CISA officially kicked off Critical Infrastructure Security and Resilience (CISR) Month last week, which occurs every November. This month, CISA is continuing with its enduring theme of Resolve to be Resilient. Throughout this month, WaterISAC will share free CISA resources that water and wastewater utilities can utilize to enhance their security and resilience.
The safety and security of the nation depends on the ability of critical infrastructure owners and operators to prepare for and adapt to changing conditions and to withstand and recover rapidly from disruptions. According to CISA, as a nation, we are grappling with continued cyber and physical threats to critical infrastructure Americans rely on every day. For example, we have seen extended, record-breaking heat and destructive weather and fire events; global conflicts with ripple effects around the world; and rapid advances in technology that enable novel cybersecurity risks.
Throughout November, CISA will highlight how critical infrastructure organizations can integrate the following practices to help make critical infrastructure organizations more secure, resilient, and better able to bounce back quickly and build back stronger when disruptions occur:
- Know Your Infrastructure and Dependencies. Organizations should identify their most critical systems and assets for their operations and understand potential dependencies on other infrastructure systems and assets that enable the continuity of their own operations.
- Assess Your Risks. Consider the full range of threats and hazards that could disrupt your organization’s infrastructure operations and evaluate specific vulnerabilities and consequences the threats and hazards could pose.
- Make Actionable Plans. Organizations should develop both a strategic risk management plan to reduce the risks and vulnerabilities identified and an actionable incident response and recovery plan to help withstand and rapidly restore operations within minimal downtime.
- Measure Progress to Continuously Improve. Exercise incident response and recovery plans under realistic conditions and periodically evaluate and update strategic plans. An organization’s ability to proactively prepare for and adapt to changing risk conditions starts with fostering a culture of continuous improvement, based on lessons learned from exercises and real-world incidents.
CISA's Critical Infrastructure Security and Resilience Month Toolkit offers a number of resources to help you and your organization get involved and help reduce risk. Read more at CISA.