Tom Rich is head of the agency’s Information Security Directorate
- How would you describe your job in three sentences or less?
My
job is to work with others to protect NRC’s information and information
systems. This includes providing security training, performing security
assessments, testing the vulnerability of our IT systems to phishing
and penetration attacks, responding to security incidents and keeping up
with situational awareness to see where we may need to strengthen our
defenses.
- What is the single most important thing you do at work?
Communication
with NRC managers and employees regarding threats to our IT systems and
data. We do security briefings, security awareness events for staff,
and daily meetings with the Chief Information Officer.
- What is the single biggest challenge you face?
The
dynamic pace of technology changes and the need for cyber defenders to
keep up. With the “Internet of Things” becoming more and more a part of
our daily lives, the devices we now use in virtually everything we do
present security and privacy concerns and introduce a much larger avenue
of attack. These devices want to communicate, in some cases sensitive
data, through multiple channels with each other and cloud services. The
challenge is that these devices do not have adequate security controls
built into their design.
- What would you consider one of your biggest successes on the job?
We
established a cyber security dashboard that measures the NRC’s
improvements in security practices. This is an internal mechanism to let
NRC stakeholders see what they are doing well and where improvements
are needed. Since implementation, we have seen significant improvement
in cybersecurity across the agency.
- What one thing about the NRC do you wish more people knew?
That
we have Resident Inspectors at each of the nuclear plants. I think a
lot of the public believe we regulate and inspect from a distance. I do
not believe many know we have feet on the ground at the nuclear plants.
Five Questions With is an occasional series where we pose the same five questions to NRC staff.
For more information on National Cyber Security Awareness Month, go
here.
No comments:
Post a Comment