• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity
January 15 2021 9:29 pm

CISA Launches Cyber Risk Reduction Venture For Nation

C

Cal Biesecker

In the wake of the recent discovery of a cyber security breach of a number of federal agencies and even more private sector entities, the Cyber Security and Infrastructure Security Agency (CISA) has introduced a new effort aimed at reducing cyber risks nationwide through better use of data, quantifying risks, and attacking areas where risks are concentrated.

The Systemic Cyber Risk Reduction Venture will be led by CISA's National Risk Management Center (NRMC), which works with critical infrastructure stakeholders in the private and public sectors to identify risks and create resiliency.

Information sharing about cyber threats and best practices is, and will remain, an important role for CISA and for strengthening the nation's cyber risk posture, but "information sharing alone will never be a silver bullet," Bob Kolasky, an assistant director of CISA in charge of the NRMC, wrote in a Jan. 14 blog post on the agency's website. "It requires using the existing efforts around vulnerability management, threat detection, and network defense as a springboard for connecting the relationship between threat, vulnerability, and consequence with actionable metrics that drive decision making."

The hack into federal and private networks was done through patches to a management software supplied by SolarWinds [SWI] that is widely used in information networks. The exploit was new, so it wasn't based on a cyber threat that had previously been seen, making it easier for the malware to reside undetected.

CISA is a component of the Department of Homeland Security.

Kolasky said the new risk reduction effort will have three main lines of effort. The first is a National Critical Functions Risk Architecture that captures data around the interdependencies and related vulnerabilities within a critical infrastructure area and puts it through a "dynamic analytic" engine. The architecture will be that engine with an initial operating capability ready this year for use "in shared cyber decision-making at the national level," he said.

The consequences of potential risks need to be understood, Kolasky said.

"Ultimately, cyber risk needs to be measured at a national level in terms of loss of functionality," Kolasky said. That means, what can happen to systems as a result of a cyber incident, how will it impact safety or economic competitiveness, and if an incident happens, how can national security impacts be mitigated or negated, he said.

The second line of effort is developing metrics for cyber risk "to quantify cyber risk in terms of functional loss," Kolasky said. This doesn't mean "Greek equations with decimal place-level specificity," he added, saying that "Metrics that provide even directional or comparative indicators are enormously useful."

Kolasky said security ratings being used to quantify cyber risk can be used with other risk metrics to inform corporate managers and national security leaders. The NRMC plans to begin work here in the coming months.

The final line of effort involves "finding concentrated sources or risk that, if mitigated, provide heightened risk management bang for the buck if addressed," he said. One example of concentrated risk is in software like open-source libraries riddled with coding flaws that can lead to vulnerabilities in systems using this software.

"Relatedly, the SolarWinds Orion cyber campaign has highlighted how tools that typically leverage a significant number of highly privileged accounts and access to perform normal business functions can themselves become adversarial attack vectors if sufficiently hardened," Kolasky said.

The NRMC, though its Information and Communications Technology Supply Chain Risk Management Task Force, has been working to address risks by prioritizing software assurance to identify risk and create tools and guidance for companies and the government to "reduce risk from software supply chains," he said.

In 2021, the ICT Supply Chain Risk Management Task Force will begin working across the critical infrastructure community and federal government on reducing software risks, he said.

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles