Example: marketing

Mission Assurance Risk Management System

Mission Assurance Risk Management SystemAntiterrorism / Force Protection Assessment Tool TrainingTrainer: Caleb JonesContact: Joint Staff J33 via US Army Armament, Research, Development and Engineering Center1 Agenda Module 1 Foundational Points: (30 min) Slides Background on MARMS, Policy drivers, Terms, Role of Automation; Intro to EPRM Module 2 Legacy Vulnerability Data: (30 min) Slides and live demo Accessing legacy data. Managing corrective actions Module 3 AT/FP Risk Assessments: (45 min) Slides and live demo Conducting AT/FP risk assessments, analyzing and managing risk2 Course Overview Scope Primary: Focus on entering and managing Antiterrorism/Force Protection (AT/FP) assessment data Secondary: Future implications to Mission Assurance (MA) assessments Delivery method: Lecture and demonstration3 Terminal Learning Objectives (TLO) the operational and policy drivers for MARMS and risk assessments (Why and who) the timeline for transition to EPRM MARMS modules (When) a risk scenario and its components (What) the benefits of risk-based assessments (Why)

Terminal Learning Objectives (TLO) 1. Understand the operational and policy drivers for MARMS and risk assessments (Why and who) 2. Understand the timeline for transition to EPRM MARMS modules (When)3.

Tags:

  Assurance

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Mission Assurance Risk Management System

1 Mission Assurance Risk Management SystemAntiterrorism / Force Protection Assessment Tool TrainingTrainer: Caleb JonesContact: Joint Staff J33 via US Army Armament, Research, Development and Engineering Center1 Agenda Module 1 Foundational Points: (30 min) Slides Background on MARMS, Policy drivers, Terms, Role of Automation; Intro to EPRM Module 2 Legacy Vulnerability Data: (30 min) Slides and live demo Accessing legacy data. Managing corrective actions Module 3 AT/FP Risk Assessments: (45 min) Slides and live demo Conducting AT/FP risk assessments, analyzing and managing risk2 Course Overview Scope Primary: Focus on entering and managing Antiterrorism/Force Protection (AT/FP) assessment data Secondary: Future implications to Mission Assurance (MA) assessments Delivery method.

2 Lecture and demonstration3 Terminal Learning Objectives (TLO) the operational and policy drivers for MARMS and risk assessments (Why and who) the timeline for transition to EPRM MARMS modules (When) a risk scenario and its components (What) the benefits of risk-based assessments (Why) how to access and update legacy vulnerability in EPRM (How) the process of entering an AT/FP risk assessment in EPRM (How) how to obtain EPRM account, training and help (How)4 Module 1 Foundational Points (30 min)5 Why not vulnerability assessments? Risk Management has long been AT Standard #3 in , however the process & tool really focused on vulnerability Previous CVAMP assessments, while good for an installation, made it very difficult to aggregate or roll-up enterprise or regional views to expose trends: Had little quantification of threats Had little standardization in asset categories Had no standardized relationships between benchmarks and threats Had minimal functionality to facilitate the Risk Management process, so results were difficult for leadership to assess where the greatest risks, and make investment new risk assessments?

3 The new method, better supports AT Standard #3 through: Benchmark focus: Walks assessors thorough benchmarks to provide leadership more complete picture of security just identified observations Standardization in threats & assets: Facilitates roll-ups and cross-unit reporting Standardized risk framework: Has common relationships that help users prioritize activities for their mitigation strategies Aggregates risk results: Inherently supports trend and risk analysis at the installation, regional, and enterprise level. This will provide leadership with the data they need to make smart decisions on where best to reduce risk on limited dollars. 7 Why use the new tool? New tool has efficiencies to assist users in executing a quality risk analysis Pushes baseline threat levels by region or allows HHQ to develop localized threat baselines to push to ATOs Allows copy from to leverage previous assessments.

4 HHQ can create Templates for common sites Users can export benchmark questionnaires exporting to an Excel spreadsheet for the other installation MA partners to complete their section, and import it back into tools Tools performs the approved math and presents results graphically and textually in Word, Excel and PowerPoint8 Background on MARMS The Mission Assurance Risk Management System (MARMS) is a Joint Staff initiative, funded by DoD CIO and managed by the US Army Armament, Research, Development and Engineering Center (ARDEC) MARMS is a multi-year program that encompasses a family of systems that will be integrated as a part of MARMS Requirement Definition Package 1 The second of MARMS capability drops (CD2) provides assessment tools ability to hold and update observations from vulnerability assessments currently in replacement risk-based capability to conduct AT/FP risk assessments follow-on capability to do risk-based capability to do MA assessments9 Policy Drivers (TLO #1) 2012 Mission Assurance Strategy and 2016 Mission Assurance Assessments Concept of Operations: Defines risk as a process integrating threat, vulnerability, consequence (criticality) Specifically includes installation-level AT/FP assessment as a required component of the MA construct 2016 Mission Assurance .

5 Requires Components to develop and implement a comprehensive and integrated MA risk- Management construct and align associated security, protection, and risk Management efforts under an MA construct. 2018 J33 Mission Assurance System of Record Designation: Established MARMS as the replacement of the Core Vulnerability Assessment Management Program (CVAMP)10 Timeline for Transition (TLO #2) Phase 1 Replace CVAMP & Provide AT/FP Risk Assessment Tool (Feb-Jun 2018) Cut-off of CVAMP data entry was 15 APR 2018, released observations to migrate Account requests by 15 MAY 2018 (for accounts on turn-on date) Initial version of EPRM must be operational in place by 1 JUN 2018 Provide Management of migrated observations from CVAMP Provide installation personnel a mechanism to facilitate risk-based AT/FP assessments Phase 2 Mission Assurance Assessment Enhancements (Jun-Dec 2018)

6 Frame Mission Assurance Assessments approach into assessment tool using guidance/input from DTRA JMAA teams Develop and incorporate full MA assessment capabilities for fielding targeting 31 DEC 2018 Phase 3 MARMS Enhancements (Jan-Sep 2019) Integration planning and execution with the MARMS Registry Push asset criticality from authoritative sources to MA & AT/FP assessors Improved Mission -risk analytics and dashboard capabilities Improved Geospatial Risk Visualization All development work on assessment tool complete by October 2019 CD2-Phase 1CD2-Phase 2CD2-Phase 311 EPRM Functionality Walks users though the life-cycle of risk assessments12& HazardsAssets (TLO #3) Asset. A distinguishable entity that provides a service or capability.

7 Assets are people, physical entities, or information located either within or outside the United States and employed, owned, or operated by domestic, foreign, public, or private sector organizations. Must have quantified (or qualified) value to the unit s / organization s missions13 Asset criticality (TLO #3)Task Critical Assets (TCA) and Defense Critical Assets (DCA) are defined in and have established criticalityOther assets are characterized by their criticality in 4 criteria (UFC 04-20-01 DoD Security Engineering Facilities Planning Manual) Criticality to Mission Criticality to National Defense Replacement (time, LOE) Relative Value (monetary, classification, etc.)14 Threats (TLO #3)Threat is any circumstance or event with the potential to cause the loss of or damage to an asset Threats are considered in terms of a threat source (sentient actor or natural hazard), a threat tactic (threat method) and a severity or severity (TLO #3)Threats are characterized by their severity (UFC 04-20-01 DoD Security Engineering Facilities Planning Manual) Local Activity Intentions and history Local Operational Capability Local Operating Environment16 Vulnerabilities (TLO #3)A situation or circumstance which, if left unchanged, may result in the loss of life or damage to Mission -essential resources from a terrorist attack.

8 ( )Vulnerabilities can result from characteristics of building characteristics equipment properties personal behavior locations of people, equipment and buildings operational procedures and personnel practices List of potential AT/FP vulnerabilities are drawn from the 2018 DoD Mission Assurance Assessment Benchmarks Each benchmark can reduce vulnerability one or more threat tactics17 Risk Scenarios (TLO #3) Risk is calculation that is based on risk scenarios A risk scenario has: Asset with a criticality(C) on a 0-1 scalelinked to a: Threatadversary-tactic combination (T) on a 0-1 scale of severity/likelihoodwith a: Vulnerabilityto the tactic (V) calculated on a 0-1 scale =3 Risk =18 Analysis of Risk Scenarios (TLO #3) Risk is understood by evaluation risk scenarios in accordance with approved metrics19 Benefits -risk-based assessments (TLO #4) Provides standardized/commonanalytical framework Converges multiple protection disciplinesinto a common sight picture Allows roll-up of multiple units into a single analysis Supports commanders in making better informed decisions on where to best allocate security resources20 CJCSM , Figure 7 Module 2 Accessing Legacy Vulnerability Data and Updating Corrective Actions on Observation (30 min)

9 21 MARMS Module AccessOnly designated users will see icon Legacy Assessment Data22 CVAMP Starts with Quad SummaryInstallation users currently land on this CVAMP page. Will have them land on different page, but will provide access to these statistics23 Mapping Legacy Assessment Data moduleHierarchy Node (unit) AttributesNot importing,Focus AreaNot needed; no new assessmentsIs a query tool; will handle with advanced analysis grid24 Linked to observations & Hierarchy Node AttributeCVAMP Manage Observations ScreenWill show details of observations in tabs below grid Will call up window for data entryNote column headersWill use new sorting and filtering fieldsReplace tabs to a status Duplicative25 CVAMP Observation Detail screenButton is on Management GridUse existing featureIn tab below observation Fields to be in tabs below observation Management gridNot editing released observations26 MARMS Manage Observations screenHeaders match CVAMP Observation Management screen.

10 (Some additions.) Mouse-overs for full selecting an observation in the grid above, data renders below. Tabs match sections in Observation Details . Data fields match for search & 2 tabsSearch window replaced by text filtersand sorting. User can sort or filter on the various grid fields to view observations falling into specific criteriaUse of Status column eliminates need for No action required and Risk Accepted Ta b s 28 Attachments & Statistics Corrective actions for selected observation References & attachments Will pull up statistics page that is the CVAMP landing page29 Excel ReportUser can export the grid data to Excel, just like CVAMP. Moving functionality to larger button at top30 CVAMP Corrective action input screen Corrective Action button will put up editable window, like the CVAMP window.


Related search queries