February 20 @5:30pm – Michael Chipley on Cybersecuring DoD Facility-Related Control Systems

REGISTER: This is a Hybrid meeting. A dinner meal will be served (Meal menu TBD). REGISTER HERE for IN PERSON & ONLINE (Microsoft Teams), Location Microsoft Reston Office 11955 Freedom Drive, Reston, VA 20190 in Room 2.2F. Metro Station Accessible and free garage parking available in across the street. Registration closes on Monday 02/17/2025.

Abstract: Over the past decade, the DoD has implemented Cybersecuring Facility-Related Control Systems to protect these Critical Infrastructure systems from adversaries and malicious actors. This presentation will review the history of how the program came to be and some key milestones such as the release of the first Cybersecurity Design Unified Facility Criteria, the first Construction Unified Facility Guide Specification, and the need for qualified Cybersecurity Subject Matter Experts and Specialists. The session will provide hands on examples of the types of control systems, how the design criteria and construction specifications are used, and what the Cyber Team does to include provisioning and hardening the components and devices, capturing the Configuration Baseline Audit Report and Artifacts, and preparing the Cyber Submittals to obtain an Authority To Operate. Similar to many of the ISSA activities for IT systems, the Control Systems now use traditional IT components and devices and the NIST SP 800-53, but now use NIST SP 800-82 to address the unique challenges of securing Operational Technologies such as Combined Heat Power Plants, Microgrids, HVAC, Fire, Lighting and Electronic Security Systems. ISSA members looking to expand their skill sets and become an OT Cyber Specialist will find a number of opportunities awaiting, this session is the introduction to get you started on the path to becoming a Cyber Warrior.

About the Speaker: Dr. Chipley has over 40 years of consulting experience in Program and Project Management in the areas of Cybersecurity, Energy, Environmental and Sustainable Design (LEED, Critical Infrastructure Protection and Analysis; Building Information Modeling (BIM) Technology; and Emergency Management/Disaster Recovery.  He is trained as a SANS Global Industrial Control Systems Professional and Project Management Professional. He has a depth and breadth of experience with federal contracts and grants; has managed and directed both small and large and complex IT and OT engineering projects and has advanced skills using cloud/virtual/mobile, project management, MS Office suite, geospatial, building information modeling, emergency management, and financial accounting applications software. He has been an active member as a chair or board member in local professional societies and universities, teaches seminars and courses on IT and OT, security, and buildings systems convergence. He is the creator and instructor of the DHS Cybersecuring Building Control Systems and Cybersecuring DoD Control Systems Workshops, author of the Whole Building Design Guide Cybersecurity Resource page, author of the DoD Cybersecurity Resource page, and author of numerous DHS Building Infrastructure Protection Series (BIPS) publications.