Showing posts with label Integrated Task Force. Show all posts
Showing posts with label Integrated Task Force. Show all posts

Wednesday, July 17, 2013

DHS ITF IdeaScale Cybersecurity Project – Two New Ideas

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier posts in this series were:


The last couple of days have seen the introduction of two new ideas that share one thing in common they propose complex new ideas that take more than a couple of paragraphs to explain. The first deals with cyber emergency incident management and the second cyber security performance measurement. And both rely on links to documents outside of the IdeaScale site to fully explain their suggestions.

Cyber Incident Management

On July 15th the idea by dgsweigert (Dan Sweigert) was moved to the site by moderators. There is a single sentence (“Here is my white paper”) on the IdeaScale site and a link to a 3 page SlideShare document. Dan eloquently makes the point that a proper response to a cyber emergency is probably more important than efforts to prevent such incidents. We are not going to be able to prevent 100% of the attacks on critical infrastructure cyber-systems, so we need to put plans in place to respond to successful attacks. He suggests that “serious consideration be given by CSF [Cybersecurity Framework] planners to incorporate a NFPA 1600 and/or NIMS response capability in the EO 13636 CSF” (pg 3).

As I noted in my IdeaScale comment to this idea, this is a good first pass review of a problem that has been grossly overlooked in our discussions of preventing cyber-attacks, particularly on control systems. Dan makes the argument for starting the emergency response planning process and we in the community need to flesh it out.

Performance Measurement

The second new idea will be familiar to readers of this blog; Russell Thomas offers up his Ten Dimensions of Cyber Security Performance that I described in an earlier blog post. Russell provides a little more meat to the introduction of his idea than did Dan, but he too has to rely on links to off-site writings (in this case his blog) to fully explain the idea.

Voting

I voted ‘Agreed’ to both ideas, not because I fully endorse them in every detail, but rather because I thing they are both important new ways of looking at the issues that the Cybersecurity Framework is supposed to address. As such they need to be shared with the community, examined, discussed and modified as necessary.

I doubt that either will make it directly into the Framework being developed. That is not due to lack of scholarship or innovation, but rather that the general game plan for the framework has already been established and there is not enough time remaining in the process to make the kinds of major changes that would be required by the incorporation either of these ideas.

Still, neither would interfere with implementation of the Framework, so just perhaps the cybersecurity community needs to address these ideas outside of the Framework. While we are currently focused on the development and implementation of the Framework, I doubt that anyone really assumes that it will be the final word on cybersecurity, particularly in control system realm.

Endorsing the IdeaScale Process


Once again, I would like to take the opportunity to urge everyone to visit this IdeaScale site and put in your two cents worth. If you have no more time available than to read a couple of the ideas that catch your fancy, please vote on whether or not you thing the idea has merit. If you have more time available, contribute a comment like Richard did; it will add to the discussion. But better yet, put one of your ideas down on paper and then post it to the site for others to read, vote upon and discuss. Be a real contributor to the development of national policy.

Sunday, July 14, 2013

DHS ITF IdeaScale Cybersecurity Project – Performance Goals

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier posts in this series were:


An interesting new ‘idea’ was posted this week on the site by David Rose [corrected source identity 7-14-13; 15:30 CDT], who prefaced the idea by commenting:

“Just discovered this [the IdeaScale ITFCC] existed, during the 3rd NIST Cyber Security Framework workshop and there are zero (0) ideas on the cyber security framework topic -- so far.
“This tool would help to ensure, or at least provide an opportunity for broader feedback.”

The comment is disappointing on at least two levels. Most of the comments, and certainly all of my comments, seem to have been submitted with the Cybersecurity Framework in mind. Secondly, the ITFCC was supposedly set up to support DHS efforts at supporting the development and implementation of the Cybersecurity Framework and it seems that the only one publicly pushing this is yours truly. Oh well, I suppose there is some satisfaction to be derived from being a voice crying in the wilderness; it provides multiple opportunities to say I told you so.

Performance Goals

Community Member states that the submission is “a current copy of the Performance Goals Discussion Paper” presumably being circulated through DHS. It provides a discussion about the purpose and use of “performance goals” as measures of the appropriate level of implementation of the Cybersecurity Framework. Currently those performance goals would be self-evaluated as there is no ‘real intention’ in the administration to use the Cybersecurity Framework as a regulatory tool (except is selected areas where cybersecurity is already regulated).

There are only two primary and three secondary goals provided in the document. They are:

Primary Performance Goals
• PPG 1: During and following a cyber incident, essential services and products continue to be delivered with a high degree of reliability, resiliency, safety and integrity.
• PPG 2: Intellectual property and personal information are protected to maintain the confidentiality of proprietary information and ensure privacy and civil liberties.

Supporting Performance Goals
• SPG 1: Capabilities are built and sustained to prevent, detect, respond to, recover, and learn from cyber incidents as part of an ongoing enterprise risk management process.
• SPG 2: Functions critical to the delivery of essential services and products are sustained, or otherwise rapidly restored, over the course of a cyber incident.
• SPG 3: Preparedness and resilience are continuously improved based on lessons learned from incidents, exercises and other activities.

These goals are broad enough that they could be applied to any organization whether or not they are designated as being ‘critical infrastructure’. This has long been one of the goals of any cybersecurity plan, that it be widely applicable. They are also so widely generic that any attempt to secure networks and control systems, no matter how ineffective, could be viewed as justifying the claim of meeting these goals.

There are to major deficiencies in these goals. First, they can only be effectively measured after a successful cyber-attack; oops it is too late then to know that your controls are ineffective. To be fair this will be the failure point of any set of performance goals. More importantly these goals fail to address preventing the worst physical consequences of a successful cyber-attack. For example; at a high-risk chemical plant safety systems should be in place to prevent off-site consequences from a cyber-attack that would release a toxic inhalation hazard chemical from storage on the site.

To address the former, I have suggested that a third primary performance goal be added to the list:

• PPG 3 - During and after a cyber-attack controls, both computer based and physical, remain actively in play to protect the community from catastrophic physical consequences of process disruptions or interruptions.

I’m not sure that there is any specific way to address the first deficiency. Any real measure of the effectiveness of a cybersecurity control will have to rely on the response to an actual attack. And even effectively responding to a real attack, or several real attacks, will not ensure that the next hacker won’t have discovered a new hole in the system.

Realistically, the appropriateness of any performance goals adopted to support the Cybersecurity Framework will be measured by political not technical means. The question will come down to the willingness of the business community to adopt and implement the performance goals as part of a wide spread cybersecurity program. Unless, or until, these goals are incorporated into law or regulation every effort must be made to ensure that the goals are inoffensive enough to be voluntarily adopted by the business community.

Voice Crying in the Wilderness


Once again, I would like to take the opportunity to urge everyone to visit this IdeaScale site and put in your two cents worth. If you have no more time available than to read a couple of the ideas that catch your fancy, please vote on whether or not you thing the idea has merit. If you have more time available, contribute a comment like Richard did; it will add to the discussion. But better yet, put one of your ideas down on paper and then post it to the site for others to read, vote upon and discuss. Be a real contributor to the development of national policy.

Tuesday, July 2, 2013

DHS ITF IdeaScale Cybersecurity Project – CI Registration

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


Earlier today the IdeaScale people moved my Friday idea submission from submitted to posted. This idea is based upon the ICS-CERT story about pipeline booster station attacks earlier this year. Unless you are signed up for the US-CERT restricted portal and logged in with the Control Systems Compartment there, you still would not have access to the list of the IPs involved in that attack. I have long recommended that facility security managers and cybersecurity managers should sign up with both the US-CERT secure portal and with Homeland Security Information Network. These should both be useable sources of sensitive but not classified intelligence information of interest to security managers.

The IdeaScale posting puts that recommendation into another venue and suggest that participation in the US-CERT site should be mandatory for facilities identified as high-risk critical infrastructure facilities under the President’s cybersecurity Executive Order (EO 1336).

Issues Discussion

I have had some interesting feedback on the ideas that I have submitted to date on the DHS ITF IdeaScale Cybersecurity Project. That is what I like about contributing to these IdeaScale projects; ideas can get discussed in a public venue with input from a wide variety of personnel with different backgrounds and experiences. Anyone can put forward an idea, and everyone can respond to that idea in a public venue that can engender further input.


Once again, I would like to take the opportunity to urge everyone to visit this IdeaScale site and put in your two cents worth. If you have no more time available than to read a couple of the ideas that catch your fancy, please vote on whether or not you thing the idea has merit. If you have more time available, contribute a comment like Richard did; it will add to the discussion. But better yet, put one of your ideas down on paper and then post it to the site for others to read, vote upon and discuss. Be a real contributor to the development of national policy.

Wednesday, June 26, 2013

DHS ITF IdeaScale Cybersecurity Project – Risk Benefit Analysis

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


Yesterday there was an interesting comment left on my latest contribution to the IdeaScale Cybersecurity Project by Richard Bennett. While the question was left on my proposal of an information sharing program it would apply to just about anything to do with the cybersecurity project. Richard asked:

“DHS and industry may be talking past each other when speaking of "actionable intelligence" since the question is not "can you do something?" but rather "should we do something?". When the level of service for water, electricity, waste disposal or such is deemed acceptible when natural disasters can cause weeks-long outages, it is difficult to say that marginal improvements in preventing a man-made outage are worth the effort.”

Similarities to Regional Storm Damage

While the question would certainly have a different response for a commercial production facility, it is apparent that the shutting down of a public utility on a regional level is something that we have come to tolerate with a modicum of discomfort. As long as a utility production facility is not catastrophically destroyed, wouldn’t the damage from a cyber-attack be ‘as easy’ to repair as say an outage caused by a large hurricane, flood or snowstorm?

Actually, cyber-damage should be easier to repair because it would not be taking place spread over a wide geographic area like the damage to power lines after a major storm. Additionally the crews would not have to be working on the proximate cause of the damage (downed tree limbs for example) before they could repair the actual system damage.

Differences

There is one significant difference that might make cyber-attack damage more of an issue than say utility damage from a hurricane. Large-scale damaging weather events are usually forecast a couple of days in advance. People have a chance to fine-tune their emergency response plan before the damage occurs. Individuals have a chance to go to the store to stock-up on emergency supplies before the incident and utilities have a chance to stage response-personnel near the to-be-damaged area before the damage occurs.

Another, harder to quantify difference would be the psychological and sociological aspects of the response. With a storm there is a chance to mentally prepare oneself for the potential effects of the storm damage. In a terrorist attack, that does not occur. Additionally, in a properly conducted terror attack, there is the additional unknown factor about what else might also be about to be attacked. Panic brought about by the fear of the unknown is something that would be expected to be more of a problem with a terror attack than with storm damage.

Issues Discussion

Richard’s response to my suggestion is a perfect example of the benefit we can derive from these IdeaScale projects. Ideas can get discussed in a public venue with input from a wide variety of personnel with different backgrounds and experiences. Anyone can put forward an idea, and everyone can respond to that idea in a public venue that can engender further input.


Once again, I would like to take the opportunity to urge everyone to visit this IdeaScale site and put in your two cents worth. If you have no more time available than to read a couple of the ideas that catch your fancy, please vote on whether or not you thing the idea has merit. If you have more time available, contribute a comment like Richard did; it will add to the discussion. But better yet, put one of your ideas down on paper and then post it to the site for others to read, vote upon and discuss. Be a real contributor to the development of national policy.

Thursday, June 20, 2013

DHS ITF IdeaScale Cybersecurity Project – Information Sharing Program

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


I posted my fifth idea of this IdeaScale campaign today and it was a follow-up to my blog post from this morning about the problems that DHS is encountering in getting private sector organizations to join the Enhanced Cybersecurity Services program to share classified information about threats to the critical infrastructure computer networks and systems.

Public Participation

A quick reminder here that the whole ITFCC program requires public participation in the suggestion, discussion, selection and implementation process. The ITFCC web site is a forum for suggesting and discussing ideas that could become parts of the process for the security of critical infrastructure cyber-systems. Failing to participate in that process makes it less likely that you will be satisfied with the products of that process; products that you may be compelled to employ.


Take a couple of minutes and look at my latest idea and the other ideas currently under discussion at the site. Provide comments where you feel appropriate; become part of the discussion. Vote up or down on all of the ideas that you feel you can or cannot live with. And more importantly, provide your own ideas on how we as a society can increase the security of the cyber-systems that are an integral part of our everyday lives.

Friday, June 14, 2013

DHS ITF IdeaScale Cybersecurity Project – Remote Infrastructure

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


Security of Remote Infrastructure

Yesterday Scott Sklar posted a new ‘idea’ to ITFSCP site. He noted that:

“Many states leverage a portfolio of programs to deploy on-site renewable energy and distributed generation at cells towers, pipeline pumps (water, sewage, fuels), intersection signal lights, etc. so they are not tied to the grid, independently powered without fuel logistics, and are not controllable other than web-enabled diagnostics. This creates resiliency that is cybersecure.”

While I voted in general agreement with this idea, I did note in comments posted to the site that I had certain reservations about the claim of these systems being “cybersecure” just because they were only remotely controllable by ‘web-enabled diagnostics’. Over the last couple of years we have seen too many control systems with unintended remote access vulnerabilities to allow a general claim of security for any web accessible device.

Public Participation

A quick reminder here that the whole ITFCC program requires public participation in the suggestion, discussion, selection and implementation process. The ITFCC web site is a forum for suggesting and discussing ideas that could become parts of the process for the security of critical infrastructure cyber-systems. Failing to participate in that process makes it less likely that you will be satisfied with the products of that process; products that you may be compelled to employ.


Take a couple of minutes and look at my latest idea and the other ideas currently under discussion at the site. Provide comments where you feel appropriate; become part of the discussion. Vote up or down on all of the ideas that you feel you can or cannot live with. And more importantly, provide your own ideas on how we as a society can increase the security of the cyber-systems that are an integral part of our everyday lives.

Tuesday, May 28, 2013

DHS ITF IdeaScale Cybersecurity Project – Software Registration

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


This weekend I posted my fourth ‘idea’ to the ITFCCP site (NOTE: It did not make it live to the site until this morning, the moderators appear to work government hours). Readers of this blog probably saw this one coming, I would like to see vendors ‘register’ their systems, particularly their software and firmware, with an organization like ICS-CERT. To encourage vendor participation DHS could give them liability protection under the SAFETY Act. In turn they would agree to

• Provide DHS with a list of third-party components of their registered systems;
• Notify DHS when they identified, or were notified of the discovery, of a zero-day vulnerability;
• Allow DHS to notify registered high-risk critical infrastructure facilities of the zero-day vulnerabilities; and
• Work with DHS to minimize the vulnerabilities of each component of their registered system.

This proposal would allow vendors to become an integral part of the protecting critical infrastructure from cyber attacks.


As I have mentioned before, participating in this forum may be the easiest way that vendors, owners and researchers in the control system community may have a direct impact on the implementation of the President’s Cybersecurity Executive Order (EO 13636). So visit, read, comment, vote, and most of all suggest.

Friday, May 24, 2013

DHS ITF IdeaScale Cybersecurity Project – System Registration


This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


Yesterday I posted a new ‘idea’ for discussion on the DHS/IdeaScale Integrated Task Force Collaboration Community (ITFCC). This idea is actually a two parter:

• Identifying high risk control systems; and
• Registering high-risk control system with ICS-CERT to get earlier warnings of zero day vulnerabilities

High-Risk Cyber Systems

I’m going to ignore information systems here; those can be dealt with by different controls and procedures. I’m going to concentrate on control systems because it is only throught their unauthorized manipulation that a cyber-attacker can cause widespread physical damage to society. This high-consequence risk provides a legitimate societal concern with the security of such systems.

Even at a high-risk, high-consequence facility, not all control systems or even their components have an equal potential to cause catastrophic off-site consequences. It is only those portions of the cyber-systems controlling physical processes that could cause off-site catastrophic consequences that society has a legitimate interest in seeing that the systems are adequate secured. Identifying and perhaps isolating those high-consequence components will help to prioritizes where to spend the time, money and manpower to ensure that the systems are adequately secured against attack or unintentional failure. Of course, any other components of the overall cyber-system that allow for access to those critical components become critical in their own right.

A prime prerequisite of any serious cybersecurity program must be to identify these components that provide a determined attacker the capability to cause widespread physical harm via computer controlled system.

Zero-Day Vulnerability Warnings

If society has a strong interest in the prevention of attacks on high-consequence control systems, they also have a concomitant obligation to provide assistance to the owners of such systems in the protection of those systems. One such critical form of assistance is the notification of system owners when a zero-day vulnerability (ZDV) is discovered in their protected system.

There is a legitimate argument to be made that the wide spread dissemination of information about ZDVs increases the risk to cyber-systems because it is generally easier to exploit a ZDV than to mitigate one, particularly since the skill sets necessary to develop a mitigation strategy are frequently not found in-house at critical infrastructure facilities.

A targeted distribution of ZDV knowledge to high-consequence installations using the vulnerable systems avoids a certain amount of the danger associated with providing ZDV information to various adversaries. But to accomplish this the ZDV information distribution agency must know what facilities have what control system components deployed in critical installations. This requires the registration (voluntary or otherwise) of those components with an organization like ICS-CERT.

If ICS-CERT were to have this information, when they were contacted with information about an ICS ZDV they could (immediately after notifying the vendor of the vulnerability if the information comes from a researcher) notify those facilities deploying the vulnerable system in a high-consequence application. For those facilities without in-house or contract control system security capabilities, ICS could provide assistance in setting up interim security processes while waiting for the vendor to rectify the vulnerability.

Public Participation

A quick reminder here that the whole ITFCC program requires public participation in the suggestion, discussion, selection and implementation process. The ITFCC web site is a forum for suggesting and discussing ideas that could become parts of the process for the security of critical infrastructure cyber-systems. Failing to participate in that process makes it less likely that you will be satisfied with the products of that process; products that you may be compelled to employ.

Take a couple of minutes and look at my latest idea and the other ideas currently under discussion at the site. Provide comments where you feel appropriate; become part of the discussion. Vote up or down on all of the ideas that you feel you can or cannot live with. And more importantly, provide your own ideas on how we as a society can increase the security of the cyber-systems that are an integral part of our everyday lives.

Friday, May 10, 2013

DHS ITF IdeaScale Cybersecurity Project – Vulnerability Information


This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


This post deals with a new idea that I submitted to the DHS-IdeaScale project last night. It describes the problem of vulnerabilities being found (and fixed) in ICS applications and then discovering that the application is used in multiple ICS systems that need to have the vulnerability resolved all over again. Coordination of various vendor efforts in instances like this would probably be most effectively accomplished through a central agency like ICS-CERT.

Once again, I urge everyone in the control system security community to join in this dialog, commenting, voting and presenting ideas of your own. It is not often that a government agency gives individuals in the affected communities the opportunity to help in establishing the regulations that govern so much of our lives. Take the opportunity while you can.

Tuesday, May 7, 2013

DHS ITF IdeaScale Cybersecurity Project – Security Reputation


This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


New ICS Security Idea

Today Bryan Owen submitted a new idea to the ITF-IdeaScale cybersecurity discussion site addressing the establishment of a security reputation program to “to classify and rank the security reputation for internet accessible assets”. This is the second ICS related posting to the site.

ICS security professionals should review Bryan’s post on the site and post their comments and cast their vote on the idea. While you’re there check out my post as well. And you might as well post an idea of your own. And facility owners and control system operators should also consider getting involved in these discussions.

LinkedIn Discussion

There has been an interesting discussion about my earlier post on this topic over on the LinkedIn ICS-ISAC group. Sam Cox expressed some reservations about an open group discussion like this IdeaScale program, noting that it is “unvetted and does not meet the security needs many of my customers seek for professional collaboration”. He is correct in noting that an open source group like IdeaScale is not an appropriate place to discuss detailed security measures, but it is not clear that the Cybersecurity Framework will include those kinds of details.

DHS ITF IdeaScale Cybersecurity Project – PLC Insecurity


This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


On Sunday I posted an idea under the topic of “What would you like to see a public-private partnership for Security and Resilience achieve? My idea is titled “Identify and Resolve Inherent ICS Insecurity”. It addresses the problem PLCs and other industrial control system components that, by design, allow anyone with access to the control system network to change the programing of these devices; not a new problem to readers of this blog.

I would like to suggest that readers of this blog should look at this particular idea on the IdeaScale site (and all of the others as well). I would like to see comments and discussion on the topic to help the program development folks at DHS better understand the problem. And supportive votes will help to raise the issue to a higher level of awareness with the bureaucrats managing the Framework process.

Saturday, May 4, 2013

DHS ITF Establishes Collaboration Community


DHS has once again partnered with IdeaScale to establish a ‘collaboration community’ to help the DHS Integrated Task Force in the implementation and the coordination of interagency, and public and private sector efforts to support the President’s Executive Order on Improving Critical Infrastructure Cybersecurity (EO 13636). Patterned on previous IdeaScale campaigns on the National Dialogue on Preparedness and the Quadrennial Homeland Security Review, the Integrated Task Force Collaboration Community (ITFCC) allows for public input and discussion of proposals associated with EO 13636 implementation.

DHS is not being real proactive in publicizing this ITFCC. I have seen a single TWEET® on the topic and nothing else. That might explain why there are only four ideas currently on the page after being up for at least a week (that’s the date on the initial suggestion).

Topics

There are three different topic about which the site is soliciting public ideas. They are:


Only the third topic has an extensive explanation of what is being sought. It is also the only topic page that specifically mentions one of the working groups from the ITFCC; Evaluation and Planning Workgroup. They explain that they have already conducted focus group analysis and have come up with a four part purpose of the development of a public-private partnership for the implementation of the EO. Those parts are:

• Evaluate and address critical infrastructure risk through public-private collaboration and collective action across the national preparedness spectrum to prevent, protect against, mitigate, respond to, and recover from all hazards.
• Define and address national priorities for all-hazards critical infrastructure security and resilience through the bidirectional sharing of relevant and actionable information and the identification and exchange of best practices, tools, capabilities, and resources.
• Build and sustain trust, leverage existing, and develop new relationships to ensure the continued maintenance and growth of the partnership.
• Work collaboratively to identify and mitigate organizational and structural barriers to entry to facilitate increased participation by State, local, and private sector stakeholders in regions across the Nation.

Participation

This is a public participation discussion site, open to all comers. To publish new suggestions, make comments, or vote upon on existing suggestions you have to be registered with IdeaScale. People who registered on the two earlier DHS discussions can still use that registration ID and password.

I don’t see a ‘registration’ tool or button, but if you try to vote, make a suggestion, or comment on an existing suggestion you will be prompted to either sign in or register. It has been  a couple of years since I registered on IdeaScale, but I seem to recall that you have a wide latitude in the information that you provide or fail to provide to the site. I can’t vouch for the whole site security thing, but it does provide some fair level of anonymity on the public side if you so desire.

Current Comments

As I mentioned earlier there are only four comments currently posted on the board. They are (in order of current vote totals; highest to lowest):


The first three are glittering generalities that fall into the general ‘motherhood and apple pie’ category. The last is a little more specific but not really directed at cybersecurity concerns. This is one of the problems with these public comment/suggestion exercises; there are very few concrete proposals and more than a few that trend off-topic. Oh well, searching for gems is like that.

Currently there are no comments that directly apply to industrial control system security efforts. I will, however, continue to monitor and report upon this site.
 
/* Use this with templates/template-twocol.html */