Annotated Bibliography Context of protecting National Infrastructure. 1300 words
Running head: NATIONAL INFRASTRUCTURE 1
NATIONAL INFRASTRUCTURE 2
Annotated Bibliography on Protecting National Infrastructure
Manaswini Vonteru
Emerging Threats & Countermeas
University of the Cumberlands
Instructor Name - Dr. Souza
Verner, Duane, Frederic Petit, and Kibaek Kim. (October 2017). “Incorporating Prioritization in Critical Infrastructure Security and Resilience Programs.” Homeland Security Affairs 13, Article 7. Retrieved from;
https://www.hsaj.org/articles/14091
This paper looks into the development of a modelling framework and optimization algorithm by Argonne laboratory as part of defense. The framework is capable of identifying failure points in critical infrastructure, CI systems, with considerations of the degree of failure consequences. The framework and algorithm can be utilized in the interdependent systems of systems level and on any other system level. The two are efficient in the modelling of combinations of CI failures. Analysts can use the results of the modelling to assist CI operators when making investment decisions, and in identify priority CI systems for assessment.
The paper also looks into the need for prioritization in defense. The lack of a prioritization process leads to mitigation, protection and assessment programs that are guided without considerations of overall resilience, redundancy, and reliability, on a system level. Decision makers can be overwhelmed by the complexity of CI systems even as prioritization for assessment is essential. The paper cites the primary goal of CI resilience and protection programs as being able to prioritize, and identify contingencies that affect these systems. Doing this will allow decision makers to prioritize resilience planning and protection investments, identify cascading events, and identify high impact failures that may be isolated. The approach should consider interdependencies in CI systems. The paper cites these as the risk attenuators for the overall system, and individual systems. Interconnections in the infrastructure constitute systems of systems where failures in a single element can affect the resilience of entire systems.
Richard Krieg. (2019). The Journal of Critical Infrastructure Policy. Retrieved from;
https://www.ipsonet.org/publications/open-access/jcip
The paper cites the development of population dependency on the internet in previous decades. It looks into the effect of the proliferation of internet based and digital systems, to the extent that they now drive the operations of CI systems. When isolated CI systems fail, they can have extensive consequences. CI systems and their interdependencies can be unplanned, interconnected and very complex, as in the systems of systems. The evolution of these systems, the paper says, happens exponentially. Societies can suffer the consequences of impairment in a single system that may cascade into multiple sectors leading to shutdowns.
The paper recognizes that each CI sector is made up of organizations and physical assets, not forgetting cyberspace or IT components. Such constitution can lead to unpredictable accidents and built in vulnerabilities. These are likely to come up as CI systems become more interactive, opaque and complex. The paper also cites the changes to national security approaches and mechanisms since 9/11. It recognizes the significant advances made by organizations such as the DHS. Changes in the security environment of the CI systems, the paper says, pose major threats to national security. These can be attributed to the increasing proliferation of disruptive technologies cutting across all CI sectors.
https://www.sciencedirect.com/science/article/pii/S1874548218301744
The paper looks into the resilience of components in CI systems. It also looks into the extensive effect such resilience has on determinations of the reliability of commodities and services facilitated by CI systems. It looks into resilience as a quality that does the following. Facilitate adoption to disruptive events. Enhances the ability of CI components when it comes to recovery and response. Moreover, absorption of the effects of disruptive occurrences and reduction of the vulnerability of CI components. With this in mind, resilience assessment can play a major role in facilitating reliability and security, for entire systems, rather than just single components.
The paper also looks into the operations of modern society regarding the role of CI. These systems ensure the functioning of state and territorial governance and the provision of goods such as communications, electricity, and transport. The paper recognizes the significance of CI systems, the instances, and development of complex researches relating to these systems. The paper also looks into the role of different levels of government in determining the inclusion of CI sectors in the list of critical systems. Such determinations ensure that there is prioritization, proper categorization of these systems and defense. This allows for adequate investment to all systems, as per their importance and the extent of the role they play.
Aali, N. A., Baina, A., & Echabbi, L. (2019). Trust Management Approach for Securing the Services Access: Telecom Operators Collaborations in IMS Network. Journal of Mobile Multimedia, 15(1), 51-70. Retrieved from;
https://www.hindawi.com/journals/scn/2018/7938727/
This paper looks into the need for application of security policies in order to protect CI infrastructure against a growing number of threats. It also looks into collaboration and studies the requirements and constraints of collaborative CI systems. The paper presents a collaborative solution that is based on the principle of evaluating the trustworthiness of collaborating individuals, on the basis of trust criteria. The criteria are aimed at ensuring decision making includes collaboration, and are relevant to trust. The paper focuses on detailing trust criteria, utilized in CI system security approaches that inculcate collaboration. It analyzes the variability of contextual considerations and relates it to the evaluation process of trust.
The paper presents a case study illustrating the feasibility of the proposed solution in CI protection, and application to electrical grids. The paper also undertakes discussion and analysis of existing research pertinent to CI protection. The architecture of the proposed solution, its preliminary components and global steps are also analyzed. The paper also looks into mathematical modelling as a way of utilizing analysis of trust metrics to evaluate trust. The paper relays a study of the application of collaborative solutions to an electrical grid. It analyzes the feasibility of the approach and the role that collaboration plays in ensuring CI protection and effective decision making.
Rehak, D., & Hromada, M. (2018). Failures in a Critical Infrastructure System. System of System Failures, IntechOpen, London, 75-93. Retrieved from;
The paper provides a comprehensive overview of CI systems. It looks into the impact and failures of the systems, relating them to resilience. Resilience ensures that the risk of failure and impacts do not cascade to dependent subsystems. The paper provides descriptions of CI systems and analyzes the hierarchical arrangement of subsystems, while providing links between these components. It looks into CI failures, their impacts on society, causes and impact on dependent components. The paper focuses on the CI impacts’ propagative characteristics while considering relevant approaches to CI modelling and defense. It also looks into the resilience of CI components and their impacts on the reduction of failure instances in different circumstances, including accidents.
The paper looks into the hierarchical underpinnings of CI systems and the levels therein. These include element, sector and system levels. The interaction and interconnection of the levels is analyzed and each level is broken down into numerous components. The relationships and interconnectedness of these levels is analyzed, and the propagation of any failures and their impacts are analyzed to enhance protection. For instance, the system level is made up of socioeconomic and technical infrastructure that work together to provide essential services including electric power and water supply.
Rajiv Shah. (2019). Protecting critical national infrastructure in an era of IT and OT convergence. Retrieved from;
https://www.aspi.org.au/report/protecting-critical-national-infrastructure-era-it-and-ot-convergence
The paper looks into the increasing convergence between the physical and digital architecture. Such convergence is referred to as the coming together of operational and information technologies. Operational technology is mostly comprised of devices and technology that control and/or monitor physical effects. The internet of things, on the other hand, facilitates interconnection of numerous devices across the CI sectors. Despite the IoT technology being beneficial, it may also pose numerous risks that need adequate management. For instance, a cybersecurity breach on OT systems can be felt on the physical world. Depending on the contextual underpinnings, such as location and size, such impact can have significant consequences for societies.
A lack of security in OT systems can provide a loophole that can be exploited to attack IT systems that may otherwise be regarded as secure. CI providers may lack adequate levels of understanding and maturity when it comes to the risks facing OT systems as compared to IT systems. The paper cites a shortage of individuals with experience, specialist knowledge and security skills pertinent to OT systems. Moreover, there is a lack of readily available commercial solutions to OT security issues and management. The paper proposes the recommendation or mandate of standards that could help CI decision makers understand the expectations of the sectors. However, there lacks clear underpinnings and studies on appropriate standards in managing OT risks.