House Homeland Security Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Emergency Preparedness, Response and…
| Federal Information & News Dispatch, Inc. |
Testimony by
Chairwoman Brooks and Chairman Meehan, Ranking Members Payne and Clarke, and distinguished Members of the Committee, it is a pleasure to appear before you today to discuss the
America's cybersecurity is inextricably linked to our nation's economic vitality - IT systems are interdependent, interconnected and critical to our daily lives - from communication, travel, and powering our homes, to running our economy, and obtaining government services. DHS is the lead Federal civilian department responsible for coordinating the national protection, prevention, mitigation, and recovery from cyber incidents and works regularly with business owners and operators to take steps to strengthen their facilities and communities, which include the nation's physical and cyber infrastructure. We are also committed to ensuring cyberspace is supported by a secure and resilient infrastructure that enables open communication, innovation, and prosperity while protecting privacy, confidentiality, and civil rights and civil liberties by design.
Cybersecurity Support to SLTT Emergency Managers
Protecting this infrastructure against growing and evolving cyber threats requires a layered approach. The government's role in this effort is to share information and encourage enhanced security and resilience, while identifying and addressing gaps not filled by the marketplace. Providing effective cybersecurity services requires fostering relationships with those who own and operate the communications infrastructure, members of the emergency responder community, and Federal, state, local, tribal, and territorial partners. Indeed, as many of the communications technologies currently used by public safety and emergency services organizations move to an Internet Protocol (IP)-based environment, there is an increase in the cyber vulnerabilities of our emergency services providers in the conduct of their mission. It is important, therefore, for the Department to engage not just Chief Information Officers (CIO) or Chief Information Security Officers (CISO) at the SLTT level, but also the emergency managers and other officials for whom a secure cyber environment is equally as important to accomplishing their mission.
The Department has initiated several activities focused on ensuring SLTT emergency managers are able to build cybersecurity resilience into those information and technology networks and systems upon which they depend. Cyber dependencies and interdependencies require interactions between several different DHS organizations and SLTT partners in order to address this complex need. DHS has been forward-thinking as the reliance upon cyber systems has grown and our engagements have been ongoing.
Previous Efforts
*
* Emergency Services Sector Cyber Risk Assessment. Encompassing a wide range of emergency response functions carried out by five disciplines n1, in 2012 the Emergency Services Sector completed a Cyber Risk Assessment, which provides a risk profile to enhance the security and resilience of the Emergency Services Sector disciplines. It is an effort to establish a baseline of cyber risks across the sector, to ensure Federal resources are applied where they offer the most benefit for mitigating risk, and to encourage a similar risk-based allocation of resources within state and local entities and the private sector. Emergency managers from local, state, and Federal government actively participated in the development process to ensure the assessment provided practical guidance for the public safety community. The Department continues to meet with officials from stakeholder associations such as the
* Local Pilot Projects with
The second pilot is underway with the
The third pilot is a joint cyber-physical assessment of a Federal facility in
The lessons from these pilots have been incorporated into our integrated physical and cyber Regional Resiliency Assessment Program (RRAP). This is helping strengthen the partnership we already have; build new relationships between SLTT CIOs, first responders, and critical infrastructure owners and operators; and lay the foundation increased collaboration to increase cybersecurity resilience.
* Nationwide Public Safety Broadband Network (NPSBN) Cyber Infrastructure Risk Assessment. The development and deployment of an IP-based network for public safety will represent a leap forward in communications capabilities for first responders, law enforcement, and other users of the NPSBN. However, the move to such a network presents a challenge for the emergency management community to identify threats to and vulnerabilities of cyber infrastructure in the NPSBN that could affect the network's reliability and security. DHS is working with the
* Cyber Threat Information Sharing
In
Ongoing Efforts
DHS continues to build upon the relationships we have established throughout the Emergency Services Sector through strategic and operational efforts to provide solutions to our SLTT partners. Ongoing efforts within DHS consist of:
* Update to the National Emergency Communications Plan. DHS is updating the National Emergency Communications Plan (NECP) in coordination with the public safety community to enhance planning, preparation, and security of broadband technologies used during response operations. The Plan will discuss how cybersecurity has become a key consideration for public safety officials as new IP-enabled technology is increasingly integrated into operations. The NECP will endorse a multifaceted approach to ensure the confidentiality, integrity, and availability of sensitive data. For example, comprehensive cyber training and education on the proper use and security of devices and applications, phishing, malware, other potential threats, and how to stay on guard against attacks will be recommended.
* 9-1-1 Centers: Next Generation 9-1-1 and Telephonic Denial of Service. Updated 9-1-1 infrastructure utilizes public voice, data, and video capabilities, which introduce new vulnerabilities into 9-1-1 systems. Separately, 9-1-1 centers have been targeted by telephonic denial of service (TDOS) attacks that overwhelm Public Safety Answering Points' administrative lines. These attacks inundate a 9-1-1 call center with a high volume of calls, overwhelming the system's ability to process calls and tying up the system from receiving legitimate calls. DHS, through the NCCIC, has worked on the development and dissemination of techniques for mitigating and managing these TDOS attacks in order to allow emergency management agencies to continue to provide these critical services to the public.
*
* Multi-State Information Sharing and Analysis Center (MS-ISAC)
DHS builds partnerships with non-federal public sector stakeholders to protect critical network systems. For example, the Multi-State Information Sharing and Analysis Center (MS-ISAC) opened its
Operational Efforts
Assuring the security and reliability of critical information networks is vital across all critical infrastructure sectors, including the Emergency Services Sector, which is charged with saving lives, protecting property and the environment, assisting communities impacted by disasters, and aiding recovery from emergencies. DHS is uniquely positioned to improve the cybersecurity posture of our stakeholders.
The Offices of the
*
CS&C maintains an overall focus on reducing risk to the communications and information technology infrastructures and the sectors that depend upon them, as well as providing threat and vulnerability information and enabling timely response and recovery of these infrastructures under all circumstances. We execute our mission by supporting 24x7 information sharing, analysis, and incident response through the
*
Coordinated Cyber/Physical Response
While the
* Hurricane Sandy: NPPD operational efforts were able to facilitate much-needed fuel deliveries to critical telecommunication sites in lower
* Boston Marathon Bombing: OEC worked closely with public safety agencies in the
Conclusion
DHS provides a variety of services and capabilities designed to support emergency managers at all levels of engagement, across education, planning, cyber-incident response, and recovery activities. The services and capabilities are all integral parts of reducing risk and building capacity of our SLTT partners. As necessary, those relationships are leveraged in operational response efforts in order to meet immediate, critical needs. As technologies continue to advance and the dependencies and interdependencies between the sectors and systems continue to advance along with them, DHS will continue to work with emergency managers in a holistic fashion to plan, prepare, mitigate and build resilience into those information and technology networks and systems upon which they depend on a daily basis. Thank you for this opportunity to testify, and I look forward to answering any questions you may have.
n1 Law Enforcement; Fire and Emergency Services; Emergency Management; Emergency Medical Services; and Public Works
Read this original document at: http://docs.house.gov/meetings/HM/HM12/20131030/101429/HHRG-113-HM12-Wstate-StempfleyR-20131030.pdf
| Copyright: | (c) 2010 Federal Information & News Dispatch, Inc. |
| Wordcount: | 2749 |


Advisor News
- Your client wants to cash out an annuity. Here’s what to consider
- How student loan debt impacts 401(k) balances
- The ‘sandwich generation’ faces compounded barriers to retirement savings
- Benefit Costs Squeeze Schools, Driving Cuts, Tax Hikes And Difficult Tradeoffs
- Why client insurance needs could change even if their life doesn’t
More Advisor NewsAnnuity News
- AM Best to Discuss Its Views on Private Credit Surge and Risks at 2026 NAIC/NIPR Insurance Summit
- OID recovers $260M in life insurance benefits
- NUNN BILLS TO COMBAT PAYMENT SCAMS, CUT FINANCIAL RED TAPE PASS FINANCIAL SERVICES COMMITTEE
- SS&C Black Diamond Expands Annuities & Insurance Marketplace with New Insurance Capabilities and Carriers
- Regulators urged to sharply limit hypothetical data in annuity illustrations
More Annuity NewsHealth/Employee Benefits News
Life Insurance News