The Cybersecurity and Infrastructure Security Agency (CISA)

You will complete a final policy paper that describes and proposes solutions to a particular digital policy problem (the problem that I chose is The Cybersecurity and Infrastructure Security Agency (CISA)). Papers should be 8-12 pages, double-spaced, 12 pt font (approximately 2500-3000 words).You will complete a final policy paper that describes and proposes solutions to a particular digital policy problem. Papers should be 8-12 pages, double-spaced, 12 pt font (approximately 2500-3000 words).

This is what we discussed during the class about this topic:
The Cybersecurity and Infrastructure Security Agency (CISA)
The nation’s newest federal agency, established in 2018, attracted public attention for its role in providing assistance to secure the 2020 election against digital vote-rigging. CISA describes itself as a “non-regulatory” and “non-law-enforcement” agency. What does CISA do and is it effective?

The Cybersecurity and Infrastructure Security Agency (CISA), created through the Cybersecurity and Infrastructure Security Agency Act of 2018, leads the national effort to understand, manage, and reduce risk to American cyber and physical infrastructure. It is essential to note the following quote from CISA’s Chief Counsel, Dan Sutherland, stating the following about CISA “We are a non-regulatory, non-law enforcement, non-intelligence community.” Specifically, CISA is authorized to share information related to cybersecurity risks and incidents and provide technical assistance upon request.

Source: https://www.passwordprotectedlaw.com/2019/04/cisa-can-help-your-business/ Links to an external site.
Part 1: About CISA and its Authorities

Read CISA’s Home Page Links to an external site. to learn a bit about the general roles and responsibilities of the agency.

If you are a more visual learner, watch the following
Link Links to an external site.

(2 Minutes), which quickly covers CISA’s objectives.

Read The Cybersecurity and Infrastructure Security Agency Act of 2018 Links to an external site. (6 U.S.C. sections 651-674) (20 pages), which establishes the CISA and details its authorities, including the roles and responsibilities for each of its operating divisions.

Specifically, 6 U.S.C. 659 establishes CISA as a central player in the sharing of cyber threat information between the federal government and the private sector and authorizes CISA to provide cybersecurity technical assistance and incident-response capabilities to Federal and non-Federal entities upon request.
So, what are these critical infrastructure sectors? On February 12, 2013, President Obama released PPD-21: Crtiical Infrastructure and Resilience Links to an external site. PPD-21: Critical Infrastructure and Resilience (15 pages), establishing the 16 critical infrastructure sectors. Please read it.

Pay especially close attention to the Designated Critical Infrastructure Sectors and Sector-Specific Agencies section and think about how each sector may be involved in cyber security.

image.png

Image Source 2: Identifying Critical Infrastructure During COVID-19 | CISA

Several of these sectors interact with operational technology (OT), which, like its information technology (IT) counterpart, also has several cybersecurity vulnerabilities and risks. The high-level differences between the 2 are below:

image.png

Image Source 3: https://www.coolfiresolutions.com/blog/difference-between-it-ot/ Links to an external site.

As the digital world becomes more connected, there is an increasing amount of convergence between IT and OT assets, which poses a major security vector. For example, an attacker may compromise an IT / Enterprise network and gain access to an OT / Control network and affect OT assets that are running critical processes, such as spinning a nuclear centrifuge faster and overheating a plant. The scenario above is just one example of why critical infrastructure security is so important.

Election Security, which has gained immense attention in recent years due to misinformation campaigns and voting tampering, is also under the responsibility of CISA as critical infrastructure. Explore CISA’s Involvement in Election Security Links to an external site. to understand the services that the agency provides to bolster security posture.

Part 2: CISA’s strategic plan

Critical infrastructure has been a national security priority over the last few years. On July 28, 2021, the White House released The National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Goals Links to an external site. (3 pages) to increase American cybersecurity maturity. However, it targets only certain sectors and is very much an early stage effort to understand the critical infrastructure landscape. Note how the program is entirely voluntary and non-regulated.

On September 2, 2022, CISA released the CISA Strategic Plan 2023-2025 Links to an external site. (37 pages), the agency’s first strategic plan. If you are short on time, focus on the Strategic Plan Overview section, which focuses on four main goals:

Goal 1: Cyber Defense

Goal 2: Risk Reduction and Resilience

Goal 3: Operational Collaboration

Goal 4: Agency Unification

Part 3: Cyber Incident Reporting for Critical Infrastructure Act of 2022

Although CISA was not created as a regulatory authority, in March 2022, President Signed The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) Links to an external site., (summary) which requires CISA to develop and mandate organizations who have experienced a cyber attack to report the incident to CISA within 72 hours from the time they were reasonably attacked. The rule takes effect once CISA finalizes the regulations. The agency has been calling for the community’s opinions through listening sections to receive input on what should be included in the future regulation.

You may read the text of the legislation at Division Y of the Consolidated Appropriations Act, 2022, available here Links to an external site., 136 Stat. 1038-1059 (pages 990-1011 of the PDF). The law is 21 pages, beginning on page 990 of this more than 1000-page appropriations act, marked as page 136 Stat. 1038.

CIRCIA is in tension with the original advisory and non-authority powers designated at CISA’s inception. The law sets a precedent for CISA to implement legislation governing critical infrastructure cybersecurity.

CISA’s call for input on Creating the CIRCIA requirements (CISA press release) Links to an external site. (2 pages). CISA is asking the public to help them form CIRCIA’s reporting requirements.

Cybersecurity Mandate for the Transportation Sector (Perkins Coie news item) Links to an external site. (2 pages). It is important to note that although CISA was not regulatory before CIRCIA, they have advised other sibling agencies on pushing mandates, such as the Transportation Security Administration (TSA) security DIrectives, which mandates certain cybersecurity requirements for specific organizations – Specifically, surface transportation sector, U.S Pipeline Operators, and more recently CISA announced to extend these requirements to critical systems.

CISA’s thoughts on CIRCIA (Washington Post) Links to an external site. (5 pages). Eric Goldstein, executive assistant director for cybersecurity at CISA, expresses CISA’s thoughts on the future and not being a regulatory authority, although recognizing the major win of facilitating CIRCIA.

Week 4 Questions

For CSCI 1952X, please post your answers to the following questions in the Canvas discussions, based on this week’s readings and the recorded discussion.

For IAPA 1811 students, we will discuss these questions in class.

1. In your opinion, what is the MOST critical infrastructure sector? What would be affected if that sector wasn’t efficiently protected and experienced a cyber attack?

2. What are your thoughts on CIRCIA, given that CISA was created as a non-regulatory authority? After this initial step, should CISA enforce any other critical infrastructure requirements? If so, what should they be? If not, explain your reasoning.The Cybersecurity and Infrastructure Security Agency (CISA), created through the Cybersecurity and Infrastructure Security Agency Act of 2018, leads the national effort to understand, manage, and reduce risk to American cyber and physical infrastructure. It is essential to note the following quote from CISA’s Chief Counsel, Dan Sutherland, stating the following about CISA “We are a non-regulatory, non-law enforcement, non-intelligence community.” Specifically, CISA is authorized to share information related to cybersecurity risks and incidents and provide technical assistance upon request.

Source: https://www.passwordprotectedlaw.com/2019/04/cisa-can-help-your-business/ Links to an external site.

I Will slo need a presentation for this paper.
Please upload or embed a short video (3-5 minutes) presenting your final paper. You will receive feedback from your peers and instructor that you will then integrate into your revised paper, if you choose to do so.

After posting your video, provide feedback to two of your peers. Prioritize peers that have not yet received feedback so that everyone has an opportunity for peer feedback. Some aspects you might focus your feedback on are: clarity, accuracy of material, organization, strength of evidence, applicability, and potential gaps or counterpoints.

You can choose to record the video using a variety of tools. Some options include:

Record yourself on Zoom where you can share your screen to share any slides or visuals. You can then upload the video to the discussion board as an attachment, or upload it to your Google Drive and obtain a link to share.
Record yourself using PowerPoint. Go to Slideshow > Record slideshow in the top menu. You can then go to File > Export and choose a MP4 or mov file. This may take a few minutes. You can then attach the file to your discussion board post.Please upload or embed a short video (3-5 minutes) presenting your final paper. You will receive feedback from your peers and instructor that you will then integrate into your revised paper, if you choose to do so.

Last Completed Projects

topic title academic level Writer delivered