Vision for Cyber Security in the Water Sector AMWA S 2008 ANNUAL MEETING October 19-22, 2008 New Orleans, Louisiana Seth Johnson and Dave Edwards

Size: px
Start display at page:

Download "Vision for Cyber Security in the Water Sector AMWA S 2008 ANNUAL MEETING October 19-22, 2008 New Orleans, Louisiana Seth Johnson and Dave Edwards"

Transcription

1 Vision for Cyber Security in the Water Sector AMWA S 2008 ANNUAL MEETING October 19-22, 2008 New Orleans, Louisiana Seth Johnson and Dave Edwards WSSC-CSWG and PCSF Water and Wastewater Representatives, respectively

2

3

4

5

6

7

8

9

10 Cyber events can affect water system operations in a variety of ways, some with potentially significant adverse effects in public health. Cyber events could do the following: Interfere with the operation of water treatment equipment, which can cause chemical over- or under-dosing Make unauthorized changes to programmed instruction in local processors to take control of water distribution or wastewater collection systems, resulting in disabled service, reduced pressure flows of water into fire hydrants, or overflow of untreated sewage into public waterways Modify the control systems software, producing unpredictable results

11 Block data or send false information to operators to prevent them from being aware of conditions or to initiate inappropriate actions Change alarm thresholds or disable them Prevent access to account information Although many facilities have manual backup procedures in place, failures of multiple systems may overtax staff resources -- even if failure is manageable in itself Be used as a ransom-ware

12

13 USGS

14 AGENDA Future Trends Vision for Securing Control Systems Goals and Milestones Key Challenges Next Steps

15 3/06 SCADA/IT Security Forum, Los Angeles, CA 6/06 Process Control Systems Forum La Jolla, CA 10/06 SCADA/IT Security Forum, Sacramento, CA 3/07 Process Control Systems Forum, Atlanta, GA 3/07 SCADA/IT Security Summit, Burbank, CA 6/07 SCADA/IT Security Forum, Denver, CO 9/07 Vision Workshop, San Jose, CA 10/07 WSCC Mtg., Washington D.C. 12/07 Roadmap Workshop, Washington, DC 1/08 SCADA and Process Control Summit, New Orleans, LA 2/08 WSCC Meeting, Washington D.C. 3/08 WSCC Releases Roadmap

16 Paul Bennett, NYC Dept Env. Protection Amy Beth, Denver Water Cliff Bowen, CA Dept Health Services Jake Brodsky, WSSC Erica Brown, AMWA Kim Bui, San Antonio Water System Vic Burchfield, Columbus Water Works Richard Castillon, Orange Co. SD Rick DaPrato, Massachusetts WRA Kim Dyches, UT Dept. Env. Protection Patrick Ellis, Broward County WWS Dave Edwards, Metropolitan WD of So. CA Rod Graupmann, Pima Co. WWM Christina Grooby, Santa Clara Valley WD Darren Hollifield, JEA Seth Johnson, WSSC-CSWG Bruce Larson, American Water Carlon Latson, Denver Water Tony McConnell, WSSC Kevin Morley, WSCC-CSWG Jerry Obrist, Lincoln Water Elissa Ouyang, CA Water Service Co. Kevin Quiggle, Detroit W and S Dept. Alan Roberson, AWWA Candace Sands, EMA, Inc. Cheryl Santor, Metropolitan WD of So. CA Birute Sonta, MWRD of Greater Chicago Keith Smith, MWRD of Greater Chicago Greg Spraul, EPA WSD Walt Wadlow, Santa Clara Valley WD Stan Williams, Santa Clara Valley WD Ray Yep, Santa Clara Valley WD Facilitators: Katie Jereza and Jack Eisenhauer, Energetics Incorporated

17

18

19

20 Develop and Deploy Industrial Control Systems (ICS) Security Programs Assess Risk Develop and Implement Risk Mitigation Measures Partnership and Outreach 80% of water system executives recognize Industrial Control Systems (ICS) security is mission critical IT staff and ICS engineers and operators coordinate cyber security efforts Integrate ICS security as a key goal in every project plan Develop a recommended practices ICS security template for widespread use in the water sector Integrate & elevate ICS security requirements with vendor contracts Isolate ICS from public switched networks Integrate Roadmap with Water Sector Specific Plan Develop ICS risk assessment & reporting guidelines published & available throughout the water sector Identify common metrics for benchmarking ICS risk (threat-vulnerabilitiesconsequence) in the water sector Develop ICS risk assessment tools, such as end-to-end, threatvulnerabilitiesconsequence analysis capability for the water sector Establish working group for developing/ maintaining best practices for ICS network architecture(s) for the water sector Develop cyber response protocol template ICS vendors start to implement or increase their cyber security features by 50% Identify and implement existing security features built into the devices Replace default security passcodes Develop effective federal & state incentives to accelerate investment to secure ICS technologies & practices Increase ICS security awareness between water sector, crosssector, vendor & commercial partners Develop essential body of ICS security knowledge for information sharing

21 Develop and Deploy ICS Security Programs Assess Risk Develop and Implement Risk Mitigation Measures Partnership and Outreach Click to edit Master text styles Conduct sectorwide training on recommended practices ICS security template Integrate ICS security awareness, education, & outreach programs into water sector operations Second Reduce level Conduct sectorwide training on risk assessment tools installation time of ICS patching Third level 50% Frameware by Fourth level by 99.9% Applications System design accommodates Fifth level restarts Develop operator ICS security training program Adopt recommended practices for ICS security in the water sector Develop public communication channels to increase confidence in efforts to prevent or minimize impacts form a cyber event

22 Develop and Deploy ICS Security Programs Assess Risk Develop and Implement Risk Mitigation Measures Partnership and Outreach Click to edit Master text styles Sustain roadmap activities in accordance with the Water Sector Specific Plan Second Develop level & Water sector actively measures ICS security performance & benchmarks with implement selfdefending ICS & infrastructure Third level Require ICS other sectors security in Fourth operator level certification Real-time security state monitoring for intrusions are commercially Fifth level available Establish life cycle investment & framework for cyber security Government maintains ICS threat support Identify, understand, & disseminate timely ICS risk information within the sector & among its partners

23

24 Periodic vulnerability assessments Limited/protected connections to other systems Network monitoring/protection Hardened configuration for control system components Strong authentication methods Regular antivirus updates and patch management Testing and backup practices for control system Strong physical security for control system components Background checks on individuals touching control system Most knowledgeable resources working collaboratively

25

26

27 Seth Johnson Water Sector Coordinating Council Cyber Security Working Group Representative (408) Dave Edwards Process Control Systems Forum Water and Wastewater representative Metropolitan Water District of So. Calif. (213)

28 Working Working separately... together We ll move ahead We move around

California Cybersecurity Integration Center (Cal-CSIC)

California Cybersecurity Integration Center (Cal-CSIC) California Cybersecurity Integration Center (Cal-CSIC) Agenda Mission and Scope Whole of State Government Approach Where is the Cal-CSIC? Cal-CSIC Partners Attaining Cyber Maturity in Parallel Machine

More information

All-Hazards Approach to Water Sector Security & Preparedness ANSI-HSSP Arlington, VA November 9, 2011

All-Hazards Approach to Water Sector Security & Preparedness ANSI-HSSP Arlington, VA November 9, 2011 All-Hazards Approach to Water Sector Security & Preparedness ANSI-HSSP Arlington, VA November 9, 2011 Copyright 2009 American Water Works Association Copyright 2011 American Water Works Association Security

More information

Securing Industrial Control Systems

Securing Industrial Control Systems L OCKHEED MARTIN Whitepaper Securing Industrial Control Systems The Basics Abstract Critical infrastructure industries such as electrical power, oil and gas, chemical, and transportation face a daunting

More information

Control Systems Cyber Security Awareness

Control Systems Cyber Security Awareness Control Systems Cyber Security Awareness US-CERT Informational Focus Paper July 7, 2005 Produced by: I. Purpose Focus Paper Control Systems Cyber Security Awareness The Department of Homeland Security

More information

The Water Sector Approach to Cybersecurity

The Water Sector Approach to Cybersecurity The Water Sector Approach to Cybersecurity Standards Certification Education & Training Publishing Conferences & Exhibits Kevin M. Morley, PhD American Water Works Association 2016 ISA Water / Wastewater

More information

Roadmap to a Secure & ResIlient Water Sector

Roadmap to a Secure & ResIlient Water Sector Roadmap to a Secure & ResIlient Water Sector Developed by: Critical Infrastructure Partnership Advisory Council Water Sector Strategic Planning Working Group October 2009 Report Documentation Page Form

More information

2011 North American SCADA & Process Control Summit March 1, 2011 Orlando, Fl

2011 North American SCADA & Process Control Summit March 1, 2011 Orlando, Fl Beyond Compliance Greg Goodrich Supervisor, Enterprise Security New York Independent System Operator 2011 North American SCADA & Process Control Summit March 1, 2011 Orlando, Fl Roles of the NYISO Reliable

More information

Energy Benchmarking Commercial Buildings. Cities that support or require energy benchmarking of commercial buildings

Energy Benchmarking Commercial Buildings. Cities that support or require energy benchmarking of commercial buildings Energy Benchmarking Commercial Buildings Cities that support or require energy benchmarking of commercial buildings Large Cities (250,000+ people) Madison WI 250,000 We are working on a voluntary program.

More information

The J100 RAMCAP Method

The J100 RAMCAP Method The J100 RAMCAP Method 2012 ORWARN Conference Kevin M. Morley, PhD Security & Preparedness Program Manager AWWA--Washington, DC Water is Key to Daily Life Potable drinking water Sanitation Public Health

More information

2016 SAC Task Force. December 1, 2016

2016 SAC Task Force. December 1, 2016 2016 SAC Task Force December 1, 2016 Welcome and Introductions Ned Smith, MCES Director of Finance & Revenue Wendy Wulff, Metropolitan Council Member Meeting 1 Overview Charter, Timeline & Meeting Plan,

More information

TERRORISM LIAISON OFFICER OUTREACH PROGRAM - (TLOOP)

TERRORISM LIAISON OFFICER OUTREACH PROGRAM - (TLOOP) To: Bay Area UASI Approval Authority From: Mike Sena, Director NCRIC/HIDTA Date: January 10, 2019 Re: Item 7: NCRIC Annual Report and Proposed FY19 Allocation Recommendation: Approve $4,454,066 from the

More information

An Introduction To: Help Me Grow-LA. August 11, 2016

An Introduction To: Help Me Grow-LA. August 11, 2016 An Introduction To: Help Me Grow-LA August 11, 2016 Presenters MODERATOR Reena John Senior Program Officer First 5 LA Christina Altmayer Vice President of Programs First 5 LA Wendy Schiffer Director of

More information

The Office of Infrastructure Protection

The Office of Infrastructure Protection The Office of Infrastructure Protection National Protection and Programs Directorate Department of Homeland Security Organisation for the Prohibition of Chemical Weapons September 13, 2011 Overall Landscape

More information

DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY ATTACHMENT A A-1: BACKGROUND AND CONTRACTOR QUALIFICATIONS A-2: SCOPE OF WORK

DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY ATTACHMENT A A-1: BACKGROUND AND CONTRACTOR QUALIFICATIONS A-2: SCOPE OF WORK DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY ATTACHMENT A A-1: BACKGROUND AND CONTRACTOR QUALIFICATIONS A-2: SCOPE OF WORK GOODS AND SERVICES CONTRACTS Page 1 of 5 RFP 16-PR-DEM-33 Comprehensive All-Hazards

More information

Cyber Partnership Blueprint: An Outline

Cyber Partnership Blueprint: An Outline Approved for Public Release; Distribution Unlimited. 13-3851 The MITRE Corporation Cyber Partnership Blueprint: An Outline October 26, 2013 Copyright 1997-2013, The MITRE Corporation. All rights reserved.

More information

Bradford J. Willke. 19 September 2007

Bradford J. Willke. 19 September 2007 A Critical Information Infrastructure Protection Approach to Multinational Cyber Security Events Bradford J. Willke 19 September 2007 Overview A framework for national Critical Information Infrastructure

More information

ALBEMARLE COUNTY SERVICE AUTHORITY

ALBEMARLE COUNTY SERVICE AUTHORITY ALBEMARLE COUNTY SERVICE AUTHORITY AGENDA ITEM EXECUTIVE SUMMARY AGENDA TITLE: Strategic Plan Process STAFF CONTACT(S)/PREPARER: Gary O Connell, Executive Director AGENDA DATE: September 20, 2018 ACTION:

More information

Trends in Cybersecurity in the Water Industry A Strategic Approach to Mitigate Control System Risk

Trends in Cybersecurity in the Water Industry A Strategic Approach to Mitigate Control System Risk Trends in Cybersecurity in the Water Industry A Strategic Approach to Mitigate Control System Risk Standards Certification Education & Training Publishing Conferences & Exhibits Steve Liebrecht W/WW Industry

More information

Top 10 ICS Cybersecurity Problems Observed in Critical Infrastructure

Top 10 ICS Cybersecurity Problems Observed in Critical Infrastructure SESSION ID: SBX1-R07 Top 10 ICS Cybersecurity Problems Observed in Critical Infrastructure Bryan Hatton Cyber Security Researcher Idaho National Laboratory In support of DHS ICS-CERT @phaktor 16 Critical

More information

Chicago Energy Benchmarking

Chicago Energy Benchmarking Chicago Energy Benchmarking Sep 15 2015 ASHRAE - Illinois meeting Kathryn Eggers Benchmarking Program Lead Amy Jewel Senior City Advisor 2015 Elevate Energy Chicago Energy Benchmarking Sep 15 2015 ASHRAE

More information

Cybersecurity Overview

Cybersecurity Overview Cybersecurity Overview DLA Energy Worldwide Energy Conference April 12, 2017 1 Enterprise Risk Management Risk Based: o Use of a risk-based approach for cyber threats with a focus on critical systems where

More information

An Update on Security and Emergency Preparedness Standards for Utilities

An Update on Security and Emergency Preparedness Standards for Utilities An Update on Security and Emergency Preparedness Standards for Utilities Linda P. Warren, Launch! Consulting Safety and Security in the Workplace March 28, 2013 Overview 1 Review of AWWA Standards in Water

More information

ENERGY. JUDI GREENWALD Deputy Director for Climate, Environment and Efficiency U.S. Department of Energy

ENERGY. JUDI GREENWALD Deputy Director for Climate, Environment and Efficiency U.S. Department of Energy U.S. DEPARTMENT OF ENERGY PARTNERSHIP FOR ENERGY SECTOR CLIMATE RESILIENCE National Summit on Smart Grid & Climate Change October 13, 015 JUDI GREENWALD Deputy Director for Climate, Environment and Efficiency

More information

Summary of Cyber Security Issues in the Electric Power Sector

Summary of Cyber Security Issues in the Electric Power Sector Summary of Cyber Security Issues in the Electric Power Sector Jeff Dagle, PE Chief Electrical Engineer Energy Technology Development Group Pacific Northwest National Laboratory (509) 375-3629 jeff.dagle@pnl.gov

More information

RESILIENT UTILITY COALITION OF SOUTH FLORIDA

RESILIENT UTILITY COALITION OF SOUTH FLORIDA RESILIENT UTILITY COALITION OF SOUTH FLORIDA RUC MISSION The Resilient Utility Coalition seeks to advance utility infrastructure resiliency efforts in South Florida and provide essential value to its members

More information

Upgrading Traffic Signals to Enable a Connected Vehicle Test Bed Somerville, Massachusetts

Upgrading Traffic Signals to Enable a Connected Vehicle Test Bed Somerville, Massachusetts Upgrading Traffic Signals to Enable a Connected Vehicle Test Bed Somerville, Massachusetts Presented in The 2018 ITE Northeastern District Meeting in Lake George, NY May 22 nd, 2018 ORGANIZATION OF THE

More information

Identifying Critical Infrastructure Through the Use of Hydraulic Modeling to Support Asset Management

Identifying Critical Infrastructure Through the Use of Hydraulic Modeling to Support Asset Management Identifying Critical Infrastructure Through the Use of Hydraulic Modeling to Support Asset Management James P. Cooper, Prof. Engineer, Cert. Operator Acknowledgements Lisa Gresehover Kimberly Six Karem

More information

EPA Near-port Community Capacity Building: Tools and Technical Assistance for Collaborative Solutions

EPA Near-port Community Capacity Building: Tools and Technical Assistance for Collaborative Solutions EPA Near-port Community Capacity Building: Tools and Technical Assistance for Collaborative Solutions Sabrina Johnson, Project Lead EPA Office of Transportation & Air Quality presented at Southeast Diesel

More information

PIPELINE SECURITY An Overview of TSA Programs

PIPELINE SECURITY An Overview of TSA Programs PIPELINE SECURITY An Overview of TSA Programs Jack Fox Pipeline Industry Engagement Manager Surface Division Office of Security Policy & Industry Engagement May 5, 2014 TSA and Pipeline Security As the

More information

Executive Order & Presidential Policy Directive 21. Ed Goff, Duke Energy Melanie Seader, EEI

Executive Order & Presidential Policy Directive 21. Ed Goff, Duke Energy Melanie Seader, EEI Executive Order 13636 & Presidential Policy Directive 21 Ed Goff, Duke Energy Melanie Seader, EEI Agenda Executive Order 13636 Presidential Policy Directive 21 Nation Infrastructure Protection Plan Cybersecurity

More information

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 PPD-21: CI Security and Resilience On February 12, 2013, President Obama signed Presidential Policy Directive

More information

Continuous protection to reduce risk and maintain production availability

Continuous protection to reduce risk and maintain production availability Industry Services Continuous protection to reduce risk and maintain production availability Managed Security Service Answers for industry. Managing your industrial cyber security risk requires world-leading

More information

City of San José 2017 Coyote Creek Flood After-Action Review & Improvement Recommendations Report

City of San José 2017 Coyote Creek Flood After-Action Review & Improvement Recommendations Report City of San José 2017 Coyote Creek Flood After-Action Review & Improvement Recommendations Report SAN JOSÉ CITY COUNCIL MEETING, 08-AUG 2017 BRAD GAIR, SENIOR MANAGING DIRECTOR, WITT O BRIEN S About Witt

More information

Features of an Active and Effective Protective Program for Water and Wastewater Utilities. Be Prepared Be Secure Be Resilient

Features of an Active and Effective Protective Program for Water and Wastewater Utilities. Be Prepared Be Secure Be Resilient Features of an Active and Effective Protective Program for Water and Wastewater Utilities Be Prepared Be Secure Be Resilient Offi ce of Water (4601M) EPA 817-F-08-005 www.epa.gov/watersecurity October

More information

NW NATURAL CYBER SECURITY 2016.JUNE.16

NW NATURAL CYBER SECURITY 2016.JUNE.16 NW NATURAL CYBER SECURITY 2016.JUNE.16 ADOPTED CYBER SECURITY FRAMEWORKS CYBER SECURITY TESTING SCADA TRANSPORT SECURITY AID AGREEMENTS CONCLUSION QUESTIONS ADOPTED CYBER SECURITY FRAMEWORKS THE FOLLOWING

More information

The CIS Security Metrics & Benchmarking Service. Clint Kreitner The Center for Internet Security

The CIS Security Metrics & Benchmarking Service. Clint Kreitner The Center for Internet Security The CIS Security Metrics & Benchmarking Service Clint Kreitner The Center for Internet Security The Center for Internet Security (CIS) Formed - October 2000 As a not-for-profit public-private partnership

More information

Southeast Florida Regional Climate Change Compact Update. Broward Climate Change Task Force February 16, 2017

Southeast Florida Regional Climate Change Compact Update. Broward Climate Change Task Force February 16, 2017 Southeast Florida Regional Climate Change Compact Update Broward Climate Change Task Force February 16, 2017 Overview Recent Activities RCAP Update Forthcoming Efforts Regional Resilience Projects Summit

More information

Green Treatment Center

Green Treatment Center Green Treatment Center IT Strategic Goals and Objectives: 2017-2019 Technology Plan The Department s IT strategies for the next four years are grounded in legislative and regulatory drivers that inform

More information

An Overview of ISA-99 & Cyber Security for the Water or Wastewater Specialist

An Overview of ISA-99 & Cyber Security for the Water or Wastewater Specialist An Overview of ISA-99 & Cyber Security for the Water or Wastewater Specialist Standards Certification Education & Training Publishing Conferences & Exhibits Speakers: Bryan L. Singer, CISM, CISSP, CAP

More information

Annual Report for the Utility Savings Initiative

Annual Report for the Utility Savings Initiative Report to the North Carolina General Assembly Annual Report for the Utility Savings Initiative July 1, 2016 June 30, 2017 NORTH CAROLINA DEPARTMENT OF ENVIRONMENTAL QUALITY http://portal.ncdenr.org Page

More information

June 5, 2018 Independence, Ohio

June 5, 2018 Independence, Ohio June 5, 2018 Independence, Ohio The Office of Infrastructure Protection National Protection and Programs Directorate Department of Homeland Security Securing the Nation at the Community Level 2018 Cuyahoga

More information

Minimum Support Needed for a Reliable SCADA System

Minimum Support Needed for a Reliable SCADA System Minimum Support Needed for a Reliable SCADA System Speaker Bio Jeff Miller, PE, ISI ENV SP Dewberry Automation Manager MEP Service Line Raleigh, NC 22 years experience in Electrical / Instrumentation &

More information

ICS-CERT Year in Review. Industrial Control Systems Cyber Emergency Response Team

ICS-CERT Year in Review. Industrial Control Systems Cyber Emergency Response Team ICS-CERT Year in Review Industrial Control Systems Cyber Emergency Response Team 2012 What s Inside Welcome 1 Organization 3 Outreach 4 Industrial Control Systems Joint Working Group 5 Advanced Analytical

More information

STRATEGIC PLAN VERSION 1.0 JANUARY 31, 2015

STRATEGIC PLAN VERSION 1.0 JANUARY 31, 2015 VERSION 1.0 JANUARY 31, 2015 2015-2018 STRATEGIC PLAN NATIONAL ALLIANCE FOR PUBLIC SAFETY GIS FOUNDATION 1250 24TH STREET NW SUITE 300 WASHINGTON, DC 20037 2015-2018 STRATEGIC PLAN VISION A Nation of emergency

More information

Active and Effective Water Security Programs. Be Informed Be Alert Be Ready

Active and Effective Water Security Programs. Be Informed Be Alert Be Ready Active and Effective Water Security Programs A Summary Report of the National Drinking Water Advisory Council Recommendations on Water Security Be Informed Be Alert Be Ready Offi ce of Water (4601M) EPA

More information

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com Cybersecurity Presidential Policy Directive Frequently Asked Questions kpmg.com Introduction On February 12, 2013, the White House released the official version of the Presidential Policy Directive regarding

More information

Testimony. Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON

Testimony. Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON Testimony Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON Defending Our Democracy: Building Partnerships to Protect America

More information

Public and Private Sector Partnerships to Promote HIT Adoption Across the United States

Public and Private Sector Partnerships to Promote HIT Adoption Across the United States Public and Private Sector Partnerships to Promote HIT Adoption Across the United States Community-Based Collaboratives Track Health Information Technology Summit October 20-23, 2004 Washington, D.C. Janet

More information

Santa Clara County. San Francisco City and County. Marin County. Napa County. Solano County. Contra Costa County. San Mateo County

Santa Clara County. San Francisco City and County. Marin County. Napa County. Solano County. Contra Costa County. San Mateo County Marin County Santa Clara County San Francisco City and County Sonoma County Napa County Contra Costa County San Mateo County Solano County Alameda County ABAG History In 1961, Bay Area leaders recognized

More information

Defensible Security DefSec 101

Defensible Security DefSec 101 Defensible Security DefSec 101 Security Day November 2017 Information Security Branch Paul Falohun Senior Security Analyst Dan Lathigee Senior Project Manager Content 1 Introduction 2 DefSec for PSO 3

More information

Advanced Monitoring Technologies for Grid Reliability, Market Efficiency, and Grid Security

Advanced Monitoring Technologies for Grid Reliability, Market Efficiency, and Grid Security Advanced Monitoring Technologies for Grid Reliability, Market Efficiency, and Grid Security CERTS Briefing for Kevin Kolevar, Director Office of Electricity and Energy Assurance Department of Energy Washington,

More information

Effectively Measuring Cybersecurity Improvement: A CSF Use Case

Effectively Measuring Cybersecurity Improvement: A CSF Use Case SESSION ID: GRC R03F Effectively Measuring Cybersecurity Improvement: A CSF Use Case Greg Witte Sr. Cybersecurity Engineer G2, Inc. @TheNetworkGuy Tom Conkle Cybersecurity Engineer G2, Inc. @TomConkle

More information

European Union Agency for Network and Information Security

European Union Agency for Network and Information Security Critical Information Infrastructure Protection in the EU Evangelos Ouzounis Head of Secure Infrastructure and Services Regional Cybersecurity Forum Sofia, Bulgaria 29 th November 2016 European Union Agency

More information

New Madrid Earthquake Catastrophic Planning Project Overview

New Madrid Earthquake Catastrophic Planning Project Overview New Madrid Earthquake Catastrophic Planning Project Overview Presented by: Jim Wilkinson Executive Director, CUSEC Derek Estes Acting Chief, FEMA Catastrophic Disaster Planning Branch EIIP - EMForum.org

More information

Physical Security Reliability Standard Implementation

Physical Security Reliability Standard Implementation Physical Security Reliability Standard Implementation Attachment 4b Action Information Background On March 7, 2014, the Commission issued an order directing NERC to submit for approval, within 90 days,

More information

Applying Mitigation. to Build Resilient Communities

Applying Mitigation. to Build Resilient Communities Applying Mitigation to Build Resilient Communities The Hazards Around Us Think about the natural hazard that... poses the greatest risk to where you live or work OR has had the greatest impact on you personally

More information

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS The Saskatchewan Power Corporation (SaskPower) is the principal supplier of power in Saskatchewan with its mission to deliver power

More information

ISAO SO Product Outline

ISAO SO Product Outline Draft Document Request For Comment ISAO SO 2016 v0.2 ISAO Standards Organization Dr. Greg White, Executive Director Rick Lipsey, Deputy Director May 2, 2016 Copyright 2016, ISAO SO (Information Sharing

More information

Position Description. Engagement Manager UNCLASSIFIED. Outreach & Engagement Information Assurance and Cyber Security Directorate.

Position Description. Engagement Manager UNCLASSIFIED. Outreach & Engagement Information Assurance and Cyber Security Directorate. Position Description Engagement Manager Business unit: Position purpose: Direct reports: Directorate overview: Business Unit Overview Remuneration indicator: Outreach & Engagement Information Assurance

More information

Critical Infrastructure Sectors and DHS ICS CERT Overview

Critical Infrastructure Sectors and DHS ICS CERT Overview Critical Infrastructure Sectors and DHS ICS CERT Overview Presented by Darryl E. Peek II REGIONAL INTELLIGENCE SEMINAR AND NATIONAL SECURITY FORUM 2 2 Authorities and Related Legislation Homeland Security

More information

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 I. Vision A highly reliable and secure bulk power system in the Electric Reliability Council of Texas

More information

STATE BROADBAND ACTION PLAN MAY 2015 Nevada Economic Development Conference PREPARED BY CONNECT NEVADA AND THE NEVADA BROADBAND TASK FORCE

STATE BROADBAND ACTION PLAN MAY 2015 Nevada Economic Development Conference PREPARED BY CONNECT NEVADA AND THE NEVADA BROADBAND TASK FORCE STATE BROADBAND ACTION PLAN MAY 2015 Nevada Economic Development Conference PREPARED BY CONNECT NEVADA AND THE NEVADA BROADBAND TASK FORCE PLAN STRUCTURE I INTRODUCTION Background History of the Project

More information

J.Enhancing energy security and improving access to energy services through development of public-private renewable energy partnerships

J.Enhancing energy security and improving access to energy services through development of public-private renewable energy partnerships J.Enhancing energy security and improving access to energy services through development of public-private renewable energy partnerships Background ESCAP, jointly with the ECLAC, the ECA, the ECE, and the

More information

Defense Security Service. Strategic Plan Addendum, April Our Agency, Our Mission, Our Responsibility

Defense Security Service. Strategic Plan Addendum, April Our Agency, Our Mission, Our Responsibility Strategic Plan 2020 Addendum, April 2017 Our Agency, Our Mission, Our Responsibility [2] DSS Strategic Plan Addendum 2020 Addendum The DSS Strategic Plan 2020 is designed to support the agency s continuous

More information

Resolution adopted by the General Assembly. [on the report of the Second Committee (A/56/561/Add.2)]

Resolution adopted by the General Assembly. [on the report of the Second Committee (A/56/561/Add.2)] United Nations A/RES/56/195 General Assembly Distr.: General 21 January 2002 Fifty-sixth session Agenda item 98 (b) Resolution adopted by the General Assembly [on the report of the Second Committee (A/56/561/Add.2)]

More information

Information Technology (CCHIT): Report on Activities and Progress

Information Technology (CCHIT): Report on Activities and Progress Certification Commission for Healthcare Information Technology Certification Commission for Healthcare Information Technology (CCHIT): Report on Activities and Progress Mark Leavitt, MD, PhD Chair, CCHIT

More information

ARRA State & Local Energy Assurance Planning & Implementation

ARRA State & Local Energy Assurance Planning & Implementation State Energy Policy and Technology Outlook Conference February 2, 2010, Washington, DC ARRA State & Local Energy Assurance Planning & Implementation Alice Lippert Senior Technical Advisor Office of Electricity

More information

Growing the Vision for Safe Mobility: Vision Zero

Growing the Vision for Safe Mobility: Vision Zero Growing the Vision for Safe Mobility: Vision Zero Vision Zero Cities Bellevue Seattle A Vision Zero City meets the following minimum standards: - Sets clear goal of eliminating traffic fatalities and

More information

Smart Cities and Security. Security - 1

Smart Cities and Security. Security - 1 Smart Cities and Security Security - 1 Where are we in 2013? Security - 2 Where are we in 2050? Security - 3 Our Topics Who is concerned? Security of the electric grid Security of the water supply Security

More information

Critical Infrastructure Protection Committee Strategic Plan

Critical Infrastructure Protection Committee Strategic Plan Critical Infrastructure Protection Committee Strategic Plan 2013-2016 CIPC Executive Committee 5/14/2013 3353 Peachtree Road NE Suite 600, North Tower Atlanta, Georgia 30326 404-446-2560 www.nerc.com Table

More information

Community-Based Water Resiliency

Community-Based Water Resiliency Community-Based Water Resiliency Helping Water Utilities Build Stronger Communities Presentation to the Mid-Atlantic APWA Chapter Conference Virginia Beach, VA May 10, 2013 What is Community-Based Water

More information

Five-Year Strategic Plan

Five-Year Strategic Plan Five-Year Strategic Plan 2016 2020 Contents A Message from the ERIS Board... 3 Introduction and Background... 4 Five-Year Plan Goal Areas... 7 Goal Area 1: State Environmental Agency Research Needs and

More information

Regional Workshop on Frameworks for Cybersecurity and CIIP Feb 2008 Doha, Qatar

Regional Workshop on Frameworks for Cybersecurity and CIIP Feb 2008 Doha, Qatar Regional Workshop on Frameworks for Cybersecurity and CIIP 18 21 Feb 2008 Doha, Qatar A National Cybersecurity Strategy aecert Roadmap Eng. Fatma Bazargan aecert Project Manager Technical Affairs Department

More information

UPU UNIVERSAL POSTAL UNION. CA C 4 SDPG AHG DRM Doc 3. Original: English COUNCIL OF ADMINISTRATION. Committee 4 Development Cooperation

UPU UNIVERSAL POSTAL UNION. CA C 4 SDPG AHG DRM Doc 3. Original: English COUNCIL OF ADMINISTRATION. Committee 4 Development Cooperation UPU UNIVERSAL POSTAL UNION CA C 4 SDPG AHG DRM 2014.1-Doc 3 Original: English COUNCIL OF ADMINISTRATION Committee 4 Development Cooperation Sustainable Development Project Group Ad hoc group on Disaster

More information

2014 Sector-Specific Plan Guidance. Guide for Developing a Sector-Specific Plan under NIPP 2013 August 2014

2014 Sector-Specific Plan Guidance. Guide for Developing a Sector-Specific Plan under NIPP 2013 August 2014 2014 -Specific Plan Guidance Guide for Developing a -Specific Plan under NIPP 2013 August 2014 How to Use this Guidance This page provides a roadmap to assist critical infrastructure partners in navigating

More information

LESSONS LEARNED IN SMART GRID CYBER SECURITY

LESSONS LEARNED IN SMART GRID CYBER SECURITY LESSONS LEARNED IN SMART GRID CYBER SECURITY Lynda McGhie CISSP, CISM, CGEIT Quanta Technology Executive Advisor Smart Grid Cyber Security and Critical Infrastructure Protection lmcghie@quanta-technology.com

More information

STRATEGY ATIONAL. National Strategy. for Critical Infrastructure. Government

STRATEGY ATIONAL. National Strategy. for Critical Infrastructure. Government ATIONAL STRATEGY National Strategy for Critical Infrastructure Government Her Majesty the Queen in Right of Canada, 2009 Cat. No.: PS4-65/2009E-PDF ISBN: 978-1-100-11248-0 Printed in Canada Table of contents

More information

CompTIA CASP (Advanced Security Practitioner)

CompTIA CASP (Advanced Security Practitioner) CompTIA CASP (Advanced Security Practitioner) Course Length: 5 days (virtual) Click here to view the current class schedule! Overview: The CompTIA Advanced Security Practitioner (CASP) Certification is

More information

Presented by Joe Burns Kentucky Rural Water Association July 19, 2005

Presented by Joe Burns Kentucky Rural Water Association July 19, 2005 Infrastructure Security for Public Water and Wastewater Utilities Presented by Joe Burns Kentucky Rural Water Association July 19, 2005 Public Health Security and Bioterrorism Preparedness and Response

More information

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services Enhancing infrastructure cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services European Union Agency for Network and Information Security Securing Europe s Information society 2

More information

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure March 2015 Pamela Curtis Dr. Nader Mehravari Katie Stewart Cyber Risk and Resilience Management Team CERT

More information

Mike Spear, Ops Leader Greg Maciel, Cyber Director INDUSTRIAL CYBER SECURITY PROGRAMS

Mike Spear, Ops Leader Greg Maciel, Cyber Director INDUSTRIAL CYBER SECURITY PROGRAMS Mike Spear, Ops Leader Greg Maciel, Cyber Director INDUSTRIAL CYBER SECURITY PROGRAMS Can You Answer These Questions? 1 What s my company s exposure to the latest industrial cyber threat? Are my plants

More information

The Connected Water Plant. Immediate Value. Long-Term Flexibility.

The Connected Water Plant. Immediate Value. Long-Term Flexibility. The Connected Water Plant Immediate Value. Long-Term Flexibility. The Water Industry is Evolving Reliable, safe and affordable access to water is not solely on the minds of water and wastewater managers.

More information

2018 Annual Report. Colorado Emergency Preparedness Partnership (CEPP)

2018 Annual Report. Colorado Emergency Preparedness Partnership (CEPP) 2018 Annual Report Colorado Emergency Preparedness Partnership (CEPP) Colorado Emergency Preparedness Partnership (CEPP) https://thecepp.org/index.html Who We Are The Colorado Emergency Preparedness Partnership

More information

Implementing Executive Order and Presidential Policy Directive 21

Implementing Executive Order and Presidential Policy Directive 21 March 26, 2013 Implementing Executive Order 13636 and Presidential Policy Directive 21 Mike Smith, Senior Cyber Policy Advisor, Office of Electricity Delivery and Energy Reliability, Department of Energy

More information

TACOMA PUBLIC UTILITIES CYBERSECURITY PROGRAM NIAC WORKSHOP JUNE 2017

TACOMA PUBLIC UTILITIES CYBERSECURITY PROGRAM NIAC WORKSHOP JUNE 2017 TACOMA PUBLIC UTILITIES CYBERSECURITY PROGRAM NIAC WORKSHOP JUNE 2017 AGENDA TPU Cybersecurity Program Overview Document Management & Program Governance Compliance Driven Best Practices Protect, Detect,

More information

National Policy and Guiding Principles

National Policy and Guiding Principles National Policy and Guiding Principles National Policy, Principles, and Organization This section describes the national policy that shapes the National Strategy to Secure Cyberspace and the basic framework

More information

American Association of Port Authorities. Navigating the Cyber Domain. Homeland Security UNCLASSIFIED

American Association of Port Authorities. Navigating the Cyber Domain. Homeland Security UNCLASSIFIED American Association of Port Authorities Navigating the Cyber Domain Captain James Cash Deputy Director U.S. Coast Guard Cyber Command Vision & Mission VISION A safe, secure and resilient cyber operating

More information

Statement for the Record

Statement for the Record Statement for the Record of Seán P. McGurk Director, Control Systems Security Program National Cyber Security Division National Protection and Programs Directorate Department of Homeland Security Before

More information

SENATE, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED DECEMBER 12, 2016

SENATE, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED DECEMBER 12, 2016 SENATE, No. STATE OF NEW JERSEY th LEGISLATURE INTRODUCED DECEMBER, 0 Sponsored by: Senator STEPHEN M. SWEENEY District (Cumberland, Gloucester and Salem) Senator LINDA R. GREENSTEIN District (Mercer and

More information

Dmitry Ishchenko/Reynaldo Nuqui/Steve Kunsman, September 21, 2016 Collaborative Defense of Transmission and Distribution Protection & Control Devices

Dmitry Ishchenko/Reynaldo Nuqui/Steve Kunsman, September 21, 2016 Collaborative Defense of Transmission and Distribution Protection & Control Devices Dmitry Ishchenko/Reynaldo Nuqui/Steve Kunsman, September 21, 2016 Collaborative Defense of Transmission and Distribution Protection & Control Devices Against Cyber Attacks (CODEF) Cyber Security of the

More information

DHS Election Task Force Updates. Geoff Hale, Elections Task Force

DHS Election Task Force Updates. Geoff Hale, Elections Task Force 1 DHS Election Task Force Updates Geoff Hale, Elections Task Force Geoffrey.Hale@hq.dhs.gov ETF Updates Where we ve made progress Services EI-ISAC/ National Cyber Situational Awareness Room What we ve

More information

ENISA Cooperation in the EU / NIS Directive

ENISA Cooperation in the EU / NIS Directive ENISA Cooperation in the EU / NIS Directive Paulo Empadinhas Head of Administration & Stakeholders Relations IT STAR Milan, Italy 28 th October 2016 European Union Agency for Network and Information Security

More information

Ad Hoc Smart Grid Executive Committee. February 10, 2011 New Orleans, LA

Ad Hoc Smart Grid Executive Committee. February 10, 2011 New Orleans, LA Ad Hoc Smart Grid Executive Committee February 10, 2011 New Orleans, LA Agenda Time Topic and Location Lead 3:00 3:10p Welcome & Introductions George Bjelovuk, AEP 3:10 3:40p Regulatory Trends for Cyber

More information

CALIFORNIA CYBERSECURITY TASK FORCE

CALIFORNIA CYBERSECURITY TASK FORCE CALIFORNIA CYBERSECURITY TASK FORCE Advancing California s cybersecurity priorities through public, private, corporate, and academic sector collaboration. Agenda Task Force Overview California Cybersecurity

More information

Homeland Security & All-Hazards Senior Advisory Committee (H-SAC)

Homeland Security & All-Hazards Senior Advisory Committee (H-SAC) Homeland Security & All-Hazards Senior Advisory Committee (H-SAC) Support and Adoption of the H-SAC Strategic Framework Peggy Littleton / Dana Reynolds Presenters Ms. Peggy Littleton, County Commissioner,

More information

THE WHITE HOUSE. Office of the Press Secretary. For Immediate Release September 23, 2014 EXECUTIVE ORDER

THE WHITE HOUSE. Office of the Press Secretary. For Immediate Release September 23, 2014 EXECUTIVE ORDER THE WHITE HOUSE Office of the Press Secretary For Immediate Release September 23, 2014 EXECUTIVE ORDER - - - - - - - CLIMATE-RESILIENT INTERNATIONAL DEVELOPMENT By the authority vested in me as President

More information

VTA s BART Silicon Valley Phase II Extension Project San Jose Downtown Association

VTA s BART Silicon Valley Phase II Extension Project San Jose Downtown Association VTA s BART Silicon Valley Phase II Extension Project San Jose Downtown Association August 24, 2017 THANK YOU! San Jose Downtown Association for inviting us & San Jose First United Methodist Church for

More information

Canada Green Building Council - Greater Toronto Chapter 3-Year Strategic Plan, BUILDING MOMENTUM 3-YEAR STRATEGIC PLAN ( )

Canada Green Building Council - Greater Toronto Chapter 3-Year Strategic Plan, BUILDING MOMENTUM 3-YEAR STRATEGIC PLAN ( ) Canada Green Building Council - Greater Toronto Chapter BUILDING MOMENTUM 3-YEAR STRATEGIC PLAN (2017-2019) Canada Green Building Council - Greater Toronto Chapter Preface About the Canada Green Building

More information

From the Trenches: Lessons learned from using the NIST Cybersecurity Framework

From the Trenches: Lessons learned from using the NIST Cybersecurity Framework From the Trenches: Lessons learned from using the NIST Cybersecurity Framework Greg Witte Sr. Cybersecurity Engineer G2, Inc. Greg.Witte@G2-inc.com Tom Conkle Cybersecurity Engineer G2, Inc. Tom.Conkle@G2-inc.com

More information