Cyber Security
Cyber Security and Global Interdependence: What Is Critical?
Programme Report
01 February 2013
Project: International Security Department , Cyber and Nuclear Security
Dave Clemente
- See more at: https://www.chathamhouse.org/publications/papers/view/189645#sthash.sPiqI1Ol.dpuf
The evolution of interconnection between infrastructure sectors has been accelerated by the spread of cyberspace, which has become the 'nervous system' linking them. There is no avoiding the security implications emerging at the intersection of cyberspace and infrastructure.
As countries become more dependent on infrastructure distributed around the world, the growing complexity of interconnections makes it harder for authorities to identify what infrastructure is 'critical'.
Improving risk management relies on using rigorous definitions of what infrastructure is 'critical', which enables more effective prioritization and protection of nodes and connection points. In this context, the ever-rising importance of data makes distinctions between 'physical' and 'information' infrastructure increasingly irrelevant.
Societal resilience can be just as important as infrastructure resilience, and policy-makers should consider closely what levels of societal dependency on digital technologies are appropriate. Building public confidence in the security and governance of the critical infrastructure ecosystem is essential to avoid policy-making driven by reactive or narrow interests.
Meeting these security challenges requires better shared understanding of what is critical between those who protect an organization and those who set its strategic direction. Better understanding of the economic and political incentives that guide stakeholders also reveals the scope for potential cooperation. - See more at: https://www.chathamhouse.org/publications/papers/view/189645#sthash.sPiqI1Ol.dpuf
http://harvardnsj.org/wp-content/uploads/2012/01/Vol.-3_Bellovin_Bradner_Diffie_Landau_Rexford.pdf
Required: Saadawi, T & Jordan, J. Jr., (2011). eds. Cyber Infrastructure Protection . Carlisle Barracks: U.S. Army War College, Strategic Studies Institute.
National Infrastructure Protection Plan (NIPP) Security and Resilience Challenge
Through the NIPP Security and Resilience Challenge, the Office of Infrastructure Protection, within the Department of Homeland Security’s National Protection and Programs Directorate, in partnership with the National Institute for Hometown Security (NIHS), provides an opportunity for the critical infrastructure community to help develop technology, tools, processes, and methods that address immediate needs and strengthen the long-term security and resilience of critical infrastructure.
The Challenge is unique in that it helps identify and fund innovative ideas that can provide technologies and tools to the critical infrastructure community that are ready or nearly ready to use. Projects funded under the NIPP Challenge are meant to not only have tangible, near-term results so they can be quickly developed and implemented, but to also be financially, practically, and logistically sustainable in the long term so that they can enhance the security and resilience of critical infrastructure across multiple sectors for years to come. These ideas, due to their innovation and research, can be risky, but are likely to offer important benefits to the critical infrastructure community.
2017 NIPP Security and Resilience Challenge
The Department of Homeland Security’s Office of Infrastructure Protection and the National Institute for Hometown Security are pleased to announce the second iteration of the NIPP Security and Resilience Challenge, which will be open for submissions from April 17, 2017, through May 12, 2017. To get the specifications and details on the submission process, visit the NIPP Challenge Submission webpage.
View the fact sheet for the 2017 NIPP Security and Resilience Challenge.
2016 NIPP Security and Resilience Challenge
The selected submissions for the 2016 NIPP Security and Resilience Challenge are underway. Get more information on progress of the 2016 projects at the NIHS website.
View fact sheets for the 2016 NIPP Security and Resilience Challenge submissions.
Contact Information
For questions about the NIPP Security and Resilience Challenge, please contact the program managers listed on the NIPP Challenge Submission webpage.
Last Published Date: April 18, 2017
National Infrastructure Protection Plan
Our Nation's well-being relies upon secure and resilient critical infrastructure—the assets, systems, and networks that underpin American society. The National Infrastructure Protection Plan (NIPP)—NIPP 2013:
Partnering for Critical Infrastructure Security and Resilience
—outlines how government and private sector participants in the critical infrastructure community work together to manage risks and achieve security and resilience outcomes.
NIPP 2013 Partnering for Critical Infrastructure Security and Resilience
NIPP 2013 represents an evolution from concepts introduced in the initial version of the NIPP released in 2006 and revised in 2009. The National Plan is streamlined and adaptable to the current risk, policy, and strategic environments. It provides the foundation for an integrated and collaborative approach to achieve the vision of: "[a] Nation in which physical and cyber critical infrastructure remain secure and resilient, with vulnerabilities reduced, consequences minimized, threats identified and disrupted, and response and recovery hastened."
NIPP 2013 meets the requirements of Presidential Policy Directive-21: Critical Infrastructure Security and Resilience , signed in February 2013. The Plan was developed through a collaborative process involving stakeholders from all 16 critical infrastructure sectors, all 50 states, and from all levels of government and industry. It provides a clear call to action to leverage partnerships, innovate for risk management, and focus on outcomes.
Read the 2013 National Infrastructure Protection Plan and its fact sheet.
NIPP 2013 Supplements
NIPP following supplements serve as tools and resources that can be used for members of the critical infrastructure community as they implement specific aspects of the Plan.
· Connecting to the NICC and the NCCIC
· Executing a Critical Infrastructure Risk Management Approach
· Incorporating Resilience into Critical Infrastructure Projects
· National Protection and Programs Directorate Resources to Support Vulnerability Assessments
2017 NIPP Security and Resilience Challenge
The Department of Homeland Security’s Office of Infrastructure Protection and the National Institute for Hometown Security are pleased to announce the 2017 NIPP Security and Resilience Challenge.
Sector-Specific Plans
PPD-21 assigns a federal agency, known as a Sector-Specific Agency (SSA), to lead a collaborative process for critical infrastructure security within each of the 16 critical infrastructure sectors. Each Sector-Specific Agency is responsible for developing and implementing a sector-specific plan (SSP), which details the application of the NIPP concepts to the unique characteristics and conditions of their sector. Sector-Specific Plans are being updated to align with the NIPP 2013.
More on the National Infrastructure Protection Plan
· Joint National Priorities - The first call to action furthered by the NIPP 2013 advocated for the development of joint national priorities to inform resource allocation and decision-making on the part of critical infrastructure partners.
Training Courses
An array of independent study courses is available to the critical infrastructure community. These courses were developed by the National Protection and Programs Directorate's Office of Infrastructure Protection and are available through the Federal Emergency Management Agency (FEMA) Emergency Management Institute.
Critical Infrastructure Partnership Courses
· IS 913.a Achieving Results through Critical Infrastructure Partnership and Collaboration
· IS 921.a Implementing Critical Infrastructure Protection Program and CI Toolkit
Security Awareness Series Courses
· IS 906 Workplace Security
· IS 907 Active Shooter
· IS 912 Retail Security Awareness
· IS 914 Surveillance Awareness: What You Can Do
· IS 915 Protecting Critical Infrastructure against Insider Threat
· IS 916 Critical Infrastructure Security: Theft and Diversion - What You Can Do
Authorities
· Homeland Security Act of 2002
· EO 13636
· PPD-21
· Cybersecurity Framework
· National Strategy for Physical Protection of Critical Infrastructure and Key Assets
· PPD-8
Bottom of Form