Critical Infrastructure Mission Implementation by State, Local, Tribal, and Territorial Agencies and Public-Private Partnerships.

Similar documents
Region Snapshot Regions I and II

South Dakota Utah Wyoming Needs and Challenges Funding assistance Training Federal program enhancements Exercises

Region Snapshot Region IV

Needs and Challenges Funding assistance Training Partnership capabilities and sustainment. Implement Risk Management

The Office of Infrastructure Protection

The Office of Infrastructure Protection

2014 Sector-Specific Plan Guidance. Guide for Developing a Sector-Specific Plan under NIPP 2013 August 2014

DHS Election Task Force Updates. Geoff Hale, Elections Task Force

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

Testimony. Christopher Krebs Director Cybersecurity and Infrastructure Security Agency U.S. Department of Homeland Security FOR A HEARING ON

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

The Office of Infrastructure Protection

U.S. Department of Homeland Security Office of Cybersecurity & Communications

DHS Cybersecurity: Services for State and Local Officials. February 2017

S&T Stakeholders Conference

PIPELINE SECURITY An Overview of TSA Programs

National Preparedness System. Update for EMForum June 11, 2014

Office of Infrastructure Protection Overview

National Infrastructure Resilience

The Office of Infrastructure Protection

Cyber Security & Homeland Security:

The Office of Infrastructure Protection

The US National Near-Earth Object Preparedness Strategy and Action Plan

The Office of Infrastructure Protection

JSC THE JUSTICE & SAFETY CENTER. Snapshot 2014

Implementing Executive Order and Presidential Policy Directive 21

NCPC ANNUAL REPORT 2015 NATIONAL CYBERSECURITY PREPAREDNESS CONSORTIUM. Helping Secure the Nation s Cyber Infrastructure One Community at a Time

DHS Emergency Services Sector Presents Tools and Resources for First Responders. June 1, pm ET

Federal Information Sharing Resources for Small and Midsize Businesses

Private Sector Clearance Program (PSCP) Webinar

Election Infrastructure Security: The How and Why of It

The Office of Infrastructure Protection

STRATEGIC PLAN VERSION 1.0 JANUARY 31, 2015

Cyber Partnership Blueprint: An Outline

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

ARRA State & Local Energy Assurance Planning & Implementation

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

Implementing the Administration's Critical Infrastructure and Cybersecurity Policy

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

CALIFORNIA CYBERSECURITY TASK FORCE

The National Network of Fusion Center: Where We Have Been and Where We are Going

Public Private Partnership

National Preparedness System (NPS) Kathleen Fox, Acting Assistant Administrator National Preparedness Directorate, FEMA April 27, 2015

The Office of Infrastructure Protection

Mississippi Emergency Management Agency. Shawn Wise. Office Of Preparedness

Applying Mitigation. to Build Resilient Communities

Emergency Support Function #2 Communications Annex INTRODUCTION. Purpose. Scope. ESF Coordinator: Support Agencies: Primary Agencies:

Her Majesty the Queen in Right of Canada, Cat. No.: PS4-66/2014E-PDF ISBN:

Emergency Management Response and Recovery. Mark Merritt, President September 2011

Food and Agriculture Sector Criticality Assessment

Member of the County or municipal emergency management organization

Quadrennial Homeland Security Review (QHSR) Ensuring Resilience to Disasters

TERRORISM LIAISON OFFICER OUTREACH PROGRAM - (TLOOP)

First Session of the Asia Pacific Information Superhighway Steering Committee, 1 2 November 2017, Dhaka, Bangladesh.

Critical Infrastructure Resilience

Overview of the Federal Interagency Operational Plans

Civil Air Patrol. National Incident Management System (NIMS) 2016 Refresh Lt Col Bob Ditch HQ CAP/DOSI CITIZENS SERVING COMMUNITIES

Greg Garcia President, Garcia Cyber Partners Former Assistant Secretary for Cyber Security and Communications, U.S. Department of Homeland Security

NGA Governor s Energy Advisors Energy Policy Institute Resiliency Panel

EMERGENCY SUPPORT FUNCTION (ESF) 13 PUBLIC SAFETY AND SECURITY

February 21, pm ET

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

Emergency Operations Center Management Exercise Evaluation Guide

Outreach and Partnerships for Promoting and Facilitating Private Sector Emergency Preparedness

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013

Water Information Sharing and Analysis Center

Critical Infrastructure Protection and Suspicious Activity Reporting. Texas Department of Public Safety Intelligence & Counterterrorism Division

HPH SCC CYBERSECURITY WORKING GROUP

National Infrastructure Protection Plan (NIPP) Transportation Sector Specific Plan (TSSP) and The TSSP R&D Working Group

STRATEGY ATIONAL. National Strategy. for Critical Infrastructure. Government

FEMA Region IX. RRCC Watch Center. August 2009

June 5, 2018 Independence, Ohio

STRATEGIC PLAN. USF Emergency Management

For providing decision support on climate stressors to infrastructure and assets for federal, state, local, and private clients...

Membership

2016 Nationwide Cyber Security Review: Summary Report. Nationwide Cyber Security Review: Summary Report

EPRO. Electric Infrastructure Protection Initiative EPRO BLACK SKY SYSTEMS ENGINEERING PROCESS

EARTH Ex 2017 Middle Planning Conference

Actions to Improve Chemical Facility Safety and Security A Shared Commitment Report of the Federal Working Group on Executive Order 13650

The UNISDR Private Sector Alliance for Disaster Resilient Societies

FY Bay Area UASI Risk and Grants Management Program Update. November 14, 2013

California Cybersecurity Integration Center (Cal-CSIC)

NASEO Central Regional Meeting

Long-Term Power Outage Response and Recovery Tabletop Exercise

Preparedness & BCP Resources: Strategies for Spreading BCP

Good morning, Chairman Harman, Ranking Member Reichert, and Members of

THE WHITE HOUSE. Office of the Press Secretary. EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS

Statement for the Record

ISAO SO Product Outline

National Level Exercise 2018 After-Action Findings

Department of Homeland Security Updates

Federal Civilian Executive branch State, Local, Tribal, Territorial government (SLTT) Private Sector (PS) Unclassified / Business Networks

POSITION DESCRIPTION

79th OREGON LEGISLATIVE ASSEMBLY Regular Session. Senate Bill 90

Kansas City s Metropolitan Emergency Information System (MEIS)

Energy Assurance State Examples and Regional Markets Jeffrey R. Pillon, Director of Energy Assurance National Association of State Energy Officials

Now Available: NIPP 2013: Partnering for Critical Infrastructure Security and Resilience

Critical Infrastructure Protection Committee Strategic Plan

The National Medical Device Information Sharing & Analysis Organization (MD-ISAO) Initiative Session 2, February 19, 2017 Moderator: Suzanne

Hazard Management Cayman Islands

Transcription:

Critical Infrastructure Mission Implementation by State, Local, Tribal, and Territorial Agencies and Public-Private Partnerships May 17, 2016

Overview Regional Overview Project Overview Background and Purpose Project Participants Project Successes Findings: Current State of Critical Infrastructure Mission Implementation State, Local, Tribal, and Territorial Programs Public-Private Partnerships Challenges and Needs Advancing Critical Infrastructure Capabilities Recommendations to Improve Federal Programs Best Practices Annual Outreach 2

Background: Regional Overview Project Background: Collaboration between the SLTTGCC and RC3 partnership councils Build upon previous reports/studies of the partnership councils (Phase 1); submitted to DHS/IP and Council networks SLTTGCC Regional Reports (2011-2013) SLTTGCC Tribal Report (2013) RC3 Member and Mission Landscape Study (2014) Phase 1 Products Phase 2 Products Purpose and Value: Help partners implement the critical infrastructure mission: Support dialogue opportunities among critical infrastructure professionals Develop documents for partners: Region Snapshot, best practice summaries, news articles Work directly with DHS: Articulate stakeholder needs Suggest improvements to DHS critical infrastructure programs to increase use/effectiveness in the field 3

Project Participants 4

Project Successes Directly engaged 200 professionals to understand their perspectives : Council-sponsored Surveys Virtual Roundtable Webinars Region Snapshots Helped the Councils meet other responsibilities: Membership and subject matter expert list development SLTTGCC Sector-Specific Plan Annex Communicated with colleagues across the country to share best practices: Presentations to national conferences Webinars: JCIP and Real-Time Forums (cybersecurity and partnership development) UASI request response (private sector engagement) Newsletters: IP Partnership Quarterly and RC3 Blog Summary Report Worked directly with the DHS Office of Infrastructure Protection: Briefings and discussions with senior DHS personnel Recommendations to improve DHS critical infrastructure programs, tools, and capabilities 5

Findings: SLTT Critical Infrastructure Mission Implementation 1. SLTT critical infrastructure programs vary considerably between jurisdictions. No two programs exactly alike in mission responsibility or resource availability. 2. SLTT critical infrastructure programs are increasingly risk-informed. Programs prioritize efforts based on the dynamic threat environment, despite limited resources. 3. SLTT critical infrastructure programs focus activities on core capabilities: identify infrastructure, assess and analyze risk, build partnerships, and share information. NIPP 2013 Risk Management Framework 6

Findings: Partnership Critical Infrastructure Mission Implementation 4. Public-private partnerships embrace a non-profit, volunteer-based governance structure and are designed to focus on all critical infrastructure issues across all sectors. Most partnerships are non-profits; some are managed by a State/local agency and many collaborate with State/local critical infrastructure programs. The level of activity and success of these partnerships are highly dependent on the energy and capabilities of volunteers. Primary motivator to join partnerships is the opportunity to network, collaborate, and exchange ideas. 12

Findings: Partnership Critical Infrastructure Mission Implementation 5. Public-private partnerships actively contribute to the critical infrastructure mission through valued preparedness and incident response activities: hosting events, sharing information, and coordinating private sector resources and expertise. Preparedness and steady-state activities include gathering and sharing information, hosting or conducting events, and facilitating relationship development. Incident response activities include coordinating private sector resource allocation and distribution, integrating private sector personnel within EOCs, and sharing situational awareness information. 13

Findings: Needs to Sustain Critical Infrastructure Activities 7. Sustainability is a major concern for public-private partnerships across the Nation. Access to additional critical infrastructure education opportunities, stronger connections between partnerships, and improved information-sharing programs and mechanisms are needed. Adaptation to the changing risk environment requires continued education and awareness regarding prominent and emerging critical infrastructure issues. Continuous, routine engagement of stakeholders is imperative for sustainment. More robust connections are needed among partnerships, the private sector, and government. Improvements needed for information-sharing programs and mechanisms include coordination of Federal, SLTT, and private sector platforms, integration of mobile computing technologies, and stronger protections for sensitive private sector information. 15

Recommendations to Improve Federal Programs 1. Update the HSGP and UASI guidance documents to provide clear guidance on cybersecurity expenses and investment justifications and ensure eligible expenses reflect current public-private partnership activity needs. 2. Update the DHS foundational and security awareness Independent Study courses to include advanced critical infrastructure topics specifically tailored to SLTT personnel. 3. Update the FEMA State/Federal Sponsored Training Course Catalog with comprehensive, academically rigorous training courses on advanced critical infrastructure topics. 4. Consolidate and disseminate a suite of successful exercise scenarios for use by SLTT agencies and partnerships in running critical infrastructure exercises. 5. Develop and deploy technical assistance programs for specific SLTT critical infrastructure core capabilities. 6. Consolidate and disseminate best practices on specific SLTT activities. 7. Develop guidance on appropriate Federal/SLTT roles and responsibilities with respect to Federal cybersecurity programs. 16

Recommendations to Improve Federal Programs (continued) 8. Sponsor regional forums to improve regional capacity, facilitate the sharing of best practices, and enable collaboration with peers and experts on emerging issues. 9. Develop a toolkit to facilitate more robust information sharing between SLTT agencies and private sector owners and operators. Include a listing of resources. 10. Increase the speed at which DHS security clearances are granted for SLTT and private sector personnel. 11. Future DHS National Programs and Partnerships Directorate regional offices should serve as coordination hubs for DHS field personnel, SLTT programs, and partnerships. 12. Enhance the user experience of IP Gateway to include valued aspects from ACAMS. 13. Incorporate the IP Gateway views, tools, and capabilities available to PSAs into those available to SLTT personnel. Provide equivalent IP Gateway training used for PSAs to SLTT users. 17

Advancing Critical Infrastructure Capabilities Collaborate with DHS to Improve Federal Programs Grants Building Capabilities Information Sharing and Collaboration DHS Field Offices IP Gateway Private Sector Outreach Cybersecurity Information Sharing Disseminate Best Practices Building cybersecurity program capabilities Hosting all-hazards exercises, topical Webinars, and sector conferences/workshops Active public-private partnerships, lifeline sector councils, and sector-specific working groups Establishing private sector liaison programs and EOC integration Real-time information-sharing networks Resource sharing networks Building local-level assessment and prioritization tools Assessments Resource Networks Nationwide Best Practices Engagements Partnerships Develop Federal Resources Compendium Conduct Annual Outreach to Critical Infrastructure Personnel 18

SLTTGCC/RC3 Regional Working Group: Kevin Clement, State of Texas (SLTTGCC Regional Initiatives Working Group Co-Chair) Tom Moran, All Hazards Consortium (RC3 Vice Chair) Irene Navis, Clark County, Nevada (SLTTGCC Regional Initiatives Working Group Co-Chair) Peter Ohtaki, California Resiliency Alliance (RC3 Executive Committee Member) Shelly Schechter, Nassau County, New York (SLTTGCC Information Sharing Working Group Chair) SLTTGCC Regional Initiatives Working Group: Irene Navis, Clark County, Nevada (Co-Chair) Kevin Clement, State of Texas (Co-Chair) Silvana Croope, State of Delaware Matthew Iannelli, Commonwealth of Massachusetts Susan Palchick, Hennepin County, Minnesota Paul Dean, University of New Hampshire Shelly Schechter, Nassau County, New York Theresa Masse, Port of Portland, Oregon Brian Clement, East Greenwich, Rhode Island Danielle Hale, Nueces County, Texas Jeff Graviet, University of Utah 19