Defense Nuclear Security Lessons Learned Center

Slides:



Advertisements
Similar presentations
Evaluation at NRCan: Information for Program Managers Strategic Evaluation Division Science & Policy Integration July 2012.
Advertisements

How Will it Help Me Do My Job?
Elements of an Effective Safety and Health Program
CDC EHDI RESOURCES for States. CDC EHDI Website CDC EHDI Website Purpose: To provide up-to-date.
1 Introduction to Safety Management April Objective The objective of this presentation is to highlight some of the basic elements of Safety Management.
Module N° 4 – ICAO SSP framework
National Association of State Auditors
HIPAA Security Presentation to The American Hospital Association Dianne Faup Office of HIPAA Standards November 5, 2003.
Normal Operations Data: Air Traffic Facility Evaluations and NOSS
Threshold System Presented by Jan Stanley, State Title I Director Office of Assessment and Accountability Fall Title I Directors Conference October 23-25,
1 DOE Safety Committee Handbook. 2 Effective Safety Committee! Make it work for you!
Presented by: Guy Prescott Common Sense Safety, Inc. (530)
MSCG Training for Project Officers and Consultants: Project Officer and Consultant Roles in Supporting Successful Onsite Technical Assistance Visits.
Introduction Lesson 1 Microsoft Office 2010 and the Internet
Privacy Impact Assessment Future Directions TRICARE Management Activity HEALTH AFFAIRS 2009 Data Protection Seminar TMA Privacy Office.
NERC Critical Infrastructure Protection Advisory Group (CIP AG) Electric Industry Initiatives Reducing Vulnerability To Terrorism.
HE in FE: The Higher Education Academy and its Subject Centres Ian Lindsay Academic Advisor HE in FE.
Software change management
EMS Checklist (ISO model)
1 Dr. Ashraf El-Farghly SECC. 2 Level 3 focus on the organization - Best practices are gathered across the organization. - Processes are tailored depending.
Effective Contract Management Planning
1 From the File Room to Facebook: Best Practices and Standards for Managing Social Media Records Chad Doran, CRM Chief Records Management Officer Arlington.
1 Division of Aging and Adult Services (DAAS) Knowledge Management and Transfer Project 7/30/12.
The importance of the service catalogue to the service desk
Abstract To provide efficient and effective access to enterprise information that meets stakeholder needs and supports mission success, NASA is implementing.
1. 2 August Recommendation 9.1 of the Strategic Information Technology Advisory Committee (SITAC) report initiated the effort to create an Administrative.
Khammar Mrabit Director Office of Nuclear Security
The Office Procedures and Technology
2009 Data Protection Seminar
NIMS Communications and Information Management IS-700.A – January 2009 Visual 4.1 NIMS Resource Management Unit 4.
SAI Performance Measurement Framework
Directions for this Template  Use the Slide Master to make universal changes to the presentation, including inserting your organization’s logo –“View”
NIMS Resource Management IS-700.A – January 2009 Visual 5.1 NIMS Resource Management Unit 5.
Quality Assurance Update Presented byRay Hardwick Presented by: Ray Hardwick.
1. 2 The San Jacinto Unified School District presents: Strategic Plan For
RTI Implementer Webinar Series: Establishing a Screening Process
U.S. Energy Information Administration Independent Statistics & Analysis Controlled Unclassified Information FCSM Conference Jacob Bournazian,
© Prentice Hall CHAPTER 15 Managing the IS Function.
Presented to: NDIA PMSC By: Keith Kratzert Date: January 29, 2009 Federal Aviation Administration Improving Program Performance at FAA.
May 22, 2000AIHCE Orlando May 20-25, Integrated Safety Management (ISM) and Public Involvement A Tool to Build Public Trust With ES&H Management.
2 Breakout Session # 504 Michael P. Fischetti, Director, Office of Procurement and Assistance Policy Department of Energy Date April 15, 2008 Time10:45.
Contractor Assurance System AC Overview October 13, 2009.
1 7/24/09 National Nuclear Security Administration Office of Defense Nuclear Security (DNS) DNS Security Lessons Learned Program Ted Wyka Director, Security.
Introduction to the State-Level Mitigation 20/20 TM Software for Management of State-Level Hazard Mitigation Planning and Programming A software program.
Departmental Initiative to Enhance Activity-level Work Planning and Control DOE and DOE Contractors Industrial Hygiene Meeting in Conjunction with the.
CD NS Chief, Defense Nuclear Safety FIRE PROTECTON FUNCTIONAL AREA CDNS BIENNIAL REVIEWS May 15, 2012 Carl Sykes.
DOE-HSS Review of LBNL Science Divisions 10/23/08.
ACADs (08-006) Covered Keywords Commission, regulation, advisory, standards. Description This presentation provides general information about each of the.
ISM at the Savannah River Site Department of Energy Best Practices Workshop Lesson Learned Program Bill Luce, Manager Regulatory Services Washington Savannah.
SESSION B TOPIC SUMMARY DOE SAFETY MANAGEMENT & OVERSIGHT ISM Workshop Denver – September 2006.
Facilitating Safe and Reliable Operations! Human Performance Center (HPC) U.S. Department of Energy Office of Corporate Safety Programs (HS-31) Define.
Disaster Recover Planning & Federal Information Systems Management Act Requirements December 2007 Central Maryland ISACA Chapter.
DOE Integrated Safety Management (ISM) Conference Knoxville, TN August 24-27, 2009 Colette Broussard, DOE-HQ Office of Quality Assurance Policy.
PRESENTED TO: ENERGY FACILITY CONTRACTORS GROUP SAFETY ANALYSIS WORKING GROUP SAFETY ANALYSIS WORKSHOP BY: CHRIS CHAVES NSR&D PROGRAM OFFICE OF NUCLEAR.
1 27 August 2009 Maryfrances Herrera Safety and Security Interface.
Click to edit Master title 1 1 Raymond W. Blowitski, Office of Analysis, HS-32 Phone: (301) Strategy for Implementing DOE O 210.2, DOE Corporate.
Small Business Programs Tatia Evelyn-Bellamy Director Small Business Division Small Business Center February 2016.
Communities of Practice & L ESSONS L EARNED Budget, Finance, and Award Management Large Facilities Office May 2016 Large Facilities Workshop 2016 S. Dillon.
1 Iowa Emergency Management Association Iowa Homeland Security and Emergency Management Department Emergency Management Program Development Course EMERGENCY.
EFCOG Safety Working Group (SWG) Status June 7, 2016 EFCOG Working Group Coordination Meeting Washington, DC John McDonald, SWG Chair.
State Coordinator Intervention
DOE NNSA CAS EFCOG/DOE CAS Effectiveness Task Team Sharon Steele Office of the Chief Defense Nuclear Safety (NA-511) November 16, 2016.
DOE Nuclear Safety Research and Development Program
The Federal Oversight and Contractor Assurance System Directives Safety Culture Improvement Panel Meeting September 7, 2016 Patricia.
Contractor Assurance Systems (CAS) Summit August 23, 2016
DOE Office of Security Policy, AU-51 July 2018
2018 EFCOG Safeguards & Security Working Group Annual Meeting
Trending Requirements and Results
Stephen Porter Safeguards & Security Working Group
Office of Health, Safety and Security
Presentation transcript:

Defense Nuclear Security Lessons Learned Center Enhancing the Defense Nuclear Security Lessons Learned Center Patricia Blount – DNS-LLC Project Leader OEC Workshop SLAC - May 5, 2010 UNCLASSIFIED

DNS SEC-LLC Mission The Security Lessons Learned Center (SEC-LLC) was established in 2007 by the Defense Nuclear Security (DNS) to provide an infrastructure for gathering, archiving, and communicating security lessons learned related to physical safeguards and security (S&S) issues across the NNSA Enterprise. Provide a platform to encourage and facilitate the sharing of lessons learned information. Mission – As originally defined Slide 2 UNCLASSIFIED

Program Drivers DOE O 210.2, DOE Corporate Operating Experience/Lessons Learned Program (OEC) DOE O 226.1A, Implementation of Department of Energy Oversight Policy NA-1 SD 226.1A, NNSA Line Oversight & Contractor Assurance System Supplemental Directive DOE Manual 470.4-1 Chg 1, Safeguards and Security Program Planning and Management Part 1, Section F, Performance Assurance Program Part 1, Section G, Survey, Review and Self-Assessment Programs Program Drivers Standard driver for all OE programs PLUS Security specific requirements Elaborate on EPAP in later slides UNCLASSIFIED

Lessons Learned Operating Experience Program The purpose of the DNS Safeguards and Security Operating Experience Program is to capture and apply lessons taken from operating experiences from across the National Security Enterprise in order to avoid repeat events, anticipate and mitigate undesirable consequences, and replicate best practices. Originally established as a LL program. Programs across the NNSA/DPE Enterprise moved toward a Operating Experience philosophy Emphasize the BLUE BOX elements Experiences are important to replicate awareness Lessons are important to replicate learning Slide 4 4

National Security Enterprise (NSE) Promote the Lessons Learned Center by leveraging the efforts of designated Points of Contact (POCs) at the site level. Patty Slide 5 UNCLASSIFIED

Points of Contact Patty Slide 6 UNCLASSIFIED

Infrastructure Webpage Database Help Desk Web-based Homepage available on open network – linked to HSS and other DOE/NNSA websites Timely posting and dissemination of security communications Database Microsoft Access database maintained by DNS-LLC for archiving, tracking, trending and reporting Operating Experiences Compatible with the Office of Health, Safety and Security (HSS) database (DOE Corporate) DNS-LLC uploads to HSS for posting to DOE Corporate Shared Resource between Safety, Security, and Project Management Professionals Gatekeeper Authority - Approve user access to security related lessons learned Help Desk Call-In and E-Mail Resource Center Patty Slide 7 UNCLASSIFIED

Website http://dns-lessons.lanl.gov/ David Slide 8 UNCLASSIFIED

Security Smarts Bethany UNCLASSIFIED Apr. 11, 2008 Avoiding Copyright Infringement Mar. 14, 2008 Detecting Unusual Behavior and Your Responsibilities Feb. 20, 2008 "You Are The Target!" Dec. 13, 2007 Holiday Security Awareness Nov. 27, 2007 Official Use Only (OUO) Sept. 27, 2007 Integrated Safeguards and Security Management Sept.24, 2007Identity Theft Slide 9 UNCLASSIFIED

CSI: Contemplating Security Incidents Bethany Feb. 27, 2008 Personally Identifiable Information (PII) Jan. 24, 2008 Unprotected Computer User ID and Password Nov.15, 2007 Improperly Secured Classified Slides Slide 10 UNCLASSIFIED

Operating Experience Template Forms & Field Descriptions Topical/Sub-Topical Area Date Originator Site Publish Anonymously Title Facility/Site POC Derivative Classifier/ Reviewing Official Lesson Learned Discussion of Activities Lesson Learned Summary Analysis Recommended Actions Estimated Savings/Cost Avoidance Keyword David Lesson Learned - Knowledge and experience, positive or negative, derived from actual events shared to promote positive information or prevent recurrence of negative events; benefit from the experiences of others. Discussion of Activities - Brief discussion focused on the facts that resulted in the initiation of the lesson learned. Lesson Learned Summary - Executive summary focusing on knowledge gained from the lesson learned. Sufficient detail to allow a reader to understand what the problem is/was, how it was identified, and what steps have/will be taken to correct the problem and prevent recurrence. Analysis - Results of any analysis that was performed, if available. Recommended Actions - Description of management-approved actions that were taken or will be taken to promote implementation of work enhancements or to prevent recurrence. Focus on actionable recommendations (i.e., the change resulting from the lesson) rather than reminders. Slide 11 UNCLASSIFIED

Quarterly Tracking/Reporting Bethany Slide 12 UNCLASSIFIED

NNSA’s Enterprise Re-Engineering and Management Reform Six-Month Moratorium on NNSA Initiated Assessments (January – June 2010) Contractor Assurance Systems (CAS) Contractor Performance Evaluation Plans (CPEP) Enterprise-wide S&S Assessment Plan Security Requirements Reform Safeguards and Security Evaluation and Performance Assurance Program (EPAP)/ Management Systems Assurance Program (MSAP) We have since moved toward Operating Awareness Program Still fulfill the requirements and expectations of an OE program PLUS, those elements unique to an Operating Awareness Program Focus is on “continuous process” that allows for describing the state of the program health at any given time Mention Fremont’s 3 key EPAP elements Align with Secretarial objective to reply more on Contractor Assurance Systems Slide 13 13

Operating Experience Program Operational Awareness Office of DNS S&S Evaluation and Performance Assurance Program (EPAP) “…those activities that ensure operations are securely performed; provide early identification of vulnerabilities; and ensure that there are effective lines of communication between organizations performing the work… Operational awareness also extends to management activities including maintaining a current awareness of the status, conditions and issues that may affect operations; performance expectations and measures; and contract deliverables or requirements. Operational awareness is not a scheduled activity…” We have since moved toward Operating Awareness Program Still fulfill the requirements and expectations of an OE program PLUS, those elements unique to an Operating Awareness Program Focus is on “continuous process” that allows for describing the state of the program health at any given time Mention Fremont’s 3 key EPAP elements Operational Awareness is a continuous process Slide 14 14

Operational Awareness What data is meaningful? Ensure that data is being analyzed & understood Communicate the operational aspects of S&S performance Ensure the application of relevant lessons learned/best practice Overview of Operational Awareness components that the SEC-LLC is actively involved in. Operational Awareness relies on timely data to anticipate shortfalls and focus resources, identify issues, gauge “weak signals,” and determine where assistance is needed in the field Slide 15 15

Screening & Distribution Process Improvements The SEC-LLC will “coordinate with the Office of Security Operations and Performance Assurance on the extent of the distribution of the lessons learned/best practice.” Routine Entered into the SEC-LLC and HSS databases Targeted distribution through normal means Significant – Major Impact on Operations or Policy Special Markings Site Office must provide “Positive Response” Green Flag – Routine Issues – Equivalent to Informational issues within the HSS Safety DB Red Flag Issues – Due to nature of security events and reporting, communications may be made before the posting to the HSS DB (ie existing vulnerabilities may still be “classified” – and won’t be downgraded until resolution) – Red flag items will still undergo the same actions as Routine Ask – “Why it occurred, not just what” Slide 16 16

Operational Awareness Data Analysis, Tracking, and Trending Lessons Learned/Best Practices Management System Assurance Program Reports (MSAP) Site Self-Assessments & Periodic Reviews Performance Metrics/Measures Other sources including, but not limited to: Office of Independent Oversight Inspector General Reports Line Oversight & Contractor Assurance System (LOCAS) Safeguards and Security Information Management System (SSIMs) Occurrence Reporting and Processing System (ORPs) Enforcement Actions/ Reports Review of safety-related lessons learned (e.g., conduct of operations, risk management) to determine whether aspects of safety lessons learned have applicability to S&S programs Microsoft Access database developed and maintained by LLC for document repository, archiving, tracking, trending, and reporting of Enterprise-wide S&S operational awareness activities. Currently houses 200+ documents. Production of analytical reports based on information collected and trended from the available reports. Provide appropriate information regarding SEC-LLC activity to NA-70 for Security Program Reviews. SEC-LLC staff trained/certified in use of the SSIMs database. Able to provide review of deviations, variances, and exceptions from an Enterprise-wide perspective. Slide 17 UNCLASSIFIED

Communicating Data Enterprise-Wide Periodic briefings provided to NNSA Administrator, Deputy Administrator for Defense Programs, and Site Office Managers Monthly Conference Calls – DNS Management & NNSA Assistant Managers for Safeguards and Security (AMSSs) & Site Office AMSSs Quarterly Program Reviews. Increased Communications and Partnership Increase Sharing and Communications Between NA-71, Site Office Points of Contacts & SEC-LLC SEC-LLC Participation & Integration with various Security Working Groups Participation on the Security Reforms Communication Team DNS Quarterly Performance Improvement Bulletins The effectiveness of the DNS EPAP is dependent upon how well the results are communicated Slide 18 UNCLASSIFIED

Targeted Distributions and Partnerships Classification Cyber Security Facility Security Human Reliability Program Information Protection Incidents of Security Concern Personnel Security Physical Security Operational Security (OPSEC) Material Control & Accountability Federal Points of Contact Protective Force Program Management Training Managers Safeguards & Security Information Management Additional Interest Groups Training Manager’s Working Group Office of Science National Training Center HSS OEC Working Group Office of Enforcement EFCOG Security Working Group (SSWG) Security Awareness Special Interest Working Group (SASIG) National Security Information Exchange (NSIE) United Kingdom Counterparts Expand as needed Slide 19

Performance Improvement News Bulletin Translating Events into Actionable Information Integration of HPI principles into communication products Analyses of patterns and trends in incidents and reportable occurrences Communication of high leverage lessons and actions Recognition for developing and sharing lessons learned Slide 20 20

Webpage: http://dns-lessons.lanl.gov/ Help Desk/Resource Center Defense Nuclear Security Lessons Learned Center Contact Information… Webpage: http://dns-lessons.lanl.gov/ Help Desk/Resource Center (505) 665-0196 sec-llc@lanl.gov Slide 21 21

Enhancing the Defense Nuclear Security Lessons Learned Center Questions? Slide 22 22