gt governors summit cybersecurity and privacy_16_presentation - building a secure and resilient...

12
Cybersecurity is about Risk (Not Just Technology) Brig. Gen. (ret) Greg Touhill Deputy Assistant Secretary Office of Cybersecurity and Communications U.S. Department of Homeland Security Homeland Security

Upload: erepublic

Post on 15-Apr-2016

27 views

Category:

Documents


0 download

DESCRIPTION

Governors Summit Cybersecurity and Privacy 16 Presentation - Building a Secure and Resilient Organization by Brig. Gen. (ret.) Greg Touhill

TRANSCRIPT

Page 1: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

Cybersecurity is about Risk (Not Just Technology)

Brig. Gen. (ret) Greg Touhill Deputy Assistant Secretary

Office of Cybersecurity and CommunicationsU.S. Department of Homeland Security

Homeland Security

Page 2: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

Buying Down Risk Through Better Cybersecurity

80%Best

Practices 15%Info

Sharing 5%Planning

& Incident Response

*Rule of thumb

Page 3: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

Best Practices

Top 5 Defensive Strategies:1. Multifactor Identification2. Network Segmentation3. Control Privileged Access4. Whitelist Apps5. Guard your Back Door:

Contract with Security in Mind

80%Best

Practices

Page 4: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

Information Sharing Works!

• Cyber Information Sharing and Collaboration Program (CISCP)

• Enhanced Cybersecurity Services

• Critical Infrastructure Cyber Community (C³) Voluntary Program

• U.S. Computer Emergency Readiness Team (US-CERT)

15%Info

Sharing

Page 5: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

Incident Response

National Cybersecurity & Communications Integration Center (NCCIC)

• U.S. Computer Emergency Readiness Team (US-CERT)• Industrial Control Systems Cyber Emergency Response

Team (ICS-CERT)• National Coordinating Center for Communications (NCC)• Cyber Watch

5%Planning

& Incident Response

Page 6: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

6

Tackling the Cybersecurity Issue

• 124+ Federal Departments and Agencies• Disparate missions and customers

Page 7: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

7

Tackling the Cybersecurity Issue

State, Local, Tribal, Territorial Governments

• 80,000+ entities• Unique authorities and

budgets

Page 8: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

8

Cyber Strategy Elements

1. Guard the boundary EINSTEIN

2. Manage and patrol interior lines Continuous Diagnostics and Mitigation

3. Train the workforce National Initiative for Cybersecurity Education

4. Adapt, innovate, and integrate new technology and tactics, techniques, and procedures

Page 9: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

9

Healthcare & Public Health

Information Technology

Government Facilities

Chemical

Commercial Facilities

Communications

Critical Manufacturing

Dams

Nuclear Reactors, Materials & Waste

Transportation Systems

Water & Wastewater

Systems

Defense Industrial Base

Emergency Services

Energy

Financial Services

Food & Agriculture

Linking the Private Sector

Page 10: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

10

Privacy, Civil Rights, Civil Liberties

Protecting:• Citizens• Economy• Values

Page 11: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

11

Cybersecurity is a team effort

National Cybersecurity and Communications Integration Center

National Cyber Investigative Task Force

U.S. Cyber Command

Intelligence Community

Security Coordination

Center

Defense Cyber Crime Center

National Security Agency’s Central Security Service Threat Operation Center

Page 12: GT Governors Summit Cybersecurity and Privacy_16_Presentation - Building a Secure and Resilient Organization - Brig. Gen. Greg Touhill

HomelandSecurity Office of Cybersecurity and Communications

12

• A threat to one is a threat to all

• Share information Cyber Neighborhood Watch

• Bake security into new products, organizational ethos, and agendas

A Call to Action