Showing posts with label DHS. Show all posts
Showing posts with label DHS. Show all posts

Tuesday, December 18, 2018

Federal Commission on School Safety Report

The Federal Commission on School Safety released a final report on December 18, 2018. The Commission was established by the President in March 2018 in the aftermath of multiple school shootings and is comprised of members representing the Department of Education (ED), Department Justice (DOJ), Department of Health and Human Services (HHS), and the Department of Homeland Security (DHS).

Appendix A of the report lists 'Federal Resources for School Safety.'

Monday, November 26, 2018

Hearing Key Points: "Interagency Cyber Cooperation: Roles, Responsibilities and Authorities of the Department of Defense & the Department of Homeland Security"

(Working Draft)

"Interagency Cyber Cooperation: Roles, Responsibilities and Authorities of the Department of Defense & the Department of Homeland Security"

Hearing held on November 14, 2018 before the:

U.S. House Armed Services Committee
Subcommittee on Emerging Threats

U.S. House Homeland Security Committee
Subcommittee on Cybersecurity and Infrastructure Protection


Witnesses:

Ms. Jeanette Manfra, Assistant Secretary, Office of Cybersecurity and Communications, National Protection Programs Directorate, U.S. Department of Homeland Security

Written Testimony Key Points:
  • Intro
  • Threat Assessment
  • Joint DoD and DHS Cybersecurity Efforts
  • Cybersecurity Priorities
    • In May of this year DHS published a Cybersecurity Strategy
    • In September the President released the National Cyber Strategy
    • Last year President signed Executive Order (EO) 13800, Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure
    • Under EO 13800, DHS and DOE, in consultation with ODNI, assessed potential impact and response readiness for a power outage associated with a significant cyber incident
  • Department of Homeland Security's Cybersecurity Responsibilities
  • National Risk Management
    • Secretary Nielsen announced rebranding of the Office of Cyber and Infrastructure Analysis as the National Risk Management Center (NRMC)
    • Enables private and public sector to assess and mitigate risks
    • NRMC's core mission focuses on systems or functions that cut across sectors
    • The NRMC will support the NCCIC and the NICC
  • Conclusion

Friday, October 5, 2018

New ICT Supply Chain Task Force

The Department of Homeland Security (DHS) held its first National Cybersecurity Summit on July 31, 2018. During the summit DHS's Christopher Krebs announced the creation of the Information Communications Technology Supply Chain Task Force and spoke with a panel of experts on what the task force should focus on for its first 90 days. The panelists included NSA's Rob Joyce, AT&T's John Donovan, and Palo Alto Network's Mark McLaughlin. The task force will be a part of the newly created DHS National Risk Management Center which launched with the task force in August. To add to that Congress is currently considering several pieces of legislation to protect the supply chain. One bill "Securing the Homeland Security Supply Chain Act of 2018" (HR 6430) was passed in the House on September 4, 2018 and has been sent to the Senate for debate.




Video: "Department of Homeland Security National Cybersecurity Summit" (Panel starts at 2:04) Source: YouTube

Tuesday, September 11, 2018

Cybersecurity and Infrastructure Security Agency Act

A bill (H.R. 3359) drafted to rename and reorganize DHS' NPPD (National Protection and Programs Directorate) as CISA (Cybersecurity and Infrastructure Security Agency) was introduced by Rep. Michael McCaul (R-TX) in July 2017. It passed in the House in December 2017, and is currently in the Senate with the Homeland Security Committee.

According to NPPD's Under Sec. Chris Krebs, "What we are trying to establish at the topline is… put a name on the door that tells stakeholders what we do,” said Krebs. “I need to be able to communicate, right out the gate. When I have that first meeting or have that phone call that says let’s work together, I’m not spending the first five minutes explaining what my name is." Here are a few more tweets and details about it.





Saturday, September 1, 2018

S&T Encourages Financial Sector Participation in CART

S&T is Partnering with Financial Service Organizations to Secure the Finance Sector from Cyber Threats
DHS is responsible for protecting the majority of the 16 critical infrastructure sectors, and even when we are not the named Sector-Specific Agency (SSA), we are partnering with agencies to offer solutions to keep our nation safe.
One example is the Financial Services Sector. The Department of Treasury is the SSA, however DHS Science and Technology Directorate (S&T) has developed the Next Generation Cyber Infrastructure (NGCI) Apex program (Cyber Apex) to provide cybersecurity solutions to this sector. Through the Cyber Apex program, S&T has partnered with the Department of Treasury to engage financial services organizations and encourage participation in the Cyber Apex Review Team, also known as the CART. […] 
Currently, the CART is a mix of large banks and financial institutions, however S&T is expanding the group to mid-sized and regional banks to increase knowledge and information sharing. As members of the CART, financial organizations will have the opportunity to identify cybersecurity gaps, review research findings and receive recommended solutions to help keep networks and systems safe from cyber threats.
To date, the Cyber Apex program is researching four efforts—detecting lateral movement within a network, gaining knowledge of artifacts on the network, improving analytical sharing methods and protecting sensitive data—but, as new capability gaps arise the program will add new research efforts.