The LOGIIC Consortium Zachary Tudor, CISSP, CISM, CCP Program Director SRI International.

Slides:



Advertisements
Similar presentations
WV High Quality Standards for Schools
Advertisements

Professor Dave Delpy Chief Executive of Engineering and Physical Sciences Research Council Research Councils UK Impact Champion Competition vs. Collaboration:
International Civil Aviation Organization Nancy Graham Director - Air Navigation Bureau 28 October 2011 Symposium on RSOOs Meeting Outcomes.
12 August 2004 Strategic Alignment By Maria Rojas.
GETBA Strategic Plan 2013 – 2016 Prepared for Jane Tongatule By Jo Malcolm and Kate Berry.
Your Technology Is Connected. Are You? Your technology doesn’t exist in a vacuum. Welcome to the networked and interconnected technology ecosystem where.
Public Safety Communications Research Program A joint program between NIST’s Communications Technology Laboratory & NTIA’s Institute for Telecommunication.
Enav.it Session 3 Steps towards the SESAR deployment and the ATM system modernisation.
Internet2, CENIC and Merit: Partnering to Deliver Cloud Services to California.
National Infrastructure Protection Plan
The U.S. Coast Guard’s Role in Cybersecurity
10/29/20091 Innovation Partnerhsip Models with the Finance Sector Dept. of Homeland Security Science & Technology Directorate Douglas Maughan, Ph.D. Branch.
DHS, National Cyber Security Division Overview
Public Private Partnerships P3s What the Public Sector Considers When Selecting the Right Private Partner Jose A. Galan - Division Director Miami-Dade.
Update on WITSML deployment in BP - Energistics Public Meeting Houston, 28 May 2009 Dr Julian Pickering Field of the Future Business Deployment.
Viewpoint Consulting – Committed to your success.
Advancing Government through Collaboration, Education and Action Financial Innovation and Transformation Shared Services Workshop March 17, 2015.
The Ideas Business Building successful think tanks Phil Rourke Executive Director Centre for Trade Policy and Law Carleton University/University of Ottawa.
Framework for Improving Critical Infrastructure Cybersecurity Overview and Status Executive Order “Improving Critical Infrastructure Cybersecurity”
Providing Practical Solutions Winning the Talent Wars for Recruiting and Retaining 21 st Century Cyber Engineers Jeff Kubik, PMP, CISSP Sr PM, Praxis Engineering.
Competency Models Impact on Talent Management
GATEWAY TO FINNISH EXPERTISE 1 Commercialization guidelines – NanoCom and ProNano results Dr. Eeva Viinikka, Business Director Programme Director of National.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
CTCN ORIGINS 2 COP 15 (Copenhagen): agreement to establish a “Technology Mechanism” COP 16 (Cancun): Technology Mechanism further elaborated (TEC and.
Opportunities to Participate in Center for Research & Technology Development (CRTD) Activities Presented at TCOB Meeting – March 1, 2012 Michael Tinkleman,
E2 Tech Forum November 15, 2011 Andrew Wilson, Executive Director.
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
Network Security Resources from the Department of Homeland Security National Cyber Security Division.
PROMOTING TECHNOLOGY TO INDUSTRY Technology transfer objectives: enhance commercial value of invention promote technology to partner / investor identify.
Partnerships and collaboration Working together: good for business, good for research I work for business.gov.au but also thought it would be a good opportunity.
Overview of UIC Technology Centers Ralph Pini Associate Dean, Corporate Relations College of Engineering University of Illinois at Chicago
NGO’s Strategy for CSR: Building a Responsible Solution Nona Pooroe Utomo.
1 © 2003 Cisco Systems, Inc. All rights reserved. CIAG-HLS Security For Infrastructure Protection: Public-Private Partnerships KEN WATSON 15 OCT.
BOTSWANA NATIONAL CYBER SECURITY STRATEGY PROJECT
ICTs Tackling Climate Changes Dr. Amr Badawi Executive President NTRA.
Information Sharing Challenges, Trends and Opportunities
ESTELA Summer Workshop, 26 June 2013 The EU-SOLARIS project.
Jerry Cochran Principal Security Strategist Trustworthy Computing Group Microsoft Corporation.
Update on WITSML deployment in BP - Energistics Public Meeting Dubai, 19 November 2008 Dr Julian Pickering IT Programme Manager Drilling & Completions.
Greenville Technical Charter High School Strategic Plan Developed October 2014.
Douglas Maughan Division Director, Cyber Security Division DHS S&T.
Stuttgart, Germany June 15-18, 2009 Ensuring the Safety of Future PCIVs Paper Presenter: Stephen Summers Co-authors: A. Brecher, J. Brewer, S.
Chapter Thirteen Copyright, John Wiley and Sons, Inc. Chapter Thirteen three Learning Concepts – Chapter Understand the increasing benefits and challenges.
Business Retention and Expansion What it is Why it is important How it works What makes it successful Business Retention and Expansion.
National Cybersecurity Center of Excellence Increasing the deployment and use of standards-based security technologies Mid-Atlantic Federal Lab Consortium.
November 2, 2006 LESSONS FROM CIPAG 1 Lessons from Critical Infrastructure Group Bill Bojorquez November 2, 2006.
1 Computing and Communications Services ● Business Analysis and Process Re-engineering Gayleen Gray, Deputy CIO.
1 1 Cybersecurity : Optimal Approach for PSAPs FCC Task Force on Optimal PSAP Architecture Working Group 1 Final Report December 10 th, 2015.
Planning for School Implementation. Choice Programs Requires both district and school level coordination roles The district office establishes guidelines,
The Commonwealth Has a “VOICCE” Virginia’s Operational Integration Cyber Center of Excellence.
Update on work of IUCN Council Private Sector Task Force Diana Shand Regional Councillor and Chair of Private Sector Task Force The International Union.
Company: Cincinnati Insurance Company Position: IT Governance Risk & Compliance Service Manager Location: Fairfield, OH About the Company : The Cincinnati.
Bob BERSANI, GS1 Vice President Global Standards GS1 Standards Development Update.
Team Leader, Technology Policy and Strategy, UNFCCC Mr Andrew Higham THE CANCUN AGREEMENTS, THE TECHNOLOGY MECHANISM AND TECHNOLOGY NEEDS ASSESSMENTS UNFCCC.
PERKINS IV AND THE WORKFORCE INNOVATION AND OPPORTUNITY ACT (WIOA): INTERSECTIONS AND OPPORTUNITIES.
U.S. Department of Agriculture eGovernment Program Smart Choice Pre-Select Phase Transition September 2002.
Laurie E. Locascio, Ph.D. Director, MML/NIST NIST/MML: Measurement Assurance for Biological Systems.
THE PROGRAMME FOR COUNTRY PARTNERSHIP: Making a difference 14 April 2016 Ciyong ZOU Director PTC/PRM.
SciencePAD Incubation Laboratory Alberto Di Meglio – CERN.
Enabling Building Efficiency: The NYC Urban Technology Innovation Center TIMOTHY CROSS, COLUMBIA ENGINEERING IEEE INNOVATION DAY POLYTECHNIC INSTITUTE.
BruinTech Vendor Meet & Greet December 3, 2015
Detection and Analysis of Threats to the Energy Sector (DATES)
The Applied Research Center at Florida International University
National Quantum Initiative
INNOVATION SUPERCLUSTERS INITIATIVE
Role of State Audit Bureau of Kuwait in promoting and audit of IT Security  
Chapter to Provide Title
The Technology Mechanism of the UNFCCC
NACE International Update
Presentation transcript:

The LOGIIC Consortium Zachary Tudor, CISSP, CISM, CCP Program Director SRI International

Presentation Outline About LOGIIC LOGIIC Projects o Correlation Project o SIS Project o Host Protection Project Summary 2

Presenter 3 Zach Tudor is a Program Director in the Computer Science Laboratory at SRI International, supporting operational and R&D cyber security programs including the DHS Cyber Security Research and Development Center (CSRDC). For CSRDC he provides technical support, subject matter expertise, and project management for projects including LOGIIC and the Industrial Control System Joint Working Group (ICSJWG) R&D working group. Prior to his work at SRI, he led a team of cyber security engineers and analysts directly supporting the Control Systems Security Program (CSSP) at DHS.

LOGIIC Value Proposition (Need and Approach) In 2004, Chevron and DHS S&T identified a need for a framework to enable collaborative, pre- competitive cybersecurity R&D in the Oil and Gas sector The approach selected was to establish a government/private partnership, leveraging national laboratories, the research community, security technology providers, and automation vendors.

LOGIIC Value Proposition (Benefits and Alternatives) Benefits to O&G include accelerated security improvements in critical networks: o 5:1 ROI on R&D investment o Access to leading R&D, facilities for technology integration, test, and evaluation o Unified voice to vendors. DHS S&T benefits from a proactive, cooperative engagement with industry to promote security in critical infrastructure systems Security technology providers have an opportunity to evaluate solutions in what may be for them new market environments Vendors have access to leading technology and new market opportunities LOGIIC differs from other O&G associations and consortia in its unique ability to fund RDT&E and enable cooperation among stakeholder communities

The LOGIIC Model of Government & Industry Partnership Linking the Oil and Gas Industry to Improve Cyber Security LOGIIC is an ongoing collaboration of oil and natural gas companies and the U.S. Department of Homeland Security, Science and Technology Directorate. LOGIIC facilitates cooperative research, development, testing, and evaluation procedures to improve cybersecurity in petroleum industry digital control systems. LOGIIC undertakes collaborative research and development projects to improve the level of cybersecurity LOGIIC promotes the interests of the sector while maintaining impartiality, the independence of the participants, and vendor neutrality

LOGIIC Broke New Ground in Consortium Governance for Collaborative R&D The Automation Federation (AF) serves as the LOGIIC host organization o Members approved a participation agreement with AF o Each project is covered by a Project Addendum to this agreement Member companies contribute financially and technically, provide personnel who meet regularly to define projects of common interest, and provide staff to serve on the LOGIIC Executive Committee. Current members of LOGIIC include BP, Chevron, Shell, Total, and other large oil and gas companies that operate significant global energy infrastructure. The U.S. Department of Homeland Security, Science and Technology Directorate has contracted with the scientific research organization SRI International to provide scientific and technical guidance as well as project management for LOGIIC.

LOGIIC Model Adds Major Value to the Oil & Gas Industry Industry gains access to Government-funded experts and labs they would otherwise not have easy access to. Participant commitment is key. This kind of partnership is not a spectator sport – the first LOGIIC project was a success because time and resources were invested and people were committed to doing great work. The LOGIIC Correlation Project resulted in a real and validated solution, not just a paper product. o Chevron Pipeline deployed the solution with some of these benefits: Monitor events in real-time instead of weekly Reduce investigation time for events by at least 85% Provide forensic evidence o Many vendors are now developing their products; some are already available in the market.

LOGIIC: A Win for All Government wins: o Contributing to security of the critical infrastructure networks of the nation o Cooperative partnership with O&G sector Oil and gas industry wins: o Improvements to the protection of their networks o Proactive engagement with government o Leveraged ROI from modest R&D investment o Unified voice in defining system security requirements o Rationale for influencing vendor product offerings Vendor wins: o Access to cutting-edge research o Vendors share ideas and build relationships with other IT security vendors, control system vendors, research institutions and labs, and industry participants o Access to new markets, future programs and opportunities

The LOGIIC Correlation Project ( ) Industry contributed o Requirements and operational expertise o Project management o Product vendor channels DHS S&T contributed o National Security Perspective on threats o Access to long term security research o Independent researchers with technical expertise o Testing facilities

The LOGIIC Correlation Project Opportunity: Reduce vulnerabilities of oil & gas process control environments by correlating and analyzing abnormal events to identify and prevent cyber security threats Approach: o Identify new types of security sensors for process control networks o Adapt a best-of-breed correlation engine to this environment o Integrate in testbed and demonstrate o Transfer technology to industry Business Network Process Control Network LOGIIC Correlation Engine External Events Attack Indications and Warnings

LOGIIC SIS Project Security of Safety Instrumented Systems SIS objective: bring a process plant to a safe state when an excursion outside pre-established operating parameters occurs SIS increasingly integrate with process control systems o Traditional physical separation between control and safeguarding has been reduced through integration of certain systems components of control systems and safeguarding systems Research Question: Is the technical integrity of our production facilities jeopardized because of Cybersecurity issues under SIS/BPCS integration? Challenges include: o Prevent false trips of SIS caused by corrupted SIS configuration or false signals to SIS o Ensure SIS activates when required o Prevent operator loss of view

Summary LOGIIC is a model for government-industry technology integration, evaluation, and demonstration efforts to address critical infrastructure R&D needs LOGIIC enables its members to leverage the collective resources of the industry, government agencies, researchers, and subject matter experts for collaborative cyber-security projects LOGIIC successful first project produced an industry- adopted solution, and validated the collaboration The LOGIIC SIS project delivered its findings to vendors and standards bodies The LOGIIC Consortium is working on new projects and planning on future projects