Richard (Dick) Brooks’ Post

Today, I attended a CISA Sector Risk Management Agency (SRMA) meeting to discuss next steps to implement NSM-22 and the ONCD implementation plan. Here are my takeaways ( I work with two SRMA's): - The US Government is working aggressively to address cyber and physical risk - NSM-22 Goals are driving goals and objectives; a major deliverable is due in Aug.2024 - The immediate focus is on Risk Identification, followed closely by Risk Mitigation - Cybersecurity harmonization will be a key driver across all 16 critical infrastructure sectors - Software, supply chain risk is a top concern - Physical and cyber risks are in scope, both man made and natural, including human error - Expect to see FAR changes in part 40 - cybersecurity that align with NSM-22 - All critical infrastructure sector SRMA's are aiming in the same direction, some are moving faster than others. Buckle up if you work with critical infrastructure.

To view or add a comment, sign in

Explore topics