Regional Resilience: Prerequisite for Defense Industry Base Resilience

Similar documents
Developing a Holistic Strategy To Achieve Community Health Resilience

Building A Disaster Resilient Quebec

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

The Office of Infrastructure Protection

STRATEGY ATIONAL. National Strategy. for Critical Infrastructure. Government

Member of the County or municipal emergency management organization

Infrastructure Interdependencies Tabletop Exercise BLUE CASCADES. Final Report. Executive Summary

Alternative Fuel Vehicles in State Energy Assurance Planning

Emergency Management Response and Recovery. Mark Merritt, President September 2011

Cyber Security & Homeland Security:

Executive Order on Coordinating National Resilience to Electromagnetic Pulses

Energy Assurance State Examples and Regional Markets Jeffrey R. Pillon, Director of Energy Assurance National Association of State Energy Officials

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Outreach and Partnerships for Promoting and Facilitating Private Sector Emergency Preparedness

S&T Stakeholders Conference

Critical Infrastructure Resilience

STATE ENERGY RISK ASSESSMENT INITIATIVE ENERGY INFRASTRUCTURE MODELING AND ANALYSIS. National Association of State Energy Of ficials

RESILIENT AMERICA ROUNDTABLE: PARTNERING WITH COMMUNITIES TO BUILD RESILIENCE

NGA Governor s Energy Advisors Energy Policy Institute Resiliency Panel

National Preparedness System (NPS) Kathleen Fox, Acting Assistant Administrator National Preparedness Directorate, FEMA April 27, 2015

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

Community-Based Water Resiliency

ARRA State & Local Energy Assurance Planning & Implementation

PIPELINE SECURITY An Overview of TSA Programs

National Policy and Guiding Principles

Long-Term Power Outage Response and Recovery Tabletop Exercise

The Office of Infrastructure Protection

DHS Supply Chain Activity: Cross-Sector Supply Chain Working Group and Strategy on Global Supply Chain Security

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

COUNTERING IMPROVISED EXPLOSIVE DEVICES

National Infrastructure Protection Center. Blue Cascades Table Top Exercise Pacific North-West Economic Region

Presidential Documents

The Office of Infrastructure Protection

National Level Exercise 2018 After-Action Findings

Earthquake Preparedness

Implementing the Administration's Critical Infrastructure and Cybersecurity Policy

BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW

STRATEGIC PLAN. USF Emergency Management

The US National Near-Earth Object Preparedness Strategy and Action Plan

Homeland Security Institute. Annual Report. pursuant to. Homeland Security Act of 2002

Overview of the Federal Interagency Operational Plans

Table of Contents. Sample

Cyber Resilience. Think18. Felicity March IBM Corporation

December 10, Statement of the Securities Industry and Financial Markets Association. Senate Committee on Banking, Housing, and Urban Development

The UNISDR Private Sector Alliance for Disaster Resilient Societies

Bradford J. Willke. 19 September 2007

Energy Assurance Energy Assurance and Interdependency Workshop Fairmont Hotel, Washington D.C. December 2 3, 2013

Strengthening Disaster Readiness. Moving from capacity to capability

Emergency Support Function #12 Energy Annex. ESF Coordinator: Support Agencies:

DHS Election Task Force Updates. Geoff Hale, Elections Task Force

STRATEGIC PLAN VERSION 1.0 JANUARY 31, 2015

Regional Disaster Resilience:

Rocky Mountain Cyberspace Symposium 2018 DoD Cyber Resiliency

Emergency Support Function #2 Communications Annex INTRODUCTION. Purpose. Scope. ESF Coordinator: Support Agencies: Primary Agencies:

Why you should adopt the NIST Cybersecurity Framework

2014 Sector-Specific Plan Guidance. Guide for Developing a Sector-Specific Plan under NIPP 2013 August 2014

April 2009 Unclassified // For Official Use Only

IAEA Action Plan on Nuclear Safety

Critical Infrastructure Protection (CIP) as example of a multi-stakeholder approach.

Region Snapshot Regions I and II

The Science and Technology Roadmap to Support the Implementation of the Sendai Framework for Disaster Risk Reduction

Resolution adopted by the General Assembly. [without reference to a Main Committee (A/62/L.30 and Add.1)]

The Office of Infrastructure Protection

MULTI-YEAR TRAINING AND EXERCISE PLAN. Boone County Office of Emergency Management

ISAO SO Product Outline

DHS Cybersecurity: Services for State and Local Officials. February 2017

THE WHITE HOUSE. Office of the Press Secretary. EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS

From Hyogo to Sendai. Anoja Seneviratne Disaster Management Centre

Federal Civilian Executive branch State, Local, Tribal, Territorial government (SLTT) Private Sector (PS) Unclassified / Business Networks

Applying Mitigation. to Build Resilient Communities

Needs and Challenges Funding assistance Training Partnership capabilities and sustainment. Implement Risk Management

FEMA Update. Tim Greten Technological Hazards Division Deputy Director. NREP April 2017

Industry role moving forward

The J100 RAMCAP Method

June 5, 2018 Independence, Ohio

Transportation Security Planning in British Columbia David Morhart, Deputy Solicitor General

Status Update from the Department of Transportation

EISAS Enhanced Roadmap 2012

The National Network of Fusion Center: Where We Have Been and Where We are Going

Office of Infrastructure Protection Overview

Business Continuity: How to Keep City Departments in Business after a Disaster

Presentation on the Community Resilience Program

Testimony. Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON

The Office of Infrastructure Protection

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

All-Hazards Approach to Water Sector Security & Preparedness ANSI-HSSP Arlington, VA November 9, 2011

Statement for the Record

CYBERSECURITY TRAINING EXERCISE KMU TRAINING CENTER NOVEMBER 7, 2017

Energy Assurance Plans

Scope Cyber Attack Task Force (CATF)

Introduction brief to the ISCe Satellite and Communications Conference

Quadrennial Homeland Security Review (QHSR) Ensuring Resilience to Disasters

Hazard Management Cayman Islands

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

STATEMENT GEORGE FORESMAN UNDERSECRETARY FOR PREPAREDNESS U.S. DEPARTMENT OF HOMELAND SECURITY

Resolution adopted by the General Assembly. [on the report of the Second Committee (A/60/488/Add.3)]

March 21, 2016 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES. Building National Capabilities for Long-Term Drought Resilience

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure

Resilience at JRC. Naouma Kourti. Dep. Head of Unit. Technology Innovation in security Security, Space and Migration Directorate

Implementing Executive Order and Presidential Policy Directive 21

Transcription:

Regional Resilience: Prerequisite for Defense Industry Base Resilience Paula Scalingi, Director Pacific Northwest Center for Regional Disaster Resilience Vice Chair, The Infrastructure Security Partnership President, The Scalingi Group, LLC April 2007

Mission Assurance/DIB Resilience Myths There is an industrial base sector Mission assurance equates to Protection (e.g., securing/hardening) of DOD critical assets and key resources Developing self-sufficient, survivable mission-critical bases and facilities In a major disaster, the priority focus of military facilities should be on relocating critical assets and equipment

Mission Assurance/DIB Resilience Realities Focus must be not just inside but outside the fence, cross-sector, grass roots to national level, all threats (including aging and deteriorating infrastructures) all-hazards and regional in scope All disasters are local All trust is local

The Resilience Tautology Resilient DOD assets and industrial base organizations require resilient regions; Regional resilience requires an understanding of infrastructure interdependencies and associated vulnerabilities, consequences of disruptions under specific scenarios, and risk-based mitigation Regional risk assessment and management requires collaboration and information-sharing among key stakeholders, which includes regional DOD assets and industrial base organizations

Scoping the Problem Region any area defined as such by key stakeholders that has a particular culture and coincides with infrastructure service areas; Can be a city, state, multi-jurisdictional area, and/or cross national borders Key stakeholders private and public sector infrastructures and organizations, non-profits, academic/research and community institutions, other entities that play significant roles in providing essential products and services and/or which are necessary for disaster preparedness and management

Building Resilience Beyond the Fence: Regional Interdependencise Initiatives Requires: Recognition by one or more influential local leaders of the importance of regional cooperation/addressing interdependencies Willingness of a state entity, local government or a cross-sector sector non- profit to mobilize and facilitate a public-private private partnership Have a process to enable regional stakeholders to build trust, share s information, and identify vulnerabilities and solutions Develop ways to provide encouragement, technical expertise, resources, and sustainability to improve disaster resilience Provide best practices that key stakeholders can customize to fit regional and organizational needs/cultural norms

Regional Partnering Process 1. Have core organizations willing to take on leadership role to bring broad key stakeholder base together and build trust 2. Hold a kick-off interactive Critical Infrastructure Resilience (CIR) workshop to raise awareness and facilitate networking 3. Enable key stakeholders to design and conduct an infrastructure interdependencies tabletop exercise 4. Produce an exercise report that identifies gaps and recommends solutions 5. Assist stakeholders to develop a prioritized Action Plan of activities for inclusion in existing preparedness plans 6. Define project requirements, secure funding and technical assistance for implementation

Status of Some Regional Interdependencies Initiatives Pacific Northwest Partnership for Regional Infrastructure Security (Blue Cascades Series) San Diego Regional Homeland Security Initiative (Golden Matrix held April 2003) Gulf Coast Regional Partnership for Infrastructure Security (Purple Crescent Series curtailed by Katrina) Great Lakes Partnership Initiative Iowa Partnership for Homeland Security (Amber Waves, May, 2004) Canadian Interdependencies Initiative (Links Series) Maryland Regional Interdependencies Initiative

Blue Cascades Regional Exercise Series Blue Cascades I (June 2002) focused on physical attacks Blue Cascades II (Sept. 2004) focused on both cyber and physical disruptions Blue Cascades III (March 2006) Recovery & Restoration from major earthquake Blue Cascades IV (January 2007) focus on pandemic CI impacts

Blue Cascades IV Objectives 1. Provide a realistic expectation of pandemic impacts on regional infrastructures/essential service providers and communities 2. Provide basic understanding of existing local, state, and federal preparedness plans, policies, regulations, and available resources 3. Assess the level and effectiveness of communication on and coordination of public- private sector and other organizational preparedness and continuity of business or operations plans 4. Examine roles and missions of local, state/provincial, and federal (civilian/defense) agencies and other key stakeholders How intelligent ad hoc decisions are made under changing situations 5. Create an integrated After Action Report that identifies shortfalls and points toward cost-effective mitigation measures

Some Key Lessons Learned No knowledge base of pandemic impacts re interdependencies effects and related vulnerabilities Need for cross-jurisdiction, cross-sector cooperation/coordination Information sharing mechanisms and procedures Roles and responsibilities who s in charge? Response/recovery challenges many and varied Public information needs huge/role of media as a first responder and communicator needs exploring Major Cyber/Com resilience challenges make telecommuting no silver bullet

Next Steps after Blue Cascades IV Review of exercise report by Scenario Design Team followed by review and validation by exercise participants Action Planning Workshop to create strategy of prioritized, specific short-term (one-year), medium-term (18 months-two years) and longer-term projects to address readiness gaps Incorporation of Action Plan projects into integrated Action Plan, state, local, and private sector plans Cooperative development of requirements/project implementation

Value of a Regional Exercise Builds awareness of interdependencies and their impacts Generates cooperation among diverse individuals/organizations Identifies, validates, and helps prioritize shortfalls Leads to collaborative cross-sector and other solutions Can be used by organizations in-house Can be used on a regional or state basis Sensitizes staff and management

Examples of Cooperative Regional Projects of benefit to DOD/DIB Development of Regional Cyber Security/Resilience Coordination mechanism Integrated Biological Restoration Demonstration (IBRD) PNW Columbia River Basin Risk Assessment and Mitigation Study Automated Interdependencies ID Template

Examples of Projects, cont. Regional Information Fusion Center with Con Ops that includes Key Stakeholders through analysts (virtual and in situ) and information sharing protocols that address: Data collection what, how, and by whom Assessment who, how Dissemination who gets what and how Access multiple levels of security Data storage and virtual sharing arrangements Envisioned: Analytic tools for key stakeholders to identify, assess interdependencies and disruption impacts/risk for infrastructure protection/resilience

Moving Beyond the Will do to the How To Achieve DIB Resilience DOD Should: Help develop, sustain, and be integral members of, regional partnerships focused on interdependencies Be part of regional preparedness planning and exercises, information sharing and analysis, and disaster management Work with state, local government, federal agencies and key stakeholders to develop and implement cooperative pilot projects and other activities Develop policies, procedures, and guidelines to make the above happen

Greatest Benefit of All: Overcoming Distrust/Fostering Cooperation Regional Interdependencies Initiatives provide a business case for organizations, regions and nations to overcome deep-rooted differences, suspicions, and stove-piped thinking Enables them to focus on how they can partner with perceived competitors to increase their own readiness and the resilience of the region

The Infrastructure Security Partnership Guide for Regional Disaster Resilience WWW.TISP.ORG

For Further Information: Paula L. Scalingi, Ph.D. Director, Pacific Northwest Center for Regional Disaster Resilience Vice Chair, The Infrastructure Security Partnership President, The Scalingi Group, LLC Tel: 206-443-7723 or 703-760-7847 Fax: 206-443-7703 Mobile: 206-601-9301 or 703-201-9236 Email: paula@pnwer.org or scalingigroup@cox.net