U.S. COAST GUARD CYBERSECURITY POLICY and CYBERSECURITY PLANNING By Paul R. Martin USCG Sector San Francisco 17AUG16 Paul Martin
Government – compromise of sensitive personnel records and secrets Government – compromise of sensitive personnel records and secrets. Business – compromise of client records and proprietary data. Individuals – compromise of personal data and financial loss. 17AUG16 Paul Martin
Government – cyberspace used for espionage Government – cyberspace used for espionage. Business – cyberspace used by criminals. Individuals – cyberspace used by cyber-bullies. 17AUG16 Paul Martin
Coast Guard Strategic Priorities : •. Defending Cyberspace • Coast Guard Strategic Priorities : • Defending Cyberspace • Enabling Operations • Protecting Infrastructure Defending Cyberspace 17AUG16 Paul Martin
The Coast Guard is the Sector Specific Agency responsible for the Maritime Transportation System under the National Infrastructure Protection Plan. This plan directs the Coast Guard to protect the Maritime Transportation System from cyber threats. The Coast Guard promotes Maritime Transportation System by encouraging its members to conduct risk assessments. 17AUG16 Paul Martin
Defense a Three Pronged Approach: 1) Defense a Three Pronged Approach: 1) By identifying and hardening its systems and networks, 2) By understanding and countering cyber threats, and 3) By increasing operational resilience. 17AUG16 Paul Martin
Operational Goals: 1). To incorporate cyberspace operations Operational Goals: 1) To incorporate cyberspace operations into mission planning and execution, 2) To deliver cyber capabilities that will enhance all Coast Guard missions. 17AUG16 Paul Martin
MTS Protection Goals: 1). Risk Assessment – to promote cyber risk MTS Protection Goals: 1) Risk Assessment – to promote cyber risk awareness and management, and 2) Prevention – to reduce cybersecurity vulnerabilities in the MTS. 17AUG16 Paul Martin
Cybersecurity Subcommittee: 1) Cybersecurity Subcommittee: 1) Include all disciplines in membership 2) Information sharing 3) Discuss capabilities 4) Increase awareness 5) Conduct cybersecurity exercises 17AUG16 Paul Martin
Port Security Grant Program (PSGP): One of the six national MTS security priorities is the enhancement of cybersecurity capabilities of port stakeholders. 17AUG16 Paul Martin
The Coast Guard does not require port stakeholders to enact a separate cybersecurity plan. Cybersecurity is viewed as another security threat to the MTS to be considered in port stakeholder security planning. 17AUG16 Paul Martin
FCC Planning Guide (2015) - Privacy & Data FCC Planning Guide (2015) - Privacy & Data - Scams & Fraud - Network Security - Website Security - Email - Mobile Devices - Employees - Facility Security - Operational Sec - Payment Cards - Incidence Actions - Policy Development 17AUG16 Paul Martin
NRECA Risk Recommendations: - People & Policy NRECA Risk Recommendations: - People & Policy - Operational Sec - Insecure Software - Physical Security - Relationships - Network Security - Platform Risks - Application Sec 17AUG16 Paul Martin
NRECA Quick Guide (2011) - Building a Risk Management Program - People and Policy Risks - Process Risks - Technology Risks - Unique Security Requirements for ICS 17AUG16 Paul Martin
Questions? Paul Martin USCG Sector San Francisco 415-399-7327 Paul.r.martin@uscg.mil 09SEP2014 Paul Martin