2012 DHS/ACT-IAC Cybersecurity Awards The “Fed Cyber Cup” Concept Overview Cheryl Soderstrom, Programs Chair, Cybersecurity SIG.

Slides:



Advertisements
Similar presentations
Stop. Think. Connect. National Cybersecurity Awareness Campaign October 2010.
Advertisements

1 NMA… the Leadership Development Organization Council Workshop.
Project L.O.F.T. Report May 2007 through October 2007 Creating a design to meet stakeholder desires and dissolve our current set of interacting problems.
Department of Education, Employment and Workplace Relations
Office of Small and Medium Enterprises (OSME) Bureau des petites et moyennes entreprises (BPME) To Kickstart Innovation Canadian Innovation Commercialization.
World’s Largest Educational Community
 Reading School Committee January 23,
Social Media Requires Change Management Urgency! Guidance & governance Vision Communication Empowerment & enablement Campaign wins + competence development.
SME DIGITAL AWARDS 2014 NOMINATIONS SUBMISSION TEMPLATE.
RACE TO EXCELLENCE This presentation provides guidance and tools for participation in the 2011 Race.
IT Governance Portfolio and Project Management in State Government Chris Cruz, Chief Information Officer, California Department of Food and Agriculture.
1 Purchasing and Procurement Processes Module Four Revision Date: 2/06/2015.
Proposal Strengths and Weakness as Identified by Reviewers Russ Pimmel & Sheryl Sorby FIE Conference Oct 13, 2007.
Inspiration and Engagement Celebration and Recognition Launch and Achievement Night April 29, 2015.
Framework for Improving Critical Infrastructure Cybersecurity Overview and Status Executive Order “Improving Critical Infrastructure Cybersecurity”
QIO Program Overview December 6, About VHQC Private, non-profit healthcare consulting and quality improvement organization More than 60 experienced.
Enterprise IT Decision Making
Bullard Education Foundation Investing in Our Future Grants Fall 2012.
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
Updated Performance Management for Exempt Staff Fall 2009.
Donald R. Rainey, Sr., CPPB/VCO Director, Office of General Services Virginia Department of Social Services.
Why principal evaluation? Because Leadership Matters!
Consultation on School Funding Arrangements for Shropshire Schools from April 2015 Meeting for Headteachers and Governors Lord Hill Hotel, Shrewsbury 2.
Virginia Local Government IT Executives (VALGITE) April 26, 2010 Bruce Sturk & Leslie Fuentes – City of Hampton.
HECSE Quality Indicators for Leadership Preparation.
State EE/RE Policy Best Practices & Next-Generation Innovations: September Meeting Feedback on overall work plan and phasing of policies September 25,
OMB’s Management Watch List (MWL) & High Risk Projects List How to More Effectively Track, Analyze and Evaluate Your Agency IT Investments October 9, 2007.
11 Welcome to All! October 26-28, 2009 Washington, D.C. Welcome to All! Accelerators for America’s Future Symposium and Workshop October 26-28, 2009 Washington,
Overview What do we mean by a Learning Organisation? Why did we develop a People Development Framework? What was the process involved in building the.
PhRMA Perspective on FDA Final Report FDA Advisory Committee on Pharmaceutical Sciences October 20, 2004 G.P. Migliaccio, Pfizer Inc.
PMC Update on Cyber Sprint June 18, Overview: 30-Day Cyber Sprint 1.Interagency Cyber Sprint Team: Launched June 11 and executing against the.
Systems Accreditation Berkeley County School District School Facilitator Training October 7, 2014 Dr. Rodney Thompson Superintendent.
Awards Subcommittee Report Brett A. Bednarcyk NASA Glenn Research Center 1 Fall Structures TC Meeting November 11, 2012 Savannah, GA.
2015 Pipeline Safety Trust Conference November 20 th, 2015 | New Orleans, LA API RP 1175 Pipeline Leak Detection Program Management – New RP Highlights.
Introduction to ACT-IAC Advancing Government through Collaboration, Education and Action.
Government and Industry IT: one vision, one community Cybersecurity Shared Interest Group Monthly Meeting January 12, 2011 Jim Graham, SecureIT, SIG ChairSecureIT.
District Accreditation Completing the Standards Assessment Report July 20, 2010.
ACT-IAC Associates Program Coaches Orientation January 14, 2014.
The ELC 2014 premise was outcomes-oriented collaboration based on specific government priorities supported by ACT-IAC’s strategic plan Next steps include:
Evaluate Phase Pertemuan Matakuliah: A0774/Information Technology Capital Budgeting Tahun: 2009.
Government and Industry IT: one vision, one community Vice Chairs April Meeting Agenda Welcome and Introductions GAPs welcome meeting with ACT Board (John.
Monitoring the Long-Term Effectiveness of Integrated Safety Management System (ISMS) Implementation Through Use of a Performance Dash Board Process Mike.
CT TEFT 1 November 5, Agenda Introduction Goal of Pilot Tier Piloting Activity to Pilot Role of Connecticut in the pilot Standards and Technologies.
Advancing Government through Collaboration, Education and Action Discovery Management Zone (DMZ) Emerging Technology (ET) Shared Interest Group (SIG)
Emerging Technology (ET) Shared Interest Group (SIG) 2012 Strategic Plan Chair: John Geraghty, MITRE Vice Chair: Victor Koo, K3 Solutions LLC Version 1.0.
Advancing Government through Collaboration, Education and Action Maximizing Your IAC Membership Investment Maximizing Your IAC Membership Investment.
Advancing Government through Collaboration, Education and Action Institute for Innovation Discussion with Shared Interest Group Vice Chairs October 14,
April 13, 2015 SIG Alignment A Vision for the Future.
2016 SME DIGITAL AWARDS NOMINATIONS SUBMISSION TEMPLATE.
Standards of Achievement for Professional Advancement District 2 Career Ladder Training April 29, 2016 Ronda Alexander & Michael Clawson.
Grand Canyon Council Annual Council Commissioner Conference April 18, 2015.
Selection Criteria and Invitational Priorities School Leadership Program U.S. Department of Education 2005.
Technical Operations Report Board of Governors Meeting May 7-9, 2015
JMFIP Financial Management Conference
Nominations Submission Template
PMI Chapter, IT Governance, Portfolio and Project Management in State Government Chris Cruz, Chief Information Officer, California Department of Food and.
44th Meeting of the Standing Committee Bonn, Germany, October 2015 Report on activities of the Strategic Plan Working Group Ines Verleye,
RECOGNIZING educator EXCELLENCE
Annual Plan Earlier this week, the SNA Board reviewed the progress we have made to date on the new Strategic Plan that was introduced last year.
NIST Cybersecurity Framework
Advances in Aligning Performance Data and Budget Information:
Nominations Submission Template
Support for the AASHTO Committee on Planning (COP) and its Subcommittees in Responding to the AASHTO Strategic Plan Prepared for NCHRP 8-36, TASK 138.
Strategic Environmental Assessment (SEA)
Nominations Submission Template
DEVELOPING A HIGH PERFORMING FEDERAL WORKFORCE THROUGH INTERAGENCY COLLABORATION Randy Bergquist Chair, Interagency Chief Learning Officer Council.
Portfolio, Programme and Project
TIBC Budget Formulation Improvement Project
MEDITERRANEAN PUBLIC SERVICE AWARDS (MPSA) ___________________________
QUEEN’S AWARDS FOR ENTERPRISE
Presentation transcript:

2012 DHS/ACT-IAC Cybersecurity Awards The “Fed Cyber Cup” Concept Overview Cheryl Soderstrom, Programs Chair, Cybersecurity SIG

Impetus for Potential Awards Desire to highlight achievements in promoting secure cyberspace within the government Matt Coose, DHS FNS, establishing the 1 st “Federal Cyber Cup” to recognize 2010 performance; interested in expanding awards program and collaboration with ACT-IAC ACT-IAC interest in promoting cybersecurity through new awards program

Establishing a Federal Cybersecurity Awards Program FNS collects and analyzes government performance against FISMA metrics through Cyberscope in accordance with M The addition of CyberStat sessions provide context around agency or department performance, and allow trends, particular challenges and innovative solutions to emerge. Together, these provide an opportunity to recognize performance against FISMA criteria at the department level. DHS will have announced federal cybersecurity awards at their October 2011 conference. – Working with federal CISOs Advisory Council to nominate or help select winners, and to offer ideas for future awards (Public Outreach POC: Antione Manson) – Overall Federal Cybersecurity Award winner; perhaps other awards to be announced against 2010 FISMA data. Integration of Fed Cyber Cup with ACT-IAC targeted post 1 st award program announcements – (Future) Potentially integrated DHS/ACT-IAC awards program associated with Excellence.gov event (spring 2012), focused on FY11 results. – Idea is that the winning Agency’s name will be engraved on the actual Federal Cybersecurity Cup, which gets passed around to the new winner each year.

Possible DHS Awards Categories Best Posture This “best of breed” in cybersecurity award will recognize the agency with the best overall security posture as indicated by the FISMA results. Most Improved This award will recognize the agency that has shown the greatest improvement in its information security program from one year to the next. Innovation This award will recognize agencies for innovation in managing and improving their information security programs. Agencies will be rewarded for utilizing creative, non-traditional, and effective ways for managing their security programs. Most Accomplished with Least Resources This award will recognize agencies that have excelled in managing their cybersecurity programs despite having a small budget or staff dedicated to security. Interagency Collaboration This award will recognize agencies that have taken the lead in promoting standards, innovation, or other best practices across all federal agencies or have been active in assisting other agencies in their cybersecurity programs. Award to Stakeholders This award will recognize the various stakeholders involved in the FISMA reporting process and will acknowledge other areas of excellence not addressed by the other award categories. Federal Initiatives This award will recognize the most outstanding agencies in achieving federal initiatives. Agencies that have shown considerable progress in meeting or exceeding the goals of various federal cybersecurity initiatives will be rewarded for their efforts.

Possible DHS Awards Selection Process Best Posture award determined by four metric criteria: CyberScope Reports – 40% Strength of security program based on analysis of responses in CyberScope. IG Concurrence – 40% Metric based on IG ratings of establishing and maintaining 10 different programs consistent with FISMA requirements. Maturity – 10% Number of years in the top 50 percentile on the FISMA scorecard. Direct Data Feeds – 10% Security management tools providing direct data feeds for metrics including inventory, configuration, and vulnerability management. The process for additional awards is: Data-Driven Awards are based on measurable criteria including CyberScope scores, documented metrics, and other objective data points. Results Oriented Recognition given to encourage actual improvement in cybersecurity results by rewarding reductions in incidents and vulnerabilities. Federal Enterprise Focused Collaborative efforts and support of standards are recognized.

ACT-IAC Involvement in Fed Cyber Cup Awards Option 1: DHS presents DHS awards; ACT-IAC provides Excellence.gov venue Option 2: DHS & ACT-IAC work together to expand awards (may include nominations, criteria development, judging alongside cross-government participants) Option 3: ACT-IAC establishes a cybersecurity award program with Fed CIO Council (and DHS if interested) Option 4: ACT-IAC establishes our own federal cybersecurity awards Option 5: Disengage on idea ACT-IAC prefers Option 2 or Option 3 Need to establish parameters within which we add value to government efforts – Resources for data analysis – Scoring schemas & judging – Adding “subjective” industry awards to process – Joint government/industry “stamp of approval” – Other?

PROPOSED NEXT STEPS Planning and role delineation with DHS (10/11 and 10/27 sessions with Matt Coose) – Questions remain: Are the awards for compliance…or better security posture? How do you judge? Is industry allowed to see FISMA data? If not, how do we help? What roles are appropriate for DHS vs. ACT-IAC in the process? What would our timing and commitments be? How do we help Matt clear DHS Ethics Office concerns, if any? Engagement & analysis of submitted data (Nov 2011 to Jan 2012) Finalization of winners and event logistics management (Feb— Spring 2012) Excellence.gov presentation (Spring 2012)

What We Need from You Identification and removal of obstacles to DHS participation Guidance and development of ‘FISMA Cup” concept Collaborative development of roles & responsibilities between DHS & ACT-IAC Leadership and engagement in program, once approved by all parties Interaction with GAP members and other government colleagues regarding awards Public identification as FISMA Cup Awards Government Chair Can you participate as currently described?