dla energy worldwide energy conference tsa surface ...€¦ · pipeline security guidelines •...

16
DLA Energy Worldwide Energy Conference TSA Surface Cybersecurity Resources April 12, 2017 Office of Security Policy & Industry Engagement Surface Division

Upload: others

Post on 26-Apr-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

DLA Energy Worldwide Energy ConferenceTSA Surface Cybersecurity Resources

April 12, 2017

Office of Security Policy & Industry EngagementSurface Division

Page 2: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

22

TSAastheCo-SectorSpecificAgency

• TSAistheTransportationSystemsSectorCO-SSAwithDOTandUnitedStatesCoastGuard.

• Missiono ContinuouslyimprovetheriskpostureofTransportationSystems

servingtheNation.• Goals

o Preventanddeteractsofterrorismusing,oragainst,thetransportationsystem.

o Enhancetheall-hazardpreparednessandresilienceoftheglobaltransportationsystemtosafeguardU.S.nationalinterests.

o Improvetheeffectiveuseofresourcesfortransportationsecurity.o Improvesectorsituationalawareness,understanding,and

collaboration.

Page 3: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

33

ThreePillarsofCriticalInfrastructureCybersecurityatTSA

• OfficeofInformationTechnologyo FacilitatingtheImplementationofNational

Policy.

• OfficeofSecurityPolicyandIndustryEngagemento Managingrisksthroughindustryengagement.

• OfficeofIntelligenceandAnalysiso Identifyandcommunicatingcyberthreats.

Page 4: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

44

CyberCriticalInfrastructureProtection

• Mandateso ExecutiveOrder13636:ImprovingCriticalInfrastructureCyberSecurity.o PresidentialPolicyDirective-21:CriticalInfrastructureSecurityand

Resilience.o PresidentialPolicyDirective-41:UnitedStatesCyberIncident

Coordination.

• Missiono Facilitatethemeasuredimprovementofthenationaltransportation

sectorcybersecurityposture.

• Approacho Non-Operational.Education,Facilitation,andCommunication.

Page 5: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

55

PutCybersecurityRiskManagementontheAgendaBeforeitBecomestheAgenda

• Itisnolongersufficienttothinkaboutcybersecurityasapurelytechnicalproblem.Justlikephysicalsecurity,thecurrentthreatenvironmentrequiresacomprehensiveapproachtocybersecurityriskmanagement.

• Asabusinessleaderandemployee,itisvitaltorealizetheimportanceofprotectingyourcompany’ssystemsfromcyberthreatsbecausethesecurityofanorganization’sassets,employees,passengers,cargoandcustomersdependsonit.

• Itiscriticalthatyouandyouremployeesareengagedinappropriatepracticestoavertpotentiallydamagingcyber-attacks.

• Incorporatecyberrisksintoyourorganization'sexistingriskmanagementandgovernanceprocesses.

Page 6: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

66

SurfaceTransportationCybersecurityResourceToolkitforSmall&MidsizeBusiness(SMB)

• Thetoolkitisacollectionofdocumentsdesignedtoprovidecyberriskmanagementinformationtosurfacetransportationmanagersownersandoperatorswhohavefewerthan1,000employees.

• ItprovidesguidanceonhowtoincorporateCyberRiskintoyourorganization'sexistingriskmanagementandgovernanceprocesses.

Page 7: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

77

SurfaceTransportationCybersecurityResourceToolkitforSmall&MidsizeBusiness(SMB)

UNCLASSIFIED//FOR OFFICIAL USE ONLY

Page 8: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

88

NoCostResourcesforSurfaceTransportationSystemsSector(TSS)IndustryStakeholders

“No-CostCybersecurityResourcesforSurfaceTransportationSystems”handoutthatprovidesalistofcybersecurityprogramsanddocuments thatindustrycanusetoreducetheircybersecurityriskandincreasetheircyberresilience.Examplesinclude:

• TheCriticalInfrastructureCyberCommunityVoluntaryProgram(CᶟVP)thatsupports criticalinfrastructureownersandoperatorsinterestedinimprovingtheircyberriskmanagementprocessesandcyberresilience.

• CyberRiskManagementPrimerforCEOsthathighlightsthefivequestionsbusiness leadersshouldaskaboutcyberriskstoprotecttheirorganization’ssystemsfromcyberthreats.

• InformationabouttheCyberResilienceReview(CRR)&CyberSecurityEvaluationTool(CSET)DHScyberriskassessmentsprovidedasthefirststepforadoptionoftheCyberFrameworkandawayforanorganizationtoview/understandtheirapproachtomanagingtheircybersecurityrisk.

Page 9: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

99

TransportationSystemsSectorCybersecurityFrameworkImplementationGuidance

TheTransportationSystemsSectorCybersecurityFrameworkImplementationGuidanceprovidesanapproachforTransportationSystemsSectorownersandoperatorstoapplytheprinciplesoftheNationalInstituteofStandardsandTechnologyCybersecurityFrameworktohelp reducecyberrisks. Specifically,organizationsmayusetheimplementationguidance to:

• Characterizetheircurrentcybersecurityposture.• Identifyopportunities forenhancingexistingcyber

riskmanagementprograms.• Findexistingtools, standards,andguides tosupport

Frameworkimplementation.• Communicatetheirriskmanagementissuesto

internalandexternalstakeholders.

Organizationsthatlackaformalcybersecurityriskmanagementprogramcouldusetheguidance toestablishrisk-basedcyberpriorities.

Page 10: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

1010

SurfaceCybersecurity“Pocket”AwarenessGuide

• Theguideoutlinesthetypesofthreatsmostcommonlyfoundincyberspaceandexplainshowyoucanprotectyourcompany’sdata,computersystems,andyourpersonalinformation. ItalsoprovidesdetailedinformationonthesafeuseoftheInternet,socialnetworks,andmobiletechnology.

• Theguideisformattedin“pocketsize”withtheaimthatfrontlineemployeeswillkeeptheguidecloseathandwhiletheyareon-dutysothatitcanserveasaconvenientreferencesourceandsecurityawarenesstool.

Page 11: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

1111

SurfaceCybersecurity“Pocket”AwarenessGuide

Over10,000surfacecybersecurityawarenesspocketawarenessguideshavebeendistributedtopipelineowner/operators.

Page 12: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

1212

PipelineSecurityGuidelines

• ContainscybersecuritymeasuresTSAhasdevelopedwithindustry.Thecyberguidelinesofferbaselinemeasurestosupportadoptionofcybersecurityprotectionstandards.

• These2011Guidelinesarebeingrevisedandthecybersectionreceived300commentsfromindustryrepresentatives. TSAplanstoaddressallcommentsbytheendofFY17andtargetsafinalguidancetobecompletebytheendofMarch2018.

Page 13: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

1313

TSSCWGTransportationSystemsSectorCyberWorkingGroup&

WeeklyNewsletter

• ImplementingNationalPolicies

• ModalOutreachAwarenessandCoordination

• InformationSharingBestPractices

• FacilitatingGovernmentProgramsandEfforts

• WeeklyNewsletter

Page 14: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

1414

https://www.tsa.gov/for-industry

Page 15: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

15

• ForadditionalinformationaboutjoiningtheTSSCWGortoreceiveThisWeekinTransportationCybersecurity,email:[email protected]

• Foradditionalinformationand/ortorequesttheAwarenessGuideorToolkit,email:[email protected]

• Pleaseinclude“CybersecurityGuideandToolkit”inthesubjectlineofyouremailtofacilitateproperhandling.

Page 16: DLA Energy Worldwide Energy Conference TSA Surface ...€¦ · Pipeline Security Guidelines • Contains cyber security measures TSA has developed with industry. The cyber guidelines

16