A Guide to Critical Infrastructure and Key Resources ...

A Guide to Critical Infrastructure and Key Resources Protection at the State, Regional, Local, Tribal, and Territorial Level

September 2008

September 2008

Table of Contents

Preface.................................................................................................................................... 1

Executive Summary............................................................................................................ 3

1. Introduction ..................................................................................................................... 3

2. Planning for CIKR Protection .......................................................................................... 4

3. Information Sharing and Protection................................................................................. 4

4. Using the Risk Management Framework to Develop a Plan........................................... 5

5. Cybersecurity Considerations ......................................................................................... 5

6. Coordinating CIKR Protection R&D Efforts ...................................................................... 5

7. Managing CIKR Protection Programs and Activities........................................................ 6

1. Introduction ..................................................................................................................... 7

1.1 Background ? The NIPP and the SSPs ........................................................................ 7

1.2 Sector Partnership Model............................................................................................ 10

1.3 Roles and Responsibilities .......................................................................................... 12

2. Planning for CIKR Protection................................................................................... 17

2.1 CIKR Protection and Grants........................................................................................ 18

2.2 The NIPP and the NRF -- Complementary Efforts ...................................................... 18

2.3 Working with CIKR Partners ....................................................................................... 19

3. Information Sharing and Protection ...................................................................... 23

3.1 Information Sharing..................................................................................................... 23

3.2 Fusion Centers............................................................................................................ 24

3.3 Information Protection ................................................................................................. 25

4. Using the Risk Management Framework to Develop a Plan ......................... 29

4.1 Introduction and Background ...................................................................................... 29

4.2 Setting Goals, Objectives, and Criteria ....................................................................... 30

4.3 Identifying Assets, Systems, and Networks ................................................................ 31

4.4 Assessing Risks .......................................................................................................... 34

4.5 Prioritizing Infrastructure ............................................................................................. 36

4.6 Developing and Implementing Protective Programs and Resiliency Strategies ......... 37

4.7 Measuring Progress .................................................................................................... 40

5. Cybersecurity Considerations ................................................................................. 43

6. Coordinating CIKR Protection R&D Efforts......................................................... 47

7. Managing CIKR Protection Programs and Activities....................................... 49

7.1 Program Management Approach ................................................................................ 49

7.2 Plan Maintenance and Update.................................................................................... 50

7.3 Annual Reporting ........................................................................................................ 50

7.4 Education, Training, and Outreach ............................................................................. 50

7.5 Implementation Plans.................................................................................................. 52

Appendix A ? Coordinating with Grant Programs ................................................... 55

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download