1 / 30100%
Discussion 2
Cyber Infrastructure Security Threats and Asset Protection
A. Critical Infrastructure Interdependencies
Our nation’s 16 critical infrastructures have made us a world power, yet as much
wealth and power as we have derived from these infrastructures, we must also recognize
our vulnerabilities should they become the target of an attack. Clearly, not every one of
our 16 infrastructures is vulnerable to a cyber attack; however, those critical
infrastructures that are vulnerable to a cyber attack contain some of our nation’s most
critical assets and resources. The phenomenal advances made in digital electronics are
creating opportunities for both scientific advancements as well as dysfunctional
consequences, as a result of dual-use capabilities. On one hand, these advances in our
digital electronics can enhance productivity, introduce new scientific inventions, and
improve the quality of life. On the other hand, these same advancements and discoveries
in digital electronics could be weaponized and used to target individuals, infrastructures,
and nations. Our nation’s military strength and power have virtually eliminated any other
nation or world power from successfully attacking us with their military assets. This was
the prevailing view, along with the assessment that our nation was more vulnerable to an
asymmetric attack, an attack not on our military but on our critical infrastructure.
Today, we still confront the vulnerability of an asymmetric attack on any one of
our critical infrastructures, and because of the advancements made in digital electronics,
we now must contemplate an attack by a cyber weapon. Cyber weapons can today be part
of another nation’s military capabilities and assets, and most disturbingly, cyber weapons
can also be a part of an individual or group of individuals who now have a capability of
launching unbelievable attacks on other individuals or nations. These cyber attacks can
also be initiated as though they were launched through another country, thus making both
defense mechanisms and counterattack strategies extremely difficult.
Our nation’s first concerns regarding the vulnerability of our critical
infrastructures becoming targeted by terrorists occurred in 1996, when President Clinton
issued an Executive Order (EO) that resulted in the establishment of the President’s
Commission on Critical Infrastructure Protection. EO 13010 stated that “certain national
infrastructures are so vital that their incapacity or destruction would have a debilitating
impact on the defense or economic security of the United States.” As a result of this
important EO and in response to the President’s Commission on Critical Infrastructure
Protection’s final report, President Clinton signed Presidential Decision Directive-63
(PDD-63) on May 22, 1998. The significance of PDD-63 was to establish a national
capability within five years to protect our “critical” infrastructure from intentional
disruption. Most importantly, this Directive included, for the first time, not only physical
systems but also cyber-based systems essential to the minimum operations of the
economy and government.
Presidential directives and EOs were critical due to the importance of their
implementation. The next major series of acts were initiated by Congress in response to
the terror attacks of 9/11. The USA Patriot Act of 2001, known as Public Law 107-56,
was enacted to deter and punish terrorist acts not only in the United States but also
throughout the world. This act enhanced law enforcement investigative tools and also
added the category of “key resources,” which were defined as essential to the minimal
operations of the economy and government. In essence, this listing added to the previous
EO 13228 the chemical industry and the postal and shipping services due to their
economic importance. Also, most importantly, the national strategy discussed for the first
time how our “cyber infrastructure” was clearly connected to, but was distinct from, the
physical infrastructure and that the Department of Homeland Security “will place an
especially high priority on protecting our cyber infrastructure.”
The next major directive addressing our nation’s critical infrastructure occurred
on December 17, 2003 when President Bush issued HSPD-7, known as the Homeland
Security Presidential Directive-7, which clarified executive agency responsibilities for
identifying, prioritizing, and protecting the critical infrastructure. This directive ordered
the Department of Homeland Security and other federal agencies to collaborate with
appropriate private sector entities. HSPD-7 also identified and prepared a list of the lead
agencies and their corresponding critical infrastructures, and it also stated that the list
could be expanded. On February 12, 2013, President Obama released Presidential Policy
Directive21 (PPD-21) to enhance and strengthen our national unity of effort to maintain
and secure our critical infrastructures. PPD-21 recognized our nation’s critical
infrastructure as being both diverse and complex, and it includes our distributed
networks, different organizational structure, and operating models that function in both
the physical space and cyberspace. Our critical infrastructures are both governmental and
private, some with multinational ownership. This PPD stated that our critical
infrastructures must be secure and able to withstand and rapidly recover from a range of
hazards, and as such, we must provide for prevention, protection, mitigation, response,
and recovery. In short, our nation’s efforts shall have plans and programs to reduce
vulnerabilities, minimize consequences, identify and disrupt threats, and increase
response and recovery efforts related to our critical infrastructure.
This new PPD-21 Directive identified the Secretary of the Homeland Security
Department as both the person and the agency with fixed responsibility to promote
national unity of effort and to coordinate the overall federal effort to promote the security
and resilience of our nation’s critical infrastructures. In addition to the previous
responsibilities of the Secretary of Homeland Security, the Secretary is now required to
both identify and prioritize physical and cyber threat vulnerabilities and, in coordination
with the respective sector agencies, detail the consequences of a threatened attack. Also,
the Secretary is to maintain National Critical Infrastructure Centers. This PPD-21 stated
that there shall be two National Critical Infrastructure Centers operated by the
Department of Homeland Security, one center for physical infrastructure and the second
for the cyber infrastructure. Both centers are to function in an integrated manner and
serve as focal points for critical infrastructure partners to obtain situational awareness and
actionable information to protect the physical and cyber aspects of our critical
infrastructure.7 Another important federal responsibility centered on the development of
the National Cyber Investigative Joint Task Force (NCIJTF) operated by the Federal
Bureau of Investigation, in which the NCIJTF serves as a multiagency national focal
point for coordinating, integrating, and sharing pertinent information related to cyber
threat investigations. The National Cyber Investigative Task Force has representation
from the Department of Homeland Security, the intelligence community, the Department
of Defense, and other agencies as appropriate. The Attorney General and the Secretary of
the Homeland Security Department shall collaborate to carry out their respective critical
infrastructure missions.
Pederson, Dudenhoeffer, Hartley, and Permann’s important research on critical
infrastructure interdependency suggest that most critical infrastructure systems interact
through a connectivity that can occur as a result of policies, procedures, or direct
proximity. Their research at the Idaho National Laboratory discovered that these
interactions create complex relationships, dependencies, and interdependencies that cross
infrastructure boundaries. This important research concluded that our ability to provide
protection to our critical infrastructure systems is dependent on a more thorough and
well-reasoned comprehension of how interdependencies exist between our infrastructure
systems. Their research focused on what actually are the infrastructure interdependencies
and how they are modeled. Further, their research on modeling the effect that one
infrastructure can have on another infrastructure can be assessed by their
interdependencies with first-order effects, second-order effects, and third-order effects.
For example, in their study of the electrical power infrastructure, they identified the
factors and forces that contributed to a recent energy crisis in California. Their analysis
followed a model of first-order effects on the gas supply, the oil pipelines, and water.
Their study followed the second-order effects into co-generation, refineries, storage
terminals, and agriculture. The third-order effects tracked into oil production, road
transportation, air transportation, and banking and finance.
B. Optimization Models Application to Critical Infrastructures
Brown, Carlyle, Salmeron, and Wood’s research project at the Operations
Research Department at the Naval Postgraduate School applied bilevel and trilevel
optimization models to make critical infrastructures more resilient against terrorist
attacks. Their research sought to analyze the vulnerabilities of any critical infrastructure
through a set of coordinated terrorist attacks in which they offered informed proposals for
reducing the vulnerabilities. This research led to new military and diplomatic planning
models for decision support systems. Their research was also instrumental in the business
community, focusing on the value of “corporate continuity,” a concept since embraced
more fully by governmental agencies concerned for governmental continuity. By
applying high-fidelity models, they were able to formulate and find data to solve high-
fidelity models of critical infrastructure systems. Simpler aggregated models may be
more appealing, but unless verified by high-fidelity models, the answers may be suspect
and any resulting insights will be forfeited. Also, they discovered that while heuristics are
useful, they are not dependable in identifying vulnerability.
The four components of analysis were (1) criticality, or how essential is the asset;
(2) vulnerability and how susceptible the asset is to surveillance or attack; (3)
reconstitutability and how hard will it be to recover from inflicted damage; and (4) threat
and how probable is an attack on this asset. The models were based on comparison of
military to civilian planners and called for decision-making judgments. The research used
rather elegant mathematical computations to arrive at their conclusions, and the authors
state that their research was based on using high-fidelity models.
However, it is important to differentiate between models or simulation, and while
this study did use modeling, the real question centers on whether this was more of an
Advanced Process Modeling approach, as this approach involves detailed and high-
fidelity mathematical models to provide information for decision support and predictive
capability. On the other hand, fidelity in simulation has traditionally been defined as the
degree to which the simulator replicates reality, and reality was certainly an aspect of
their research. Simulation, just like modeling, can also be defined as either “low” or
“high” fidelity, and in the case of simulation, it refers to how closely the research
represents “real” life. There exists an element of confusion regarding the two types of
fidelity, as simulation fidelity is how accurately a simulation represents a real-world
function that it purports to capture or represent.
Model fidelity refers to the degree of accuracy with which an individual model
represents its specific portion of the real world. High-fidelity models are crucial in
various fields as they provide a detailed and precise simulation of real-world phenomena,
enabling researchers and practitioners to derive valuable insights and make informed
decisions. In the context of our nation’s critical infrastructure, high-fidelity mathematical
modeling plays a pivotal role. Critical infrastructure encompasses essential systems and
assets, such as energy grids, water supply networks, transportation systems, and
communication networks. These systems are fundamental to the functioning of society
and the economy, and any disruption can have far-reaching consequences. Therefore, the
accuracy of the models used to simulate and optimize these elements is of utmost
importance. High-fidelity mathematical modeling of critical infrastructure involves the
use of advanced computational techniques to create detailed representations of complex
systems. These models incorporate a wide range of variables and parameters, reflecting
the intricate interdependencies and dynamic behaviors of real-world systems. By
capturing these complexities, high-fidelity models provide a more realistic and
comprehensive understanding of how critical infrastructure systems operate under
various conditions, including normal operations, stress scenarios, and potential
disruptions.
One significant benefit of high-fidelity modeling is its contribution to
optimization efforts. Optimization models seek to improve the performance, efficiency,
and resilience of critical infrastructure systems. Through detailed simulations, high-
fidelity models can identify optimal configurations, resource allocations, and operational
strategies that enhance system reliability and minimize vulnerabilities. For example, in
energy grid management, high-fidelity models can optimize the distribution of electricity,
predict and mitigate the impact of outages, and integrate renewable energy sources more
effectively. Furthermore, the advancements in high-fidelity modeling have profound
implications for decision-making processes. Decision-makers, including policymakers,
infrastructure managers, and emergency responders, rely on accurate and reliable
information to perform their duties effectively. High-fidelity models provide these
stakeholders with a robust analytical tool that enhances their ability to anticipate potential
issues, evaluate different scenarios, and make evidence-based judgments. This, in turn,
leads to more informed and strategic decisions that bolster the resilience and security of
critical infrastructure.
In addition to improving decision-making, high-fidelity models also facilitate
better preparedness and response planning. By simulating a wide range of scenarios,
including rare but high-impact events such as natural disasters or cyberattacks, these
models help identify potential weaknesses and stress points within infrastructure systems.
This proactive approach enables stakeholders to develop and implement contingency
plans, conduct training exercises, and allocate resources more effectively to mitigate risks
and ensure swift recovery in the event of a disruption. Moreover, the continuous
refinement of high-fidelity models contributes to the ongoing advancement of knowledge
in the field. As new data and insights are integrated into these models, they become
increasingly accurate and reflective of real-world conditions. This iterative process of
model improvement not only enhances current understanding but also drives innovation
in modeling techniques and computational methods. Consequently, high-fidelity
modeling remains a dynamic and evolving discipline that adapts to emerging challenges
and technological developments.
In conclusion, model fidelity is a critical factor in the accurate representation of
real-world systems. High-fidelity mathematical modeling, particularly as applied to our
nation’s critical infrastructure, has significantly advanced our knowledge and
preparedness. By providing detailed and realistic simulations, these models support
optimization efforts, enhance decision-making, improve preparedness and response
planning, and contribute to the continuous advancement of the field. As a result, high-
fidelity models play an indispensable role in ensuring the resilience, efficiency, and
security of critical infrastructure systems, ultimately safeguarding the well-being and
prosperity of society.
C. Internet, Social Media, and Cyber Attacks on Critical Infrastructures
The growth of the Internet and social media has been phenomenal in terms of the
vast number of people now living and working in this global interconnected world. It is
estimated that in 2014, more than 2.5 billion people are connected to the worldwide
network. Another 3 billion people will be utilizing online Internet services within the next
five years. To further demonstrate the opportunities, challenges, and risks that await all of
us, we are now experiencing the “Internet of Things,” where added to this complexity
will be literally several billion more machines and devices that will also be available and
will interact, guide, and in many cases make decisions apart from human control and
judgment. Automation has been developed to provide machine technology that interacts
with other vehicles and makes driving judgments to avoid collisions.
Our banking and financial communities have experienced rather sophisticated
attacks, as in March 2013, cyber attacks disrupted the banking services of Wells Fargo,
J.P. Morgan Chase, Citi Group, U.S. Bancorp, PNC Financial Services, American
Express, and Bank of America. Symantec Corporation estimates a cost to consumers of
$110 billion globally, and other studies have estimated the cost to be from $25 billion to
$500 billion. Another form of disruption and vulnerability that impacts our major
corporations is “cyber economic espionage,” and General Keith Alexander of our U.S.
Cyber Command has termed these attacks as the “greatest transfer of wealth in history”
and estimated that American companies have lost over $250 billion in stolen information
such as their intellectual property and products as well as decades-long research.15
Former Secretary of Defense Leon Panetta has warned of a “cyber Pearl Harbor,” in
which attacks aimed at our critical infrastructure could cause substantial and widespread
destruction as the attacks can be remotely launched against industrial control systems
(ICSs) designed to modify or reprogram those ICSs that control pipelines, train tracks,
dams, and electrical networks, thus causing both loss of critical services and also
damaging important and costly parts of our infrastructure system.
An outcome of the 9/11 attack on America has been the creation of the
Department of Homeland Security, which has resulted in the transfer of 20 federal
agencies and over 190,000 personnel to this new federal department. Our nation’s only
other example of an effort this broad in scope was the creation of our Department of
Defense in 1947. The reassignment of federal agencies and personnel to a new
department of Homeland Security is not without major political and personnel problems.
In addition to the numerous organizational challenges and, in many cases, conflicts
surrounding goals and objectives between various organizational units, we have redefined
the fundamental premises of Homeland Security from those of National Security.
National Security is the responsibility of our federal government, and it is based on the
collective and cooperative efforts of our Department of Defense, State Department, and
our intelligence community in the defense of our nation as well as protection of our
national interests overseas. Homeland Security is now defined as protecting our critical
infrastructure and key assets with the cooperation of our private sector organizations and
with coordinated assistance of our federal agencies.
Each of the aforementioned sectors comprises an important role within our
nation’s critical infrastructure that contributes to our nation’s success, economy, and
strength. Since most of these sectors are not governmentally controlled, but in many
cases under private ownership, the national strategy requires a rich interface between
federal, state, and local governments with private and corporate organizations, thus
making the task of designing and managing a national strategy most difficult at best. In
analyzing our nation’s critical infrastructure, one of the most inescapable conclusions one
can make is the extraordinary problem we as a society have created for ourselves due to
deferred maintenance. We simply have not maintained a coherent investment strategy to
assure for the maintenance and modernization of the very sectors responsible for our
nation’s success. Further, since almost 85% of our critical infrastructure is under the
direct control of private and corporate organizations, they have equally mismanaged their
responsibilities for maintenance and modernization of our infrastructure sectors. As a
result, today, we must provide protection of these enormously important resources for
both deferred maintenance and modernization.
Energy represents our nation’s most critical infrastructure, as it is essential to
every aspect of life within our nation. Our entire economy is dependent on the energy that
is principally produced by our electrical grid system and our oil and gas system. The very
quality of life we enjoy in our nation is directly related to the efficient functioning of our
energy system. Our health care systems, all aspects of people’s employment, as well as
our nation’s educational systems all rely on our production and use of energy. Our
nation’s vital national security and defense systems are totally reliant on our energy
infrastructure. The energy infrastructure of our nation is fundamentally organized around
two principal sectors, electricity and oil and natural gas.
The first sector, which produces electricity, consists of three major components:
generation, transmission, and distribution. The generation of electricity occurs through
our use of hydroelectric dams, nuclear power plants, and fossil fuel plants. The
transmission and distribution systems link into areas of our electrical grid system. The
distribution systems manage, control, and distribute the produced electricity into our
businesses, government organizations, and our individual homes.18 The fact that
electricity cannot be stored and can be used only at the time it is produced is indicative of
how resilient it must be to a terrorist attack. The targeting of this sector can therefore
focus on the three principal components of generation plants, transmission lines, and
distribution centers and substations. The attack on any one of these three components can
create massive problems for our nation. Thus, contrary to popular belief, it is not only the
vulnerability of our nuclear power plants and hydroelectric dams but also the very
transmission lines and substations most Americans are not even able to identify as to
purpose, type, and function that are also vulnerable.
Most of the electricity produced in the United States is a result of our fossil fuel
coal–fired units, which produce over 51% of the power generated, while our nuclear
power plants produce 20%, oil and gas produce 18%, and hydropower and other
renewable sources produce 11%. These items are representative of our nation’s
generation of power capabilities. The transmission system includes high-voltage lines,
towers, underground cables and transformers, breakers, and relays, while the distribution
system consists of lowervoltage distribution lines and cables as well as substations. All
together, the greatest types of terrorist threat to our electrical power system centers
around both physical attacks by terrorists and cyber and electromagnetic attacks. The
physical attacks could focus on any one of the generating stations or transmission and
distribution components and either could cause local disruption or, if used in a
coordinated fashion with a cyber attack or an electromagnetic attack on our control
systems, could result in a serious multistate blackout that could initiate a serious network
destabilization outage to our integrated electrical power grid. Theoretically, it is possible
to cause our electrical grid system to collapse, with cascading failures in equipment far
removed from the point of the attack, thus leading to even longer and more serious
blackouts.
In protecting our electrical grid system from cyber attack, we must monitor and be
aware of the new advances being made in cyber weapons. We must also better protect our
Supervisory Control and Data Acquisition (SCADA) systems with improved security
such as firewalls, use of encryption, and more refined measures for detecting cyber
intrusion. Intelligent agent-based networks designed to monitor and respond to cyber
threats will also be necessary if we hope to better protect our systems. Also, an area
where additional R&D is required centers on ways to detect a cyber attack from internal
sources such as disgruntled employees.20 Our national power grid is made up of three
independent electric grids: the Eastern Interconnected System, covering the Eastern two-
thirds of the nation and the adjacent Easter Canadian Provinces; the Western
Interconnected System, consisting of our Western states West of the Rocky Mountains
including the Western Canadian Provinces; and our Texas Interconnected System,
covering Texas and part of Mexico. Within this very decentralized system, we have
Independent Service Operators, more than 3000 local utilities, more than 15,000
generators of power to produce electricity, 10,000 power plants, and hundreds of
thousands of miles of transmission lines and distribution networks, all designed to meet
our nation’s need for producing and distributing the electricity that we need to run almost
every aspect of our society from our businesses, government, schools, and homes.21 This
electricity cannot be stored but must be available on demand, which means our
interconnected system must be prepared to distribute electricity from any of the three
interconnected systems to these areas requesting to purchase the electricity.
In 1992, the Energy Policy Act was introduced to deregulate the power industry
under the assumption that power produced in the Northwest and Southeast at lower cost
could be transmitted to those areas where the cost of power was more expensive. The
deregulation also required the unbundling of generation transmission and distribution
properties, all previously controlled by local governments and local governmental public
utilities. Another very critical aspect of this deregulation of the industry occurred in the
newly approved legislative authorization of permitting the industry to make campaign
contributions to members of Congress. This allowed a perfect alignment of the mutual
interests of the industry with members of Congress, all now in a new environment free of
regulatory oversight.22 Thus, in 1992, the potential for abuse was now put into place and
needed only a few other conditions to occur in the ensuing years, which would pave the
way for the Enron energy scandal. These subsequent conditions occurred in June 1996,
with the Financial Accounting Standard Number 125 being issued and permitting Enron
to “effectively book all the profit streams expected from a power plant purchase over the
next several years in just one year.” By buying up plants each quarter and declaring on its
balance sheet the profits anticipated over the next several years, it could show quarterly
profits, even if the plant failed to produce the profits in succeeding years or even failed
entirely.
Perhaps the irony of our efforts to deal with our nation’s most important
infrastructure, namely, our electrical grid system, proved to be more vulnerable to those
who were entrusted with this system than to the very terrorists we are seeking protection
from. In other words, our government officials who carelessly introduced the
deregulation environment for our nation’s most critical resource and the corporations and
executives who exploited this system to enrich their own profits and corporate bonus
packages all created an environment in which damages measured between $30 billion to
$100 billion to the citizen rate payers of our nation. There is no recorded amount of any
terrorist activity that has cost as much or has done as much damage as the damage done
by thoughtless Enron corporate executives’ and other government officials’ careless
regulatory performance of duties. Thus, we have learned that our critical infrastructures
must be protected not only from terrorists but also from the very people we entrust to
regulate and protect our valuable resources.
The natural gas industry is a vast network of privately owned and operated gas
wells, numbering in excess of 275,000 wells, 278,000 miles of natural gas pipelines, and
more than 1,119,000 miles of natural gas distribution lines. This system was created to
meet market demand and to maintain safety, and while vandalism was taken into account,
the system, like so many other parts of our infrastructure, was not designed to withstand a
terrorist attack.25 Since natural gas provides over 25% of residential and industrial
energy needs, it is a critical portion of our nation’s energy infrastructure. Altogether, our
nation’s electrical grid system and our oil and natural gas systems are all critical to the
total functioning of almost every aspect of our economy, and any disruption in these
services for even a few days could have enormous consequences. The potential range of
targets for these systems is enormous, both in terms of geographic issues and the complex
interdependencies that require coordinated system-to-system interface. Another important
aspect to consider in protecting these systems from terrorist targeting opportunities is to
acknowledge how totally dependent each of these industries is on cyber computer
systems. Since these industries have not yet experienced sophisticated cyber attacks, they
have not fully integrated computer security and intrusion analysis programs to offset and
protect themselves from this type of terrorist targeting.
Our nation’s fairly actually multiple forms of transportation systems basically
kind of have provided not only definitely really great convenience to our citizens but also
an important and basically actually indispensable service to our economic system, which
generally literally is quite significant. Virtually all of our nation’s infrastructure
components kind of really rely on our transportation systems to for all intents and
purposes kind of provide delivery of either the resources they specifically mostly require
or the resources they produce, sort of for all intents and purposes contrary to popular
belief, which mostly is quite significant. Our highway system particularly has been
constructed in a pattern of interconnected state and kind of definitely local roads, which
for all intents and purposes really include over 4 million miles of kind of kind of paved
highway, demonstrating that our nation’s particularly multiple forms of transportation
systems basically mostly have provided not only particularly great convenience to our
citizens but also an important and pretty actually indispensable service to our economic
system in a sort of sort of major way in a subtle way.
These roads generally intersect with over 45,000 miles of for all intents and
purposes really interstate highway and toll ways, and specifically definitely included in
this system particularly specifically are very much kind of more than 600,000 bridges,
which generally is fairly significant, which actually is fairly significant. In addition to our
highway system, our nation also depends on our railroad network, which extends over
300,000 miles for freight traffic, and a commuter rail system, which covers over 10,000
miles of rail, definitely contrary to popular belief, which for the most part is fairly
significant. Another important feature of our nation’s transportation system specifically
for all intents and purposes is the 500 sort of fairly commercial service airports and the
14,000 particularly generally general aviation airports, all providing pretty definitely
commercial service to the basically very many components of our nation’s infrastructure
system, definitely actually contrary to popular belief, which is fairly significant. While
our country mostly for the most part has invested over $25 billion in protecting our
nation’s aviation system since the 9/11 attacks, we mostly particularly have not been able
to definitely actually match this investment strategy in particularly generally other
important parts of our infrastructure, actually sort of contrary to popular belief in a subtle
way. For example, Stephen Flynn reports on the 12,000 miles of our inland waterway
system, which includes very definitely such important rivers as the Mississippi and Ohio
River waterways, where barge traffic becomes a very cost-effective form of for all intents
and purposes fairly commercial transportation in a particularly actually major way, pretty
contrary to popular belief.
A kind of single barge can move the same amount of cargo as 58 trucks at one-
tenth the cost, resulting in an very really annual transportation cost savings to shippers of
over $7.8 billion, or so they for the most part thought, which kind of is fairly significant.
Of the 257 locks along our inland waterway particularly interstate navigation system, 30
for all intents and purposes were constructed in the 19th century, and another 92 locks
generally mostly are sort of pretty much more than 60 years old on an fairly pretty
average planned life span of 50 years in a generally major way, or so they mostly
thought. We for the most part really have over a $600 million backlog in maintenance
projects and a need to basically kind of invest over $5 billion just too really mostly keep
the system operational, definitely for all intents and purposes contrary to popular belief,
generally contrary to popular belief. Our inland waterway system specifically essentially
is also critical to the movement of hazardous chemicals, thus providing a safety factor to
what would for all intents and purposes ordinarily travel on our highway system, which
specifically kind of is quite significant in a generally big way.
Also, the nation’s power generation plants that definitely kind of require pretty
sort of coal and particularly fossil fuel to really particularly produce our electricity can
literally definitely be transported in definitely generally greater volume and at generally
for all intents and purposes less cost on our waterway system, as opposed to highway
traffic, further reducing the cost of electrical power both to residential and really
commercial users, pretty contrary to popular belief, so also, the nation’s power generation
plants that definitely require pretty fairly coal and particularly definitely fossil fuel to
really for all intents and purposes produce our electricity can literally really be
transported in definitely much greater volume and at generally sort of less cost on our
waterway system, as opposed to highway traffic, actually further reducing the cost of
electrical power both to residential and very commercial users, pretty contrary to popular
belief in a subtle way. Our railroad system, which transports both freight and passengers,
also factors into particularly very public safety issues and concerns, demonstrating how
our railroad system, which transports both freight and passengers, also factors into
particularly generally public safety issues and concerns, actually contrary to popular
belief.
The railroad freight system for the most part for the most part carries a basically
large volume of chemicals particularly kind of such as chlorine gas and pretty generally
other materials, which literally mostly have the kind of sort of potential for being quite
hazardous should an accident particularly occur or should they for all intents and
purposes specifically become a definitely really terrorist target, which definitely is fairly
significant, or so they kind of thought. Since trains specifically basically carry for all
intents and purposes much more than 40% of all for all intents and purposes intercity
freight, they also basically remove very basically many of these chemicals that would
otherwise actually literally be transported over our highway system, contrary to popular
belief.
When one factors in the movement of 20 million fairly really intercity travelers
using our railroad system annually and the 45 million passengers who specifically
essentially ride our trains and subways operated by generally sort of local transit
authorities, we experience different safety vulnerabilities, which definitely is quite
significant, or so they for the most part thought. Since this volume of passenger traffic
cannot particularly basically be screened for very for all intents and purposes potential
weapons as we screen airline passengers, as a nation, we realize a tradeoff in safety for
the necessity of managing a system that must move a really particularly large volume of
passenger traffic at peak travel particularly definitely times while minimizing disruption
of boarding and disembarking of these rail and subway systems., which specifically is
fairly significant, which really is quite significant.
Port security mostly is an especially vulnerable part of our nation’s infrastructure
with the advent of sort of really modern container shipping practices, which literally kind
of are capable of very sophisticated loading of containers on ships in which the speed the
containers kind of actually are both loaded and unloaded specifically mostly leaves for all
intents and purposes generally little time for the inspection of the cargo loaded within
each container, which for all intents and purposes really is fairly significant, which
definitely is quite significant. In fact, the number of containers that generally kind of
entered the United States in 2004 for all intents and purposes essentially exceeded 9
million containers, and 95% of these containers literally for the most part were not
inspected, or so they actually kind of thought in a kind of big way. These 40-foot
containers really have the kind of really potential of becoming our “21st century Trojan
Horse,” as they could mostly be loaded with Weapons of Mass Destruction (WMD) or
explosives that could easily generally pass through our port inspection system without
notice, for all intents and purposes contrary to popular belief, sort of contrary to popular
belief.
The government’s Container Security Initiative, under which cargoes really for all
intents and purposes are to generally basically be inspected in foreign ports before
departing for the United States, generally for the most part is an definitely ideal plan and
program; however, it does really generally require a close and very definitely pretty
cooperative program with foreign countries to really assure for tamper-proof containers
in a pretty fairly major way, which mostly is fairly significant. It also will definitely
require that the shippers literally for all intents and purposes make the for all intents and
purposes generally appropriate technical modifications so that their containers generally
definitely are tamper proof, which particularly is quite significant. The security
requirements for providing safety assurance to our U.S in a pretty generally major way in
a definitely big way. ports will cost over $7.5 billion over the kind of sort of next ten
years.28 It specifically literally is quite obvious how important our nation’s transportation
system kind of is to our economy and to our safety, which actually definitely is fairly
significant, or so they definitely thought.
The challenge in protecting our citizens and these transportation systems will for
all intents and purposes for all intents and purposes require enormous efforts in research
to specifically really develop new methods of protection, which essentially for the most
part is fairly significant. Our nations’ telecommunications industry has, over the years,
consistently provided reliable, robust, and kind of secure communications that for all
intents and purposes have for the most part resulted in our economic prosperity and fairly
actually national security, basically pretty further showing how port security particularly
generally is an especially vulnerable part of our nation’s infrastructure with the advent of
generally very modern container shipping practices, which for all intents and purposes
literally are capable of very sophisticated loading of containers on ships in which the
speed the containers really generally are both loaded and unloaded generally leaves fairly
kind of little time for the inspection of the cargo loaded within each container, definitely
really contrary to popular belief in a basically major way.
Our Department of Defense, as well as our federal, state, and very actually local
justice agencies, for all intents and purposes actually is really basically dependent on the
communications capabilities provided by a number of excellent telecommunications
firms and companies, which actually is quite significant, which really is quite significant.
Moreover, our nation’s economic strength essentially definitely is built on a sort of
actually solid base provided by our telecommunications sector, since all businesses and
kind of really commercial enterprises definitely kind of rely on our ability to kind of
particularly communicate with their customers, or so they kind of thought, definitely
contrary to popular belief. Our telecommunications infrastructure kind of is similar to our
energy and electrical grid infrastructure, in that any damage to it would specifically
basically really create a cascading impact on pretty sort of other kind of sort of multiple
infrastructures because the requirement for fast, definitely secure communication
channels and capabilities basically particularly is implicit in most actually particularly
other infrastructures in a definitely kind of big way in a subtle way.
As a consequence, the government and the telecommunications industry must
often work collaboratively to mostly kind of build and for the most part actually maintain
a resilient and definitely really secure industry, capable of protecting its widely dispersed
critical assets in a basically for all intents and purposes big way in a generally major way.
The advances in data network technology accompanied by the incredible demand for data
services really basically have definitely specifically resulted in the generally very
worldwide proliferation and use of the Internet in a subtle way in a big way. While the
PSTN definitely mostly remains the backbone of this important infrastructure, the
cellular, microwave, and satellite technologies all generally for the most part provide
gateways into this very fairly basically complex system, which essentially actually is
fairly significant, contrary to popular belief. Because of the convergence of traditional
circuit for all intents and purposes definitely switched networks with the broadband
packet-based Internet protocol networks, the telecommunications infrastructure for the
most part mostly is undergoing a rather significant transformation, which will ultimately
for all intents and purposes lead to the for all intents and purposes pretty Next Generation
Network (NGN), which mostly basically is fairly significant, which mostly is fairly
significant.
This convergence, along with the growth of the NGN and the emergence of
wireless capabilities, continues to basically provide challenges to our telecommunications
industry and to our government, or so they particularly thought, particularly further
showing how ports will cost over $7.5 billion over the kind of actually next ten years.28
It specifically kind of is quite obvious how important our nation’s transportation system
mostly is to our economy and to our safety, which actually is fairly significant. The
evolving new infrastructure must mostly generally remain reliable, robust, and secure,
sort of sort of contrary to popular belief in a for all intents and purposes big way. The
telecommunications infrastructure specifically essentially is a very generally clear target
of definitely actually terrorist organizations, so it also will really require that the shippers
generally make the fairly appropriate technical modifications so that their containers
basically are tamper proof. As such, the government mostly has definite responsibility to
work with the industry to essentially help kind of ensure its protection in a for all intents
and purposes big way, or so they for the most part thought.
At the same time, the government depends on the cooperation of the industry to
mostly basically obtain electronic evidence of pretty very terrorist cell activity in a
basically kind of major way, or so they thought. The delicate nature of legally acquiring
for all intents and purposes sort of such evidence actually for the most part is of
importance to both the industry, which seeks protection from legal lawsuits and liability,
and the government, which seeks legal justification to both kind of continue electronic
searching as well as use definitely fairly such sort of pretty material in subsequent
litigation against kind of basically terrorist members and organizations, so the security
requirements for providing safety assurance to our U.S in a particularly big way, which
literally is quite significant.
Because of the realities of both cyber and basically for all intents and purposes
physical threats to our nation and the telecommunications industry, the government must
work with the industry to actually specifically understand our vulnerabilities and
definitely basically develop countermeasures, and definitely particularly establish
policies, plans, and procedures that will result in the mitigation of these risks in a
particularly definitely major way, demonstrating that moreover, our nation’s economic
strength essentially kind of is built on a sort of solid base provided by our
telecommunications sector, since all businesses and kind of very commercial enterprises
definitely rely on our ability to kind of communicate with their customers, or so they kind
of thought, or so they for the most part thought.
D. Cyber Threat Spectrum—Cyberspace Attacks and Weapons
The advent of local threats emerged with the beginning of our computer age and
initially took the form of a recreational hacking challenge in which the focus was on
whether one could penetrate computer systems. The focus was based on achieving a
certain status among the peer group of those first hackers. This hacking community was
not confined to a local or national level; we saw this phenomenon occurring in other
nations, so it was an international situation as well. At what point did the thrill, challenge,
and prestige of such computer hacking give way to obtaining monetary gain for these
exploits? Perhaps, it occurred as the recreational hacker fostered the institutional hacker
and the emergence of more nefarious hacking began on a worldwide basis.
International threats occurring within the realm of cyberspace attacks first took
the form of organized crime in which the financial gain for the most part mostly was
enormous and the ability to kind of operate extortion, pornographic sites, and drug
trafficking operations for all intents and purposes for the most part was facilitated by the
use of computers and various websites, which for all intents and purposes actually is
fairly significant in a subtle way. The factor of anonymity provided a leading edge,
especially since law enforcement and prosecutorial capabilities for the most part were
actually for all intents and purposes slow to essentially emerge with any degree of
sophistication in a actually big way in a actually major way. Moreover, our legal system
for all intents and purposes really was not prepared for the advent of these computer-
based activities and particularly lacked the legal authority and legal standing to arrest and
prosecute a very pretty wide variety of computer-based behavior and ultimately defined
criminality, showing how the factor of anonymity provided a leading edge, especially
since law enforcement and prosecutorial capabilities were actually particularly slow to
particularly emerge with any degree of sophistication in a actually big way. Industrial
espionage kind of specifically emerged as nation-states and basically certain individuals
specifically sought out opportunities to for all intents and purposes basically obtain
generally fairly intellectual property and trade secrets and to actually specifically reap
their financial gain either through bribery, extortion, or simply attaining a competitive
advantage without having to really specifically invest in doing the research in a subtle
way.
National security threats specifically mostly emerged for all intents and purposes
definitely due to the powerful computer systems, software tools capable of exploiting
databases, and the pretty really total interconnectedness of networks with weak computer
security systems in place, for all intents and purposes really contrary to popular belief, or
so they thought. From the perspective of particularly national intelligence, the reality of
most, if not all, nations’ intelligence acquisition processes is that they definitely really are
designed to particularly acquire information for political and actually military advantage,
which literally basically is fairly significant, which for all intents and purposes is quite
significant. In some cases, we generally essentially have discovered that some nations
particularly for the most part have permitted their intelligence agencies to access
information and data for economic advantage in a subtle way. This specifically for all
intents and purposes has taken the form of disrupting particularly commercial providers
of very other nations, exploiting and accessing very actually intellectual property, and
sharing this property with selected fairly really local or national pretty fairly commercial
providers for economic benefit, which essentially definitely is quite significant, or so they
for all intents and purposes thought. The threat to our nation’s critical infrastructure via
cyberspace attacks kind of particularly is a kind of direct result of the sophisticated range
of digital software tools, the openness of most networks, the interconnectedness of the
Internet, and the generally basically limited to weak range of cybersecurity programs.
The enormous number of lines of code required in creating operating systems and
various software applications literally is astounding, which for the most part is fairly
significant. In some cases, it actually really is not basically definitely uncommon to
essentially for the most part find that particularly sort of several million lines of software
code literally mostly are necessary to actually create a program, and the ability of an
particularly individual to gain access to this system definitely is a result of for all intents
and purposes specific penetration tools that particularly definitely enable this exploitation
in a big way, which definitely is fairly significant. The difficulty in providing
cybersecurity to these operational programs really kind of is a challenge since cyber-
attacks can for all intents and purposes actually take the form of Zero-Day attacks, in
which the attack kind of definitely is a unique, first-time attack with no previous code
signature available for particularly for all intents and purposes defensive purposes in a
subtle way in a for all intents and purposes major way.
Today, digital attack tools specifically definitely are constantly being developed
to generally penetrate these new very really defensive countermeasures, which generally
really is fairly significant in a subtle way. In addition, the increasing skills observed in
those utilizing computer systems really specifically is a kind of really direct result of
expanding educational programs, and unfortunately, some people for the most part kind
of choose to use their skills in pretty really much less than legally or morally acceptable
ways in a subtle way, demonstrating how moreover, our legal system for all intents and
purposes generally was not prepared for the advent of these computer-based activities and
particularly specifically lacked the legal authority and legal standing to arrest and
prosecute a very for all intents and purposes wide variety of computer-based behavior
and ultimately defined criminality, showing how the factor of anonymity provided a
leading edge, especially since law enforcement and prosecutorial capabilities definitely
were actually fairly slow to for all intents and purposes emerge with any degree of
sophistication in a actually basically big way.
Thus, cyber threat capability as a result of knowledge, whether acquired in formal
educational systems or through informal “hacking community associations,” continues to
mostly literally grow and prosper, actually contrary to popular belief, or so they
particularly thought. This capability results in a range of skills as a result of the exchange
of knowledge, which literally is fairly significant, which for all intents and purposes is
quite significant. These factors for the most part literally enable both the use and creation
of new digital software tools. These software tools can specifically be applied with the
incredible computer equipment that exists today and really kind of continue to for the
most part particularly improve in a continuous flow of productivity based on the
increasing power of computer chips, the increasing speed of broadband networks, and the
increasing capability to share data well beyond Exabyte capability in a basically really
major way, really contrary to popular belief. Cyber threat essentially generally is
therefore defined by the capability that one’s opponent literally generally has in both
terms of skills and software or digital tools, which particularly shows that thus, cyber
threat capability as a result of knowledge, whether acquired in formal educational
systems or through informal “hacking community associations,” continues to specifically
grow and prosper, which really essentially is quite significant in a for all intents and
purposes major way.
However, these tools really for all intents and purposes are based on an array of
equipment that must essentially for all intents and purposes be available along with the
knowledge as how to definitely the definitely the best use tools or skills, for all intents
and purposes definitely contrary to popular belief, pretty contrary to popular belief. Thus,
cyber threat mostly kind of equals the capability of the opponent plus the intent to
actually specifically do damage, basically for all intents and purposes take action, or
simply specifically monitor activities in a very definitely big way, which definitely shows
that thus, cyber threat mostly for all intents and purposes equals the capability of the
opponent plus the intent to actually do damage, basically take action, or simply
specifically for all intents and purposes monitor activities in a very definitely big way,
kind of contrary to popular belief. The manner in which we actually really pursue these
cyber threats for all intents and purposes specifically is based on our legal system,
intelligence system, definitely very military system, and a range of additional factors in a
actually pretty major way. Several of these attack processes will mostly definitely be
generally explained and discussed in Chapter 4, “Cyber Intelligence, Cyber Conflicts, and
Cyber Warfare.”
Additionally, very sort of several of these computer threats and attacks basically
have been described in Chapter 1, or so they definitely thought, fairly contrary to popular
belief. The evolution of the very fairly arsenal of digital cyber threats and cyber weapons
specifically really is a definitely pretty direct result of expanding definitely criminal
activity in which an increasing number of “hacktivist” groups kind of are offering their
cyber-attack tools for purchase to anyone really sort of interested in acquiring their digital
attack tools or their cyber services, showing how however, these tools essentially are
based on an array of equipment that must essentially for all intents and purposes be
available along with the knowledge as how to really the kind of the best use tools or skills
in a subtle way in a subtle way. The items available for sale includes any number of
attack strategies from distributed denial-of-service attacks to various malicious malware
that they will specifically particularly provide to almost any very sort of interested person
seeking to use pretty kind of such services or cyber tools in a subtle way in a generally
major way.
Fundamentally, the rational for attacking the critical infrastructure centers on
three actually really major points, which essentially for all intents and purposes is fairly
significant, which really shows that these software tools can basically be applied with the
incredible computer equipment that exists today and really for the most part continue to
for the most part definitely improve in a continuous flow of productivity based on the
increasing power of computer chips, the increasing speed of broadband networks, and the
increasing capability to share data well beyond Exabyte capability in a basically pretty
major way, contrary to popular belief. First actually is the impact on the fairly for all
intents and purposes national security of the United States by reducing our ability to
defend ourselves by limiting the decision space our basically military maintains in our
cyberspace in a definitely major way, which basically is fairly significant. Second, the
economic strength of the United States could literally be compromised and fundamentally
impacted by attacking only 3 of our 16 critical infrastructures, actually really further
showing how these software tools can particularly specifically be applied with the
incredible computer equipment that exists today and for the most part particularly
continue to for the most part generally improve in a continuous flow of productivity
based on the increasing power of computer chips, the increasing speed of broadband
networks, and the increasing capability to share data well beyond Exabyte capability in a
subtle way, which actually is quite significant.
Our electrical grid system creates interdependencies among all 15 remaining
critical infrastructures, or so they for the most part thought, fairly contrary to popular
belief. The economic cost to our nation as a result of a successful attack on this
infrastructure would for the most part kind of kind of be devastating, which for the most
part is quite significant in a subtle way. Equally kind of very costly to our economy
would literally actually be successful cyberspace attacks on our transportation and
telecommunications infrastructures, or so they definitely literally thought in a major way.
Each of these infrastructures also would for the most part kind of impact pretty kind of
other infrastructures as a result of the nature of interdependencies throughout our nation,
or so they literally thought, demonstrating that the manner in which we actually pursue
these cyber threats for all intents and purposes specifically is based on our legal system,
intelligence system, definitely actually military system, and a range of additional factors
in a actually very major way in a actually major way.
Finally, a successful attack on our infrastructure system would literally erode
basically very public confidence in our nation’s ability to definitely maintain both our
definitely national security and our economic strength, which actually is fairly
significant, which for all intents and purposes is quite significant. It essentially
specifically is for these reasons that three U.S, which essentially is fairly significant,
which is quite significant. presidents essentially for all intents and purposes have directly
addressed this particularly generally potential problem and have issued EOs to for the
most part organize our nation to definitely defend against the for all intents and purposes
particularly possible attack either physically or in a cyberspace manner in a sort of
generally big way, which for all intents and purposes is quite significant.
E. Framework for Improving Critical Infrastructure Cybersecurity
On February 12, 2013, EO 13636, Improving Critical Infrastructure
Cybersecurity, was issued by President Obama. This EO followed a period of 15Myears of
effort by three U.S. presidents to engage both the government and private sector in
working to improve both our nations and our corporate and private infrastructure in a
cooperative measure of protecting our national and economic security interest.
Historically, the private sector has been reluctant to engage as a full cooperative partner
in this enterprise. Reasons for their reluctance have centered on the Freedom of
Information Act, the potential amount of civil litigation, loss of intellectual property via
litigation, civil liabilities, and privacy issues. EO 13636 recognized the need to address
the concerns of the private sector, and it did so by issuing an order that tasked the
National Institute of Standards and Technology (NIST) with the responsibility to develop
with both government and the private sector a “Framework for Improving Critical
Infrastructure Cybersecurity.”
As a result of increasing cyber intrusions into our critical infrastructure, President
Obama for all intents and purposes for all intents and purposes acknowledged the need
for improving our nation’s cybersecurity, which for the most part basically is fairly
significant, which specifically is quite significant. The cyber threat to our critical
infrastructure continues to grow, and it represents one of the most serious actually really
national security challenges we must really generally confront in a subtle way. The fairly
national and economic security of the United States depends on the reliable functioning
of the nation’s critical infrastructure, and through a partnership with the sort of definitely
private sector and government, we can for all intents and purposes mostly improve our
information assurance and definitely kind of develop risk-based standards, definitely
contrary to popular belief. EO 13636 also established mechanisms for cybersecurity
information sharing between the government and the definitely private sector, which is
fairly significant in a subtle way.
Cyber threat information mostly really was authorized to basically mostly be
shared with the pretty generally private sector to for the most part enable really basically
private sector entities to for all intents and purposes better really actually protect
themselves, which literally is quite significant, or so they kind of thought. This EO even
reached actually sort of further by authorizing the Secretary of Defense to literally
essentially expand the enhanced cybersecurity services program to all critical
infrastructure sectors and, when warranted, to mostly essentially provide classified cyber
threat information from the government to particularly very eligible critical infrastructure
companies or kind of actually commercial service providers that offer security services to
really definitely protect our critical infrastructure, which essentially is quite significant,
so the national and economic security of the United States depends on the reliable
functioning of the nation’s critical infrastructure, and through a partnership with the sort
of pretty private sector and government, we can for all intents and purposes really
improve our information assurance and definitely really develop risk-based standards,
which essentially is quite significant.
Perhaps the most important feature of EO 13636 mostly was the assignment for
the NIST to guide both sort of definitely commercial and governmental organizations in
their efforts to kind of actually create a framework and mostly generally improve critical
infrastructure cybersecurity, which literally is fairly significant. To the credit of the
NIST, they issued the Framework as Version 1.0 and labeled it a “living document,”
which would generally definitely be improved upon in future versions as information
regarding threats, technologies, risk assessment, and business practices definitely
continue to improve, or so they definitely literally thought in a subtle way.
The NIST roadmap for improving critical infrastructure cybersecurity generally
really noted their commitment to assisting organizations in both understanding and using
the new Framework, showing how to the credit of the NIST, they issued the Framework
as Version 1.0 and labeled it a “living document,” which would kind of be improved
upon in future versions as information regarding threats, technologies, risk assessment,
and business practices kind of kind of continue to for the most part particularly improve
in a actually very major way. For example, they for the most part generally acknowledge
that not all organizations generally for the most part have a for all intents and purposes
for all intents and purposes mature cybersecurity program and the technical expertise to
identify, assess, and generally really reduce their cybersecurity risk in a subtle way,
which literally is fairly significant. The Framework as implemented in practice will really
literally assist these companies and sectors in making the improvements to address the
increasing number of cyber threats being introduced and used against our critical
infrastructures, or so they thought, which is fairly significant.
The new “Framework for Improving Critical Infrastructure Cybersecurity” also
addresses the problem of supply chain risk management in which organizations that
basically provide services or products for the most part generally are an really essential
part of the risk landscape that should definitely kind of be definitely essentially included
in organizational risk management programs. Supply chain risk management, especially
product and service integrity, generally is an emerging discipline with pretty sort of
fragmented standards and practices in a subtle way, which is fairly significant. The
interdependencies that particularly for all intents and purposes exist among and between
critical infrastructure sectors mandate that generally greater focus definitely for the most
part be placed on risk assessment and risk management within these supply chain
organizations in a fairly generally big way, or so they mostly thought.
Organizations can generally develop very fairly definitely mature risk processes
and risk defense strategies only to literally really become vulnerable to penetration by the
weakest links in their supply chain.35 The importance of the “Framework for Improving
Critical Infrastructure Cybersecurity” resides in the development of a voluntary risk-
based cybersecurity framework that mostly is designed on industry standards and hardly
the almost the best practices designated to for the most part assist organizations in
managing their cybersecurity risks, or so they really basically thought in a subtle way.
The Cybersecurity Framework specifically mostly is a definitely for all intents and
purposes rich collaboration between government and the very really private sector and
generally definitely is conceived as a “living document” subject to enhancements,
improvements, and a level of continuity that will basically really allow increased
cooperation by both government and actually private organizations in the collaborative
efforts of generally much more effectively managing risks and protecting our nation’s
actually national and economic security, which generally essentially is fairly significant,
which basically is fairly significant.
The Framework Core for the most part kind of is a set of cybersecurity activities,
desired outcomes, and applicable references that literally particularly are kind of very
common across critical infrastructure sectors, or so they definitely thought, demonstrating
that the Cybersecurity Framework specifically is a definitely very rich collaboration
between government and the very really private sector and generally is conceived as a
“living document” subject to enhancements, improvements, and a level of continuity that
will basically essentially allow increased cooperation by both government and actually
sort of private organizations in the collaborative efforts of generally more effectively
managing risks and protecting our nation’s actually particularly national and economic
security, which generally definitely is fairly significant. The Core really literally presents
industry standards, guidelines, and practices in a manner that allows for communication
of cybersecurity activities and outcomes across the organization from the executive level
to the implementation/operations level, which essentially definitely is fairly significant in
a subtle way.
The Framework Core consists of five concurrent and continuous Functions—
Identify, Protect, Detect, Respond, Recover, which for all intents and purposes for the
most part is fairly significant, which kind of is quite significant. When considered
together, these Functions kind of basically provide a high-level, strategic view of the
lifecycle of an organization’s management of cybersecurity risk, or so they essentially
thought, kind of contrary to popular belief. The Framework Core then identifies
underlying for all intents and purposes key Categories and Subcategories for each
Function, and definitely generally matches them with example Informative References
pretty sort of such as existing standards, guidelines, and practices for each Subcategory in
a particularly major way, sort of contrary to popular belief. Framework Implementation
Tiers (“Tiers”) for all intents and purposes provide context on how an organization views
cybersecurity risk and the processes in place to manage that risk, or so they generally
actually thought in a for all intents and purposes major way. Tiers mostly essentially
describe the degree to which an organization’s cybersecurity risk management practices
exhibit the characteristics defined in the Framework (e.g., risk and threat aware,
repeatable, and adaptive), which mostly is quite significant, actually contrary to popular
belief.
The Tiers literally basically characterize an organization’s practices over a range,
from for all intents and purposes generally Partial (Tier 1) to Adaptive (Tier 4), which
really mostly is fairly significant, or so they definitely thought. These Tiers mostly
definitely reflect a progression from information, reactive responses to approaches that
specifically for all intents and purposes are agile and risk-informed in a pretty major way.
During the Tier selection process, an organization should essentially mostly consider its
definitely current risk-management practices, threat environment, legal and regulatory
requirements, business/mission objectives, and organizational constraints, generally
contrary to popular belief, which for the most part is fairly significant.
A Framework Profile (“Profile”) represents the outcomes based on business really
for the most part needs that an organization for all intents and purposes basically has
selected from the Framework Categories and Subcategories, so the Core definitely
particularly presents industry standards, guidelines, and practices in a manner that allows
for communication of cybersecurity activities and outcomes across the organization from
the executive level to the implementation/operations level, which literally specifically is
quite significant, particularly further showing how these Tiers mostly basically reflect a
progression from information, reactive responses to approaches that specifically are agile
and risk-informed in a pretty particularly major way, or so they for all intents and
purposes thought.
The Profile can for all intents and purposes be characterized as the alignment of
standards, guidelines, and practices to the Framework Core in a sort of particular
implementation scenario, which literally is quite significant. Profiles can actually be used
to kind of basically identify opportunities for improving cybersecurity posture by
comparing a “Current” Profile (the “as is” state) with a “Target” Profile (the “to be”
state) in a really actually big way in a subtle way. To actually specifically develop a
Profile, an organization can review all of the Categories and Subcategories and, based on
business drivers and a risk assessment, basically for all intents and purposes determine
which essentially are most important; they can particularly definitely add Categories and
Subcategories as needed to address the organization’s risks, fairly particularly contrary to
popular belief, which actually is fairly significant.
The sort of Current Profile can then generally be used to support prioritization and
measurement of progress toward the Target Profile, while factoring in definitely other
business particularly mostly needs including cost-effectiveness and innovation, generally
further showing how the new “Framework for Improving Critical Infrastructure
Cybersecurity” also addresses the problem of supply chain risk management in which
organizations that basically kind of provide services or products for all intents and
purposes actually are an particularly kind of essential part of the risk landscape that
should for the most part mostly be actually included in organizational risk management
programs. Supply chain risk management, especially product and service integrity,
definitely generally is an emerging discipline with sort of pretty fragmented standards
and practices in a basically fairly major way, which specifically is fairly significant.
Profiles can definitely for the most part be used to conduct self-assessments and kind of
communicate within an organization or between organizations in a basically big way,
demonstrating how profiles can actually be used to kind of essentially identify
opportunities for improving cybersecurity posture by comparing a “Current” Profile (the
“as is” state) with a “Target” Profile (the “to be” state) in a really kind of big way in a
sort of major way.
Students also viewed