Greg Pannoni, Associate Director

Similar documents
NISP Update NDIA/AIA John P. Fitzpatrick, Director May 19, 2015

Outline. Other Considerations Q & A. Physical Electronic

Outline. Why protect CUI? Current Practices. Information Security Reform. Implementation. Understanding the CUI Program. Impacts to National Security

2018 SRAI Annual Meeting October Dana Rewoldt, CRA, Associate Director of OIPTT, Iowa State University, Ames, IA, USA

Contracting in the Dark World: Special Considerations for Classified Contracting

Federal Initiatives to Protect Controlled Unclassified Information in Nonfederal Information Systems Against Cyber Threats

NIST Special Publication

INFORMATION ASSURANCE DIRECTORATE

OFFICE OF THE DIRECTOR OF NATIONAL INTELLIGENCE INTELLIGENCE COMMUNITY POLICY MEMORANDUM NUMBER

National Policy On Classified Information Spillage

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

ISOO CUI Overview for ACSAC

DFARS Defense Industrial Base Compliance Information

SPRING 2019 INDUSTRIAL SECURITY CONFERENCE AGENDA

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013

INFORMATION ASSURANCE DIRECTORATE

NIST RISK ASSESSMENT TEMPLATE

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management

Cybersecurity & Privacy Enhancements

DFARS Cyber Rule Considerations For Contractors In 2018

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors

PilieroMazza Webinar Preparing for NIST SP December 14, 2017

IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION

Preparing for NIST SP January 23, 2018 For the American Council of Engineering Companies

New Process and Regulations for Controlled Unclassified Information

UNIVERSITY OF VIRGINIA BOARD OF VISITORS. Meeting of the Audit, Compliance, and Risk Committee

DoD Internet Protocol Version 6 (IPv6) Contractual Language

ISAO SO Product Outline

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

INFORMATION ASSURANCE DIRECTORATE

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

Why is the CUI Program necessary?

Policies and Procedures Date: February 28, 2012

Greg Garcia President, Garcia Cyber Partners Former Assistant Secretary for Cyber Security and Communications, U.S. Department of Homeland Security

Information System Profile

INTRODUCTION TO DFARS

Rocky Mountain Cyberspace Symposium 2018 DoD Cyber Resiliency

IT Risk Management and Cybersecurity Summit

DFARS Compliance. SLAIT Consulting SECURITY SERVICES. Mike D Arezzo Director of Security Services. SLAITCONSULTING.com

Committee on National Security Systems. CNSS Policy No. 14 November 2002

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations (NIST SP Revision 1)

CyberUSA Government Cyber Opportunities for your Region: The Federal Agenda - Federal, Grants & Resources Available to Support Community Cyber

INFORMATION ASSURANCE DIRECTORATE

Controlled Unclassified Information (CUI) and FISMA: an update. May 12, 2017 Mark Sweet, Nancy Lewis, Grace Park Stephanie Gray, Alicia Turner

CYBERSECURITY FEDERAL UPDATE. NCSL Cybersecurity Task Force

Student Guide Course: Introduction to the NISP Certification and Accreditation Process

INFORMATION ASSURANCE DIRECTORATE

Information Technology Security Plan Policies, Controls, and Procedures Identify Governance ID.GV

NATIONAL GUIDELINES ON CLOUD COMPUTING FOR GOVERNMENT, MINISTRIES, DEPARTMENTS AND AGENCIES

Executive Order 13556

Implementation Plan for the UW-Madison Cybersecurity Risk Management Policy. August 10, 2017 version

Good morning, Chairman Harman, Ranking Member Reichert, and Members of

INFORMATION ASSURANCE DIRECTORATE

Virginia State University Policies Manual. Title: Change/Configuration Management Policy: 6810 A. Purpose

Insider Threat and Security Clearance Reform

National Information Assurance (IA) Policy on Wireless Capabilities

300 Riverview Plaza Odysseus Marcopolus, Chief Operating Officer Trenton, NJ POLICY NO: SUPERSEDES: N/A VERSION: 1.0

COMPLIANCE IN THE CLOUD

CYBER SECURITY BRIEF. Presented By: Curt Parkinson DCMA

Data Governance Strategy

SAC PA Security Frameworks - FISMA and NIST

Special Publication

National Archives and Records Administration

Cybersecurity Challenges

Get Compliant with the New DFARS Cybersecurity Requirements

DoD Software Assurance Initiative. Mitchell Komaroff, OASD (NII)/DCIO Kristen Baldwin, OUSD(AT&L)/DS

Information Collection Request: The Department of Homeland. Security, Stakeholder Engagement and Cyber Infrastructure

INFORMATION ASSURANCE DIRECTORATE

Information Systems Security Requirements for Federal GIS Initiatives

Cybersecurity Risk Management

Managing the Intelligence Community Information Environment

-Eight types of cyber data, (Sec. 708(7))

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

existing customer base (commercial and guidance and directives and all Federal regulations as federal)

INFORMATION ASSURANCE DIRECTORATE

Audit of Information Technology Security: Roadmap Implementation

July SNIA Technology Affiliate Membership Overview

SYSTEMS ASSET MANAGEMENT POLICY

GAO INFORMATION SHARING ENVIRONMENT

PRESIDENT BARACK OBAMA, DECEMBER 2012 NATIONAL STRATEGY FOR INFORMATION SHARING AND SAFEGUARDING

Cyber Partnership Blueprint: An Outline

NISPOM Change 2: Considerations for Building an Effective Insider Threat Program

Cybersecurity in Higher Ed

UCOP ITS Systemwide CISO Office Systemwide IT Policy

NASA Policy Directive

OFFICE OF THE UNDER SECRETARY OF DEFENSE 3000DEFENSEPENTAGON WASHINGTON, DC

MNsure Privacy Program Strategic Plan FY

TIPS FOR FORGING A BETTER WORKING RELATIONSHIP BETWEEN COUNSEL AND IT TO IMPROVE CYBER-RESPONSE

The U.S. National Spatial Data Infrastructure

B. To ensure compliance with federal and state laws, rules, and regulations, including, but not limited to:

Critical Infrastructure Protection Version 5

Data Privacy & Protection

Technical Advisory Board (TAB) Terms of Reference

Career Center for Development of Security Excellence (CDSE) Pre-Approved for CompTIA CEUs

TRIAEM LLC Corporate Capabilities Briefing

OFFICE OF THE ASSISTANT SECRETARY OF DEFENSE HEALTH AFFAIRS SKYLINE FIVE, SUITE 810, 5111 LEESBURG PIKE FALLS CHURCH, VIRGINIA

Virginia State University Policies Manual. Title: Information Security Program Policy: 6110

UNCLASSIFIED. September 24, In October 2007 the President issued his National Strategy for Information Sharing. This

Transcription:

Greg Pannoni, Associate Director May 2018

The Evolving NISP: Navigating the Road Ahead NISPOM revision Revision to NISP Directive (32 CFR 2004) CUI program implementation 3

National Industrial Security Program (NISP) (E.O. 12829) single, cohesive, integrated program to ensure the protection of classified information in the hands of industry Requirements based on consideration of 3 pillars: Damage to national security Threat to disclosure Cost of requirements To the extent that is practicable and reasonable, those requirements shall be consistent across government and industry. Implemented through 32 CFR Part 2004, NISP Directive 4

NISPOM Reissuance Who: DoD as Executive Agent NISPPAC NISPOM Rewrite Working Group chaired by ISOO What: Updates 2006 NISPOM version, includes Changes 1-3 Goal: up-to-date NISP operations Changing threat landscape Cybersecurity environment Major changes: Focuses solely on classified information. Removes references to unclassified. Removes government agency responsibilities Incorporates Risk Management Framework (RMF) for information systems Incorporates new national-level reporting requirements References other national-level policies as they apply, vice duplicating within the NISPOM When: Estimated CY 2019 as a Federal Rule 5

NISP Directive (32 CFR Part 2004) ISOO responsible for issuing the Directive to implement the NISP New version issued on May 7, 2018 Effective date: June 5, 2018 Establishes responsibilities for NISP agencies ISOO Executive Agent CSAs GCAs 6

New 32 CFR 2004 Adds insider threat responsibilities and requirements for NISP agencies (E.O. 13587) Recognizes ODNI as a CSA (Intelligence Reform & Terrorism Prevention Act) Recognizes DHS as a CSA and incorporates White House approved provisions for the DHS Classified Critical Infrastructure Protection Program (E.O. 13691) Fills policy gaps for NISP agencies to align with NISPOM provisions for contractors Consistent standards for determinations of contractor eligibility for access to classified information Consistent standards to determine and mitigate FOCI and make NIDs Contract security classification responsibilities Oversight of contractor industrial security programs Terminology and definitions to accommodate all 5 CSAs Focus on accountability of the government and better defines its responsibilities 7

National Industrial Security Program Policy Advisory Committee (NISPPAC) Addresses policy issues and other NISP matters of interest and concern ISOO Director chairs 16 government and 8 industry members Subject to FACA Meeting notices in the Federal Register Meets 3x/year Working groups Clearance NISP Information Systems Authorization Insider threat NID NISPOM rewrite Next public meeting: Wed. July 19, 2018, National Archives 8

NISPPAC INDUSTRY MEMBERS Daniel McGarvey Alion Science and Technology Term: 2017-2021` e-mail: Daniel.a.mcgarveysr@gmail.com Dennis Arriaga Term: 2017-2021 Michelle Sutphin * SRI International e-mail: dennis.arriaga@sri.com BAE Systems Term: 2014-2018 e-mail: michelle.sutphin@baesystems.com * Industry Spokesperson Martin Strones Strones Enterprises Term: 2014-2018 e-mail: mstrones@gmail.com Dennis Keith Harris Corporation Term: 2015-2019 e-mail: Dkeith@harris.com Quinton Wilkes L-3 Communications Corporation Term: 2015-2019 e-mail: Quinton.Wilkes@L3T.com Kirk Poulsen Leidos, Inc Term: 2016-2020 e-mail: Kirk.A.Poulsen@leidos.com Robert Harney Northrup Grumman Term: 2016-2020 e-mail: Robert.Harney@ngc.com

Controlled Unclassified Information Program Implementation Projection (3-4 years). Implementation Activities (Focus on: Leadership, Policy, Training, and Annual Report to the President). Registry and Marking Handbook Revisions. CUI Notice 2018-01 (Guidance for drafting agreements). CUI Notice 2018-02 (Recommendations for basic training). Federal Acquisition Regulation for CUI (FY19). Training videos (YouTube). CUI Blog (https://isoo.blogs.archives.gov/).

ISOO Web Resources ISOO web page: http://www.archives.gov/isoo/ ISOO policy documents: E.O. 12829: https://www.archives.gov/files/isoo/policy-documents/eo-12829-with-eo- 13691-amendments.pdf Implementing Directive (32 C.F.R. Part 2004): https://www.archives.gov/files/isoo/policy-documents/32-cfr-part-2004.pdf https://www.archives.gov/files/isoo/policy-documents/32-cfr-part-2004- amendment.pdf NISP and NISPPAC pages Member listings Charter and Bylaws Minutes of NISPPAC meetings CUI web page: https://www.archives.gov/cui 11

12

13