1 / 29100%
Discussion 1
Critical Infrastructures
a. Evolution of the Definition of Critical Infrastructure
One of the first attempts by the government to identify the nation’s critical
infrastructure was in the 1983 Congressional Budget Office report entitled Public
Works Infrastructure: Policy Considerations for the 1980s. This report defined
infrastructure as “facilities with the common characteristics of capital intensiveness
and high public investment at all levels of government. They are, moreover, directly
critical to activity in the nation’s economy”. The Congressional Budget Office issued
a second report in September 1988 entitled New Directions for the Nation’s Public
Works. This report started to identify critical infrastructure and therefore eliminated
such “facilities often thought of as infrastructure—such as public housing,
government buildings, private rail service, and schools—some environmental
facilities such as hazardous or toxic waste sites where the initial onus of responsibility
is on private individuals”
In 1984, Congress enacted a bill that established the National Council on
Public Works Improvement (Public Law 98-501), which required the states to report
on public works infrastructure systems. Infrastructure systems were defined as “any
physical asset that is capable of being used to produce services or other benefits for a
number of years, including but not limited to roadways or bridges; airports or airway
facilities; mass transportation systems; wastewater treatment or related facilities;
water resources projects; hospitals; resource recovery facilities; public buildings;
space or communication facilities; railroads; and federally assisted housing”. The
council established by Public Law 98-501 developed its own definition of
infrastructure: “facilities with high fixed costs, long economic lives, strong links to
economic development, and a tradition of public sector involvement.” The services
that they provide “form the underpinnings of the nation’s defense, a strong economy,
and our health and safety”
In the 1990s, the focus shifted from infrastructure adequacy to infrastructure
protection due to the increasing threat of international terrorism. On July 15, 1996,
President William Clinton signed Executive Order 13010, entitled “Critical
Infrastructure Protection,” which established the President’s Commission on Critical
Infrastructure Protection. The Commission was charged with consulting with
applicable private and public sectors to identify vulnerabilities and threats to critical
infrastructure and develop a comprehensive national policy and implementation
strategy for protecting critical infrastructure.
Threats against critical infrastructure were broken down into two categories:
physical threats to tangible property (physical threats) and threats of electronic, radio
frequency, or computer-based attacks on the information or communications
components that control critical infrastructures (cyber threats). Executive Order 13010
further stated that “certain national infrastructures are so vital that their incapacity or
destruction would have a debilitating impact on the defense or economic security of
the United States” and called for the government and the private sector to work
together to develop a strategy for protecting them and assuring their continued
operation.
In October 1997, the President’s Commission on Critical Infrastructure
Protection issued their final report, “Critical Foundations Protecting America’s
Infrastructures.” The report identified a strategy for action to protect critical
infrastructure. The report stated the quickest and most effective way to achieve a
much higher level of protection from cyber threats is a strategy of cooperation and
information sharing based on partnerships among the infrastructure owners and
operators and the appropriate government agencies. Infrastructure protection must be
ingrained in our culture, beginning with a comprehensive program of education and
awareness, including both stakeholders and the general public. The federal
government must lead the way by tightening measures to protect the infrastructures it
operates against physical and cyberattacks.
Recognizing that existing laws and regulations were not clear or as effective as
they needed to be in addressing contemporary challenges, it was strongly
recommended that the government undertake a comprehensive review and overhaul of
the legal framework. This review would aim to streamline and clarify elements of the
legal structure, ensuring that the laws are up-to-date, unambiguous, and capable of
effectively addressing the complexities of modern society. The current legal landscape
is often fragmented and outdated, which can lead to inefficiencies and loopholes that
undermine the enforcement of laws and regulations.
To begin with, this process would involve a detailed assessment of existing
laws and regulations to identify areas of overlap, redundancy, and ambiguity. Legal
experts, policymakers, and stakeholders from various sectors would need to
collaborate to pinpoint specific provisions that require amendment or repeal. This
collaborative approach ensures that the revised legal framework is comprehensive and
considers the perspectives and needs of all affected parties.
One major area of focus should be the simplification of regulatory processes.
Businesses, especially small and medium-sized enterprises (SMEs), often struggle
with the complex and cumbersome regulatory requirements that can stifle innovation
and growth. By streamlining these processes, the government can reduce
administrative burdens, making it easier for businesses to comply with regulations
while fostering a more conducive environment for economic activity. Simplified
regulations can also enhance transparency and accountability, making it easier to
monitor compliance and enforce laws effectively.
Furthermore, the overhaul should address emerging issues that current laws
inadequately cover. For instance, the rapid advancement of technology has outpaced
the existing regulatory frameworks, leaving gaps in areas such as cybersecurity, data
privacy, and digital commerce. Updating the legal structure to incorporate these new
realities is crucial for protecting individuals and businesses from new forms of risk
and exploitation. Clear and robust cybersecurity laws, for example, would help protect
sensitive information and critical infrastructure from cyber threats, which have
become increasingly sophisticated and pervasive.
In addition to legal reforms, there was a compelling call for the federal
government to take a proactive leadership role in research and development efforts
aimed at developing new technologies to protect our essential systems. These
essential systems, which include critical infrastructure such as power grids, water
supplies, transportation networks, and communication systems, are the backbone of
national security and economic stability. Ensuring their protection against both
physical and cyber threats is paramount.
To this end, the federal government should spearhead initiatives that bring
together public and private sector stakeholders, academic institutions, and research
organizations. Collaborative research and development (R&D) efforts can accelerate
the innovation process, leading to the creation of advanced technologies that enhance
the resilience and security of essential systems. Government funding and incentives
can play a crucial role in supporting these initiatives, ensuring that there is adequate
investment in cutting-edge research.
One specific area where R&D efforts are urgently needed is in the field of
cybersecurity. With the increasing frequency and sophistication of cyberattacks, it is
imperative to develop advanced security technologies and protocols to safeguard
critical infrastructure. This includes developing more robust encryption methods,
intrusion detection systems, and automated response mechanisms that can quickly
neutralize threats. Additionally, investing in artificial intelligence and machine
learning technologies can enhance the ability to predict and prevent cyber incidents
before they occur.
Another critical area is the development of resilient infrastructure
technologies. This involves designing systems that can withstand and quickly recover
from disruptions, whether they are caused by natural disasters, technical failures, or
deliberate attacks. Research into smart grid technologies, for example, can lead to
power systems that are more adaptable and less vulnerable to outages. Similarly,
advancements in water management technologies can ensure the sustainability and
security of water supplies in the face of environmental changes and population
growth.
Moreover, the federal government should focus on fostering innovation in the
transportation sector. Developing autonomous vehicles, smart traffic management
systems, and resilient transportation infrastructure can significantly enhance the
efficiency and security of movement within and across cities. These technologies not
only improve safety and reduce congestion but also ensure that transportation
networks remain operational during emergencies.
In conclusion, recognizing the need for clearer and more effective laws and
regulations is the first step towards addressing the challenges of modern society. By
undertaking a comprehensive overhaul of the legal framework, the government can
create a more streamlined, transparent, and responsive regulatory environment. At the
same time, by leading research and development efforts, the federal government can
drive innovation and develop advanced technologies that protect and enhance our
essential systems. These combined efforts will ensure that the nation is better
equipped to face the complexities and threats of the future, fostering a more secure
and prosperous society.
In response to the President’s Commission on Critical Infrastructure Protection
final report, President Clinton issued Presidential Decision Directive 63 (PDD 63) on
May 22, 1998. The goal of the PDD was to establish a national capability within 5
years to protect critical infrastructure from intentional disruption. PDD 63 defined
critical infrastructures as “those physical and cyber based systems essential to the
minimum operations of the economy and government” and included assets in both
public and private sectors. This definition included cyber security within the realm of
critical infrastructure for the first time.
Vulnerability Analyses. For each sector of the economy and each sector of the
government that might be a target of infrastructure attack intended to significantly
damage the United States, there shall be an initial vulnerability assessment, followed
by periodic updates. As appropriate, these assessments shall also include the
determination of the minimum essential infrastructure in each sector.
The first version of the National Infrastructure Assurance Plan for Critical
Infrastructure, called for in PDD 63, defined critical infrastructures as “those systems
and assets—both physical and cyber—so vital to the Nation that their incapacity or
destruction would have a debilitating impact on national security, national economic
security, and/or national public health and safety.”
Following the terrorist attacks on the United States on September 11, 2001,
President George W. Bush issued Executive Order 13228 on October 8, 2001. This
Executive Order established the new Office of Homeland Security and the Homeland
Security Council. Included in the Executive Order were the mission, functions,
administration, and authorities of the new Office of Homeland Security.
Executive Order 13231, which was signed on October 16, 2001 by President
George W. Bush, established the President’s Critical Infrastructure Protection Board.
The Executive Order referred primarily to information systems, but made reference to
the importance of information systems to other critical infrastructures including
telecommunications, energy, financial services, manufacturing, water, transportation,
healthcare, and emergency services.
b. Current Definition of Critical Infrastructure
In response to the terrorist attacks of September 11, 2001, Congress passed the
Uniting and Strengthening America by Providing Appropriate Tools Required to
Intercept and Obstruct Terrorism Act of 2001 (USA PATRIOT Act of 2001) (Public
Law 107-56). The USA PATRIOT Act was intended to “deter and punish terrorist acts
in the United States and around the world, to enhance law enforcement, investigatory
tools, and for other purposes.”
The PATRIOT Act, a landmark piece of legislation enacted in the aftermath of
the September 11, 2001 terrorist attacks, goes on to define critical infrastructure as
“systems and assets, whether physical or virtual, so vital to the United States that the
incapacity or destruction of such systems and assets would have a debilitating effect
on security, national economic security, national public health or safety, or any
combination of those matters.” This comprehensive definition underscores the
fundamental importance of safeguarding the nation's infrastructure, which
encompasses a broad array of interconnected systems and assets essential to the
functioning and well-being of the country.
Critical infrastructure includes a diverse range of sectors that are integral to
the everyday life of American citizens and the operation of the economy. These
sectors encompass the energy sector, which includes power generation, transmission,
and distribution systems; the water and wastewater systems sector, responsible for
providing clean drinking water and managing wastewater treatment; and the
transportation sector, which covers aviation, railways, highways, and maritime
systems essential for the movement of people and goods.
The information technology sector, which forms the backbone of
communication and data management, is also classified as critical infrastructure. This
sector includes internet service providers, telecommunications networks, and data
centers that support the digital economy and facilitate secure communications. The
financial services sector, which includes banks, stock exchanges, and payment
systems, is another vital component, ensuring the stability and integrity of the nation’s
financial system.
Healthcare and public health systems are also categorized as critical
infrastructure. This includes hospitals, clinics, pharmaceutical supply chains, and
public health agencies, all of which are crucial for maintaining public health and
responding to medical emergencies. The food and agriculture sector, which ensures
the supply of safe and nutritious food, from farming and processing to distribution and
retail, is equally critical.
Moreover, the definition extends to government facilities, which include
buildings and networks that support federal, state, and local government operations.
Emergency services, such as police, fire departments, and emergency medical
services, are also part of critical infrastructure, as they provide essential responses to
crises and disasters.
The protection of these critical infrastructure sectors is paramount because
their incapacity or destruction would have cascading effects on the nation’s security
and economic stability. For example, a significant disruption in the energy sector
could lead to widespread power outages, affecting other critical sectors such as
healthcare, water supply, and communication systems. Similarly, a cyberattack on the
financial services sector could undermine the confidence in financial institutions and
disrupt economic activities on a national and global scale.
In recognition of these vulnerabilities, the PATRIOT Act emphasizes the need
for a robust and coordinated approach to protecting critical infrastructure. This
involves collaboration between various stakeholders, including federal, state, and
local governments, private sector entities, and international partners. Each of these
stakeholders plays a crucial role in implementing security measures, sharing
information, and responding to threats.
The federal government, through agencies such as the Department of
Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency
(CISA), leads the national effort to protect critical infrastructure. These agencies
develop policies, guidelines, and best practices for infrastructure protection, conduct
risk assessments, and coordinate response efforts to incidents.
State and local governments are responsible for implementing protective
measures at the regional and community levels. They work closely with federal
agencies and private sector partners to ensure that security protocols are tailored to
local needs and threats. Additionally, they play a vital role in emergency response and
recovery efforts, providing resources and support to affected communities.
The private sector, which owns and operates a significant portion of the
nation’s critical infrastructure, is a key partner in this effort. Businesses in sectors
such as energy, telecommunications, finance, and healthcare invest in security
measures to protect their assets and services from physical and cyber threats. They
also collaborate with government agencies to share information about vulnerabilities
and incidents, enhancing the overall resilience of the infrastructure.
International cooperation is also essential, as many critical infrastructure
systems are interconnected and global in nature. For example, cyber threats often
originate from outside the United States, necessitating collaboration with international
partners to identify and mitigate risks. Multilateral organizations and agreements play
a role in facilitating this cooperation, ensuring that standards and practices for
infrastructure protection are aligned across borders.
In conclusion, the definition of critical infrastructure in the PATRIOT Act
highlights the importance of these systems and assets to the security, economic
stability, and public health and safety of the United States. Protecting this
infrastructure requires a coordinated effort among various stakeholders, including
government agencies, private sector entities, and international partners. Through
collaboration, information sharing, and the implementation of robust security
measures, the nation can enhance the resilience of its critical infrastructure and
mitigate the risks posed by potential threats and disruptions.
The President’s National Strategy for Homeland Security, issued in July 2002
and updated in October 2007, restates the definition of critical infrastructure from the
USA PATRIOT Act. The Homeland Security Act of 2002 (passed in November 2002)
uses the definition of critical infrastructure from the USA PATRIOT Act. The National
Infrastructure Protection Plan (NIPP) was released in 2006 and updated in 2009. It
was retitled NIPP 2013: Partnering for Critical Infrastructure Security and Resilience
and re-issued in 2013.
The National Infrastructure Protection Plan (NIPP) also utilizes the PATRIOT
Act definition for critical infrastructure, underscoring the significance of systems and
assets so vital to the United States that their incapacity or destruction would have a
debilitating impact on national security, economic security, public health or safety, or
a combination of these factors. The NIPP provides a comprehensive framework for
the protection and resilience of the nation's critical infrastructure, organizing it into 16
distinct sectors. Each sector encompasses a wide range of assets, systems, and
networks that are crucial for the functioning of society and the economy.
To effectively manage and coordinate efforts to protect these critical sectors,
the NIPP designates a Federal department or agency as the lead coordinator, referred
to as the Sector-Specific Agency (SSA). The role of the SSA is to facilitate the
implementation of protective measures, support sector-specific risk assessments, and
enhance collaboration among public and private sector stakeholders.
Each SSA is tasked with developing and implementing sector-specific plans to
protect critical infrastructure. These plans involve identifying and assessing risks,
implementing protective measures, and enhancing the resilience of infrastructure to
withstand and recover from disruptions. The SSAs collaborate with other federal
agencies, state and local governments, private sector partners, and international
entities to share information, resources, and best practices.
The NIPP also emphasizes the importance of public-private partnerships in
protecting critical infrastructure. Given that a significant portion of the nation's
critical infrastructure is owned and operated by the private sector, these partnerships
are essential for leveraging the expertise, resources, and capabilities of all
stakeholders. Regular communication, joint exercises, and collaborative research and
development efforts are key components of these partnerships.
In conclusion, the NIPP's use of the PATRIOT Act definition for critical
infrastructure highlights the importance of protecting vital systems and assets from a
wide range of threats. By organizing critical infrastructure into 16 sectors and
designating SSAs to lead coordination efforts, the NIPP provides a structured and
comprehensive approach to enhancing the security and resilience of the nation's
infrastructure. Through collaboration, information sharing, and the implementation of
protective measures, the NIPP aims to safeguard the essential systems that underpin
the nation's security, economy, and public health.
c. Discussion of Critical Infrastructure
From a national perspective, not all infrastructures are critical. A critical
infrastructure is a collection of indispensable assets, necessary to maintain our
standard of living. An asset, which is a component of a critical infrastructure, is
something of high importance or high value and can include people, property,
products, economic value, or information systems. Critical infrastructure can be
owned by either the public or private sector. Critical infrastructures are best selected
by each individual jurisdiction, as they are most familiar with their specific
circumstances. However, there must also be a national system as ranking
infrastructure’s importance plays a part in the expenditure of resources necessary to
harden and protect them. It must be realized that what may be deemed critical
infrastructure by a local jurisdiction may not meet the definition when compared to
other national or regional assets. An individual jurisdiction may decide they will
expend their own resources to protect what they have deemed critical without
assistance from regional or federal governments.
Critical infrastructures are very complex systems that provide the products and
services we as a society rely on every day. Quite simply, critical infrastructures are
those important assets that we want and depend on to be available and functional
when needed. Our increasing dependence on these systems has caused them to
become larger and even more complex. Critical infrastructures drive all of the
necessary functions on which our society depends and help keep our country
functioning. America’s critical infrastructures provide the foundation for our national
security, governance, economic vitality, comfort, and way of life. Continued
reliability, robustness, and resiliency of our critical infrastructures create a sense of
confidence and form an important part of our national identity and purpose.
Historically, we have just assumed that these critical infrastructures would
always be there, readily available, getting the job done. We have grown accustomed to
their output and have ignored the need to protect their ability to provide the products
and services they do, because it has never been necessary to do so. Over time these
critical infrastructures have evolved in complexity, cost, and sophistication. They have
been threatened by natural disasters and accidental damage in the past. Now, with the
use of terrorism on a global scale, they must be reevaluated and protected against
intentional acts. Little consideration was given to protect them from adversaries intent
upon their destruction.
Assets that were lightly designed and built without regard for an intentional
attack perpetrated to damage or destroy it or did not have robust security
countermeasures in place are considered “soft,” while the few that were designed and
built to be protected are said to be “hardened.” Therefore these ill protected “soft”
critical infrastructures, key resources, and key assets are vulnerable to attack and are
very brittle, unable to resist or sustain the type of damage that might result from a
terrorist attack.
Critical infrastructure, key resources, and key assets can be static or mobile.
Static assets are those that are fixed in place, such as a hospital. Mobile assets are
those that move around from place to place, such as a subway car. The attacks against
critical infrastructure, key resources, and key assets can be either a physical attack or
a cyberattack. Physical attacks are those that are conducted at the location of the asset
and employ physical weapons such as an explosive device. A cyberattack can be
executed great distances from the target, using the World Wide Web to perpetrate an
attack against a software system, such as an asset’s website. Some targets carry value
for both the damage inflicted based on their disruption and their potential for causing
mass casualties.
A power generation plant may be targeted because a successful attack can
disrupt its ability to generate and distribute electricity to its customers. This disruption
of service will have a downstream effect on people and other critical infrastructure,
key resources, and key assets, perhaps causing additional casualties and economic
damage. Some critical infrastructure, key resources, or key assets typically have large
amounts of people present in a relatively small, confined area such as a sports
stadium.
This type of asset may be targeted with a weapon such as a chemical device
because it would cause many injuries and fatalities among the attendees. Much of our
critical infrastructure, key resources, and key assets are dangerously exposed to
simple attacks, which require little or no planning or resources. The July 2005 suicide
bomb attacks against the London bus and subway system illustrate just how difficult it
can be to protect “soft” critical infrastructure, key resources, and key assets in an open
society, especially one that must be available and readily accessible to the general
public.
Critical infrastructure, key resources, and key assets are located everywhere
and anywhere. They are present in all aspects of our daily routine and are embedded
in our communities. It is easy to define them as a collection of assets present within a
jurisdiction. A jurisdiction is a responsible party that has authority and control over
the activities within a specific geographical area. A jurisdiction can be private sector
or public sector. A private sector jurisdiction is privately owned and operated by an
individual or a legal entity such as a corporation and has direct control of the asset. A
public sector jurisdiction is one in which the assets are owned by the citizens and
controlled and operated by a government agency, entity, or employee.
Critical infrastructure can be interdependent upon each other. Interdependence
is mutual dependence between things, a situation where two or more things are
dependent upon each other. An example would be the interdependency of two critical
infrastructure sectors: critical manufacturing and energy. A critical manufacturing
facility that makes the sophisticated electrical components a power station needs to
operate needs electrical power in order to manufacture their product. If a terrorist
attack against a power generation station is successful, the manufacturing facility may
not be able to make their product, and the power generating station will not have the
components it needs to operate. Therefore, the critical manufacturing facility and the
power generation station are interdependent.
A product or service is critical when either it provides an essential contribution
in maintaining a defined minimum level of national or international law and order,
public safety, economic life, public health, and environmental protection, or if the
disruption of its ability to provide product or services hurts citizens or government
administration and may endanger security. Some infrastructure is critical only when
other infrastructure is damaged.
A terrorist attack is not always designed to destroy a target. It may be designed
to exploit the target, making full use of and deriving a benefit from the critical
infrastructure, key resource, or key asset that was targeted. An example would be an
attack on a nuclear power facility, with the resultant release of radiation adversely
affecting people and the environment. An attack may also be designed to degrade or
debilitate a target—that is to make the quality or output of the asset worse. An
example would be an attack on a hospital, with the result being it could only treat
10% of its normal amount of patients.
Critical infrastructures enable Americans to enjoy one of the highest overall
standards of living in the world. Without our critical infrastructure, our economy
would fail to operate. Critical infrastructure, key resources, and key assets are both
physical and cyber based and span all sectors of our economy. Critical infrastructure,
key resources, and key assets provide the essential services on which American
society depends. The nation possesses numerous critical assets, whose exploitation or
destruction by terrorists could cause catastrophic health effects or mass casualties, or
could profoundly affect our national prestige and morale. In addition, there are critical
infrastructure, key resources, and key assets so vital that their incapacitation,
exploitation, or destruction through a terrorist attack could have a debilitating effect
on security and economic well-being.
The physical critical infrastructure, key resource, or key asset may not be
physically damaged in an attack, but it may be debilitated. An asset is considered
debilitated when it is rendered ineffective or unable to fulfill its mission of providing
essential products or services. To address this issue, a critical infrastructure, key
resource, or key asset is considered “mission critical” meaning it is essential—if its
damage or destruction would have a debilitating effect on its ability to perform its
function or provide its service. Despite our best efforts, fully protecting all of our
critical infrastructure, key resources, and key assets is not possible considering the
various scenarios that could challenge the security of America today. The challenge in
protecting critical infrastructure, key resources, and key assets is having a well-
developed prioritization system and finding the appropriate protective balance as
some assets are very resource intensive to fully protect.
We will not be able to prevent all accidental, natural, and intentional disasters
that can impact our critical infrastructure, key resources, and key assets; however, we
can work to ensure operational and structural resilience by hardening assets against
these potential disasters as appropriate. Resiliency is the capacity to reduce the
magnitude and duration of disruptive events, recover quickly after a disaster, and be
able to quickly restore the ability to provide services or products. We must now focus
on the resilience of the system as a whole—an approach that centers on investments
that make the system better able to absorb the impact of an event without losing the
capacity to function. While this might include the building of redundant assets,
resilience often is attained through the dispersal of key functions across multiple
service providers and flexible supply chains and related systems [8]. Critical assets
must heed the lessons learned from past disasters and evolve. In keeping with the all-
hazards approach, damage hardening a critical asset against damage caused in a
natural disaster will also provide protection and resiliency from an intentional act.
Constant evaluation and assessment of existing plans is necessary to ensure a critical
asset’s resiliency strategy is effective and meeting changing needs.
To help prevent terrorists from using our critical infrastructure as a weapon
against us, President George W. Bush issued Homeland Security Presidential
Directive (HSPD) 7, entitled Critical Infrastructure Identification, Prioritization, and
Protection, on December 17, 2003. This directive requires that the Department of
Homeland Security and other federal agencies collaborate with appropriate private
sector entities in sharing information and protecting critical infrastructure. HSPD 7
supersedes PDD 63. HSPD 7 adopts, by reference, the definitions of critical
infrastructure and key resources of the Homeland Security Act. It also adopts the
critical infrastructure and key asset categories from the National Strategy for the
Physical Protection of Critical Infrastructure and Key Assets. HSPD 7 has been
revoked by Presidential Policy Directive 21 (PPD 21), Critical Infrastructure Security
and Resilience issued by President Barack Obama on February 21, 2013.
During the past decade, new programs and initiatives have been established to
address specific infrastructure issues, and priorities have shifted and expanded. As a
result, Federal functions related to critical infrastructure security and resilience shall
be clarified and refined to establish baseline capabilities that will reflect this evolution
of knowledge, to define relevant Federal program functions, and to facilitate
collaboration and information exchange between and among the Federal Government,
critical infrastructure owners and operators, and SLTT entities. As part of this refined
structure, there shall be two national critical infrastructure centers operated by DHS—
one for physical infrastructure and another for cyber infrastructure.
They shall function in an integrated manner and serve as focal points for
critical infrastructure partners to obtain situational awareness and integrated,
actionable information to protect the physical and cyber aspects of critical
infrastructure. Just as the physical and cyber elements of critical infrastructure are
inextricably linked, so are the vulnerabilities. Accordingly, an integration and analysis
function (further developed in Strategic Imperative 3) shall be implemented between
these two national centers.
Terrorists will plan attacks where the possibility of success is greatest. Since
most publicly owned critical infrastructure, key resources, and key assets have been
hardened to some degree, they will likely look to attack softer targets within the
private sector. The concentration on high profile targets has diminished steadily in
response to increased efforts to protect them against well-established threats.
Historically, terrorist attacks have been planned and directed against large, high value
targets. Although terrorists have not given up aspirations to attack major, highly
visible targets in the US homeland, soft targets are the kind of targets terrorists have
traditionally targeted successfully in terms of planning, surveillance, and execution.
The recent trend has been to focus on a campaign of simple attacks against these
lightly defended soft targets.
Consider the possibility that an adversary may attack our food supply, animals,
or crops, which is known as agroterrorism. Agroterrorism is the malicious use or
threatened use of biological, chemical, or radiological agents against some component
of the agriculture sector (livestock, food supply, crops, or workers) in such a way as to
adversely impact a component of the agriculture industry, the economy, or the
consuming public. Therefore, based on the amount and importance of agriculture in
the United States, an agroterrorist attack would primarily be an attack on our
economy. CIA official Peter Probst was quoted in the October 4, 2001 New York
Times, stating “agriculture is the soft underbelly of the American economy. It’s an
absolutely vital sector, but it’s terribly difficult to protect.” Tommy Thompson, the
former US Department of Health and Human Services secretary from 2001 to 2005 in
the President George W. Bush administration, was quoted in December 2004: “For the
life of me, I cannot understand why the terrorists have not attacked our food supply
because it is so easy to do.” As of 2012, there are approximately 2.1 million farms in
the United States encompassing over 912 million acres. The 2016 forecasted net
income for farms in the United States is $71.5 billion the location and relative density
of farms in the United States, illustrates the number of potential targets and how an
attack on one may impact another thereby presenting an opportunity for attack.
Why is the US agriculture sector such an attractive target? Agriculture and
agriculture-related industries contributed $835 billion to the US gross domestic
product (GDP) in 2014, a 4.8% share. The output of America’s farms contributed
$177.2 billion of this sum—about 1% of GDP. In 2014, 17.3 million full- and part-
time jobs were related to agriculture—about 9.3% of total US employment. Direct on-
farm employment provided over 2.6 million of these jobs. Employment in the related
industries supported another 14.7 million jobs. The production of food in the United
States is so extensive (in over 31,000 food and beverage manufacturing plants located
throughout the country, 1.5 million workers were engaged in transforming raw
agricultural materials into products for intermediate or final consumption) that if even
a small number of contaminants were intentionally introduced into some part of the
food chain, such an incident could seriously damage public confidence in the safety of
the nation’s food supply and could result in staggering economic losses for the
agriculture industry [11]. There are a large number of easily accessible targets within
a relatively small area. Although spread out over several states, 70% of US beef cattle
are raised in an area with a 200 mile radius [12]. There are also a large number of
biological and chemical agents that can be introduced into the agricultural sector very
easily.
When comparing critical infrastructure, key resources, and key assets from
several different jurisdictions, it may be necessary to categorize, prioritize, or rank
assets. This categorization may be necessary to ensure that proper resources,
especially funding, are directed at the proper asset so they can be hardened and
protected. For this purpose, critical infrastructure, key resources, and key assets are
categorized based on national level of importance, state or regional level of
importance, and local community level of importance.
d. Soft Targets
Soft targets are those critical infrastructure, key resources, or key assets that
are typically privately owned, usually lack proper security or are difficult to protect
and defend because they are not perceived as an attractive target to terrorists and are
open to the general public by their very design. Security is not a primary concern at a
soft target. An adversary would generally have largely unimpeded access to large
concentrations of people utilizing the soft target. Soft targets are not designed to limit
or restrict free and easy access by the general public. Enhanced security or access
restriction would likely cause disruption of people’s normal activities, impair and
impede the normal function of the asset, and would cause the perception of adverse or
inconvenient effects on the general public. Soft targets are relatively unguarded or
difficult to secure and harden effectively. They are typically undefended civilian
assets easy to access and attack or obtain an advantage from because they are not very
secure due to their perceived low risk of exploitation. Soft targets are favored by
adversaries because they require shorter planning cycles and are easier and cheaper to
attack. Most jurisdictions have many more soft targets than hard targets. Examples of
soft targets include shopping centers, hotels, places of worship, buses, trains,
nightclubs, and restaurants.
The Islamic State (ISIS) has leveraged social media platforms and
disseminated propaganda through various channels to radicalize individuals and incite
violence against soft targets. This nefarious use of online platforms has posed
significant challenges to counterterrorism efforts worldwide, as it allows ISIS to reach
a global audience and inspire lone-wolf attackers or small cells to carry out acts of
violence.
One of the most concerning aspects of ISIS's online presence is its adeptness
at exploiting social media platforms to spread its extremist ideology and encourage
violent actions. Through platforms like Twitter, Facebook, and Telegram, ISIS
disseminates propaganda videos, images, and messages glorifying terrorism and
encouraging attacks against civilians and soft targets. These messages often target
vulnerable individuals who may feel marginalized, disenfranchised, or sympathetic to
extremist narratives.
Moreover, ISIS has also utilized encrypted messaging apps like WhatsApp and
Signal to communicate securely with its operatives and sympathizers, making it
difficult for law enforcement agencies to monitor and disrupt their activities. This
clandestine communication allows ISIS to coordinate attacks, share tactics, and recruit
new members without detection.
In addition to social media, ISIS has published English-language magazines
and online publications that serve as propaganda tools to radicalize and recruit
individuals to its cause. These publications, such as "Dabiq" and "Rumiyah," contain
articles that justify violence, provide practical guidance on carrying out attacks, and
glorify past terrorist acts. They often portray Western societies as legitimate targets
and encourage followers to strike where they are most vulnerable, such as crowded
public spaces, transportation hubs, or entertainment venues.
The emphasis on attacking soft targets is a deliberate strategy employed by
ISIS to maximize casualties and instill fear in the population. Soft targets, which
include places like cafes, restaurants, shopping malls, and cultural events, are
typically less fortified and more accessible to attackers, making them attractive targets
for terrorists seeking to inflict mass casualties with minimal resistance. By targeting
these locations, ISIS aims to sow chaos, undermine public confidence, and amplify
the impact of its attacks.
The number of soft targets will vary depending on the makeup and size of the
jurisdiction, but every jurisdiction has at least one. The intent of attacks on soft targets
will not only be to kill or injure, but to generate terror, create chaos, and intimidate the
population. Imagine a terrorist attack at a local elementary school, with coordinated
and simultaneous attacks against the local police, fire, and emergency medical
services along with the hospital. There would be immediate chaos within the
jurisdiction, which would rapidly spread to neighboring communities and eventually
the entire country.
The basic nature of our free and open society greatly facilitates the tactics and
operations espoused by terrorists and make soft targets very attractive. Critical
infrastructure, key resources, and key assets must be readily accessible to those who
need or desire access, yet be protected sufficiently to avoid damage or destruction.
This need for public access hinders our ability to prevent the effects of a successful
terrorist attack. The protection of critical infrastructure, key resources, and key assets
takes precedence over protection of soft targets as they serve the masses and are
needed to maintain our standard of living.
In January 2017, a gunman attacked a nightclub in Istanbul, Turkey, killing at
least 39 and wounding 70 during New Year’s celebrations. The shooter killed a police
officer and security guard before entering the nightclub. After he fired at nightclub
patrons and before leaving the establishment, the perpetrator changed his clothing to
blend into the crowd.
e. Hard Targets
A hard target is an asset that has sufficient security countermeasures in place
to provide a high degree of protection against a terrorist attack. Hard targets typically
have restricted access that would prevent free and easy access by the general public. A
significant amount of both physical hardening as well as administrative
countermeasures would be in place to deter an attack by an adversary. Although hard
targets are highly protected, an adversary may decide to attack anyway. A successful
attack on a hard target would not only be spectacular, but it would also be very
disruptive and have widespread consequences to those in the jurisdiction as they are
our most important assets.
Terrorist organizations often prioritize targeting what are commonly referred
to as "hard targets" due to the potential impact such attacks can have on society,
governance, and global perceptions. These targets are characterized by their
significance, strategic importance, and often fortified defenses, making them
challenging to breach. The very nature of these targets lends a symbolic weight to any
successful attack, amplifying the message of the terrorists and instilling fear and
uncertainty among populations.
Government facilities stand as symbols of authority and power, making them
prime targets for those seeking to challenge or undermine established governance
structures. Attacks on government buildings not only disrupt essential functions and
services but also serve as a direct assault on the legitimacy of the ruling authorities.
Furthermore, the symbolic value of such targets can reverberate internationally,
sending shockwaves through diplomatic channels and global security alliances.
Airports represent critical nodes in the global transportation network,
facilitating the movement of people and goods across vast distances. An attack on an
airport not only disrupts travel and commerce but also undermines confidence in the
safety and security of air travel. Given the interconnected nature of the modern world,
any disruption to air travel can have far-reaching economic and social consequences,
amplifying the impact of such attacks.
Nuclear power plants, with their potential for catastrophic consequences in the
event of a breach or sabotage, are among the most feared of all hard targets. An attack
on a nuclear facility not only poses immediate risks to public safety but also carries
the specter of long-term environmental contamination and health hazards. The
symbolic significance of nuclear power plants as symbols of technological prowess
and energy security further amplifies the impact of any successful attack, both
domestically and internationally.
Beyond the immediate physical damage and casualties, attacks on hard targets
have a profound psychological impact on societies. They shatter the illusion of
security and invulnerability, leaving populations feeling exposed and vulnerable to
future attacks. The fear and uncertainty generated by such events can be exploited by
terrorist organizations to further their agendas, whether through recruitment efforts,
propaganda dissemination, or the erosion of civil liberties in the name of security.
In response to the heightened threat posed by attacks on hard targets,
governments invest significant resources in bolstering security measures and
fortifying vulnerable infrastructure. However, despite these efforts, the dynamic
nature of terrorism means that no target can ever be entirely immune to attack. Thus,
the challenge for security agencies lies not only in preventing attacks but also in
effectively managing the consequences and mitigating the impact when they do occur.
f. Cascading Effects from Interdependencies of Critical Infrastructures
A cascading effect is a chain of events due to an act affecting a system that
causes one event to cause another event. Interdependencies between infrastructure
sectors drive these effects. It is likely that a successful attack on a particular critical
infrastructure sector will have an adverse cascading effect on other sectors. The
cascading effect is initiated by some sort of accidental, natural, or intentional event.
The impact and consequences of a successful attack can be magnified by the
cascading effect.
On August 20, 2003, there was a cyberattack on the information technology
system which had a cascading effect on the transportation system. A computer virus
was blamed for bringing down train signaling systems throughout the Eastern United
States, ultimately affecting 23 states east of the Mississippi River. The virus infected
the computer system at CSX Corporation’s Jacksonville, Florida headquarters,
shutting down signaling, dispatching, and other systems and causing delays in freight,
local commuter, and Amtrak passenger trains. An example of a cascading event would
be a successful terrorist attack that destroys a dam, and the resultant surge of water
flows into the local community causing casualties and property destruction.
Critical infrastructures are not mutually exclusive and are often dependent on
one another. There are many interdependencies and interconnections between the
various critical infrastructure sectors. In the event of an attack on one sector, these
cross-sector interdependencies will cause adverse consequences and hinder the ability
of another sector to function properly. For example, the chemical sector depends on
the transportation sector to deliver raw materials that are necessary for their
manufacturing operation, and to transport the finished manufactured products to the
market. If various key assets of the transportation sector are eliminated or services
degraded through a terrorist attack, the chemical sector will suffer losses as well as be
unable to manufacture product or move finished product to their customers.
Interconnection is when one or more sector is connected to another to provide
essential services or products. A catastrophic event in one could cause a series of
disruptions, degradation, or interruptions in essential services or production. The
communication sector and information sector are interconnected. A successful attack
on the communication sector would seriously impact the information technology
sector being able to function efficiently and effectively. These cascading,
interdependent, and interconnected effects can lead to an adversary realizing indirect
or exploitative results. Indirect effects are the hidden results that are achieved and
may not be as obvious as the direct effects.
The loss of life and destruction of the World Trade Center towers were the
direct effects of the September 11 terrorist attacks in New York City. The indirect
effect was the massive economic damage that followed. Exploitation is when a
vulnerability to attack is taken advantage of to cause even more damage. Again
referring to the September 11 attacks, the terrorist hijackers exploited a weak airport
security system to smuggle weapons aboard the aircraft which were then used as
missiles against their targets.
The Gulf Coast hurricanes of September 2005 illustrated not only the
cascading effect, but also the interdependencies among critical infrastructures, key
resources, and key assets. As a result of the hurricanes striking land, a significant
amount of critical infrastructure, key resources, and key assets was damaged or
destroyed, and this had a significant dramatic effect on the impacted communities,
showing just how intimately some critical infrastructures, key resources, and key
assets are tied together. Due to the hurricane’s impact, the remaining critical
infrastructure, key resources, and key assets were severely taxed to provide their
services or products. A tremendous amount of help was provided from nearby
unaffected critical infrastructure, key resources, and key assets to help fill the
shortfall. A successful terrorist attack against an already compromised critical
infrastructure, or against a critical infrastructure in a neighboring community that was
providing assistance, could have been disastrous.
As a result of hurricane damage to the Gulf Coast of the United States in 2005,
there was a loss of the electrical generating capability. This in turn led to the loss of
the domestic water supply, as there was no power to operate the supply pumps.
Petroleum refineries were also shut down due to the lack of electricity.
Communications systems were adversely impacted due to electrical outages. Each of
the critical infrastructures that were degraded had an effect on the emergency services
infrastructure and its ability to provide services. Firefighters were at a disadvantage
because there was no water for the fire hydrants. The lack of fuel led to fire trucks,
ambulances, and police cars sitting unused. The emergency services were unable to
communicate via radio or cellular phones. This example illustrates how the
emergency services sector, even though not directly attacked, lost its ability to provide
critical services due to the cascading, interdependencies, and interconnections on
critical infrastructures, key resources, and key assets that were degraded. All of these
issues can be traced back to the initiating event, the loss of electrical power.
Based on this example, it should come as no surprise that an adversary may try
to capitalize on the strain a natural disaster has placed on the remaining critical
infrastructure. This may lead to an increase in the threat of exploitation by adversaries
intent on further degrading critical infrastructures, key resources, key assets,
economic stability, and public morale.
g. Coordination of Critical Infrastructure Protection
The Department of Homeland Security coordinates with other appropriate
federal departments and agencies to ensure the protection of critical infrastructure,
key resources, and key assets. The Department of Homeland Security developed a
national indications and warnings architecture for critical infrastructure protection and
capabilities that facilitates (1) an understanding of baseline infrastructure operations,
(2) the identification of indicators and precursors to attacks, and (3) surge capacity for
detecting and analyzing patterns of potential attacks.
Recognizing that each infrastructure sector possesses its own unique
characteristics, the government has designated sector specific federal departments and
agencies that are responsible for coordinating the counterterrorism activities. The
Department of State and other appropriate agencies will work with foreign countries
and international organizations to strengthen the protection of US critical
infrastructure, key resources, and key assets.
America is a large country that has porous borders. This provides some unique
challenges in trying to secure the country to prevent the entry of adversaries or
weapons of mass destruction. There are long stretches of both the northern and
southern borders that are unpopulated, not secure, and not regularly patrolled by law
enforcement personnel. The United States shares a 5525 mile border with Canada and
a 1989 mile border with Mexico. Our maritime border includes over 96,000 miles of
shoreline and navigable waterways as well as a 3.4 million square mile exclusive
economic zone. There are 354 international airports and 146 seaports. All people and
goods legally entering into the United States must be processed through an air, land,
or sea port of entry. The US Customs and Border Patrol processed more than 382
million travelers at air, land, and sea ports of entry in 2015; more than 85% enter via
land borders, often as daily commuters. There are between 9 and 11 million illegal
aliens living today in the continental United States. In 2015, 102.7 million cars, 11.3
million trucks, 2.1 million loaded rail freight cars, and over 82,000 port calls by
commercial vessels entered the United States at more than 3700 terminals and 301
ports of entry [16]. There are 15 international mail facilities. An enormous volume of
trade also crosses our borders every day—some $2.309 trillion in imports and $1.51
trillion in exports were processed in 2015.
Ninety percent of the world’s general cargo moves inside seagoing shipping
containers. Nearly 95% of all imported goods arrive in the United States via container
ships. Each container can carry up to 65,000 pounds of cargo. Containers carry more
than 20 billion tons of goods through US ports and waterways each year. Over 12
million cargo containers are offloaded at US seaports each year, and more than 200
million cargo containers move between the world’s major ports each year, according
to the US Customs and Border Patrol.
Terrorism is a crime. Any crime, regardless how heinous, requires motive,
means, and opportunity. Our job is to eliminate the opportunity—vulnerabilities—at
critical infrastructure, key resources, and key assets to prevent terrorist activity. By
careful control of dangerous materials and enhanced surveillance and screening, we
can reduce the risk of terrorists obtaining and deploying their weapons. We are not
likely to eliminate motive. In order to eliminate the means and opportunity, it is
imperative that our critical infrastructures, key resources, and key assets be identified,
assessed, and have the appropriate countermeasures installed to reduce vulnerabilities.
The reason for this is simple: it is quite likely that a terrorist may try to use our critical
infrastructure, key resources, or key assets against us by involving it in an attack or
using it as a WMD. The elimination of vulnerabilities reduces the likelihood of a
successful attack.
United States customs officials divide shipping containers into two categories:
trusted and untrusted. A trusted container is the one that has been shipped by an
importer or consolidator (an intermediate that consolidates the contents or two or
more containers into one) who is known to customs officials. A trusted importer is the
one who is familiar to customs officials and has no history of smuggling or attempting
to violate US laws. The containers shipped by a trusted importer are cleared by
customs officers without any inspection or examination. Untrusted containers are
those that come from the world’s trouble spots or from new importers who are
unfamiliar to customs officials. Untrusted containers are subject to inspection and
examination. On average, overseas containers pass through 17 intermediate points
before they arrive at their final destination in the United States.
A possible terrorist attack scenario involving a shipping container being used
as a weapon against us would start out with—radiological material and explosives
being placed into a shipping container along with other commercial goods somewhere
in the Middle East. This container moves along the global supply chain for several
months, being transferred from ship to ship at the world’s container ports. Ultimately,
the container is carried to a US port of entry by a trusted shipper. The container is
offloaded from the ship and put on a truck. Since the container arrived in the United
States from a trusted carrier, it is not inspected upon arrival. The container is
transported to or near a critical infrastructure, key resource, or key asset, and the
explosive device is detonated, spreading radiological material across a wide area,
causing significant environmental and health issues.
According to the US Environmental Protection Agency, there are 471 sites in
the United States where the toll of death or injury from a catastrophic chemical
release at a chemical plant could impact between 100,000 and more than 1 million
people. A terrorist could cause a deliberate release of a chemical from a
manufacturing or storage facility, causing mass casualties and environmental damage.
For example, a terrorist could set off an explosive device on a standard railroad tanker
containing 90 tons of liquid chlorine parked on a publically accessible railroad right
of way. When the liquid chlorine is released from its container, it immediately turns
into a gas and moves downwind, hugging the ground as it travels. Anyone in the path
of the ensuing vapor cloud would be in grave danger of serious injury or death.
h. Selection of Critical Infrastructure, Key Resources, and Key Assets
It is important to select critical infrastructure, key resources, and key assets so
that informed decisions can be made concerning proper planning and sufficient
resource allocation to develop systems for their protection. Every jurisdiction,
whether public sector or private sector, is obligated to identify its critical
infrastructure, key resources, and key assets so they can be prioritized and have the
proper security enhancements developed and implemented to prevent exploitation.
This is the first step in developing protective systems.
The identification and importance of critical infrastructure, key resources, and
key assets are certainly in the eye of the beholder. It is understood that what may be
critical or key to a particular jurisdiction, whether owned by the public or private
sector, may or may not be considered critical or key when compared to and prioritized
against other assets on a regional or federal level. Each jurisdiction should identify
and assess their own critical assets to prioritize their importance to the jurisdiction,
identify the interdependencies between those assets and other systems, and prioritize
which assets need to be protected first.
Critical infrastructure, key resources, and key assets are prioritized based on
which is the most essential in regard to the function it provides to the jurisdiction it
serves, or which poses the most significant danger to life and property if threatened or
damaged. This information is necessary for developing an effective protection
strategy.
The scope and complexity of critical infrastructure pose a significant challenge
to identify which specific resources and assets are in fact critical. The selection of
critical infrastructure, key resources, and key assets is at the discretion of the local
jurisdiction or facility. Critical infrastructure, key resources, and key assets are
uniquely selected based on the particular circumstances and situation concerning the
entity involved. Critical infrastructures are not uniformly critical in nature,
particularly in a national or regional context.
The classification of infrastructure, resources, and assets as critical or key can
vary significantly depending on the context, scale, and socio-economic dynamics of a
given area. While certain entities may be deemed critical in one setting, they might
not hold the same level of significance in another.
In a small town, a modest shopping center could indeed be considered a
critical infrastructure, key resource, or key asset due to its substantial impact on the
local economy and community dynamics. Such a center may serve as a primary hub
for commerce, providing essential goods and services to residents and generating
employment opportunities. Additionally, it might serve as a social gathering place,
fostering community cohesion and serving as a focal point for local events and
activities. In this context, any disruption to the functioning of the shopping center
could have ripple effects throughout the town, impacting businesses, livelihoods, and
overall quality of life.
Conversely, in a large metropolitan city characterized by a diverse and robust
economy, the same small shopping center may not hold the same level of importance
relative to other assets and resources. In such a dynamic urban environment, there
may be numerous commercial centers, each catering to different demographic
segments or offering specialized goods and services. As a result, the loss or disruption
of one small shopping center may have a relatively minor impact on the overall
economic landscape of the city compared to larger commercial districts or major
financial centers.
However, even in a metropolitan setting, the classification of a small shopping
center as critical infrastructure or a key asset is not solely determined by its economic
contribution. Other factors, such as its role in providing essential goods and services
to nearby communities, its significance as a cultural or historical landmark, or its
function as a gathering place for local residents, can also influence its importance.
Additionally, considerations of resilience, vulnerability, and interconnectedness with
other critical systems may further shape its designation as a key asset in emergency
planning and risk management efforts.
Ultimately, the classification of infrastructure, resources, and assets as critical
or key is a multifaceted and context-dependent process that takes into account a range
of factors, including economic, social, and strategic considerations. Understanding the
unique role and significance of each entity within its specific context is essential for
effective planning, preparedness, and response to potential threats and disruptions.
The criticality of individual assets is dynamic. Criticality varies as a function
of time, risk, market conditions, population, and other critical infrastructure, key
resources, and key assets in the area. Therefore the critical infrastructure selection and
prioritization process must be constantly reviewed and revised to reflect the most
current and up-to-date situation. There are many tools available to help a jurisdiction
select critical infrastructure, key resources, and key assets based on local conditions.
Some of these are commercially available products, and some have been developed
internally.
The tools also vary in their level of complexity to use and their sophistication.
Care should be taken to select a tool that is user friendly and meets the requirements
of the jurisdiction. As an example, the internally developed “Critical
Infrastructure/Key Resource/Key Asset/Soft Target Attractiveness Matrix”. Identifies
and quantifies five important criteria associated with critical infrastructure:
occupancy, economic impact, business or service interruption, interdependencies, and
criticality.
The development of a comprehensive matrix for rating and prioritizing critical
infrastructure, key resources, key assets, and soft targets is a crucial step in enhancing
the resilience and security of jurisdictions and facilities. By systematically assessing
the importance and vulnerability of each entity, decision-makers can allocate
resources more effectively, prioritize mitigation efforts, and enhance overall
preparedness and response capabilities.
The matrix provides a structured framework for evaluating the significance of
various assets within a jurisdiction or facility. This evaluation encompasses a range of
factors, including but not limited to economic importance, societal impact, strategic
value, and potential consequences of disruption. By considering these factors
holistically, decision-makers can gain a nuanced understanding of the
interdependencies and vulnerabilities inherent in their infrastructure and resources.
One key aspect of the matrix is its ability to facilitate informed decision-
making regarding resource allocation and risk management. By identifying and
prioritizing critical assets, jurisdictions and facilities can focus their efforts and
investments on enhancing the security and resilience of those entities most essential to
their functioning and well-being. This targeted approach helps maximize the
effectiveness of limited resources while minimizing vulnerabilities and potential
consequences of disruption.
Moreover, the matrix serves as a tool for fostering collaboration and
coordination among stakeholders. By involving representatives from various sectors
and disciplines in the assessment process, jurisdictions and facilities can leverage
diverse expertise and perspectives to develop comprehensive risk mitigation
strategies. This collaborative approach enhances information sharing, promotes
mutual understanding of shared risks, and fosters a collective commitment to
enhancing security and resilience across the board.
Furthermore, the matrix facilitates a proactive approach to risk management
by enabling jurisdictions and facilities to identify potential threats and vulnerabilities
before they escalate into crises. By conducting regular assessments and updates,
decision-makers can stay ahead of emerging risks, adapt to changing threats and
vulnerabilities, and continuously improve their preparedness and response
capabilities. This iterative process of risk assessment and mitigation helps build a
culture of resilience and adaptive governance within jurisdictions and facilities.
In addition to rating and prioritizing critical infrastructure and resources, the
matrix also recognizes the importance of soft targets – entities that may not possess
the same level of strategic or economic significance but are nonetheless vulnerable to
attack or disruption. By acknowledging the potential risks associated with soft targets,
decision-makers can develop targeted strategies for enhancing their security and
resilience, thereby reducing the overall vulnerability of the jurisdiction or facility.
In summary, the development and implementation of a comprehensive matrix
for rating and prioritizing critical infrastructure, key resources, key assets, and soft
targets are essential steps in enhancing the security and resilience of jurisdictions and
facilities. By systematically assessing the importance and vulnerability of each entity,
decision-makers can allocate resources more effectively, prioritize mitigation efforts,
and build a more resilient and secure environment for all.
Students also viewed