National Cybersecurity & Communications Integration Center (NCCIC)



Similar documents
Department of Homeland Security

Statement of. Mike Sena. President, National Fusion Center Association. Director, Northern California Regional Intelligence Center (NCRIC)

Preventing and Defending Against Cyber Attacks November 2010

Integrating Cybersecurity with Emergency Operations Plans (EOPs) for Institutions of Higher Education (IHEs)

Integrating Cybersecurity with Emergency Operations Plans (EOPs) for K-12 Education

CYBERSECURITY BEST PRACTICES FOR SMALL AND MEDIUM PENNSYLVANIA UTILITIES

US-CERT Year in Review. United States Computer Emergency Readiness Team

Resources and Capabilities Guide

7 Homeland. ty Grant Program HOMELAND SECURITY GRANT PROGRAM. Fiscal Year 2008

Preventing and Defending Against Cyber Attacks June 2011

ICS-CERT Year in Review. Industrial Control Systems Cyber Emergency Response Team. National Cybersecurity and Communications Integration Center

[This page intentionally left blank]

CYBER SECURITY GUIDANCE

THE WHITE HOUSE. Office of the Press Secretary. For Immediate Release February 12, February 12, 2013

Report on CAP Cybersecurity November 5, 2015

Get the most out of Public Sector Cyber Security Associations & Collaboration

Cyber Incident Annex. Cooperating Agencies: Coordinating Agencies:

Department of Homeland Security

Cyber Incident Annex. Federal Coordinating Agencies. Coordinating Agencies. ITS-Information Technology Systems

El Camino College Homeland Security Spring 2016 Courses

NH!ISAC"ADVISORY"201.13" NATIONAL"CRITICAL"INFRASTRUCTURE"RESILIENCE"ANALYSIS"REPORT""

Water Security in New Jersey: Partnership and Services

INFRAGARD.ORG. Portland FBI. Unclassified 1

MARYLAND. Cyber Security White Paper. Defining the Role of State Government to Secure Maryland s Cyber Infrastructure.

Critical Infrastructure Security and Resilience

Homeland Security Perspectives: Cyber Security Partnerships and Measurement Activities

United States Coast Guard Cyber Command. Achieving Cyber Security Together. Homeland Security

How To Protect The Internet From Natural Disasters

National Cybersecurity Assessment and Technical Services

All. Presidential Directive (HSPD) 7, Critical Infrastructure Identification, Prioritization, and Protection, and as they relate to the NRF.

DHS, National Cyber Security Division Overview

Department of Homeland Security Federal Government Offerings, Products, and Services

Written Testimony. Dr. Andy Ozment. Assistant Secretary for Cybersecurity and Communications. U.S. Department of Homeland Security.

National Health Information Sharing & Analysis Center. The National Health ISAC (NH-ISAC) NH-ISAC

Lessons from Defending Cyberspace

AT&T Cybersecurity Policy Overview

Testimony of. Before the United States House of Representatives Committee on Oversight and Government Reform And the Committee on Homeland Security

Actions and Recommendations (A/R) Summary

Network Security Deployment Obligation and Expenditure Report

JOINT EXPLANATORY STATEMENT TO ACCOMPANY THE CYBERSECURITY ACT OF 2015

The Comprehensive National Cybersecurity Initiative

I N T E L L I G E N C E A S S E S S M E N T

Global Justice Information Sharing Initiative. Cyber Integration

National Communications System. December 6, 2007

Homeland Security Lessons Learned: An Analysis from Cyber Security Evaluations

U.S. Cyber Security Readiness

DHS Cyber Security & Resilience Resources: Cyber Preparedness, Risk Mitigation, & Incident Response

Performs the Federal coordination role for supporting the energy requirements associated with National Special Security Events.

U. S. Attorney Office Northern District of Texas March 2013

Local Government Cyber Security:

Cybersecurity Converged Resilience :

A Crisis Response, Information Sharing View of FFIEC Appendix J?

New York State Energy Planning Board. Cyber Security and the Energy Infrastructure

Working with the FBI

National Emergency Communications Plan

The U.S. Department of Homeland Security s Response to Senator Franken s July 1, 2015 letter

NGA Paper. Act and Adjust: A Call to Action for Governors. for cybersecurity;

FCC HOMELAND SECURITY LIAISON ACTIVITIES

Into the cybersecurity breach

Managing Cyber Risks to Transportation Systems. Mike Slawski Cyber Security Awareness & Outreach

NEBRASKA STATE HOMELAND SECURITY STRATEGY

NH-ISAC. Cybersecurity Resilience Securing the Infrastructures that Secure Healthcare & Public Health. The National Health ISAC

Cyber security Country Experience: Establishment of Information Security Projects.

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

Written Statement of Richard Dewey Executive Vice President New York Independent System Operator

By: Gerald Gagne. Community Bank Auditors Group Cybersecurity What you need to do now. June 9, 2015

Data Breach Response Planning: Laying the Right Foundation

ITU National Cybersecurity/CIIP Self-Assessment Toolkit. Background Information for National Pilot Tests

High Level Cyber Security Assessment 2/1/2012. Assessor: J. Doe

NASCIO 2014 State IT Recognition Awards

Cybersecurity & the Department of Homeland Security

Critical Controls for Cyber Security.

Washington State Fusion Center. The Pacific Northwest Economic Region

Transcription:

National Cybersecurity & Communications Integration Center (NCCIC)

FOR OFFICIAL USE ONLY NCCIC Overview NCCIC Overview The National Cybersecurity and Communications Integration Center (NCCIC), a division of DHS National Programs and Protection Directorate s (NPPD) Office of Cybersecurity and Communications (CS&C), operates at the intersection of government, private sector, and international network defense and communications communities by: Applying unique analytic perspectives Ensuring shared situational awareness Orchestrating synchronized response, mitigation and recovery efforts while protecting the Constitutional and privacy rights of Americans in both cybersecurity and communications domains. Four Components of the NCCIC US-CERT ICS-CERT NCC O & I 2

FOR OFFICIAL USE ONLY Comm ISAC Industry Partners - 63 members as of August 2013 3

Level of Impact FOR OFFICIAL USE ONLY Scope of Operations National Security Emergency Preparedness HIGH Nuclear War Strategic Cyber War Conventional War Theater Cyber War Coordinated Response Mobilization Special Operations Terrorism (includes Cyber) Civil Disorder Local Response LOW Probability of Occurrence HIGH 4

Current Public Safety Issues Telephonic Denial of Service Attacks (TDoS) Spectrum Interference Disaster Communications Coordination (ESF-2) Traditional ESF-2 Issues Cyber attacks on public safety communications Coordination of technical recovery resources in the event of a cyber attack with disaster level effects Migration to Next Generation 911 Cyber vulnerabilities and network defense leveraging NCCIC partnerships and capabilities Coordinating protection of the.gov Domain and sharing signatures and processes with public safety 5

TDoS- Criminal Acts by Sector Retail 28% Public Transportation 0% Transportation-Freight 1% School 9% PSAP 1% Security 1% (blank) 2% Police 7% Transportation 0% Other 0% 0% Communications Ambulance Service 1% 0% Oil/ Gas/ Electric 3% Financial 1% Fire 1% Government 4% Healthcaresupplier Healthcare 14% 1% Hospital 24% Ambulance Service Communications Financial Fire Government Healthcare Healthcare-supplier Hospital Oil/ Gas/ Electric Other Police PSAP Public Transportation Retail School Security Transportation-Freight

Jamming Spectrum There have been numerous reports of signal jamming devices employed to facilitate criminal activity and disrupt public safety operations Small handheld multi-frequency jammers capable of jamming Global Positioning Systems (GPS) and wireless communications including two-way radio communications Cost to purchase under $1000; some as little as $200 Disrupts communications and/or GPS from 15 to 75 feet Concern of power boosting using off the shelf tools Local law enforcement typically does not have laws or capability to detect, identify or mitigate if they are confronted with jammers FCC & USDOJ have enforcement authority

NCCIC Capabilities- TDoS & Jamming Develop Best Practices in coordination with public safety officials, telcom service providers, APCO & NENA on reporting, enforcement, legislative, and contingency ops, including Federal and International Law Enforcement coordination with DHS, FBI, FCC, FTC, DOS with UK & Indian investigators Coordination with key stakeholders Emergency/First responders Telecommunications Providers Government Policy Community Federal Emergency Communications Community Coordinate DHS/National Program Protection Directorate resources Protective Security Advisors (PSAs) Homeland Threat Reduction Analysis Center (HITRAC) Identify vulnerabilities to Cyber Attacks, TDoS Events and RF jamming Coordinating Cyber Center resources- MS ISAC

Multi-State Information Sharing Analysis Center (MS-ISAC) The MS-ISAC is the focal point for cyber threat prevention, protection, response and recovery for the nation's state, local, tribal, and territorial (SLTT) governments. The MS-ISAC 24x7 Cyber Security Operations Center (SOC) provides real-time network monitoring, early cyber threat warnings and advisories, vulnerability identification and mitigation and incident response.

Multi-State Information Sharing Analysis Center (MS-ISAC) MS-ISAC is only a phone call away to assist you with your Incident Response needs by providing you with the following capabilities: Malware Analysis Computer Forensics Network Forensics Incident Response Onsite Assistance Intelligence Coordination and Analysis

Multi-State Information Sharing Analysis Center (MS-ISAC) As these call centers move to a more data-centric model (Next Generation 911, VOIP) PSAPs are going to be increasingly susceptible to attack, as any other data network. MS-ISAC can help PSAPs with incident response and provide services, such as net flow monitoring. MS-ISAC can assist with any Cyber attacks, such as intrusion, malware or DDoS. Currently MS ISAC has supported PSAPs, as information is shared through Cyber SOC notices for the IT personnel, CERT services, etc., pushed to our distribution lists and published on the MS ISAC Websites

Multi-State Information Sharing Analysis Center (MS-ISAC) Membership in the MS ISAC is free to qualified organizations If you would like to leverage the MS-ISAC for any of the above capabilities, please contact our 7x24 Security Operation Center by calling 1.866.787.4722 or emailing soc@msisac.org

1