The Australian Government s Approach to Critical Infrastructure Resilience

Similar documents
Outreach and Partnerships for Promoting and Facilitating Private Sector Emergency Preparedness

CIPMA CRITICAL INFRASTRUCTURE PROTECTION MODELLING & ANALYSIS. Overview of CIP in Australia

STRATEGY ATIONAL. National Strategy. for Critical Infrastructure. Government

Telecommunications: Preventing Service Disruption

Energy Assurance Plans

how to manage risks in those rare cases where existing mitigation mechanisms are insufficient or impractical.

Final Draft/Pre-Decisional/Do Not Cite. Forging a Common Understanding for Critical Infrastructure. Shared Narrative

Principles for a National Space Industry Policy

National Policy and Guiding Principles

Critical Information Infrastructure Protection Law

THE WHITE HOUSE. Office of the Press Secretary. EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS

Critical Infrastructure Resilience

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

Australia s national positioning program. Dr John Dawson, Section Leader Positioning

RESILIENT AMERICA ROUNDTABLE: PARTNERING WITH COMMUNITIES TO BUILD RESILIENCE

Building A Disaster Resilient Quebec

Critical Infrastructure Protection (CIP) as example of a multi-stakeholder approach.

June 5, 2018 Independence, Ohio

December 10, Statement of the Securities Industry and Financial Markets Association. Senate Committee on Banking, Housing, and Urban Development

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Implementing Executive Order and Presidential Policy Directive 21

Bradford J. Willke. 19 September 2007

PIPELINE SECURITY An Overview of TSA Programs

The Office of Infrastructure Protection

Government-Industry Collaboration: 7 Steps for Resiliency in Critical Infrastructure Protection

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

The Office of Infrastructure Protection

Alternative Fuel Vehicles in State Energy Assurance Planning

Resilience at JRC. Naouma Kourti. Dep. Head of Unit. Technology Innovation in security Security, Space and Migration Directorate

Statement for the Record

Enhancing the security of CIIPs in Europe - ENISA s Approach Dimitra Liveri Network and Information Security Expert

21ST OSCE ECONOMIC AND ENVIRONMENTAL FORUM

Implementing the Administration's Critical Infrastructure and Cybersecurity Policy

Energy Assurance Energy Assurance and Interdependency Workshop Fairmont Hotel, Washington D.C. December 2 3, 2013

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

AGENCY: National Weather Service, National Oceanic and Atmospheric Administration, U.S.

Emergency Support Function #12 Energy Annex. ESF Coordinator: Support Agencies:

National Cross Sector Forum Action Plan for Critical Infrastructure BUILDING A SAFE AND RESILIENT CANADA

Her Majesty the Queen in Right of Canada, Cat. No.: PS4-66/2014E-PDF ISBN:

Energy Assurance State Examples and Regional Markets Jeffrey R. Pillon, Director of Energy Assurance National Association of State Energy Officials

Shared Responsibility: Roles and Responsibilities in Emergency Management Geoff Hay

PD 7: Homeland Security Presidential Directive 7: Critical Infrastructure Identification, Prioritization, and Protection

Critical Infrastructure Sectors and DHS ICS CERT Overview

ENCS The European Network for Cyber Security

DISASTER RISK MANAGEMENT (DRM/DRR) TEAM

Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA. The African Internet Governance Forum - AfIGF Dec 2017, Egypt

DHS Cybersecurity: Services for State and Local Officials. February 2017

The UNISDR Private Sector Alliance for Disaster Resilient Societies

Cyber Security: Threat and Prevention

COMESA CYBER SECURITY PROGRAM KHARTOUM, SUDAN

Secure Societies Work Programme Call

H2020 Opportunities in the Area of Security and Critical Infrastructure Protection

Critical Infrastructure

Control Systems Cyber Security Awareness

National Infrastructure Resilience

Public Governance and Territorial Development Directorate OECD High Level Risk Forum. Governance of critical risks

Modelling & Simulation for National Security

NATIONAL CYBER SECURITY STRATEGY. - Version 2.0 -

Critical Infrastructure Analysis and Protection - A Case for Secure Information Exchange. August 16, 2016

GPS Vulnerability and DHS Mitigation Efforts. David Wulf Acting Deputy Assistant Secretary Infrastructure Protection Department of Homeland Security

Critical Information Infrastructure Protection. Role of CIRTs and Cooperation at National Level

Michael Rühle, Head, Energy Security Section, NATO ENERGY SECURITY AND NATO: EMERGING CHALLENGES TO CRITICAL ENERGY INFRASTRUCTURE

The UK Water Partnership. Business Plan 2018

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

NATIONAL STRATEGY FOR GLOBAL SUPPLY CHAIN SECURITY

Panel 1 National CSIRT Experience

Office of Infrastructure Protection Overview

Cyber Security in Europe

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

Implementation Strategy for Cybersecurity Workshop ITU 2016

The Hyogo Framework for Action: an instrument to reduce the impact of disasters

Marine Transportation System Resilience: A Federal Agency Perspective

Critical Infrastructure Partnership

The Federal Council s Basic Strategy. for Critical Infrastructure Protection

National Cyber Incident Response - Architectural Concepts

Discussion on MS contribution to the WP2018

The NIS Directive and Cybersecurity in

Future-Proof Security & Privacy in IoT

Security and resilience in the Information Society: the role of CERTs/CSIRTs in the context of the EU CIIP policy

Executive Order on Coordinating National Resilience to Electromagnetic Pulses

Special Action Plan on Countermeasures to Cyber-terrorism of Critical Infrastructure (Provisional Translation)

FINNISH APPROACH TO CRITICAL INFRASTRUCTURE PROTECTION

DHS Supply Chain Activity: Cross-Sector Supply Chain Working Group and Strategy on Global Supply Chain Security

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

Securing Europe s IoT Devices and Services

2014 Sector-Specific Plan Guidance. Guide for Developing a Sector-Specific Plan under NIPP 2013 August 2014

2018 Summary Report into the cyber security preparedness of the National and WA Wholesale Electricity Markets. AEMO report to market participants

CYBER INCIDENT REPORTING GUIDANCE. Industry Reporting Arrangements for Incident Response

Rachel Nibbs, General Manager Resilience and Recovery

The challenges of the NIS directive from the viewpoint of the Vienna Hospital Association

From Hyogo to Sendai. Anoja Seneviratne Disaster Management Centre

Valérie Andrianavaly European Commission DG INFSO-A3

19-20 September 2018 The Trans Resort Kuta, Bali - Indonesia

ASEAN REGIONAL COOPERATION ON DISASTER MANAGEMENT

The Office of Infrastructure Protection

Progress of Regional Cooperation in the Field of Disaster Risk Reduction in Asia

Commonwealth Cyber Declaration

The European Policy on Critical Information Infrastructure Protection (CIIP) Andrea SERVIDA European Commission DG INFSO.A3

Community-Based Water Resiliency

THE LINK BETWEEN ENTERPRISE RISK MANAGEMENT AND DISASTER MANAGEMENT

Transcription:

The Australian Government s Approach to Critical Infrastructure Resilience GNSS Workshop University of New South Wales 4 December 2013 Mr Kris Garred, Director Critical Infrastructure Policy Attorney-General s Department 1

Presentation overview Critical infrastructure policy context Background and operation of the TISN Space infrastructure as critical infrastructure 2

Critical infrastructure definition The Australian and State and Territory Governments define critical infrastructure as: Those physical facilities, supply chains, information technologies and communication networks which, if destroyed, degraded or rendered unavailable for an extended period, would significantly impact on the social or economic wellbeing of the nation or affect Australia s ability to conduct national defence and ensure national security. 3

Role of the Government Community expects the Government to be engaged on issues that impact the nation Failure in Critical infrastructure (CI) could impact our social or economic wellbeing and national security Accordingly, the Australian Government is a key stakeholder in assisting critical infrastructure providers increase their organisational resilience to ensure the continuity of essential services to businesses, governments and the community. 4

The non-regulatory approach The Australian Government generally takes a nonregulatory approach to critical infrastructure, with a focus on developing a strong business-government partnership Owners and operators of critical infrastructure are best placed to manage risks to their operations 5

Critical Infrastructure Resilience Strategy Launched by the then A-G in June 2010 (The) continued operation of critical infrastructure in the face of all hazards, as this critical infrastructure supports Australia s national defence and national security and underpins our economic prosperity and social wellbeing 6

Critical Infrastructure Resilience Strategy 1. Critical infrastructure owners and operators are effective in managing foreseeable risks to the continuity of their operations, through an intelligence and information led, risk-informed approach 2. Critical infrastructure owners and operators enhance their capacity to manage unforeseen or unexpected risk to the continuity of their operations, through an organisational resilience approach 7

The strategic imperatives 1. Operate an effective business-government partnership with critical infrastructure owners and operators 2. Develop and promote an organisational resilience body of knowledge and a common understanding of organisational resilience 3. Assist owners and operators of critical infrastructure to identify, analyse and manage cross-sectoral dependencies 4. Provide timely and high quality policy advice on issues relating to critical infrastructure resilience 5. Implement the Australian Government s Cyber Security Strategy to maintain a secure, resilient and trusted electronic operating environment, including for critical infrastructure owners and operators 6. Support the critical infrastructure resilience programs delivered by Australian States and Territories, as agreed and as appropriate 8

Business Government partnership Why? A significant proportion of Australia s critical infrastructure is privately owned or operated Critical infrastructure resilience cannot be achieved by either Government or Industry alone Partnership required to share information, raise awareness of dependencies and vulnerabilities, and to facilitate collaboration to develop security solutions and address any impediments 9

Business Government partnership How? The Trusted Information Sharing Network (TISN) for Critical Infrastructure Resilience A forum in which the owners and operators of critical infrastructure work together to share security and resilience information The TISN operates on an all hazards basis, including terrorism, natural disasters, pandemics, accidents, cyber attack, criminal activity and negligence 10

The Australian Government s Trusted Information Sharing Network (TISN) Attorney- General Critical Infrastructure Advisory Council (CIAC) Sector Groups Expert Advisory Groups (EAGs) Banking & Finance (AGD) Health (DH) Food Chain (DA) Transport (DIRD) IT Security (DC) Resilience (AGD) Communications (DC) Water Services (AGD) Energy (DI) Oil & Gas Security Forum (DIRD) Communities of Interest (CoI) AGD Attorney-General s Department DIRD Department of Infrastructure and Regional Development DA Department of Agriculture DC Department of Communications DH Department of Health DI Department of Industry

Cross-sectoral dependencies CI networks and operations are becoming increasingly complex and interconnected. A disruption in one CI sector has the potential to significantly impact or disrupt other CI sectors leading to cascading failures A cross-sectoral analysis of dependencies allows CI and the Government to understand system-wide risks that are beyond the purview of individual organisations or sectors Australian Government undertake a number of activities to raise awareness of cross-sectoral dependencies, including conducting cross-sectoral exercises and workshops with industry and running the Critical Infrastructure Program for Modelling and Analysis (CIPMA). 12

Space infrastructure where does it fit in? Space infrastructure is an important enabler of other critical infrastructure Space capabilities are increasingly important aspects of critical infrastructure assets, networks and supply chains. Australia s Satellite Utilisation Policy Global Positioning System (GPS); Global Navigation Satellite System (GNSS); Position, Navigation & Timing (PNT) Satellite communications Earth observation 13

Cross-sectoral dependencies space infrastructure Communication disruption Multiple Sectors Financial transactions Banking and Finance Communications Timing systems Communication disruption Multiple Sectors Energy Energy Resource exploration and drilling Fuel disruption Transport Synchronisation of power grids Power blackouts Multiple Sectors Transport of foodstuff Food and Grocery Disruption to GNSS Infrastructure Supply chain interruption Liquid fuel Health supplies (i.e. pathology services) Multiple Sectors Health Geolocation and positioning Transport accidents Health Chemicals Water Transport Security systems (vehicle tracking) Banking and Finance Customs tracking and coordination Supply chains interruption Multiple Sectors Water Flood monitoring and mitigation Emergency preparation Health 14

Space Community of Interest Satellite Utilisation Policy Principle 7: Protect and enhance national security and economic well-being. The Australian Government will consider opportunities to establish a Space Community of Interest through the Trusted Information Sharing Network to bring relevant interested parties from industry, academia and government together to explore vulnerabilities, including interdependencies between space-related infrastructure and critical infrastructure, and to develop options to mitigate risk. For further information on the Space Community of Interest please contact: Joe Andrews - Space Coordination Unit - Department of Industry Phone: 02 6213 6431 Email: joe.andrews@innovation.gov.au A Space Community of Interest has been established and will hold it s first meeting in early 2014. 15

Further information Attorney-General s Department Web: www.ag.gov.au Email: cir@ag.gov.au Trusted Information Sharing Network Web: www.tisn.gov.au 16

Questions? 17