AAPA Smart Ports. Cyber Management for Ports Panel. Small Port Cyber Security Workshops. March 6, 2018

Similar documents
Cyber Management for Ports Results of Small Port Cyber Security Workshops

American Association of Port Authorities. Navigating the Cyber Domain. Homeland Security UNCLASSIFIED

ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED FEBRUARY 4, 2016

Cybersecurity Risk Management:

Implementing Executive Order and Presidential Policy Directive 21

PIPELINE SECURITY An Overview of TSA Programs

Implementing the Administration's Critical Infrastructure and Cybersecurity Policy

Commonwealth Cyber Declaration

Critical Infrastructure Protection (CIP) as example of a multi-stakeholder approach.

COUNTRY PROFILE. Malaysia

National Policy and Guiding Principles

Doug Couto Texas A&M Transportation Technology Conference 2017 College Station, Texas May 4, 2017

Public Power Forward Challenges & Opportunities

Marine Transportation System Resilience: A Federal Agency Perspective

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure

The Office of Infrastructure Protection

The UNISDR Private Sector Alliance for Disaster Resilient Societies

79th OREGON LEGISLATIVE ASSEMBLY Regular Session. Senate Bill 90

Cybersecurity governance in Europe. Sokratis K. Katsikas Systems Security Laboratory Dept. of Digital Systems University of Piraeus

DAPhNE Danube Ports Network Motivation & Project Status Q4 / 2018

Regional Security Initiatives in the Columbia River. One Port s Prospective

Principles for a National Space Industry Policy

COUNTRY PROFILE. Colombia

Inter-American Port Security Cooperation Plan

Mapping to the National Broadband Plan

The APEC Model. Global Partnership through Regional Initiatives

COUNTRY PROFILE. Italy

The Africa Utilities Telecom Council Johannesburg CC, South Africa 1 st December, 2015

Technical Conference on Critical Infrastructure Protection Supply Chain Risk Management

STRATEGIC PLAN. USF Emergency Management

COUNTRY PROFILE. Philippines

Resiliency & Maritime Security Preparedness Planning

UAE National Space Policy Agenda Item 11; LSC April By: Space Policy and Regulations Directory

EUROPEAN ORGANISATION FOR SECURITY SUPPLY CHAIN SECURITY WHITE PAPER

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

COMESA CYBER SECURITY PROGRAM KHARTOUM, SUDAN

COUNTRY PROFILE. Mexico

December 10, Statement of the Securities Industry and Financial Markets Association. Senate Committee on Banking, Housing, and Urban Development

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

The NIST Cybersecurity Framework

Marine Security Overview

Master Plan on ASEAN Connectivity 2025: A Blueprint for a Stronger ASEAN

COUNTRY PROFILE. Korea Republic

COUNTRY PROFILE. Estonia

Position Title: IT Security Specialist

Provisional Translation

NATIONAL STRATEGY FOR GLOBAL SUPPLY CHAIN SECURITY

European Cybersecurity PPP European Cyber Security Organisation - ECSO

DHS Cybersecurity: Services for State and Local Officials. February 2017

COUNTRY PROFILE. Qatar

About Issues in Building the National Strategy for Cybersecurity in Vietnam

COUNTRY PROFILE. Brazil

Donor Countries Security. Date

March 21, 2016 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES. Building National Capabilities for Long-Term Drought Resilience

Department of Defense. Installation Energy Resilience

COUNTRY PROFILE. Iceland

Cybersecurity and Data Protection Developments

COUNTRY PROFILE. Russia

COUNTRY PROFILE. Bulgaria

Poland: Initiative for Polish Industry 4.0 The Future Industry Platform

Department of Homeland Security Customs and Border Protection. Centers of Excellence and Expertise

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Bradford J. Willke. 19 September 2007

American Association of Port Authorities Port Security Seminar & Expo Cyber Security Preparedness and Resiliency in the Marine Environment

COUNTRY PROFILE. Croatia

Thailand Digital Government Development Plan Digital Government Development Agency (Public Organization) (DGA)

Commonwealth Telecommunications Organisation Proposal for IGF Open Forum 2017

The NIS Directive and Cybersecurity in

SAINT PETERSBURG DECLARATION Building Confidence and Security in the Use of ICT to Promote Economic Growth and Prosperity

Cybersecurity & Digital Privacy in the Energy sector

Canada s Asia-Pacific Gateway and Corridor Initiative and Future Gateway Strategies

Department of Homeland Security Updates

Office of Infrastructure Protection Overview

CYBERSECURITY AND THE MIDDLE MARKET

Defense Security Service. Strategic Plan Addendum, April Our Agency, Our Mission, Our Responsibility

Mergers & Acquisition in an Evolving and Consolidating Industry. CoBank Rob West, SVP. May 12, 2016

How Sendai Framework will affect future Resilience for Business & Consumers

National Preparedness System (NPS) Kathleen Fox, Acting Assistant Administrator National Preparedness Directorate, FEMA April 27, 2015

Cyber Risk for Maritime

THE WHITE HOUSE. Office of the Press Secretary EXECUTIVE ORDER

Angela McKay Director, Government Security Policy and Strategy Microsoft

Performance Measurement, Data and Decision Making: A Matter of Alignment. Mark F. Muriello Assistant Director Tunnels, Bridges & Terminals

Private Sector Engagement in Disaster Risk Reduction

THE WHITE HOUSE Office of the Press Secretary EXECUTIVE ORDER

South Dakota Utah Wyoming Needs and Challenges Funding assistance Training Federal program enhancements Exercises

COUNTRY PROFILE. Taiwan

ITG. Information Security Management System Manual

Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

COUNTRY PROFILE AUSTRALIA

Security and Privacy Governance Program Guidelines

System-of-systems framework for global infrastructure vulnerability assessment

Cybersecurity for ALL

UNSCR 1540 Compliance From Policy to Implementation

The U.S. Manufacturing Extension Partnership - MEP

COUNTERING IMPROVISED EXPLOSIVE DEVICES

ARRA State & Local Energy Assurance Planning & Implementation

Jane s Defence Industry & Markets Intelligence Centre. Develop Advantage. Mitigate Risk. Capture Opportunity.

Transportation Security Planning in British Columbia David Morhart, Deputy Solicitor General

8 th APEC Transportation Ministerial Meeting Tokyo, Japan SEPTEMBER 5, 2013 Ministerial Joint Statement

Transcription:

AAPA Smart Ports Cyber Management for Ports Panel Small Port Cyber Security Workshops March 6, 2018 1200 New Jersey Ave., SE Washington DC 20590 w w w. d o t. g o v

Port Infrastructure Development More than 300 U.S. ports ( approximately 175 public ports) serve as Gateways to world markets for U.S. products and as intermodal hubs for exports and domestic distribution. Waterborne commerce contributes more than $649 billion annually to the U.S. GDP, and sustains more than 13 million jobs. 42% of the value of exports and imports (71% by volume) leaves or enters the U.S. by water. 2

Transportation Supply Chain 3

Marine Terminal Information Systems 4

Cyber Threat Issues 5

Maritime Administration MISSION: Strengthen the U.S. marine transportation system including infrastructure, industry and labor to meet the economic and security needs of the Nation. STRATEGIC GOALS: CARGO: Develop domestic and international transportation opportunities to modernize and sustain a competitive commercial U.S.-flag fleet that ensures the Nation s economic and national security READINESS: Ensure the availability of a capable U.S. Merchant Marine fleet with modern U.S.-flag vessels, skilled labor and global logistics support to drive the Nation s economy and to meet national maritime transportation requirements in peacetime emergencies and armed conflicts INFRASTRUCTURE: Support the development of America s ports, shipyards and related intermodal infrastructure as key integrated components of an efficient, resilient and sustainable national transportation system and freight network ADVOCACY: Advance awareness of the necessity and importance of a strong U.S. Marine Transportation System 6

MARAD Program Elements 7

Ports & Waterways Infrastructure Provide Port and Intermodal Planning Assistance Access Funding and Financing Options for Port Modernization and Expansion Educate re: P3 Opportunities Expand domestic movement of freight by waterborne transportation Administer Grants and Loans for Projects These services are offered to Port Authorities, State Departments of Transportation, Metropolitan Planning Organizations, and Regional and Local communities. Also offered to privately owned port terminal operators, vessel operators, export industry groups, manufacturers, and other stakeholders. Technology Development Cargo Handling Cooperative Program 8

Cargo Handling Cooperative Program BACKGROUND: The Cargo Handling Cooperative Program (CHCP) was established in 1983 by the Maritime Administration (MARAD) to work on the issue of productivity in the marine freight transportation sector. The CHCP was set up as a public-private partnership designed to foster research and technology development to increase productivity of cargo operations. In 1996 the CHCP revised its membership to include all intermodal entities. ORGANIZATION: The CHCP is run by its members with MARAD acting as sponsor and catalyst. The head of the CHCP is a Chair person who is assisted by a Vice-Chair, both are elected by the membership. The CHCP also has a Treasurer to oversee all financial activities of the organization, also elected by the members. The day-today activities are performed by a Program Administrator, which is currently done by MARAD. 9

Cargo Handling Cooperative Program (cont.) FOCUS: The overall focus of the CHCP is to assist the intermodal industry with its own technology priorities. This focus is critical for the movement of international and domestic freight. It has been proven that the use of advanced technologies can lead to (1) more efficient infrastructure design, (2) more productive international transportation networks, and (3) better communication and information flows. This approach allows technology to be used in segments of the transportation network to help the total transportation system work more efficiently. PROJECTS: ISO 10374 Automatic Identification of Freight Containers 1991 Optical Character Recognition at Marine Terminals 1996 Chassis Tag Location on Container Chassis 2001 Electronic Seals for Container Security 2003 Marine Terminal Productivity Study 2010 10

Cargo Handling Cooperative Program (cont.) Recently, MARAD and the CHCP have identified a specific group within the maritime sector that has a need for assistance in the increasingly complex area of cybersecurity. Small ports (those with fewer than 50 employees or under 20 million tons of cargo) are having a difficult time navigating the issues that arise from cybersecurity requirements. Cybersecurity is an evolving area that has many facets. With so much emphasis on data movement and electronic processing, ports, marine terminals and their customers are vulnerable to a number of security problems. MARAD, through the CHCP, has teamed with Hudson Analytix to develop a small port cyber security workshop program. MARAD staff contacted several small ports to seek their interest in participating in a workshop to assess their individual readiness under a number of different criteria. The results of the individual assessments are only known by the port. MARAD an the CHCP have been provided a combined view of all three assessments. 11

Small Ports Cybersecurity Workshop Project Geographic Diversity of Ports East Coast West Coast Great Lakes Variety of Cargo Types Bulk Project cargo Containers Cargo Tonnage Handled 1 port < 20 million tons 2 ports < 10 million tons Staff Size <40 full time staff members 12

HudsonAnalytix HudsonAnalytix, Inc. offers integrated risk management and technical advisory services to the global maritime industry. Clients include: Port Authorities and terminal operators National and regional port systems Integrated oil/gas companies National oil companies Global maritime transportation companies Insurance companies Governments Operating Divisions: HudsonCyber - Cybersecurity + Risk Management HudsonSystems - Software Solutions HudsonTrident - Security (Physical and Operational) HudsonMarine - Operational Marine Management HudsonTactix - Consequence Management Key Facts Established in 1986 Worldwide Presence: Philadelphia (Global HQ) Washington, DC San Diego, CA Houston, TX Santo Domingo, Dominican Republic London, UK Rome, Italy Piraeus, Greece Jakarta, Indonesia (JV) Manila, Philippines 13

Objectives 1. Identify the current state of cyber risk in and provide recommendations to MARAD- and CHCP-designated ports 2. Provide MARAD with a summary of project findings and recommendations for how to support small US ports with future cyber risk management activities 3. Explore how to modify the HACyberLogix application for the maritime terminal environment. 14

Cybersecurity Capability Maturity what is it? 15

Common Strengths Cyber Risk Management Governance Workforce and Training Change Management Situational Awareness Information Sharing Threat and Vulnerability Management Commercial Information and Communications Technology Incident Response and Continuity of Operations Physical Security Cyber Program Management 16

Common Areas for Improvement Cyber Risk Management Governance Workforce and Training Change Management Situational Awareness Information Sharing Threat and Vulnerability Management Commercial Information and Communications Technology Incident Response and Continuity of Operations Physical Security Cyber Program Management 17

Priority Recommendations Establish governance framework Develop strong cybersecurity program Implement basic course required for all personnel Train executives Establish roles and responsibilities Update procurement policies, procedures, and notification reporting Update/amend FSPs to include cyber risk factors Establish and maintain activities to coordinate the collection, aggregation, and use of data, such as log data, from critical IT and OT assets Leverage existing structure to establish information-sharing mechanisms with port community, law enforcement, and regulatory bodies Establish dedicated and sustainable budgets for addressing cyber risks 18