Title: CRITICAL INFRASTRUCTURE PROTECTION
1 InfoSecurity New York December 9, 2004
William F. Pelgrin Director New York State
Cyber Security and Critical
Infrastructure Coordination
Office of
2Resolution 1 I will recognize the relationship
between physical and cyber security.
- Cyber events can have physical consequences.
- Cyber security and homeland security entities
should foster strong lines of communication and
cooperation.
3Resolution 2 I will not be overwhelmed by the
challenges faced in cyber security.
- Break it up into chunks.
- Just get started.
- One size does not fit all.
- Realize that the cost of insecurity is great -
usually more expensive to respond and recover
than detect and prevent.
4Resolution 3 I will not be afraid to admit to a
cyber security incident.
- 100 Security Does Not Exist.
- Its not about the Blame Game.
- Its only through sharing that we can truly help
each other be better prepared. - Its the starts that stop most people!
- ?/_at_!! Happens!
5Resolution 4 I will practice good cyber
security principles
- I will not open emails from un-trusted sources.
- I will not forward jokes/chain letters/photos
that I receive from unknown sources via email. - I will not divulge my password for a cheap pen--
or chocolates! - I will not fall prey to phishing scams.
6Resolution 5 I will empower my Information
Security Officer
- I will take cyber security seriously.
- I will have my ISO at the table.
- I will be personally involved.
7Resolution 6 I will be a role model for the
next generation in good cyber security practices
- I will practice what I preach.
- I will promote cyber ethics.
8Resolution 7 I will collaborate with others.
- I will collaborate with the public and private
sectors to enhance our collective security. - I recognize that I cant do it alone.
9Resolution 8 I will promote the idea that good
cyber security is everyones responsibility.
- I will ensure that I understand my
responsibility in using computing technology
safely and securely. - The computing power in the hands of the home
users today well-surpasses what was previously
available to only the largest corporations or
government agencies. - I will not assume that someone else is taking
care of it (e.g. the IT department, government,
etc)
10Resolution 9 I will promote National Cyber
Security Awareness Month October 2005
- I will develop a cyber security awareness
campaign within my organization.
11Resolution 10 I will not be afraid to challenge
the status quo.
- I will seek creative solutions.
12Final Resolution I will have a passion for cyber
security.