Resource
Developing An Effective Cybersecurity Strategy: USACE Implementation Efforts
Recognizing the need to address the risks associated with cyber systems, Dams Sector partners collaborated to develop a uni¬fied cyber and control systems security strategy in order to address the most significant issues and concerns regarding cybersecurity and control systems within the Dams Sector, including the criticality of control systems in all areas related to dam operations. The Dams Sector Roadmap to Secure Control Systems effectively describes a concise plan and provides strategic direction for voluntarily improving the cybersecurity posture of control systems within the Dams Sector, including specified goals and milestones on which to focus efforts and activities, while addressing the sector’s most urgent challenges.
An effective implementation of these concepts is represented by the corporate strategy developed by the U.S. Army Corps of Engineers (USACE) to identify short-, mid-, and long-term solutions to comply with the North American Electric Reliability Corporation (NERC) Reliability Standards. USACE has committed to a program of voluntary compliance to meet all applicable NERC reliability standards within resources and operating constraints. Major challenges include the existence of a wide variety of industrial control systems across the different USACE Divisions and Districts. These systems range from those designed and installed over 20 years ago, which are highly dependent on human interaction, to newer, more sophisticated systems. This paper describes the development of the USACE Compliance Monitoring and Enforcement Program, in collaboration with the USACE Critical Infrastructure Protection and Resilience Program, to monitor and assess current and future requirements. These efforts will identify critical compliance-related issues and propose solutions promoting cost-effectiveness. 13 pp. 8 references.