Annotated bibliograpgy on Context of Protecting National Infrastructure.

profileManu8
AnnotatedBibliographyonDefenseinDepthinProtectionofNationalInfrastructure.docx

Running head: ANNOTATED DEFENSE IN DEPTH BIBLIOGRAPHY 1

ANNOTATED DEFENSE IN DEPTH BIBLIOGRAPHY 5

Annotated Bibliography on Defense in Depth in Protection of National Infrastructure.

Students Name

Instructors Name

Institution Affiliation

Course

Date

Small, P. E. (2012). Defense in Depth: An Impractical Strategy for a Cyber World. SANS Institute, 1-22. Retrieved July 29, 2018, from https://www.sans.org/reading-room/whitepapers/warfare/defense-depth-impractical-strategy-cyber-world-33896.

The author defines in depth Defense as a security strategy that makes use of multiple layers of security mechanisms to protect the infrastructure of an organization. In the subsequent part of the work, the author traces the foundation and evolution of the concept of in Defense in depth and finds that it is a strategy was used by the military to press the enemy to use more time and resources to pass the subsequent protective layers. Additionally, this peer reviewed work addresses how businesses and Information Technology Security Professionals have spent a tremendous amount of time, money and resources to deploy a Defense in Depth approach to Information Technology Security. Other terms, are defined in this work. This includes Advanced Persistent Threat (APT) originally a euphemism for network attacks supported by the government of the People's Republic of China have endured similar transitions. The author opines that migration of terminology is beneficial, as it develops better specificity in discussions of technology operations. However, the author says that the use of in depth Defense cannot provide a completely eliminate criminality in the age of cyber sophistication. The author gives an example of a successful attack against RSA, HB Gary, Booz, Allen & Hamilton, and the United States Military.

Darko Galinec, Darko Možnik & Boris Guberina (2017) Cybersecurity and cyber defence: national level strategic approach, Automatika. Retrieved from https://www.tandfonline.com/doi/full/10.1080/00051144.2017.1407022.

This study gives a new approach to incorporating Defense in depth at the national level. The article acknowledges the confusion in the use of cybersecurity as synonym of information security and the challenge it possesses. The author recommends that “cybersecurity” should be used to designate only security practices related to the defensive actions involving or relying upon information technology and/or OT environments and systems. The author opines that cyber defence focuses on preventing, detecting and providing timely responses to attacks or threats so that no infrastructure or information is tampered with. The author expresses worry due to growth in volume as well as complexity of cyber-attacks on national infrastructure. The paper argues that cyber defence is essential for most entities in order to protect sensitive information as well as to safeguard national assets.

This research explains “cybersecurity” as well as describes the relationships between cybersecurity, information security, OT security, IT security, and other related concepts and practices, e.g. cyber defence, related to their implementation aligned with the planned or existing cybersecurity strategy at the national level. The subsequent part of the paper gives a case study National Cybersecurity Strategy of the Republic of Croatia. The paper elaborates action plan as well as strategy that the republic of Croatia is planning to undertake in order to protecting all the users of modern electronic services, both in the public and economic sectors and among the general population. It identifies loopholes, strengths and weaknesses of this plan as well as giving recommendations are also provided. The main objective of the paper is to identify the main organizational problems to implementation of Defense in depth.

Robinson, C., Woodard, j.; Varnado, S. (1998). Critical Infrastructure: Interlinked and Vulnerable. Issues in Science and Technology, 15(1), 61-67. Retrieved from http://www.jstor.org.gate.lib.buffalo.edu/stable/43311852

This article talks about the interconnectivity brought about by the advancement of information technology particularly the use of computers and the internet particularly in the United States of America. The author is worried of the ‘‘domino effect’’ which he describes as risks associated by interconnectivity. The article states that elements of infrastructure themselves such as transportation, electric power, financial institutions, communications systems, and oil and gas supply are vulnerable to physical and electronic disruptions, and a dysfunction in any one may produce consequences in the others. It provides instances and examples of situations in the U.S. in which disruption of one part of the system caused consequences in other parts. For instance the western states power outage of 1996 in which a power line shorting after it sagged onto a tree caused massive unforeseen consequences: a power-grid collapse that persisted for six hours and very nearly brought down telecommunications network. The author states that use of Information Technology exposes national infrastructure to the outside world making it possible for attackers to execute their plans easily. The author further notes that the use of internet makes it almost impracticable for one to protect their sensitive information. The author recommends measures that can eliminate risk due to anonymity of connectivity such as that of the internet.

Deibert, R. (2014). Cybersecurity: The new frontier. Great Decisions, 45-58. Retrieved from http://www.jstor.org.gate.lib.buffalo.edu/stable/43682574.

This report by foreign policy association broadens the idea of cyber space to include not only the internet but also telecommunications as well as digital electronics. It further acknowledges the role of IT in a countries economy by stating that a failure in telecommunication system of a county can lead to business loss. It acknowledges that has penetrated to almost all aspects of human society including but not limited to states, civil society, businesses, militants and organized criminal groups and potential chaos that may be witnessed as a result of struggle for interest. The article also notes the relationship between information technological democracies in countries. A section of the report traces instances of cybercrimes in the United States and china particularly due to technology-enhanced dissidents and ethnic-nationalist movements seeking greater autonomy. The article urges on the need to adapt in depth Defense on telecommunication systems. The author states that having multiple layered Defense will increase the surveillance of assets in a country. However, the article does not provide detailed solutions to cyber security problem.

Ridley, G. (2011). National Security as a Corporate Social Responsibility: Critical Infrastructure Resilience. Journal of Business Ethics, 103(1), 111-125. Retrieved from http://www.jstor.org.gate.lib.buffalo.edu/stable/41476014

This research published by Journal of Business Ethics argues for an extension to the scope of corporate social responsibility (CSR) research to include a contemporary issue of importance to national and global security, critical infrastructure resilience. It identifies a method of recognising CSR-related issues, before applying it to two dissimilar case studies on critical infrastructure resilience. Additionally, it provides case study of tree companies- an international telecommunications company based in the US while the other a railway network in Britain during a period of privatisation. It looks at data rupture at these companies; Target, Lifelock and Experian and concludes that critical infrastructure resilience is a rising issue that needs to be addressed. The research looks into the role of the state in securing public data. It also notes that private companies play a role in safeguarding national assets. It states that the only solution to ever rising security breaches is multiple layer security strategy. The article acknowledges the need for online infrastructure security.

Choucri, N. & Jackson, C. (2016) Perspectives on Cybersecurity: A Collaborative Study. Electronic journal. Retrieved from https://www.researchgate.net/publication/315531141_Perspectives_on_Cybersecurity_A_Collaborative.

This paper is divided into nine chapters. Chapter one of this paper "Cybersecurity – Problems, Premises, Perspectives,"- this chapter gives detailed explanations of sources of cybersecurity threat, the boundaries of cybersecurity as well as different manifestations of threats. Chapter two -"An Abbreviated Technical Perspective on Cybersecurity," views technicalities of cybersecurity. Chapter three and four looks at cybersecurity in the conceptual aspects and its domain of contents respectively. Chapter five "The Conceptual Underpinning of Cyber Security Studies," while chapter six gives China’s Perspective on Cyber Security; this article gives china’s perspective of the concept of in depth Defense as a way of achieving cybersecurity. It further states the most basic strategies that china uses to curb cyber security issues. The article enables the reader to compare and contrast the communist view of cyber security to that of democratic countries for example, the United States. Cyber threats associated with fast growing economies and how they secure their infrastructure. Chapter seven -"Pursuing Deterrence Internationally in Cyberspace," this chapter acknowledges that cyber threat is an international threat that requires combined efforts to ensure it is dealt with. Chapter eight- answers the question is Deterrence Possible in Cyber Warfare. Finally chapter nine is a theoretical framework for analysing of interactions between contemporary transnational activism and digital communication.