37
© Copyright 2017 OSIsoft, LLC INTELLIGENCE AND NATIONAL SECURITY FORUM Presented by Addressing Challenges in Federal Facilities from Cyber Risk to Operational Performance Ryan M. Colker, J.D. Director, Consultative Council/Presidential Advisor National Institute of Building Sciences

Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

copy Copyright 2017 OSIsoft LLCINTELLIGENCE AND NATIONAL SECURITY FORUM

Presented by

Addressing Challenges

in Federal Facilities from

Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Public Law 93-383 Sect 809

Develop and maintain performance criteria for maintenance of life safety health and public welfare for the built environmentEvaluate and prequalify building technology and productsConduct related and needed investigationsAssemble store and disseminate technical data and related information

Congress directed the Institute to ldquoexercise its functions and responsibilities in four general areashelliphelliphelliprdquo

Advance Science and Technology

High-Performance building means a building that

integrates and optimizes on a life-cycle basis all

major high-performance attributes including

energy [and water] conservation environment

safety security durability accessibility cost-

benefit productivity sustainability functionality

and operational considerations-Energy Independence and Security Act of 2007 sect401 (PL 110-140)

High-Performance Buildings Defined

Secure

Accessible

Productive

Aesthetics

Sustainable

BuildingSupplies

Manufacturing

Finance

Transportation

Workforce

Buildings are a Key Aspect of the Economy

Utilities

Materials

Historic Preservation

Safe

Resilient

Cost Effective

Integrate

Optimize

Life-Cycle

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 2: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Public Law 93-383 Sect 809

Develop and maintain performance criteria for maintenance of life safety health and public welfare for the built environmentEvaluate and prequalify building technology and productsConduct related and needed investigationsAssemble store and disseminate technical data and related information

Congress directed the Institute to ldquoexercise its functions and responsibilities in four general areashelliphelliphelliprdquo

Advance Science and Technology

High-Performance building means a building that

integrates and optimizes on a life-cycle basis all

major high-performance attributes including

energy [and water] conservation environment

safety security durability accessibility cost-

benefit productivity sustainability functionality

and operational considerations-Energy Independence and Security Act of 2007 sect401 (PL 110-140)

High-Performance Buildings Defined

Secure

Accessible

Productive

Aesthetics

Sustainable

BuildingSupplies

Manufacturing

Finance

Transportation

Workforce

Buildings are a Key Aspect of the Economy

Utilities

Materials

Historic Preservation

Safe

Resilient

Cost Effective

Integrate

Optimize

Life-Cycle

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 3: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Public Law 93-383 Sect 809

Develop and maintain performance criteria for maintenance of life safety health and public welfare for the built environmentEvaluate and prequalify building technology and productsConduct related and needed investigationsAssemble store and disseminate technical data and related information

Congress directed the Institute to ldquoexercise its functions and responsibilities in four general areashelliphelliphelliprdquo

Advance Science and Technology

High-Performance building means a building that

integrates and optimizes on a life-cycle basis all

major high-performance attributes including

energy [and water] conservation environment

safety security durability accessibility cost-

benefit productivity sustainability functionality

and operational considerations-Energy Independence and Security Act of 2007 sect401 (PL 110-140)

High-Performance Buildings Defined

Secure

Accessible

Productive

Aesthetics

Sustainable

BuildingSupplies

Manufacturing

Finance

Transportation

Workforce

Buildings are a Key Aspect of the Economy

Utilities

Materials

Historic Preservation

Safe

Resilient

Cost Effective

Integrate

Optimize

Life-Cycle

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 4: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Advance Science and Technology

High-Performance building means a building that

integrates and optimizes on a life-cycle basis all

major high-performance attributes including

energy [and water] conservation environment

safety security durability accessibility cost-

benefit productivity sustainability functionality

and operational considerations-Energy Independence and Security Act of 2007 sect401 (PL 110-140)

High-Performance Buildings Defined

Secure

Accessible

Productive

Aesthetics

Sustainable

BuildingSupplies

Manufacturing

Finance

Transportation

Workforce

Buildings are a Key Aspect of the Economy

Utilities

Materials

Historic Preservation

Safe

Resilient

Cost Effective

Integrate

Optimize

Life-Cycle

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 5: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

High-Performance building means a building that

integrates and optimizes on a life-cycle basis all

major high-performance attributes including

energy [and water] conservation environment

safety security durability accessibility cost-

benefit productivity sustainability functionality

and operational considerations-Energy Independence and Security Act of 2007 sect401 (PL 110-140)

High-Performance Buildings Defined

Secure

Accessible

Productive

Aesthetics

Sustainable

BuildingSupplies

Manufacturing

Finance

Transportation

Workforce

Buildings are a Key Aspect of the Economy

Utilities

Materials

Historic Preservation

Safe

Resilient

Cost Effective

Integrate

Optimize

Life-Cycle

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 6: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Secure

Accessible

Productive

Aesthetics

Sustainable

BuildingSupplies

Manufacturing

Finance

Transportation

Workforce

Buildings are a Key Aspect of the Economy

Utilities

Materials

Historic Preservation

Safe

Resilient

Cost Effective

Integrate

Optimize

Life-Cycle

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 7: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Integrate

Optimize

Life-Cycle

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 8: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Identifying and Meeting Performance Goals

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 9: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Army Net Zero Initiative

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 10: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Common Definition for ZEBbull Zero Energy Building (ZEB)

ndash An energy-efficient building where on a source energy basis the actual annual delivered energy is less than or equal to the on-site renewable exported energy

bull The designation Zero Energy Building (ZEB) should be used only for buildings that have demonstrated through actual annual measurements that the delivered energy is less than or equal to the on-site renewable exported energy

bull Also similar definitions for campus community portfolio

httpenergygoveerebuildingsdownloadscommon-definition-zero-energy-buildings

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 11: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Achieving Energy Performance Goals

bull Establishing targets based on Actual Measured Results

ndash Performance Standards

ndash Outcome-Based Codes

ndash ESPCsUSPCs

ndash Performance-Based Contracting

ndash Design-Build-Operate-MaintainP3

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 12: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

IIIIIIIIIII

I

I

I

IIIIIIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

IIIIIIIIIIIIIIII

Mind the Gap

Design amp Construction

Operations

$$$$$$$$$$$$

$$

$$

$ $$$$$$$$$$$$$$$$

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

COBieIntegrative Design

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 13: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Performance-Focused GSA P100

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 14: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

GSA Federal Center South

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 15: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Governor Deukmejian Courthouse Long Beach

bull Public-Private PartnershipDBFOM

bull The performance-based contract allowed the courthouse to be constructed without any public funding and provides for the ongoing maintenance and performance of the facility

bull Judicial Council can deduct a specific amount from the availability payment if components of the building do not work

bull For example there is a $5000 deduct for every two hours that certain elevators are inoperable

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 16: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Management Processes for Resilience

bull The Critical Infrastructure Security and Resilience Risk Management Process (CISR-RMP) objective is a model process that can be implemented by a variety of tools and adaptations of existing processes to provide results for comparisons interdependencies analysis options valuation aggregations and major resource decisions at multiple scales

bull Operationalizing the NIPP 2013ndash Set Goals amp Objectivesndash Identify Infrastructurendash Assess amp Analyze Riskndash Implement Risk Management

Activitiesndash Measure Effectiveness

httpswwwnibsorgpage=irdp_projects

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 17: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Data and Information Supporting Performance

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 18: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Rethinking the Data Ecosystem

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 19: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Shared Services + Access to Data

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 20: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

A Building Information Model (BIM) is a digital representation of physical and functional characteristics of a facility As such it serves as a shared knowledge resource for information about a facility forming a reliable basis for decisions during its life-cycle from inception onward

A basic premise of BIM is collaboration by different stakeholders at different phases of the life cycle of a facility to insert extract update or modify information in the BIM process to support and reflect the roles of that stakeholder The BIM is a shared digital representation founded on open standards for interoperability

United States National BIM Standard V1 P1 Jan 2008

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 21: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Courtesy of Autodesk

The Facility Lifecycle

21

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 22: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Simulations-Comfort

-Ventilation heating

-Energy

-Light sound

-Insulation

-Fire usage

-Environment

-Life time predictions

-Crowd behavior

- Safety

Specifications-Specification sheets

-Classification standards

-Estimates accounting

Briefing-Functional req

-Estimates

-Conditions

-Requirements

Knowledge databases-Best practise knowledge

-Own practice

Laws and regulations-Building regulations

-Building specifications

Design and Analysis-Drawings calculations

-Architect engineerhellip

Modeling-Visualisation 3D models

Procurement-Product databases

-Price databases

Facility management-Letting sale operations

-Maintenance

-Guaranties

Demolition refurbishment-Rebuild

-Demolition

-Restoration

Construction management-Scheduling

-Logistics 4D

By Lars Bjoslashrkhaug

Illustrations by Byggforsk Olof

Granlund NBLN University of

California Stanford University

Costing- Initial cost

- Life-cycle

- Value Engineering

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 23: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Construction toOperations

Buildinginformation

exchange(COBie)

SpecifiersrsquoPropertiesinformationexchange(SPie)

EquipmentLayoutinformationexchange(ELie)

Keys to Facility Management Handover

ERDC (c) 2009

Equipment Lists

Warranties and Spares

Approved Submittals

Layout Drawings

Performance

Standards

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 24: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Information Hierarchy ndash GIS-CIM-BIM RelationshipIA

I-IFC U

sage

Space

Natural Asset

Linear Structure

Structure

Building

Facility Built

Theatre World

Sub-SystemsSystem

Level

Site

Real Property Asset

Country

State Province

County

Installation Region

Node

Segment

Room

Space

System

Level

Sub-Systems

Room

Water Sea

Land Parcel

Underground

Air Space

Overlay

Overlay

Components

Components

City

OGCreg

KeyGISCIMBIM

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 25: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Using BIM Gaming amp VR to Optimize Facility Performance

COBieBIM

Rich VR

Basic Walkthrough

Scenario Development

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 26: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

bull A simple quick and reliable means for obtaining preliminary risk and resilience scores and ratings

bull A software tool designed to prepare rapid but comprehensive assessments

bull An all hazard approach

bull Applicable to facilities in federal state and local agencies and the private sector

bull Covers buildings tunnels and mass transit stations

bull Allows individual facility assessments to be customized to specific protection strategies for specific hazards

bull Includes automated checklist for ISC criteria evaluation

Integrated Rapid Visual Screening (IRVS)

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 27: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Sensors Controls and the Internet of Things

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 28: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

OT IP Controllers are in Everything

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 29: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

EIampE Cybersecurity Efforts

EEIM AMI TWG

MILDEP ICS Inventories

Network CampA

JTANICS

Installation

CDRrsquos Handbook

CYBERCOM

JBASICS TTPs

SPIDERS Phases 1 2 3

Cybersecuring Control Systems UFC

CYBERGUARD

14-1 Exercise

CSET 40 51 60 62 70 71 80

NIST SP 800-82 R2 ICS

RMF KS EIampE Control System webpage

lsquo14lsquo13lsquo12 lsquo15 lsquo16

IampE ICS Memo 1

Many Stakeholders DoD Policy Experiment Exercise Roles

IG Reports

HASC

brief 1

DoDI 8500

Cybersecurity

DoDI 8510

Risk Mgt

Framework

FFC Workshops

HASC

brief 2

DoDI 8530

Network

DoDI 8531

Vulnerability

IampE ICS Memo 2

DoDI 8140

Workforce

NIST Cyber-Physical Systems

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 30: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

WBDG Cybersecurity Resource Page

httpwwwwbdgorgresourcescybersecurityphp

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 31: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Workforce Credentials

In Development Blast Design Professional

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 32: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Workforce Credentials

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 33: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Workforce Cyber Skills ndash NIST NICE

Collect and Analyze Data Capture cybersecurity workforce and training data to understand capabilities and needsRecruit and Retain Incentivize the hiring and retention of highly skilled and adaptive professionals needed for a secure digital nationEducate Train and Develop Expand the pipeline for and deliberately develop an unrivaled cybersecurity workforceEngage Educate and energize all cybersecurity workforces and the American public to strengthen the nationrsquos front lines of cybersecurity

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 34: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Taking the Next Steps

bull Optimizing Procurement and Management Processes

bull Changing the Data Ecosystem Operationalizing BIM

bull Shifting to PerformanceOutcome-Based Standards and Criteria

bull Engaging the Workforce of Today and Tomorrow

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 35: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Attracting The Next Generation

httpwwwnibsorgMarsCity

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017

Page 36: Addressing Challenges in Federal Facilities from Cyber Risk ......Cybersecurity DoDI 8510 Risk Mgt Framework FFC Workshops HASC brief 2 DoDI 8530 Network DoDI 8531 Vulnerability I&E

Addressing Challenges in Federal Facilities from Cyber Risk to

Operational Performance

Ryan M Colker JD

Director Consultative CouncilPresidential Advisor

National Institute of Building Sciences

1090 Vermont Ave NW 700

Washington DC 20005

202-289-7800 x133

rcolkernibsorg

rmcolker

OSIsoft Intelligence and National Security ForumApril 20 2017