Gemini Observatory and CTSC have wrapped up an intensive engagement that both trudged through the trenches of policy development and literally took CTSC personnel to new heights. In the late Fall and early Winter of 2015/2016, CTSC and Gemini executed an engagement plan focused on core policy processes and documentation, as well as a close unified look at ICS/SCADA, technical, and physical controls at Gemini North.
The engagement’s policy work focused on initiating a draft Policy Development Protocol, and updating Gemini’s core policy documentation (e.g., beginning a Master Information Security Policy and revising Gemini’s AUP). CTSC gave feedback on existing documentation, advice on the policy development lifecycle, and guidance on how best to utilize CTSC’s policy templates. Gemini developed a priority list and timeline for the development/revision and implementation of these and additional policies.
Gemini’s openness and commitment to this engagement made this a huge learning experience for CTSC. We were able to closely observe how a facility can effectively incorporate security initiatives into long term project management processes. The site visit enabled fact gathering at a level of detail that allowed CTSC to produce one of its most specific, tailored reports to date. We’ve learned a great deal from all our Large Facility engagements; this was a truly special hand’s on, collaborative experience.
The CTSC team deeply appreciates the time and effort Tim Minick and Chris Morrison dedicated to this engagement, as well as the welcoming and forthcoming attitudes of all the Gemini staffers who met with our team at Gemini North.