Maintaining Resiliency Within the Defense Industrial Base Through Preparedness Response and Recovery

Similar documents
BOEING OVERVIEW. Connect Protect Explore Inspire. Copyright 2018 Boeing. All rights reserved.

BOEING OVERVIEW. Connect Protect Explore Inspire. Copyright 2018 Boeing. All rights reserved.

Business Continuity Planning

Continuity of Business

Business Continuity: How to Keep City Departments in Business after a Disaster

How to Conduct a Business Impact Analysis and Risk Assessment

TUFTS HEALTH PLAN CORPORATE CONTINUITY STRATEGY

Build a viable plan for disaster recovery and crisis management.

STRATEGY ATIONAL. National Strategy. for Critical Infrastructure. Government

Bradford J. Willke. 19 September 2007

Quadrennial Homeland Security Review (QHSR) Ensuring Resilience to Disasters

Business Continuity and Disaster Recovery

BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW

Why you should adopt the NIST Cybersecurity Framework

Appendix 3 Disaster Recovery Plan

FEMA Update. Tim Greten Technological Hazards Division Deputy Director. NREP April 2017

Cyber Resilience. Think18. Felicity March IBM Corporation

WHITE PAPER OCTOBER 2017 VMWARE ENTERPRISE RESILIENCY. Integrating Resiliency into Our Culture and DNA

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

Addressing Vulnerabilities By Integrating Your Incident Response Plans. Brian Coates Enaxis Consulting

La gestione di Security e Safety con un singolo sistema di supporto alle decisioni Baltimore/Washington Airport - USA

Outreach and Partnerships for Promoting and Facilitating Private Sector Emergency Preparedness

Security Director - VisionFund International

National Cyber Incident Response - Architectural Concepts

All-Hazards Approach to Water Sector Security & Preparedness ANSI-HSSP Arlington, VA November 9, 2011

Critical Information Infrastructure Protection Law

Business continuity management and cyber resiliency

Executive Order on Coordinating National Resilience to Electromagnetic Pulses

Number: USF System Emergency Management Responsible Office: Administrative Services

How ISO helps organisation to achieve operational readiness Ong Liong Chuan 26 Apr 2016

New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines

EQUINIX BUSINESS CONTINUITY ADVANCED SERVICES KEEP YOUR BUSINESS UP AND RUNNING

Business Continuity Management Program Overview

Applying Mitigation. to Build Resilient Communities

2 nd Cybersecurity Workshop Test and Evaluation to Meet the Advanced Persistent Threat

Security Guideline for the Electricity Sector: Business Processes and Operations Continuity

CRITICAL INFRASTRUCTURE AND KEY RESOURCES

MARCH 2016 ONE BILLION COALITION FOR RESILIENCE

Data Recovery Policy

Local Government Disaster Planning and what can be learned from it.

STRATEGIC PLAN. USF Emergency Management

Balancing Compliance and Operational Security Demands. Nov 2015 Steve Winterfeld

The Need for Operational and Cyber Resilience in Transportation Systems

Cyber Risk in the Marine Transportation System

Cybersecurity, safety and resilience - Airline perspective

Introduction brief to the ISCe Satellite and Communications Conference

Presidential Documents

SOLUTION BRIEF RSA ARCHER BUSINESS RESILIENCY

Business Continuity Policy

Risk Management. Continuity Management

Integrating Cyber Security with Business Continuity Management to Build the Resilient Enterprise

EMERGENCY SUPPORT FUNCTION (ESF) 13 PUBLIC SAFETY AND SECURITY

MassMutual Business Continuity Disclosure Statement

THE LINK BETWEEN ENTERPRISE RISK MANAGEMENT AND DISASTER MANAGEMENT

Bringing cyber to the Board of Directors & C-level and keeping it there. Dirk Lybaert, Proximus September 9 th 2016

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Introduction to Business continuity Planning

Joining Forces: Collaborating with Law Enforcement to Boost Resilience

01.0 Policy Responsibilities and Oversight

Emergency Support Function #12 Energy Annex. ESF Coordinator: Support Agencies:

3.4 DISASTER RECOVERY (L , M.3.9, comp_req_id 806)

Global Security Consulting Services, compliancy and risk asessment services

NYDFS Cybersecurity Regulations

Heavy Vehicle Cyber Security Bulletin

Introduction to the National Response Plan and National Incident Management System

Business Continuity Management

NUIT Tech Talk. Emergency Preparedness. March 1, Sharlene Mielke. Jay Bagley. Disaster Recovery / Business Continuity Coordinator

THE WHITE HOUSE. Office of the Press Secretary. EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS

Securing Your Digital Transformation

December 10, Statement of the Securities Industry and Financial Markets Association. Senate Committee on Banking, Housing, and Urban Development

Symantec Security Monitoring Services

Table of Contents. Sample

Member of the County or municipal emergency management organization

Virginia State University Policies Manual. Title: Information Security Program Policy: 6110

STRENGTHENING THE CYBERSECURITY OF FEDERAL NETWORKS AND CRITICAL INFRASTRUCTURE

Critical Infrastructure Protection (CIP) as example of a multi-stakeholder approach.

SYMANTEC: SECURITY ADVISORY SERVICES. Symantec Security Advisory Services The World Leader in Information Security

Building a BC/DR Control Library and Regulatory Response Program

National Cyber Security Strategy - Qatar. Michael Lewis, Deputy Director

INTELLIGENCE DRIVEN GRC FOR SECURITY

Final Draft/Pre-Decisional/Do Not Cite. Forging a Common Understanding for Critical Infrastructure. Shared Narrative

Making YOUR Organization More Efficient and Effective Through Business Continuity / Continuity of Operations Planning

Airport Security & Safety Thales, Your Trusted Hub Partner

TIPS FOR FORGING A BETTER WORKING RELATIONSHIP BETWEEN COUNSEL AND IT TO IMPROVE CYBER-RESPONSE

National Policy and Guiding Principles

CCISO Blueprint v1. EC-Council

Integration of Business Continuity, Emergency Preparedness, and Emergency Response

Business Continuity Management Standards A Side-by-Side Comparison

Corporate Security & Emergency Management Summary of Submitted 2015 Budget From Rates

NATIONAL STRATEGY FOR GLOBAL SUPPLY CHAIN SECURITY

Exam4Tests. Latest exam questions & answers help you to pass IT exam test easily

NHS Gloucestershire Clinical Commissioning Group. Business Continuity Strategy

The Common Controls Framework BY ADOBE

HOTEL RESILIENT Plan ahead stay ahead. With support from the German Government through

Hazard Management Cayman Islands

Oracle Buys Palerra Extends Oracle Identity Cloud Service with Innovative Cloud Access Security Broker

Cyber Security Program

Implementing a Global Business

Panel 1 National CSIRT Experience

CYBER SECURITY AIR TRANSPORT IT SUMMIT

Transcription:

Maintaining Resiliency Within the Defense Industrial Base Through Preparedness Response and Recovery Dave Komendat Chief Security Officer The Boeing Company

What We Do Today Design, assemble and support commercial jetliners Boeing 7-series family of airplanes lead the industry Commercial Aviation Services (CAS) offers broad range of services to passenger and freight carriers Design, assemble and support defense systems World s largest designer and manufacturer of military transports, tankers, fighters and helicopters Support Systems provides services to government customers worldwide Design and assemble satellites and launch vehicles World s largest provider of commercial and military satellites; largest NASA contractor Integrate large-scale systems; develop networking technology and network-centric solutions Provide financing solutions focused on customer requirements Develop advanced systems and technology to meet future customer needs Connect and protect people globally

Global Boeing Customers in more than 90 countries Total revenue in 2008: $60.9 billion 70 percent of commercial airplane revenue historically from customers outside the United States Manufacturing, service and technology partnerships with companies around the world Contracts with 22,000 suppliers and partners globally Research, design and technology-development centers and programs in multiple countries More than 160,000 Boeing employees in 49 states and 70 countries Partnering worldwide for mutual growth and prosperity

How We Are Organized World-class performance Commercial Airplanes Integrated Defense Systems Corporate functions: Business Development and Strategy Communications Engineering, Operations and Technology Finance/Shared Services Group/Boeing Capital Corp. Human Resources/Administration International Law Office of Internal Governance Government Relations Delivering products and services to commercial and defense customers

Presidential Disaster Declarations 1965-2003

Achieving 2016 Vision Requires the ability to manage and mitigate impact of events on the business Business Continuity contributes by: Preparing and testing formal plans that provide the ability to respond and recover from impacting events to the business Integrating three disciplines of Emergency Preparedness, Information Technology Preparedness and Business Preparedness

Physical Security & Information Security Relationship Promotes Collaboration Security & Fire Protection CSO Common Sharing Threat Info Facility Assessments Projects, e.g. Secure Badge Issuance Domestic Security Activity International Security Activity DoD Program Support Common Sharing Threat Info IT Assessments Projects, e.g. Secure Badge Specifications DIB Activity Information Security CISO IS Policy & Governance Risk Management Technical Controls Data Protection Forensics Monitoring & Response Identity Management Access Provisioning Vulnerability Assessments Involvement at the Leadership Team level Quarterly information exchange Escalation of critical issues Open door policy Shared training Common disaster recovery & business continuity plans

The Process Incident Occurs Normal Operations Emergency Response and Damage Assessment Preparing for Recovery of Critical Operations Operating in Recovery Mode Implement Restoration Plan Normal Operations Acceptable Business Capability Time Hour 0 Recovery Begins Recovery In Place Restoration Begins Back to Normal Emergency Response Plans Save lives and protect assets. Conduct damage assessment. Establish site emergency operations center (EOC) Business Recovery Plans Ensure that critical functions continue to be performed. Establish departmental recovery plans. Requires EOC communication and authorization. Crisis Management Plans Establish enterprise crisis management center (ECMC). Activate multiple EOCs. Establish command, control, and communications. Technology Recovery Plans Ensure site operations and physical infrastructure. Ensure critical technical and operational infrastructure. Establish alternate site recovery. Initiate mitigation actions. Avoid or minimize disruption. Risk Mitigation Plans Return to normal operations. Restoration Plans

Business Continuity Emergency Preparedness Focus: People, Environment & Property Program launch: 1994 Emergency Action Plans in place 137 (as of mid 2008) 1 plan per Boeing site Plans owned and managed by site S&FP EmP Emergency Preparedness BC ITP Information Technology Preparedness IT Preparedness Program, Focus: Applications & Infrastructure Program launch: 1996 Plans complete: 13,031 Plans in-work: 850 Applications still needing plans: 3260 BP Business Preparedness Business Preparedness Planning Focus: Critical Business Processes Program launch: 2006 Critical processes identified: 102 Critical processes with plans: 33 Plans built: 65

Business Continuity Benefits Enhances our ability to avoid adverse impacts to: Production capability Economic health Corporate image Contractual commitments Safety / Legal / Regulatory Competitive position Nisqually Earthquake Seattle, WA February 2001

Key Elements and Challenges Governance and compliance Executive sponsorship & commitment Execution plan Risk assessment plan Validate, test, and maintain plans Integration Tanker Fire I-90, Washington State 2005