Posts

Nothing Found

Sorry, no posts matched your criteria

Interviews

Nothing Found

Sorry, no posts matched your criteria

CORE-Observatory

Comentario de “Protección de la Infraestructura Crítica Marítima – El Departamento de Seguridad Nacional necesita dirigir mejor la seguridad cibernética Portuaria”, Informe al Presidente, Comisión de Comercio, Ciencia y Transporte, Senado de los Estados Unidos, Oficina de Rendición de Cuentas del Gobierno de los Estados Unidos, junio de 2014 (CORE1098)

Resumen: Las medidas adoptadas por el Departamento de Seguridad Nacional (DHS, por sus siglas en inglés) y dos de las agencias que lo componen, la Guardia Costera de los Estados Unidos y la Agencia Federal para el Manejo de Emergencias (FEMA, por sus siglas en inglés), así como otras agencias federales, para hacer frente a la seguridad cibernética en el entorno marítimo portuario, han sido limitadas. Reporte disponible (en inglés) en: http://www.gao.gov/assets/670/663828.pdf

[s2If is_user_logged_in()]

Full review: While the Coast Guard initiated a number of activities and coordinating strategies to improve physical security in specific ports, it has not conducted a risk assessment that fully addresses cyber-related threats, vulnerabilities, and consequences. Coast Guard officials stated that they intend to conduct such an assessment in the future, but did not provide details to show how it would address cybersecurity. Until the Coast Guard completes a thorough assessment of cyber risks in the maritime environment, the ability of stakeholders to appropriately plan and allocate resources to protect ports and other maritime facilities will be limited.

Maritime security plans required by law and regulation generally did not identify or address potential cyber-related threats or vulnerabilities. This was because the guidance issued by Coast Guard for developing these plans did not require cyber elements to be addressed. Officials stated that guidance for the next set of updated plans, due for update in 2014, will include cybersecurity requirements. However, in the absence of a comprehensive risk assessment, the revised guidance may not adequately address cyber-related risks to the maritime environment.

The degree to which information-sharing mechanisms (e.g., councils) were active and shared cybersecurity-related information varied. Specifically, the Coast Guard established a government coordinating council to share information among government entities, but it is unclear to what extent this body has shared information related to cybersecurity. In addition, a sector coordinating council for sharing information among nonfederal stakeholders is no longer active, and the Coast Guard has not convinced stakeholders to reestablish it. Until the Coast Guard improves these mechanisms, maritime stakeholders in different locations are at greater risk of not being aware of, and thus not mitigating, cyber-based threats.

Under a program to provide security-related grants to ports, FEMA identified enhancing cybersecurity capabilities as a funding priority for the first time in fiscal year 2013 and has provided guidance for cybersecurity-related proposals. However, the agency has not consulted cybersecurity-related subject matter experts to inform the multi-level review of cyber-related proposals—partly because FEMA has downsized the expert panel that reviews grants. Also, because the Coast Guard has not assessed cyber-related risks in the maritime risk assessment, grant applicants and FEMA have not been able to use this information to inform funding proposals and decisions. As a result, FEMA is limited in its ability to ensure that the program is effectively addressing cyber-related risks in the maritime environment.

Why GAO Did This Study? U.S. maritime ports handle more than $1.3 trillion in cargo annually. The operations of these ports are supported by information and communication systems, which are susceptible to cyber-related threats. Failures in these systems could degrade or interrupt operations at ports, including the flow of commerce. Federal agencies—in particular DHS—and industry stakeholders have specific roles in protecting maritime facilities and ports from physical and cyber threats. GAO’s objective was to identify the extent to which DHS and other stakeholders have taken steps to address cybersecurity in the maritime port environment. GAO examined relevant laws and regulations; analyzed federal cybersecurity-related policies and plans; observed operations at three U.S. ports selected based on being a high-risk port and a leader in calls by vessel type, e.g. container; and interviewed federal and nonfederal officials.

What GAO Recommends? GAO recommends that DHS direct the Coast Guard to (1) assess cyber-related risks, (2) use this assessment to inform maritime security guidance, and (3) determine whether the sector coordinating council should be reestablished. DHS should also direct FEMA to (1) develop procedures to consult DHS cybersecurity experts for assistance in reviewing grant proposals and (2) use the results of the cyber-risk assessment to inform its grant guidance. DHS concurred with GAO’s recommendations.

Full citation:  “MARITIME CRITICAL INFRASTRUCTURE PROTECTION – DHS Needs to Better Address Port Cybersecurity”, Report to the Chairman, Committee on Commerce, Science, and Transportation, U.S. Senate, United States Government Accountability Office, June 2014.

CORE1098

Keywords: Maritime Security, Port Security, Cyber – Security, CBP U.S. – Customs and Border Protection, Coast Guard U.S., DHS-Department of Homeland Security, FEMA-Federal Emergency Management Agency, ISAC-information sharing and analysis center, IT-information technology, MTSA-Maritime Transportation Security Act of 2002, NIPP-National Infrastructure Protection Plan, AFE Port Act-Security and Accountability for Every Port Act of 2006, TSA-Transportation Security Administration

[/s2If]

Introduction to Supply Chain Management (CASSANDRA Compendium Chapter 2, CORE2007a)

Summary

The second chapter of the CASSANDRA compendium gives a general outlook on the theory and practice of modern supply chain management. Written in lay-man’s language, the text explains a broad range of strategies for managing supply chains, from lean management to agile and responsive logistics. The chapter also defines fundamental supply chain terminology and discusses current trends in the logistics, including synchromodality, use of 4PL logistics service providers, and green logistics. The chapter introduces several supply chain reference frameworks that illustrate a series of interdependent activities and stakeholders involved in the international transport of cargo. The CASSANDRA compendium is available for download here.

Review by Toni Männistö (CBRA)

[s2If is_user_logged_in()]

Full review

The compendium summarizes the SCOR and UN/CEFACT supply chain models, that may be the two most used logistics reference frameworks in the world. The document also discusses less known academic conceptual models that seek to simplify the complexity of supply chain management by categorizing and explaining management strategies, activities, stakeholders and their roles and responsibilities. The section on the future trends in logistics offers a great outlook on the most likely changes and driving forces in the logistics industry. The outlook suggests that for example synchromodality (increased flexibility in transport mode selection), green logistics (less emissions), use of 4PL logistics service providers (outsourced supply chain management), and continuously increasing ship and port sizes will reshape the cross-border logistics over the years. The document also explains key CASSANDRA concepts and their impacts on international supply chain management. For instance, the Data Pipeline, a pivotal CASSANDRA concept, seeks to enhance sharing of information across supply chain stakeholders, in particularly from business operators to customs and other border control authorities. Most importantly, the Data Pipeline would allow customs officers to access commercial information, that normally is exchanged only between buyers and sellers, early in the upstream supply chain at the consignment completion point (CCP). This accurate, early commercial information would enable the customs and other border control agencies to assess security and other risks of cargo early on.

All in all, the document provides a crash refresher course on basic and advanced logistics terminology that would be beneficial for many the CORE consortium, especially for those partners whose expertise is mainly outside the logistics industry. The CORE demonstrators benefit from descriptions of CASSANDRA innovations that support information exchange and improve visibility across the supply chain. The demos might choose to reuse some of these CASSANDRA innovations or their components. The CASSANDRA compendium also contains a great deal of material that could be reused for education and training purposes in CORE (WP19). Finally, the chapter concludes with recommendations that are relevant also for CORE. The chapter recommends, for example, that because of broad variety of international supply chains, CASSANDRA solutions should be adaptable for different contexts.

Reference

Hintsa, J. and Uronen, K. (Eds.) (2012), “Common assessment and analysis of risk in global supply chains “, Compendium of FP7-project CASSANDRA, Chapter 2

CORE2007

[/s2If]

Introducción a la Gestión de la Cadena de Suministro (Capítulo 2 Compendio CASSANDRA, CORE2007a)

Resumen

El segundo capítulo del Compendio CASSANDRA brinda una visión general sobre la teoría y práctica de la gestión moderna de la cadena de suministro. Escrito en un lenguaje común, el texto explica una amplia gama de estrategias para la gestión de cadenas de suministro, desde la gestión eficiente a la logística ágil y de rápida reacción. El capítulo también define terminología fundamental de cadena de suministro y discute las tendencias actuales en la logística, incluyendo la “sincro-modalidad”, el uso de los proveedores de servicios logísticos “4PL” (fourth-party logistics) y la logística verde. El capítulo presenta varios marcos de referencia de la cadena de suministro que ilustran una serie de actividades interdependientes y actores de interés involucrados en el transporte internacional de carga. El compendio CASSANDRA está disponible en(disponible solo en inglés).

Revisión por Toni Männistö (CBRA).

[s2If is_user_logged_in()]

Full review

The compendium summarizes the SCOR and UN/CEFACT supply chain models, that may be the two most used logistics reference frameworks in the world. The document also discusses less known academic conceptual models that seek to simplify the complexity of supply chain management by categorizing and explaining management strategies, activities, stakeholders and their roles and responsibilities. The section on the future trends in logistics offers a great outlook on the most likely changes and driving forces in the logistics industry. The outlook suggests that for example synchromodality (increased flexibility in transport mode selection), green logistics (less emissions), use of 4PL logistics service providers (outsourced supply chain management), and continuously increasing ship and port sizes will reshape the cross-border logistics over the years. The document also explains key CASSANDRA concepts and their impacts on international supply chain management. For instance, the Data Pipeline, a pivotal CASSANDRA concept, seeks to enhance sharing of information across supply chain stakeholders, in particularly from business operators to customs and other border control authorities. Most importantly, the Data Pipeline would allow customs officers to access commercial information, that normally is exchanged only between buyers and sellers, early in the upstream supply chain at the consignment completion point (CCP). This accurate, early commercial information would enable the customs and other border control agencies to assess security and other risks of cargo early on.

All in all, the document provides a crash refresher course on basic and advanced logistics terminology that would be beneficial for many the CORE consortium, especially for those partners whose expertise is mainly outside the logistics industry. The CORE demonstrators benefit from descriptions of CASSANDRA innovations that support information exchange and improve visibility across the supply chain. The demos might choose to reuse some of these CASSANDRA innovations or their components. The CASSANDRA compendium also contains a great deal of material that could be reused for education and training purposes in CORE (WP19). Finally, the chapter concludes with recommendations that are relevant also for CORE. The chapter recommends, for example, that because of broad variety of international supply chains, CASSANDRA solutions should be adaptable for different contexts.

Reference

Hintsa, J. and Uronen, K. (Eds.) (2012), “Common assessment and analysis of risk in global supply chains “, Compendium of FP7-project CASSANDRA, Chapter 2

CORE2007

[/s2If]

Punta Cana Resolution, Resolution of the Policy Commission of the World Customs Organization on the Role of Customs in the Security Context, WCO 2015 (CORE2004)

The new Punta Cana Resolution sets guidelines for customs’ security roles in the combat against the new wave of terrorism, as manifested by recent attacks in Tunisia, Turkey, Lebanon, France and Mali. The resolution highlights that the customs authorities are typically the first line of defense against transnational crime, terrorism and extremism: the customs control cross-border movements of people, cargo, money and modes of transport and thus protect communities against terrorists that may exploit international supply chains to move materials, funds or operatives across borders. Building on the previous WCO instruments and agreements, especially on the WCO Security Programme, the Punta Cana resolution is the customs community’s action plan and renewed pledge of solidarity that provides a diplomatic backdrop for further counterterrorism activities. More information at: http://www.wcoomd.org/en/media/newsroom/2015/december/wco-issues-the-punta-cana-resolution.aspx

[s2If is_user_logged_in()]

Full review

The new Punta Cana Resolution sets guidelines for customs’ security roles in the combat against the new wave of terrorism, as manifested by recent attacks in Tunisia, Turkey, Lebanon, France and Mali. The resolution highlights that the customs authorities are typically the first line of defense against transnational crime, terrorism and extremism: the customs control cross-border movements of people, cargo, money and modes of transport and thus protect communities against terrorists that may exploit international supply chains to move materials, funds or operatives across borders. Building on the previous WCO instruments and agreements, especially on the WCO Security Programme, the Punta Cana resolution is the customs community’s action plan and renewed pledge of solidarity that provides a diplomatic backdrop for further counterterrorism activities.

The Punta Cana resolution encourages customs administrations worldwide to intensify collaboration within the customs community and with other border control agencies, both domestically and internationally. In case of missing or obsolete counter-terrorism strategy, the resolution urges customs to add new security roles in their mandates and activities. The Punta Cana document also recommends customs to pay close regard to the WCO’s previous agreements and instruments, such as the WCO Compliance and Enforcement Package, SAFE Framework of Standards and the WCO Security Programme. At more practical level, the resolution promotes the use of the full range of modern detection and investigation techniques, especially advance risk profiling on the basis of Advance Passenger Information (API) and Passenger Name Record (PNR). The resolution also calls governments from around the world to provide necessary financial and human support so that their national customs administrations can contribute towards the goals of the WCO Security Programme.

The Punta Cana Resolution informs CORE consortium about the changing risk landscape where the threat of transnational terrorism is high again. The Resolution also reminds the CORE’s risk cluster of the three cornerstones of effective border security management: collaboration, technology and human resources. The Punta Cana document also gives an overlook on the customs’ security priorities over the following years. For example, the global customs community will likely invest a great deal of time and money to develop new risk profiling systems that tap into new data sources such as the Advance Passenger Information (API) and Passenger Name Record (PNR). The same trend towards better risk profiling is likely to define also the future cargo security efforts at the borders.

Reference: WCO, 2015. Punta Cana Resolution, Resolution of the Policy Commission of the World Customs Organization on the Role of Customs in the Security Context.

CORE2004

[/s2If]