Showing posts with label ISAO. Show all posts
Showing posts with label ISAO. Show all posts

Thursday, April 21, 2016

DHS Publishes ISAO Meeting Notice – 5-18-16

Today the Department of Homeland Security published a public meeting notice in the Federal Register (81 FR 23506-23507) for a two-day meeting in Anaheim, CA on May 18th, 2016. The meeting will support the establishment of Information Sharing and Analysis Organizations (ISAO) in accordance with EO 13691.

The first day of the meeting will be limited to the ISAO Standards Organization and its six working groups. The second day will the public forum for the discussion about an initial set of draft documents that will focus on the needs of those seeking to join or form an ISAO and should be released for public comment by early May on the ISAO web site.

Seven questions will be addressed during the public discussion:

• What needs to be considered by a newly-forming ISAO and what are the first steps?
• What capabilities might an ISAO provide?
• What types of information will be shared and what are some mechanisms for doing so?
• What security and privacy is needed for a newly-forming ISAO?
• What mentoring support is available for newly-forming ISAOs?
• What government programs and services are available to assist ISAOs?
• What concerns do regulators and law enforcement have about the new ISAO construct?


The DHS also be soliciting written comments on the draft documents and the above questions. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2015-0017). There is some confusion about when such comments should be submitted. The notice states that the comments should be received by November 14th, 2015, but that is obviously a hold-over from a previous notice. The Portal notes that the comment period is closed on this notice. This may be clarified when the Standards Organization posts the draft documents.

Friday, July 3, 2015

DHS Announces ISAO Workshop

Today the DHS Office of Cybersecurity and Communications (OCC) published a meeting notice in the Federal Register (80 FR 38453-38454) for a public workshop concerning Information Sharing and Analysis Organizations (ISAO). The public meeting will be held in San Jose, CA on July 30th [date corrected, 07-03-15 10:20 CDT].

No agenda is currently available for this meeting. Advance registration is required, but the RSVP link mentioned in the notice does not yet exist. Public comments about this program may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2015-0017).

Commentary

This will be the third ISAO workshop being held by DHS since the publication of  EO 13691; Promoting Private Sector Cybersecurity Information Sharing. I mentioned the second in an earlier post and noted that like this meeting announcement there had been no agenda provided in the meeting notice. Even though that meeting was held on June 9th, there is still no meeting agenda provided for that meeting on the ‘ISAO Engagements’ page. There is more information available on the first meeting that was held in March.

All in all the OCC seems to be doing a really bad job of information sharing about this new program. It makes me wonder about how much commitment and support this program is receiving in DHS.

BTW: DHS does have an $11 Million dollar grant available for developing standards for ISAO’s. The application period closes on July 17th, 2015. There is no direct link to the grant opportunity notice (DHS-15-NPPD-128-001), but here are the directions on how to get to the site:


A Notice of Funding Opportunity (NOFO) for the ISAO Standards Organization Cooperative Agreement has been created and posted online to Grants.gov. To locate the NOFO and application package, please visit http://www.grants.gov/web/grants/search-grants.html and search “97.128” in the CFDA Number search bar on the top left of the page. The Funding Opportunity Number is DHS-15-NPPD-128-001.

Wednesday, May 27, 2015

DHS Requests Comments on ISAOs

The DHS Office of Cybersecurity and Communications (OCC) published a request for comments in today’s Federal Register (80 FR 30258-30259) on the formation of Information Sharing and Analysis Organizations (ISAOs) for cybersecurity information sharing, as directed by Executive Order 13691. This request for comments is roughly associated with the ISAO workshop being conducted by DHS on June 9th.

The request for comments is looking generally for comments on the ISAO program outlined in EP 13691 and specifically for answers to 8 questions (the verbiage says five questions but lists 8; either a typo or poor editing):

1. Describe the overarching goal and value proposition of Information Sharing and Analysis Organizations (ISAOs) for your organization.
2. Identify and describe any information protection policies that should be implemented by ISAOs to ensure that they maintain the trust of participating organizations.
3. Describe any capabilities that should be demonstrated by ISAOs, including capabilities related to receiving, analyzing, storing, and sharing information.
4. Describe any potential attributes of ISAOs that will constrain their capability to best serve the information sharing requirements of member organizations.
5. Identify and comment on proven methods and models that can be emulated to assist in promoting formation of ISAOs and how the ISAO “standards” body called for by E.O. 13691 can leverage such methods and models in developing its guidance.
6. How can the U.S. government best foster and encourage the organic development of ISAOs, and what should the U.S. government avoid when interacting with or supporting ISAOs?
7. Identify potential conflicts with existing laws, authorities that may inhibit organizations from participating in ISAOS and describe potential remedies to these conflicts.
8. Please identify other potential challenges and issues that you believe may affect the development and maturation of effective ISAOs.


While DHS is soliciting public feedback, there is nothing in the notice that specifically tells people how to provide that feedback. There is, however, a docket (DHS-2015-0017) set up on the Federal eRulemaking Portal (www.Regulations.gov) for submitting these comments. Comments should be submitted by June 10th, 2015.

Thursday, May 7, 2015

DHS Announces ISAO Workshop

Today the DHS National Protection and Programs Directorate (NPPD) published a meeting notice in the Federal Register (80 FR 262383) for a public workshop on June 9th, 2015 in Cambridge, MA. The workshop will address automated indicator sharing and analysis by Information Sharing and Analysis Organizations (ISAO).

This is part of the DHS program (initiated by EO 13691; Promoting Private Sector Cybersecurity Information Sharing) to expand access to threat sharing information to companies that do not fit into the existing structure of sector based Information Sharing and Analysis Centers (ISACS).

The formal agenda will be published on the ISAO web site at some unspecified future date.

Public participation is being solicited by NPPD. Advanced registration is recommended and may be accomplished on the RSVP page. The registration is a tad bit more complicated than normal as you have to register for the overall workshop and then for the individual sessions and tracks in which you wish to participate. There are only 352 workshop registrations remaining (as of 7:30 am CDT) and only 25 registrations remaining for the “Automated Indicator Sharing Requirements” track, so early registrations seems to be indicated.


NPPD has provided for public comments to be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2015-0017). Comments should be submitted by July 8th, 2015.
 
/* Use this with templates/template-twocol.html */