首页> 外文会议>International Conference on Cyber Warfare and Security >Quantifying Decision Making in the Critical Infrastructure
【24h】

Quantifying Decision Making in the Critical Infrastructure

机译:量化在关键基础设施中的决策

获取原文

摘要

In this paper, we examine ways to better position senior leaders to make critical decisions to protect and defend their information assets against cyber-attacks. There has been, for obvious reasons, consistent pressure for engagement and cooperation between governments, the private sector, and other stakeholders. However, historically, there has been mistrust and lack of collaboration between the three communities largely because of concerns of the fallout from information sharing and concerns that the government might impose more regulations on the commercial sector. In the context of our discussion, information assets are divided into two categories based on relevant technologies, i.e., information technologies (IT) and operational technologies (OT). The IT side is focused on the Internet Protocol (IP) systems. The OT side, on the other hand, is focused onindustrial control systems (ICS) that have a significant impact on the way critical environments enable us to acquire and sustain desired qualities of life. The OT side is the one in which a discussion of weapons of mass destruction (WMD) might have merit. For a collapse or failure of some of the sectors designated as critical infrastructure could have catastrophic and long-term impact on essential services and functionality that are critical to our survival. Nowhere is the importance of collaboration between the public, private, and government sectors more important than in the critical infrastructure (CI). Though a large amount of the critical infrastructure is owned by the private sector, it is considered by the Department of Homeland Security (DHS) to be essential in the nation's national economic and physical security, national public health or safety, or any combination thereof (Critical Infrastructure, 2015). The Internet has become a game changer, in thatit has become an 'equalizer' of sorts due to its adoption by many governments, especially the industrialized nations, as the world has transitioned to a global economy. The transformative changes that we see illustrate how technology and the Internet have brought greater convenience and functionality to the three communities (public, private, and government) and the adverse impact they can have on the critical infrastructure. Historically, the concern has been for attacks from nation states that generally had a large military and a heavily stockpiled resource-base (including huge cash amounts). The asymmetry within the cyber domain has created an unexpected balance that has now brought a new wave of committed players, including as non-nation states to a level of influence that requires them to be reckoned with and no longer ignored. As a result, senior leadership is much more cautious in its approach to decision making because of the potential consequences. This is especially true because cyber assets, though so valuable can be also so vulnerable. In this study, we will discuss a method that moves decision making from a 'gut', experience or insight-based, qualitative approach to a more data-centric, quantifiable approach. This approach supports more certainty of senior leaders in the major decisions on how to optimize the performance and security of the critical infrastructure through targeted and more accurately placed cyber investments.
机译:在本文中,我们研究了更好地位高级领导人的方式,以使他们的信息资产免受网络攻击来保护和捍卫他们的信息资产的重要决策。出于明显的原因,政府,私营部门和其他利益攸关方之间的参与和合作的一致压力。然而,从历史上看,由于信息分享和担忧可能会对商业部门施加更多规定,这三个社区之间存在不信任和缺乏合作。在我们讨论的背景下,信息资产基于相关技术,即信息技术(IT)和运营技术(OT),分为两类。 IT侧专注于互联网协议(IP)系统。另一方面,OT侧是专注于对关键环境使我们获得和维持所需生活质量的显着影响的ONINDURIAL CONTRORY SYSTEM(IC)。 OT侧是讨论大规模毁灭性武器(WMD)可能具有优点的OT侧。对于指定为关键基础设施的一些扇区的崩溃或失败可能对对我们生存至关重要的基本服务和功能来影响灾难性和长期影响。无处是公共,私营和政府部门之间合作的重要性,而不是在关键基础设施(CI)中更重要。虽然私营部门拥有大量的临界基础设施,但它被国土安全部(DHS)审议在国家全国经济和物理安全,国家公共卫生或安全或其任何组合中必不可少(关键基础设施,2015)。由于世界转向全球经济,因此,互联网已成为一个游戏更换者,因为它通过许多政府的采用,这是一种“均衡器”,尤其是工业化国家,因为世界转向全球经济。我们看到的变革变化说明了技术和互联网如何为三个社区(公共,私人和政府)以及他们可以对关键基础设施的不利影响带来更大的便利和功能。从历史上看,关切的是来自国家攻击,这些国家通常具有大型军事和重大储存的资源基础(包括巨额现金金额)。网络域内的不对称是创造了意想不到的平衡,现在已经带来了一个新的承诺玩家,包括非国家各国,这需要他们需要他们被忽视并不再被忽视的影响程度。因此,由于潜在的后果,高级领导力在其决策方法方面更加谨慎。这尤其如此,因为网络资产,虽然如此有价值,但也可能如此脆弱。在这项研究中,我们将讨论一种从“GUT”,经验或基于洞察力的,定性方法中移动决策的方法,以更具资格为中心的,可量化的方法。这种方法支持更多关于如何通过目标和更准确地放置网络投资来优化关键基础设施的绩效和安全性的主要决定中的高级领导人。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号