CNPIC - ENISA · PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR CI CNPIC...

Post on 08-Oct-2020

37 views 0 download

Transcript of CNPIC - ENISA · PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR CI CNPIC...

CNPIC as CNPIC as coordinationcoordination centre in centre in SpainSpain

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

MINISTERIO DEL INTERIOR MINISTERIO DEL INTERIOR MINISTERIO DEL INTERIOR MINISTERIO DEL INTERIOR MINISTERIO DEL INTERIOR

www.mir.eswww.mir.es

““ThoseThose physicalphysical resourcesresources, , servicesservices, , andandinformationinformation technologytechnology facilitiesfacilities, , networksnetworks andand

infrastructureinfrastructure assetsassets whichwhich, , ifif disrupteddisrupted orordestroyeddestroyed, , wouldwould havehave a a majormajor impactimpact onon thethe

citizenscitizens´́ healthhealth, , safetysafety, , securitysecurity oror economiceconomic wellwell--beingbeing, , oror onon thethe effectiveeffective functioningfunctioning ofof thethe

governmentgovernment””

CRCRIITICATICALL INFRASTRUCTURINFRASTRUCTUREES : DEFINIS : DEFINITIOTIONN

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

EnergeticEnergeticNuclear Nuclear IndustryIndustryITITTransportsTransportsWaterWater //sewagesewageFoodFoodHealthHealthFinancFinance / e / bankingbankingCheChemicamicall IndustrIndustryySpaceSpaceResearchResearchPoPowwerer CentrCentreess

STRATEGIC SECTORSSTRATEGIC SECTORS

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

SecuritySecurity isis a a basicbasic human human needneed

PublicPublic securitysecurity isis anan exclusive exclusive responsibilityresponsibility ofof thethe StateState

CICI protectionprotection isis responsibilityresponsibility ofofStateStateCI CI operatorsoperatorsCERTsCERTs (ICT (ICT scopescope))CitizensCitizens (ICT (ICT scopescope))

CI CI protectionprotection can can onlyonly be be providedprovided ifif eacheach andand everyevery actor actor acceptaccepttheirtheir responsibilityresponsibility

CICI

SHARED RESPONSIBILITYSHARED RESPONSIBILITY

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

CI are CI are developeddeveloped withinwithin a a multimulti--sectoralsectoral scenarioscenario andandare are highlyhighly interdependentinterdependent. . ItIt’’ss mandatorymandatory thatthat CI CI protectionprotection regardsregards thethe participationparticipation ofof::

PolicePolice ForcesForcesGovermentGoverment DepartmentsDepartmentsOperatorsOperators, , ManagersManagers & & OwnersOwnersInternaInternattionalional cooperationcooperation

CI CI protectionprotection can can onlyonly be be providedprovided throughthrough aaholisticholistic approachapproach

HOLISTIC APPROACHHOLISTIC APPROACH

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CICI

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

CI CI protectionprotection relatedrelated notnot onlyonly toto thethe physicalphysical securitysecuritybutbut alsoalso toto thethe logiclogic oneone

CCII ddefiniefinitiotion n && affectaffecteded sectorssectorsCI catalogue CI catalogue onon a a nationalnational basisbasisThreatThreat levelslevelsJointJoint StateState Plan Plan forfor CIP CIP launchinglaunching

Territorial Territorial PlansPlansSectoralSectoral PlansPlans

CreaCreatiotion n ofof a a PermanentPermanent Centre Centre forfor thethefollowfollow--upup ofof CIP CIP incidentsincidentsPHYSICAL & LOGICALPHYSICAL & LOGICAL

NPCIPNPCIP

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

STRATEGSTRATEGIC INFRASTRUCTURIC INFRASTRUCTUREESSNATIONALNATIONAL CATALOGUECATALOGUE

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

BasedBased onon whichwhich thethe CIPNPCIPNP isis settledsettledInteracInteractiotion n withwith otherother actorsactors: : ““LivingLiving”” ccatataaloglogueue

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

BUILDBUILD--UP PATTERNSUP PATTERNS

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

FIELDFIELDSS►► DescriptivDescriptivee InformaInformatiotionn►► PointPoint ofof ContactContact

►►KindKind ofof InfrastructurInfrastructuree

►►MappingMapping DatDataa

►► SecuriSecurityty InformaInformatiotionn

►► RiskRisk ParParaametmetererss

►► SecuritySecurity ForcesForces InformaInformatiotion n

►► VisualVisual InformaInformatiotionn

CATALOGUE CONTENTSCATALOGUE CONTENTS

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

CasualtiesCasualties / / FatalitiesFatalities

EssentialEssentialservicesservices

EconomicEconomicImpactImpact

RangeRange

TimeTimeEffectsEffects

ScaleScale

CROSSCROSS--CUTTING CRITERIACUTTING CRITERIA

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

CasualtiesCasualties / / FatalitiesFatalities

EssentialEssentialServicesServices

EconomicEconomicImpactImpact VULN

ERABILI

VULNERABILIT

YTY

SeSeccuriurityty measuresmeasures

PremisesPremises sstructurtructuree

++

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

CROSSCROSS--CUTTING CRITERIACUTTING CRITERIADAMAGE DEFIN

ITION

DAMAGE DEFINITI

ON / / PUBLIC

PUBLIC

EFFECTS

EFFECTS

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

ACTIONS IN COURSEACTIONS IN COURSE

CIP GLOBAL PERSPECTIVECIP GLOBAL PERSPECTIVE

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

PhysicalPhysical securitysecurity

ICT ICT securitysecurityDoubleDouble

DimensionDimension

PreventionPrevention

PreparednessPreparedness

DamageDamage minimizingminimizing& & recoveryrecovery

StrategicStrategicTargetsTargets

GOALSGOALSCoordinationCoordination atat nationalnational levellevelCommunicationCommunication atat internationalinternational levellevelKnowledgeKnowledge aboutabout cybercyber incidentsincidentsSupportSupport lawlaw enforcementenforcementEfficientEfficient response response toto incidentsincidents onon criticalcritical infrastructuresinfrastructures

COOPERATION WITH COOPERATION WITH CERTsCERTs

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

WHY?WHY?Actual knowActual know--how how aboutabout cybercyber--incidentsincidentsDedicatedDedicated andand specializedspecialized in in thethe ICT ICT incidentincidentresponseresponse

CIP Operator

User guide Kind of incident

CNPIC

IntelligenceUnits

CERTCERT

CERTs

Critical? END1

23

45

SI

NO

ESES--CERTCERT--CCCC

• CNPIC as Spanish Point of Contact (POC)• Coordination of trans-national incidents• CIWIN• Involved in the definition of the criteria for

the establisment of European CriticalInfrastructures

INTERNATIONAL PERSPECTIVEINTERNATIONAL PERSPECTIVE

InterInter--DepartmentDepartment CooperationCooperationCoordinatedCoordinated by CNPICby CNPICLegal Legal measuresmeasuresDraftDraft ofof a a nationalnational strategystrategyPPermanentermanent WorkingWorking--GroupGroup

REQUIRED ACTIONSREQUIRED ACTIONS

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

CIPCIP

Intnal.

Coord.

Stakeh.

Coord.

Deptm.

Coord.InternationalInternational CooperationCooperationEPCIPEPCIPEssentialEssential forfor CITCIT

CooperationCooperation withwith stakeholdersstakeholders & agencies& agenciesCERTsCERTs coordinationcoordination --> > ESES--CERTCERT--CCCCSectoralSectoral WorkingWorking--GroupGroupssInterchangeInterchange ofof informationinformation & & proceduresproceduresLegal Legal bindingsbindings & Best & Best PracticesPractices: : SupervisionSupervision by CNPICby CNPIC

ItIt’’ss basicallybasically a a coordinatingcoordinating agencyagencyThreatThreat & & risksrisks assessmentassessmentCataloguCatalogue e ccustodyustodySupervision & participation on projects, Supervision & participation on projects, research & funding research & funding programmesprogrammesOpen channels of information, communication, Open channels of information, communication, coordination & alert with:coordination & alert with:

CERTsCERTsOtherOther departmentsdepartmentsStakeholdersStakeholders andand agenciesagenciesPolicePolice ForcesForcesInternationalInternational counterpartscounterparts (POC)(POC)

CNPIC MISSIONSCNPIC MISSIONS

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

CNPIC

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS | MINISTERIO DEL INTERIOR

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS

GOBIERNO DE ESPAÑA

MINISTERIO DEL INTERIOR

GOBIERNO DE ESPAÑA

MINISTERIO DEL INTERIOR

www.mir.eswww.mir.es

©En

ero

2008

CNPICCENTRO NACIONAL DE PROTECCIÓN DE INFRAESTRUCTURAS CRÍTICAS