Balance of Power - Building a Resilient Electric Grid

In early September, Hurricane Ida caused a massive blackout, leaving New Orleans in the dark for more than two days. A month before Ida, Tropical Storm Henri cut power to 100,000 households in Rhode Island. The wildfires in the western United States are common sources of blackouts in California. And earlier this year in Central Texas, harsh winter conditions led to a breakdown of the state’s electric grid, leaving one million people without heat and electricity for days.

These types of events are increasing in frequency as the nation’s infrastructure ages and climate change leads to extreme weather events. Hotter, wetter summers and harsher winters require more reliance on heating and cooling utilities, placing higher stress on the nation’s electric grid. For nearly a decade and a half, the Science and Technology Directorate (S&T) has teamed up with industry and one of the nation’s largest (and windiest) cities to study how technology can ‘help keep the lights on’ during emergencies. This fall, S&T and its partners announced the fruits of this labor: the successful installation and operation of the Resilient Electric Grid (REG) system in Chicago.

How the Electric Grid Works

This is a simplified arrangement of the grid system in the U.S. At the Generation step, electricity is generated at various kinds of power plants by utilities and independent power producers. The plant has lines leading to a transmission substation. The next step is Transmission where electric transmission is the vital link between power production and power usage. There are transmission lines from the generating plant that carry electricity at high voltages over long distances from power plants to communities. These lines lead to a Substation. At the bottom of the image are three light gray buildings with yellow windows, and the bottom right of the image are tall dark gray buildings. Lines from the substation lead to these buildings to represent the Distribution step, where electricity from transmission lines is reduced to lower voltages at substations, and distribution companies then bring the power to your home and workplace. Power lines lead from the Substation to another Substation to the right of the image. Lines from this substation lead to a farm and four houses.The electric grid is a complex network that spans the creation of electricity at a power generation station to the delivery of electricity to the end user. To get from the generation site to the end user, often several (possibly hundreds of) miles away, electricity travels through the transmission system, which converts the very high voltage electricity generated by the power plant to lower voltages. The electricity is further stepped down in voltage through the distribution network as it gets closer to homes, business, and other facilities. Major urban communities have multiple distribution level substations throughout the city to meet the electrical power needs of its population.

Ideally, these distribution substations would be interconnected, so if one substation fails for any reason, another can step in and provide electricity—like driving on system of highways, streets, and roads where you have multiple routes that can get you to the same destination. In reality, however, distribution substations are not interconnected. This is a designed safety feature in the grid so that an issue at one substation, such as a fault current (a large spike in electric current) doesn’t cascade down through the system and impact other substations.

As a result of this set up, if a substation fails, the area that that substation serves experiences a blackout. But what if we could prevent the risk associated with connecting substations so that in the event of a substation failure, other substations could step in and “help” continue to deliver power, creating multiple paths for power to flow just like how traffic flows on the internet?
S&T Powered (and Empowered) a Solution

Finding a solution to increase grid resilience inspired S&T to launch its REG project back in 2007. The project built on the Department of Energy’s (DOE) previous research on High Temperature Superconducting (HTS) cables.

S&T’s Sarah Mahmood, an electrical engineer, led the S&T project team in collaboration with American Superconductor (AMSC), a leading system provider of megawatt-scale power resiliency solutions.

Together, the team developed REG systems featuring cable systems that utilize AMSC’s proprietary Amperium® HTS technology designed to suppress surges while providing the ability to connect substations without risking a cascading fault current.

“Substations are usually not connected because of the risk of fault currents. It’s like a surge. In your house, you use a surge protector. If you don’t have protection against fault currents, you risk damaging the equipment downstream. But because they’re not connected, they lack resiliency,” Mahmood explained.

How a Superconductor Works

HTS cables use liquid nitrogen to keep the cable cool enough to function in a superconducting state. If the HTS cable experiences a fault, the fault creates energy which heats up the system so that it is no longer in a superconducting state, essentially turning itself off automatically, like a switch, preventing equipment damage. What’s more, because HTS cables are superconducting there is very little resistance or loss of power over the length of the cable making them more efficient compared to traditional power cables, which experience a loss of power over distance.

After years of research, development and lab testing to prove the concept of a fault current limiting high temperature superconducting cable, S&T and AMSC partnered with Commonwealth Edison (ComEd), the largest electric utility in Illinois serving over four-million customers, to integrate the technology in the grid.

“S&T is grateful for the partnership with ComEd enabling us to install the REG system in the grid as a permanent asset, hopefully setting a pathway for broader market adoption of this new capability by industry as a potential solution to increase grid resilience,” Mahmood explained.

“The successful integration of the REG system is a major milestone in our efforts to enhance our service to customers through innovation,” said Terence R. Donnelly, President and COO of ComEd. “The increasingly frequent and severe weather events associated with climate change and the need for enhanced cyber and physical security require grid investments that will sustain the high levels of safe and reliable power that our customers depend on.”

HTS Technology Brings Resiliency to Power Grid Operations

A stable homeland is dependent on the reliable delivery of electricity—from public health to the economy and national security. According to DOE's Grid Modernization and the Smart Grid project, there are more than 9,200 electric generating units with more than 1 million megawatts of generating capacity feeding more than 600,000 miles of transmission lines that comprise the U.S. electric grid.

“Our superconductor-based REG system improved the reliability and resiliency of the grid, reducing disruption to public infrastructure and saving money for utility customers—all in an environmentally-friendly manner,” said Daniel P. McGahn, Chairman, President & CEO, AMSC. “We believe this accomplishment opens opportunities for AMSC to deploy REG systems to other innovative utilities.”

On September 30, DHS and DOE participated in a ribbon-cutting in Chicago to highlight the REG system installation into the ComEd grid. ComEd is the first utility in the United States to permanently install the AMSC REG system into the grid and will evaluate connecting it to multiple substations in order to create a back-up system for continuous power delivery even with a disruption to the power grid.

“S&T will continue to monitor the REG system’s performance with hopes for future commercialization, as other utilities look to increase grid resiliency,” said Mahmood.

According to a DOE study, the United States loses nearly $70 billion each year from power outages. S&T’s continued research and development efforts aim to enhance the nation’s overall energy resilience, so future generations can keep the lights on.

[Article source: DHS S&T]

Artificial Intelligence: How to make Machine Learning Cyber Secure

Machine learning (ML) is currently the most developed and the most promising subfield of artificial intelligence for industrial and government infrastructures. By providing new opportunities to solve decision-making problems intelligently and automatically, artificial intelligence (AI) is applied in almost all sectors of our economy.

While the benefits of AI are significant and undeniable, the development of AI also induces new threats and challenges, identified in the ENISA AI Threat Landscape.

How to prevent machine learning cyberattacks? How to deploy controls without hampering performance? The European Union Agency for Cybersecurity answers the cybersecurity questions of machine learning in a new report recently published.

Machine learning algorithms are used to give machines the ability to learn from data in order to solve tasks without being explicitly programmed to do so. However, such algorithms need extremely large volumes of data to learn. And because they do, they can also be subjected to specific cyber threats.

The Securing Machine Learning Algorithms report presents a taxonomy of ML techniques and core functionalities. The report also includes a mapping of the threats targeting ML techniques and the vulnerabilities of ML algorithms. It provides a list of relevant security controls recommended to enhance cybersecurity in systems relying on ML techniques. One of the challenges highlighted is how to select the security controls to apply without jeopardising the expected level of performance.

The mitigation controls for ML specific attacks outlined in the report should in general be deployed during the entire lifecycle of systems and applications making use of ML.

Machine Learning Algorithms Taxonomy

Based on desk research and interviews with the experts of the ENISA AI ad-hoc working group, a total of 40 most commonly used ML algorithms were identified. The taxonomy developed is based on the analysis of such algorithms.

The non-exhaustive taxonomy devised is to support the process of identifying which specific threats target ML algorithms, what are the associated vulnerabilities and the security controls needed to address those vulnerabilities.

The EU Agency for Cybersecurity continues to play a bigger role in the assessment of Artificial Intelligence (AI) by providing key input for future policies. The Agency takes part in the open dialogue with the European Commission and EU institutions on AI cybersecurity and regulatory initiatives to this end.

ESF Members, NSA and CISA publish the fourth installment of 5G cybersecurity guidance

The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) published the fourth installment on securing integrity of 5G cloud infrastructures, Ensure Integrity of Cloud Infrastructure. As 5G networks and devices continue to increase in popularity, the importance of platform security to harden your systems against malicious cyber activity and persistence is apparent.

This guidance has been created by the Critical Infrastructure Partnership Advisory Council (CIPAC) Cross Sector Enduring Security Framework (ESF) Working Group - a public-private working group led by NSA and CISA, that provides cybersecurity guidance addressing high priority threats to the nation’s critical infrastructure.

Ensure Integrity of Cloud Infrastructure provides guidance on platform integrity, build time security, launch time integrity, and micro services infrastructure integrity. An industry trend has been to deploy stand-alone 5G core using virtualized functions of micro services on an architecture that provides rapid enablement of services. It is imperative for device and system security that the underlying 5G cloud infrastructure platform on which micro services are deployed, or orchestrated, have been designed and built securely and continue operating as intended.

"A secure 5G core requires cybersecurity mitigations that are implemented at the foundation level and carried forward," said Jorge Laurel, NSA Project Director for ESF. "A secure underlying foundation ensures the services deployed on the network are done so on a secure infrastructure, which further strengthens the security of data across the network."

“The document provides actionable advice for 5G operators, said Neal Ziring, NSA Cybersecurity Technical Director. “The fourth installment in the series covers an essential topic: integrity. Integrity is the most fundamental security property, and ensuring integrity from base hardware up through the software stack is critical for maintaining trustworthy 5G services.”

“The issues facing the cloud community, such as lateral movement to pod security and infrastructure integrity, are complex as are their solutions,” said Alaina Clark, Assistant Director of Stakeholder Engagement, CISA. “This series demonstrates the value of collaboration, spotlighting several cyber best practices that cloud providers, mobile network operators, and customers alike can implement for long-term security benefits. With our ESF government and industry associates, CISA will continue working with the Cloud and 5G communities to secure our Nation’s network infrastructure through partnership efforts like this.”

Maritime Infrastructure: Public Ports Engage in an Extensive Range of Activities beyond Freight Movement

Coastal, Great Lakes, and inland ports are critical to the U.S. economy. Aside from moving freight, ports across the U.S. have a variety of non-freight activities—like cruise ship and ferry terminals, commercial fishing, recreation, and commercial and residential development. Ports engage in non-freight activities to diversify business, find new uses for underused facilities, and contribute to community development.

Federal grant programs we reviewed provided some support to ports for these activities, with the Department of Transportation providing most funding for freight and non-freight projects.

Public ports across the U.S. pursue an extensive range of activities unrelated to freight movement. Examples of such non-freight activities include cruise ship and ferry terminals, commercial fishing, recreation, and commercial and residential development. In a GAO survey of ports, 67 of the 80 respondents reported being involved in non-freight activities in the last 10 years, with most respondents having a mix of freight and non-freight activities. Port officials said they pursue non-freight activities to diversify lines of business, find new uses for underused facilities, and address unmet community development needs, among other reasons. Non-freight activities can also have economic impacts including creating jobs, according to port stakeholders and economic impact studies. For example, one study estimated that commercial fishing activity at the Port of Seattle accounted for 11,300 jobs and generated $1.4 billion in total business output in 2017. Ports most commonly reported funding their non-freight activities with port revenues (55 survey respondents) or state funds (53 survey respondents).

Federal grant programs GAO reviewed have provided some funding to ports for non-freight projects but have largely focused on freight. According to GAO's analysis of federal grant award data for fiscal years 2010 through 2020, agencies provided at least $141 million to ports for non-freight projects during this time, or about 8 percent of the almost $1.9 billion in total funding these programs awarded to ports, in fiscal year 2020 dollars. The U.S. Department of Transportation (DOT) provided the majority of funding to ports for both freight and non-freight projects. DOT-funded non-freight projects include ferry-, cruise-, and fishing-related projects, among others. Stakeholders reported that ports, especially small ports, face challenges with federal grant programs. For example, stakeholders and federal officials said that many grant programs GAO reviewed are consistently oversubscribed and that smaller ports may lack the resources to develop a competitive application. Stakeholders GAO spoke with differed on the need for additional federal funding for non-freight activities.

The nation's coastal, Great Lakes, and inland ports have long been recognized as critical to the national and local economies. Ports can contribute not only by moving freight but also, for example, through activities related to tourism, transportation, or real estate. Nationwide port studies have typically focused on the impact of freight, and less attention has been paid to these non-freight activities.

House Report 116-452 included a provision for GAO to examine ports' non-freight activities. This GAO report describes (1) what is known about the nature of and funding for non-freight activities at public ports, and (2) the extent to which federal discretionary grant programs have provided funds to public ports for non-freight and freight projects, and stakeholders' views on this federal assistance.

To address the two objectives above, GAO conducted a non-generalizable survey of 80 ports and interviewed officials at 15 ports and 14 port industry stakeholders. GAO selected ports for variety based on their level of non-freight activity, freight traffic, and location, and whether they have applied for DOT funding. GAO also interviewed officials within DOT; the Departments of Commerce (Commerce), Defense, and Homeland Security; and the Environmental Protection Agency (EPA).

ESA and PSCE cooperate on Space Applications and Digital Transformation in Public Safety

The European Space Agency (ESA) and Public Safety Communication Europe (PSCE) are working together to support the emergence of space-based applications in the domain of public safety. Having jointly signed a Memorandum of Intent (MoI), the organisations will join efforts to support the emergence of applications that leverage on secure satellite communications for addressing the needs of blue forces. ESA will launch a funding call early in 2022 to invite companies to develop and demonstrate digital services that are enabled by secure satcom solutions for addressing the urgent needs of public safety operators.

Security in space and on Earth are inextricably linked. The deployment of advanced satellite systems and their safe circulation in space are crucial for resilient and secure connectivity on Earth. As set out in its recently released vision for European space activities, ESA is stepping up its efforts to enable Europe to address new safety and security user needs to make sure that our space programmes continue to be at the service of all citizens through Agenda 2025. ESA's Strategic Programme Line “Space Systems for Safety and Security (4S)” combines both to include applications within disaster preparedness, response and resilience, situational awareness, assessments of damages, navigation-based services for tracking and coordinating rescue forces on-site and for emergency vehicles.

Through its ARTES (Advanced Research in Telecommunications Systems) programme, ESA is forging strong links between institutions, industries, and business to leverage the capabilities of space to drive digital services.

“I’m pleased to be working with PSCE to realise the potential of space to drive commercial solutions for secure satellite communication in public safety. This is a great example on how ESA is promoting the use of space technologies and applications to address safety and security needs expressed by the organisations operating in this domain. This collaboration will pave the way to the ESA Rapid and Resilient Crisis Response (R3) Accelerator,“ says Rita Rinaldo, Head of the Partner-led and Thematic Initiatives Section, ESA Space Solutions.

DHS Announces New Cybersecurity Requirements for Surface Transportation Owners and Operators

DHS’s Transportation Security Administration (TSA) has announced two new Security Directives and additional guidance for voluntary measures to strengthen cybersecurity across the transportation sector in response to the ongoing cybersecurity threat to surface transportation systems and associated infrastructure. These actions are among several steps DHS is taking to increase the cybersecurity of U.S. critical infrastructure.

“These new cybersecurity requirements and recommendations will help keep the traveling public safe and protect our critical infrastructure from evolving threats,” said Secretary of Homeland Security Alejandro N. Mayorkas. “DHS will continue working with our partners across every level of government and in the private sector to increase the resilience of our critical infrastructure nationwide.”

TSA is increasing the cybersecurity of the transportation sector through Security Directives, appropriately tailored regulations, and voluntary engagement with key stakeholders. In developing its approach, including these new Security Directives, TSA sought input from industry stakeholders and federal partners, including the Department’s Cybersecurity and Infrastructure Security Agency (CISA), which provided expert guidance on cybersecurity threats to the transportation network and countermeasures to defend against them.

The TSA Security Directives announced today target higher-risk freight railroads, passenger rail, and rail transit, based on a determination that these requirements need to be issued immediately to protect transportation security. These Directives require owners and operators to:

- designate a cybersecurity coordinator;
- report cybersecurity incidents to CISA within 24 hours;
- develop and implement a cybersecurity incident response plan to reduce the risk of an operational disruption; and,
- complete a cybersecurity vulnerability assessment to identify potential gaps or vulnerabilities in their systems.

TSA is also releasing guidance recommending that all other lower-risk surface transportation owners and operators voluntarily implement the same measures. Further, TSA recently updated its aviation security programs to require that airport and airline operators implement the first two provisions above. TSA intends to expand the requirements for the aviation sector and issue guidance to smaller operators. TSA also expects to initiate a rule-making process for certain surface transportation entities to increase their cybersecurity resiliency.

These efforts are part of a series of new steps to prioritize cybersecurity across DHS. Secretary Mayorkas first outlined his vision for the Department’s cybersecurity priorities in March, which included a series of focused 60-day sprints designed to elevate existing work, remove roadblocks to progress, and launch new initiatives and partnerships to achieve DHS’s cybersecurity mission and implement Biden-Harris Administration priorities. To learn more about the sprints, please visit www.dhs.gov/cybersecurity.

GAO Report: Cybersecurity - Federal Actions Urgently Needed to Better Protect the Nation's Critical Infrastructure

Recent events—including the ransomware attack on a major U.S. fuel pipeline—illustrate the need to strengthen the cybersecurity of the nation's critical infrastructure.

We testified on the need for the federal government to develop and execute a comprehensive national cyber strategy, and to strengthen the role that it plays in protecting the cybersecurity of critical infrastructure. Ensuring the cybersecurity of the nation is on our High Risk List, and we have urged federal agencies to act on it.

If the federal government doesn't act with greater urgency, the security of our nation's critical infrastructure will be in jeopardy.

GAO has previously reported on major cybersecurity challenges facing the nation and the critical federal actions needed to address them (see figure).

Four Major Cybersecurity Challenges and 10 Associated Critical Actions

To address critical infrastructure cybersecurity, key actions the federal government needs to take include (1) developing and executing a comprehensive national cyber strategy and (2) strengthening the federal role in protecting the cybersecurity of critical infrastructure.

Develop and execute a comprehensive national cyber strategy. In September 2020, GAO reported that the White House's 2018 National Cyber Strategy and related implementation plan addressed some, but not all, of the desirable characteristics of national strategies, such as goals and resources. GAO also reported that it was unclear which official within the executive branch ultimately maintained responsibility for coordinating the execution of the National Cyber Strategy. Accordingly, GAO recommended that the National Security Council update the cybersecurity strategy and for Congress to consider legislation to designate a position in the White House to lead such an effort.

In January 2021, a federal statute established the Office of the National Cyber Director within the Executive Office of the President. In June 2021, the Senate confirmed a Director to lead this new office. In October 2021, the National Cyber Director issued a strategic intent statement, outlining a vision for the Director's planned high-level lines of efforts. The establishment of a National Cyber Director is an important step toward positioning the federal government to better direct activities to address the nation's cyber threats. Nevertheless, GAO's recommendation to develop and execute a comprehensive national cyber strategy is not yet fully implemented. As a result, a pressing need remains to provide a clear roadmap for addressing the cyber challenges facing the nation, including its critical infrastructure.

Strengthen the federal role in protecting the cybersecurity of critical infrastructure. Pursuant to legislation enacted in 2018, the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security (DHS) was charged with responsibility for, among other things, enhancing the security of the nation's critical infrastructure in the face of both physical and cyber threats. In March 2021, GAO reported that DHS needed to complete key activities related to the transformation of CISA, including finalizing the agency's mission-essential functions and completing workforce planning activities. GAO also reported that DHS needed to address challenges identified by selected critical infrastructure stakeholders, including having consistent stakeholder involvement in the development of related guidance (see figure). Accordingly, GAO made 11 recommendations to DHS. As of November 2021, DHS had not yet implemented them, though it stated its intent to do so.

Cybersecurity and Infrastructure Security Agency (CISA) Coordination Challenges Reported by Stakeholders Representing the 16 Critical Infrastructure Sectors

Regarding specific critical infrastructure sectors, since 2010 GAO has made about 80 recommendations to enhance the cybersecurity of these sectors and subsectors, including within the aviation and pipeline industries. In October 2020, GAO reported that, although the Federal Aviation Administration had established a process for certification and oversight of U.S. commercial airplanes, it had not prioritized risk-based cybersecurity oversight or included periodic testing as part of its monitoring process, among other things. In July 2021, GAO testified that the Transportation Security Administration had not fully addressed pipeline cybersecurity-related weaknesses that GAO had previously identified, such as aged protocols for responding to pipeline security incidents. Until GAO's recommendations to address issues such as these are fully implemented, federal agencies will not be effectively positioned to ensure critical infrastructure sectors are adequately protected from potentially harmful cybersecurity threats.

2nd edition of National Cybersecurity Strategy Guide Launched

The Guide to Developing a National Cybersecurity Strategy is one of the most comprehensive overviews of what constitute successful cybersecurity strategies. It is the result of a unique, collaborative, and equitable multi-stakeholder effort.

Over the last two decades, people worldwide have benefitted from the growth and adoption of information and communication technologies (ICTs) and associated socio-economic and political opportunities. Digital transformation can be a powerful enabler of inclusive and sustainable development, but only if the underlying infrastructure and services that depend on it are safe, secure, and resilient. To reap the benefits and manage the challenges of digitalization, countries need to frame the proliferation of ICT-enabled infrastructures and services within a comprehensive national cybersecurity strategy.

To help governments in this endeavour, a consortium of partner organisations jointly developed and published the first Guide to Developing a National Cybersecurity Strategy (NCS) in 2018. Since then, the number of national cybersecurity strategies or frameworks worldwide has increased significantly. In 2018, only 76 countries had adopted a strategy while today more than 127 countries have such strategies in place, and many have used the Guide as a reference and blueprint.1

However, the fast-changing nature of cyberspace, the increased dependency on ICT, and the proliferation of digital risks all call for continuous improvements to national cybersecurity strategies. Most countries have both accelerated their digital transformation and become increasingly concerned about the immediate and future threats to their critical services, infrastructures, sectors, institutions, and businesses, as well as to international peace and security, that could result from the misuse of digital technologies and inadequate resilience.

This second edition of the Guide could not come at a more critical time. The updated content reflects the complex and evolving nature of cyberspace, as well as the main trends that can impact cybersecurity and should, therefore, be included into national strategic planning. The objective of the Guide is to instigate strategic thinking and continue supporting national leaders and policy-makers in the ongoing development, establishment, and implementation of such national cybersecurity strategies and policies. We are confident that this new Guide will serve as a useful tool for all stakeholders with cybersecurity responsibilities.

The purpose of the report is to guide national leaders and policy-makers in the development of a National Cybersecurity Strategy, and in thinking strategically about cybersecurity, cyber-preparedness and resilience.

This Guide aims to provide a useful, flexible and user-friendly framework to set the context of a country’s socio-economic vision and current security posture and to assist policy-makers in the development of a Strategy that takes into consideration a country’s specific situation, cultural and societal values, and that encourages the pursuit of secure, resilient, ICT-enhanced and connected societies.

The Guide is a unique resource, as it provides a framework that has been agreed on by organisations with demonstrated and diverse experience in this topic area and builds on their prior work in this space. As such, it offers the most comprehensive overview to date of what constitutes successful national cybersecurity strategies.

Security Industry raises threat level to Omega Status (Plan for the worst)

The Private Security Industry is the largest force in the world, bigger than any police, military unit or navy that is active 24/7. The security industry has been in a constant state of monitoring the threat and on August the 1st 2021 certain things rolled out that confirmed information which set the time clock for using specific second stage research that ended on the 12th of November.

On the 20th of November 2021, the recent biological threat security investigation now dictates that the Omega Status must be enforced based on the monitoring of the viral pattern formation taking into consideration, the human disorder besides other crime related to the threat. Within two days of the status being called for, a variant was identified by South Africa and within hours some countries banned flight travel to and from South Africa. This is even before the world -health organization named the variant which is now named Omicron.

It is the security industry that is implementing the health protocols on the ground but do more. They take the temperatures of people, manage the movement of people and that the populous satanize. They do more because there is crime related to the threat. The practitioners on the ground not only have to find new crime, evolving copycat crime, increased habitual crime, besides handling violent and aggressive behaviour. Furthermore, the practitioners have to protect their companies and sites.

Juan Kirsten Director Genera of ISIO | International Security Industry Organization says,‘’ the Alpha is the leader of the pack, and the Omega is the last born. We have experienced this Alpha beast that is changing at a moments notice in its way of movement and devouring everything in its path. The world is now at a time where the fundamental information gives conclusion to now plan for the worst because we have no idea of when and how the last born will behave’’

Security Success depends on the level of situational awareness of the people on the ground and their reaction speed (Kirsten, J 2018). Authentic situational awareness dictates that the security industry or any practitioner can never afford to be in a state of denial or bias towards any threat. When the industry calls for Omega Threat Status, the members know this is the highest form of threat alert and must be taken seriously!

This knowledge affirms the fact sufficiently to activate the planning and implementation of protocols to limit the level of damage of the Omega Impact (the worst situation)

Taking into consideration two objectives namely,
• the profit protection of security industry practitioners as well as their clients
• limiting the level of collateral damage of the active mutating bio-threat and its tailing threats.

Professional practitioners in this field are realistic and relevant! They consciously accept without bias the fact that the threat in theatre is here to stay and that they need to live with it but - the threat can easily turn nasty based on sound logical thought because of the pattern formation. They know that they must be in Omega Status.

Tony Botes the Administrator of Security Association of South Africa says, ‘’Security practitioners besides all stake holders must realize the importance the security sector as it is now officially on the ground and front line for Chemical, Biological, Radiological or Nuclear Warfare (CBRN). All must know the security protocols and crime related to the threat as to avoid collateral of not only the pandemic but also by citizens for example, anarchy which will cause even more ciaos’’

Professionals know what objectives and goals to focus on and where to obtain reliable information and protocols that they need to be fully versed on. Simply put - It is their obligation to be relevant!

Chairman Kunwar Vikram Singh of India’s Central Association of Private Security Industry (CAPSI) states that ‘’the security and safety professionals are still undermining the bio security threats and not responding the way they should have. They are responsible for millions of people. Political leadership and bureaucrats must realize the gravity of the new security challenges and act fast. Protocols already available by the security industry must be followed by law to save your world’’

View (https://www.human-investigation-management.com/cbts-certified-for-biological-threat-security/ )the knowledge and skills to set protocols to plan for the worst and actions to take for profit protection for the Omega Impact.

Presented by the following representing 9.15 Million Security Practitioners
Juan Kirsten Director General ISIO | International Security Industry Organization,
Kunwar Vikram Singh Chairman CAPSI | Central Association of Private Security Industry
Tony Botes Administrator of SASA | South African Security Association

 

CISA Should Assess the Effectiveness of its Actions to Support the Communications Sector

The Communications Sector is an integral component of the U.S. economy and faces serious physical, cyber-related, and human threats that could affect the operations of local, regional, and national level networks, according to the Department of Homeland Security's (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and sector stakeholders.

The communications sector—comprising mostly private broadcast, cable, satellite, wireless, and wired systems and networks—is vital to national security.

The Cybersecurity and Infrastructure Security Agency supports the security and resilience of this sector, primarily through incident management and information-sharing activities. For instance, the agency coordinates federal activities during severe weather events, and manages cybersecurity programs.

However, the agency has not assessed the effectiveness of its programs and services to support this sector. We recommended that it do so.

In addition, CISA determined that the Communications Sector depends on other critical infrastructure sectors—in particular, the Energy, Information Technology, and Transportation Systems Sectors—and that damage, disruption, or destruction to any one of these sectors could severely impact the operations of the Communications Sector.

CISA primarily supports the Communications Sector through incident management and information-sharing activities, such as coordinating federal activities to support the sector during severe weather events and managing cybersecurity programs, but has not assessed the effectiveness of these actions. For example, CISA has not determined which types of infrastructure owners and operators (e.g., large or small telecommunications service providers) may benefit most from CISA's cybersecurity programs and services or may be underrepresented participants in its information-sharing activities and services. By assessing the effectiveness of its programs and services, CISA would be better positioned to identify its highest priorities.

CISA has also not updated the 2015 Communications Sector-Specific Plan, even though DHS guidance recommends that such plans be updated every 4 years. As a result, the current 2015 plan lacks information on new and emerging threats to the Communications Sector, such as security threats to the communications technology supply chain, and disruptions to position, navigation, and timing services. Developing and issuing an updated plan would enable CISA to set goals, objectives, and priorities that address threats and risks to the sector, and help meet its sector risk management agency responsibilities.

GAO is making three recommendations to CISA, including that CISA assess the effectiveness of its support to the Communications Sector, and revise its Communications Sector-Specific Plan. The Department of Homeland Security concurred with the recommendations. The Department of Commerce and the Federal Communications Commission did not provide comments on the draft report.

The Director of CISA should assess the effectiveness of CISA's programs and services to support the Communications Sector, including developing and implementing metrics and analyzing feedback received from owners and operators, to determine the usefulness and relevance of its activities to support sector security and resilience. (Recommendation 1)

The Director of CISA should complete a capability assessment for Emergency Support Function #2, such as establishing requirements, maintaining a list of current capabilities, and conducting a capability gap analysis to identify if and where other resources may be needed. (Recommendation 2)

The Director of CISA, in coordination with public and private Communications Sector stakeholders, should produce a revised Communications Sector-Specific Plan, to include goals, objectives, and priorities that address new and emerging threats and risks to the Communications Sector and that are in alignment with sector risk management agency responsibilities. (Recommendation 3)

1 31 32 33 34 35 63