The Role of The ISACs in Critical Infrastructure Protection and Resiliency Denise Anderson Vice Chair-National Council of ISACs Vice President FS-ISAC,

Slides:



Advertisements
Similar presentations
Protective Security Advisors Securing the Nations critical infrastructure one community at a time.
Advertisements

Homeland Security Information Network-Emergency Management (HSIN-EM) Fire Service Community Overview Technologies for Critical Incident Preparedness Conference.
Idaho Critical Infrastructure and Key Resources Protection Program and Fusion Center Brief.
The Financial Services Sector Coordinating Council
Kenneth Watson Partnership for Critical Infrastructure Security Partnership for Critical Infrastructure Security.
National Infrastructure Protection Plan
DHS, National Cyber Security Division Overview
Partnership for Critical Infrastructure Security PCIS Mission: The mission of the Partnership for Critical Infrastructure Security (PCIS) is to coordinate.
InfraGard A Partnership For Protecting America. What is InfraGard “ A cooperative undertaking between the U.S. Government (the FBI) and an association.
National Space-Based Positioning, Navigation, and Timing (PNT) Federal Advisory Board DHS Challenges & Opportunities Captain Curtis Dubay, P.E. Department.
US Army Corps of Engineers BUILDING STRONG ® Ty Brumfield (LNO to FEMA –RSF-IS National Coordinator Office of Homeland Security Directorate of Contingency.
June 9, 2003 Updated July 2004 Slide 1 Critical Infrastructure Assurance: The US Experience.
Food Safety and Inspection Service U.S. Department of Agriculture Homeland Security: Protecting the U.S. Food Supply Office of Food Security & Emergency.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
Food and Agriculture Sector Coordinating Councils John L. Williams, DVM U.S. Department of Agriculture AFDO Annual Conference Kansas City, MO June 7, 2005.
Public-Private Partnerships in Action: Emergency Response
National Infrastructure Protection Plan (NIPP). 2 The NIPP Provides a Strategic Context for Infrastructure Protection/Resiliency Dynamic threat environment.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
Seán Paul McGurk National Cybersecurity and Communications
Network Security Resources from the Department of Homeland Security National Cyber Security Division.
Nuclear Power Plant/Electric Grid Regulatory Coordination and Cooperation - ERO Perspective David R. Nevius and Michael J. Assante 2009 NRC Regulatory.
OverviewOverview Critical InfrastructuresCritical Infrastructures Presidential Decision Directive 63Presidential Decision Directive.
1 © 2003 Cisco Systems, Inc. All rights reserved. CIAG-HLS Security For Infrastructure Protection: Public-Private Partnerships KEN WATSON 15 OCT.
1 Information System Security Assurance Architecture A Proposed IEEE Standard for Managing Enterprise Risk February 7, 2005 Dr. Ron Ross Computer Security.
April 29, 2004 Slide 1 ANSI Homeland Security Standards Panel ANSI Homeland Security Standards Panel Presented by: Amy Marasco, ANSI VP and General Counsel.
The Office of Infrastructure Protection
Division of Emergency Management & Homeland Security Department of Emergency Services & Public Protection June 25, 2013 Connecticut All-Hazards Response.
Introduction to the National Cybersecurity & Communications Integration Center (NCCIC) “A Partnership for Strength” 1.
Association of Defense Communities June 23, 2015
Critical Infrastructure Protection Overview Building a safer, more secure, more resilient America The National Infrastructure Protection Plan, released.
Information Sharing Challenges, Trends and Opportunities
Catastrophe Readiness and Response Session 7b 1 Session 7b Critical Infrastructure Drew Bumbak.
Critical Infrastructure Protection Critical Infrastructure Protection Private Sector Programs April 7, 2005 Rod Nydam, JD, GMU Law School Private Sector.
Standardized Awareness Authorized Training, Train-the-Trainer Prevention and Deterrence.
EECS 710: Information Security and Assurance Assignment #3 Brent Frye 10/13/
Role for Electric Sector in Critical Infrastructure Protection R&D Presented to NERC CIPC Washington D.C. June 9, 2005 Bill Muston Public Release.
Jerry Cochran Principal Security Strategist Trustworthy Computing Group Microsoft Corporation.
Information Security: It’s Everyone’s Business September 16, 2003 Greg Garcia, Vice President, Information Security ITAA.
Food and Agriculture Sector A Collaborative Path to Agriculture Security and Food Defense LeeAnne Jackson, HHS/FDA Multistate Partnership Meeting Madison,
U.S. Department of Homeland Security Brief to the Inter Agency Board Incident Management and Communications Subgroup Oct 22, 2010 Pete Owen, PSA San Diego.
1 Session 7, Section 2 Critical Infrastructure Drew Bumbak.
CI/KR Public-Private Partnerships Overview March 2010 Prepared By: Thomas DiNanno International Assessment and Strategy Center.
InfraGard A Government and Private Sector Alliance Information sharing begins with human relationships – people talking with people whom they trust. Information.
A-16 Data Theme Gaps for Homeland Security and Homeland Defense Mike Lee - FGDC Homeland Security Working Group January 15, 2008.
The Challenging Landscape of Critical Information Infrastructure: Are We Ready? Leonard Bailey Senior Counsel Computer Crime & Intellectual Property Section.
A Global Approach to Protecting the Global Critical Infrastructure Dr. Stephen D. Bryen.
1 Washington State Critical Infrastructure Program “No security, No infrastructure” Infrastructure Protection Office Emergency Management Division Washington.
Governor’s Office of Homeland Security & Emergency Preparedness LOUISIANA BANKERS ASSOCIATION 2010 Louisiana Emergency Preparedness Coalition Meetings.
Cyber Attacks Threaten: privacy reliability safety resiliency 2.
1 Update from the ANSI Homeland Security Standards Panel (HSSP) Presented by Karen Hughes Director, Homeland Security Standards American National Standards.
What is “national security”?  No longer defined only by threat of arms  It really is the economy  Infrastructure not controlled by the government.
UNCLASSIFIED Homeland Security Introduction to the National Cybersecurity & Communications Integration Center (NCCIC) “A Partnership for Strength” 1.
March 17, 2004 Slide 1 Presented by Dan Bart, ANSI-Homeland Security Standards Panel Private Sector Co-Chair March 17, 2004 Defense Standardization Program.
Financial Services Sector Coordinating Council (FSSCC) 2011 KEY FSSCC INITIATIVES 2011 Key FSSCC Initiatives Project Name: Project Description: All-Hazards.
Critical Infrastructure Protection Committee Report to NERC Standing Committees in Joint Session Long Beach, CA March 2005 Public Release.
1 Iowa Emergency Management Association Iowa Homeland Security and Emergency Management Department Emergency Management Program Development Course EMERGENCY.
November 19, 2002 – Congress passed the Homeland Security Act of 2002, creating a new cabinet-level agency DHS activated in early 2003 Original Mission.
April 19 th, 2016 Governors Homeland Security and All-Hazards Cyber Security Sub-Committee.
Ken Watson 9 Sep 2003 Critical Infrastructure Assurance: Business Case for Public-Private Partnership Ken Watson 9 Sep 2003
CIPC Relationships & Roles
Cybersecurity at PJM Jonathon Monken
Role for Electric Sector in Critical Infrastructure Protection R&D
John M. Felker Director, NCCIC.
John Carlson Senior Director, BITS
The U.S. Department of Homeland Security
MIMOSA Open Meeting Standards-based Critical Infrastructure Risk Management Alan Johnston.
European Programme for Critical Infrastructure Protection (EPCIP)
Cybersecurity at PJM Jonathon Monken
Infragard national 2019 Strategic direction & plans
Presentation transcript:

The Role of The ISACs in Critical Infrastructure Protection and Resiliency Denise Anderson Vice Chair-National Council of ISACs Vice President FS-ISAC, Government and Cross Sector Programs Financial Services Information Sharing & Analysis Center (FS-ISAC) National Council of ISACs

Critical Infrastructure What is an ISAC? Sample descriptions of the various ISACs and capabilities/reach What is the National Council of ISACs? Brief Overview of the FS-ISAC and Recent Incidents Three Initiatives To Enhance Critical Infrastructure Protection and Resilience Agenda

18 Defined Sectors: Critical Infrastructure Agriculture and Food Defense Industrial Base Energy Healthcare & Public Health Banking & Finance Water Chemical Commercial Facilities Critical Manufacturing Dams Communications Postal & Shipping Transportation Systems Government Facilities Emergency Services Nuclear Reactors, Materials & Waste Information Technology National Monuments & Icons

What is an ISAC? Relationship to sectors Funding/Structure/Operations Functions

Why ISACs?  Trusted entities established by CI/KR owners and operators.  Comprehensive sector analysis  Reach-within their sectors, with other sectors, and with government to share critical information.  All-hazards approach  Threat level determination for sector

Why ISACs?  Operational services such as risk mitigation, incident response, and information sharing  Fast response on accurate, actionable and relevant information  Empower business resiliency through security planning, disaster response and recovery execution. Most ISACs, by definition, have 24/7 threat warning, incident reporting capabilities

ISACs Communications ISAC Electricity ISAC Emergency Management & Response ISAC Financial Services ISAC Highway ISAC Information Technology ISAC Maritime ISAC Multi-State ISAC

ISACs National Health ISAC Public Transit ISAC Real Estate ISAC Research and Education ISAC Supply Chain ISAC Surface Transportation ISAC Water ISAC

Other Operational Entities Defense Industrial Base (DIB) Nuclear Oil & Gas Chemical Airline

The only industry forum for collaboration on critical security threats facing the financial services sector Over 4,200 direct members and 30 member associations Ability to reach 99% of the banks and credit unions and 85% of the securities industry, and nearly 50% of the insurance industry Financial Services ISAC

Includes all 50 States, the District of Columbia, five U.S. Territories, one local governments per state and all state homeland security offices The MS-ISAC continues to broaden its local government participation to include all of the approximate 39,000 municipalities and fusion centers Multi-State ISAC

Created by the Association of American Railroads in 2002 at the request of the Secretary of Transportation The ST-ISAC supports 95% of the North American freight railroad infrastructure Surface Transportation ISAC

National Council of ISACs Mission The mission of the National Council of Information Sharing and Analysis Centers Council (ISACs) is to advance the physical and cyber security of the critical infrastructures of North America by establishing and maintaining a framework for valuable interaction between and among the ISACs and with governments.

National Council of ISACs Began meeting in 2003 to address common concerns and cross-sector interdependencies Volunteer group of ISACs who meet monthly to develop trusted working relationships among sectors on issues of common interest and work on initiatives of value to CI/KR

National Council of ISACs Information SourcesCommunications Briefings Best Practice Sharing - Joint Statements - White Papers Monthly Meetings Daily & Weekly ISAC Calls CIP Congress ENS Calls And Crisis Calls ListServ and Trusted Relationships ISAC Ops Centers ISACs & Other Sectors DHS & Other Government Partners Private Sector Liaison At The NICC Other Sources (Hundreds) PCIS

Brief Overview and Recent Incidents in 2011 Financial Services ISAC

FS-ISAC Background The Financial Services Information Sharing and Analysis Center is: A nonprofit private sector initiative Designed/developed/owned by financial services industry Lead agency: U.S. Treasury Founded in

18 FS-ISAC Membership Growth

FS-ISAC Information Sharing and Analysis Tools for Members Cyber & Physical alerts from 24/7 Security Ops Center Briefings/white papers Risk Mitigation Toolkit Document Repository Anonymous Submissions Committee Listservs Member surveys Bi-weekly Threat calls Special info sharing member conference calls Crisis Management process– CMLT, CINS Semi-annual conferences Webinars Regional Program Viewpoints

2011 YTD: Recent Incidents

US companies experienced 662 reported data breaches in 2010 March: RSA Open Letter reveals Advanced Persistent Threat (APT) attack against its two-factor authentication product (SecurID) April 1: Epsilon data breach divulged addresses for unknown number –2,500 corporate clients –112 potential companies 2011 Breaches Data Breaches (Identity Theft Resource Center)

March 11, 2011-Breach detected not public –Thursday March 17, 2011 story broke Threat Intelligence Committee Call –Friday March 18, 2011 Cyber UCG call NCI call with DHS Threat Intelligence Committee Call w/RSA FS-ISAC Membership Call w/RSA NCI call –Mitigation Report Working Group Calls –Mitigation Report –FS-ISAC, BITS Annual Summit – May 2011 RSA Breach

Three Major Initiatives To Enhance Critical Infrastructure Protection and Resilience 1.Liaison Programs 1.NICC 2.NCCIC 2.Information Sharing Frameworks 1.Directorate 2.CSISF 3.GISF 3.Classified Information Sharing

Who Is The NCCIC? DHS Office of Cybersecurity and Communications (CS&C) US CERT NCC ICS- CERT DHS I&A NCSC Liaisons UCG NCCIC

CLICK

National Security Telecommunications Advisory Council-NSTAC Cross-Sector Cyber Security Collaboration and Analysis Pilot project initially involving the FS-ISAC; IT-ISAC; Defense Security Information Exchange (DSIE) and Communications ISAC. Joint Coordination Center - CSISF

CONTACT Denise Anderson VP FS-ISAC, Government & Cross-Sector Programs - FS-ISAC Vice Chair-National Council of ISACs