Featured A 'First Responder' Approach to Cybersecurity

Published on July 15th, 2021 📆 | 5233 Views ⚑


A ‘First Responder’ Approach to Cybersecurity

Powered by iSpeech

Credentialing Program First Step Toward Creating Network of Cyberattack Responders

Lessons learned by first responders' efforts to deal with natural disasters can be applied to cyberattack responses, according to organizations that have teamed up to launch a cybersecurity first responder credentialing program. The organizers see the project as the first step toward creating a network of professionals that can help the U.S. government and enterprises respond to high-impact cyberattacks.

See Also: Live Panel | Zero Trusts Given- Harnessing the Value of the Strategy

Credentialed cybersecurity first responders will use the Federal Emergency Management Agency's Incident Command System framework to communicate and coordinate responses to large-scale cyber incidents, organizers say. The FEMA framework is widely used globally by first responders for responses to hurricanes, floods, earthquakes and industrial accidents.

FEMA's framework, which will now be applied to cybersecurity, aims to help companies, organizations and municipalities identify, assess and address incidents, communicate with the right agencies and stakeholders, and resume day-to-day operations.

Those involved in launching the credentialing effort are the International Society of Automation's Global Cybersecurity Alliance; the Incident Command System for Industrial Control Systems, or ICS4ICS; the U.S. Cybersecurity and Infrastructure Security Agency and incident response teams from more than 50 companies.

The program will help identify qualified first responders who can participate in a national response to a cyberattack, such as restoring the power grid, says Megan Samford, ISAGCA advisory board chairperson and ICS4ICS leader.

This announcement follows a string of recent cyber incidents - including the REvil ransomware attack on remote management software vendor Kaseya; the Colonial Pipeline attack and the SolarWinds supply chain attack.

'An Important Milestone'

Applying FEMA's framework to cybersecurity will help ensure first responders rely on common terminology and resources and can scale to handle incidents of all sizes - including nation-state offensives or attacks on complex supply chains, backers say.

"Credentialing cybersecurity first responders is an important milestone in this valuable public-private partnership" designed to identify qualified professionals to voluntarily assist with the response to cyber incidents beyond their own enterprises, says Samford, the vice president and chief product security officer of Schneider Electric's energy management business.

The credentialing program, managed by a formal committee within ICS4ICS, involves having a panel of subject matter experts review candidates' qualifications, including formal training and proven incident response experience.

CISA will build response plan templates, formal tabletop exercises and ransomware guides that first responders can use in a crisis, Samford says.

'Mobilizing the Troops'

Because 85% of the United States' critical infrastructure is maintained by the private sector, cybersecurity pros at enterprises must play a critical role in responses to cyber incidents, she says.

"This is about mobilizing the troops," says Samford, whose background includes emergency management for the Commonwealth of Virginia. The goal, she adds, is to go far beyond today's incident response approach that "might include small groups of well-intentioned people that are [largely] unorganized."

First Four Credentialed

In addition to Samford, the inaugural round of credentialing recognized three other cybersecurity experts, who will also help vet future applicants:

  • Mark Bristow, branch chief of cyber defense coordination at CISA: His 15-year career within U.S. government cybersecurity agencies includes responses to Ukraine cyberattacks and attempts by Russian government hackers to intrude energy equities;
  • Neal Gay, senior manager of managed defense/industrial control systems at FireEye;
  • Brian Wisniewski, U.S. Army Reserve

The program is open to those who work in the public and private sectors who want to take part in a "multilateral preparedness scheme for responding to cyber incidents," backers say.

By participating in the first responder initiative, security professionals can gain a better understanding of the "common language" around incident response, Samford adds.

Those interested in the credentialing program can contact ISA Global Cybersecurity Alliance for more information.

Source link

Tagged with:

Comments are closed.