibility Decomposition to ensure consistency in the names before outputting it all in a JSON file, let’s call it countries.json.\nAs an example:\nJSON Wrap Copy { \"name\": \"Austria\", \"alpha_2\": \"AT\", \"alpha_3\": \"AUT\", \"numeric\": \"040\", \"iso_alternate\": [ \"republic of austria\" ], \"wikipedia_alternate\": [ \"republik o\\u0308sterreich\", \"o\\u0308sterreich\" ] }, Making Maps Google has a very nice ‘geochart’ package, a component of Google Charts designed specifically for geographical data representation that accepts an ISO 3166-1 alpha-2 country code as input.\nNow, we can look for alpha-2 country names using any of the country’s official names, alpha-2, alpha-3 code, or its alternate names from ISO or Wikipedia. This best-effort method ensures that the country data is accurately identified regardless of the input format, ensuring that as many entries as possible are plotted on the map.\nNow, this sounds all boring and technical, but imagine having a magical map that comes to life with just a simple copy-paste. I’d previously become very intrigued with the workflow of clipboard2markdown and thought it would be perfect to apply here as well. Picture yourself with a list of countries, trying to normalise their names from your own memory, tediously entering each one by one, removing duplicates, or playing with some obscure Excel addon. Does it sound painful? Now you just copy your list, and voilà – you paste it into this special area on the webpage, and you get a map.\ncb2geochart interface\nThis isn’t just about maps and countries; it’s about making things easier and more enjoyable. I built this for myself but wanted to share it, I have no idea who will use it. Whether you’re a teacher looking to bring lessons to life, a student on a quest for knowledge, or doing something fancy and professional with global markets (please verify the output, non-matches are logged to console.log), I hope you find some use in it.\nExample of a generated map\n","date_published":"2023-02-17T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/harnessing-visualisation-maps/","image":"https://blog.mitcdh.au/images/harnessing-visualisation-maps.webp","summary":"Fun fact: my first work experience was with maps.","tags":["Writing","Technology","Code"],"title":"Harnessing Visualisation Because Maps","url":"https://blog.mitcdh.au/posts/harnessing-visualisation-maps/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003e🌨️ In lands where winter's touch grew cold,\u003cbr/\u003eAnd snowflakes danced, fierce and bold,\u003cbr/\u003eI dreamt of warmth, a tale untold,\u003cbr/\u003eA beach in Mexico, with sands like gold.\u003cbr/\u003e\u003cbr/\u003e🌊 Away from frost, from icy thrill,\u003cbr/\u003eTo warmer climes, my heart to fill,\u003cbr/\u003eWith waves that kissed the sunlit shore,\u003cbr/\u003eAnd winter's bite felt no more.\u003cbr/\u003e\u003cbr/\u003e🌞 Underneath the azure sky,\u003cbr/\u003eWhere seagulls soared and palms did sigh,\u003cbr/\u003eThe sun caressed my skin so bare,\u003cbr/\u003eIn that sweet escape from winter's snare.\u003cbr/\u003e\u003cbr/\u003e🌴 There, where time began to slow,\u003cbr/\u003eIn Mexico, with warm winds that blow,\u003cbr/\u003eI sipped on tequila, smooth and fine,\u003cbr/\u003eA liquid gold, like sunshine's line.\u003cbr/\u003e\u003cbr/\u003e🍹 It warmed me more than just in taste,\u003cbr/\u003eIn Mexico, no moment to waste,\u003cbr/\u003eWith every sip, I felt free,\u003cbr/\u003eFrom winter's grasp, I had my spree.\u003cbr/\u003e\u003cbr/\u003e🏖️ So let the cold its course pursue,\u003cbr/\u003eFor there I found a world anew,\u003cbr/\u003eWhere warmth and laughter freely flowed,\u003cbr/\u003eIn my winter escape to Mexico.\u003cbr/\u003e\n","content_text":"🌨️ In lands where winter's touch grew cold,And snowflakes danced, fierce and bold,I dreamt of warmth, a tale untold,A beach in Mexico, with sands like gold.🌊 Away from frost, from icy thrill,To warmer climes, my heart to fill,With waves that kissed the sunlit shore,And winter's bite felt no more.🌞 Underneath the azure sky,Where seagulls soared and palms did sigh,The sun caressed my skin so bare,In that sweet escape from winter's snare.🌴 There, where time began to slow,In Mexico, with warm winds that blow,I sipped on tequila, smooth and fine,A liquid gold, like sunshine's line.🍹 It warmed me more than just in taste,In Mexico, no moment to waste,With every sip, I felt free,From winter's grasp, I had my spree.🏖️ So let the cold its course pursue,For there I found a world anew,Where warmth and laughter freely flowed,In my winter escape to Mexico. ","date_published":"2023-02-04T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/once-upon-a-winter-escape-to-mexico/","image":"https://blog.mitcdh.au/images/once-upon-a-winter-escape-to-mexico_01.webp","summary":"Wherein I post pictures of warmer climates.","tags":["Writing","Poetry","Travel"],"title":"Once Upon a Winter Escape to Mexico","url":"https://blog.mitcdh.au/posts/once-upon-a-winter-escape-to-mexico/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-01-26T18:45:29Z","id":"https://blog.mitcdh.au/posts/the-food-and-sea-of-oaxaca-mexico/","image":"https://blog.mitcdh.au/images/the-food-and-sea-of-oaxaca-mexico.jpg","summary":"Worth it.","tags":["Album"],"title":"The Food and Sea of Oaxaca, Mexico","url":"https://blog.mitcdh.au/posts/the-food-and-sea-of-oaxaca-mexico/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2023-01-15T11:40:56Z","id":"https://blog.mitcdh.au/posts/weekend-romance-in-paris-france/","image":"https://blog.mitcdh.au/images/weekend-romance-in-paris-france.jpg","summary":"C'était la première fois que je voyais la tour Eifel ; elle ne m'a plus jamais regardé de la même façon.","tags":["Album"],"title":"Weekend Romance in Paris, France","url":"https://blog.mitcdh.au/posts/weekend-romance-in-paris-france/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-12-27T12:27:15Z","id":"https://blog.mitcdh.au/posts/a-warmer-christmas-in-pavia-italy/","image":"https://blog.mitcdh.au/images/a-warmer-christmas-in-pavia-italy.jpg","summary":"When the snow's not around it's time to hit the streets; see the town.","tags":["Album"],"title":"A Warmer Christmas in Pavia, Italy","url":"https://blog.mitcdh.au/posts/a-warmer-christmas-in-pavia-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-12-12T21:13:08Z","id":"https://blog.mitcdh.au/posts/stuck-in-london-united-kingdom/","image":"https://blog.mitcdh.au/images/stuck-in-london-united-kingdom.jpg","summary":"Nice try BA but you didn't realise this time I had a friend in town ✨","tags":["Album"],"title":"Stuck in London, United Kingdom","url":"https://blog.mitcdh.au/posts/stuck-in-london-united-kingdom/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-12-09T14:24:22Z","id":"https://blog.mitcdh.au/posts/washington-state-united-states/","image":"https://blog.mitcdh.au/images/washington-state-united-states.jpg","summary":"Everyone has a first time on a sled. This was mine.","tags":["Album"],"title":"Washington State, United States","url":"https://blog.mitcdh.au/posts/washington-state-united-states/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eOn a flight from Vienna to London, we struck up a conversation that changed the course of our journeys, particularly when we knew both our connecting flights were delayed. As the plane soared above the clouds, we shared stories of our travels and dreams, forming an instant connection. Little did we know that this chance encounter would leave a mark on our lives.\u003c/p\u003e\n\u003cp\u003eMonths later, in the heart of Seattle, we reunited under the city\u0026rsquo;s grey skies. The months apart had only strengthened our bond, and it felt like no time had passed. We explored the city\u0026rsquo;s coffee shops, braved the drizzling rain, and laughed as if we had known each other for a lifetime, all in a one-day stopover.\u003c/p\u003e\n\u003cp\u003eOur brief encounter on that flight had blossomed into a lasting friendship, a testament to the magic of unexpected connections. Those memories would forever remind us of the incredible life journeys we had embarked on and the beautiful friendships that could be found along the way 🥂😍\u003c/p\u003e\n","content_text":"On a flight from Vienna to London, we struck up a conversation that changed the course of our journeys, particularly when we knew both our connecting flights were delayed. As the plane soared above the clouds, we shared stories of our travels and dreams, forming an instant connection. Little did we know that this chance encounter would leave a mark on our lives.\nMonths later, in the heart of Seattle, we reunited under the city’s grey skies. The months apart had only strengthened our bond, and it felt like no time had passed. We explored the city’s coffee shops, braved the drizzling rain, and laughed as if we had known each other for a lifetime, all in a one-day stopover.\nOur brief encounter on that flight had blossomed into a lasting friendship, a testament to the magic of unexpected connections. Those memories would forever remind us of the incredible life journeys we had embarked on and the beautiful friendships that could be found along the way 🥂😍\n","date_published":"2022-12-05T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/friendships-take-flight/","image":"https://blog.mitcdh.au/images/friendships-take-flight_01.webp","summary":"Wherein I found friendship mid-journey.","tags":["Writing","Musings","Travel","Friends"],"title":"Friendships Take Flight","url":"https://blog.mitcdh.au/posts/friendships-take-flight/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003eIn autumn's embrace, hues unseen, 🍂 unfold,\u003cbr/\u003eFrom Australia's sun 🇦🇺 to Austria's cold 🇦🇹.\u003cbr/\u003eEach leaf, a brushstroke of nature's own awe 🤩,\u003cbr/\u003eCrafting a tapestry without a flaw.\u003cbr/\u003e\u003cbr/\u003eFour years have passed, yet still my heart is smitten,\u003cbr/\u003eBy colors that dance, by the seasons written.\u003cbr/\u003eIn every leaf, 🍁 a story fresh and new,\u003cbr/\u003eAutumn's magic, in every vibrant hue. 🎨\u003cbr/\u003e\n","content_text":"In autumn's embrace, hues unseen, 🍂 unfold,From Australia's sun 🇦🇺 to Austria's cold 🇦🇹.Each leaf, a brushstroke of nature's own awe 🤩,Crafting a tapestry without a flaw.Four years have passed, yet still my heart is smitten,By colors that dance, by the seasons written.In every leaf, 🍁 a story fresh and new,Autumn's magic, in every vibrant hue. 🎨 ","date_published":"2022-10-26T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/autumn-hues-from-australia-to-austria/","image":"https://blog.mitcdh.au/images/autumn-hues-from-australia-to-austria_01.webp","summary":"Wherein I celebrate seasons.","tags":["Writing","Poetry"],"title":"Autumn Hues from Australia to Austria","url":"https://blog.mitcdh.au/posts/autumn-hues-from-australia-to-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-10-17T13:45:26Z","id":"https://blog.mitcdh.au/posts/autumn-in-vienna-austria/","image":"https://blog.mitcdh.au/images/autumn-in-vienna-austria.jpg","summary":"Coming from Australia, I never knew there were so many colours.","tags":["Album"],"title":"Autumn in Vienna, Austria","url":"https://blog.mitcdh.au/posts/autumn-in-vienna-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003e🌟 In Daejeon's charm, I found my way,\u003cbr/\u003eThrough years of one-week work trips, come what may.\u003cbr/\u003eLike a river's gentle flow, we intertwined,\u003cbr/\u003eFriendship blossomed, hearts and souls aligned.\u003cbr/\u003e\u003cbr/\u003e🎤 At karaoke nights, we sang our hearts out loud,\u003cbr/\u003eIn Daejeon's neon lights, a joyous crowd.\u003cbr/\u003eLike Blackpink's fierce spirit, we rocked the stage,\u003cbr/\u003eOur friendship grew stronger with every song's page.\u003cbr/\u003e\u003cbr/\u003e☢️ Amidst discussions of nuclear security's place,\u003cbr/\u003eWe found common ground in that high-stakes space.\u003cbr/\u003eLike the secrets held within a fortified chest,\u003cbr/\u003eOur trust and friendships, were put to the test.\u003cbr/\u003e\u003cbr/\u003e🌞 Seasons passed, and our bonds grew solid and true,\u003cbr/\u003eLike the sun that shines on mornings anew.\u003cbr/\u003eThrough the ups and downs, we weathered it all,\u003cbr/\u003eLike the river carving paths, we'd never fall.\u003cbr/\u003e\u003cbr/\u003e🌏 Though miles apart, our friendship endures,\u003cbr/\u003eLike the river's journey, forever matures.\u003cbr/\u003eFrom one-week work trips to a lifelong embrace,\u003cbr/\u003eDaejeon's gift of friends, time cannot erase.\u003cbr/\u003e\n","content_text":"🌟 In Daejeon's charm, I found my way,Through years of one-week work trips, come what may.Like a river's gentle flow, we intertwined,Friendship blossomed, hearts and souls aligned.🎤 At karaoke nights, we sang our hearts out loud,In Daejeon's neon lights, a joyous crowd.Like Blackpink's fierce spirit, we rocked the stage,Our friendship grew stronger with every song's page.☢️ Amidst discussions of nuclear security's place,We found common ground in that high-stakes space.Like the secrets held within a fortified chest,Our trust and friendships, were put to the test.🌞 Seasons passed, and our bonds grew solid and true,Like the sun that shines on mornings anew.Through the ups and downs, we weathered it all,Like the river carving paths, we'd never fall.🌏 Though miles apart, our friendship endures,Like the river's journey, forever matures.From one-week work trips to a lifelong embrace,Daejeon's gift of friends, time cannot erase. ","date_published":"2022-10-11T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/echoes-of-daejeon/","image":"https://blog.mitcdh.au/images/echoes-of-daejeon_01.webp","summary":"Wherein I cherish connections made.","tags":["Writing","Travel","Poetry","Friends"],"title":"Echoes of Daejeon: Bonds of Work and Song","url":"https://blog.mitcdh.au/posts/echoes-of-daejeon/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-10-02T11:53:52Z","id":"https://blog.mitcdh.au/posts/wandering-daejeon-south-korea/","image":"https://blog.mitcdh.au/images/wandering-daejeon-south-korea.jpg","summary":"Explorations while running a training course.","tags":["Album"],"title":"Wandering Daejeon, South Korea","url":"https://blog.mitcdh.au/posts/wandering-daejeon-south-korea/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-05-31T21:36:21Z","id":"https://blog.mitcdh.au/posts/tm-in-berlin-germany/","image":"https://blog.mitcdh.au/images/tm-in-berlin-germany.jpg","summary":"","tags":["Album"],"title":"TM in Berlin, Germany","url":"https://blog.mitcdh.au/posts/tm-in-berlin-germany/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-05-20T13:01:21Z","id":"https://blog.mitcdh.au/posts/weekend-in-valencia-spain/","image":"https://blog.mitcdh.au/images/weekend-in-valencia-spain.jpg","summary":"Came for the Paella. Stayed for the new friends.","tags":["Album"],"title":"Weekend in Valencia, Spain","url":"https://blog.mitcdh.au/posts/weekend-in-valencia-spain/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-05-17T22:51:14Z","id":"https://blog.mitcdh.au/posts/seeing-the-vasa-sweden/","image":"https://blog.mitcdh.au/images/seeing-the-vasa-sweden.jpg","summary":"Not the craziest place I've had a candlelit dinner.","tags":["Album"],"title":"Seeing the Vasa, Sweden","url":"https://blog.mitcdh.au/posts/seeing-the-vasa-sweden/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-05-07T13:08:21Z","id":"https://blog.mitcdh.au/posts/big-ben-in-london-united-kingdom/","image":"https://blog.mitcdh.au/images/big-ben-in-london-united-kingdom.jpg","summary":"I've seen bigger.","tags":["Album"],"title":"Big Ben in London, United Kingdom","url":"https://blog.mitcdh.au/posts/big-ben-in-london-united-kingdom/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-05-04T09:03:11Z","id":"https://blog.mitcdh.au/posts/seasides-of-cote-dazur/","image":"https://blog.mitcdh.au/images/seasides-of-cote-dazur.jpg","summary":"It was Nice!","tags":["Album"],"title":"Seasides of Côte d'Azur","url":"https://blog.mitcdh.au/posts/seasides-of-cote-dazur/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003e🌊 In lands where azure waves kiss golden stones,\u003cbr/\u003eWhere sun-drenched shores whisper tales untold,\u003cbr/\u003eI wander, heart in hand, through these grand strands,\u003cbr/\u003eOn coastal paths, where stories unfold.\u003cbr/\u003e\u003cbr/\u003e☀️ The sun, a fiery orb, sets seas aflame,\u003cbr/\u003eIts light cascading over waters clear.\u003cbr/\u003eI walk by coasts, each day anew, the same,\u003cbr/\u003eIn awe of vistas, so precious, so dear.\u003cbr/\u003e\u003cbr/\u003e🏞️ Off beaten tracks, where tourists rarely tread,\u003cbr/\u003eI find the essence of this coast's allure.\u003cbr/\u003eThe tranquil bays, the rocky cliffs widespread,\u003cbr/\u003eA symphony of sights, profoundly pure.\u003cbr/\u003e\u003cbr/\u003e🚶‍♂️So when the choice is mine, and roads diverge,\u003cbr/\u003eI'll always seek the path by ocean's side.\u003cbr/\u003eFor there, in nature's grand, unending surge,\u003cbr/\u003eI find my peace, in azure tides abide.\u003cbr/\u003e\n","content_text":"🌊 In lands where azure waves kiss golden stones,Where sun-drenched shores whisper tales untold,I wander, heart in hand, through these grand strands,On coastal paths, where stories unfold.☀️ The sun, a fiery orb, sets seas aflame,Its light cascading over waters clear.I walk by coasts, each day anew, the same,In awe of vistas, so precious, so dear.🏞️ Off beaten tracks, where tourists rarely tread,I find the essence of this coast's allure.The tranquil bays, the rocky cliffs widespread,A symphony of sights, profoundly pure.🚶‍♂️So when the choice is mine, and roads diverge,I'll always seek the path by ocean's side.For there, in nature's grand, unending surge,I find my peace, in azure tides abide. ","date_published":"2022-05-03T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/always-take-the-coastal-path/","image":"https://blog.mitcdh.au/images/always-take-the-coastal-path_01.webp","summary":"Wherein I choose the scenic route.","tags":["Writing","Travel","Poetry","Philosophy"],"title":"Always Take the Coastal Path","url":"https://blog.mitcdh.au/posts/always-take-the-coastal-path/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-04-08T19:52:47Z","id":"https://blog.mitcdh.au/posts/lockdown-in-seoul-south-korea/","image":"https://blog.mitcdh.au/images/lockdown-in-seoul-south-korea.jpg","summary":"Cherry Blossom season in the height of the Korean Covid pandemic. Yes, I got it.","tags":["Album"],"title":"Lockdown in Seoul, South Korea","url":"https://blog.mitcdh.au/posts/lockdown-in-seoul-south-korea/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2022-01-25T08:47:59Z","id":"https://blog.mitcdh.au/posts/homebound-in-sydney-australia/","image":"https://blog.mitcdh.au/images/homebound-in-sydney-australia.jpg","summary":"Short trip home. But someday we'll all be together once more.","tags":["Album"],"title":"Homebound in Sydney, Australia","url":"https://blog.mitcdh.au/posts/homebound-in-sydney-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e💭 What is nostalgia? Some of my best memories of family and friends, ones I can never recreate, were made at these three beaches 🏄‍♂️\u003c/p\u003e\n\u003cp\u003eThese Days 🎶 I have found myself living on the other side of the world in a landlocked country with no beaches or kangaroos 🇦🇹 When I feel the pressures of life, I think back to these moments.\u003c/p\u003e\n\u003cp\u003eNow, for the first time in years, I relive this— to breathe that same sea breeze, feel my feet sink into the sand as the wave returns, and taste the salt. That makes me think 🤔\u003c/p\u003e\n\u003cp\u003eI realise they are just that, memories of times and people past. I won\u0026rsquo;t forget them, but I won\u0026rsquo;t let them hold me back 💪 when that wave washes over you, all the stresses of life, mortgages, work, and relationships wash away, and now I find that worries of never surpassing these memories do, too 😊\u003c/p\u003e\n\u003cp\u003eSo here\u0026rsquo;s to the new friends and family who today run into the waves with me or the ones I will share these pictures with back in my new home, hoping that one day they can join me here too 🥂\u003c/p\u003e\n","content_text":"💭 What is nostalgia? Some of my best memories of family and friends, ones I can never recreate, were made at these three beaches 🏄‍♂️\nThese Days 🎶 I have found myself living on the other side of the world in a landlocked country with no beaches or kangaroos 🇦🇹 When I feel the pressures of life, I think back to these moments.\nNow, for the first time in years, I relive this— to breathe that same sea breeze, feel my feet sink into the sand as the wave returns, and taste the salt. That makes me think 🤔\nI realise they are just that, memories of times and people past. I won’t forget them, but I won’t let them hold me back 💪 when that wave washes over you, all the stresses of life, mortgages, work, and relationships wash away, and now I find that worries of never surpassing these memories do, too 😊\nSo here’s to the new friends and family who today run into the waves with me or the ones I will share these pictures with back in my new home, hoping that one day they can join me here too 🥂\n","date_published":"2022-01-17T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/nostalgia-beach/","image":"https://blog.mitcdh.au/images/nostalgia-beach_01.webp","summary":"Wherein I go to the beach, now far from home.","tags":["Writing","Musings","Travel"],"title":"Nostalgia, Beaches, and Embracing the Present","url":"https://blog.mitcdh.au/posts/nostalgia-beach/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2021-09-04T19:06:17Z","id":"https://blog.mitcdh.au/posts/the-canals-of-venice-italy/","image":"https://blog.mitcdh.au/images/the-canals-of-venice-italy.jpg","summary":"I don't know what you're complaining about. It really didn't smell that bad.","tags":["Album"],"title":"The Canals of Venice, Italy","url":"https://blog.mitcdh.au/posts/the-canals-of-venice-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2021-07-22T20:54:27Z","id":"https://blog.mitcdh.au/posts/csir-in-bucharest-romania/","image":"https://blog.mitcdh.au/images/csir-in-bucharest-romania.jpg","summary":"","tags":["Album"],"title":"CSIR in Bucharest, Romania","url":"https://blog.mitcdh.au/posts/csir-in-bucharest-romania/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003eGolden coast fades away,\u003cbr/\u003eSurfboard rests, day's echoes cease,\u003cbr/\u003eNext wave calls, \"Don't delay.\"\u003cbr/\u003e\u003cbr/\u003eMaps unfold under stars,\u003cbr/\u003eDistant shores in mind's eye,\u003cbr/\u003eNew tides near, yet so far.\u003cbr/\u003e\u003cbr/\u003eDawn whispers of new seas,\u003cbr/\u003eHeart surges with wanderlust,\u003cbr/\u003eNext journey, on the breeze.\u003cbr/\u003e🏄🏻\u003cbr/\u003e\n","content_text":"Golden coast fades away,Surfboard rests, day's echoes cease,Next wave calls, \"Don't delay.\"Maps unfold under stars,Distant shores in mind's eye,New tides near, yet so far.Dawn whispers of new seas,Heart surges with wanderlust,Next journey, on the breeze.🏄🏻 ","date_published":"2021-07-11T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/surfers-journey-to-distant-shores/","image":"https://blog.mitcdh.au/images/surfers-journey-to-distant-shores_01.webp","summary":"Wherein I see the sea for the first time in years.","tags":["Writing","Poetry","Travel"],"title":"Surfer's Journey to Distant Shores","url":"https://blog.mitcdh.au/posts/surfers-journey-to-distant-shores/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2021-07-07T20:40:49Z","id":"https://blog.mitcdh.au/posts/surf-trip-portugal/","image":"https://blog.mitcdh.au/images/surf-trip-portugal.jpg","summary":"Back to the sea, where my soul finds its melody, in the endless dance of waves where I have so longed to be.","tags":["Album"],"title":"Surf Trip, Portugal","url":"https://blog.mitcdh.au/posts/surf-trip-portugal/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eThere\u0026rsquo;s a special allure in riding at the front of the boat, where the world seems to open up with endless possibilities. Here, the salty breeze is a gentle whisper and a vibrant, living force. It rushes towards me, carrying the essence of the sea, a symphony of brine and freedom.\u003c/p\u003e\n\u003cp\u003eAs the boat slices through the waves, the wind greets me first, unfiltered and exhilarating. It\u0026rsquo;s a place of privilege where the ocean spray kisses my face, and the horizon stretches infinitely. Each journey becomes a personal dialogue with the elements, where the sea\u0026rsquo;s breath becomes my guide.\u003c/p\u003e\n\u003cp\u003eThe front of the boat is not just a physical space; it\u0026rsquo;s a sanctuary where I can immerse myself in the raw beauty of nature, feeling the pulse of the ocean and the rhythm of the wind as they converge in a dance of untamed splendour.\u003c/p\u003e\n\u003cdiv class=\"gallery-box\"\u003e\n  \u003cdiv class=\"gallery\"\u003e\n    \u003cimg src=\"/images/a-journey-with-the-sea_01.webp\" width=\"3000\" height=\"3000\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_02.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_03.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_04.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_05.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_06.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_07.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_08.webp\" width=\"1200\" height=\"1200\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/a-journey-with-the-sea_09.webp\" width=\"1126\" height=\"1126\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n  \u003c/div\u003e\n\u003c/div\u003e","content_text":"There’s a special allure in riding at the front of the boat, where the world seems to open up with endless possibilities. Here, the salty breeze is a gentle whisper and a vibrant, living force. It rushes towards me, carrying the essence of the sea, a symphony of brine and freedom.\nAs the boat slices through the waves, the wind greets me first, unfiltered and exhilarating. It’s a place of privilege where the ocean spray kisses my face, and the horizon stretches infinitely. Each journey becomes a personal dialogue with the elements, where the sea’s breath becomes my guide.\nThe front of the boat is not just a physical space; it’s a sanctuary where I can immerse myself in the raw beauty of nature, feeling the pulse of the ocean and the rhythm of the wind as they converge in a dance of untamed splendour.\n","date_published":"2021-06-30T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/a-journey-with-the-sea/","image":"https://blog.mitcdh.au/images/a-journey-with-the-sea_01.webp","summary":"Wherein I connect with the ocean.","tags":["Writing","Travel","Musings"],"title":"A Journey with the Sea","url":"https://blog.mitcdh.au/posts/a-journey-with-the-sea/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2021-06-25T20:41:59Z","id":"https://blog.mitcdh.au/posts/sailing-greece-and-turkey/","image":"https://blog.mitcdh.au/images/sailing-greece-and-turkey.jpg","summary":"I'm on a boat.","tags":["Album"],"title":"Sailing, Greece and Turkey","url":"https://blog.mitcdh.au/posts/sailing-greece-and-turkey/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2021-06-15T08:44:24Z","id":"https://blog.mitcdh.au/posts/lake-relaxation-in-carinthia-austria/","image":"https://blog.mitcdh.au/images/lake-relaxation-in-carinthia-austria.jpg","summary":"Vergiß, vergiß und laß uns jetzt nur dies erleben, wie die Sterne durch geklärten Nachthimmel dringe.","tags":["Album"],"title":"Lake Relaxation in Carinthia, Austria","url":"https://blog.mitcdh.au/posts/lake-relaxation-in-carinthia-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2020-12-28T15:29:28Z","id":"https://blog.mitcdh.au/posts/snowy-christmas-in-pavia-italy/","image":"https://blog.mitcdh.au/images/snowy-christmas-in-pavia-italy.jpg","summary":"Cappelli e sciarpe sono la novità del mio primo Natale invernale.","tags":["Album"],"title":"Snowy Christmas in Pavia, Italy","url":"https://blog.mitcdh.au/posts/snowy-christmas-in-pavia-italy/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2020-12-28T15:29:28Z","id":"https://blog.mitcdh.au/posts/road-trip-through-croatia-slovenia-and-bosnia-herzegovina/","image":"https://blog.mitcdh.au/images/road-trip-through-croatia-slovenia-and-bosnia-herzegovina.jpg","summary":"I'll never reveal who makes my favourite burek.","tags":["Album"],"title":"Road Trip through Croatia, Slovenia, and Bosnia-Herzegovina","url":"https://blog.mitcdh.au/posts/road-trip-through-croatia-slovenia-and-bosnia-herzegovina/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eIn Italy, amidst the rolling hills and vibrant streets, I discovered something unexpected and profoundly touching—people who embraced me like family. Growing up, because of everyone going in different directions after a shared traumatic experience, I often felt a sense of distance from my own family, a subtle but persistent disconnect that left a void in my heart.\u003c/p\u003e\n\u003cp\u003eBut in Italy, that void began to heal. The people I met there, with their open arms and generous hearts, showed me what it felt like to be part of a family. From shared meals under the stars on a boat, where laughter and stories flowed as freely as the local wine, to quiet moments of understanding and companionship between the early morning rises at Christmas, they filled my days with a sense of belonging. Each gesture, whether a comforting word in times of need or a shared joke, wove a tapestry of familial love that transcended blood ties.\u003c/p\u003e\n\u003cp\u003eThis experience in Italy taught me that family isn\u0026rsquo;t just about the bonds we\u0026rsquo;re born into; it\u0026rsquo;s about the connections we forge through love, understanding, and shared humanity. It was a poignant reminder that sometimes, family is not absolute; it can be found in the most unexpected places, among people who start as strangers but soon become an integral part of our lives.\u003c/p\u003e\n\u003cdiv class=\"gallery-box\"\u003e\n  \u003cdiv class=\"gallery\"\u003e\n    \u003cimg src=\"/images/finding-family-in-italia_01.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_02.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_03.webp\" width=\"1080\" height=\"1080\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_04.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_05.webp\" width=\"1080\" height=\"1080\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_06.webp\" width=\"1440\" height=\"1440\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_07.webp\" width=\"2252\" height=\"2252\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_08.webp\" width=\"2252\" height=\"2252\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/finding-family-in-italia_09.webp\" width=\"2252\" height=\"2252\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n  \u003c/div\u003e\n\u003c/div\u003e","content_text":"In Italy, amidst the rolling hills and vibrant streets, I discovered something unexpected and profoundly touching—people who embraced me like family. Growing up, because of everyone going in different directions after a shared traumatic experience, I often felt a sense of distance from my own family, a subtle but persistent disconnect that left a void in my heart.\nBut in Italy, that void began to heal. The people I met there, with their open arms and generous hearts, showed me what it felt like to be part of a family. From shared meals under the stars on a boat, where laughter and stories flowed as freely as the local wine, to quiet moments of understanding and companionship between the early morning rises at Christmas, they filled my days with a sense of belonging. Each gesture, whether a comforting word in times of need or a shared joke, wove a tapestry of familial love that transcended blood ties.\nThis experience in Italy taught me that family isn’t just about the bonds we’re born into; it’s about the connections we forge through love, understanding, and shared humanity. It was a poignant reminder that sometimes, family is not absolute; it can be found in the most unexpected places, among people who start as strangers but soon become an integral part of our lives.\n","date_published":"2020-12-28T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/finding-family-in-italia/","image":"https://blog.mitcdh.au/images/finding-family-in-italia_01.webp","summary":"Wherein I reflect on what family is.","tags":["Writing","Musings","Friends"],"title":"Finding Family in Italia","url":"https://blog.mitcdh.au/posts/finding-family-in-italia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003eI embarked on the ascent, my hands gripping the cold metal of the klettersteig, each step a testament to the delicate balance between trust and skill. The route wound up the rugged cliffs of the Salzkammergut, revealing vistas of serene lakes nestled like hidden treasures in the valley below. With every meter I climbed, the landscape unfurled its grandeur – rugged peaks crowned with snow, lush forests in myriad shades of green, and the distant twinkle of quaint villages.\u003c/p\u003e\n\u003cp\u003eWhat I hadn’t realised was this journey on the klettersteig was more than a physical test; it was a mental odyssey, a venture into the depths of my own courage. Trusting the cable that tethered me to the mountain was a leap of faith, especially as the path narrowed and the ground fell away. Suspended over the abyss, the world beyond seemed to vanish, leaving just the mountain and us in a silent pact, bound by the strength of steel and the resolve within.\u003c/p\u003e\n","content_text":"I embarked on the ascent, my hands gripping the cold metal of the klettersteig, each step a testament to the delicate balance between trust and skill. The route wound up the rugged cliffs of the Salzkammergut, revealing vistas of serene lakes nestled like hidden treasures in the valley below. With every meter I climbed, the landscape unfurled its grandeur – rugged peaks crowned with snow, lush forests in myriad shades of green, and the distant twinkle of quaint villages.\nWhat I hadn’t realised was this journey on the klettersteig was more than a physical test; it was a mental odyssey, a venture into the depths of my own courage. Trusting the cable that tethered me to the mountain was a leap of faith, especially as the path narrowed and the ground fell away. Suspended over the abyss, the world beyond seemed to vanish, leaving just the mountain and us in a silent pact, bound by the strength of steel and the resolve within.\n","date_published":"2020-08-08T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/scaling-heights-on-a-klettersteig/","image":"https://blog.mitcdh.au/images/scaling-heights-on-a-klettersteig_01.webp","summary":"Wherein I test my trust and push my limits in nature.","tags":["Writing","Musings","Travel"],"title":"Scaling Heights on a Klettersteig Journey","url":"https://blog.mitcdh.au/posts/scaling-heights-on-a-klettersteig/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2020-08-02T12:30:13Z","id":"https://blog.mitcdh.au/posts/klettersteig-in-salzkammergut-austria/","image":"https://blog.mitcdh.au/images/klettersteig-in-salzkammergut-austria.jpg","summary":"No one is more surprised than me that I didn't fall and die.","tags":["Album"],"title":"Klettersteig in Salzkammergut, Austria","url":"https://blog.mitcdh.au/posts/klettersteig-in-salzkammergut-austria/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2020-04-04T18:02:32Z","id":"https://blog.mitcdh.au/posts/covid-stuck-in-sydney-australia/","image":"https://blog.mitcdh.au/images/covid-stuck-in-sydney-australia.jpg","summary":"Home is where the beach is. Especially when they decide you can't leave because of a global pandemic.","tags":["Album"],"title":"Covid Stuck in Sydney, Australia","url":"https://blog.mitcdh.au/posts/covid-stuck-in-sydney-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003eIn Europe's lands, I wander wide,\u003cbr/\u003eThrough ancient streets and countryside.\u003cbr/\u003eYet in my heart, I cannot hide,\u003cbr/\u003eThe longing for Australian tides.\u003cbr/\u003e\u003cbr/\u003eEurope's cities, grand and old,\u003cbr/\u003eTheir tales of history, for long told.\u003cbr/\u003eYet none can stir my heart bold,\u003cbr/\u003eLike Southern stars, when nights unfold.\u003cbr/\u003e\u003cbr/\u003eSo here's my truth, as I roam,\u003cbr/\u003eNo matter where I call my own,\u003cbr/\u003eIn Europe's charm, I wander alone,\u003cbr/\u003e'Cause It's Australia I still call home.\u003cbr/\u003e\n","content_text":"In Europe's lands, I wander wide,Through ancient streets and countryside.Yet in my heart, I cannot hide,The longing for Australian tides.Europe's cities, grand and old,Their tales of history, for long told.Yet none can stir my heart bold,Like Southern stars, when nights unfold.So here's my truth, as I roam,No matter where I call my own,In Europe's charm, I wander alone,'Cause It's Australia I still call home. ","date_published":"2020-03-15T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/australian-at-home/","image":"https://blog.mitcdh.au/images/australian-at-home_01.webp","summary":"Wherein I return from Europe for a visit.","tags":["Writing","Travel","Poetry"],"title":"Australian at Home","url":"https://blog.mitcdh.au/posts/australian-at-home/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003eVienna's clock strikes night,\u003cbr/\u003eUnder the New Year's light,\u003cbr/\u003eWaltz begins, sheer delight.\u003cbr/\u003e\u003cbr/\u003eIn the rhythm of the chime,\u003cbr/\u003eCouples dance, in time sublime,\u003cbr/\u003eMidnight's waltz, a rhyme.\u003cbr/\u003e\u003cbr/\u003eCity swirls in dance and cheer,\u003cbr/\u003eWelcoming the fresh New Year,\u003cbr/\u003eIn waltz, all sorrows disappear.\u003cbr/\u003e\n\u003cdiv class=\"gallery-box\"\u003e\n  \u003cdiv class=\"gallery\"\u003e\n    \u003cimg src=\"/images/waltzing-into-viennas-new-year_02.webp\" width=\"1080\" height=\"1080\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/waltzing-into-viennas-new-year_03.webp\" width=\"1080\" height=\"1080\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/waltzing-into-viennas-new-year_04.webp\" width=\"1080\" height=\"1080\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n  \u003c/div\u003e\n\u003c/div\u003e","content_text":"Vienna's clock strikes night,Under the New Year's light,Waltz begins, sheer delight.In the rhythm of the chime,Couples dance, in time sublime,Midnight's waltz, a rhyme.City swirls in dance and cheer,Welcoming the fresh New Year,In waltz, all sorrows disappear. ","date_published":"2020-01-01T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/waltzing-into-viennas-new-year/","image":"https://blog.mitcdh.au/images/waltzing-into-viennas-new-year_01.webp","summary":"Wherein I embrace bitter endings and joyous beginnings.","tags":["Writing","Poetry"],"title":"Waltzing Into Vienna's New Year","url":"https://blog.mitcdh.au/posts/waltzing-into-viennas-new-year/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cbr/\u003eIn a world so vast and wide,\u003cbr/\u003eI met a soul, my guide,\u003cbr/\u003eWho took my hand, side by side,\u003cbr/\u003eShowed me life on the other side.\u003cbr/\u003e\u003cbr/\u003eThrough lands of sun and snow,\u003cbr/\u003eBeyond where I'd ever go,\u003cbr/\u003eThey taught me to let go,\u003cbr/\u003eIn travel's flow, I began to grow.\u003cbr/\u003e\u003cbr/\u003eWe wandered through streets unknown,\u003cbr/\u003eAt every step, a new tone,\u003cbr/\u003eUnder skies that shone,\u003cbr/\u003eLife's true colours were shown.\u003cbr/\u003e\u003cbr/\u003eThey pushed me past my fears,\u003cbr/\u003eThrough laughter and through tears,\u003cbr/\u003eYears in moments, moments in years,\u003cbr/\u003eIn their gaze, the world appears.\u003cbr/\u003e\u003cbr/\u003eBut paths diverge in life's maze,\u003cbr/\u003eWhat was once a joint blaze,\u003cbr/\u003eTurns to memory's haze,\u003cbr/\u003eAs we reach our separate ways.\u003cbr/\u003e\u003cbr/\u003eA goodbye under foreign skies,\u003cbr/\u003eWith grateful tears in our eyes,\u003cbr/\u003eFor the journey that ties,\u003cbr/\u003eIn our hearts, where it never dies.\u003cbr/\u003e\u003cbr/\u003eThough we part, I understand,\u003cbr/\u003eLife's journey is but grains of sand,\u003cbr/\u003eThey showed me the world, so grand,\u003cbr/\u003eNow I walk alone, yet stand.\u003cbr/\u003e\u003cbr/\u003eIn their absence, a new start,\u003cbr/\u003eWith a world map in my heart,\u003cbr/\u003eFor they played the most vital part,\u003cbr/\u003eIn the story of my art.\u003cbr/\u003e\n\u003cdiv class=\"gallery-box\"\u003e\n  \u003cdiv class=\"gallery\"\u003e\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_02.webp\" width=\"4128\" height=\"3096\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_03.webp\" width=\"3264\" height=\"2448\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_04.webp\" width=\"3264\" height=\"2448\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_05.webp\" width=\"3264\" height=\"2448\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_06.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_07.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_08.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_09.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_10.webp\" width=\"1024\" height=\"768\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_11.webp\" width=\"4608\" height=\"3456\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_12.webp\" width=\"4608\" height=\"3456\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_13.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_14.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_15.webp\" width=\"4608\" height=\"3456\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_16.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_17.webp\" width=\"4032\" height=\"3024\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_18.webp\" width=\"4608\" height=\"3456\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n    \u003cimg src=\"/images/journeys-with-a-guiding-soul_19.webp\" width=\"4608\" height=\"3456\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n  \u003c/div\u003e\n\u003c/div\u003e\n","content_text":"In a world so vast and wide,I met a soul, my guide,Who took my hand, side by side,Showed me life on the other side.Through lands of sun and snow,Beyond where I'd ever go,They taught me to let go,In travel's flow, I began to grow.We wandered through streets unknown,At every step, a new tone,Under skies that shone,Life's true colours were shown.They pushed me past my fears,Through laughter and through tears,Years in moments, moments in years,In their gaze, the world appears.But paths diverge in life's maze,What was once a joint blaze,Turns to memory's haze,As we reach our separate ways.A goodbye under foreign skies,With grateful tears in our eyes,For the journey that ties,In our hearts, where it never dies.Though we part, I understand,Life's journey is but grains of sand,They showed me the world, so grand,Now I walk alone, yet stand.In their absence, a new start,With a world map in my heart,For they played the most vital part,In the story of my art. ","date_published":"2019-12-11T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/journeys-with-a-guiding-soul/","image":"https://blog.mitcdh.au/images/journeys-with-a-guiding-soul_01.webp","summary":"Wherein I cherish shared adventures.","tags":["Writing","Poetry"],"title":"Journeys with a Guiding Soul","url":"https://blog.mitcdh.au/posts/journeys-with-a-guiding-soul/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2019-09-15T17:51:31Z","id":"https://blog.mitcdh.au/posts/meeting-in-warsaw-poland/","image":"https://blog.mitcdh.au/images/meeting-in-warsaw-poland.jpg","summary":"I travelled for a short meeting with NCBJ but uncovered a rich history, captivating culture, and dynamic energy – a city that never ceases to amaze me.","tags":["Album"],"title":"Meeting in Warsaw, Poland","url":"https://blog.mitcdh.au/posts/meeting-in-warsaw-poland/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2019-07-13T18:21:06Z","id":"https://blog.mitcdh.au/posts/attacking-asherah-in-fredericton-canada/","image":"https://blog.mitcdh.au/images/attacking-asherah-in-fredericton-canada.jpg","summary":"The true essence of a cyber-attack research project isn't just about understanding vulnerabilities or enhancing security; it's about bringing your friends together to break things.","tags":["Album"],"title":"Attacking Asherah in Fredericton, Canada","url":"https://blog.mitcdh.au/posts/attacking-asherah-in-fredericton-canada/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2019-02-25T12:54:16Z","id":"https://blog.mitcdh.au/posts/birthday-in-budapest-hungary/","image":"https://blog.mitcdh.au/images/birthday-in-budapest-hungary.jpg","summary":"As the years add wisdom (maybe not to me), why not add stamps to my passport too?","tags":["Album"],"title":"Birthday in Budapest, Hungary","url":"https://blog.mitcdh.au/posts/birthday-in-budapest-hungary/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2018-04-21T14:30:00Z","id":"https://blog.mitcdh.au/posts/adventures-in-spain-portugal-and-morocco/","image":"https://blog.mitcdh.au/images/adventures-in-spain-portugal-and-morocco.jpg","summary":"The food. My god.","tags":["Album"],"title":"Adventures in Spain, Portugal, and Morocco","url":"https://blog.mitcdh.au/posts/adventures-in-spain-portugal-and-morocco/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2018-03-21T18:19:19Z","id":"https://blog.mitcdh.au/posts/2nd-rcm-in-toronto-and-kincardine-canada/","image":"https://blog.mitcdh.au/images/2nd-rcm-in-toronto-and-kincardine-canada.jpg","summary":"","tags":["Album"],"title":"2nd RCM in Toronto and Kincardine, Canada","url":"https://blog.mitcdh.au/posts/2nd-rcm-in-toronto-and-kincardine-canada/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis post has been adapted verbatim from a paper accepted and presented during \u003ca href=\"https://www.igorr.com/\"\u003eInternational Group on Research Reactors (IGORR) 2017\u003c/a\u003e titled \u0026lsquo;Secure Enterprise Integration for Multipurpose Research Reactors\u0026rsquo; authored by \u003ca href=\"https://www.linkedin.com/in/nickhowarth/\"\u003eNick Howarth\u003c/a\u003e, myself, Christina Hunt, and \u003ca href=\"https://www.linkedin.com/in/anthony-noonan-09732364/\"\u003eAnthony Noonan\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"abstract\"\u003eAbstract\u003c/h1\u003e\n\u003cp\u003eThe OPAL research reactor operated by the Australian Nuclear Science and Technology Organisation (ANSTO) is a multi-purpose scientific and manufacturing facility. Information produced by the reactor\u0026rsquo;s operational technology (OT) systems is relied upon by engineering, scientific, and manufacturing information systems.\u003c/p\u003e\n\u003cp\u003eWe present an overview of the requirements for, and the techniques applied to achieve secure enterprise integration between the OPAL Research Reactor\u0026rsquo;s Operational Technology (OT) and associated these information systems, while conforming to international and national guidance including:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eMinimising what \u0026ldquo;information system\u0026rdquo; functionality is present on reactor OT systems;\u003c/li\u003e\n\u003cli\u003eProviding a controlled, uni-directional security gateway for data flows from the OT systems to the ERP; and\u003c/li\u003e\n\u003cli\u003eLimiting data entry to reactor OT systems to operator controlled barcoded paper forms using strictly defined data formats.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch1 id=\"introduction\"\u003eIntroduction\u003c/h1\u003e\n\u003cp\u003eThe OPAL research reactor operated by the Australian Nuclear Science and Technology Organisation (ANSTO) is a multi-purpose scientific and manufacturing facility. Information produced by the reactor\u0026rsquo;s operational technology (OT) systems is relied upon by engineering, scientific, and manufacturing information systems, including:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEngineering, operations and maintenance information systems;\u003c/li\u003e\n\u003cli\u003eNeutron beamline data acquisition systems; and\u003c/li\u003e\n\u003cli\u003eANSTO\u0026rsquo;s Enterprise Resource Planning (ERP) system for the scheduling of:\u003c/li\u003e\n\u003cli\u003eSilicon Neutron Transmutation Doping (NTD) irradiations, and\u003c/li\u003e\n\u003cli\u003eIrradiation of materials for scientific analysis and for the production of radiopharmaceuticals.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eEach consumer of information produced by the OPAL research reactor has its own computer security model ranging from the collaborative network operated by the Australian Centre for Neutron Scattering (ACNS), to the secure network requirements of the ANSTO ERP platform. The differing requirements of each area were taken into account with one fundamental security control from the reactor itself, the physical isolation of the OT network from inward network communication.\u003c/p\u003e\n\u003cp\u003eThrough the application of international guidance from the International Atomic Energy Agency (IAEA), national frameworks and procedures from the Australian Signals Directorate (ASD), and local expertise, ANSTO has formed a security architecture that meets the requirement of all users of the OPAL research reactor while protecting the key OT systems that ensure safe, secure, and sustainable operation.\u003c/p\u003e\n\u003cp\u003eThe techniques applied to achieve this secure enterprise integration while conforming to international and national guidance included:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eMinimising what \u0026ldquo;information system\u0026rdquo; functionality is present on reactor OT systems;\u003c/li\u003e\n\u003cli\u003eProviding a controlled, uni-directional security gateway for data flows from the OT systems to the ERP; and\u003c/li\u003e\n\u003cli\u003eLimiting data entry to reactor OT systems to operator controlled barcoded paper forms using strictly defined data formats.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch1 id=\"data-generation-and-integration-requirements\"\u003eData Generation and Integration Requirements\u003c/h1\u003e\n\u003cp\u003eGenerally, individual users of reactor OT systems generate data when performing engineering, operational, and maintenance activities. This data is then required to be exported from these systems for use in an appropriate enterprise information system for further analysis or storage. Additional to this ad-hoc data generated by users may be data generated automatically by reactor OT systems for the same purpose, generally at a low frequency e.g. daily or weekly, and is not required for use by users or other information systems in real time.\u003c/p\u003e\n\u003cp\u003eNeutron beamline telemetry is acquired by reactor OT systems for use in scientific analysis by the ACNS. This data is comprised of measurements of key neutron beam related reactor plant systems, including temperatures, flows, neutron flux and other reactor plant state information. This data is collected at a comparatively high frequency (multiple samples per minute), and is generally required for use by ACNS scientific analysis systems in near real-time.\u003c/p\u003e\n\u003cp\u003eFor manufacturing purposes, manufacturing job data is first required to be loaded into the reactor OT systems. This data is used to control various aspects of the manufacturing process, executed by the reactor OT system. During the manufacturing processes, data is collected by the reactor OT system for use by ERP systems. This data is used to track the progress of the manufacturing process, and to record data such as irradiation duration, received neutron flux etc. This data is then used for further manufacturing or other supply chain activities within the ERP system in near-real time.\u003c/p\u003e\n\u003cp\u003eA summary of the data generation and integration requirements is presented below.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTable 1 - Summary of Data Generation Requirements\u003c/strong\u003e\u003c/p\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003e\u003cstrong\u003eData Type\u003c/strong\u003e\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003e\u003cstrong\u003eGeneration Method\u003c/strong\u003e\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003e\u003cstrong\u003eGeneration  Freq.\u003c/strong\u003e\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003e\u003cstrong\u003eUsage Req.\u003c/strong\u003e\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eEngineering, Operations, Maintenance\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eUser generated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eDaily or Weekly\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAd-hoc, non-real-time\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eNeutron Beam Line Telemetry\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSystem generated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMultiple samples per minute\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAutomated real-time analysis\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eManufacturing execution data\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eUser and System generated\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHourly\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCorporate ERP system, near real-time\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch1 id=\"legacy-mex-system\"\u003eLegacy MEX System\u003c/h1\u003e\n\u003cp\u003ePreviously, a discrete manufacturing execution system (MEX) was operated on the reactor OT network. Scheduling staff used this MEX to schedule the manufacturing activities described previously. Manufacturing operations staff then used the MEX to execute the manufacturing activities. The MEX passed data to and from the reactor OT systems in real-time during manufacturing execution using the reactor OT network. Data was then passed between the MEX and the ERP system using USB storage media. Due to the volume and pace of these manufacturing activities, data was required to be passed between the MEX and ERP systems up to several times per day.\u003c/p\u003e\n\u003cp\u003eA high level data flow across this legacy architecture is presented below.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/reactor-enterprise-integration_fig1.webp\" width=\"583\" height=\"231\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 1 - Legacy Data Flow\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"cyber-security-requirements\"\u003eCyber Security Requirements\u003c/h1\u003e\n\u003cp\u003eThrough the application of international guidance from the IAEA (International Atomic Energy Agency, 2011), national frameworks and procedures from the ASD (Australian Signals Directorate, 2017), and local expertise, ANSTO has formed a security architecture that meets the requirement of all users of the OPAL research reactor while protecting the key OT systems that ensure safe, secure, and sustainable operation. The techniques applied to achieve this secure enterprise integration while conforming to international and national guidance included:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eMinimising what \u0026ldquo;information system\u0026rdquo; functionality is present on reactor OT systems;\u003c/li\u003e\n\u003cli\u003eProviding a controlled, uni-directional security gateway for data flows from the OT systems to the ERP; and\u003c/li\u003e\n\u003cli\u003eLimiting data entry to reactor OT systems to operator controlled barcoded paper forms using strictly defined data formats.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eDue to upgrades required to the reactor\u0026rsquo;s OT systems that would render the legacy MEX system obsolete, the opportunity to remove the legacy MEX was realised. The scheduling functionality used in the legacy MEX system was replaced by supply chain wide scheduling functionality in the corporate ERP system, and manufacturing execution functionality was implemented directly in the reactors primary control system. This allowed the removal of the legacy MEX system entirely, reducing the overall \u0026ldquo;information system\u0026rdquo; functionality of the reactor OT environment, and reducing the volume and frequency of data transfers required to and from the OT environment.\u003c/p\u003e\n\u003cp\u003eIn addition to the removal of the legacy MEX system, other \u0026ldquo;information system\u0026rdquo; functionality present on the OT environment was reduced or removed, such as:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWord processing, spreadsheet and other desktop productivity software;\u003c/li\u003e\n\u003cli\u003eReporting and analytics systems;\u003c/li\u003e\n\u003cli\u003ePrinting facilities; and\u003c/li\u003e\n\u003cli\u003eData storage for conventional files.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eTo facilitate the access to data generated by the reactor\u0026rsquo;s OT systems, a uni-directional security gateway (data diode) is utilised, providing secure data transfer from the OT systems to the corporate IT systems, while simultaneously providing a physical barrier to incoming connectivity. The specific data diode system employed for this purpose uses a single, transmit-only optical fibre connection, without a corresponding receive optical fibre. Due to the physical nature of the barrier, there is no risk of the gateway being compromised by a remote attacker in software only.\u003c/p\u003e\n\u003cp\u003eThe data diode system allows for the real-time transmission of OT system and user generated data from the OT network to the corporate IT network. The specific data diode system employed supports the capacity and reliability requirements of the OT systems and users previously described, without need to reduce or otherwise modify existing processes, with significant additional capacity available for future expansion.\u003c/p\u003e\n\u003cp\u003eWhen removing the legacy MEX system, the requirement to be able to efficiently and accurately input manufacturing work order data remained. To facilitate this requirement, barcoded paper forms, generated by the corporate ERP system are employed. The input data requirements for manufacturing work orders are sufficiently low that an industry standard two-dimensional barcode provides adequate capacity for encoding this data, while conserving physical space on the paper form. The small size and fixed format nature of this barcode data allows for thorough validation processes to be performed when the data is read into the control system, for manufacturing execution. The use of barcodes additionally removes the need for work order data to be keyed in manually by operators, preventing keying errors.\u003c/p\u003e\n\u003ch1 id=\"enhanced-manufacturing-process-data-flow\"\u003eEnhanced Manufacturing Process Data Flow\u003c/h1\u003e\n\u003cp\u003eThe lifecycle of a manufacturing work order using this enhanced data flow is as follows:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eScheduling of manufacturing activities occurs in the corporate ERP system, integrated with the complete supply chain. Ongoing changes to scheduling data are simplified as there is no need to continually transfer data between the corporate ERP system and the legacy MEX.\u003c/li\u003e\n\u003cli\u003eImmediately prior to manufacturing activities commencing, a paper work order form is generated from the corporate ERP containing manufacturing data encoded on a two-dimensional barcode.\u003c/li\u003e\n\u003cli\u003eThe work order data is scanned into the control system using a barcode reader. This data is then available for use by the control system when executing manufacturing activities.\u003c/li\u003e\n\u003cli\u003eAs manufacturing activities are executed, data is generated by the control system, and is securely transmitted to the corporate ERP system via the data diode on the OT network, in real-time. The corporate ERP system can then report this data to supply chain managers and other stakeholders.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/reactor-enterprise-integration_fig2.webp\" width=\"461\" height=\"252\" alt=\"\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFigure 2 - Enhanced Data Flow\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"other-data-flows\"\u003eOther Data Flows\u003c/h1\u003e\n\u003cp\u003eThe data diode system is also utilised for transmitting data generated by other reactor OT systems for integration into other corporate information systems in real-time, including data for scientific, engineering, operations and maintenance information systems. By removing or reducing \u0026ldquo;information system\u0026rdquo; functionality from the OT environment, and by consolidating \u0026ldquo;engineering system\u0026rdquo; functionality into the OT environment, the need for bi-directional network connectivity between the OT and corporate networks is significantly reduced.\u003c/p\u003e\n\u003ch1 id=\"limitations\"\u003eLimitations\u003c/h1\u003e\n\u003cp\u003eBy implementing a data diode in this security architecture, the restriction on incoming connectivity poses two main limitations:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eThe inability for users to transmit data to the OT environment from the corporate environment for legitimate purposes; and\u003c/li\u003e\n\u003cli\u003eThe inability to receive confirmations that data transmitted over the data diode system has been received and processed correctly.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eThe inability for users to transmit legitimate data to the OT environment from the corporate environment for legitimate purposes is mitigated by incorporating the needs of all stakeholders into the overall design of the OT environment. By consolidating \u0026ldquo;engineering system\u0026rdquo; functionality into the OT environment, the need to transmit data into the environment is greatly reduced. This also has the added benefit of allowing greater technical and administrative controls to be applied to the engineering systems together with other systems on the OT environment.\u003c/p\u003e\n\u003cp\u003eThe inability to receive confirmations is mitigated to an extent by including sequencing information within data sent across the data diode system. This sequencing information is then used by corporate information systems to detect if data received from the OT environment is in-order, and used to detect if data has been missed.\u003c/p\u003e\n\u003ch1 id=\"summary\"\u003eSummary\u003c/h1\u003e\n\u003cp\u003eAs described above, by detailed consideration of data flow, \u0026ldquo;information system\u0026rdquo; and \u0026ldquo;engineering system\u0026rdquo; requirements, it is possible to design a security architecture that supports the scientific, engineering, operations and maintenance enterprise integration needs of a research reactor, while maintaining very high levels of cyber security assurance.\u003c/p\u003e\n\u003cp\u003eReducing \u0026ldquo;information system\u0026rdquo; functionality and consolidating \u0026ldquo;engineering system\u0026rdquo; functionality on the OT environment greatly simplifies data flow requirements. Implementing a controlled, uni-directional security gateway for data flows from the OT systems to the ERP provides a high level of cyber security control, while still allowing enterprise integration to continue. Finally, where regular data entry to the OT environment is required, limiting this data entry to operator controlled barcoded paper forms allows for semi-automation of data entry, while still maintaining a high level of cyber security assurance.\u003c/p\u003e\n\u003ch1 id=\"references\"\u003eReferences\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAustralian Signals Directorate, 2017. \u003cem\u003eInformation Security Manual.\u003c/em\u003e [Online] Available at: \u003ca href=\"https://www.asd.gov.au/infosec/ism/\"\u003ehttps://www.asd.gov.au/infosec/ism/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInternational Atomic Energy Agency, 2011. \u003cem\u003eComputer Security at Nuclear Facilities.\u003c/em\u003e [Online] Available at: \u003ca href=\"http://www-pub.iaea.org/MTCD/Publications/PDF/Pub1527_web.pdf\"\u003ehttp://www-pub.iaea.org/MTCD/Publications/PDF/Pub1527_web.pdf\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n","content_text":"This post has been adapted verbatim from a paper accepted and presented during International Group on Research Reactors (IGORR) 2017 titled ‘Secure Enterprise Integration for Multipurpose Research Reactors’ authored by Nick Howarth, myself, Christina Hunt, and Anthony Noonan.\nAbstract The OPAL research reactor operated by the Australian Nuclear Science and Technology Organisation (ANSTO) is a multi-purpose scientific and manufacturing facility. Information produced by the reactor’s operational technology (OT) systems is relied upon by engineering, scientific, and manufacturing information systems.\nWe present an overview of the requirements for, and the techniques applied to achieve secure enterprise integration between the OPAL Research Reactor’s Operational Technology (OT) and associated these information systems, while conforming to international and national guidance including:\nMinimising what “information system” functionality is present on reactor OT systems; Providing a controlled, uni-directional security gateway for data flows from the OT systems to the ERP; and Limiting data entry to reactor OT systems to operator controlled barcoded paper forms using strictly defined data formats. Introduction The OPAL research reactor operated by the Australian Nuclear Science and Technology Organisation (ANSTO) is a multi-purpose scientific and manufacturing facility. Information produced by the reactor’s operational technology (OT) systems is relied upon by engineering, scientific, and manufacturing information systems, including:\nEngineering, operations and maintenance information systems; Neutron beamline data acquisition systems; and ANSTO’s Enterprise Resource Planning (ERP) system for the scheduling of: Silicon Neutron Transmutation Doping (NTD) irradiations, and Irradiation of materials for scientific analysis and for the production of radiopharmaceuticals. Each consumer of information produced by the OPAL research reactor has its own computer security model ranging from the collaborative network operated by the Australian Centre for Neutron Scattering (ACNS), to the secure network requirements of the ANSTO ERP platform. The differing requirements of each area were taken into account with one fundamental security control from the reactor itself, the physical isolation of the OT network from inward network communication.\nThrough the application of international guidance from the International Atomic Energy Agency (IAEA), national frameworks and procedures from the Australian Signals Directorate (ASD), and local expertise, ANSTO has formed a security architecture that meets the requirement of all users of the OPAL research reactor while protecting the key OT systems that ensure safe, secure, and sustainable operation.\nThe techniques applied to achieve this secure enterprise integration while conforming to international and national guidance included:\nMinimising what “information system” functionality is present on reactor OT systems; Providing a controlled, uni-directional security gateway for data flows from the OT systems to the ERP; and Limiting data entry to reactor OT systems to operator controlled barcoded paper forms using strictly defined data formats. Data Generation and Integration Requirements Generally, individual users of reactor OT systems generate data when performing engineering, operational, and maintenance activities. This data is then required to be exported from these systems for use in an appropriate enterprise information system for further analysis or storage. Additional to this ad-hoc data generated by users may be data generated automatically by reactor OT systems for the same purpose, generally at a low frequency e.g. daily or weekly, and is not required for use by users or other information systems in real time.\nNeutron beamline telemetry is acquired by reactor OT systems for use in scientific analysis by the ACNS. This data is comprised of measurements of key neutron beam related reactor plant systems, including temperatures, flows, neutron flux and other reactor plant state information. This data is collected at a comparatively high frequency (multiple samples per minute), and is generally required for use by ACNS scientific analysis systems in near real-time.\nFor manufacturing purposes, manufacturing job data is first required to be loaded into the reactor OT systems. This data is used to control various aspects of the manufacturing process, executed by the reactor OT system. During the manufacturing processes, data is collected by the reactor OT system for use by ERP systems. This data is used to track the progress of the manufacturing process, and to record data such as irradiation duration, received neutron flux etc. This data is then used for further manufacturing or other supply chain activities within the ERP system in near-real time.\nA summary of the data generation and integration requirements is presented below.\nTable 1 - Summary of Data Generation Requirements\nData Type Generation Method Generation Freq. Usage Req. Engineering, Operations, Maintenance User generated Daily or Weekly Ad-hoc, non-real-time Neutron Beam Line Telemetry System generated Multiple samples per minute Automated real-time analysis Manufacturing execution data User and System generated Hourly Corporate ERP system, near real-time Legacy MEX System Previously, a discrete manufacturing execution system (MEX) was operated on the reactor OT network. Scheduling staff used this MEX to schedule the manufacturing activities described previously. Manufacturing operations staff then used the MEX to execute the manufacturing activities. The MEX passed data to and from the reactor OT systems in real-time during manufacturing execution using the reactor OT network. Data was then passed between the MEX and the ERP system using USB storage media. Due to the volume and pace of these manufacturing activities, data was required to be passed between the MEX and ERP systems up to several times per day.\nA high level data flow across this legacy architecture is presented below.\nFigure 1 - Legacy Data Flow\nCyber Security Requirements Through the application of international guidance from the IAEA (International Atomic Energy Agency, 2011), national frameworks and procedures from the ASD (Australian Signals Directorate, 2017), and local expertise, ANSTO has formed a security architecture that meets the requirement of all users of the OPAL research reactor while protecting the key OT systems that ensure safe, secure, and sustainable operation. The techniques applied to achieve this secure enterprise integration while conforming to international and national guidance included:\nMinimising what “information system” functionality is present on reactor OT systems; Providing a controlled, uni-directional security gateway for data flows from the OT systems to the ERP; and Limiting data entry to reactor OT systems to operator controlled barcoded paper forms using strictly defined data formats. Due to upgrades required to the reactor’s OT systems that would render the legacy MEX system obsolete, the opportunity to remove the legacy MEX was realised. The scheduling functionality used in the legacy MEX system was replaced by supply chain wide scheduling functionality in the corporate ERP system, and manufacturing execution functionality was implemented directly in the reactors primary control system. This allowed the removal of the legacy MEX system entirely, reducing the overall “information system” functionality of the reactor OT environment, and reducing the volume and frequency of data transfers required to and from the OT environment.\nIn addition to the removal of the legacy MEX system, other “information system” functionality present on the OT environment was reduced or removed, such as:\nWord processing, spreadsheet and other desktop productivity software; Reporting and analytics systems; Printing facilities; and Data storage for conventional files. To facilitate the access to data generated by the reactor’s OT systems, a uni-directional security gateway (data diode) is utilised, providing secure data transfer from the OT systems to the corporate IT systems, while simultaneously providing a physical barrier to incoming connectivity. The specific data diode system employed for this purpose uses a single, transmit-only optical fibre connection, without a corresponding receive optical fibre. Due to the physical nature of the barrier, there is no risk of the gateway being compromised by a remote attacker in software only.\nThe data diode system allows for the real-time transmission of OT system and user generated data from the OT network to the corporate IT network. The specific data diode system employed supports the capacity and reliability requirements of the OT systems and users previously described, without need to reduce or otherwise modify existing processes, with significant additional capacity available for future expansion.\nWhen removing the legacy MEX system, the requirement to be able to efficiently and accurately input manufacturing work order data remained. To facilitate this requirement, barcoded paper forms, generated by the corporate ERP system are employed. The input data requirements for manufacturing work orders are sufficiently low that an industry standard two-dimensional barcode provides adequate capacity for encoding this data, while conserving physical space on the paper form. The small size and fixed format nature of this barcode data allows for thorough validation processes to be performed when the data is read into the control system, for manufacturing execution. The use of barcodes additionally removes the need for work order data to be keyed in manually by operators, preventing keying errors.\nEnhanced Manufacturing Process Data Flow The lifecycle of a manufacturing work order using this enhanced data flow is as follows:\nScheduling of manufacturing activities occurs in the corporate ERP system, integrated with the complete supply chain. Ongoing changes to scheduling data are simplified as there is no need to continually transfer data between the corporate ERP system and the legacy MEX. Immediately prior to manufacturing activities commencing, a paper work order form is generated from the corporate ERP containing manufacturing data encoded on a two-dimensional barcode. The work order data is scanned into the control system using a barcode reader. This data is then available for use by the control system when executing manufacturing activities. As manufacturing activities are executed, data is generated by the control system, and is securely transmitted to the corporate ERP system via the data diode on the OT network, in real-time. The corporate ERP system can then report this data to supply chain managers and other stakeholders. Figure 2 - Enhanced Data Flow\nOther Data Flows The data diode system is also utilised for transmitting data generated by other reactor OT systems for integration into other corporate information systems in real-time, including data for scientific, engineering, operations and maintenance information systems. By removing or reducing “information system” functionality from the OT environment, and by consolidating “engineering system” functionality into the OT environment, the need for bi-directional network connectivity between the OT and corporate networks is significantly reduced.\nLimitations By implementing a data diode in this security architecture, the restriction on incoming connectivity poses two main limitations:\nThe inability for users to transmit data to the OT environment from the corporate environment for legitimate purposes; and The inability to receive confirmations that data transmitted over the data diode system has been received and processed correctly. The inability for users to transmit legitimate data to the OT environment from the corporate environment for legitimate purposes is mitigated by incorporating the needs of all stakeholders into the overall design of the OT environment. By consolidating “engineering system” functionality into the OT environment, the need to transmit data into the environment is greatly reduced. This also has the added benefit of allowing greater technical and administrative controls to be applied to the engineering systems together with other systems on the OT environment.\nThe inability to receive confirmations is mitigated to an extent by including sequencing information within data sent across the data diode system. This sequencing information is then used by corporate information systems to detect if data received from the OT environment is in-order, and used to detect if data has been missed.\nSummary As described above, by detailed consideration of data flow, “information system” and “engineering system” requirements, it is possible to design a security architecture that supports the scientific, engineering, operations and maintenance enterprise integration needs of a research reactor, while maintaining very high levels of cyber security assurance.\nReducing “information system” functionality and consolidating “engineering system” functionality on the OT environment greatly simplifies data flow requirements. Implementing a controlled, uni-directional security gateway for data flows from the OT systems to the ERP provides a high level of cyber security control, while still allowing enterprise integration to continue. Finally, where regular data entry to the OT environment is required, limiting this data entry to operator controlled barcoded paper forms allows for semi-automation of data entry, while still maintaining a high level of cyber security assurance.\nReferences Australian Signals Directorate, 2017. Information Security Manual. [Online] Available at: https://www.asd.gov.au/infosec/ism/ International Atomic Energy Agency, 2011. Computer Security at Nuclear Facilities. [Online] Available at: http://www-pub.iaea.org/MTCD/Publications/PDF/Pub1527_web.pdf ","date_published":"2017-12-08T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/reactor-enterprise-integration/","image":"https://blog.mitcdh.au/images/reactor-enterprise-integration.webp","summary":"Presented during IGORR 2017.","tags":["writing","Nuclear","Technology","Security"],"title":"Secure Enterprise Integration for Multipurpose Research Reactors","url":"https://blog.mitcdh.au/posts/reactor-enterprise-integration/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2017-12-02T15:18:38Z","id":"https://blog.mitcdh.au/posts/accelerating-to-beijing-china/","image":"https://blog.mitcdh.au/images/accelerating-to-beijing-china.jpg","summary":"Alfoil really is a physicist's best friend.","tags":["Album"],"title":"Accelerating to Beijing, China","url":"https://blog.mitcdh.au/posts/accelerating-to-beijing-china/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis post has been adapted verbatim from a paper accepted and presented during \u003ca href=\"https://www.isofic.org/\"\u003eISOFIC 2017\u003c/a\u003e titled \u0026lsquo;Security Management of Virtualised Supervisory I\u0026amp;C Systems in Nuclear Facilities\u0026rsquo; authored by myself \u003ca href=\"https://www.linkedin.com/in/nickhowarth/\"\u003eNick Howarth\u003c/a\u003e, Christina Hunt, and \u003ca href=\"https://www.linkedin.com/in/anthony-noonan-09732364/\"\u003eAnthony Noonan\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"1-introduction\"\u003e1 Introduction\u003c/h1\u003e\n\u003cp\u003eInstrumentation and Control (I\u0026amp;C) systems in nuclear facilities provide information and control capabilities for the operation of the plant in operational states and in accident conditions\u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e. I\u0026amp;C system vendors are continuing to adopt virtualisation technologies in their product offerings. Consequently, nuclear facilities will continue to expand the use of virtualised I\u0026amp;C systems. In this paper we review a number of out of band security management techniques available to nuclear I\u0026amp;C operators when responding to an incident on virtualised I\u0026amp;C systems.\u003c/p\u003e\n\u003ch1 id=\"2-change-control-and-configuration-management\"\u003e2 Change Control and Configuration Management\u003c/h1\u003e\n\u003cp\u003eThe inherent abstraction of a virtualised environment along with the features provided by all major virtualisation host software offerings can be leveraged to enhance Engineering Change Control and configuration management process, as recommended by IAEA guidance\u003csup id=\"fnref:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003cp\u003eThe use of virtualization allows for of simplified engineering and maintenance processes, while allowing for systematic enforcement of configuration management policy. For example, the application of software patches to a system can be performed on isolated instances of virtual machines for testing and validation purposes, prior to the patching of operational systems. This process can be enforced by the virtualisation environment itself, with testing, review and approval data collected and stored by the system itself, reducing the administrative overhead that may otherwise be required.\u003c/p\u003e\n\u003cp\u003eVirtual machine deployment can also be automated, providing the ability to apply predefined and authorised policies and configuration management standards when deploying new systems, further reducing the risk of introducing additional security vulnerabilities and risks.\u003c/p\u003e\n\u003ch1 id=\"3-operational-considerations\"\u003e3 Operational Considerations\u003c/h1\u003e\n\u003cp\u003eThe ability to perform live migration between different virtualisation hosts provides the ability to move a virtual machine between physical infrastructure while the virtual machine remains online ensuring continued operation of running plant. This can allow hardware and operating system changes to the host server, such as the application of security patches, while minimising disruption to services provided within the hosted virtual machines.\u003c/p\u003e\n\u003cp\u003eThis live migration of virtual machines is achieved due to the nature of how storage is provided by the physical host to the virtual machine. In comparison to a conventional system where the raw storage media is directly accessed by the running system, the hypervisor powering the virtual infrastructure presents each virtual machine a virtual disk. This virtual disk appears as standard files to the hypervisor and can exist on a highly available and fault tolerant storage platform.\u003c/p\u003e\n\u003cp\u003eWhen presented to a virtual machine, the virtual disk mimics the characteristics of a raw storage medium. As these source files are accessible from the hypervisor they are able to be accessed and monitored outside of the execution context of the virtual machine itself. This enables the monitoring software to run without a threat to its integrity from malicious software able to control the execution context of the virtual machine.\u003c/p\u003e\n\u003ch1 id=\"4-backups-and-snapshots\"\u003e4 Backups and Snapshots\u003c/h1\u003e\n\u003cp\u003eAdditional benefits can be realised with the use of virtual machines within Nuclear I\u0026amp;C by the use of Snapshots. Snapshots capture a complete image of a virtual machine including its data, virtual hardware configuration, memory state, and power state\u003csup id=\"fnref:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e. The image of the memory state can also be loaded into a number of commercial and open-source memory analysis toolsets\u003csup id=\"fnref:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e. These tools allow visibility of compromises which may leverage advanced techniques to insert malicious software into memory without any on-disk file persistence that would be uncovered from forensically investigating the disk images. These snapshots can also be used to quickly recover from unexpected failures during the course of implementing a change.\u003c/p\u003e\n\u003cp\u003eAlternatively a virtual machine snapshot can be migrated to a test environment to facilitate offline testing of changes to be implemented or enable connection to simulated I/O. During an incident it may be beneficial to allow an infected virtual machine to continue running to understand the behaviour of any compromise. Within the context of Nuclear I\u0026amp;C this is counter to nuclear design criteria which would see the systems restored to design basis immediately on detection. With a virtual infrastructure it is possible to clone the compromised host, restore the running instance to a known good image that operates within design basis, and migrate the compromised clone to a sandbox with simulated I/O that records any actions undertaken to gain a greater understanding of the threat actor.\u003c/p\u003e\n\u003cp\u003eThe ability for a virtual machine to be cloned and restored to a known good state supports release management and change management activities by streamlining the process, minimising the risk associated with change and minimising the possibility of a negative impact to the integrity and availability of productions systems. These technologies directly contribute to both increased agility and reduction in risk during short maintenance windows, typically encountered on industrial and nuclear facilities.\u003c/p\u003e\n\u003ch1 id=\"5-virtual-machine-introspection\"\u003e5 Virtual Machine Introspection\u003c/h1\u003e\n\u003cp\u003eA more advanced technique for securing and monitoring a virtual environment is by using Virtual Machine Introspection (VMI). VMI is a technique for externally monitoring the runtime state of a virtual machine, without the monitored virtual machine participating in, or having an awareness of the monitoring process\u003csup id=\"fnref:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. Monitors can be placed in another virtual machine, within the host hypervisor, or within any other part of the virtualization architecture. For virtual machine introspection, the runtime state can be defined broadly to include processor registers, memory, disk, network, and any other hardware-level events. Using VMI, monitoring tools can perform anti-malware, intrusion prevention and detection, and many other security and compliance functions.\u003c/p\u003e\n\u003ch1 id=\"6-summary\"\u003e6 Summary\u003c/h1\u003e\n\u003cp\u003eIn summary, a robustly engineered, operated and maintained virtualisation based nuclear  I\u0026amp;C system provides significant benefits to the operations and security of the facility. These benefits range from a reduction in capital and ongoing costs; improved agility both for internal customers e.g. engineering changes, and external forces e.g. security incidents and software patches; decreased recovery times in the event of failures other security incidents; and the facilitation of sophisticated virtual machine based operational and digital forensic techniques.\u003c/p\u003e\n\u003ch1 id=\"references\"\u003eReferences\u003c/h1\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eINTERNATIONAL ATOMIC ENERGY AGENCY, Design of Instrumentation and Control Systems for Nuclear Power Plants, IAEA Safety Standard Series No. SSG-39, IAEA, Vienna (2016)\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:2\"\u003e\n\u003cp\u003eINTERNATIONAL ATOMIC ENERGY AGENCY, Configuration management in nuclear power plants, IAEA-TECDOC-1335, IAEA, Vienna (2003)\u0026#160;\u003ca href=\"#fnref:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:3\"\u003e\n\u003cp\u003eVMWARE, INC., Understanding VM snapshots in ESXi / ESX (2015). VMWare, Inc. Retrieved 5 June 2017, from \u003ca href=\"https://kb.vmware.com/selfservice/microsites/search.do?language=en_US\u0026amp;cmd=displayKC\u0026amp;externalId=1015180\"\u003ehttps://kb.vmware.com/selfservice/microsites/search.do?language=en_US\u0026amp;cmd=displayKC\u0026amp;externalId=1015180\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:4\"\u003e\n\u003cp\u003eVOLATILITY FOUNDATION, VMware Snapshot File. (2013). GitHub. Retrieved 1 June 2017, from \u003ca href=\"https://github.com/volatilityfoundation/volatility/wiki/VMware-Snapshot-File\"\u003ehttps://github.com/volatilityfoundation/volatility/wiki/VMware-Snapshot-File\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:5\"\u003e\n\u003cp\u003eTAPASWI, Shashikala, Virtual machine introspection: towards bridging the semantic gap, Journal of Cloud Computing. Retrieved October 2017, from \u003ca href=\"https://link.springer.com/article/10.1186/s13677-01\"\u003ehttps://link.springer.com/article/10.1186/s13677-01\u003c/a\u003e 4-0016-2\u0026#160;\u003ca href=\"#fnref:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This post has been adapted verbatim from a paper accepted and presented during ISOFIC 2017 titled ‘Security Management of Virtualised Supervisory I\u0026C Systems in Nuclear Facilities’ authored by myself Nick Howarth, Christina Hunt, and Anthony Noonan.\n1 Introduction Instrumentation and Control (I\u0026C) systems in nuclear facilities provide information and control capabilities for the operation of the plant in operational states and in accident conditions1. I\u0026C system vendors are continuing to adopt virtualisation technologies in their product offerings. Consequently, nuclear facilities will continue to expand the use of virtualised I\u0026C systems. In this paper we review a number of out of band security management techniques available to nuclear I\u0026C operators when responding to an incident on virtualised I\u0026C systems.\n2 Change Control and Configuration Management The inherent abstraction of a virtualised environment along with the features provided by all major virtualisation host software offerings can be leveraged to enhance Engineering Change Control and configuration management process, as recommended by IAEA guidance2.\nThe use of virtualization allows for of simplified engineering and maintenance processes, while allowing for systematic enforcement of configuration management policy. For example, the application of software patches to a system can be performed on isolated instances of virtual machines for testing and validation purposes, prior to the patching of operational systems. This process can be enforced by the virtualisation environment itself, with testing, review and approval data collected and stored by the system itself, reducing the administrative overhead that may otherwise be required.\nVirtual machine deployment can also be automated, providing the ability to apply predefined and authorised policies and configuration management standards when deploying new systems, further reducing the risk of introducing additional security vulnerabilities and risks.\n3 Operational Considerations The ability to perform live migration between different virtualisation hosts provides the ability to move a virtual machine between physical infrastructure while the virtual machine remains online ensuring continued operation of running plant. This can allow hardware and operating system changes to the host server, such as the application of security patches, while minimising disruption to services provided within the hosted virtual machines.\nThis live migration of virtual machines is achieved due to the nature of how storage is provided by the physical host to the virtual machine. In comparison to a conventional system where the raw storage media is directly accessed by the running system, the hypervisor powering the virtual infrastructure presents each virtual machine a virtual disk. This virtual disk appears as standard files to the hypervisor and can exist on a highly available and fault tolerant storage platform.\nWhen presented to a virtual machine, the virtual disk mimics the characteristics of a raw storage medium. As these source files are accessible from the hypervisor they are able to be accessed and monitored outside of the execution context of the virtual machine itself. This enables the monitoring software to run without a threat to its integrity from malicious software able to control the execution context of the virtual machine.\n4 Backups and Snapshots Additional benefits can be realised with the use of virtual machines within Nuclear I\u0026C by the use of Snapshots. Snapshots capture a complete image of a virtual machine including its data, virtual hardware configuration, memory state, and power state3. The image of the memory state can also be loaded into a number of commercial and open-source memory analysis toolsets4. These tools allow visibility of compromises which may leverage advanced techniques to insert malicious software into memory without any on-disk file persistence that would be uncovered from forensically investigating the disk images. These snapshots can also be used to quickly recover from unexpected failures during the course of implementing a change.\nAlternatively a virtual machine snapshot can be migrated to a test environment to facilitate offline testing of changes to be implemented or enable connection to simulated I/O. During an incident it may be beneficial to allow an infected virtual machine to continue running to understand the behaviour of any compromise. Within the context of Nuclear I\u0026C this is counter to nuclear design criteria which would see the systems restored to design basis immediately on detection. With a virtual infrastructure it is possible to clone the compromised host, restore the running instance to a known good image that operates within design basis, and migrate the compromised clone to a sandbox with simulated I/O that records any actions undertaken to gain a greater understanding of the threat actor.\nThe ability for a virtual machine to be cloned and restored to a known good state supports release management and change management activities by streamlining the process, minimising the risk associated with change and minimising the possibility of a negative impact to the integrity and availability of productions systems. These technologies directly contribute to both increased agility and reduction in risk during short maintenance windows, typically encountered on industrial and nuclear facilities.\n5 Virtual Machine Introspection A more advanced technique for securing and monitoring a virtual environment is by using Virtual Machine Introspection (VMI). VMI is a technique for externally monitoring the runtime state of a virtual machine, without the monitored virtual machine participating in, or having an awareness of the monitoring process5. Monitors can be placed in another virtual machine, within the host hypervisor, or within any other part of the virtualization architecture. For virtual machine introspection, the runtime state can be defined broadly to include processor registers, memory, disk, network, and any other hardware-level events. Using VMI, monitoring tools can perform anti-malware, intrusion prevention and detection, and many other security and compliance functions.\n6 Summary In summary, a robustly engineered, operated and maintained virtualisation based nuclear I\u0026C system provides significant benefits to the operations and security of the facility. These benefits range from a reduction in capital and ongoing costs; improved agility both for internal customers e.g. engineering changes, and external forces e.g. security incidents and software patches; decreased recovery times in the event of failures other security incidents; and the facilitation of sophisticated virtual machine based operational and digital forensic techniques.\nReferences INTERNATIONAL ATOMIC ENERGY AGENCY, Design of Instrumentation and Control Systems for Nuclear Power Plants, IAEA Safety Standard Series No. SSG-39, IAEA, Vienna (2016) ↩︎\nINTERNATIONAL ATOMIC ENERGY AGENCY, Configuration management in nuclear power plants, IAEA-TECDOC-1335, IAEA, Vienna (2003) ↩︎\nVMWARE, INC., Understanding VM snapshots in ESXi / ESX (2015). VMWare, Inc. Retrieved 5 June 2017, from https://kb.vmware.com/selfservice/microsites/search.do?language=en_US\u0026cmd=displayKC\u0026externalId=1015180 ↩︎\nVOLATILITY FOUNDATION, VMware Snapshot File. (2013). GitHub. Retrieved 1 June 2017, from https://github.com/volatilityfoundation/volatility/wiki/VMware-Snapshot-File ↩︎\nTAPASWI, Shashikala, Virtual machine introspection: towards bridging the semantic gap, Journal of Cloud Computing. Retrieved October 2017, from https://link.springer.com/article/10.1186/s13677-01 4-0016-2 ↩︎\n","date_published":"2017-11-30T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/virtualised-security-management/","image":"https://blog.mitcdh.au/images/virtualised-security-management.webp","summary":"A review of the functionality provided by virtualisation platforms, available to Nuclear I\u0026C operators from a cyber security management perspective.","tags":["writing","Nuclear","Technology","Security"],"title":"Security Management of Virtualised Supervisory I\u0026C Systems in Nuclear Facilities","url":"https://blog.mitcdh.au/posts/virtualised-security-management/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2016-12-29T12:05:50Z","id":"https://blog.mitcdh.au/posts/descending-into-the-blue-mountains-australia/","image":"https://blog.mitcdh.au/images/descending-into-the-blue-mountains-australia.jpg","summary":"Hiking up top too hot? Go down nature's water slide and take a canyon below.","tags":["Album"],"title":"Descending into the Blue (Mountains), Australia","url":"https://blog.mitcdh.au/posts/descending-into-the-blue-mountains-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2016-10-05T11:52:27Z","id":"https://blog.mitcdh.au/posts/on-the-southern-ocean-in-tasmania-australia/","image":"https://blog.mitcdh.au/images/on-the-southern-ocean-in-tasmania-australia.jpg","summary":"When Melbourne is no longer cold enough for you.","tags":["Album"],"title":"On the Southern Ocean in Tasmania, Australia","url":"https://blog.mitcdh.au/posts/on-the-southern-ocean-in-tasmania-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2016-06-26T11:47:32Z","id":"https://blog.mitcdh.au/posts/atop-the-blue-mountains-australia/","image":"https://blog.mitcdh.au/images/atop-the-blue-mountains-australia.jpg","summary":"","tags":["Album"],"title":"Atop the Blue Mountains, Australia","url":"https://blog.mitcdh.au/posts/atop-the-blue-mountains-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2015-10-25T13:42:43Z","id":"https://blog.mitcdh.au/posts/sydneys-sculptures-by-the-sea-australia/","image":"https://blog.mitcdh.au/images/sydneys-sculptures-by-the-sea-australia.jpg","summary":"Seagulls are the toughest art critics.","tags":["Album"],"title":"Sydney's Sculptures by the Sea, Australia","url":"https://blog.mitcdh.au/posts/sydneys-sculptures-by-the-sea-australia/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2015-08-14T13:26:35Z","id":"https://blog.mitcdh.au/posts/def-con-23-tour-of-california-and-las-vegas-united-states/","image":"https://blog.mitcdh.au/images/def-con-23-tour-of-california-and-las-vegas-united-states.jpg","summary":"Don't use the Wifi. Just don't.","tags":["Album"],"title":"DEF CON 23 Tour of California and Las Vegas, United States","url":"https://blog.mitcdh.au/posts/def-con-23-tour-of-california-and-las-vegas-united-states/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"\u003cp\u003e\u003cem\u003eThis post has been adapted verbatim from a paper accepted and presented during \u003ca href=\"https://www-pub.iaea.org/iaeameetings/46530/international-conference-on-computer-security-in-a-nuclear-world-expert-discussion-and-exchange\"\u003eInternational Conference on Computer Security in a Nuclear World: Expert Discussion and Exchange\u003c/a\u003e titled \u0026lsquo;Building and Breaking the Protection Provided by an Optical Data Diode Using Spare Parts\u0026rsquo; authored by myself \u003ca href=\"https://www.linkedin.com/in/danielgleesontechie/\"\u003eDaniel Gleeson\u003c/a\u003e, and \u003ca href=\"https://www.linkedin.com/in/ben-donovan-au/\"\u003eBen Donovan\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003ch1 id=\"abstract\"\u003eAbstract\u003c/h1\u003e\n\u003cp\u003eThis paper presents an overview of the construction and implementation of unidirectional networking through an optical fibre data diode while demonstrating post-implementation issues that need to be addressed to ensure the desired protection is provided.  This particular topic was chosen due to its relevance for nuclear facility operators.  Nuclear Security Series 17 highly encourages no inwards data flow of any kind to Level 1 systems.  Technical solutions are provided on implementing select applications that require stateful network protocols over the constructed unidirectional link. The paper stresses that there are further issues around implementing a data diode that are shared with both entirely connected and disconnected networks. Where a lack of a robust security culture on the more protected segment can lead to a compromise of the additional integrity protection that the data diode provides.  Throughout detail is provided that is accessible and easily understandable to various skill levels in networking, programming, and control system design; empowering operators and practitioners with a greater understanding of the optical diode technology and its implementation.  The design of the optical fibre diode, the software created in overcoming the requirement for stateful networking, and details of a covert device allowing foreign input will all be provided as technical resources. Where possible physical components are constructed with spare parts that would likely be found in a converged Industrial Control and Information Technology environment.\u003c/p\u003e\n\u003ch1 id=\"1-introduction\"\u003e1.  Introduction\u003c/h1\u003e\n\u003cp\u003eWhen there are two networks or devices that require different levels of protection employing a security risk management perspective they would be entirely disconnected forming what is termed as an \u0026ldquo;air gap\u0026rdquo;.\u003c/p\u003e\n\u003cp\u003eA unidirectional link describes a network link that allows data to flow between two devices in only a single direction. Techniques for unidirectional networking can be seen in terrestrial broadcast television and satellite downlinks where the communications infrastructure is only capable of passing data in a single direction \u003csup id=\"fnref:1\"\u003e\u003ca href=\"#fn:1\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e1\u003c/a\u003e\u003c/sup\u003e.  When a unidirectional link is implemented as part of a security gateway between two systems of differing protection requirements a demonstrable one way connection can be achieved. This is an enabling mechanism to allow data to flow in a single direction while still providing an effective air gap for the other direction of data flow across the link.\u003c/p\u003e\n\u003cp\u003eA modern unidirectional link termed a \u0026ldquo;Data Diode\u0026rdquo; implemented through optical fibre first originated in two 1999 technical reports published by Australia\u0026rsquo;s Defence Science and Technology Organisation (DSTO) entitled \u0026ldquo;Data Diodes\u0026rdquo; \u003csup id=\"fnref:2\"\u003e\u003ca href=\"#fn:2\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e2\u003c/a\u003e\u003c/sup\u003e and \u0026ldquo;Implications of an Optical Data Diode\u0026rdquo; \u003csup id=\"fnref:3\"\u003e\u003ca href=\"#fn:3\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e3\u003c/a\u003e\u003c/sup\u003e.  The DSTO papers outline two modes of operation for a data diode that depend on the inherent risks to the systems, processes, and information on the more secure side. Where confidentiality is the primary concern a link can be created to allow data to flow into the more secure network while preventing exfiltration of any information that resides within. Typically employed to separate systems of differing security classification this allows a strict implementation of the Bell-Lapadula model for access control (no read-up, no write-down)\u003csup id=\"fnref:4\"\u003e\u003ca href=\"#fn:4\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e4\u003c/a\u003e\u003c/sup\u003e. Alternatively in a mode where Integrity or Availability make up the key risks to a network the unidirectional link is configured in such a way that data is allowed to only flow out of the more secured system. This can then be considered an implementation of the Biba Integrity Model (no write-up, no read-down)\u003csup id=\"fnref:5\"\u003e\u003ca href=\"#fn:5\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e5\u003c/a\u003e\u003c/sup\u003e. Of the two the Integrity mode is the most relevant to critical infrastructure. This is supported by the IAEA through NSS 17\u0026rsquo;s suggestion for Level 1 systems to have no networked data flow of any kind from weaker security levels\u003csup id=\"fnref:6\"\u003e\u003ca href=\"#fn:6\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e6\u003c/a\u003e\u003c/sup\u003e.\u003c/p\u003e\n\u003ch1 id=\"2-purpose\"\u003e2. Purpose\u003c/h1\u003e\n\u003cp\u003eThe Australian Nuclear Science and Technology Organisation (ANSTO) separates it\u0026rsquo;s Reactor Control and Management System (RCMS) for the Open Pool Australian Lightwater (OPAL) research reactor from a network housing the detectors and computing infrastructure for the attached Neutron Beam Instrument Facility. Experiments undertaken on these beamlines require data from the RCMS to offset their calculations while the RCMS is a Nuclear Safety contributing system and therefore has inbound data flow restrictions. To address this during commissioning of the reactor, a gateway was created between the two networks to achieve unidirectional networking through a high assurance optical fibre data diode.\u003c/p\u003e\n\u003cp\u003eDuring a recent upgrade project a requirement to engineer an equivalent setup for a lab environment emerged to assist in the development a new transfer mechanism. It was broken down into three phases: construction of the diode following the principles outlined in the DSTO paper, development of software to proxy information across the diode, and a smaller side project to demonstrate a credible security threat to the RCMS.\u003c/p\u003e\n\u003ch1 id=\"3-building-a-unidirectional-link\"\u003e3. Building a Unidirectional Link\u003c/h1\u003e\n\u003cp\u003eIt is possible to create a unidirectional link across any medium that separates the cable medium for transmission and receipt of data. This approach can be applied to Ethernet running over twisted pair cabling up to a standard of 100BASE-TX, later standards have moved to a technology that transmits and receives on all pairs simultaneously. When implementing such a link it is important to sever every cable besides the desired transmit pair as any remaining connection could covertly be used to subvert the provided protection via a return return path.\u003c/p\u003e\n\u003cp\u003eThere is also a major disadvantage with this approach, in an off the shelf network card the pins in physical transceiver are not necessarily exclusive to a transmit or receive function and there is no way of visually inspecting this. The transceiver can determine which cable pairs are assigned to transmit and receive before the media access controller, this is observable through the application of Auto Medium Dependent Interface Crossover (Auto MDI-X) in modern network interfaces.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/breaking-data-diode_gbic.webp\" width=\"490\" height=\"653\" alt=\"Gigabit Interface Converter\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFIG. 1. PCB of a GBIC\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eTransceivers used in two-cable optical fibre networking on the other hand do not carry this disadvantage. Taking apart a pluggable transceiver shows an observable visual distinction between the modulator and light source on the transmit side and the photo sensor and demodulator on the receive side. Both channels are then able to pass traffic, independently across separate cables utilising dedicated, physically isolated circuitry, where FIG. 1. shows a clear electrical separation on the circuit board between onboard transmit and receiving functions.\u003c/p\u003e\n\u003cp\u003eBuilding on this an optical data diode is constructed by removing one of the fibre cables between a pair of transceivers. The remaining cable depends on the chosen protection model, for integrity or availability the transmit on the more protected segment\u0026rsquo;s interface will be connected to the receive on the destination less protected segment\u0026rsquo;s interface. Whichever side hosts the transmit role in the optical diode needs the receive side cabled to a the transmit of another powered transceiver so a carrier signal is received, a requirement before the link will be considered up and transmission to the other side of the diode can occur.  This additional transceiver should be physically located on or powered by a chassis on the transmission side of the diode to avoid the potential of creating a secondary channel and breaking the provided protection. This model also ensures the absence of data being transmitted across the carrier signal providing interface by maintaining the integrity of an entire data path.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/breaking-data-diode_switch-config.webp\" width=\"743\" height=\"186\" alt=\"Diode Config on Two Switches\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFIG. 2. Logical network interconnection topology\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eRather than a direct connection between two servers with fibre network interface cards the diode was built between existing lab networking equipment as exhibited in FIG. 2. This model employed, while providing an equivalent level of protection, also allowed utilisation of a dedicated and flexible networking stack independent of the sending and receiving systems. While not a true security gateway this flexibility allowed the development and testing of multiple approaches to achieving the desired unidirectional networking simultaneously.\u003c/p\u003e\n\u003cp\u003eEach side of the data diode was configured as an interface on subnets respectively representing the transmitting and receiving networks split by the implementation of the diode. There were a number of networking technologies supported by the hardware that needed to be configured in a specific manner to ensure full support for caveats of implementing a data diode.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eModern fibre interfaces support speed negotiation. Due to the nature of the diode preventing bidirectional communication this negotiation will fail to complete. While speed negotiation is enabled and not complete the link is unable to become active. Therefore to implement the diode speed negotiation needed to be disabled.\u003c/li\u003e\n\u003cli\u003eThe particular hardware used supported a feature called unidirectional link detection designed to shut interfaces where a unidirectional link is detected in order to prevent looping. As a diode is by definition a unidirectional link this protocol requires disabling.\u003c/li\u003e\n\u003cli\u003eStatic Address Resolution Protocol (ARP) entries were created on the protected transmitting segment so communication could be appropriately directed to devices on the less protected receiving segment.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1 id=\"4-transfer-across-a-data-diode\"\u003e4. Transfer Across a Data Diode\u003c/h1\u003e\n\u003cp\u003eTo understand the communication across the data diode will be achieved it is best to reference the OSI model. This model splits the communication up into seven encapsulated layers which each facilitate part of the communication. As a transmission occurs it passes from the sender\u0026rsquo;s application layer down to physical where transmission occurs. The transmission then reaches the receiver and progresses back up the layers.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/breaking-data-diode_osi.webp\" width=\"228\" height=\"220\" alt=\"OSI Model\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFIG. 3. The OSI model showing conceptual stages within the data transfer process.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eWithin a standard network, state is typically maintained within a protocol such as the Transmission Control Protocol (TCP). TCP is able to achieve a highly reliable transmission through techniques such as SYN/ACK numbering and sliding windows, operates on the transport layer, and underpins most common protocols operating at higher OSI layers.  Due to the nature of the data diode, stateful protocols are impossible to implement. The receiver isn\u0026rsquo;t able to acknowledge receipt of data or complete a handshake to initiate communication.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/breaking-data-diode_handshake.webp\" width=\"256\" height=\"227\" alt=\"TCP Handshake\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFIG. 4. The TCP handshake, demonstrating required bidirectional communication in a TCP session.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eAnother transport protocol, User Datagram Protocol (UDP) is capable of working over this type of link as it is unidirectional and stateless, it has no handshake requirement to start transmission and doesn\u0026rsquo;t acknowledge receipt of data.  This however means it provides no solid guarantees to the successful transfer and ordering of data. There are limited options available on each endpoint as each must execute in isolation. UDP\u0026rsquo;s primitive environment for transmission shouldn\u0026rsquo;t be entirely relied upon and on its own it should be assumed unreliable.\u003c/p\u003e\n\u003cp\u003eOne approach to increasing reliability is by implementing extra functionality within another layer of the OSI stack, typically the Application layer. Not all techniques are achievable given the unidirectional link however even implementing basic sequence numbering helps to reconstruct data, detect errors and track communication. A common technique is to include a checksum with the transfer, which can detect errors and trigger a retransmission. Due to the unidirectional link there is an inability to request retransmissions so this gives us no greater reliability.  Instead implementing Erasure coding techniques such as Reed Solomon can provide the desired functionality\u003csup id=\"fnref:7\"\u003e\u003ca href=\"#fn:7\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e7\u003c/a\u003e\u003c/sup\u003e. This technology allows detection and most importantly, correction of certain data errors without requiring a retransmission. While this can dramatically improve reliability, the system still has to be viewed as a \u0026ldquo;best-effort\u0026rdquo; transfer.\u003c/p\u003e\n\u003cp\u003eNetcat was initially investigated as an easy way to implement communications between hosts. It already includes some of the functionality required such as send / receive mode and protocol selection. Netcat however was missing key requirements such as datagram sequencing and transfer termination which we would\u0026rsquo;ve had to implement in another application sitting behind it. It was decided that bundling the sequencing, erasure coding and other plugins into the application would provide more fine grained control over the transfer.\u003c/p\u003e\n\u003cp\u003eThe Trivial File Transfer Protocol (TFTP)\u003csup id=\"fnref:8\"\u003e\u003ca href=\"#fn:8\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e8\u003c/a\u003e\u003c/sup\u003e already includes this sequencing and is seen as a clear and configurable platform to build with. Many implementations are available online written in high level languages which make it easy to extend for this particular use case. TFTP still utilises bidirectional communication to provide an acknowledgement mechanism as transmission occurs during session creation and periodically as a lock-step mechanism to ensure each packet is transferred correctly. Both of these responses can be engineered out and are not required for a successful data transfer apart from one small issue. The initial response by the receiver specifies an ephemeral data port for the transfer to be directed to. Instead in the unidirectional implementation the requirement for this response has been removed. The sender is considered to control the state of a set of ports that are reserved on the receiver and specifies the port it intends to use by declaring it as the source port in the initial UDP packet that contains the write request. To facilitate adding modules to process arbitrary protocols a syntax for the filename field in TFTP has been defined that can trigger the receiver to forward the traffic to a registered plugin.\u003c/p\u003e\n\u003ch1 id=\"5-breaking-the-protection\"\u003e5. Breaking the Protection\u003c/h1\u003e\n\u003cp\u003eBefore attempting to break the protection provided by the data diode it was important to first consider what we aim to achieve, for a diode operating in a confidentiality-protecting mode this would be the exfiltration of data from the protected segment. An integrity protecting diode is different; here the focus is on preventing foreign input from entering a system.\u003c/p\u003e\n\u003cp\u003eWith such an input channel a capable malicious adversary could compromise the integrity assurance of the network that the diode provides to the risk management process. Such a channel would require a device of some sort that is able to provide remote input onto the protected network. In designing such a device sample routine engineering processes were considered and analysed in order to identify a potential vector for compromise that highlighted the idea that peripheral devices will be introduced to Level 1 and 2 systems throughout their lifetime. Each introduction of a peripheral device carries with it a risk. Take the case of USB storage devices which are credited with the spread of the Stuxnet worm to isolated networks resulting in a vendor issued advisory notice recommending customers avoid their use\u003csup id=\"fnref:9\"\u003e\u003ca href=\"#fn:9\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e9\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref:10\"\u003e\u003ca href=\"#fn:10\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e10\u003c/a\u003e\u003c/sup\u003e. Most operating systems allow device restriction policies to be put in place to block entire classes of unwanted device types\u003csup id=\"fnref:11\"\u003e\u003ca href=\"#fn:11\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e11\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref:12\"\u003e\u003ca href=\"#fn:12\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e12\u003c/a\u003e\u003c/sup\u003e \u003csup id=\"fnref:13\"\u003e\u003ca href=\"#fn:13\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e13\u003c/a\u003e\u003c/sup\u003e. There is however one class that is almost universally whitelisted, the Human Interface Device (HID).\u003c/p\u003e\n\u003cp\u003eThe parts used in the device are a commodity USB-based microcontroller development board, a few jumper wires, GSM phone module, an internal USB cable destructively salvaged from an old computer chassis, and a few spare micro-USB cables.  Each part had been acquired by ANSTO through it\u0026rsquo;s normal business activities or for other purposes. In particular the USB development board, a Teensy 3.1 \u003csup id=\"fnref:14\"\u003e\u003ca href=\"#fn:14\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e14\u003c/a\u003e\u003c/sup\u003e had been purchased by ANSTO previously for a security awareness exercise and the GSM module, an Adafruit FONA \u003csup id=\"fnref:15\"\u003e\u003ca href=\"#fn:15\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e15\u003c/a\u003e\u003c/sup\u003e for evaluating its use as part of an SMS alerting system. The theory of operation behind the device is it would use a spare USB header in place on a workstation or server mainboard and be entirely concealed inside the chassis. For the device to be introduced covertly a scenario where a compromised supply chain allowed a malicious adversary to intercept the delivery of a pre-built chassis to a facility was conceived. Further due to an insufficient security culture the chassis would be considered trusted by the facility and configured in such that is was operating with a permanently active login session.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTABLE I: CONNECTING THE TEENSY AND FONA\u003c/strong\u003e\u003c/p\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eFONA PIN\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eTeensy PIN\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eVIO\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e3.3V\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eTX\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003ePin0\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eRX\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003ePin1\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eKey\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eGND\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eRST\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003ePin4\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eGND\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAGND\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003eThe Teensy was connected to the FONA using the onboard UART at 3.3V TTL level with the cable configuration as shown in TABLE I. After cabling all configuration was done on the Teensy through the Arduino IDE. While directly interfacing with the SIM800 chip on the FONA is possible \u003csup id=\"fnref:16\"\u003e\u003ca href=\"#fn:16\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e16\u003c/a\u003e\u003c/sup\u003e Adafruit maintains a library that provides a helpful level of abstraction \u003csup id=\"fnref:17\"\u003e\u003ca href=\"#fn:17\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e17\u003c/a\u003e\u003c/sup\u003e. In the setup phase the teensy creates the serial connection between itself and the FONA and does some initial checks to ensure that an IMEI can be read from a SIM card indicating there is indeed a SIM card present. An optional define macro taking a PIN code for the SIM card as a string allows the teensy to unlock the SIM prior to entering the loop phase. For ease of use at the end of the setup phase assuming setup has been completed successfully the Teensy will activate a LED to show the logic has progressed to the main loop.\u003c/p\u003e\n\u003cp\u003eWithin the loop the Teensy continually polls the FONA for the arrival of new SMS messages and processes them through a parsing function. The message is then deleted and the program goes into a delay before entering the execution loop again. In order for the device to be successful in introducing advanced exploits an interpreter was written for Duckyscript the scripting language from the USB Rubber Ducky project, an established HID penetration testing platform \u003csup id=\"fnref:18\"\u003e\u003ca href=\"#fn:18\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e18\u003c/a\u003e\u003c/sup\u003e. Duckyscript allows complex combinations of keyboard commands to be sent to the host system and has a suite of existing payloads \u003csup id=\"fnref:19\"\u003e\u003ca href=\"#fn:19\" class=\"footnote-ref\" role=\"doc-noteref\"\u003e19\u003c/a\u003e\u003c/sup\u003e and tools that are fully supported by the interpreter. In addition to fully realise the capabilities of the Teensy a number of extended commands have been developed to allow control of all mouse input functions.\u003c/p\u003e\n\u003cp\u003e\u003cimg class=\"content-image\" src=\"/images/breaking-data-diode_bypass.webp\" width=\"628\" height=\"308\" alt=\"Method of Bypassing a Diode\" loading=\"lazy\" decoding=\"async\"\u003e\n\n\u003cem\u003eFIG. 5. An adversary with bidirectional communication across a data diode\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThe realised scenario is shown in FIG. 5. where a malicious adversary is able to use the proposed covert device to introduce foreign input onto the highside network therefore compromising it\u0026rsquo;s integrity. An advanced adversary that has also initiated a full compromise of the less protected lowside system could use the proposed device as an input channel into the network and then after a persistent attack would be able to achieve full bidirectional communication by exploiting the data diode itself as an output channel. While this is an additional capability allowed by the output channel provided by the data diode the same vector behind compromising the integrity of the more protected segment, the introduction of foreign input would apply to completely air gapped systems.\u003c/p\u003e\n\u003ch1 id=\"6-conclusion\"\u003e6. Conclusion\u003c/h1\u003e\n\u003cp\u003eAn optical fibre data diode is a provably secure device for its purpose, protecting a single link from all communication in a single direction. An optical fibre diode is incredibly simple to construct and prove with a high level of assurance that it will perform its intended function.  The complexities in communicating data over a diode are easily addressed by end users by implementing a transfer mechanism over a higher layer in the OSI model allowing greater flexibility and support. Further there do exist robust application protocols that can be leveraged to provide the unidirectional communication without necessitating large development costs. A successful implementation of a data diode does not itself remove the risk of foreign input entering the protected segment. Similar to an air gapped network a robust security culture and computer security program complementing the deployment of a data diode is required to ensure the desired protection is achieved.\u003c/p\u003e\n\u003ch1 id=\"7-technical-resources\"\u003e7. Technical Resources\u003c/h1\u003e\n\u003cp\u003eAll configuration and software produced as part of this paper can be found as technical resources within the following github repositories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitcdh/diode-switch-config\"\u003ehttps://github.com/mitcdh/diode-switch-config\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitcdh/ducksy-sms\"\u003ehttps://github.com/mitcdh/ducksy-sms\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1 id=\"references\"\u003eReferences\u003c/h1\u003e\n\u003cdiv class=\"footnotes\" role=\"doc-endnotes\"\u003e\n\u003chr\u003e\n\u003col\u003e\n\u003cli id=\"fn:1\"\u003e\n\u003cp\u003eDUROS, E., et al., \u0026ldquo;A Link-Layer Tunneling Mechanism for Unidirectional Links\u0026rdquo;, RFC3077, (2001), \u003ca href=\"https://tools.ietf.org/html/rfc3077\"\u003ehttps://tools.ietf.org/html/rfc3077\u003c/a\u003e.\u0026#160;\u003ca href=\"#fnref:1\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:2\"\u003e\n\u003cp\u003eSTEVENS, M. W., POPE, M,. \u0026ldquo;Data Diodes\u0026rdquo;, DSTO, Technical Report DSTO-TR-0209, (1999)\u0026#160;\u003ca href=\"#fnref:2\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:3\"\u003e\n\u003cp\u003eSTEVENS, M. W., \u0026ldquo;An Implication of an Optical Data Diode\u0026rdquo;, DSTO, Technical Report DSTO-TR-0785, (1999)\u0026#160;\u003ca href=\"#fnref:3\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:4\"\u003e\n\u003cp\u003eBIBA, K.J., \u0026ldquo;Integrity Considerations for Secure Computer Systems\u0026rdquo;, \u003ca href=\"http://seclab.cs.ucdavis.edu/projects/history/papers/biba75.pdf\"\u003eMTR-3153\u003c/a\u003e, The MITRE\u003ca href=\"http://en.wikipedia.org/wiki/Mitre_Corporation\"\u003e Corporation\u003c/a\u003e, (1977).\u0026#160;\u003ca href=\"#fnref:4\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:5\"\u003e\n\u003cp\u003eBELL, DAVID ELLIOTT AND LAPADULA, LEONARD J., \u003ca href=\"http://www.albany.edu/acc/courses/ia/classics/belllapadula1.pdf\"\u003e\u0026ldquo;Secure Computer Systems: Mathematical Foundations\u0026rdquo;\u003c/a\u003e, MITRE Corporation, (1973).\u0026#160;\u003ca href=\"#fnref:5\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:6\"\u003e\n\u003cp\u003eINTERNATIONAL ATOMIC ENERGY AGENCY, Computer Security at Nuclear Facilities, IAEA Nuclear Security Series No. 17, IAEA, Vienna (2011).\u0026#160;\u003ca href=\"#fnref:6\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:7\"\u003e\n\u003cp\u003eREED, IRVING S., CHEN, XUEMIN., \u0026ldquo;Error-Control Coding for Data Networks\u0026rdquo;, Boston, MA, (1999)\u0026#160;\u003ca href=\"#fnref:7\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:8\"\u003e\n\u003cp\u003eSOLLINS, K., \u0026ldquo;THE TFTP PROTOCOL (REVISION 2)\u0026rdquo;, STD33, RFC1350, (1992), \u003ca href=\"https://tools.ietf.org/html/rfc1350\"\u003ehttps://tools.ietf.org/html/rfc1350\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:8\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:9\"\u003e\n\u003cp\u003eMATROSOV, A., RODIONOV, E., HARLEY, D., MALCHO, J., \u0026ldquo;Stuxnet Under the Microscope\u0026rdquo;, ESET, (2011).\u0026#160;\u003ca href=\"#fnref:9\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:10\"\u003e\n\u003cp\u003eSIEMENS., \u0026ldquo;SIMATIC WinCC / SIMATIC PCS 7: Information concerning Malware / Virus / Trojan\u0026rdquo;, Product note (2011).\u0026#160;\u003ca href=\"#fnref:10\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:11\"\u003e\n\u003cp\u003eRED HAT, INC., \u0026ldquo;How to disable USB storage devices on Red Hat Enterprise Linux?\u0026rdquo;, Knowledgebase Article (2014), \u003ca href=\"https://access.redhat.com/solutions/18978\"\u003ehttps://access.redhat.com/solutions/18978\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:11\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:12\"\u003e\n\u003cp\u003eMICROSOFT DEVELOPER NETWORK., \u0026ldquo;Step-By-Step Guide to Controlling Device Installation Using Group Policy\u0026rdquo;, Knowledgebase Article (2007), \u003ca href=\"https://msdn.microsoft.com/en-us/library/bb530324.aspx\"\u003ehttps://msdn.microsoft.com/en-us/library/bb530324.aspx\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:12\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:13\"\u003e\n\u003cp\u003eMICROSOFT DEVELOPER NETWORK., \u0026ldquo;System-Defined Device Setup Classes Available to Vendors\u0026rdquo;, Knowledgebase Article, \u003ca href=\"https://msdn.microsoft.com/en-us/library/windows/hardware/ff553426%28v=vs.85%29.aspx\"\u003ehttps://msdn.microsoft.com/en-us/library/windows/hardware/ff553426%28v=vs.85%29.aspx\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:13\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:14\"\u003e\n\u003cp\u003eSTOFFREGEN, P. COON, R., \u0026ldquo;Teensy 3.1\u0026rdquo;, \u003ca href=\"https://www.pjrc.com/teensy/teensy31.html\"\u003ehttps://www.pjrc.com/teensy/teensy31.html\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:14\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:15\"\u003e\n\u003cp\u003eADAFRUIT INDUSTRIES., \u0026ldquo;Adafruit FONA - Mini Cellular GSM Breakout - SMA Version - V1\u0026rdquo;, \u003ca href=\"https://www.adafruit.com/products/1963\"\u003ehttps://www.adafruit.com/products/1963\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:15\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:16\"\u003e\n\u003cp\u003eSIMCOM, \u0026ldquo;SIM 800 Series AT Commands Module\u0026rdquo; (2013)\u0026#160;\u003ca href=\"#fnref:16\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:17\"\u003e\n\u003cp\u003eFRIED, L., et al., \u0026ldquo;Adafruit FONA Library\u0026rdquo;, (Github Repository), \u003ca href=\"https://github.com/adafruit/Adafruit_FONA_Library\"\u003ehttps://github.com/adafruit/Adafruit_FONA_Library\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:17\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:18\"\u003e\n\u003cp\u003eUSB RUBBER DUCKY CONTRIBUTORS., \u0026ldquo;Duckyscript\u0026rdquo;, (Github Wiki), \u003ca href=\"https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript\"\u003ehttps://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:18\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli id=\"fn:19\"\u003e\n\u003cp\u003eUSB RUBBER DUCKY CONTRIBUTORS., \u0026ldquo;Payloads\u0026rdquo;, (Github Wiki), \u003ca href=\"https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads\"\u003ehttps://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads\u003c/a\u003e\u0026#160;\u003ca href=\"#fnref:19\" class=\"footnote-backref\" role=\"doc-backlink\"\u003e\u0026#x21a9;\u0026#xfe0e;\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/div\u003e\n","content_text":"This post has been adapted verbatim from a paper accepted and presented during International Conference on Computer Security in a Nuclear World: Expert Discussion and Exchange titled ‘Building and Breaking the Protection Provided by an Optical Data Diode Using Spare Parts’ authored by myself Daniel Gleeson, and Ben Donovan.\nAbstract This paper presents an overview of the construction and implementation of unidirectional networking through an optical fibre data diode while demonstrating post-implementation issues that need to be addressed to ensure the desired protection is provided. This particular topic was chosen due to its relevance for nuclear facility operators. Nuclear Security Series 17 highly encourages no inwards data flow of any kind to Level 1 systems. Technical solutions are provided on implementing select applications that require stateful network protocols over the constructed unidirectional link. The paper stresses that there are further issues around implementing a data diode that are shared with both entirely connected and disconnected networks. Where a lack of a robust security culture on the more protected segment can lead to a compromise of the additional integrity protection that the data diode provides. Throughout detail is provided that is accessible and easily understandable to various skill levels in networking, programming, and control system design; empowering operators and practitioners with a greater understanding of the optical diode technology and its implementation. The design of the optical fibre diode, the software created in overcoming the requirement for stateful networking, and details of a covert device allowing foreign input will all be provided as technical resources. Where possible physical components are constructed with spare parts that would likely be found in a converged Industrial Control and Information Technology environment.\n1. Introduction When there are two networks or devices that require different levels of protection employing a security risk management perspective they would be entirely disconnected forming what is termed as an “air gap”.\nA unidirectional link describes a network link that allows data to flow between two devices in only a single direction. Techniques for unidirectional networking can be seen in terrestrial broadcast television and satellite downlinks where the communications infrastructure is only capable of passing data in a single direction 1. When a unidirectional link is implemented as part of a security gateway between two systems of differing protection requirements a demonstrable one way connection can be achieved. This is an enabling mechanism to allow data to flow in a single direction while still providing an effective air gap for the other direction of data flow across the link.\nA modern unidirectional link termed a “Data Diode” implemented through optical fibre first originated in two 1999 technical reports published by Australia’s Defence Science and Technology Organisation (DSTO) entitled “Data Diodes” 2 and “Implications of an Optical Data Diode” 3. The DSTO papers outline two modes of operation for a data diode that depend on the inherent risks to the systems, processes, and information on the more secure side. Where confidentiality is the primary concern a link can be created to allow data to flow into the more secure network while preventing exfiltration of any information that resides within. Typically employed to separate systems of differing security classification this allows a strict implementation of the Bell-Lapadula model for access control (no read-up, no write-down)4. Alternatively in a mode where Integrity or Availability make up the key risks to a network the unidirectional link is configured in such a way that data is allowed to only flow out of the more secured system. This can then be considered an implementation of the Biba Integrity Model (no write-up, no read-down)5. Of the two the Integrity mode is the most relevant to critical infrastructure. This is supported by the IAEA through NSS 17’s suggestion for Level 1 systems to have no networked data flow of any kind from weaker security levels6.\n2. Purpose The Australian Nuclear Science and Technology Organisation (ANSTO) separates it’s Reactor Control and Management System (RCMS) for the Open Pool Australian Lightwater (OPAL) research reactor from a network housing the detectors and computing infrastructure for the attached Neutron Beam Instrument Facility. Experiments undertaken on these beamlines require data from the RCMS to offset their calculations while the RCMS is a Nuclear Safety contributing system and therefore has inbound data flow restrictions. To address this during commissioning of the reactor, a gateway was created between the two networks to achieve unidirectional networking through a high assurance optical fibre data diode.\nDuring a recent upgrade project a requirement to engineer an equivalent setup for a lab environment emerged to assist in the development a new transfer mechanism. It was broken down into three phases: construction of the diode following the principles outlined in the DSTO paper, development of software to proxy information across the diode, and a smaller side project to demonstrate a credible security threat to the RCMS.\n3. Building a Unidirectional Link It is possible to create a unidirectional link across any medium that separates the cable medium for transmission and receipt of data. This approach can be applied to Ethernet running over twisted pair cabling up to a standard of 100BASE-TX, later standards have moved to a technology that transmits and receives on all pairs simultaneously. When implementing such a link it is important to sever every cable besides the desired transmit pair as any remaining connection could covertly be used to subvert the provided protection via a return return path.\nThere is also a major disadvantage with this approach, in an off the shelf network card the pins in physical transceiver are not necessarily exclusive to a transmit or receive function and there is no way of visually inspecting this. The transceiver can determine which cable pairs are assigned to transmit and receive before the media access controller, this is observable through the application of Auto Medium Dependent Interface Crossover (Auto MDI-X) in modern network interfaces.\nFIG. 1. PCB of a GBIC\nTransceivers used in two-cable optical fibre networking on the other hand do not carry this disadvantage. Taking apart a pluggable transceiver shows an observable visual distinction between the modulator and light source on the transmit side and the photo sensor and demodulator on the receive side. Both channels are then able to pass traffic, independently across separate cables utilising dedicated, physically isolated circuitry, where FIG. 1. shows a clear electrical separation on the circuit board between onboard transmit and receiving functions.\nBuilding on this an optical data diode is constructed by removing one of the fibre cables between a pair of transceivers. The remaining cable depends on the chosen protection model, for integrity or availability the transmit on the more protected segment’s interface will be connected to the receive on the destination less protected segment’s interface. Whichever side hosts the transmit role in the optical diode needs the receive side cabled to a the transmit of another powered transceiver so a carrier signal is received, a requirement before the link will be considered up and transmission to the other side of the diode can occur. This additional transceiver should be physically located on or powered by a chassis on the transmission side of the diode to avoid the potential of creating a secondary channel and breaking the provided protection. This model also ensures the absence of data being transmitted across the carrier signal providing interface by maintaining the integrity of an entire data path.\nFIG. 2. Logical network interconnection topology\nRather than a direct connection between two servers with fibre network interface cards the diode was built between existing lab networking equipment as exhibited in FIG. 2. This model employed, while providing an equivalent level of protection, also allowed utilisation of a dedicated and flexible networking stack independent of the sending and receiving systems. While not a true security gateway this flexibility allowed the development and testing of multiple approaches to achieving the desired unidirectional networking simultaneously.\nEach side of the data diode was configured as an interface on subnets respectively representing the transmitting and receiving networks split by the implementation of the diode. There were a number of networking technologies supported by the hardware that needed to be configured in a specific manner to ensure full support for caveats of implementing a data diode.\nModern fibre interfaces support speed negotiation. Due to the nature of the diode preventing bidirectional communication this negotiation will fail to complete. While speed negotiation is enabled and not complete the link is unable to become active. Therefore to implement the diode speed negotiation needed to be disabled. The particular hardware used supported a feature called unidirectional link detection designed to shut interfaces where a unidirectional link is detected in order to prevent looping. As a diode is by definition a unidirectional link this protocol requires disabling. Static Address Resolution Protocol (ARP) entries were created on the protected transmitting segment so communication could be appropriately directed to devices on the less protected receiving segment. 4. Transfer Across a Data Diode To understand the communication across the data diode will be achieved it is best to reference the OSI model. This model splits the communication up into seven encapsulated layers which each facilitate part of the communication. As a transmission occurs it passes from the sender’s application layer down to physical where transmission occurs. The transmission then reaches the receiver and progresses back up the layers.\nFIG. 3. The OSI model showing conceptual stages within the data transfer process.\nWithin a standard network, state is typically maintained within a protocol such as the Transmission Control Protocol (TCP). TCP is able to achieve a highly reliable transmission through techniques such as SYN/ACK numbering and sliding windows, operates on the transport layer, and underpins most common protocols operating at higher OSI layers. Due to the nature of the data diode, stateful protocols are impossible to implement. The receiver isn’t able to acknowledge receipt of data or complete a handshake to initiate communication.\nFIG. 4. The TCP handshake, demonstrating required bidirectional communication in a TCP session.\nAnother transport protocol, User Datagram Protocol (UDP) is capable of working over this type of link as it is unidirectional and stateless, it has no handshake requirement to start transmission and doesn’t acknowledge receipt of data. This however means it provides no solid guarantees to the successful transfer and ordering of data. There are limited options available on each endpoint as each must execute in isolation. UDP’s primitive environment for transmission shouldn’t be entirely relied upon and on its own it should be assumed unreliable.\nOne approach to increasing reliability is by implementing extra functionality within another layer of the OSI stack, typically the Application layer. Not all techniques are achievable given the unidirectional link however even implementing basic sequence numbering helps to reconstruct data, detect errors and track communication. A common technique is to include a checksum with the transfer, which can detect errors and trigger a retransmission. Due to the unidirectional link there is an inability to request retransmissions so this gives us no greater reliability. Instead implementing Erasure coding techniques such as Reed Solomon can provide the desired functionality7. This technology allows detection and most importantly, correction of certain data errors without requiring a retransmission. While this can dramatically improve reliability, the system still has to be viewed as a “best-effort” transfer.\nNetcat was initially investigated as an easy way to implement communications between hosts. It already includes some of the functionality required such as send / receive mode and protocol selection. Netcat however was missing key requirements such as datagram sequencing and transfer termination which we would’ve had to implement in another application sitting behind it. It was decided that bundling the sequencing, erasure coding and other plugins into the application would provide more fine grained control over the transfer.\nThe Trivial File Transfer Protocol (TFTP)8 already includes this sequencing and is seen as a clear and configurable platform to build with. Many implementations are available online written in high level languages which make it easy to extend for this particular use case. TFTP still utilises bidirectional communication to provide an acknowledgement mechanism as transmission occurs during session creation and periodically as a lock-step mechanism to ensure each packet is transferred correctly. Both of these responses can be engineered out and are not required for a successful data transfer apart from one small issue. The initial response by the receiver specifies an ephemeral data port for the transfer to be directed to. Instead in the unidirectional implementation the requirement for this response has been removed. The sender is considered to control the state of a set of ports that are reserved on the receiver and specifies the port it intends to use by declaring it as the source port in the initial UDP packet that contains the write request. To facilitate adding modules to process arbitrary protocols a syntax for the filename field in TFTP has been defined that can trigger the receiver to forward the traffic to a registered plugin.\n5. Breaking the Protection Before attempting to break the protection provided by the data diode it was important to first consider what we aim to achieve, for a diode operating in a confidentiality-protecting mode this would be the exfiltration of data from the protected segment. An integrity protecting diode is different; here the focus is on preventing foreign input from entering a system.\nWith such an input channel a capable malicious adversary could compromise the integrity assurance of the network that the diode provides to the risk management process. Such a channel would require a device of some sort that is able to provide remote input onto the protected network. In designing such a device sample routine engineering processes were considered and analysed in order to identify a potential vector for compromise that highlighted the idea that peripheral devices will be introduced to Level 1 and 2 systems throughout their lifetime. Each introduction of a peripheral device carries with it a risk. Take the case of USB storage devices which are credited with the spread of the Stuxnet worm to isolated networks resulting in a vendor issued advisory notice recommending customers avoid their use9 10. Most operating systems allow device restriction policies to be put in place to block entire classes of unwanted device types11 12 13. There is however one class that is almost universally whitelisted, the Human Interface Device (HID).\nThe parts used in the device are a commodity USB-based microcontroller development board, a few jumper wires, GSM phone module, an internal USB cable destructively salvaged from an old computer chassis, and a few spare micro-USB cables. Each part had been acquired by ANSTO through it’s normal business activities or for other purposes. In particular the USB development board, a Teensy 3.1 14 had been purchased by ANSTO previously for a security awareness exercise and the GSM module, an Adafruit FONA 15 for evaluating its use as part of an SMS alerting system. The theory of operation behind the device is it would use a spare USB header in place on a workstation or server mainboard and be entirely concealed inside the chassis. For the device to be introduced covertly a scenario where a compromised supply chain allowed a malicious adversary to intercept the delivery of a pre-built chassis to a facility was conceived. Further due to an insufficient security culture the chassis would be considered trusted by the facility and configured in such that is was operating with a permanently active login session.\nTABLE I: CONNECTING THE TEENSY AND FONA\nFONA PIN Teensy PIN VIO 3.3V TX Pin0 RX Pin1 Key GND RST Pin4 GND AGND The Teensy was connected to the FONA using the onboard UART at 3.3V TTL level with the cable configuration as shown in TABLE I. After cabling all configuration was done on the Teensy through the Arduino IDE. While directly interfacing with the SIM800 chip on the FONA is possible 16 Adafruit maintains a library that provides a helpful level of abstraction 17. In the setup phase the teensy creates the serial connection between itself and the FONA and does some initial checks to ensure that an IMEI can be read from a SIM card indicating there is indeed a SIM card present. An optional define macro taking a PIN code for the SIM card as a string allows the teensy to unlock the SIM prior to entering the loop phase. For ease of use at the end of the setup phase assuming setup has been completed successfully the Teensy will activate a LED to show the logic has progressed to the main loop.\nWithin the loop the Teensy continually polls the FONA for the arrival of new SMS messages and processes them through a parsing function. The message is then deleted and the program goes into a delay before entering the execution loop again. In order for the device to be successful in introducing advanced exploits an interpreter was written for Duckyscript the scripting language from the USB Rubber Ducky project, an established HID penetration testing platform 18. Duckyscript allows complex combinations of keyboard commands to be sent to the host system and has a suite of existing payloads 19 and tools that are fully supported by the interpreter. In addition to fully realise the capabilities of the Teensy a number of extended commands have been developed to allow control of all mouse input functions.\nFIG. 5. An adversary with bidirectional communication across a data diode\nThe realised scenario is shown in FIG. 5. where a malicious adversary is able to use the proposed covert device to introduce foreign input onto the highside network therefore compromising it’s integrity. An advanced adversary that has also initiated a full compromise of the less protected lowside system could use the proposed device as an input channel into the network and then after a persistent attack would be able to achieve full bidirectional communication by exploiting the data diode itself as an output channel. While this is an additional capability allowed by the output channel provided by the data diode the same vector behind compromising the integrity of the more protected segment, the introduction of foreign input would apply to completely air gapped systems.\n6. Conclusion An optical fibre data diode is a provably secure device for its purpose, protecting a single link from all communication in a single direction. An optical fibre diode is incredibly simple to construct and prove with a high level of assurance that it will perform its intended function. The complexities in communicating data over a diode are easily addressed by end users by implementing a transfer mechanism over a higher layer in the OSI model allowing greater flexibility and support. Further there do exist robust application protocols that can be leveraged to provide the unidirectional communication without necessitating large development costs. A successful implementation of a data diode does not itself remove the risk of foreign input entering the protected segment. Similar to an air gapped network a robust security culture and computer security program complementing the deployment of a data diode is required to ensure the desired protection is achieved.\n7. Technical Resources All configuration and software produced as part of this paper can be found as technical resources within the following github repositories:\nhttps://github.com/mitcdh/diode-switch-config https://github.com/mitcdh/ducksy-sms References DUROS, E., et al., “A Link-Layer Tunneling Mechanism for Unidirectional Links”, RFC3077, (2001), https://tools.ietf.org/html/rfc3077. ↩︎\nSTEVENS, M. W., POPE, M,. “Data Diodes”, DSTO, Technical Report DSTO-TR-0209, (1999) ↩︎\nSTEVENS, M. W., “An Implication of an Optical Data Diode”, DSTO, Technical Report DSTO-TR-0785, (1999) ↩︎\nBIBA, K.J., “Integrity Considerations for Secure Computer Systems”, MTR-3153, The MITRE Corporation, (1977). ↩︎\nBELL, DAVID ELLIOTT AND LAPADULA, LEONARD J., “Secure Computer Systems: Mathematical Foundations”, MITRE Corporation, (1973). ↩︎\nINTERNATIONAL ATOMIC ENERGY AGENCY, Computer Security at Nuclear Facilities, IAEA Nuclear Security Series No. 17, IAEA, Vienna (2011). ↩︎\nREED, IRVING S., CHEN, XUEMIN., “Error-Control Coding for Data Networks”, Boston, MA, (1999) ↩︎\nSOLLINS, K., “THE TFTP PROTOCOL (REVISION 2)”, STD33, RFC1350, (1992), https://tools.ietf.org/html/rfc1350 ↩︎\nMATROSOV, A., RODIONOV, E., HARLEY, D., MALCHO, J., “Stuxnet Under the Microscope”, ESET, (2011). ↩︎\nSIEMENS., “SIMATIC WinCC / SIMATIC PCS 7: Information concerning Malware / Virus / Trojan”, Product note (2011). ↩︎\nRED HAT, INC., “How to disable USB storage devices on Red Hat Enterprise Linux?”, Knowledgebase Article (2014), https://access.redhat.com/solutions/18978 ↩︎\nMICROSOFT DEVELOPER NETWORK., “Step-By-Step Guide to Controlling Device Installation Using Group Policy”, Knowledgebase Article (2007), https://msdn.microsoft.com/en-us/library/bb530324.aspx ↩︎\nMICROSOFT DEVELOPER NETWORK., “System-Defined Device Setup Classes Available to Vendors”, Knowledgebase Article, https://msdn.microsoft.com/en-us/library/windows/hardware/ff553426%28v=vs.85%29.aspx ↩︎\nSTOFFREGEN, P. COON, R., “Teensy 3.1”, https://www.pjrc.com/teensy/teensy31.html ↩︎\nADAFRUIT INDUSTRIES., “Adafruit FONA - Mini Cellular GSM Breakout - SMA Version - V1”, https://www.adafruit.com/products/1963 ↩︎\nSIMCOM, “SIM 800 Series AT Commands Module” (2013) ↩︎\nFRIED, L., et al., “Adafruit FONA Library”, (Github Repository), https://github.com/adafruit/Adafruit_FONA_Library ↩︎\nUSB RUBBER DUCKY CONTRIBUTORS., “Duckyscript”, (Github Wiki), https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript ↩︎\nUSB RUBBER DUCKY CONTRIBUTORS., “Payloads”, (Github Wiki), https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads ↩︎\n","date_published":"2015-06-04T18:05:55+03:00","id":"https://blog.mitcdh.au/posts/breaking-data-diode/","image":"https://blog.mitcdh.au/images/breaking-data-diode.webp","summary":"Using Spare Parts","tags":["Writing","Nuclear","Technology","Security"],"title":"Building and Breaking the Protection Provided by an Optical Data Diode","url":"https://blog.mitcdh.au/posts/breaking-data-diode/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2014-11-29T14:38:13Z","id":"https://blog.mitcdh.au/posts/training-in-daejeon-korea/","image":"https://blog.mitcdh.au/images/training-in-daejeon-korea.jpg","summary":"","tags":["Album"],"title":"Training in Daejeon, Korea","url":"https://blog.mitcdh.au/posts/training-in-daejeon-korea/"},{"authors":[{"avatar":"https://blog.mitcdh.au/images/profile-about.webp","name":"Mitchell Hewes","url":"https://blog.mitcdh.au/about/"}],"content_html":"","content_text":"","date_published":"2014-08-31T17:49:55Z","id":"https://blog.mitcdh.au/posts/hiking-the-south-island-new-zealand/","image":"https://blog.mitcdh.au/images/hiking-the-south-island-new-zealand.jpg","summary":"Boy meets girl on bus. Next weekend, they go backpacking for two weeks in another country.","tags":["Album"],"title":"Hiking the South Island, New Zealand","url":"https://blog.mitcdh.au/posts/hiking-the-south-island-new-zealand/"}],"title":"blog.mitcdh","version":"https://jsonfeed.org/version/1.1"}