disaster recovery coordinators’ meeting

23
1 August 18, 2010 Disaster Recovery Coordinators’ Meeting

Upload: derica

Post on 09-Feb-2016

26 views

Category:

Documents


1 download

DESCRIPTION

August 18, 2010. Disaster Recovery Coordinators’ Meeting. Welcome. Meeting Agenda. OIS Management Changes. Disaster Recovery Plan Reviews An Update. California Cyber Incident Response Plan. Cyber Exercises. California Cyber Exercise August 12, 2010. Cyber Exercises. CyberStorm III. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Disaster Recovery Coordinators’ Meeting

1

August 18, 2010

Disaster Recovery Coordinators’ Meeting

Page 3: Disaster Recovery Coordinators’ Meeting

Meeting Agenda

----- Topics -----

Topics: Welcome OIS Management Changes DRP Reviews California Cyber Incident Response Plan Cyber Exercises – CCSMM & Cyber Storm III Legislation 2010 Federal Grants Enterprise BIA: Critical IT Infrastructure Enterprise Information Security Awareness Web App Public Scorecard The Future

70 minutes

Q&A and Closing 20 minutes

Page 5: Disaster Recovery Coordinators’ Meeting

5

Disaster Recovery Plan Reviews An Update

Page 6: Disaster Recovery Coordinators’ Meeting

6

California Cyber Incident Response Plan

Page 7: Disaster Recovery Coordinators’ Meeting

7

Cyber Exercises

California Cyber Exercise

August 12, 2010

Page 8: Disaster Recovery Coordinators’ Meeting

8

Cyber Exercises

“The last major cybersecurity exercise conducted by DHS was held in 2008. Cyberstorm III is slated to include a number of international computer emergency readiness teams (CERTS), including representatives from Australia, New Zealand, Canada and the United Kingdom.

Previous Cyberstorm exercises focused on attacks attempting to take down the Internet or spread malicious software on high priority government systems. Cyberstorm III is expected to test the processes and roles in place while simulating a cyberattack against the underlying control systems of country's critical infrastructure – power grids, dams and systems that protect energy facilities.”

-- 15 Jun 2010 | SearchSecurity.com

CyberStorm III

Page 9: Disaster Recovery Coordinators’ Meeting

9

Legislation

Page 10: Disaster Recovery Coordinators’ Meeting

10

Pending LegislationAB 1899

• Transparency.

• State agencies to post specific audit information.

• OCIO and DGS to post specific summary information regarding contracts awarded to the state.

• Governor's Office to post specific financial information.

Page 11: Disaster Recovery Coordinators’ Meeting

11

Pending LegislationAB 2091

• Public Records Act (PRA) exemption.

• Information Security records that would reveal vulnerabilities or would increase the potential for an attack on an information system.

• Although AB 2091 does limit the public’s right of access, it is a very limited and targeted exemption.

Page 12: Disaster Recovery Coordinators’ Meeting

12

Pending LegislationAB 2408

• Governor’s Reorganization Plan clean-up bill

• Codifies Executive Order S-10-03

• Name change – OCIO to California Technology Agency

• Extends the OCIO’s sunset set date from 2013 to 2015

Page 13: Disaster Recovery Coordinators’ Meeting

13

Pending LegislationAB 1055

• State Chief Information Officer - fingerprints and criminal history checks.

• OCIO employees and contractors that have access to sensitive or confidential information.

• Conviction of crimes related to dishonesty, fraud, or deceit and is substantially related to the duties of the person.

• There is an appeals process.

Page 14: Disaster Recovery Coordinators’ Meeting

14

2010 Federal Grants

OIS Grant Requests

• Threat Vulnerability Management Program

• Enterprise Vulnerability Assessment Service

• Statewide PCI Compliance

• CA Information Sharing and Analysis Center

• State and Local Government Training

• Content Learning Management System

Page 15: Disaster Recovery Coordinators’ Meeting

15

2010 Federal Grants

Page 16: Disaster Recovery Coordinators’ Meeting

16

Enterprise Information Security Awareness Web Application

Page 17: Disaster Recovery Coordinators’ Meeting

17

Public Scorecard

Page 18: Disaster Recovery Coordinators’ Meeting

18

Public Scorecard

http://www.cio.ca.gov/OIS/Government/activities_schedule.asp

Page 19: Disaster Recovery Coordinators’ Meeting

19

Public Scorecard

• There will be no surprises. You and your management will be fully aware of the scores before publication.

• First Scorecard will be published on our website in late August or early September 2010.

Page 20: Disaster Recovery Coordinators’ Meeting

20

National Preparedness Month

September is National Preparedness Month

www.Ready.gov

Page 21: Disaster Recovery Coordinators’ Meeting

21

National Preparedness Month

FEMA Urges You to Take Part in National Preparedness Month This September, organizations and citizens from across the nation will come together for the seventh annual National Preparedness Month (NPM), designed to encourage Americans to prepare for emergencies in their homes, businesses, and communities.  FEMA’s Ready Campaign is asking organizations to take part by joining the National Preparedness Month Coalition, committing simply to inform members, employees, and customers about the importance of being prepared for emergencies, large and small. Registering for the Coalition is easy – visit http://ready.adcouncil.org/. Coalition members will be listed on the NPM Web site and receive a toolkit with templates, tools and ideas. For more information about NPM, visit: www.Ready.gov.

Sample of National Preparedness Month Educational Tools Available ·         Website Widgets http://www.fema.gov/help/widgets o   Ready campaign Widget: inform how to get a kit, make a plan and be informed. o   National Preparedness Month widget. ·         Popular Links & Downloadable Materials o   Ready Campaign: www.ready.gov (English) and www.listo.gov (Español) o   Get an emergency supply kit: http://www.ready.gov/america/getakit/index.html o   Family emergency plan: http://www.ready.gov/america/makeaplan/index.html o   Emergency supply kit list: http://www.ready.gov/america/getakit/kit-print.html ·         Newsletters /Articles o   E-mail for Employees, Members and Stakeholders. o   Newsletter /Web Site Article/ Blog Entry for a General Audience o   Newsletter/ Web site Article/ Blog Entry for Business Owners/ Managers Audience ·         Bill Stuffers ·         Instructional Videos ·         Public Service Announcements ·         Materials ·         Poster

Page 22: Disaster Recovery Coordinators’ Meeting

22

Future Policies

• Security Reporting Scorecard Policy Letter

• Infrastructure Consolidation Scorecard (Done)

• Use of SmartPhones

• Cloud Computing

• Privacy

• Power Management PL (Done)

• Accessibility PL (Done)

Page 23: Disaster Recovery Coordinators’ Meeting

23

Questions