Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Wednesday, October 1, 2025

Safely Steering Scientific Progress on the High Seas

Modern cars are like computers on wheels. From the dashboard displays to the steering wheel and even your car keys, a complex dance of computer parts and mechanical components work together to keep you safe and on the road. Today’s maritime ships are a similar blend of machinery and software. From computers to networks and satellites, the modern ship purrs with an electronic hum, but also includes more mechanical tools like winches, cranes, engines, and bilge pumps. But the very same seamless systems that help ships run smoothly can be compromised. Like cars, ships must be protected against potential hackers and other malicious actors. 



The R/V Sally Ride, docked in Alameda, CA in 2024.


Trusted CI, the NSF Cybersecurity Center for Excellence, has been working with operators of research vessels across the United States to defend ships from cyberattacks. They have been supporting ships before construction on "secure by design" approaches as well as cybersecurity in research vessel operations. Research vessels are floating laboratories and instruments for landlocked researchers to gather information about what lies beneath the waves. The U.S. Academic Research Fleet includes 17 vessels, which are built with the finest electronics and observational instrumentation. They depend upon strict safety protocols to keep them safe.


But as Sean Peisert, the director of Trusted CI explains, “There are the experiments and equipment that are brought onboard, many of which also have digital and computing elements in them, making them potentially vulnerable to cybersecurity issues.”  The consequences of a successful cyberattack could range from loss of data in a scientific experiment to a ship being dead in the water without propulsion, with the implications ranging from loss of time and funding to dangers of the safety of those on board.




Trusted CI’s Sean Peisert prepares for an inspection of the R/V Sally Ride in 2024.


Cybersecurity for a ship isn’t easy. It’s hard enough just keeping a ship running without thinking about computers. Case in point, Trusted CI had plans to join a training cruise in 2024 that was cancelled due to weather conditions. These are the kinds of real-world issues that research vessel operators have to deal with on top of all of the computers and science equipment that makes research vessels so special and distinctive.


In 2023, Trusted CI worked with experts in maritime operational technology at Scripps Institution of Oceanography and Oregon State University to develop “The Operational Technology Procurement Vendor Matrix,” a guide to ensure protection against cyberattacks by a proactive procurement process. Additionally, Trusted CI’s staff has been involved in visiting ships to better understand just how technology operates in real-world conditions.  Most recently, Trusted CI's visits have also included observation of ship inspections, which happen at regular intervals by the National Science Foundation, the U.S. Coast Guard, and the U.S. Navy.


What happens during one of these ship inspections? Peisert says that when he visited the Office of Naval Research’s R/V Sally Ride for a National Science Foundation and US Navy / INSURV inspection, they examined the vessel’s in-port and onboard elements. The inspection of the ship involved evaluating its performance while underway, including its engines, navigation equipment, and crew procedures, and verifying that it met Coast Guard requirements for communication and navigation, including a range of traditional and modern systems. A man-overboard drill was also conducted, including communications between the ship and the recovery team. 




Trusted CI’s Dan Arnold, left, conferring with marine technicians on the R/V Sally Ride in 2023.


The inspection wasn’t just limited to computer systems; inspectors also checked the state of the vessel's physical assets. “It may be interesting to know that Coast Guard rules require not just satellite, modern GPS, and digital, topological navigation charts,” Peisert observes, “but that ships must also carry HF radios that can propagate for thousands of miles, as well as paper charts, and even a sextant for determining latitude.” Inspectors even conducted visual inspections of the ship’s overboard handling system (“A-Frame”) to check the metal for potentially corrosive rust.  


So far, the Trusted CI team has visited the Office of Naval Research’s R/V Sally Ride and Oregon State University’s Hatfield Marine Science Center in Newport, Oregon, the future home port of the R/V Taani. Team members Mike Simpson and Mikeal Jones were present for the Office of Naval Research’s R/V Thomas G. Thompson inspection in September 2024. The Trusted CI team was also involved at the RVTEC 2024 Meeting hosted by the University of New Hampshire in October 2024.


The Trusted CI team is currently preparing for upcoming collaborations with research vessel teams. Simpson and Jones will be present in October for the National Science Foundation Inspection of the R/V Atlantic Explorer in Bermuda.  Another Trusted CI team member, Ishan Abhinit will be involved in the National Science Foundation inspection of the R/V Rachel Carson this November. Finally, Mike Simpson will be involved in the National Science Foundation inspection of the Office of Naval Research’s R/V Armstrong in December 2025.


As for Trusted CI Director Peisert, he plans to join the crew of the R/V Sikulaq, operated by University of Alaska, Fairbanks, in the Spring. While on board, he plans to participate in a cyber-incident drill that will take place during the transit to exercise the crew's skills and procedures in responding to simulated cybersecurity threats while at sea. Peisert says, “Trusted CI looks forward to more of these visits going forward as it continues its ongoing support of the U.S. Academic Research Fleet to ensure that the vessels' cybersecurity programs are as robust as possible for ensuring ship safety and the progress of the ocean science being conducted on the vessels.


Stay tuned for more information about Trusted CI’s maritime activities. Want to check out the activities happening on land this fall? We are hosting a ‘birds of a feather’ session at the NSF Cybersecurity Summit and we will be presenting during Cyber Monday at RVTEC this November. 


Thursday, January 30, 2025

Trusted CI: Relaunching and Expanding the Student Program

As cybersecurity continues to grow in importance across the scientific community, the need to cultivate the next generation of cybersecurity leaders is more critical than ever. Trusted CI is proud to announce the relaunch and expansion of its Student Program, designed to provide students with very useful insights, mentorship, and hands-on experiences in cybersecurity while fostering a cybersecurity workforce for all. Applications for the 2025 cohort open on February 3, 2025.
Why the Student Program Matters
For over a decade, Trusted CI has significantly impacted the NSF community by equipping researchers and institutions with comprehensive cybersecurity knowledge and resources. Our analysis revealed opportunities to extend this impact by engaging students from a wider range of academic fields, such as those in the NSF Education and Human Resources (EHR) and Biological Sciences (BIO) Directorates, as well as reaching out to new institutions not currently engaged in cybersecurity programs. The Student Program aims to ensure that perspectives from across all disciplines and institutions contribute to shaping the future of cybersecurity.
Alumni Insights: Mentorship and Impactful Experiences in Cybersecurity


On the Mentor Program
Sandra Darkson - University of New Haven, MS in Cybersecurity and Networks
“My mentor (Carolyn Ellis) is really one of a kind; she is among those few individuals who sees the potential in me and, at the same time, believes so much in me that this belief drives me to work harder, and strive for excellence. I am so fortunate enough to have her as my guide and mentor on my path.”
On the Poster Session
Nana Sarfo Dwomoh - Sam Houston State University, MS Information Assurance & Cybersecurity
“The 2024 NSF Cybersecurity Summit was a big, unforgettable platform for me as a Cybercorp  Scholar, where I presented my poster, "Defending Electoral Integrity in the Age of Cyber Warfare,"  which gave me the chance to share my research on how digital disinformation, botnets, and deepfakes are impacting elections.”
On Networking
Konstantin Metz - University of Central Florida, MS Cybersecurity and Privacy
“The event is unlike any other in the industry! It brings together industry professionals, faculty, and students from across the globe to learn, network, and collaborate on current and emerging cybersecurity issues. It gives students an unparalleled opportunity to learn and grow while showcasing some of their own work. I am honored to have been selected to present and cannot wait for next year!”
Abigail Whittle - Oregon State University, BS in Computer Science
“I had the opportunity to meet some incredibly interesting individuals. Overall, I would highly recommend this experience to other students in the future, as it was beneficial both professionally and educationally, and I took away a lot from it.”
On Capture the Flag
Dignora Castillo-Soto - Bay Path University, MS in Cyber Security
“The CTF session provided a hands-on experience that challenged my problem-solving skills. It was refreshing to participate in a group project, as collaboration helped me gain new insights that I wouldn’t have achieved working solo.”
On Summit Courses
Owen Seltzer - Northeastern University, MS Cybersecurity
“The talks and panel discussions were not only engaging but also thought-provoking, covering topics ranging from emerging threats to innovative protection strategies. As someone still exploring career paths in cybersecurity, I found the presentations particularly enlightening.”
Goals of the Program
The Trusted CI Student Program is committed to:
  • Providing Foundational Knowledge: Selected students will gain practical insights into cybersecurity through workshops, mentorship, and participation in the annual NSF Cybersecurity Summit.
  • Fostering Community: By actively recruiting students from a wide range of backgrounds, the program aims to create a supportive environment that values a variety of perspectives.
  • Empowering Advocacy: Students will serve as cybersecurity ambassadors in their communities, equipping their peers with knowledge and connecting them with Trusted CI for more complex challenges.
  • Building Long-Term Connections: Participants will join a growing network of Trusted CI alumni, opening doors to mentorship, networking, and career opportunities in the cybersecurity field.
What’s New in the Trusted CI Student Program for 2025?
The Trusted CI Student Program continues to evolve, and we are excited to share the enhancements coming in 2025! Designed to nurture the next generation of cybersecurity researchers, this program has been refined based on past participant feedback and our commitment to providing a more impactful experience. These changes reflect our goal to improve the program from what it has been and make it more valuable for the entire Trusted CI community, not just prospective students.
Larger Cohorts Over Time
While the program currently welcomes five students annually, our goal is to expand participation to 15 students in future cycles as resources allow. This growth ensures more students benefit from Trusted CI’s expertise.
Alumni Engagement
We recognize the value of long-term connections, which is why past participants will now retain access to valuable program resources and opportunities to attend the Trusted CI Summit. This fosters an ongoing learning community and professional network.
Focused Workshops and Mentorship
Students will gain deeper insights through tailored workshops and dedicated one-on-one mentorship sessions. These sessions will be led by Trusted CI staff and esteemed industry experts, ensuring a well-rounded educational experience.
Streamlined Application Process
To provide a holistic evaluation of applicants, the revised application process will require a personal statement, a professional biosketch, and letters of support. This approach ensures we select students who are not only qualified but also deeply passionate about cybersecurity.
These enhancements are part of our commitment to continually improving the program, ensuring that both new and returning members of the Trusted CI community benefit from its evolution. We look forward to welcoming the 2025 cohort and continuing to build a thriving community of cybersecurity professionals!
What Students Can Expect
The Trusted CI Student Program will run from May to November 2025, featuring webinars and workshops twice a month to foster growth and prepare students for careers in cybersecurity.
From their first day in the program, Students will:
  • Attend workshops on cybersecurity fundamentals, career development, and emerging trends.
  • Network with top professionals and researchers at the NSF Cybersecurity Summit, an annual conference dedicated to advancing cybersecurity in research and education. This event provides a unique opportunity to learn from experts, engage in discussions on emerging cybersecurity challenges, and build valuable connections within the field.
  • Work closely with mentors who will guide their growth and help them navigate the cybersecurity landscape.
  • Share their experiences through blog posts, presentations, and outreach activities, inspiring others to explore careers in cybersecurity.
Join a Community of Innovators: Apply for the Trusted CI Student Program

The Trusted CI Student  Program is not just about equipping students with technical skills; it’s about creating a community that values collaboration, and innovation. If you are a student passionate about cybersecurity or know someone who is, we encourage you to apply and join us in shaping a safer, more secure future for science and beyond.

Applications for the 2025 cohort open on February 3, 2025. For more information on how to apply, visit Trusted CI’s website or reach out to students@trustedci.org. Let’s build a stronger cybersecurity community together!

Monday, November 6, 2023

Trusted CI members help Indiana local governments prevent cyber attacks

Trusted CI’s Craig Jackson and Ranson Ricks are leading an effort, called Cybertrack, to help local Indiana governments prevent cyber attacks. Cybertrack was initiated by the Indiana Office of Technology in partnership with cybersecurity experts from Indiana University and Purdue.

To accomplish this, they are relying on the Trusted CI Framework, which has been adopted by the state as part of its standard for local government cybersecurity. The Cybertrack team is expected to complete more than 300 assessments by 2026.

Read the full article published by Indiana University

Monday, August 1, 2022

Analysis of NSPM-33: Cybersecurity Requirements for Federally Funded Research Organizations

By: Anurag Shankar and Scott Russell

This blog post provides research organizations a summary of the National Security Presidential Memorandum on United States Government-Supported Research and Development National Security Policy” (NSPM-33) and the recent Office of Science and Technology Policy (OSTP) / National Science and Technology Council (NSTC) guidance, along with analysis of the requirements. 

Summary

In January 2021, then President Trump issued a directive “National Security Presidential Memorandum on United States Government-Supported Research and Development National Security Policy” (NSPM-33) to all federal agencies to: 1) standardize disclosure requirements and 2) mandate a research security program for all institutions receiving a total of $50 million or more in federally-funded research. In January 2022, the Office of Science and Technology Policy (OSTP) released further guidance on these requirements, including details on four elements specified in NSPM-33: cybersecurity, foreign travel security, research security training, and export control training. The cybersecurity guidance identifies 14 controls that it recommends as requirements for federal agencies to flow down to organizations receiving federal research funding. Twelve of these controls are included in the 17 “basic hygiene” controls specified by CMMC Level 1 and the 15 “minimum security controls” specified by FAR 52.204-21, “Basic Safeguarding of Covered Contractor Information Systems.” The rest are NSPM-33 specific, addressing training and ransomware/data integrity.

The OSTP guidance also includes a number of additional recommendations for federal agencies to flow down to research organizations, summarized below:

  1. Documentation: Research organizations should be required to document their research security program and provide this documentation within 30 days of a request from a research agency that is funding an award or considering an application for award funding.

  2. Certification: Research organizations should be required to provide certification of compliance with the research security program requirement. OSTP, in consultation with the NSTC Subcommittee on Research Security and OMB, plans to develop a single certification standard and process that will apply across all research agencies.

  3. Timeline: Research organizations should establish a research security program as soon as possible, but given one year from the date of issuance of the formal requirement to comply. Organizations that become subject to the requirement in subsequent years are supposed to be similarly provided one additional year to comply.

  4. Assistance: The Federal Government should provide technical assistance to support development of training content and program guidelines, tools, and best practices for research organizations to incorporate at their discretion. Agencies represented on the National Counterintelligence Task Force, in conjunction with the National Counterintelligence and Security Center, should jointly develop content that research organizations can leverage to meet requirements for research security programs and training. The Federal Government should consider supporting the formation of a community consortium to develop and maintain research security program information and implementation resources for research organizations, to include resources suitable for use within research security programs. The development of program content should be a collaborative effort between the government and organizations.

  5. Discretion: Research organizations should be provided flexibility to structure the organization’s research security program to best serve its particular needs, and to leverage existing programs and activities where relevant, provided that the organization implements all required program components. Research organizations should be given flexibility in how they choose to integrate research security requirements into existing programs, such as existing cybersecurity programs. Research organizations should be strongly encouraged to integrate some or all elements into a coherent research security program, where applicable and feasible.

  6. Funding agencies should consider integrating the research security program requirement into the Compliance Supplement’s Research and Development Cluster audit guidance as part of the single audit of Federal grant and assistance programs (2 C.F.R. Part 200, Appendix XI).

Analysis

The primary questions raised by NSPM-33 and the NTSC/OSTP guidance are 1) How will these requirements be flowed down to research organizations; 2) To what extent will funding agencies follow the guidance put forth by the NTSC; and 3) What is the scope of the requirements? 

Regarding the first question, NSPM-33 only directly impacts federal funding agencies (e.g., NSF, DOE): the NSPM does not impose any requirements directly on research institutions. Instead, it instructs federal funding agencies to impose these requirements on research institutions receiving federal research funding. While the NTSC/OSTP guidance specifies January 2023 as the deadline for eligible institutions to comply, it does not specify how the requirements should be imposed. Moreover, the provision of NSPM-33 that specifically mentions cybersecurity is only intended to apply to research institutions receiving over $50 million in federal research funding, without clarifying how these institutions should be identified.

Practically speaking, the funding agencies may impose these requirements on all *new* grants. So although existing grants are technically unaffected, research institutions that wish to continue to get funding will be forced to implement the requirements regardless. 

Moreover, it is also unclear to what extent federal funding agencies are bound by the NTSC guidance. NSPM-33 only instructs OSTP to “promulgate guidelines for research institutions to mitigate risks to research security and integrity”: it is not empowered to dictate what requirements federal funding agencies impose. Indeed, neither OSTP nor NTSC were mentioned in the subsection referencing research security programs and cybersecurity.

Scope is another issue. The guidance does not clarify whether the security program requirements apply only to researchers receiving federal funding or every researcher within the organization. It specifies controls for programs to implement but does not explicitly state if every system used by researchers (e.g, their workstations) is in scope or institutional systems only. Since this has financial repercussions, clarity is needed on what the requirements cover.

A research security program clearly requires controls to secure projects. However, prescribing a set of controls which research systems must implement can be problematic, as research systems have unique needs that may not function using traditional controls (instead requiring alternate controls to achieve their mission.) Moreover, the focus on system-centric controls is not well suited for securing research workflows, which require more than technical controls alone. The uniqueness of research systems (telescopes, sensors, microscopes, etc.) requires different approaches than controls designed to secure “systems.” For example, the Trusted CI Framework is a more appropriate fit for research programs. It includes controls, but provides the institution flexibility in choosing a baseline control set that is tailored to the institution’s mission. Additionally, this baseline control set is supplemented with additional and alternate controls that are particularly important in the research context, as research infrastructure often requires specialized protections. Securing research ultimately requires flexibility.

Applying the same level of security to all research is also unwise. How research is protected is currently scoped to data by sensitivity and regulatory requirements. This is done for a reason, namely to apply security proportionally to risk to contain cost. Expanding it indiscriminately will be wasteful and unnecessary. For instance, public data does not need the same level of security as patient data.

The guidance asks agencies to allow flexibility on which program components institutions choose to implement but also directs them to “strongly encourage” choosing them all. With a documentation submission requirement, it is unclear how the program will be judged and what the impact of a “less than perfect choice” might be (e.g., of not having all of the controls in place).

The certification requirement also is likely to present challenges. As the CMMC rollout shows, designing a certification process for compliance at this scale is extremely challenging. And whereas CMMC is limited in scope, NSPM-33 is potentially much broader. With CMMC compliance, most organizations can design isolated environments for controlled data CUI to limit scope, certifying compliance for research will be much more challenging, given the variety and complexity of research infrastructure.

Tuesday, May 24, 2022

2022 NSF Cybersecurity Summit- Call for Participation is now open- Submission deadline June 10th

We are pleased to announce that the 2022 NSF Cybersecurity Summit is taking place the week of October 17th with the training and workshops occurring on Tuesday, October 18th, and plenary sessions occurring on Wednesday, October 19th, and Thursday, October 20th. 

The final program is still evolving, but we will maintain our mission of providing a format designed to increase the NSF community’s understanding of cybersecurity strategies that strengthen trustworthy science: what data, processes, and systems are crucial to the scientific mission, what risks they face, and how to protect them. 

Call for Participation (CFP)

Program content for the Summit is driven by our community. We invite proposals for plenary presentations & workshops. The deadline for CFP submissions is July 8th. To learn more about the CFP, please visit: www.trustedci.org/2022-summit-cfp

Student Program

 To support workforce development, the Summit organizers invite several students to attend the Summit at no cost every year. Both undergraduate and graduate students may apply, and no specific major or course of study is required, as long as the student is interested in learning and applying cybersecurity innovations to scientific endeavors. To learn more about the student program, visit our website: https://www.trustedci.org/summit2022/students

On behalf of the 2022 NSF Cybersecurity Summit organizers and program committee, we welcome your participation and hope to see you in October.

More information can be found at: https://www.trustedci.org/2022-cybersecurity-summit