Laserfiche WebLink
public and private entities and combines k e y e l e me n t s o f c a p a b i l i t i e s a n d <br />functions to deliver an impactful solution relative to the outcomes of the Cybersecurity Framework. <br />Specifically, ECS offers intrusion prevention and analysis services that help U.S.-based companies and <br />SLTT governments defend their computer systems against unauthorized access, exploitation, and data <br />exfiltration. ECS works by sourcing timely, actionable cyber threat indicators from sensitive and classified <br />Government Furnished Information (GFI). DHS then shares those indicators with accredited Commercial <br />Service Providers (CSPs). Those CSPs in turn use the indicators to block certain types of malicious traffic <br />f r o m e n t e r i n g a. Gu)upmkOewstrdYiri subscrmbingttmECaniust contract directly with a <br />CSP in order to receive services. Please visit http://www.cisa.gov/enhanced-cybersecurity-services-ecs for a <br />current list of ECS CSP points of contact. <br />" Hu b s 4D m I e" c y b e r s e c u r i t y p r o f e c t s a r e a l t o wa b l e u r <br />mu t i pl e p o r t a ea f a c i l i t i e s. Hub and s poke cyber <br />multiple eligible entities, and maritime security partners, in multiple port areas to provide a port -wide <br />benefit. Such projects may be submitted within a primary Port Area for the project implementation. For <br />example, an applicant in the Port of Houston may submit a hub and spoke project within the <br />Houston/Galveston p o r t a r e a w h i c h i n c l u d e s s y s t e m h a r d e n i n g <br />Houston, Port Lavaca, and Corpus Christi. Proportionally, costs associated with entities or subcomponents <br />that are not covered under an AMSP and are not instrumental to enhancing maritime security must not be <br />included in the detailed budget worksheet or investment justification and thereby prorating the cost of the <br />project only to those facilities that are covered by the AMSP. Following the example noted above, the <br />applicant may not include costs associated with cybersecurity of their non -maritime facilities, such as a <br />non-MTSA regulated facility located in San Antonio. Hub and spoke projects are limited only to the <br />enhancement of maritime security as outlined in this section and may not include non -maritime systems or <br />facilities. Please clearly identify hub and spoke projects as such within your IJ and consult your COTP to <br />verify project applicability to enhancing maritime security. <br />Cybersecurity projects should address risks to the marine transportation system and/or Transportation <br />Security Incidents (TSIs) outlined in the applicable AMSP, or priorities prescribed under applicable FSP <br />or VSP, as mandated under the MTSA or the PRMPs. At the port level, examples of cybersecurity <br />projects include but are not limited to projects that enhance the cybersecurity of access control, sensors, <br />security cameras, badge/ID readers, ICSISCADA systems, process monitors and controls (such as those <br />that monitor flow rates, valve positions, tank levels, etc.), security/safety of the ship -to port -to facility-to- <br />intermodal interface, and systems that control vital cargo machinery at the ship/shore interface (such as <br />cranes, manifolds, loading arms, etc.), and passengerlvehiclelcargo security screening equipment. <br />Vulnerability assessments are generally not funded under PSGP. However, considering the evolving <br />malicious cyber activity, the relative novelty of cybersecurity as a priority within the program, and the need <br />to adopt best practices included in the voluntary Cybersecurity Framework, vulnerability assessments may <br />be funded as contracted costs. Port -wide assessments are eligible and must demonstrate that the assessment <br />includes port area partners and are necessary to be completed as a single project to ensure a comprehensive <br />evaluation of port area cyber security vulnerabilities. Personnel costs (other than M&A) are not an <br />allowable expense for conducting these assessments. <br />CISA offers free resources to assist with initial assessments, please see https://www.cisa.gov/cyber- <br />resource-hub for additional information. Applicants are encouraged to utilize free resources prior to <br />requesting funds under this program. <br />Copies of completed cybersecurity assessments funded under PSGP that impact the maritime <br />transportation system, lead to a "transportation security incident" (as that term is defined under 46 <br />U.S.C. § 7010](6)), or are otherwise related to systems, personnel, and procedures addressed by the <br />F�� <br />��� <br />FEMA PSGP Program Appendix 12023 Page G-9 <br />