America’s First National Critical Infrastructure Exercise

Slides:



Advertisements
Similar presentations
NERC Critical Infrastructure Protection Advisory Group (CIP AG) Electric Industry Initiatives Reducing Vulnerability To Terrorism.
Advertisements

Business Continuity Training & Awareness by Sulia Toutai (ANZ)
NOTE: To change the image on this slide, select the picture and delete it. Then click the Pictures icon in the placeholde r to insert your own image. Cybersecurity.
DHS, National Cyber Security Division Overview
National Protection and Programs Directorate Department of Homeland Security The Office of Infrastructure Protection Cybersecurity Brief [Date of presentation]
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
Greg Shaw How do we turn private sector preparedness into an investment rather than a cost of doing.
Unit 8: Tests, Training, and Exercises Unit Introduction and Overview Unit objectives:  Define and explain the terms tests, training, and exercises. 
James Ennis, Department of State, USA ITU-D Question 22/1 Rapporteur.
Part of a Broader Strategy
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
October 27, 2005 Contra Costa Operational Area Homeland Security Strategic and Tactical Planning and Hazardous Materials Response Assessment Project Overview.
Unit 5:Elements of A Viable COOP Capability (cont.)  Define and explain the terms tests, training, and exercises (TT&E)  Explain the importance of a.
“Building sustainable capabilities across all phases of Emergency Management in Kansas through selfless service” KDEM EMPG 2012 OVERVIEW 13 September 2011.
PAR CONFERENCE Homeland Defense A Provider’s Perspective Lessons from TMI Dennis Felty November 15, 2001.
Japanese Government’s Efforts to Address Information Security Issues October, 2007 National Information Security Center (NISC)
BOTSWANA NATIONAL CYBER SECURITY STRATEGY PROJECT
EDS Incident Command System Tabletop Exercise [Exercise Location] [Exercise Date] [Insert Logo Here]
Critical Infrastructure Protection Overview Building a safer, more secure, more resilient America The National Infrastructure Protection Plan, released.
Critical Infrastructure Protection: Program Overview
Homeland Security Grant Program 2015 Process Michelle Hanneken Illinois Emergency Management Agency.
Role for Electric Sector in Critical Infrastructure Protection R&D Presented to NERC CIPC Washington D.C. June 9, 2005 Bill Muston Public Release.
S/L/T Version 1 National Response Framework Overview for Local, Tribal and State Audiences January 22, 2008.
PS Version 1 National Response Framework Overview for Private Sector Audiences January 22, 2008.
MATOC Trial Phase Dec 2008 to Jun 2009 Presentation to the Transportation Planning Board Richard W. Steeg, PE Chair MATOC Steering Committee VDOT Regional.
Proprietary Information of BearingPoint Inc. | Copyright 2005 BearingPoint Inc. All rights reserved. America’s First National Critical Infrastructure Exercise.
SNS Planning Elements Tabletop Exercise [Exercise Location] [Exercise Date] [Insert Logo Here]
Sicherheitsaspekte beim Betrieb von IT-Systemen Christian Leichtfried, BDE Smart Energy IBM Austria December 2011.
SEC 480 assist Expect Success/sec480assistdotcom FOR MORE CLASSES VISIT
Overview Briefing Threat and Hazard Identification and Risk Assessment (THIRA) Presidential Policy Directive 8 / PPD-8: National Preparedness May 2012.
Pipeline Safety Management Systems
Security and resilience for Smart Hospitals Key findings
[Exercise Name] [Date]
BruinTech Vendor Meet & Greet December 3, 2015
Energy Emergency Response in Australia
NATIONAL INCIDENT MANAGEMENT SYSTEM (NIMS)
Iowa Communications Alliance
Crisis management related research at
INFORMATION SECURITY IN ARMENIA: PRESENT STATUS AND TASKS
Controller and Evaluator Briefing
Cyber-crisis exercises
CIRAS FINAL CONFERENCE
Introduction to the Federal Defense Acquisition Regulation
Critical Infrastructure Protection Policy Priorities
Security challenges in the Balkans
Cybersecurity EXERCISE (CE) ATD Scenario intro
Cost of Service Analysis & Rate Design
8 Building Blocks of National Cyber Strategies
Personal Introduction
Protective Security Advisor Program Brief
2017 Health care Preparedness and Response Draft Capabilities
Communication and Consultation with Interested Parties by the RB
Role for Electric Sector in Critical Infrastructure Protection R&D
NERC Critical Infrastructure Protection Advisory Group (CIP AG)
John M. Felker Director, NCCIC.
Continuity Guidance Circular Webinar
Crisis Communications Plan
Cybersecurity ATD technical
Introduction to: National Response Plan (NRP)
Copyright © 2012, Elsevier Inc. All rights Reserved.
Group Meeting Ming Hong Tsai Date :
SOUTH AFRICAN INSURANCE ASSOCIATION
Business Continuity Program Overview
BHF Northern Regional Meeting Johannesburg 27 November 2007
Cyber Security in a Risk Management Framework
A Risk Management Approach to Business Continuity
THE 10 x 10 RESILIENCE FRAMEWORK
Global Platform on Disaster Risk Reduction May 17th 2019
Directions for this Template
Central New York HEALTH EMERGENCY PREPAREDNESS COALITION
Presentation transcript:

America’s First National Critical Infrastructure Exercise Public Release America’s First National Critical Infrastructure Exercise Mr. Mark Gembicki, National Managing Director Critical Infrastructure Resiliency Practice +1 443 756 6161 | Mark.Gembicki@BearingPoint.com

Background To date, no exercise has been conducted by, or for, the Private Sector Government exercises reflect the needs and requirements of the “government” Organization plans, policies, and procedures are not adequately assessed or evaluated in current government exercises dealing with critical infrastructures

Objectives Conduct a private sector exercise Improve relationships among and between key stakeholders Exercise threat scenarios against operational aspects of the electrical grid Provide an infrastructure for organizations to self test and evaluate organizational plans, policies, and procedures Capture performance data to evaluate Critical Infrastructure Resiliency metrics and models – U.S. comparison against other countries Identify key successes and failures Allow for a natural response to scenarios – inaction as well as action is evaluated Consider both socio-economic and national security impact Articulate benefits for preventative security

Overview Funded by the private sector All exercise data will be protected under multi-party non-disclosure agreements Exercise will simulate and maintain perspective between parties All information will be treated as sensitive but unclassified information Participants will play at the location from which they would most likely respond to a cyber event “Functional” exercise- simulating a real time emergency scenario using real people and equipment to test plans and procedures Conducted with a comprehensive “hot wash” and after action analysis report available to all participants

General Framework of Scenario Scenario and General Framework: NCIE will use a common series of scenario and varying perspectives for all players that would a) produce a response, and b) resemble possible attacks directed toward participants The draft framework includes four stages: Stage 1: Situational Awareness - Background information on an emerging threat/vulnerability will be provided to assess organizational incident detection capabilities Stage 2: Crisis Identification - Increased activity will be presented in an escalating fashion Stage 3: Business Impact - Activity will cause a series of business impacts to trigger contingency plans Stage 4: Recovery - Activities should diminish and begin the recovery/restoration process to “normal” conditions

Participant Benefits Participants are provided with a stable framework to exercise and self evaluate organizational capabilities to respond to security events Improved understanding of social, economic, and national security impacts as well as a way to measure them against stakeholder equity and “Duty of Care” principles Opportunity to provide recommendations to the Department of Homeland Securities, Science & Technology directorate for future R&D spending Establish and/or improve relationships for future response situations Ensure plans are accurate, up to date and understood Test core emergency response personnel Identify success/weakness in organizational policies with tangible improvements identified Increased awareness of attacks and effects Participation in follow-on exercises across remaining critical infrastructures

Critical Dates Completion of Final Exercise Plan: September 23, 2005 Concepts and Objectives Meeting Date: May 23, 2005 Initial Plan Completed: June 24, 2005 Initial Planning Conference: July 11, 2005 Mid-Planning Conference: August 30, 2005 Final Planning Conference: September 8, 2005 Exercise Execution Date: October 18-19, 2005 Interim Findings Report: November 7, 2005 After Action Reports: December 16, 2005

NCIE Points of Contact Exercise Director Mr. Mark Gembicki Phone: 1 443 756 6161 Email: Mark.Gembicki@BearingPoint.com Program Manager Mr. Joe Albaugh Phone: 1 410 707 5085 Email: Joe.Albaugh@BearingPoint.com Exercise Advisor Mr. Amit Yoran Phone: 1 703 966 1254 Email: Amit@Yoran.org Program Manager Ms. Jacklyn Blecker Phone: 1 703 965 6134 Email: Jacklyn@Yoran.org