ix 1 WEA Best Practices 1 2 WEA “Go Live” Checklist 3 3 WEA Training and Drilling Guide 9 4 WEA Governance Guide 17 5 WEA Cybersecurity Risk Management Strategy 24 Appendix Methods in Best Practices 32
Abstract : Trust is a key factor in the effectiveness of the Wireless Emergency Alerts (WEA) service. Alert originators (AOs) must trust WEA to deliver alerts to the public in an accurate and timely manner. Members of the public must also trust the WEA service before they will act on the alerts that they receive. This research aimed to develop a trust model to enable the Federal Emergency Management Agency (FEMA) to maximize the effectiveness of WEA and provide guidance for AOs that would support them in using WEA in a manner that maximizes public safety. The research method included Bayesian belief networks to model trust in WEA because they enable reasoning about and modeling of uncertainty. The research approach was to build models that could predict the levels of AO trust and public trust in specific scenarios, validate these models using data collected from AOs and the public, and execute simulations on these models for numerous scenarios to identify recommendations to AOs and FEMA for actions to take that increase trust and actions to avoid that decrease trust. This report describes the process used to develop and validate the trust models and the resulting structure and functionality of the models.
This material is based on work funded and supported by Department of Homeland Security and is also available at FirstResponder.gov in the Technology Documents Library. This report presents four best practices for the Wireless Emergency Alerts (WEA) program. These best practices were identified through interviews with emergency management agencies across the United States. The WEA Go Live Checklist identifies key steps that an emergency management agency should perform when implementing WEA in a local jurisdiction and provides guidance for completing each action. The WEA Training and Drilling Guide identifies the steps for preparing staff to use WEA and includes suggestions shared by alerting authorities that have implemented WEA. The WEA Governance Guide identifies steps for using or preparing to use WEA to ensure coordination between participating alerting agencies. The WEA Cybersecurity Risk Management (CSRM) Strategy describes a strategy that alert originators can use throughout WEA adoption, operations, and sustainment, as well as a set of governance activities for developing a plan to execute the CSRM. Because best practices will evolve as WEA matures and becomes more widely used, an appendix provides information on how a best practice–driven organization can search for best practices, adapt them to the local context, and adopt them for everyday use.
This material is based on work funded and supported by Department of Homeland Security and is also available at FirstResponder.gov in the Technology Documents Library. The Wireless Emergency Alerts (WEA) service is anew national capability for delivering geographically targeted alerts to the public on all mobile phones. This report describes the adoption of WEA by the New York City Office of Emergency Management (NYC OEM). NYC OEM was the first alert originator to adopt WEA, so the agency experienced some unique challenges. These challenges included finding software compatible with the Federal Emergency Management Agency (FEMA) Integrated Public Alert and Warning System, of which WEA is a component; obtaining emergency alerting authority from FEMA; and demonstrating use of the new WEA system from end to end. NYC OEM's experiences also offer other alert originators information that can guide their own adoption and integration of WEA, including coordinating alerting authority with local and neighboring jurisdictions, handling the challenges presented by geotargeting and the 90-character limit, and informing the public about what to expect from WEA. An interview with NYC OEM's information security officer covers organizational learning in the areas of resources, staff buy-in,public outreach, technology, standard operating procedures, and staff training.