Showing posts with label large facilities. Show all posts
Showing posts with label large facilities. Show all posts

Wednesday, February 7, 2024

Advancing the Cybersecurity of NSF Major Facilities and National Research Cyberinfrastructure: Trusted CI’s Framework Cohort Achievements in 2023


Trusted CI successfully conducted two more six-month engagements in its ongoing Cybersecurity Framework Cohort Program during 2023, mentoring 11 additional research cyberinfrastructure providers through Framework validated self-assessments and cybersecurity program strategic planning. The cohort during the first half of 2023 comprised representatives from the following NSF major facilities, mid-scale projects, and a scientific consortium:

U.S. Academic Research Fleet (ARF), an NSF major facility
IceCube Neutrino Observatory, an NSF major facility
United States Antarctic Program (USAP), an NSF major facility
Deep Soil Ecotron (DSE), an NSF mid-scale project
Network for Advanced NMR (NAN), an NSF mid-scale project
Giant Magellan Telescope Observatory Corporation (GMTO), a scientific consortium

Five of NSF’s leading high performance computing (HPC) centers composed the cohort during the second half of 2023:

The foundation of the cohort program is the Trusted CI Framework. The Framework was created as a minimum standard for cybersecurity programs. In contrast to cybersecurity guidance focused narrowly on cybersecurity controls, the Trusted CI Framework provides a more holistic and mission-focused standard for managing cybersecurity. For these organizations, the cohort was their first formal training in the Trusted CI Framework “Pillars” and “Musts” and how to apply these fundamental principles to assess their cybersecurity programs.

Cohort members entered the engagement with a commitment to adopting the Framework at their sites. They then worked closely with Trusted CI to gather site information and create validated self-assessments of their organization’s cybersecurity programs based on the Trusted CI Framework. Each site emerged from the program with a draft Cybersecurity Program Strategic Plan (CPSP) identifying priorities and directions for further refining their cybersecurity programs.

Several participants provided feedback on the value of the cohort experience to their organizations.

GMTO’s Sam Chan, IT Director and Information Security Officer, and Efren Sandoval, Cybersecurity Analyst, noted that “...the cohort collaboration process has given us a better understanding of a holistic and mission focused approach to cybersecurity. The cohort collaboration process also brought us together with colleagues from different fields and requirements with similar security controls.  Sharing our experiences amongst ourselves helped us learn different approaches to similar areas of concern.”

Michael Wilson, Infrastructure Architect at UConn Health and Cybersecurity Lead of NAN, observed: “As a result of the cohort experience, NAN was not only able to identify gaps in our original cybersecurity implementation plan and significantly advance our cybersecurity posture, but I have also personally expanded my professional network to share and discuss cybersecurity implementation ideas and lessons learned with colleagues from other NSF facilities. While the cohort program demands considerable effort, the NAN executive team found it to be a worthwhile endeavor. I heartily encourage the leadership of NSF facilities that have not yet participated in the cohort training to do so.”

Scott Sakai, Security Analyst at SDSC, found that: “Trusted CI’s Framework cohort provided a supportive environment to explore the strengths and weaknesses of the state of our cybersecurity efforts in the context of the Trusted CI Framework.  While strengths were praised, shortcomings and challenges were met with non-judgmental, matter-of-fact discussion rather than punitive shaming: a response that promotes a path to resolution and understanding.”

Mr. Sakai also noted that: “Importantly, the Trusted CI Framework, and guidance from the Trusted CI cohort team emphasize the significance of governance and mission alignment – two foundational concepts that bring together cybersecurity and leadership, and help formulate what a meaningful dialog between the two might look like. This sets it apart from other approaches to a security program that focus on policy and controls, a difference that will hopefully foster an asset that is approachable and predictable instead of a mysterious line-item expense in the budget.”

In January 2024 Trusted CI began the fifth Framework cohort engagement, whose members include:  

Trusted CI is excited to be working with these new sites to advance their understanding and implementation of cybersecurity programs and best practices!

For more information, please contact us at info@trustedci.org.


Wednesday, February 15, 2023

Advancing the Cybersecurity of NSF Major Facilities and National Research Cyberinfrastructure: Trusted CI’s Framework Cohort Achievements in 2022


Trusted CI’s second Framework Cohort, “Bravo”, successfully completed the six-month program of training and workshop engagement focused on learning and applying the Trusted CI Framework. Cohort members entered the engagement with a commitment to adopting the Framework at their sites. They then worked closely with Trusted CI to gather site information and create validated self-assessments of their facility’s cybersecurity programs based on the Framework. In addition, each site emerged with a draft Cybersecurity Program Strategic Plan (CPSP) identifying priorities and directions for further refining their cybersecurity programs. Bravo cohort included the following NSF Major Facilities (MFs) and research cyberinfrastructure providers:

The foundation of the cohort program is the Trusted CI Framework. The Framework was created as a minimum standard for cybersecurity programs. In contrast to cybersecurity guidance focused narrowly on cybersecurity controls, the Trusted CI Framework provides a more holistic and mission-focused standard for managing cybersecurity. For these organizations, the cohort was their first formal training in the Trusted CI Framework “Pillars” and “Musts” and how to apply these fundamental principles to assess their cybersecurity programs.

Concurrent with leading Bravo, Trusted CI continued engagement with the inaugural “Alpha” cohort through the end of 2022. Alpha cohort followed up on the success of the first half of the year by focusing on implementation challenges each cohort member was currently facing. Each of the monthly workshops was led by a different cohort member, with the workshop focused on addressing a specific cybersecurity challenge that the facility was facing. The Trusted CI Framework team is exploring ideas to continue the productive engagement with the cohort alumni.

In January 2023 Trusted CI began a third Framework cohort engagement (“Charlie”). Charlie cohort includes the following organizations:

Trusted CI is excited to be working with these new sites to advance their understanding and implementation of cybersecurity programs and best practices!

For more information, please contact us at info@trustedci.org.


Friday, September 30, 2022

Trusted CI at 2022 NSF Research Infrastructure Workshop in Boulder

Earlier this month, members of Trusted CI presented a workshop at the NSF 2022 Research Infrastructure Workshop in Boulder, Colorado. 

The Research Infrastructure Workshop was a four-day event on safety, cyberinfrastructure, cybersecurity, and science communication. The hybrid event included a poster session, social gatherings, site tours of NCAR’s Research Aviation Facility, GAGE, and NEON, and virtual ice breaker and speed dating sessions to facilitate networking opportunities for everyone. Several members of Trusted CI attended the multi-day event, making new connections with operational and senior leadership at major facilities, midscale facilities, and the NSF.

Our workshop on Friday targeted cyber security officers and focused on the JASON advisory report on Cybersecurity at NSF Major Facilities, cybersecurity guidelines in the Research Infrastructure Guide (RIG), a panel on building a cybersecurity program using the Trusted CI Framework, ransomware, and how the ResearchSOC supports NSF major facilities.

Representatives from the NSF, NRAO, OOI, GAGE, and the ResearchSOC presented and participated during the workshop. We thank Craig Risien (OOI), Wade Craig (NRAO), and Doug Ertz (GAGE) for participating in the Framework panel.

Trusted CI’s partner, CI Compass, led a cyberinfrastructure workshop earlier in the day that included panels on data management and workforce development.

We are grateful to the event organizers for giving us the opportunity to present, as well as meeting with our community members, both online and in-person.

Slides and videos from the event will be posted to the NSF Research Infrastructure Knowledge Sharing Gateway when they become available.


Trusted CI's Jim Basney and NSF's Jim Ulvestad
NSF's Robert Beverly
Trusted CI's Scott Russell
Framework panel

Trusted CI's Ryan Kiser
ResearchSOC's Susan Sons


Tuesday, July 26, 2022

Advancing the Cybersecurity of NSF Major Facilities: Trusted CI’s Inaugural Framework Cohort Successfully Completes Six-Month Program (June 2022)

Trusted CI’s first Framework Cohort has successfully completed its initial six-month period of workshops designed to improve NSF Major Facilities’ alignment to the Trusted CI Framework. Each cohort member adopted the Trusted CI Framework as the foundation for their cybersecurity program. Additionally, each cohort member worked closely with Trusted CI to produce 1) a validated self-assessment of their cybersecurity program’s alignment with the Trusted CI Framework; and 2) a draft Cybersecurity Program Strategic Plan identifying priorities and directions for further refining their cybersecurity programs.

The inaugural Cohort included the following NSF Major Facilities:

The success of the Framework Cohort is particularly notable as each of these facilities voluntarily adopted and rallied around the Trusted CI Framework as the foundation for their cybersecurity programs. 

The foundation of the Cohort program is the Trusted CI Framework, which was created as a minimum standard for cybersecurity programs. In contrast to cybersecurity guidance focused narrowly on cybersecurity controls, the Trusted CI Framework provides a more holistic and mission-focused standard for managing cybersecurity.

For GAGE, LIGO, NRAO, NSO, and OOI, the Cohort was their first formal training in the Trusted CI Framework’s “Pillars” and “Musts” and how to apply these fundamental principles to assess and strengthen their cybersecurity programs. NOIRLab contributed their experience as an early adopter of the Framework, having previously completed a one-on-one Framework engagement with Trusted CI.

Feedback from members of the first cohort on their experience has been strongly positive:

Eric Cross, Head of Information Technology, National Solar Observatory, said the following about his experience:

"The TrustedCI Framework Cohort was a valuable experience. The process required us to research and reflect on our internal cybersecurity policies and procedures. The Cohort provided a platform to meet with other facilities and work through challenges with feedback from peers. The experience resulted in formal documentation that provided our organization's leadership clear direction to improve our cybersecurity program with specific short-term and long-term goals. I highly recommend this exercise for all NSF facilities."

Craig Risien, CI Systems Project Manager, Ocean Observatories Initiative, said the following about his experience: 

“I found participating in Trusted CI’s first Framework Cohort to be exceptionally instructive and really enjoyed the opportunities to discuss cybersecurity challenges and lessons learned with Trusted CI and colleagues at other NSF Major Facilities. Working with Trusted CI on creating a validated self-assessment based on the Trusted CI Framework over the past six months has helped the Ocean Observatories Initiative (OOI) better understand the current state of its cybersecurity program. Being part of this cohort has also assisted the OOI with the development of a plan to fully implement the Trusted CI Framework and create a well-established and mature cybersecurity program. I look forward to the follow-on cohort sessions in the coming months.”

Trusted CI is continuing to support the first cohort through the end of 2022 by facilitating monthly workshops. Each facility will have the opportunity to lead a workshop in which they are encouraged to share their specific challenges and seek advice among the other cohort members.

Concurrently, Trusted CI is conducting its second cohort engagement leveraging the lessons learned from the first cohort. The second cohort includes the following organizations:

Trusted CI is excited to be working with these new facilities to advance their understanding and implementation of cybersecurity programs and best practices!

For more information, please contact us at info@trustedci.org.


Thursday, May 5, 2022

Call for Trusted CI Framework Cohort Participation

 

The Framework Cohort is a six month, group engagement aimed at facilitating adoption and implementation of the Trusted CI Framework among NSF Major Facilities. During the engagement, members of the cohort will work closely with Trusted CI to adopt the Trusted CI  Framework at their facility, emerging with a validated assessment of their cybersecurity program and a strategic plan detailing their path to fully implement each Framework Must.Cohort members will participate in six monthly workshops (each three hours) and spend no more than eight hours each month outside of the workshops on cohort assignments. The second cohort will meet from July to December 2022.

 Since January 2022, Trusted CI has been working with six Major Facilities in the inaugural Framework cohort: GAGE, LIGO, NOIRLab, NRAO, NSO and OOI. As this inaugural Framework cohort approaches completion in June 2022, Trusted CI is looking for Major Facilities that are interested in participating in the upcoming second cohort.

 NSF Major Facilities interested in participating in the Framework cohort should respond to the call by completing the form at the bottom of this page: https://www.trustedci.org/trusted-ci-framework-cohort-participation

If you have any questions, please contact us at info@trustedci.org.


Wednesday, March 9, 2022

Trusted CI Applauds JASON Report on Facilities Cybersecurity

In 2021, the NSF "commissioned a study by the JASON advisory group to assess and make recommendations regarding cybersecurity at NSF’s major facilities.” In December, NSF publicly released the seven recommendations from the JASON group and NSF’s response to those recommendations. Given Trusted CI’s role over the past 10 years in providing leadership and guidance to NSF Major Facilities, we welcomed the opportunity to contribute to the JASON group’s study and the dialogue it spurred. The following text consists of each of the JASON group’s recommendations, followed by the response from NSF, and Trusted CI’s response, which is the unique contribution of this document. We provide our responses to help the community understand how Trusted CI can help them as they consider these recommendations and their impact within their own projects.

  1. JASON recommendation: “NSF should maintain its current approach of supporting major facilities to enhance cybersecurity through assessments of risk, and development and implementation of mitigation plans. A prescriptive approach to cybersecurity should be avoided because it would be a poor fit to the diversity of facilities, would inefficiently use resources, and would not evolve quickly enough to keep up with changing threats.” NSF response: “NSF intends to maintain its current philosophy of performing oversight of awardee plans that are tailored to the unique natures of the individual major facilities. Through its review processes, NSF will ensure that these plans are consistent with best practices for cybersecurity that are in common between major research facilities and other types of infrastructure.”
Trusted CI response: Trusted CI will continue helping the NSF community develop and improve their cybersecurity plans which capture and prioritize best practices. Trusted CI will continue training and advising Major Facilities as they mature their cybersecurity programs and develop prioritized, mission-sensitive plans. We are available to support NSF reviews in any way that serves the community. We encourage expansion of NSF’s current approach and the inclusion of Trusted CI in the process of establishing generalized best practices for Major Facilities. We recommend those best practices align closely or equate to the Trusted CI Framework. NSF also recently released a new version of the Research Infrastructure Guide (formerly the Major Facilities Guide). Section 6.3 (Guidelines for Cybersecurity of NSF’s Major Facilities) has been significantly updated to align and refer to the Framework.

2. JASON recommendation: “An executive position for cybersecurity strategy and coordination for major facilities should be created at NSF. This executive should have authorities that allow them to continually support the balancing of cybersecurity, scientific progress, and cost in the distinct ways that will be appropriate for each facility.” 

NSF response: “NSF notes and agrees with the emphasis on such a position on strategy and coordination. NSF will explore different options for initiating the position and plans to create such a position within the next six months."

Trusted CI response: We strongly endorse this foundational recommendation and we look forward to collaborating with the new executive to fulfill our aligned missions. In Trusted CI’s experience, cybersecurity frequently proves ineffective or counterproductive when cybersecurity leadership lacks an understanding of the organization’s mission. An executive at NSF with expertise in both cybersecurity and the research mission would bring valuable additional perspective and leadership to NSF.

3. JASON recommendation: “Using annual reporting and review processes, NSF should ensure major facilities implement robust cybersecurity programs that remain consistent with current best practice.” 

NSF response: “NSF plans to review the elements of a good facility cybersecurity program, currently described in Section 6.3 of the NSF Major Facilities Guide, to ensure that this section is up to date. NSF will add cybersecurity as a required element of annual reports and program plans and conduct any additional specialized reviews based on perceived risk.”

Trusted CI response: Trusted CI helps facilities develop cybersecurity programs that help ensure productive, trustworthy science. The Trusted CI Framework is a tool to help organizations establish and refine their cybersecurity programs. In March 2021, we released the Framework Implementation Guide for Research Cyberinfrastructure Operators, which contains detailed guidance that can help major facilities implement effective cybersecurity programs and thereby addresses Section 6.3 of the Research Infrastructure Guide.

4. JASON recommendation: “NSF should develop a procedure for response to major cybersecurity incidents at its major research facilities, encompassing public relations, coordination mechanisms, and a pre-ordained chain of authority for emergency decisions. Each major facility should also have their own response plan that is both specific to its needs and consistent with NSF's plan.” 

NSF response: “NSF has charged a working group to develop a more robust response plan that integrates with both the agency's overall crisis communications plan and the response plans at the individual major facilities.”

Trusted CI response: Through our ongoing engagement activities with NSF Major Facilities and our mission "to lead in the development of an NSF Cybersecurity Ecosystem," we are uniquely positioned to provide guidance to this working group. During the past decade, we have built our understanding of cybersecurity challenges faced by the Major Facilities by hosting the annual Cybersecurity Summit, establishing and facilitating monthly meetings of the Large Facilities Security Team, and conducting 13 direct one-on-one engagements with the 10 of the Major Facilities. We look forward to bringing that experience, along with our ever-increasing understanding of the threat landscape faced by research facilities, to a productive collaboration with the working group and the executive identified in recommendation #2.

5. JASON recommendation: “NSF and the major facilities must be adequately resourced for their cyberinfrastructure and cybersecurity needs. What is appropriate will depend on each facility's unique characteristics and specific needs. The cybersecurity budget should be commensurate with perceived risk of an event, which may be unrelated to the cost of constructing or operating the facility.” 

NSF response: “NSF will work with each awardee to develop a cybersecurity risk register for each major facility and will then integrate those risk registers in order to determine the highest NSF risks and implement any needed mitigations.”

Trusted CI response: We agree with the JASON group’s assertion that Major Facilities must be adequately resourced for their cybersecurity needs. Cybersecurity spending is a necessary focus area in the expanding dialogue among Major Facilities, NSF, and other relevant stakeholders. Adequate resourcing to address unacceptable cybersecurity risk is precisely the subject of the Trusted CI Framework’s Must 11. Cybersecurity risk registers may be a helpful tool assessing whether cybersecurity spending is commensurate with the threats posed by unmitigated risk. However, the need for the allocation of cybersecurity resources is fundamental.

6. JASON recommendation: “NSF should refine facility proposal and design review processes to ensure that new major facilities plan cybersecurity as an integral part of the information technology infrastructure. NSF should regularly review the cybersecurity plans and efforts of both new and existing major facilities. Shifts to cloud-based cyberinfrastructure and to a wider range of partners will impact cybersecurity planning and need to be considered at proposal time.” 

NSF response: “NSF believes that the cybersecurity review process at the time of awards should be risk-based. NSF will work to ensure that cybersecurity is a specified element and review criterion of each call for proposals in a major facility competition. For a renewal proposal, NSF will include a requirement for submission of a cybersecurity plan. For a new construction award, or a project in the Design Stage, the cybersecurity plan will be required to be integrated with the Project Execution Plan. NSF will assure that appropriate expertise is present on review panels to assess the adequacy of the cybersecurity plan.”

Trusted CI response: We support the recommendation to require cybersecurity planning as part of facility proposal and design and would extend that recommendation to include the construction phase as well. For renewal proposals, we recommend expanding the requirement such that facilities must submit evidence of an active cybersecurity program (not just a plan). Trusted CI’s guidance provides facilities with the means to both plan and assess their programs. Prioritized, mission-based cybersecurity planning is central to the Trusted CI Framework, and we have demonstrated experience supporting NSF Major Facilities with cybersecurity strategic planning, through activities like the LFST, regular engagements, the NSF Summit and our 2022 Framework cohort.

7. JASON recommendation: “NSF should remain aware of national security concerns regarding its facilities and continue to facilitate coordination with appropriate agencies.” 

NSF response: “NSF will conduct an assessment of national security concerns that may be associated with its major research facilities.”

Trusted CI response: Several members of the Trusted CI team have experience working at the intersection of cybersecurity and national security, and we are happy to be a resource to facilities in this area. Trusted CI has a long and successful history providing tailored, actionable guidance and expertise to NSF Major Facilities. The JASON working group’s recommendations are a strong endorsement of NSF’s direction, Trusted CI’s contribution, and if followed, represent a step forward in ensuring the security of our nation’s science. Collaborating with NSF and Major Facilities to enable trustworthy science is central to Trusted CI’s mission.

Friday, January 28, 2022

NOIRLab Engagement Focuses on Framework Adoption, Assessment, and Strategic Planning

Over the course of 2021, Trusted CI and NOIRLab (NSF Major Facility) collaborated on an engagement to assist NOIRLab in formally adopting and aligning to the Trusted CI Framework. NOIRLab is the preeminent US national center for ground-based, nighttime optical and infrared astronomy. 

In the first half of 2021, Trusted CI conducted an assessment of NOIRLab’s cybersecurity program using the Trusted CI Framework. The assessment culminated in the delivery of an Assessment Report [1] describing NOIRLab’s cybersecurity program and recommendations to improve. The report also included an “implementation rating” for each of the 16 Trusted CI Framework Musts. 

In the second half of 2021, NOIRLab and Trusted CI continued the engagement with a series of monthly workshops designed to aid NOIRLab in implementing the highest priority recommendations from the Assessment Report. These workshops allowed Trusted CI to continue to provide input and guidance while NOIRLab tackled the most pressing changes needed to its cybersecurity program.  

Engagement Outcomes

  • NOIRLab is among the first Major Facilities to formally adopt the Trusted CI Framework. NOIRLab’s adoption is formalized in policy.
  • NOIRLab received an Assessment Report detailing Strengths and Opportunities, Challenges and Barriers, and discrete recommendations to improve their cybersecurity program.
  • NOIRLab developed an updated Master Information Security Policy and Procedures document, aligning with Trusted CI’s updated template.
  • NOIRLab adopted and began using the CIS Controls as its baseline control set.
  • NOIRLab developed a Cybersecurity Program Strategic Plan (CPSP). The CPSP described NOIRLab’s mission, how NOIRLab’s cybersecurity program supports its mission, a cybersecurity strategy, and a timeline detailing the strategic outcomes the cybersecurity program will plan to achieve over the next three years. 
  • NORILab’s strategic planning efforts dramatically helped Trusted CI refine its cybersecurity strategic planning approach and will lead to updates to the CPSP template.
  • The success of the monthly workshops led to the development of a new Trusted CI “cohort” engagement approach to support scaling Framework adoption and implementation.

John Maclean, the Director of Center Operations Services for NOIRLab, said the following of the engagement:

“Trusted CI has given us a Framework, appropriate to our environment, with which to build our cybersecurity program. It allows us to do this in a manner that balances scientific productivity against organizational risk in a cost effective manner.”

Chris Morrison, the engagement lead for NOIRLab, said the following of the engagement:

“As we continue to merge technologies and processes throughout our constituent programs, the Framework assessment helped us focus our cybersecurity effort and think strategically. The programmatic focus on the initiatives is helping us make cybersecurity visible and understandable across the organization. The follow-on activities will unquestionably support this systematic deployment and facilitate communication and decision-making with NOIRLab’s senior leadership. We are incredibly pleased with the process and outcome of the engagement with Trusted CI, and we now have a clear and prioritized path forward.”


[1] This assessment was based on the PACT cybersecurity assessment methodology. PACT was developed by the Center for Applied Cybersecurity Research in collaboration with the US Navy. For more information about PACT, see https://cacr.iu.edu/pact/index.html. 


Wednesday, January 26, 2022

Trusted CI Launches “Operation Framework Cohort” to Accelerate Framework Adoption Across NSF

During the first half of 2022, Trusted CI is engaging with NSF Major Facilities by supporting a newly-established cohort that has committed to adopting and implementing [1] the Trusted CI Framework. Members of the cohort will work closely with Trusted CI staff through a series of workshops enabling Framework adoption. The outcome at the end of the engagement period will be for each cohort member to have adopted the Trusted CI Framework and to emerge possessing a validated assessment of their cybersecurity program along with a strategic plan detailing their path to fully implement each Framework Must. 

The cohort pilot officially begins in January 2022 and will include the following NSF Major Facilities:

The Trusted CI Framework is a resource to help organizations establish and refine their cybersecurity programs. It is the product of Trusted CI’s many years of accumulated experience conducting cybersecurity research, training, assessments, consultations, and collaborating closely with the research community. In March 2021 Trusted CI published the Trusted CI Framework Implementation Guide (FIG) for Research Cyberinfrastructure Operators as the standard for cybersecurity programs among NSF funded organizations. Publishing the FIG represented a major step forward in advancing Trusted CI’s mission to enable trustworthy science through cybersecurity guidance, templates, and tools, empowering those projects to focus on their science endeavors.

Now that the FIG has been published, Trusted CI’s aim is to help facilitate Framework adoption and implementation across the broader NSF community. To fully realize the cybersecurity benefits provided by Framework implementation, community adoption must be facilitated at a much faster pace than is possible through the traditional one-on-one engagements undertaken by Trusted CI. To address this challenge, Trusted CI launched the “cohort” approach, where representatives from multiple NSF Major Facilities will participate in a group engagement with Trusted CI focused on adoption and implementation of the Framework. 

Trusted CI anticipates the cohort project will span from CY2021 to CY2024 to reach the 25-30 NSF Major Facilities and other NSF research programs targeted for this effort. Trusted CI leadership will discuss the timing and plans for future cohorts in early spring based on the progress and success of this pilot. As Trusted CI gains experience from this initial Framework Cohort, we will keep the community informed of upcoming plans and opportunities for additional facilitated Framework adoption. 


[1]  “Adoption” refers to an organizational commitment to use the Framework as the foundation for its cybersecurity program, and to make the Musts a strategic priority. Adoption is designed to be a low bar, and does not require any implementation. “Implementation” refers to bringing all Musts to (at least) a minimum level of competence. This is a longer term goal.

 




Monday, January 10, 2022

Trusted CI Tackling Major Facilities' Cybersecurity and Ransomware in 2022

Last year brought great progress and success for Trusted CI, including the March release of the Trusted CI Framework Implementation Guide for Research Cyberinfrastructure Operators. At the same time we observed an increase in the risk of ransomware on the research community

As we enter 2022, we are looking forward to building on Trusted CI’s progress and momentum to address the increasing threats to the NSF research community. We are kicking off the year with new initiatives which will provide additional support, consultation and guidance to NSF Major Facilities. Announced during the 2021 Summit, we are piloting a Framework cohort, which will accelerate Major Facility adoption of the Framework via a group engagement approach. The cohort kicks off this month with the first in the workshop series and the following facilities participating:

In addition to the Framework cohort, we are establishing the Trusted CI Major Facilities Ambassadors program. This program seeks to provide direct support to NSF Major Facilities by helping them to establish, evaluate, implement and evolve their cybersecurity programs using the Framework. Each Major Facility will have an assigned Ambassador whose role it is to develop an understanding of the facility’s activities, cybersecurity program, and unique challenges to enable them to provide tailored support and guidance.

As our 2021 engagement with Michigan State University showed, the effects of ransomware continue to impact the research community. Trusted CI is taking action to help prepare the NSF community for the threat. We are leveraging our expertise, relationships, and program activities to identify, document, and educate the NSF community about best practices for mitigating ransomware threats. We will add a page to the Trusted CI website with easy access to those best practices and resources as well as any related presentations, reports, etc.

We look forward to another successful year and welcome community member input on our priorities for 2022. If you have any questions or feedback you’d like to share, please email info@trustedci.org.

Tuesday, January 4, 2022

2021 NSF Cybersecurity Summit Report is now available

The 2021 NSF Cybersecurity Summit for Large Facilities and Cyberinfrastructure continued a nine-year tradition of providing a forum for NSF scientists, researchers, and cybersecurity professionals to develop community and share best practices. Trusted CI, NSF’s Cybersecurity Center of Excellence, hosted the Summit and looks forward to the 10th anniversary of hosting the Summit in 2022. 

Due to the ongoing COVID-19 pandemic, Trusted CI hosted the Summit virtually for the second year in a row. The 2021 Summit was held online Oct. 12-13, 15, 18-19. On Oct. 14, NSF held a Large Facilities Workshop in coordination with Trusted CI.

Collaboration, communicating with leadership about technology, mitigating against cyberattacks, identity management, building the cybersecurity workforce, and compliance were among important themes at the Summit.

The number of individuals who registered for the 2021 Summit increased to 329, including 15 students, 101 NSF-supported projects, and 19 of 20 NSF Large Facilities.

By removing the budget constraints of travel and hotel costs, this year’s online Summit enabled increased international participation, with representation from 11 countries from the previous high of eight in 2020.


The Trusted CI team looks forward to an in-person 2022 Summit, along with a virtual attendance option, so we can continue to advance the mission of the NSF science community.


Click here to see the 2021 Summit report.

Wednesday, March 24, 2021

Trusted CI’s Large Facilities Security Team Update Spring 2021


Trusted CI continues to address the cybersecurity needs of NSF’s Large Facilities (LFs) by coordinating the Large Facilities Security Team (LFST). The LFST comprises representatives from each of the LFs who are responsible for cybersecurity at their sites. The primary goal of the LFST is to encourage sharing of best practices, policies, and technologies among the team members to further cybersecurity at each of the LFs.

Communication among LFST participants is via a dedicated email list and monthly calls. Call format is either facilitated discussion of a pre-selected topic or a presentation followed by Q. and A. Topics during the past year included COVID-19 pandemic-related cybersecurity issues and response, a ResearchSOC overview, cybersecurity policy development, risk assessment, asset categorization, and supply chain vulnerability. The Trusted CI facilitators actively encourage input from all LFST members during these monthly calls, often producing informative insights on similarities and differences among site priorities and practices.

In service to the broader NSF cybersecurity community, input from the LFST was valuable to development of Trusted CI’s recently released Framework Implementation Guide for Research Cyberinfrastructure Operators. The team is reviewing NSF’s proposed revision to the Major Facilities Guide, which is currently open for comment.

We look forward to another year of learning and active cybersecurity collaboration among NSF’s Large Facilities!

For more information, or to join the LFST, email benninger@psc.edu or info@trustedci.org.


Thursday, December 19, 2019

NSF releases JASON report on research security with CUI finding

NSF recently released the JASON report on research security. Quoting Wikipedia, “JASON is an independent group of elite scientists which advises the United States government on matters of science and technology, mostly of a sensitive nature.“

Much of this report focuses on research integrity, that is the “objectivity, honesty, openness, fairness, accountability, and stewardship” of research. For research with confidentiality needs, cybersecurity has a role to play in research integrity, by protecting research such as intellectual property from being unfairly accessed. For open research, cybersecurity still has a large role in assuring data integrity: “
the assurance of the accuracy and consistency of data over its entire life-cycle” which is a small, but critical, part of research integrity and reproducibility.

In that context, this report contains a finding and discussion on CUI and research security:
8. Universities have mechanisms to handle Controlled Unclassified Information (CUI) under existing categories, such as HIPAA, FERPA, Export control, and Title XIII. CUI protection is difficult, but suited to these tasks, however it is ill-suited to the protection of fundamental research areas.

This finding is further discussed in Section 4.2, which concludes with the following statement:
Given the current state of affairs, JASON cannot recommend adoption of a CUI mechanism to secure additional categories of information generated by U.S. universities, beyond those currently covered by applicable laws designed to protect personal information (e.g., HIPAA, GINA, FERPA, Title 13, etc.). Rather, the general principle of creating high walls, i.e., classification, around narrowly defined areas should be adhered to, minimizing conflicts that might adversely affect U.S. open science practices.

A challenge we know many in the community face is internal pressure for all of research cybersecurity to shift to CUI. Trusted CI believes careful consideration is needed to select appropriate cybersecurity based on science mission, and agrees with the JASON report that CUI is not suitable for all research, including a fair amount of NSF-funded research. Trusted CI suggests approaches such as Trusted CI’s Guide to Developing Cybersecurity Programs for NSF Science and Engineering Projects and the emerging Trusted CI Framework are better suited.  We hope this report provides valuable input for ongoing discussions some of you may be having.

Thursday, October 3, 2019

CI CoE Pilot - NEON IdM Experiences

The Cyberinfrastructure Center of Excellence (CI CoE) Pilot project, in collaboration with Trusted CI, recently completed an identity and access management engagement with the National Ecological Observatory Network (NEON) to update the NEON Data Portal to use OpenID Connect for user authentication. A paper summarizing this engagement is available.

The goal of the CI CoE Pilot project is to develop a model for a CI CoE that facilitates community building and sharing, and applies knowledge of best practices and innovative solutions for NSF's major multi-user research facilities. One sub-component of the Pilot project is to gain experience with implementing identity management (IdM) solutions for facilities.

NEON was selected as the initial IdM engagee with the intent to assist them with moving the NEON Data Portal away from managing local user credentials and towards leveraging industry standards such as OpenID Connect (OIDC). The implementation involved transitioning to Auth0, which not only imported the existing database of Data Portal users, but also allowed users to log in with third-party OIDC Identity Providers (IdPs) Google and CILogon.

Monday, February 25, 2019

Comments on NSF's Major Facilities Guide from Trusted CI


Trusted CI has submitted the following comments in response to section 6.3 of


We are pleased to see NSF publish cybersecurity guidance for Major Facilities. In our experience working closely with Large Facilities via the Large Facility Security Team (LFST), one-on-one engagements, and at community events like the NSF Cybersecurity Summit, we know many cybersecurity and information technology practitioners at facilities have eagerly anticipated more guidance on cybersecurity expectations. Since 2014, we have collaborated with the Large Facilities Office to provide eight drafts of suggested content for this cybersecurity section of the Large Facility Manual (now Major Facilities Guide). We vetted the most recent Trusted CI drafts with the LFST.  While the published draft provides less detail and specificity than our most recent drafts, we believe much of the content is well-aligned with Trusted CI’s advice and experience working with the community. This MFG section will be well-aligned with the Trusted CI Framework and the companion Trusted CI Framework Implementation Guide for Providers of Scientific CyberInfrastructure we’re developing as a follow-on to our Guide to Developing Cybersecurity Programs for NSF Science and Engineering Projects.  That framework and its related products will provide explicit requirements for what it takes to stand up and maintain a competent cybersecurity program that supports open science missions.

The following are our detailed comments and suggested changes or additions.  The purpose of these suggestions is to aid in usability and readability, as well as alignment with Trusted CI’s guidance to the community.

Detailed comments:

1

Throughout the document

Suggested change: Replace “information security” with “cybersecurity” throughout or define them as being equivalent terms
Discussion: Cybersecurity and information security - both used but not explicitly described as equivalent.
Justification: Clarity and consistency

2

Throughout the document

Suggested change: Add page numbers to the document
Discussion: The lack of page numbers makes referencing or communicating about the text in the document more difficult.
Justification: Improve ease of communication about parts of the text.

3

6.3.1 Paragraph 1

Suggested change: Last sentence - strike “of the program”
Justification: redundant and awkward phrasing

4

6.3.2 Paragraph 1

Suggested paragraph replacement text:
A cybersecurity plan is a required element of the Project Execution Plan (PEP) per Section 3.4 of this Guide. Additionally, based on Uniform Guidance §200.303, to the extent the award recipient’s IT infrastructure is integral to internal controls, the relevant portion of the cybersecurity program should be compliant with guidance published by the Comptroller General or Committee of Sponsoring Organizations of the Treadway Commission (COSO).  Further, the Cooperative Agreement Supplemental Financial & Administrative Terms and Conditions (CA-FATC) for Recipients of Major Facilities or Federally Funded Research and Development Centers (FFRDC) requires an information security program and identifies a modest set of required components for the program. [add footnote references where appropriate]
Discussion: The first paragraph is confusing since it is an amalgam of requirements from different sources with different scopes. We suggest moving the sentence with the broadest scope (the requirement for the PEP to include a cybersecurity plan) to the start of the paragraph. Next would be the requirement on the internal controls but reworded to narrow applicability to cases when internal controls implemented through information technology. Finally, close with the Cooperative Agreement Supplement(s). Note: Uniform Guidance §200.303 does not actually include the phrase “including technology infrastructure and security management”.
Justification: The document now applies to more than Large Facilities or FFRDCs, so it adds clarity to state the requirements in order of scope. Also, clarifying the application of 200.303 to IT implementations of internal controls.

5

6.3.2 Paragraph 2

Suggest changing the sentence “The three pillars of a cybersecurity program which rest on this foundation are governance; resources; and controls.”
To read “ The four pillars of a cybersecurity program which rest on this foundation are mission alignment, governance; resources; and controls.
Discussion: While the “research mission and goals of the facility” are foundational, the actual alignment of the cybersecurity program is an additional pillar because the program elements there need to evolve in concert with the other pillars.
Justification: Adding the Mission alignment pillar will be consistent with the upcoming Trusted CI Framework.

6

6.3.2 Paragraph 3

Suggest changing the sentence: “This framework is based on the previously mentioned three pillars of information security programs: Governance, Resources, and Controls.”
To read: “This framework is based on the previously mentioned four pillars of cybersecurity programs: Mission Alignment, Governance, Resources, and Controls.”
Discussion: Alignment with changes suggested for paragraph 2
Justification: Consistent changes

7

6.3.2 Paragraph 4

Suggest inserting a new page formatting command
Suggest changing the sentence: “The three pillars of a cybersecurity program rely on a project-specific inventory of “information assets” to be protected.”
To read:
“6.3.3 Mission Alignment


The other three pillars of a cybersecurity program rely on a project-specific inventory of “information assets” to be protected.”
Note: Requires changing the numbering of subsequent sections and updating page headers/footers
Discussion: Add the Mission Alignment pillar
Justification: See above

8

6.3.3.1 Paragraph 3

Suggest changing: “In addition, most cybersecurity programs identify a senior security role …:
To read: “In addition, cybersecurity programs should have an identified senior security role …”
Discussion: Having an individual responsible for the cybersecurity program is important and should not be an undue burden. The task is not necessarily full-time but the core responsibility for the program should be centralized.
Justification: Strengthen the guidance to have individual primary program responsibility

9

6.3.3.3 Paragraph 1

Suggest changing: “Center for Trustworthy Scientific Cyberinfrastructure (CTSC)”
To read: “Trusted CI”
Discussion: CTSC has changed its name to Trusted CI.
Justification: Update organization name

10

6.3.3.4 Paragraph 1

Suggest changing: “... organizations are advised to plan for …”
To read: “ … organizations should plan for …”
Suggest changing: “ …  the project is encouraged to consider …”
To read: “... the project should include in the NSF review …”
Discussion: Given that NSF oversight will require a review of the cybersecurity program, the language in this paragraph should be strengthened.
Justification: Ensure the cybersecurity program undergoes periodic evaluation and review

11

6.3.4.2 Paragraph 3

Suggest changing: “In addition to technical skills…”
To read: “While technical skills are important …”
Discussion: The sentence is easily misread due to the comma-separated list.
Justification: Better separation of “technical skills” from the other listed items

12

6.3.5 Paragraph 1

Suggested paragraph replacement text: “Controls are tailored to the facility’s portfolio of information assets and aligned to protect confidentiality, integrity, and availability based on the corresponding information classification for those information assets.”
Discussion: The paragraph is poorly worded or contains redundant information.
Justification: Better wording for the point being made.

13

6.3.5.1 and 6.3.5.2

Suggested change: Move the two sections under the Mission Alignment pillar and renumber the Control Set section. Make appropriate page header/footer alterations.
Discussion: The subsections now belong under Mission Alignment and should be moved entirely under that pillar.
Justification: These topics are part of the Mission Alignment pillar.