HSGP Funding for Security Efforts Presented by Michele Robinson
Office of Information Security What is the HSGP? U.S. Department of Homeland Security Grant Program Federal funding to help States achieve a variety of prevention and preparedness goals. Supports prevention, mitigation, preparedness, response and recovery activities. January 2008 Office of Information Security
The Cyber Security Piece Many CI/KR sectors are now highly dependent on technology and the Internet Communications and Information Technology Banking and Finance Energy and Water So…just as many are now highly dependent upon robust cyber security as well as physical security 17 Sectors – At one point Cyber Security was identified as its own sector. Now it is recognized that cyber security has a role in many of the other sectors. January 2008 Office of Information Security
Consider Your State Security Requirement Needs Disaster management Planning, training and testing/exercise efforts Information sharing & analysis Communication and collaboration tools Cyber security IDS/IPS, log correlation and forensics tools Physical Security Cameras, alarms, access controls All Computer Hardware/Software Planning, training, testing plans Some items/efforts in these areas may qualify for grant funding. Thing that are not typically funded – staff resources, maintenance costs, etc. Should consider this as 1X funding. January 2008 Office of Information Security
Navigating the Application Process Not always clear Moving target Attend the grant application workshop when offered Will take some effort More so, if you are small agency and do not have a grants management unit with experienced grant writers and support Process is fairly new, and OHS is continually responding to DHS change requirements as well as trying to improve the process for State agencies. Our experience was some frustration with the process as… January 2008 Office of Information Security
Navigating the Application Process Read through all of the DHS/OHS Strategy and Grant Guidance documents Read through additional resource material Determine your eligibility and Agency requirements Obtain Executive Management support Your agency may need to undergo auditing for expenditure of funds, and/or commit some of its own funds to support the effort and/or its ongoing maintenance. Make sure management understands this as part of the decision to go forward with a grant application. January 2008 Office of Information Security
Navigating the Application Process Follow the application instructions exactly Obtain clarification from the OHS State representative as needed Talk with others who have been successful Take your best shot If you don’t succeed…try again! January 2008 Office of Information Security
Tentative Timeline Jan – Program Guidance and Application Kit published by DHS Mar – CA Supplement published by OHS Mar- Apr – CA sub-grantee application workshops Apr – State applications due to DHS Jul – State funding awards announced by DHS Jul – State sub-allocations released by OHS Aug – CA sub-grantee applications due to OHS Oct – CA sub-grantee awards announced by OHS Performance period = 2 to 2.5 years Based on 2007 timeline. January 2008 Office of Information Security
Office of Information Security Our Request Statewide Cyber Security Strategy Technical assistance with gap analyses Development of incident response strategy and plan Cyber Security Training (Sentinel) Development of exercise plans Participation in Cyber Storm II Equipment to support activities Reference materials and other tools for standards and policy development 2007 awards have not yet been announced. We still do not know if we were successful. January 2008 Office of Information Security
Office of Information Security Our Request 2008 Cyber Security Awareness Conference Online Learning Management System for Cyber Security & Privacy Awareness Training Online Incident Reporting System 2007 awards have not yet been announced. We still do not know if we were successful. January 2008 Office of Information Security
Office of Information Security Questions January 2008 Office of Information Security
Office of Information Security DHS Resources DHS – 2007 Homeland Security Grant Program http://www.dhs.gov/xlibrary/assets/grants_st-local_fy07.pdf National Strategy for Homeland Security http://www.dhs.gov/xabout/history/gc_1193938363680.shtm National Strategy to Secure Cyberspace http://www.dhs.gov/xprevprot/programs/editorial_0329.shtm National Strategy for the Physical Protection of Critical Infrastructures and Key Assets http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm National Infrastructure Protection Plan http://www.dhs.gov/xlibrary/assets/NIPP_Plan.pdf January 2008 Office of Information Security
Office of Information Security DHS/OHS Resources DHS-NIPP IT Sector Plan http://www.nascio.org/committees/security/IT_SSP_in_InDesign3.pdf OHS Grants Management Home page http://www.ohs.ca.gov/grants.html OHS FY 07 Grant Information http://www.homeland.ca.gov/grantsinfo2007.html OHS Critical Infrastructure Protection page http://www.ohs.ca.gov/infrastructure.html January 2008 Office of Information Security
Other Recommended Resources IT Sector Coordinating Council (SCC) http://www.it-scc.org/ Critical Infrastructure Partnership Advisory Council http://www.dhs.gov/xprevprot/committees/editorial_0843.shtm National Security Telecommunications Advisory Committee (NASTAC) http://www.ncs.gov/nstac/nstac_publications.html January 2008 Office of Information Security
Other Recommended Resources NASCIO Privacy & Security Committee http://www.nascio.org/committees/security/ US-Cert posting of DHS-NIPP & Cyber Security Fact Sheet http://www.us-cert.gov/reading_room/infosheet_NIPP.pdf January 2008 Office of Information Security