WORKSHOP ON DEVELOPING NATIONAL CRITICAL INFRASTRUCTURE PROTECTION IN SERBIA – ROLE OF PRIVATE SECURITY COMPANIES CoESS and developing critical infrastructure.

Slides:



Advertisements
Similar presentations
Critical Infrastructure Protection Policy Priorities Sara Pinheiro European Commission DG Home Affairs.
Advertisements

Transport EU Maritime Security Policy and legislation Christian DUPONT Deputy Head of Unit for Maritime & Land Transport Security DG Mobility and Transport.
CIRAS PROJECT OVERVIEW
Management’s Role in Information Security V.T. Raja, Ph.D., Oregon State University.
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
Re silience of C ritical I nfrastructure P rotection in E urope (RECIPE) PhD Robert Mikac, RECIPE Project Manager Head of Sector for Civil Protection,
National Disaster Risk Management Program NDRMP Belgrade, March
INSAG DEVELOPMENT OF A DOCUMENT ON HIGH LEVEL SAFETY RECOMMENDATIONS FOR NUCLEAR POWER Milestone Issues: Group C. Nuclear Safety. A. Alonso (INSAG Member)
Security Controls – What Works
Greg Shaw How do we turn private sector preparedness into an investment rather than a cost of doing.
UK Office for Security & Counter Terrorism Future threats and the potential role of the CBRN Action plan in supporting the BTWC Dr Catherine Terry International.
Session 3 – Information Security Policies
Accessibility, Integrity, & Confidentiality: Security Challenges for E-Business Rodney J. Petersen University of Maryland & Educause/Internet2 Security.
Welcome ISO9001:2000 Foundation Workshop.
 Road Safety the European Union Policy Carla Hess European Commission, Directorate General for Mobility & Transport Road.
Steve Jones, SHEQ Manager (Emergency & Critical Services)
Central Asia Regional Health Security Workshop Co-organized with the Command Surgeon, US Central Command and the George C. Marshall European Center for.
Evolving IT Framework Standards (Compliance and IT)
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
HOMELAND SECURITY ADVISORY SYSTEM. Established after the terrorist attacks on America September 11, 2001.
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
Approaches and Mainstreaming of Ecosystem-based Adaptation in Europe International workshop “Mainstreaming an ecosystem based approach to climate change.
Isdefe ISXXXX XX Your best ally Panel: Future scenarios for European critical infrastructures protection Carlos Martí Sempere. Essen.
27 February 2009Conference Warsaw1 Private security from a European perspective: Current situation and possible future trends Eduardo Cobas Urcelay Chairman.
Insurance Institute for Business & Home Safety Even if the worst happens, be prepared to stay.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
Critical Infrastructure Protection Overview Building a safer, more secure, more resilient America The National Infrastructure Protection Plan, released.
Cyber Security & Fraud – The impact on small businesses.
Role for Electric Sector in Critical Infrastructure Protection R&D Presented to NERC CIPC Washington D.C. June 9, 2005 Bill Muston Public Release.
Recent Cyber Attacks and Countermeasures September 2006.
Overview of Integrated Solid Waste Management (ISWM) Presentation made at the European Commission 7 th Framework Programme on Capacity Building Workshop.
Approaches and Mainstreaming of Ecosystem-based Adaptation in Europe International workshop “Mainstreaming an ecosystem based approach to climate change.
THE REPUBLIC OF SLOVENIA MINISTRY OF HIGHER EDUCATION, SCIENCE AND TECHNOLOGY e: Kotnikova 38, 1000 Ljubljana p:
Piemonte Workshop 1 11 September 2006 Paolo Salieri European Commission DG ENTR-H4 Security research in FP7.
Enhancing Partnerships in Support of the Maritime Sector: An Overview of Transport Canada Initiatives 20 th CMC Towboat Conference May 25, 2013.
ENISA efforts for securing European Internet Infrastructure
ITU CoE/ARB 11 th Annual Meeting of the Arab Network for Human Resources 16 – 18 December 2003; Khartoum - Sudan 1 The content is based on New OECD Guidelines.
| 1 European Maritime Day 2010 Gijon Workshop 2.9 Shipping in the Common European Maritime Space Gijón, 21 May 2010 European maritime transport space without.
International Recovery Forum 2014 ~ The Role of Private Sector in Disaster Recovery ~ 21 January 2014 Kobe, Japan Dr Janet L. Asherson THE LINK BETWEEN.
EU activities against cyber crime Radomír Janský Unit - Fight against Organised Crime Directorate-General Justice, Freedom and Security (DG JLS) European.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
What is “national security”?  No longer defined only by threat of arms  It really is the economy  Infrastructure not controlled by the government.
European Commission Directorate General Environment Civil Protection Unit Page 1 Chief Fire Officers’ Association Conference 2004 – Wexford, 5 – 6 May.
Role and Objectives of the Cybersecurity Bureau კიბერუსაფრთხოების ბიურო Cyber Security Bureau Speaker: Mari Malvenishvili GITI 2015.
EU Cybersecurity Strategy and Proposal for Directive on network and information security (NIS) {JOIN(2013) 1 final} {COM(2013) 48 final} Digital Enlightenment.
ISACA Ireland Cyber Security Policy 9 February 2016.
OAS Secretariat for Multidimensional Security CICTE Secretariat Disasters and Critical Infrastructure Protection.
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
EUROPEAN SECURITY POLICY A SNAPSHOT ON SURVEILLANCE AND PRIVACY DESSI WORKSHOP, CPH 24 JUNE 2014 Birgitte Kofod Olsen, Chair Danish Council for Digital.
Business Continuity Management Business Continuity Management (BCM) is a holistic management process that identifies potential impacts that threaten an.
Comparison between the ISM and the ISPS codes A quick comparison.
1 Presented by David Thompson, TIA December 14, 2005 NFPA 1600 and Emergency Communications.
CRITICAL INFRASTRUCTURE RISK ASSESSMENT SUPPORT CIRAS PROJECT OVERVIEW 2nd Stakeholders’ Workshop Aschaffenburg, November, 26th, 2015 Jaime Martín, Project.
IS YOUR ORGANISATION’S INFORMATION SECURE?
Information Security Program
and Security Management: ISO 28000
French Port Cybersecurity Initiative
California Cybersecurity Integration Center (Cal-CSIC)
CIRAS FINAL CONFERENCE
About the NIS directive
USCG Roles & Responsibilities During a Ship Fire
Critical Infrastructure Protection Policy Priorities
Agenda What is a standard, who uses standards and what are they for?
Role for Electric Sector in Critical Infrastructure Protection R&D
Oman Experience on Telecommunications Emergency Plan
Cyber Security in a Risk Management Framework
European Programme for Critical Infrastructure Protection (EPCIP)
Deborah Housen-Couriel, ADV.
CYBER RISKS IN SECURITIES SERVICES
Operational Risk Management
Presentation transcript:

WORKSHOP ON DEVELOPING NATIONAL CRITICAL INFRASTRUCTURE PROTECTION IN SERBIA – ROLE OF PRIVATE SECURITY COMPANIES CoESS and developing critical infrastructure security systems, services and standards Presentation by Alex Carmichael President of the CoESS Critical Infrastructure Committee Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

Contents of Presentation  Critical Infrastructure Overview  CoESS view on Critical Infrastructure  Trusted Partner  Standards  CoESS Check List  Public Private Partnerships  Conclusion Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

CRITICAL INFRASTRUCTURE Overview  Secure and Protected Critical Infrastructure sites are vital to the security and stability of each European state and to Europe as a whole.  Each individual European country determines its sites of critical infrastruture. These may include energy plants, transport hubs/network, water supplies, telecommunications (IT) hubs, etc.  Information about Critical Infrastructure is confidential and should stay confidential.  Council Directive 2008/114/EC – on the identification and designation of European Critical Infrastructure (ECI) and the assessment of the need to improve their protection. Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

CRITICAL INFRASTRUCTURE Overview  Most Critical Infrastructure (CI) is privately owned or privately run.  State provides security guidance to CI owner, but owner buys (in the main) the security package.  Security package – risk analysis based on the threats, vulnerabilities and potential impacts - leads to identification, selection and prioritisation of counter measures. Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

CRITICAL INFRASTRUCTURE Overview  Graduate Security Measures – based on risk and threat.  Three pillars  Prevention (detection)  Preparedness  Response/recovery & (resiliance)  CI protection (prevention)  Asset protection – Ditchs, walls,fences, bollards, lighting etc  Technical – CCTV, intruder, access control, cyber security, etc  Private Security Services – Guards, dogs, mobile patrols  Public Security Services – Military, police, etc. Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

CRITICAL INFRASTRUCTURE Overview  Preparedness  Contingency planning  Training  Exercises  Testing  Response/Recovery  Actions on  Containment  Damage assessment  Recovery phase Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

CRITICAL INFRASTRUCTURE CoESS view  Private Security Services have a main role in protecting critical infrastructure – (Protection, Preparedness and Response)  Based on Public-Private Partnership  Based on high levels of quality and service  Private Security Service Provider - Trusted Partner with Public Authority and CI site owner Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

CRITICAL INFRASTRUCTURE Trusted Partner  Comisario Esteban Gandara Tureba – Head of Private Security Unit – Spanish National Police - 4th European Security Summit – Madrid in March 2013  do ut des = Respect between public and private  Trust  Culture of cooperation (360 o )  Legal restriction  Industry – (Trust)  Individuals – security cleared/screened – trained and competent.  Company – security cleared – transparent corporate governance – works to high standards and can fulfil the customer and public authority requirements. Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

 No European Generic Guarding Standards for Critical Infrastructure  Sector Specific Guarding Standards  EN 16502: Security Service Providers – Terminology  EN 16082: Airport and Aviation Security Services  PD ISO/PAS 28007:2012 – Ships and Maritime – Guideline for security companies providing armed security personnel on board ships  Draft CEN (TC/417) – EN for Maritime and Port Security Services  ISO 9001 – Quality Management Systems  Industry can produce a framework for quality and services of private security – flexible to cover Europe, but high quality level for CI.  CoESS Check List - CI Operators and National Authorities. CRITICAL INFRASTRUCTURE Standards Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

Trusted Partner Private Guarding Company CoESS CI Check list  Basic Tender Requirements  Industry Lead – CoESS Check List (overview)  Personnel security vetting  Standards for operation  Corporate governance  Financial stability  Insurance requirements applicable to task  Meet national employee requlations and have comprehensive staff policy and training policy  Ability to carry out site risk and threat assessment  Have sufficient resources to carry out contract  Robust communications  Escalation plans and inbuilt resiliance  Check list, not a standard Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

Public - Private Security CI Partnerships  Private Security Industry  Minimum requirements – (CoESS check list?)  Quality of service  Critical Intrastructure Operator  Set requirements  Quality security service costs money  Public Authorities  Inform industry of the minimum requirements  Partnership built on trust and cooperation  European Commission  Include the Private Security Industry in discussions  Industry can advise on sector capability  Set EU criteria for CI Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

Public - Private Security Partnerships Do they work?  London – Project Griffin (2004) – set up to aid the security of the London’s financial district (partnership between police, private security industry and security professionals) (  4 activities  Awareness days for private security officers.  Online refresher days to maintain skills.  Regular communications between police and private security officers – conference calls, SMS messages or to ensure current intelligence and incident reports are disseminated in a timely manner.  Emergency deployment – private security officers who have undergone Griffin training may be used by police to support them in responding to incidents, e.g help in establishing cordons. (Recognised as Natioanl best practice and is being looked at by Canada, Austrialia and the United States.) Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

Public - Private Security Partnerships Do they work?  Germany - Security Partnership Programmes – police ask private security companies operating mobile patrols in certain locations (CI) to pass on information on suspect persons or vehicles or unlawful activities to company operations who then pass on to local police.  Germany Dusseldorf – 500 reports of suspect activities reported. Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

CoESS View on Critical Infrastructure  Public – Private Partnerships in CI work - many examples of good practice across Europe.  Private Security Services needs to establish agreed level of quality and service for CI acceptable to all National Authorities, but at a European standard level.  Only Private Security Services of the highest quality should be able to offer guarding services for critical infrastructure.  do ut des = Respect between public and private Belgrade, Serbia, April 2013TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC

Q&A Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC Q&A

Thank you! Belgrade, Serbia, April 2013 TAIEX – CoESS – NCPSC – Workshop on Developing NCIP in Serbia – Role of PSC Thank You!