National Airspace System Infrastructure Management Conference

advertisement
National Airspace
System Infrastructure
Management
Conference
Air Traffic Operations
Information Assurance
Steve Carver, ATO NAS & Mission Support
Information System Security Manager
September 9, 2005
Federal Aviation
Administration
National Airspace System (NAS)
Information Assurance
• Protects and defends information and information
systems
• Oversees development and implementation of
Contingency Plans / Disaster Recovery Plans for all
systems
• Provides policy that assures information &
information systems are managed to Information
Systems Security (ISS) standards
• Ensures that ISS requirements are implemented
throughout the system life cycle
Air Traffic Operations Information Assurance
September 9, 2005
Federal Aviation
Administration
2
Information Assurance Life Cycle
System Operations / Management
System Development
Product Team
Program Security Risk Assessment Based on Security Requirements
System
Operation
Accreditation
Team
Certification
Team
Independent Security Risk Assessment
Air Traffic Operations Information Assurance
September 9, 2005
Initial System Security
Certification &
Accreditation
Package (SCAP)
Annual & Triennial
System SCAP
Re-accreditations
Federal Aviation
Administration
3
Information Assurance Costs
• C&A
– Risk discovery & documentation costs are decreasing each year
– Annual level of effort determination
– Represents a core business annual investment
• Enterprise Residual Risk
– Based on real events or perceptions
• Safety of the flying public
• Loss of aviation community revenue
• Loss of public trust
– Eliminates system-centric business decisions
– Results in system life cycle savings
Air Traffic Operations Information Assurance
September 9, 2005
Federal Aviation
Administration
4
Challenges
• Providing ATO-relevant guidance that keeps
pace with evolving NAS architecture, public
law and federal guidelines
• Keeping ahead of evolving threats
• Fusing real time cyber and physical event
data to support Air Traffic Management
Air Traffic Operations Information Assurance
September 9, 2005
Federal Aviation
Administration
5
Download