Cybersecurity Policy for Water and Electricity Infrastructures

所在平台: CourseraArchive

课程类别: 其他类别

大学或机构: CourseraNew

课程主页: https://www.coursera.org/archive/cybersecurity-policy-water-electricity

课程评论:没有评论

第一个写评论        关注课程

课程简介

University of Colorado System

课程评论(0条)

课程详情

This course will examine the drinking water and electricity infrastructures, and various policies that have been developed to help guide and strengthen their cybersecurity programs. The drinking water and electricity infrastructures are two of fourteen subsectors comprising what are known as "lifeline infrastructure". The 2013 National Infrastructure Protection Plan identifies four lifeline infrastructure sectors: 1) water, 2) energy, 3) transportation, and 4) communications. These sectors are designated "lifeline" because many other infrastructures depend upon them. The drinking water subsector is part of the water sector, and the electricity subsector is part of the energy sector. Both subsectors are overseen by the Department of Homeland Security National Protection and Programs Directorate which manages the DHS National Infrastructure Protection Program. The NIPP employs a five-step continuous improvement program called the Risk Management Framework. NIPP implementation is overseen by DHS-designated Sector-Specific Agencies staffed by various Federal departments. The Sector-Specific Agencies work in voluntary cooperation with industry representatives to apply the Risk Management Framework and document results in corresponding Sector-Specific Plans. The program began in 2007 and the most recent Sector-Specific Plans were published in 2016. In February 2013, President Obama issued Executive 13636 directing the National Institute of Standards and Technology to develop a voluntary set of recommendations for strengthening infrastructure cybersecurity measures. EO13636 also asked Federal agencies with regulating authority to make a recommendation whether the NIST Cybersecurity Framework should be made mandatory. The Environmental Protection Agency who is both the SSA and regulatory authority for the drinking water subsector recommended voluntary application of the NIST Cybersecurity Framework. The Department of Energy who is both the SSA and regulatory authority for the electricity subsector replied that it was already implementing the Electricity Subsector Cybersecurity Capability Maturity Model, which indeed was what the NIST Cybersecurity Framework was based on. The Department of Energy, though, recommended voluntary application of the ES-C2M2. This module will examine both the drinking water and electricity lifeline infrastructure subsectors, and elements and application of the NIST Cybersecurity Framework and ES-C2M2.

水和电力基础设施的网络安全政策:本课程将研究饮用水和电力基础设施以及为帮助指导和加强其网络安全计划而制定的各种政策。饮用水和电力基础设施是十四个子领域中的两个,包括所谓的“生命线基础设施”。 2013年《国家基础设施保护计划》确定了四个生命线基础设施部门:1)水,2)能源,3)运输和4)通信。这些部门被称为“生命线”,因为许多其他基础架构都依赖它们。饮用水子行业是水行业的一部分,电力子行业是能源行业的一部分。这两个子部门均由国土安全部国家保护和计划局负责管理,该局负责管理DHS国家基础设施保护计划。 NIPP采用称为风险管理框架的五步持续改进计划。 NIPP的实施由DHS指定的特定部门机构监督,这些机构由各个联邦部门负责。特定行业机构与行业代表自愿合作,以应用风险管理框架并在相应的特定行业计划中记录结果。该计划于2007年开始,最新的行业特定计划于2016年发布。2013年2月,奥巴马总统发布了13636号执行官,指示国家标准与技术研究院制定一套自愿性建议,以加强基础设施网络安全措施。 EO13636还要求具有监管权的联邦机构就是否应强制执行NIST网络安全框架提出建议。既是SSA也是饮用水子行业监管机构的环境保护署(EPA)建议自愿应用NIST网络安全框架。既是SSA还是电力子行业监管机构的能源部答复说,它已经在实施“电力子行业网络安全能力成熟度模型”,这实际上是NIST网络安全框架所基于的模型。但是,能源部建议自愿使用ES-C2M2。本模块将研究饮用水和电力生命线基础设施子行业,以及NIST网络安全框架和ES-C2M2的要素和应用。

课程标签

0人关注该课程

主题相关的课程