CI/KR Public-Private Partnerships Overview March 2010 Prepared By: Thomas DiNanno International Assessment and Strategy Center.

Slides:



Advertisements
Similar presentations
Protective Security Advisors Securing the Nations critical infrastructure one community at a time.
Advertisements

Minnesota Port and Waterway Security Working Group Meeting April 12, 2012.
Department of Homeland Security Site Assistance Visit (SAV)
Homeland Security at the FCC July 10, FCCs Homeland Security Focus Interagency Partnerships Industry Partnerships Infrastructure Protection Communications.
Idaho Critical Infrastructure and Key Resources Protection Program and Fusion Center Brief.
Unit 1: Introductions and Course Overview Administrative Information  Daily schedule  Restroom locations  Breaks and lunch  Emergency exit routes 
©2010 National Center for Food Protection and Defense. All rights reserved. Do not copy or distribute without permission of NCFPD. Food and Agriculture.
“Measuring Water Security Progress” 2008 Water Policy Conference AMWA Security Committee March 3, 2008 By Billy Turner, President, Columbus Water Works.
National Infrastructure Protection Plan
1 NGA Regional Bio-Terrorism Conference Boston, Massachusetts January 12-13, 2004.
DHS, National Cyber Security Division Overview
Partnership for Critical Infrastructure Security PCIS Mission: The mission of the Partnership for Critical Infrastructure Security (PCIS) is to coordinate.
National Protection and Programs Directorate Department of Homeland Security The Office of Infrastructure Protection Cybersecurity Brief [Date of presentation]
Fiscal Year 2008 Urban Areas Security Initiative Nonprofit Security Grant Program Investment Justification Questions, Criteria, and Prioritization Methodology.
National Space-Based Positioning, Navigation, and Timing (PNT) Federal Advisory Board DHS Challenges & Opportunities Captain Curtis Dubay, P.E. Department.
US Army Corps of Engineers BUILDING STRONG ® Ty Brumfield (LNO to FEMA –RSF-IS National Coordinator Office of Homeland Security Directorate of Contingency.
PPA 573 – Emergency Management and Homeland Security Lecture 9b - Department of Homeland Security Strategic Plan.
Consumer Work Group Presentation Federal Health IT Strategic Plan January 9, 2015 Gretchen Wyatt Office of Planning, Evaluation, and Analysis.
Alabama GIS Executive Council November 17, Alabama GIS Executive Council Governor Bob Riley signs Executive Order No. 38 on November 27 th, 2007.
Session 121 National Incident Management Systems Session 12 Slide Deck.
Food Safety and Inspection Service U.S. Department of Agriculture Homeland Security: Protecting the U.S. Food Supply Office of Food Security & Emergency.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
Food and Agriculture Sector Coordinating Councils John L. Williams, DVM U.S. Department of Agriculture AFDO Annual Conference Kansas City, MO June 7, 2005.
Technician Module 2 Unit 8 Slide 1 MODULE 2 UNIT 8 Prevention, Intelligence & Deterrence.
National Infrastructure Protection Plan (NIPP). 2 The NIPP Provides a Strategic Context for Infrastructure Protection/Resiliency Dynamic threat environment.
Part of a Broader Strategy
National Response Plan Overview [date] [location] [presenter]
The U. S. National Strategy for Global Supply Chain Security Neema Khatri Office of International Affairs U.S. Department of Homeland Security.
Introduction to the National Infrastructure Protection Plan IS 860 Amelia Muccio Director of Disaster Planning NEW JERSEY PRIMARY CARE ASSOCIATION.
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
October 27, 2005 Contra Costa Operational Area Homeland Security Strategic and Tactical Planning and Hazardous Materials Response Assessment Project Overview.
National Preparedness All Hazards Consortium Corey Gruber Assistant Deputy Administrator, National Preparedness National Preparedness.
The City and Security Era 1--The Walled City: 500 AD to 1700 Era 2--The Unwalled City: 1700 to 9/11/2001 Era 3--Securing the Unwalled City: April 8, 2003.
NIST Special Publication Revision 1
National Infrastructure Protection Plan (NIPP) Sector Specific Plan (SSP) AFDO Annual Meeting June 7, 2005 LeeAnne Jackson, Ph.D. Center for Food Safety.
Food and Agriculture Sector Update NASDA Food & Agriculture Security Task Force February 19, 2009.
Critical Infrastructure Protection Overview Building a safer, more secure, more resilient America The National Infrastructure Protection Plan, released.
Critical Infrastructure Protection: Program Overview
Information Sharing Challenges, Trends and Opportunities
DRAFT – For Discussion Only HHSC IT Governance Executive Briefing Materials DRAFT April 2013.
Catastrophe Readiness and Response Session 7b 1 Session 7b Critical Infrastructure Drew Bumbak.
Homeland Security Grant Program 2015 Process Michelle Hanneken Illinois Emergency Management Agency.
Role for Electric Sector in Critical Infrastructure Protection R&D Presented to NERC CIPC Washington D.C. June 9, 2005 Bill Muston Public Release.
PS Version 1 National Response Framework Overview for Private Sector Audiences January 22, 2008.
Food and Agriculture Sector A Collaborative Path to Agriculture Security and Food Defense LeeAnne Jackson, HHS/FDA Multistate Partnership Meeting Madison,
U.S. Department of Homeland Security Brief to the Inter Agency Board Incident Management and Communications Subgroup Oct 22, 2010 Pete Owen, PSA San Diego.
1 Session 7, Section 2 Critical Infrastructure Drew Bumbak.
A-16 Data Theme Gaps for Homeland Security and Homeland Defense Mike Lee - FGDC Homeland Security Working Group January 15, 2008.
Bioterrorism and Emergency Preparedness November 16, 2005 Jon Huss Director, Community Preparedness Section.
1 Washington State Critical Infrastructure Program “No security, No infrastructure” Infrastructure Protection Office Emergency Management Division Washington.
Governor’s Office of Homeland Security & Emergency Preparedness LOUISIANA BANKERS ASSOCIATION 2010 Louisiana Emergency Preparedness Coalition Meetings.
What is “national security”?  No longer defined only by threat of arms  It really is the economy  Infrastructure not controlled by the government.
Business Crisis and Continuity Management (BCCM) Class Session
NATIONAL INCIDENT MANAGEMENT SYSTEM (NIMS)
AUSTRALIA. A National Strategy for Enhancing the Safety and Security of our Food Supply ที่มา : We pride ourselves on our high safety and security standards.
Fiscal Year 2007 Urban Area Security Initiative Nonprofit Security Grant Program Investment Justification Questions, Criteria, and Prioritization Methodology.
NIMS AND THE NRF – MADE SIMPLE. 2  NIMS is a comprehensive, national approach to incident management  NIMS provides the template for incident management,
National Emergency Communications Plan Update National Association of Regulatory Utility Commissioners Winter Committee Meeting February 16, 2015 Ron Hewitt.
November 19, 2002 – Congress passed the Homeland Security Act of 2002, creating a new cabinet-level agency DHS activated in early 2003 Original Mission.
DHS/ODP OVERVIEW The Department of Homeland Security (DHS), Office for Domestic Preparedness (ODP) implements programs designed to enhance the preparedness.
Community Health Centers of Arkansas Hazard Vulnerability Assessment Workshop August 11, 2017 Mark Fuller.
NATIONAL INCIDENT MANAGEMENT SYSTEM (NIMS)
and Security Management: ISO 28000
Role for Electric Sector in Critical Infrastructure Protection R&D
Continuity Guidance Circular Webinar
The U.S. Department of Homeland Security
Cybersecurity ATD technical
MIMOSA Open Meeting Standards-based Critical Infrastructure Risk Management Alan Johnston.
Introduction to: National Response Plan (NRP)
Prevention, Intelligence
Presentation transcript:

CI/KR Public-Private Partnerships Overview March 2010 Prepared By: Thomas DiNanno International Assessment and Strategy Center

March Vision The United States will forge an unprecedented level of cooperation throughout all levels of government, with private industry and institutions, and with the American people to protect our critical infrastructure and key assets from terrorist attack. The National Strategy for Homeland Security July 2002

March HSPD-7 Requirements HSPD-7 directs the development of a National Infrastructure Protection Plan (NIPP) The NIPP is a comprehensive, integrated National Plan for Critical Infrastructure and Key Resources Protection to outline national goals, objectives, milestones, and key initiatives. The Plan includes the following elements:  A strategy to identify, prioritize, and coordinate CI/KR protection, including how DHS intends to work with Federal departments and agencies, State and local governments, the private sector, foreign countries, and international organizations;

March HSPD-7 Designated Sectors & Agencies DHS is responsible for coordinating the overall national effort to enhance protection of CI/KR across Sectors Agriculture, Food Critical Infrastructure Sectors Key Resources Public Health, Healthcare, Food Drinking Water, Water Treatment Defense Industrial Base Energy Banking and Finance National Monuments & Icons Transportation Systems Information Technology Telecommunications Chemical Emergency Services Postal and Shipping USDA HHS EPA DoD DOE TREAS DOI DHS Commercial Facilities Government Facilities Dams Commercial Nuclear Reactors, Materials, & Waste DHS Sector-Specific Agencies (SSAs)

March Major NIPP Theme: Information Sharing and Protection  The NIPP uses a network approach to information sharing that:  Enables secure multidirectional information sharing between and across government and CI/KR owners and operators at all levels.  Provides mechanisms, using “need to know” protocols as required, to support the development and sharing of strategic and specific threat assessments, incident reports and threat warning, impact assessments, and best practices.  Allows security partners to assess risks, conduct risk management activities, allocate resources, and make continuous improvements to the Nation’s CI/KR protective posture  DHS and other Federal agencies use a number of programs and procedures, such as the Protected Critical Infrastructure Information (PCII) Program, to ensure that CI/KR information is properly safeguarded

March Major NIPP Theme: Providing Resources for the CI/KR Protection Program Resources must be directed to areas of greatest priority to enable effective management of risk. The NIPP resource allocation process describes:  The integrated risk-based approach that will be used to determine how CI/KR protection programs will be prioritized and funded  How State- and local-level CI/KR protection efforts will be supported through DHS and other CI/KR protection Grant Programs  How all of these investments, coupled with appropriate incentives, support collaboration among security partners to enhance CI/KR protection

March NIPP Value Proposition The success of the partnership for CI/KR protection depends on articulating the mutual benefits to government and private sector partners. This value proposition:  Enables Federal, State, local, tribal and private sector security partners to clearly understand the national CI/KR protection priorities  Provides CI/KR protection planning, information sharing, risk management, resource coordination, and program implementation processes  Is intended to be used as a framework for coordinating CI/KR protection efforts across sectors and security partners

March Major NIPP Theme: Sector Partnership Model Provides the framework for security partners to work together in a robust public-private partnership.

March Implementing the NIPP Public Health, Healthcare, Food Drinking Water, Water Treatment Defense Industrial Base Energy Banking and Finance National Monuments & Icons Transportation Systems Information Technology Telecommunications Chemical Emergency Services Postal and Shipping HHS EPA DoD DOE TREAS DOI DHS Commercial Facilities Government Facilities Dams Commercial Nuclear Reactors, Materials, & Waste DHS

March Sector-Specific Plans (SSPs) Content  SSPs are annexes to the NIPP Base Plan  SSPs detail the application of the NIPP risk management framework across each of the 17 CI/KR sectors  Sector-Specific Agencies partner with their sector to develop the individual SSP  Finalized SSPs are to be submitted to DHS within 180 days after the NIPP is issued by the Secretary of Homeland Security Sector-Specific Plans Sector-Specific Plans (17)

March Set Security Goals  Security goals collectively represent the desired national and sector- specific security posture  These goals will vary between sectors and should consider the physical, human, and cyber elements of CI/KR protection  From the sector perspective, security goals:  Define the protective (and, if appropriate, the response or recovery) posture that security partners seek to attain  Consider distinct assets, systems, networks, operational processes, business environments, and risk management approaches  Vary according to the specific characteristics and security landscape for the affected sector, jurisdiction, or locality

March Identify Assets, Systems, Networks, and Functions  Involves developing a comprehensive inventory containing basic information on the Nation’s assets, systems, and networks  This inventory can be used to determine which assets systems, or networks are nationally critical, state critical, or locally critical based on the most current risk profile

March Evaluating Existing Risk Methodologies Is the Methodology Credible?  Integrity: Is the methodology based on classic risk analysis and security vulnerability analysis  Complete: Does the methodology provide reasonably complete results via a quantitative, systematic, and rigorous process  Defensible: Is the methodology thorough and does it use the recognized methods of the professional disciplines relevant to the analysis Is the Methodology Comparable to Other Methodologies?  Documented  Transparent  Reproducible  Accurate

March Prioritize  DHS will work with security partners to prioritize the results of risk assessments to help identify where risk reduction is most pressing and to subsequently determine what protective actions should be taken  Requires a comparison of the relative levels of asset and sector risk along with options for achieving the established security goals  Enables protective actions to be applied where they offer the greatest reduction in risk relative to the cost

March Implement Protective Programs  Protective actions are intended to reduce risk by:  Deterring attacks  Devaluing the attractiveness of the asset, system, or network  Detecting potential attacks  Defending the asset, system, or network to delay or prevent an attack  Protective programs may also include actions that reduce consequences should an attack occur, including:  Mitigating the range of potential attacks  Responding and recovering efficiently and effectively

March Measure Effectiveness  NIPP establishes a metrics-based system to provide feedback on efforts to attain specified security goals  Metrics provide a basis for establishing accountability, documenting actual performance, facilitating diagnoses, promoting effective management, and reassessing goals and objectives at the national and sector level  NIPP Risk Management Framework uses three types of metrics  Descriptive  Process (or output)  Outcome

March NIPP Development & Coordination  The NIPP was developed as a collaborative process between DHS, the SSAs and State, local, and private sector security partners.  The review and comment process:  Broadly distributed for review across sectors and at each level of government and the private sector and the public to obtain individual comments and input  Draft NIPP Base Plan was Distributed to the following Security Partners:  Federal Government  DHS; Sector-Specific Agencies; HSPD-7 Departments & Agencies; Government Coordinating Councils  State, Local, Territorial, and Tribal Governments  Homeland Security Advisors; State Administrative Agents and Emergency Managers  Advisory Councils  National Infrastructure Advisory Council; National Security Telecommunications Committee; Homeland Security Advisory Committee  Private Sector Partners  Sector Coordinating Councils; Private Sector Security Partners

March 2010 Facilities deemed not high-risk 20,000 ? Tier 1= HIGH RISK CHEMICAL FACILITIES – Sec Universe Potentially High-Risk Chemical Facilities Perform CSAT Consequence Screen 20, Tier 1= Chemical Security

March 2010 Chemical Security Define the Performance Standards  Have defined 17 Performance Standards  Standards will be tied to specific risk types present at the facility (i.e., release hazard; precursor; sabotage; economic/mission criticality).  Standards address the full range of security practices:  Physical Security  Perimeter Control  Access Control  Cyber Security (physical and logical)  Personnel surety  Deter Detect Delay  Security and Response Force planning and training & Exercise  Material Control  Counter Theft – Counter Diversion 19 Risk Based Performance Standards

March 2010 Emergency Management  Support response, recover, and reconstitution efforts of States affected by a disaster:  Support PFO and FCO in Joint Field Offices (JFOs)  Serve as pre-designated IL and JFO when requested  Help coordinated Federal, State, and LLE CIKR protection efforts  Coordinate sharing of IP HQ analysis within JFO  Perform SAVs to identify vulnerabilities  Provide advice on protective measures to enhance security at CIKR in and around impact area  Provide key stakeholders with updates on issues relating to CIKR assets 20