Showing posts with label NIPP. Show all posts
Showing posts with label NIPP. Show all posts

Tuesday, December 24, 2013

White House Issues Twin Policy Documents

As the sixth year of the Obama Administration quickly approaches, the White House has issued two high-level homeland security policy document that are designed to shape future of programs of the Federal Government. These two documents (in order of release) are the National Strategy for Information Sharing and Safeguarding (NSISS) and the National Infrastructure Protection Plan (NIPP). Neither of these documents has any specific regulatory force, yet they are both intended to help shape the direction of a wide range of regulatory programs within the Federal government.

NISS

This strategy is designed to address the conflicts in the twin nature of information. First information must be shared to have any effect on the real world and second information shared is likely to be released to someone who should not get the information. Finding the proper balance between these two aspects of information policy is never easy.

The NISS starts out with a discussion of the current operating environment in which information collection and sharing takes place. It then establishes three Core Principals that define the Administration’s approach to information sharing (pgs 6-7):

• Information as a National Asset
• Information Sharing and Safeguarding Requires Shared Risk Management
• Information Informs Decisionmaking

With those motherhood and apple pie principals in place, the NISS outlines five goals in some depth. The listed goals are (pgs 8-13):

• Drive Collective Action through Collaboration and Accountability.
• Improve Information Discovery and Access through Common Standards.
• Optimize Mission Effectiveness through Shared Services and Interoperability.
• Strengthen Information Safeguarding through Structural Reform, Policy, and Technical Solutions.
• Protect Privacy, Civil Rights, and Civil Liberties through Consistency and Compliance.

Finally the document lists sixteen information sharing objectives with five being given the title of Priority Objectives. Those Priority Objectives are (pg 14):

• Align information sharing and safeguarding governance to foster better decisionmaking, performance, accountability, and implementation of the Strategy’s goals.
• Develop guidelines for information sharing and safeguarding agreements to address common
requirements, including privacy, civil rights, and civil liberties, while still allowing flexibility to
meet mission needs.
• Adopt metadata standards to facilitate federated discovery, access, correlation, and monitoring
across Federal networks and security domains.
• Extend and implement the FICAM [Federal Identity Credential and Access Management] Roadmap [Link] across all security domains,
• Implement removable media policies, processes and controls; provide timely audit capabilities of assets, vulnerabilities, and threats; establish programs, processes and techniques to deter, detect and disrupt insider threats; and share the management of risks, to enhance unclassified and classified information safeguarding efforts.


NIPP

The 2013 NIPP is an update of the 2009 document that I found negatively stimulating. The newer document reads better, but it still doesn’t really say much.

It starts out with the standard corporate vision-mission-goal statement (pg 5):

Vision Statement - A Nation in which physical and cyber critical infrastructure remain secure and resilient, with vulnerabilities reduced, consequences minimized, threats identified and disrupted, and response and recovery hastened.

Mission Statement – Strengthen the security and resilience of the Nation’s critical infrastructure by managing physical and cyber risks through the collaborative and integrated efforts of the critical infrastructure community.

Goals:

• Assess and analyze threats to, vulnerabilities of, and consequences to critical infrastructure to inform risk management activities;
• Secure critical infrastructure against human, physical, and cyber threats through sustainable efforts to reduce risk, while accounting for the costs and benefits of security investments;
• Enhance critical infrastructure resilience by minimizing the adverse consequences of incidents through advance planning and
mitigation efforts, as well as effective responses to save lives and ensure the rapid recovery of essential services;
• Share actionable and relevant information across the critical infrastructure community to build awareness and enable risk informed decision making; and
• Promote learning and adaptation during and after exercises and incidents.

There is an interesting, if broadly painted, discussion of the risk environment (pg 8) with the a summary of the information provided in figure 2, a graphic representation of the ‘evolving threats to critical infrastructure’. They are categorized as:

• Extreme weather
• Accidents or technical failures
• Cyber threats
• Acts of terrorism
• Pandemics

Interestingly there is a wide degree of overlap between the middle three categories that is not mentioned in the NIPP discussion. There is, however, one interesting risk that is tossed off at the end of this discussion that is then promptly ignored in the rest of the document; “vulnerabilities may exist as a result of a retiring workforce or lack of skilled labor”. Add in ‘reductions in force’ and you have an interesting topic for a whole series of discussions.

Then it provides a set of motherhood and apple pie statements (this time called ‘Core Tenets’; pgs 13-14) that will guide the remaining discussion of critical infrastructure protection:

• Risk should be identified and managed in a coordinated and comprehensive way across the critical infrastructure community to enable the effective allocation of security and resilience resources.
• Understanding and addressing risks from cross-sector dependencies and interdependencies is essential to enhancing critical infrastructure security and resilience.
• Gaining knowledge of infrastructure risk and interdependencies requires information sharing across the critical infrastructure community.
• The partnership approach to critical infrastructure security and resilience recognizes the unique perspectives and comparative advantages of the diverse critical infrastructure community.
• Regional and SLTT partnerships are crucial to developing shared perspectives on gaps and actions to improve critical infrastructure security and resilience.
• Infrastructure critical to the United States transcends national boundaries, requiring cross-border collaboration, mutual assistance, and other cooperative agreements.
• Security and resilience should be considered during the design of assets, systems, and networks.

The NIPP then goes into a lengthy discussion (pgs 15-20) of the iterative risk management framework that weaves together three elements of critical infrastructure; physical, cyber and human. It outlines five steps in the repetitive process:

• Set Infrastructure Goals and Objectives
• Identify Infrastructure
• Assess and Analyze Risks
• Implement Risk Management Activities
• Measure Effectiveness

It then goes on to describe 12 separate ‘Calls to Action’ that “will inform and guide efforts identified via the priority-setting and joint planning processes. They fall into three easily remembered categories:

• Build upon Partnership Efforts
• Innovate in Managing Risk
• Focus on Outcomes

Probably the most useful part of this document can be found in descriptions of the various organizations that have been established to aid in the critical infrastructure coordination process. This is found in Appendix A and includes:

• Sector Coordinating Councils
• Government Coordinating Councils
• Sector-Specific Agencies
• Critical Infrastructure Cross-Sector Council
• Federal Senior Leadership Council (FSLC)
• State, Local, Tribal, and Territorial Government Coordinating Council (SLTTGCC)
• Regional Consortium Coordinating Council (RC3)
• ISACs
• Critical Infrastructure Partnership Advisory Council
• NICC and NCCIC
• NOC
• NCIJTF

The Real Effect


There is nothing really new or earthshaking here, as one would expect from policy documents issued at the end of the fifth year of an Administration. How much effect this will have on future actions by the Federal government will depend more on who wins control of the Senate next November than how well the Administration writes regulations reflecting these goals in the next two years.

Thursday, June 6, 2013

DHS Publishes NIPP Change Notice

Today the DHS National Protection and Programs Directorate (NPPD) published a notice in the Federal Register (78 FR 34112-34115) requesting public comments on their planned changes to the National Infrastructure Protection Plan (NIPP). This revision of the NIPP was mandated by the President’s Presidential Policy Directive (PPD) 21, Critical Infrastructure Security and Resilience, that was published concurrently with the Cybersecurity EO (EO 13636).

The current version of the NIPP was published in 2009 after the triennial review. There was a short public comment period for that revision, but it was preceded by a comment period on the actual review. Neither comment period produced a lot in the way of responses.

The Proposed Changes

This notice provides a list of changes that the Department knows will be included in the revision. This include:

Changes to the sectors and designated SSAs;
Changes in terminology based on recent directives;
• Alignment with PPD-8 on National Preparedness;
Critical infrastructure security and resilience regulatory programs;
Updates on measurement and reporting and risk-informed resource allocation;
Review and update cycles for the NIPP and Sector-Specific Plans (SSPs);
Closer integration of physical and cybersecurity, including increased coordination of research and development efforts;
Sector dependencies on energy and communications systems;
Increased regional emphasis of critical infrastructure security and resilience; and
Other issues, such as aging infrastructure and climate change adaptation.

The links provided above only provide a very general overview of the changes that NPPD intends to make in the NIPP. I’m not sure how DHS expects the public to intelligently comment on the changes with such little information provided.

Public Comments

Public comments are being solicited on the proposed revision of the NIPP. Such comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2013-0024) and need to be submitted by July 8th. This short comment period is driven by the 240 day requirement in PPD-8 for the Secretary to have this revision submitted to the President.


I suppose that we should be grateful that a public comment period is provided at all. Comments should be relatively easy to formulate due to the lack of information upon which to comment.

Monday, December 6, 2010

NIPP Page Updates 12-02-10

As part of the President’s declared Critical Infrastructure Protection Month, DHS has promised to provide new information about CIP through links on their Critical Infrastructure landing page. Last week they ‘updated/reviewed’ the information on two pages that are linked from that page, the National Infrastructure Protection Plan page and the Critical Infrastructure and Key Resources Support Annex page.

I don’t track the CIKRSA page, but I don’t see anything that looks really new on the page (though it is dated as being 'reviewed/updated on 12-02-10). The NIPP page is another page that I don’t track as closely as the chemical security pages on the DHS site, but I do note some changes since I last looked at the page in August. They have added a brief video about the NIPP, a link to subscribe to the NIPP Newsletter (this link has been on the landing page since August), and a new link to an established (and unchanged) page on NIPP Resources for State and Local Partners.

The changes on the NIPP page don’t really provide any new information, but they do make it easier to find some of the information and the video does provide an easier method to learn about the NIPP. So, I suppose this update is a net positive.

Tuesday, February 24, 2009

2009 National Infrastructure Protection Plan Released

A blog at HSDL.org reported Friday that DHS had released the new version of the National Infrastructure Protection Plan (NIPP). The NIPP provides a strategy for managing and reducing the risks to the nation’s critical infrastructure and key resources (CIKR) from a “from a complex mix of manmade and naturally occurring threats and hazards”. The 2009 version of the NIPP replaces the 2006 version. The draft of this document was published in November, 2008 with the public comment period ending on December 1st. Only five comments were received in the two week comment period. The complex subject and the bureaucratic language made the draft so hard to read that I was surprised to see that many comments. It does not appear that there were any substantive improvements to the writing style in the final version. I highly recommend this document as a substitute for harsh chemical sleep aids.
 
/* Use this with templates/template-twocol.html */