Instruction
8-1
BACKGROUND: Over the last several weeks, we’ve talked about the concepts of cybersecurity and risk. As I’m sure you’re aware, our cyber infrastructures face a variety of threats, and proper management requires that we devise procedures to protect them. However, risk assessments are never foolproof -- and when it comes to cybersecurity issues -- even less so with the onslaught of daily threats. Therefore, as an informational brainstorming session for just those of us within the CIRRUS Office, I’d like the team to continue the previous discussion associated with the cybersecurity and risk concepts but from a slightly different perspective.
PoD Tasker - Assume you’re a newly appointed Chief Risk Officer for a large energy organization; in fact, you’re the first-ever Chief Risk Officer hired by this organization. Congratulations. With that, it turns out that two topics of intense interest among the organization’s senior leadership has recently been those of “cybersecurity” and “risk.” So much so that this was one of the reasons the organization’s senior leadership decided to make their first-ever hire of a Chief Risk Officer. With your arrival, one of the first tasks assigned to you is to provide the organization’s senior leadership with an informational briefing on the risk of cybersecurity to the organization. What sort of policies and frameworks would you advocate the company use guidance to set up their own coherent cyber defense strategy for the organization? What -- if any -- is the relationship between cybersecurity and risk? What would you highlight as your three (3) most prominent “head scratchers” -- i.e., what are the top three problems or challenges that keep you up at night worrying about? Since funding is not unlimited, prioritize your three problems or challenges that you highlight. What might be some steps/procedures/best practices that could be used for the organization to protect valuable and/or proprietary information? And anything else you think important enough to brief to your organization’s senior leadership.
8-2
BACKGROUND: At the latest NPPD staff meeting, Mr. Krebs (Under Secretary for the NPPD) asked for a CIRRUS point paper identifying major talking points for his consideration as part of a future cybersecurity-related briefing. At this time, Mr. Krebs has been approached to be a keynote speaker as part of the 11th Annual National Cyber Summit being held on June 4-6, 2019 in Huntsville, AL. The conference theme and agenda are still in the planning stage. Therefore, Mr. Krebs is initially seeking some preliminary “talking points” around which he could potentially build his briefing content and message. Mr. Krebs has requested that his DHS NPPD team members provide him with some initial talking points for consideration to include within his final briefing content. An overview and videos from the 2018 National Cyber Summit can be found at https://www.nationalcybersummit.com/. Therefore, I’d like our Team to discuss this topic; I’ll use your discussion inputs and comments to develop a point paper back to Mr. Krebs’ staff for action closure.
PoD Tasker- Discuss the concept of “cyber” as it relates to critical infrastructure. Specially, identify what you believe are the three (3) main talking points that Mr. Krebs should include within this briefing content for the 2019 National Cyber Summit presentation. What are the top three points that Mr. Krebs should communicate to the audience; that is, what messages should the audience “walk away with” after listening to Mr. Krebs’ briefing? Be sure to provide a short discussion as to why you’ve identified each of the talking points you discuss. When identifying your top three talking points, be sure to place them in priority order.
8-3
BACKGROUND: DHS Secretary Nielsen and NPPD Under Secretary Krebs had been planning to attend the National Institute of Standards and Technology (NIST) Cybersecurity Risk Management Conference on November 7-9, 2018 in Baltimore MD (https://www.nist.gov/news-events/events/2018/11/nist-cybersecurity-riskmanagement-conference). Unfortunately, both Ms. Nielsen and Mr. Krebs have had to cancel their appearances at this NIST conference due other commitments in support of various National Critical Infrastructure Security and Resilience Month activities. As a result, I your fearless leader, have now been requested to attend the NIST Cybersecurity Risk Management Conference on their behalf. While I don’t have a speaking role, I would like to become more familiar with the one of the NIST conference agenda items (https://www.nist.gov/sites/default/files/documents/2018/10/03/2018_risk_manage ment_conference_agenda.pdf). Specifically, NIST’s Framework for Improving Critical Infrastructure Cybersecurity version 1.1 dated April 2018 (https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf). Therefore, I’d like our Team to discuss this document; I’ll use your discussion inputs and comments to “come up to speed” on this important policy document prior to the conference.
PoD Tasker- Discuss NIST’s Framework for Improving Critical Infrastructure Cybersecurity version 1.1 dated April 2018. Provide a brief, succinct overview describing the purpose of this document. Provide the top three (3) items in this NIST document that you think I need to be aware of as preparation for me attending the conference. Be sure to provide a short discussion as to why you think each of these three items stands out in your mind. And anything else you think important to communicate to me.