UNCLASSIFIED Homeland Security 2016 TRB Annual Meeting Cyber Risk Management CAPT Verne Gifford (CG-5PC) 1.

Slides:



Advertisements
Similar presentations
1 Title Goes Here Canadas Maritime Security Threats and Responses.
Advertisements

United States Coast Guard Marine Safety, Security, and Stewardship 1 U.S. Coast Guard Regulations “Making a difference” 1 Jeff Lantz Director, Commercial.
Lisanne Sison Director ERM Bickmore
NOTE: To change the image on this slide, select the picture and delete it. Then click the Pictures icon in the placeholde r to insert your own image. Cybersecurity.
Copyright © 2014 American Water Works Association Water Sector Approach to Process Control System Security.
What is Insider Threat? “Potential damage to the interests of an organization by a person(s) who is regarded, falsely, as loyally working for or on behalf.
David A. Brown Chief Information Security Officer State of Ohio
National Infrastructure Protection Plan
The U.S. Coast Guard’s Role in Cybersecurity
DHS, National Cyber Security Division Overview
National Protection and Programs Directorate Department of Homeland Security The Office of Infrastructure Protection Cybersecurity Brief [Date of presentation]
Framework for Improving Critical Infrastructure Cybersecurity NIST Feb 2014.
National Space-Based Positioning, Navigation, and Timing (PNT) Federal Advisory Board DHS Challenges & Opportunities Captain Curtis Dubay, P.E. Department.
EMI Higher Education Symposium 5 June 2014
Progressiveness A Vital Principle in Emergency Management.
PPA 573 – Emergency Management and Homeland Security Lecture 9b - Department of Homeland Security Strategic Plan.
Passenger Vessel Safety Specialist Paul Culver Seventh Coast Guard District.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Maintaining Essential Business and Community Services During a Pandemic Paul R. Patrick, Director Bureau of Emergency Medical Services Utah Department.
Marine Industry Day 2015 Sector Command Center (24 hours): (504) National Response Center: Website:
Part of a Broader Strategy
Jeffery Graviet Emergency Services Coordinator, Salt Lake County Chairperson, Salt Lake Urban Area Working Group.
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
Basics of OHSAS Occupational Health & Safety Management System
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
Seán Paul McGurk National Cybersecurity and Communications
A Proposed Risk Management Regulatory Framework Commissioner George Apostolakis Presented at the Organization of Agreement States 2012 Annual Meeting Milwaukee,
© 2001 Carnegie Mellon University S8A-1 OCTAVE SM Process 8 Develop Protection Strategy Workshop A: Protection Strategy Development Software Engineering.
Risk Management - the process of identifying and controlling hazards to protect the force.  It’s five steps represent a logical thought process from.
The Building of a Security Exercise Program APEC, Vancouver, September /TPT-WG-28/MEG-SEC/ th APEC Transportation Working Group Meeting.
IAEA International Atomic Energy Agency IAEA Nuclear Security Programme Enhancing cybersecurity in nuclear infrastructure TWG-NPPIC – IAEA May 09 – A.
Security Professional Services. Security Assessments Vulnerability Assessment IT Security Assessment Firewall Migration Custom Professional Security Services.
Association of Defense Communities June 23, 2015
Critical Infrastructure Protection Overview Building a safer, more secure, more resilient America The National Infrastructure Protection Plan, released.
Critical Infrastructure Protection: Program Overview
Dr. Charles W. Beadling Central Asia Regional Health Security Conference April 2012 Garmisch-Partenkirchen, Germany.
Homeland Security UNCLASSIFIED United States Coast Guard Office of Port and Facility Compliance (CG-FAC) Cyber Security and the Marine Transportation System.
Homeland Security Grant Program 2015 Process Michelle Hanneken Illinois Emergency Management Agency.
Jerry Cochran Principal Security Strategist Trustworthy Computing Group Microsoft Corporation.
Developing a Security Program. Exercise Plan Develop/Update Plan Review/Revisit Plan.
U. S. Coast Guard Security Maritime Transportation.
Health Emergency Risk Management Pir Mohammad Paya MD, MPH,DCBHD Senior Technical Specialist Public Health in Emergencies Asian Disaster Preparedness Center.
USACE Flood Risk Management and Silver Jackets Workshop Sandra K. Knight, PhD, PE, D.WRE Deputy Associate Administrator for Mitigation, FEMA August.
Tom Lenart & John Field CT DEMHS Region 2.  Department of Emergency Services and Public Protection (DESPP)  Commission on Fire Prevention and Control.
Homeland Security UNCLASSIFIED Coast Guard Cyber Strategy Awareness Training.
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
Protection of Transportation Infrastructure from Cyber Attacks EXECUTIVE BRIEFING.
Security and Resilience Pat Looney Brookhaven National Laboratory April 2016.
Coast Guard Cyber Command
Program Overview and 2015 Outlook Finance & Administration Committee Meeting February 10, 2015 Sheri Le, Manager of Cybersecurity RTD.
November 19, 2002 – Congress passed the Homeland Security Act of 2002, creating a new cabinet-level agency DHS activated in early 2003 Original Mission.
Business Continuity Planning 101
Cyber Security Phillip Davies Head of Content, Cyber and Investigations.
Risks and Hazards to Consider Unit 3. Visual 3.1 Unit 3 Overview This unit describes:  The importance of identifying and analyzing possible hazards that.
Chris Lintern Co-operative Financial Services
Disaster and Emergency Planning
Cyber Security Enterprise Risk Management: Key to an Organization’s Resilience Richard A. Spires CEO, Learning Tree International Former CIO, IRS and.
and Security Management: ISO 28000
U.S. COAST GUARD CYBERSECURITY POLICY and CYBERSECURITY PLANNING
USCG Roles & Responsibilities During a Ship Fire
United States Coast Guard
Know Your Revised Alternate Security Program (ASP) Jen Wilk
Cyber defense management
I have many checklists: how do I get started with cyber security?
Chapter 7: RISK ASSESSMENT, SECURITY SURVEYS, AND PLANNING
Cybersecurity ATD technical
Workshop A: Understanding and Implementation Decisions around the NIST Cybersecurity Framework CyberSat Summit November 16, 2018.
Cyber Security in a Risk Management Framework
Presentation transcript:

UNCLASSIFIED Homeland Security 2016 TRB Annual Meeting Cyber Risk Management CAPT Verne Gifford (CG-5PC) 1

UNCLASSIFIED Homeland Security “THERE WERE QUESTIONS FROM THE AUDIENCE ABOUT TIMELINES AND INCENTIVES THAT I’D LIKE TO ADDRESS. THE COAST GUARD JUST RECENTLY CONDUCTED A STUDY ABOUT THE COST BURDEN TO INDUSTRY OF ALL THE REGULATIONS THAT WE HAVE PUBLISHED SINCE WE FOUND THAT 88% OF THE ENTIRE COST BURDENS OF ALL REGULATIONS, OVER ALL THOSE YEARS, WERE DUE TO TWO REGULATIONS, OPA 90 AND MTSA. BOTH OF THESE REGULATIONS FOLLOWED PREDICTABLE DISASTERS. THE LESSON LEARNED SHOULD BE THAT WE SHOULD NOT WAIT FOR AN INCIDENT TO OCCUR THAT WILL MAKE US MOVE FORWARD ON REACTIVE, MORE EXPENSIVE, REGULATIONS; WE NEED TO BE PROACTIVE IN APPROACHING THIS. WE ARE HERE TO HAVE A DISCUSSION WITH INDUSTRY SO WE CAN DEVELOP A STANDARD TOGETHER, ONE THAT WORKS AND IS REASONABLE IN TERMS OF THE COST BENEFIT. IF WE WAIT UNTIL AN INCIDENT OCCURS, THAT OPPORTUNITY GOES AWAY.” EDDED#T= EDDED#T= EDDED#T= Quote from Rear Admiral Paul Thomas, Assistant Commandant for Prevention Policy

UNCLASSIFIED Homeland Security Ships Then

UNCLASSIFIED Homeland Security Ships Now

UNCLASSIFIED Homeland Security Cargo Operations Then

UNCLASSIFIED Homeland Security Cargo Operations Now

UNCLASSIFIED Homeland Security Why Cyber Risks Matter Loss of PII Loss of intellectual property Direct and indirect financial loss Reputation loss Threat to human life/injury Harm to the marine environment Harm to property Disruptions to the MTS The Coast Guard’s mission is to address these risks – whether from cyber or other sources.

UNCLASSIFIED Homeland Security What Makes Cyber Risk Special? Vulnerability increases with every new device Threat is unlimited Likelihood of an incident is near certain Detection is a factor rapidly growing portion of our total risk exposure

UNCLASSIFIED Homeland Security Cyber Security Risk Model APT/Organized Crime Insider Threats Technical Error MTS Disruption Human life, safety, health SYSTEM FAILURE Environmental PREVENTION/PROTECTIONMEASURES Various Attack Types Impacts MITIGATIONMEASURES Property Damage All activities must take place against a backdrop of the training, education, and policies needed to promote a culture of cyber security Hacktivists Technical controls Policy controls Defense in depth Physical controls Recovery & Continuity of Business Planning Manual Back ups Exercises & Contingency Plans Notifications & Communications

UNCLASSIFIED Homeland Security United States Coast Guard Cyber Strategy

UNCLASSIFIED Homeland Security Cyber Strategy Three Strategic Priorities 1. Defending Cyberspace 2. Enabling Operations 3. Protecting Infrastructure

UNCLASSIFIED Homeland Security  Goal 1. Risk Assessment – Promote Cyber Risk Awareness and Management Cyber Security Assessment & Risk Management Approach 3. Protecting Infrastructure 1. Defending Cyberspace 2. Enabling Operations 3. Protecting Infrastructure

UNCLASSIFIED Homeland Security  Goal 2. Prevention – Reduce Cybersecurity Vulnerabilities in the MTS. 3. Protecting Infrastructure 1. Defending Cyberspace 2. Enabling Operations 3. Protecting Infrastructure

UNCLASSIFIED Homeland Security Ongoing Initiatives Working with NIST to develop MTS Implementation Guide Review existing policy for cyber updates –Drafting NVIC for domestic policy –IMO Proposal Standardize terms/definitions Clarify notification procedures Collaboration with the NIST CCOEEvaluate guidance & tools for industry on risk reduction processes

UNCLASSIFIED Homeland Security NIST Collaboration on MTS Profile 15 By creating a Subsector level Cybersecurity Framework Profile, we are: Minimizing future work by each organization Decreasing the chance that organizations accidentally omit a requirement Reducing errors due to varying interpretations

UNCLASSIFIED Homeland Security Profile: Cybersecurity Framework Component 16 Identify Protect Detect Respond Recover Ways to think about a Profile: A customization of the Core for a given sector, subsector, or organization A fusion of business/mission logic and cybersecurity outcomes An alignment of cybersecurity requirements with operational methodologies A basis for assessment and expressing target state A decision support tool for cybersecurity risk management

UNCLASSIFIED Homeland Security Industry Engagement USCG engaging with multiple industry groups on cyber Held a Public Meeting on January in attendance, 300 watched online. Purpose of outreach is develop guidelines for industry Working with FACA committees to address cyber concerns (NMSAC, NOSAC) Actively involved in industry IT Subcommittees (AAPA, API) Transportation Systems Sector Cyber Working Group (TSS-CWG)

UNCLASSIFIED Homeland Security IMO Proposal In January 2016, submitted a paper to IMO proposing the development of guidelines on managing cyber related risks in the maritime The paper proposed: Establish procedures to identify & evaluate cyber related risks. Establish procedures that to reduce the vulnerabilities through well-recognized practices, including training. Establish procedures to reduce the potential consequences of a cyber attack or incident by promoting recovery and resilience. Establish procedures to incorporate the risk assessment and mitigation process into vessel and port facility security plans, or into other recognized protocols.

UNCLASSIFIED Homeland Security Academia Engagement USCG is collaborating with academia and DHS University Programs: Look to identify Recommended Practices Support Research for Maritime Community Ensure USCG Policies reflect latest knowledge of cyber risks and technology

UNCLASSIFIED Homeland Security Available resources

UNCLASSIFIED Homeland Security QUESTIONS? Thank You for your time! Further inquiries: LCDR Josh Rose