{"id":{"repo_id":"nps","oai_identifier":"oai:calhoun.nps.edu:10945/34237"},"canonical_url":"https://search.dev.ndltd.org/etd/nps/oai:calhoun.nps.edu:10945/34237","repository":{"repo_id":"nps","name":"Naval Postgraduate School","base_url":"https://calhoun.nps.edu/server/oai/request"},"display":{"title":"State methods for a cyber incident","abstract":"The National Cyber Incident Response Plan stipulates the state homeland security advisor as the contact point for a significant cyber incident. But this may not be the most effective method of response because the state homeland security advisors are not domain experts for cyberspace. A questionnaire was sent to state chief information officers and/or state chief information security officers to determine current capability and procedures for responding to a national cybersecurity incident. Nineteen states replied with 227 responses relating to information sharing between states and the federal government; use of established cybersecurity event and response definitions, coordination and control mechanisms, and terms; use of risk-based approaches to cyber incident planning, including remediation based on workflows and procedures; establishment of thresholds when predefined boundaries are crossed; and instigation of varying courses of action. As a result of the survey, the author recommends increasing knowledge and information flow between state and federal agencies regarding national cyber incidents; the establishment of regional cybersecurity hubs throughout the nation; and the creation of a national cyber incident teleconferencing network and prearranged protocols for situational awareness and communication of courses of action following a cybersecurity incident.","abstract_html":"The National Cyber Incident Response Plan stipulates the state homeland security advisor as the contact point for a significant cyber incident. But this may not be the most effective method of response because the state homeland security advisors are not domain experts for cyberspace. A questionnaire was sent to state chief information officers and/or state chief information security officers to determine current capability and procedures for responding to a national cybersecurity incident. Nineteen states replied with 227 responses relating to information sharing between states and the federal government; use of established cybersecurity event and response definitions, coordination and control mechanisms, and terms; use of risk-based approaches to cyber incident planning, including remediation based on workflows and procedures; establishment of thresholds when predefined boundaries are crossed; and instigation of varying courses of action. As a result of the survey, the author recommends increasing knowledge and information flow between state and federal agencies regarding national cyber incidents; the establishment of regional cybersecurity hubs throughout the nation; and the creation of a national cyber incident teleconferencing network and prearranged protocols for situational awareness and communication of courses of action following a cybersecurity incident.","abstract_has_math":false,"creators":["Mulligan, Michael R."],"institution":"Monterey California. Naval Postgraduate School","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"National Security Affairs","school":null,"contributors":[],"advisors":["Bergin, Richard","Lewis, Ted"],"committee_chairs":[],"committee_members":[],"year":2012,"date_issued":"2012-03","date_published":"2012-03","updated_at":"2026-07-27T20:24:46Z","subjects":[],"languages":[],"rights":["Copyright is reserved by the copyright owner."],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10945/34237","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Bergin, Richard","Lewis, Ted"]},{"key":"dc:contributor.department","label":"Department","values":["National Security Affairs"]},{"key":"dc:creator","label":"Author","values":["Mulligan, Michael R."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["March 2012"]},{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2013-07-03T20:17:47Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2013-07-03T20:17:47Z"]},{"key":"dc:date.issued","label":"Date","values":["2012-03"]},{"key":"dc:publisher","label":"Institution","values":["Monterey California. Naval Postgraduate School"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["Copyright is reserved by the copyright owner."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10945/34237"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The National Cyber Incident Response Plan stipulates the state homeland security advisor as the contact point for a significant cyber incident. But this may not be the most effective method of response because the state homeland security advisors are not domain experts for cyberspace. A questionnaire was sent to state chief information officers and/or state chief information security officers to determine current capability and procedures for responding to a national cybersecurity incident. Nineteen states replied with 227 responses relating to information sharing between states and the federal government; use of established cybersecurity event and response definitions, coordination and control mechanisms, and terms; use of risk-based approaches to cyber incident planning, including remediation based on workflows and procedures; establishment of thresholds when predefined boundaries are crossed; and instigation of varying courses of action. As a result of the survey, the author recommends increasing knowledge and information flow between state and federal agencies regarding national cyber incidents; the establishment of regional cybersecurity hubs throughout the nation; and the creation of a national cyber incident teleconferencing network and prearranged protocols for situational awareness and communication of courses of action following a cybersecurity incident."]},{"key":"dc:title","label":"Title","values":["State methods for a cyber incident"]}]}],"canonical_facts":{"dc:contributor.advisor":["Bergin, Richard","Lewis, Ted"],"dc:contributor.department":["National Security Affairs"],"dc:creator":["Mulligan, Michael R."],"dc:date":["March 2012"],"dc:date.accessioned":["2013-07-03T20:17:47Z"],"dc:date.available":["2013-07-03T20:17:47Z"],"dc:date.issued":["2012-03"],"dc:description.abstract":["The National Cyber Incident Response Plan stipulates the state homeland security advisor as the contact point for a significant cyber incident. But this may not be the most effective method of response because the state homeland security advisors are not domain experts for cyberspace. A questionnaire was sent to state chief information officers and/or state chief information security officers to determine current capability and procedures for responding to a national cybersecurity incident. Nineteen states replied with 227 responses relating to information sharing between states and the federal government; use of established cybersecurity event and response definitions, coordination and control mechanisms, and terms; use of risk-based approaches to cyber incident planning, including remediation based on workflows and procedures; establishment of thresholds when predefined boundaries are crossed; and instigation of varying courses of action. As a result of the survey, the author recommends increasing knowledge and information flow between state and federal agencies regarding national cyber incidents; the establishment of regional cybersecurity hubs throughout the nation; and the creation of a national cyber incident teleconferencing network and prearranged protocols for situational awareness and communication of courses of action following a cybersecurity incident."],"dc:identifier.uri":["https://hdl.handle.net/10945/34237"],"dc:publisher":["Monterey California. Naval Postgraduate School"],"dc:rights":["Copyright is reserved by the copyright owner."],"dc:title":["State methods for a cyber incident"],"dc:type":["Thesis"]},"updated_at":"2026-07-27T20:24:46Z"}