Discussion 2
Risk
a. Introduction
As adversaries continue to threaten attacks against our critical infrastructure,
key resources, key assets, and soft targets (collectively known as critical assets), it is
imperative that we develop the necessary systems to obtain and analyze intelligence
concerning their plans. The basic premise is that the terrorist threat is credible and the
terrorists are highly motivated, well-trained and equipped, and capable of causing us
great harm. We must identify and analyze the vulnerabilities of our critical assets and
implement the appropriate security countermeasures to reduce the risk of an attack. As
part of this process, a threat identification, threat credibility, and risk assessment
process must be developed. Once those steps are completed, appropriate security
countermeasures can be developed and implemented.
The cyclical nature of risk management underscores the dynamic and ever-
evolving nature of security and resilience efforts. While implementing risk reduction
methodologies is a crucial step in enhancing preparedness and mitigating
vulnerabilities, it's equally important to continuously reassess their effectiveness and
adapt to changing circumstances. This iterative process ensures that jurisdictions and
facilities remain agile and responsive to emerging threats and vulnerabilities, thereby
maintaining a proactive stance in safeguarding critical infrastructure, key resources,
key assets, and soft targets.
Reevaluation of risk reduction methodologies involves a comprehensive
review of existing strategies, tactics, and protocols to assess their efficacy in
mitigating identified risks and vulnerabilities. This process entails gathering and
analyzing data on threat intelligence, security incidents, and operational performance
to evaluate the impact of implemented measures and identify areas for improvement.
By conducting thorough assessments, decision-makers can identify gaps, weaknesses,
or emerging risks that may have been overlooked during initial planning stages.
Furthermore, the reevaluation process provides an opportunity to incorporate
lessons learned from past experiences and incidents into future risk management
strategies. By analyzing the root causes and consequences of security breaches or
disruptions, jurisdictions and facilities can identify systemic vulnerabilities and
implement targeted interventions to address underlying issues. This proactive
approach helps prevent recurrence of similar incidents and strengthens overall
resilience against evolving threats.
Moreover, reevaluation of risk reduction methodologies involves engaging
stakeholders from across sectors and disciplines to solicit feedback, insights, and
perspectives on existing strategies and their effectiveness. By fostering collaboration
and dialogue among key stakeholders, decision-makers can leverage diverse expertise
and knowledge to enhance risk management practices and develop innovative
solutions to emerging challenges. This participatory approach promotes a culture of
shared responsibility and collective action in addressing complex security threats.
In addition to assessing the effectiveness of existing risk reduction
methodologies, reevaluation also involves scanning the horizon for new and emerging
risks or vulnerabilities that may pose potential threats in the future. This proactive
approach to risk identification allows jurisdictions and facilities to stay ahead of
evolving security threats, anticipate emerging risks, and preemptively implement
measures to mitigate their impact. By continuously monitoring trends, developments,
and emerging technologies, decision-makers can adapt their risk management
strategies to address evolving threats and vulnerabilities effectively.
Furthermore, the reevaluation process serves as an opportunity to ensure
compliance with regulatory requirements, industry standards, and best practices in
security and resilience. By conducting regular audits and assessments, jurisdictions
and facilities can demonstrate adherence to established guidelines and frameworks,
thereby enhancing public confidence and trust in their ability to manage security risks
effectively.
In summary, the cyclical process of reevaluating risk reduction methodologies
is essential for maintaining the effectiveness and relevance of security and resilience
efforts over time. By continuously reassessing existing strategies, identifying
emerging risks, and adapting to changing circumstances, jurisdictions and facilities
can enhance their preparedness, mitigate vulnerabilities, and build a more resilient
and secure environment for all.
b. The Risk of Attack
The adversary needs to have various capabilities in order to perpetrate a
successful attack. The critical infrastructure, key resource, or key asset must present
features that make it an attractive target for an adversary to attack. Once an adversary
has completed their planning and selected possible targets, they must have the
capability to execute a successful attack. The following criteria can be used to
determine whether the adversary has obtained the necessary capabilities in order to
pose a potential threat and whether the critical infrastructure, key resource, or key
asset is an attractive target.
Access to a Weapon: The ability of adversaries to acquire weapons or
materials necessary for constructing them is a critical consideration in threat
assessment. This entails evaluating the availability of illicit markets, smuggling
routes, and black market networks through which weapons may be obtained.
Additionally, factors such as the ease of access to firearms, explosives, or other
dangerous materials within a given jurisdiction or region play a significant role in
determining the level of threat posed by adversaries.
Knowledge and Expertise: Assessing whether adversaries possess the requisite
skills, resources, and expertise to plan and execute an attack is essential in gauging the
potential threat they pose. This involves considering factors such as their training,
technical capabilities, access to intelligence, and organizational structure. Adversaries
with a history of carrying out sophisticated attacks or with ties to extremist networks
may present a higher risk due to their demonstrated operational proficiency and
strategic acumen.
History of Threat: Examining past incidents targeting critical infrastructure,
key resources, or key assets provides valuable insights into the likelihood of future
attacks. Patterns of previous attacks, including tactics, techniques, and procedures
employed, can inform risk assessments and help identify vulnerabilities that
adversaries may exploit. Moreover, intelligence indicating heightened interest or
intent to target specific assets enhances situational awareness and informs proactive
security measures.
Critical Asset Visibility: The significance of a critical infrastructure, key
resource, or key asset within society plays a pivotal role in determining its
attractiveness as a target to adversaries. Assets that hold economic, cultural, financial,
or symbolic importance are more likely to be targeted due to their perceived value or
impact on societal stability. Understanding the symbolic or strategic significance of an
asset helps prioritize security measures and allocate resources effectively.
Critical Asset Accessibility: Assessing the physical accessibility of critical
assets to adversaries is essential in evaluating the feasibility of potential attacks.
Factors such as proximity to population centers, ease of entry, and existing security
measures influence the vulnerability of assets to hostile actors. Vulnerabilities in
perimeter security, surveillance systems, or access control mechanisms may increase
the likelihood of successful attacks and necessitate heightened vigilance and
protective measures.
Expanding on these factors enables a comprehensive understanding of the
threat landscape and informs risk mitigation strategies aimed at safeguarding critical
infrastructure, key resources, and key assets from potential adversaries. By
continuously assessing and adapting to evolving threats, stakeholders can enhance
security resilience and mitigate the impact of hostile actions on societal stability and
well-being.
Examining the critical asset population involves a detailed analysis of the
demographics surrounding the infrastructure, resource, or asset in question.
Understanding the population dynamics can provide insights into the potential
attractiveness of the asset as a target for adversaries. Factors such as population
density, composition, socioeconomic status, and cultural or religious affiliations may
influence the perceived value of the asset to adversaries. For example, assets located
in densely populated urban areas or areas with a high concentration of specific
demographic groups may be deemed more attractive targets due to the potential for
causing mass casualties or instigating social unrest. Additionally, assets with symbolic
or cultural significance to certain demographic groups may be more likely to be
targeted as a means of conveying a message or inciting fear.
Assessing the critical asset value involves evaluating the potential impact of
its degradation or destruction on society at large. This entails considering the asset's
role in supporting essential services, economic activity, public safety, and overall
societal well-being. Assets that are integral to the functioning of critical infrastructure
systems, such as transportation networks, energy grids, or communication systems,
may have far-reaching consequences if compromised. Similarly, assets with cultural,
historical, or symbolic significance may elicit emotional or psychological responses
from the public, amplifying the societal impact of their loss or damage. Understanding
the value of the asset helps prioritize protective measures and allocate resources
effectively to mitigate the potential consequences of an attack.
Analyzing the security systems in place involves assessing the effectiveness of
existing countermeasures in mitigating the various threats posed by adversaries. This
includes evaluating the physical security infrastructure, such as barriers, access
controls, surveillance systems, and security personnel, as well as cybersecurity
measures, emergency response protocols, and resilience planning. Additionally,
considering the adaptability and scalability of security systems to address evolving
threats is crucial in maintaining robust defense mechanisms. Identifying gaps or
vulnerabilities in existing security systems allows stakeholders to implement targeted
enhancements and improvements to strengthen overall resilience and readiness to
respond to potential threats effectively.
Expanding on these factors enables a comprehensive understanding of the risk
landscape surrounding critical infrastructure, key resources, and key assets. By
conducting thorough assessments and analyses, stakeholders can develop proactive
risk management strategies tailored to address the unique challenges and
vulnerabilities associated with each asset. Continuously monitoring and reassessing
the risk environment allows for timely adjustments to security measures and ensures
the ongoing protection of critical assets against potential threats posed by adversaries.
c. Risk
Risk, in its basic form, has three components: (1) there must be a threat to a
critical asset; (2) the critical asset must be vulnerable to a threat; and (3) there is an
adverse consequence or adverse impact if an attack against a critical asset is
successful. Therefore, Risk = Vulnerability × (Threat × Consequence).
In this formula, the “threat” segment represents the likelihood of an attack.
The “consequence” segment represents the severity or the effect of the loss of the
critical asset to the jurisdiction should the attack succeed. Combining these two
determines the likelihood and severity. The “vulnerability” segment represents the
countermeasure system effectiveness. If the countermeasure system effectiveness is
rated high, then the vulnerability is correspondingly low. Combine this rating with the
likelihood and severity rating and the overall risk rating is determined.
Managing a security risk posed by an adversary means defining what the risk
to the critical asset is, determining the likelihood of an attack, assessing the relative
magnitude (or severity) of the risk, identifying the vulnerabilities, and installing
security countermeasures.
It should be noted that there is no way to protect against every threat that an
adversary can make against a critical asset. There is no such thing as absolute security,
regardless of the time, effort, money, and material invested, which assures 100%
protection against all possible threats, at all times; to do so would involve exorbitant
costs and would impede the free and easy access that critical assets and soft targets
often need in order to make their product or provide their service. Therefore, the goal
of the risk management process is not necessarily to eliminate all risk, but to manage
the risk posed by an adversary to an acceptable level, at an acceptable cost, within
tolerable limits. This technique is known as risk minimization.
We can expand the mathematical formula for risk that we discussed earlier to
refine our efforts in estimating risk. In this example, we will add two additional
factors: the value of the critical asset and the likelihood of an attack. To properly
estimate risk, a number of factors must be considered. The first is to determine the
value of the critical asset, in terms of the products or services it provides to the
jurisdiction. The vulnerabilities that exist at the critical asset and could be exploited
by an adversary are quantified. Next, identify and rate the threats that could cause
harm to the critical asset. The likelihood of an attack is predicted, and the adverse
consequences of a successful attack are determined. The risk formula presented above
can be expanded so that the risk from an attack on a critical asset can be defined
mathematically as Risk = (Value) × (Vulnerabilities) × (Threats) × (Likelihood) ×
(Consequences).
Acceptable risk is a measure of the amount of risk that will be tolerated by an
individual, group, jurisdiction, or society as a whole in exchange for the benefits of
having access to or use of something. Whether a risk is acceptable or not will depend
on the advantage that the person or group perceives to be obtainable in return for
taking the risk.
There are times when a threat poses a risk to people, information, the
economy, or property, which is so severe that it cannot be considered acceptable. This
is known as an unacceptable risk. When unacceptable risk is present, more work must
be done to mitigate the adverse effects posed by the threat by implementing additional
risk reduction measures until the level of risk becomes acceptable.
Risk analysis methodology uses specific scenarios to evaluate the system
effectiveness of the critical asset’s security systems against the threat identified in the
threat assessment. Risk analysis is a detailed identification, examination, and
assessment performed to understand the nature of unwanted, negative consequences
resulting from undesired events. The level of risk is based on (1) the value of the
critical assets, (2) threats to the critical assets, and (3) their vulnerabilities and
likelihood of exploitation.
As part of the critical infrastructure, key resource, and key asset protection
process, risk analysis occurs when a jurisdiction determines that one or more of the
critical assets that were identified in the inventory step are threatened and vulnerable
to deliberate attacks by an adversary, by natural disasters, or by accidents. Risk
analysis begins with an examination of the negative effects of the degradation or loss
of a critical asset. The likelihood of the occurrence is determined, and appropriate
security countermeasures are developed and implemented. These scaled
countermeasures should be appropriate to the threat posed against the critical asset.
Following this action is an evaluation of the cost of the security countermeasures in
terms of available resources.
Evaluation of System Effectiveness. The ability of the existing security system
to prevent undesired events is evaluated. An overall assessment is conducted of the
effectiveness of existing security countermeasure systems, both administrative and
physical, provided internally or externally to the critical asset, and assigning an
overall risk. The existing security countermeasures should be assessed for system
effectiveness in terms of detection of the adversary before they can get into position to
perpetrate an attack; the ability to delay an adversary as they move toward the target if
they penetrate the outer layer of security countermeasures; internal and external
response capabilities in the event of an attack; internal and external mitigation
capabilities to minimize the adverse consequences of an attack; and overall security
system integration. System integration is evaluated based on whether the detection,
delay, response, and mitigation attributes occur in a timely manner, and whether they
have been practiced and demonstrated effective through exercising. System
effectiveness is determined by the most vulnerable attribute rating. The weakest link
is the most susceptible to exploitation by an adversary.
Risk analysis tools enable personnel to assess, compare, and select effective
countermeasure proposals and potential upgrades to determine which plans and
countermeasures should be implemented. The probable negative effects caused by
doing nothing to prevent the degradation or loss of a critical asset are then weighed
against the cost of doing something with protective measures. Decision-makers
should conclude that a risk is unacceptable if the impact of the degradation or loss of
the critical asset will be catastrophic to the jurisdiction. Based on the evaluations and
assessments performed, the critical assets that are susceptible to compromise by the
various threats through the exploitation of system vulnerabilities will be identified. A
combination of the impact of loss rating and the vulnerability rating can be used to
evaluate the potential risk to the critical asset from a given threat.
Risk analysis can be quantitative or qualitative, but in most cases, it is partly
both. There are many variants of risk analysis that are known by many different
names—hazard analysis, consequence analysis, worstcase analysis, fault tree analysis,
failure modes and effects analysis—and there are numerous models and tools that can
be used in a systematic assessment. Whether quantitative or qualitative, simple or
complex, some type of systematic analysis of the risks needs to be done in all cases to
serve as the basis for developing an effective risk management strategy. Risk analysis
is a continuous process. The risk assessment process fosters a risk-aware culture and
establishes a philosophy of timely response by critical asset management. When new
security countermeasures are implemented, a new assessment should be conducted to
ensure the intended benefits were realized and no new vulnerabilities or risks have
been created by the implementation of the enhancements. This assessment should
identify any changes that were made to the critical asset, threat, and vulnerabilities.
This is particularly important as new threats can emerge or existing threats can evolve
and adapt to security countermeasures.
Quantitative relates to, concerns, or is based on the amount or number of
something. Risk is capable of being measured or expressed in numerical terms.
Quantitative risk analysis is a formalized and specialized method of estimating the
magnitude of risk by calculating a numerical value for both consequences and
likelihood. It provides a degree of objectivity for ranking risks and establishing
priorities for protective security countermeasures. The approach employs two
fundamental elements: the probability of an event occurring and the likely loss should
it occur. The advantage of a quantitative analysis is that it provides a measurement of
the magnitude that can be used in the cost–benefit analysis of the recommended
security countermeasures. The disadvantage is that depending on the units in which
the measurement is expressed, the meaning of a quantitative analysis may be unclear,
requiring the result to be interpreted in a qualitative manner.
Qualitative analysis involves distinctions based on qualities. Qualitative risk
assessment usually uses a matrix. This methodology uses a qualitative, event-
descriptive, scalable table for hazard likelihood and consequences by reviewing
considerations such as people, assets, environmental damage, financial aspects,
business or service interruption, and corporate reputation.
Qualitative risk analysis is by far the most widely used risk analysis
methodology. The advantage of a qualitative risk analysis is that it provides a relative
prioritization of the specific risks that an attack may pose and identifies immediate
areas for improvement to reduce the risks posed by the vulnerabilities present at the
critical asset. The disadvantage of qualitative risk analysis is that it does not provide
specific quantifiable measurements of the magnitudes of the impact, thereby making
the cost– benefit analysis difficult.
The soft target to be evaluated in this example is a local shopping center. The
shopping center contains 100 stores, with 800 generally unskilled, part-time
employees working at any given time. The stores include retailers, service providers,
and a food court. Competition between the stores is fierce. The shopping center’s
hours of operation are 9:00 a.m. until 10:00 p.m., 7 days per week. There is an
average of 3000 shoppers in the shopping center at any given time, serving primarily
middle income clientele. The shopping center generates approximately $1,000,000 in
gross sales daily and pays $1,250,000 in property taxes to the municipality annually.
The shopping center pays $21.9 million in sales tax to the state annually. The
shopping center has an insured replacement cost of $150,000,000 and the inventory of
the various stores is insured for $75,000,000. Deliveries to the stores in the shopping
center occur between 8:00 a.m. and noon, Monday through Friday. There are a total of
eight security guards on site during normal business hours. The security guards are
hired from a private company, are unarmed, and have only basic security training.
There are no security guards present during nonbusiness hours. Each store has a
metal, roll-down security door that is closed and locked when the store is closed. All
entrances to the shopping center, as well as the individual stores, are equipped with a
burglar alarm system. Typical response time of the local police department to the
shopping center is 5 minutes.
A Risk Acceptance Authority (RAA) plays a pivotal role within an
organization or jurisdiction by wielding the financial and organizational authority
necessary to effectively manage risks. Tasked with the responsibility of identifying,
assessing, and addressing potential risks, the RAA operates at the nexus of strategic
decision-making and risk management.
At its core, the role of the RAA is multifaceted, encompassing a range of
duties and responsibilities aimed at ensuring the resilience and viability of the
organization or jurisdiction in the face of uncertainty. One key aspect of the RAA's
role is the formulation and implementation of risk mitigation strategies. This involves
analyzing identified risks, evaluating their potential impact, and devising proactive
measures to either reduce, retain, or transfer these risks.
In addition to risk mitigation, the RAA is also tasked with the crucial
responsibility of risk retention. This entails assessing the feasibility and implications
of assuming certain risks within acceptable thresholds. By carefully weighing the
potential costs and benefits of retaining specific risks, the RAA ensures that the
organization or jurisdiction maintains a balanced risk profile that aligns with its
overarching objectives and risk appetite.
Furthermore, the RAA serves as a pivotal liaison between various
stakeholders, including executive leadership, department heads, and external partners.
Through effective communication and collaboration, the RAA facilitates informed
decision-making processes that take into account the diverse perspectives and
interests of all relevant parties.
Beyond risk management itself, the RAA also plays a vital role in fostering a
culture of risk awareness and accountability within the organization or jurisdiction.
By promoting a proactive approach to risk identification and mitigation, the RAA
helps cultivate a climate where risks are acknowledged, understood, and addressed in
a systematic and strategic manner.
Overall, the role of the Risk Acceptance Authority is integral to the effective
governance and sustainability of any organization or jurisdiction. By leveraging their
financial and organizational authority, coupled with their expertise in risk
management principles and practices, the RAA plays a crucial role in safeguarding the
interests and long-term viability of the entity they serve.
d. Risk Management
Risk is present in everything we do. However, risk can be controlled. It is up
to us to control and minimize the unnecessary risks faced each day. Risk management
is a systematic, analytical process. Risk management involves using all of the
information gathered during the risk analysis and assessment processes to evaluate
security policy options. Risk management is the process involved in the identification,
selection, and adoption of security measures justified by the identified risks to a
critical asset, and the reduction of these risks to acceptable levels that reflects the best
combination of security and cost. The goal of risk management is to enable
individuals and organizations to isolate separate risks and to identify potential
mitigation options. The challenge of risk management is to find the balance between
protecting critical assets, not interfering with the primary mission of the critical asset,
and avoiding fiscal collapse in the process of implementing security countermeasures.
Each jurisdiction must take the responsibility to determine the amount and
type of risk it is willing to accept. The decision about accepting residual risk is based
on the risk assessment process and cost–benefit analysis to implement the appropriate
security countermeasures. When attempting to implement the appropriate security
countermeasures, it is sometimes helpful to remember the acronym ALARP, which
stands for as low as reasonably practicable. ALARP means that a residual risk is low
enough and that attempting to make it lower would actually be more costly than any
benefit likely to come from reducing the risk further. The ALARP principle arises
from the fact that it would be possible to spend infinite time, effort, and money
attempting to reduce all risks to zero.
Accept No Unnecessary Risks. If all the hazards that could have been detected
have not been detected, then unnecessary risks are being accepted by the critical asset.
This reemphasizes the need for a strong intelligence gathering and evaluation process
involving not only law enforcement but critical asset personnel. Once the intelligence
information has been gathered and analyzed, it must be communicated to the
appropriate levels of personnel within the organization to ensure the appropriate
security countermeasures can be implemented.
Make Risk Decisions at the Appropriate Level. Risk decisions should be made
at the lowest possible level in the organization. This will allow for the timeliest
decision to be made and allow for the quickest response time to implement
appropriate security countermeasures. Appropriate personnel should be empowered
and assigned the resources to make and implement these risk management decisions.
Accept Risks When the Costs Outweigh the Benefits. The fundamental
objective of risk management is to minimize and ultimately eliminate risk. Someone
will need to make the decision not to implement a particular security countermeasure
to address a specific threat. This decision must be made after a careful evaluation of
the threat, the risk, the security countermeasures, and the cost–benefit ratio.
Everything can be protected; it’s just a matter of time, money, and resources.
Sometimes, it is more practical to accept the risk based on the analysis that an attack
is unlikely to occur or will be unsuccessful.
Integrate Risk Management into Operations and Planning at All Levels. Risk
management must be incorporated at all levels of an organization in everyday
planning and security operations. Risk management must be conducted at the source
in order for the timeliest decisions to be made.
Senior management's commitment to ongoing improvements in security is not
merely a procedural checkbox; it's a fundamental cornerstone of organizational
resilience and effectiveness. This commitment manifests in various ways, from the
formulation and enforcement of robust security policies and procedures to the
allocation of adequate resources to support these efforts. Additionally, senior
management's commitment is reflected in their proactive communication of security
priorities and expectations throughout the organization. By consistently reinforcing
the importance of security and demonstrating a willingness to invest in its
enhancement, senior management sets the tone for a culture of vigilance and
accountability.
Moreover, management's commitment to security extends beyond rhetoric to
tangible actions that prioritize risk mitigation and preparedness. This may include
regular reviews and updates of security protocols in response to evolving threats, as
well as the establishment of clear accountability structures to ensure compliance with
security standards. Furthermore, senior management's commitment to ongoing
improvements serves as a catalyst for innovation, encouraging the exploration of new
technologies and strategies to enhance security posture and adapt to emerging
challenges.
Recognizing employees as frontline players in identifying and managing risks
underscores the importance of cultivating a culture of active engagement and
empowerment within the organization. Employees possess invaluable insights and
perspectives that can contribute to the early detection and mitigation of security
threats. As such, providing employees with a direct conduit to management to
communicate suggestions for improvement and report suspicious occurrences is
essential for maximizing the effectiveness of the organization's security efforts.
Empowering employees to actively participate in security initiatives involves
more than just soliciting feedback; it requires fostering an environment where
employees feel supported and encouraged to speak up about potential security
concerns without fear of reprisal. This may involve implementing anonymous
reporting mechanisms or providing regular training and awareness programs to
educate employees about the importance of security awareness and vigilance.
Furthermore, effective employee participation in security efforts relies on clear
communication channels and well-defined processes for reporting and addressing
security incidents. By establishing transparent procedures for handling reports of
suspicious activity and providing timely feedback on the outcomes of such reports,
organizations can reinforce the importance of employee engagement in maintaining a
secure work environment.
In summary, management commitment and employee participation are two
critical pillars of effective security management. By demonstrating a steadfast
commitment to ongoing improvements and empowering employees to actively
contribute to security initiatives, organizations can enhance their resilience against
security threats and foster a culture of collective responsibility for safeguarding assets
and resources.
Training. Employees and contractors must have a thorough understanding of
the security risks, threats to the critical asset, and risk management plan. They should
be trained to recognize suspicious activities, how to report these concerns, what
actions to take, and emergency procedures. Periodic emergency response drills and
exercises involving all personnel should be conducted, and at least one drill or
exercise per year should involve outside emergency response and law enforcement
agencies.
Standard Operating Procedures. Critical assets should develop and implement
comprehensive standard operating procedures that provide clear instructions to all
employees and contractors as regards security and risk management procedures.
Applicable employees should be trained on their responsibilities in the risk
management plan and emergency response plan. Incident Reporting. All potential
security-related incidents should immediately be reported to management and
investigated by law enforcement authorities if appropriate. Corrective actions to
improve security and reduce risk should be developed and implemented in response to
each security incident reported. Emergency Preparedness and Response. If all else
fails, critical assets should have a comprehensive and specific emergency
preparedness and response plan in the event security is breached and an attack is
launched against the critical asset. As a minimum, each employee should know his/her
responsibilities in the emergency response plan and the emergency evacuation
procedure.
Based on the results of the risk analysis, the next step in the process is to
identify security countermeasures that will lower the risk posed to the critical asset to
an acceptable level. There are usually numerous risk reduction opportunities for
which various kinds of interventions could reduce the risk. Based on the risk analysis
results, the most important risks associated with current operations should be
prioritized for immediate remediation. Options include new security countermeasures,
modification of existing security countermeasures, and the removal of security
countermeasures considered unnecessary or obsolete. As it is impossible to
completely eliminate all risk, residual risks should be identified and quantified so that
they can be evaluated and an informed determination can be made as to whether or
not they are acceptable.
Once security countermeasures have been meticulously installed and
rigorously implemented, the journey towards ensuring organizational safety and
resilience is far from over. In fact, it marks the beginning of a crucial phase:
evaluation and ongoing assessment. This stage is essential to ascertain not only the
effectiveness of the implemented countermeasures but also their alignment with the
overarching security objectives of the organization.
The evaluation of security countermeasures encompasses a multifaceted
approach that delves into various dimensions of their performance and impact. Firstly,
it involves conducting comprehensive assessments to gauge the extent to which the
countermeasures have achieved their intended purpose. This entails examining key
performance indicators and metrics to measure the effectiveness of the
countermeasures in mitigating identified risks and enhancing the overall security
posture.
Furthermore, the evaluation process extends beyond mere performance
metrics to encompass a holistic analysis of the countermeasures' functionality,
reliability, and adaptability. This includes assessing their ability to withstand evolving
threats and changing operational environments, as well as their compatibility with
existing systems and processes. By conducting thorough evaluations, organizations
can identify any potential gaps or shortcomings in the implemented countermeasures
and take proactive measures to address them.
Moreover, the evaluation of security countermeasures is not a one-time
endeavor but rather an ongoing and iterative process. As security threats continue to
evolve and new vulnerabilities emerge, organizations must remain vigilant in
monitoring the effectiveness of their countermeasures and adapting them accordingly.
This requires establishing robust mechanisms for continuous monitoring and
feedback, as well as regular reviews and updates to ensure that the security measures
remain relevant and effective in the face of changing circumstances.
Additionally, the evaluation process provides valuable insights into the overall
effectiveness of the organization's security strategy and infrastructure. By analyzing
the outcomes of the evaluations, organizations can identify patterns, trends, and areas
for improvement, which can inform future security planning and decision-making.
Furthermore, the findings of the evaluation process can serve as a basis for refining
security policies, procedures, and training programs to enhance the organization's
resilience and responsiveness to security threats.
In conclusion, the evaluation of security countermeasures is a critical
component of effective security management, serving to validate their effectiveness,
identify areas for improvement, and inform ongoing security planning and decision-
making. By adopting a proactive and systematic approach to evaluation, organizations
can ensure that their security measures remain robust, adaptive, and aligned with their
overarching security objectives.
The applicable threat, vulnerability, risk, and security countermeasure
information must be shared with all applicable parties. This information must be
communicated to ensure that all affected parties fully understand the process of and
information generated by the risk analysis, and their responsibilities in ensuring the
integrity of the security countermeasures and reducing the risk to the critical asset.
The risk management process is a never-ending process. Risk management
demands continuous improvement. Even though the threats and vulnerabilities have
been assessed, and security countermeasures installed, the process is not complete.
Adversaries continue to develop new tactics, and threats continue to evolve. The
implementation of security countermeasures may very well address one vulnerability,
but inadvertently create another.
Therefore, the next step in the risk analysis process is to start over and
reevaluate the vulnerabilities and the impact of a loss, taking into consideration the
newly implemented security countermeasures as well as changes in the socio-political
landscape. A reevaluation of the vulnerabilities and risks must be completed after
security countermeasures have been implemented to see if anything was missed on the
original analysis, or if the security countermeasures have created new vulnerabilities
and risk.
The objective of identifying countermeasure options is to provide the RAA
with countermeasures or groups of countermeasures which will lower the overall risk
to the critical asset to an acceptable level. By evaluating the effectiveness of possible
countermeasures against specific adversaries using a scaled approach that is
threatbased, the most cost-effective options can be determined. Each option should
also include the expected costs and the amount of risk the RAA will accept by
selecting a particular option. All countermeasure options must have the cost
information attached so the RAA will be able to balance the value of the
countermeasure option against available resources. Once the countermeasures have
been selected and implemented, they must be evaluated. Scrutinize the
countermeasures with the eye of your adversary. What will they see and experience?
How will they evolve and adapt?
e. Risk Assessment and Management Approach
Once all of the critical assets have been inventoried, they must be prioritized
to reflect their importance to the specific jurisdiction and to allow for proper resource
allocation. The Department of Homeland Security (DHS) defines criticality
assessment as follows: “A systemic effort to identify and evaluate important or critical
assets within a jurisdiction. Criticality assessments help planners determine the
relative importance of assets, helping to prioritize the allocation of resources to the
most critical assets.” Typically, people are a jurisdiction’s most critical asset and
therefore are most at risk and require protection. Asset criticality is defined as a
critical infrastructure, key asset, or key resource’s perceived value or the significance
of its system in the event of a loss.
The criticality of an asset is determined by evaluating the consequences if the
integrity and/or availability of the asset or the asset function are compromised.
Critical assets are rated in terms of their importance; this rating is used to determine
which critical assets get priority in terms of resources for the implementation of
security countermeasures. In order to prioritize them, they should be assigned an
importance value. There are a number of asset value scales available, but the principle
is the same: higher asset values reflect a more significant loss.
Very high indicates substantial loss of life or irreparable, permanent, or
prohibitive costly damage to the critical asset. High means loss or serious and costly
damage of the critical asset but no loss of life. Medium high indicates no loss of life
but serious and costly damage to the critical asset but no significant loss of functional
capability, while medium means minor loss or damage of the critical asset and no loss
of life. Medium low indicates minor loss or damage of the critical asset which would
have minor consequences, while low means loss or damage of the critical asset would
have low consequences or impact. Very low indicates insignificant loss or damage of
the critical asset which would have negligible consequences or impact.
The jurisdiction to be assessed in this example is a threestory elementary
school. The school has 1000 students and 50 staff. The scenario involves an adversary
who hijacks a gasoline tank truck loaded with 8800 gallons of gasoline. The truck is
driven into the main lobby of the school and the gasoline is ignited. An assessment
team is assembled to develop a list of critical assets, assign an asset value, and
prioritize the assets for protection.
Since September 11, 2001, we have lived under the increased threat that
terrorists may attempt additional attacks against our country. A threat is simply the
potential for an attack. Threats come in different forms and from different sources. It
is important to understand who the people are who intend to cause harm. It is also
essential to understand the weapons and tactics that could be used to cause harm.
Threats from outside the critical asset could affect people and the critical asset itself
and may involve trespassing, unauthorized entry, theft, burglary, or vandalism.
Threats from inside the critical asset may arise from inadequate designs, management
systems, staffing, training, or other internal problems. These may include theft,
substance abuse, sabotage, disgruntled employee or contractor actions, or workplace
violence, among others. Threats are not restricted to people and property and could
also involve sensitive critical asset information. Outsiders, employees, or contractors
could pose threats to the critical asset. They could also pose a threat to computer-
controlled equipment. These threats may include breaches in data access and storage,
uncontrolled dissemination of information, destruction of information or automated
information systems, and the disruption of control systems.
life here in the United States. There is a generalized concern at all levels that
the terrorism threat is real, but the concern is not universally accepted. There is a trend
toward more aggressive and frequent foreign and domestic terrorism. The terrorist
threat is dynamic and has evolved in response to social, political, and technological
changes. Terrorist attacks will continue to evolve with even more efficient ways
discovered to cause death and destruction. The tactics and weapons that can be used
are limited only by the adversary’s creativity. Threat analysis includes not only the
likelihood of becoming a target, but also whether or not the security countermeasures
that are implemented are sufficient to discourage an attack.
To assist in the risk analysis process, a listing of each potential threat and type
of attack should be compiled. This list would capture the various specific types of
threats from each of the three categories that may occur and adversely affect a critical
asset. The threat must be described in specific terms to determine a critical asset’s
vulnerability and to establish protective security countermeasures. This description
should include the tactics that adversaries will use to attack the critical asset. These
types of threat descriptions can be used to design detailed protective security systems
to mitigate the threat.
Threats against a target represent a diverse spectrum of potential risks that
organizations and individuals must contend with on a daily basis. These threats can
arise from various sources and manifest in different forms, each presenting unique
challenges and implications for the safety and security of the target. By categorizing
threats based on their origin and nature, stakeholders can gain a better understanding
of the underlying factors driving these risks and tailor their mitigation strategies
accordingly.
Natural threats encompass a broad range of environmental phenomena and
natural disasters that are beyond human control. These can include events such as
floods, hurricanes, earthquakes, wildfires, and severe storms. While their occurrence
may be unpredictable, their potential impact on the target can be significant, leading
to property damage, disruption of operations, and, in some cases, loss of life.
Recognizing the inherent vulnerabilities posed by natural threats, organizations and
communities must adopt proactive measures to enhance resilience and preparedness,
such as implementing robust disaster recovery plans, fortifying infrastructure against
potential hazards, and investing in early warning systems and emergency response
capabilities.
Accidental threats stem from unintentional events or human error that can
result in adverse consequences for the target. These threats may include incidents such
as fires, chemical spills, industrial accidents, equipment failures, or structural
collapses. While they may not be deliberate in nature, accidental threats can still pose
significant risks to the safety and security of individuals and assets. Therefore,
organizations must prioritize risk mitigation efforts to prevent or minimize the
likelihood of such incidents occurring, as well as establish effective response
protocols to mitigate their impact if they do occur. This may involve implementing
stringent safety protocols, conducting regular inspections and maintenance checks,
and providing comprehensive training to personnel to promote a culture of safety and
risk awareness.
Intentional threats represent deliberate acts carried out with the intent to cause
harm or disruption to the target. These threats can take various forms, including
criminal activities, acts of terrorism, cyberattacks, espionage, or sabotage. Unlike
natural or accidental threats, intentional threats are motivated by malicious intent and
often involve premeditated planning and execution. As such, they pose a significant
challenge to security and law enforcement agencies tasked with preventing and
mitigating their impact. Addressing intentional threats requires a multifaceted
approach that encompasses proactive threat intelligence gathering, robust security
measures, effective risk assessment, and coordinated response strategies. Additionally,
fostering collaboration and information sharing among relevant stakeholders is
essential to effectively identify, disrupt, and neutralize potential threats before they
materialize.
Regardless of their origin or nature, threats have the potential to cause
undesirable impacts on the target, ranging from financial losses and reputational
damage to physical harm and societal disruption. By understanding the potential
consequences of different types of threats, stakeholders can prioritize their risk
mitigation efforts and allocate resources more effectively to address the most pressing
vulnerabilities. Additionally, conducting comprehensive risk assessments and scenario
planning exercises can help organizations anticipate and prepare for potential threats,
enabling them to respond more effectively and resiliently when faced with adversity.
In conclusion, threats against a target can be categorized based on their origin
and nature, including natural, accidental, and intentional threats. By recognizing the
distinct characteristics of each type of threat and their potential impact, stakeholders
can develop tailored risk management strategies to enhance resilience and safeguard
against adverse consequences. Moreover, fostering a culture of vigilance,
preparedness, and collaboration is essential to effectively mitigate the diverse array of
threats faced by organizations and communities in today's complex and dynamic
threat landscape.
The DHS defines threat assessment as follows: “A systematic effort to identify
and evaluate existing or potential terrorist threats to a jurisdiction and its target assets.
Due to the difficulty in accurately assessing terrorist capabilities, intentions, and
tactics, threat assessments may yield only general information about potential risks.”
The threat assessment is used to evaluate the likelihood of an attack against a critical
asset. It is a decision support tool which helps to establish and prioritize security
program requirements, planning, and resource allocations. The first most important
step in the risk assessment and management process is a threat assessment. A threat
assessment is a statement of threats that are related to vulnerabilities of a critical asset.
A threat assessment considers all potential adversary threats, as well as their
capabilities, against a specific critical asset. Threat and risk assessments are widely
recognized as effective decision support tools for prioritizing security countermeasure
investments. The threat assessment should examine supporting information to
evaluate the likelihood of occurrence for each specific threat.
Threat is expressed as a function of the likelihood that an adversary will
successfully exploit a vulnerability present at a critical asset. This vulnerability can be
triggered accidentally or intentionally. Without a vulnerability that can be exploited,
the threat does not pose a risk to the target. In the threat assessment step, the analyst
focuses on the adversaries or events that can adversely affect a specific asset (the
potential target). Threat assessments replace intuition and vague generalities with
reliance on data and information obtained from research and interviews. Intelligence
is the foundation of threat assessment. The threat is evaluated in terms of an
adversary. The threat an adversary poses is evaluated in terms of capability, history,
and intent to cause an unwanted event and a proven track record of successful attacks
against similar critical assets. The threat assessment step enables a critical asset to
maximize priority of effort, manpower, and budget to scaled countermeasures and
plans appropriate to the threat.
After the threats and their potential impacts have been identified, an analysis
of the probability of these threats being carried out must be completed to properly
evaluate the risk. Each threat is assigned a value, either quantitative or qualitative.
After the severity of each undesired event and the likelihood of attack for each
adversary group have been determined, these values are ranked in a matrix. The
highest level of risk would receive priority for security countermeasures. Once the
threats and corresponding risks have been identified, a critical asset must take steps to
reduce its vulnerability by (1) eliminating or reducing risks as far as possible by
inherently safe design and construction, (2) enacting protective security
countermeasures, and (3) informing users of residual risk.
f. The CARVER Assessment Tool
The CARVER matrix was developed by the US Special Forces during the
Vietnam War and is a decision tool used by the Special Forces for rating the relative
desirability of potential targets and for properly allocating attack resources. CARVER
is used in the analysis and examination of the interrelationships between assets,
threats, vulnerabilities, and countermeasures that protect a facility. The CARVER
selection factors assist in selecting which targets would be most open to attack. The
selection factors range from 1 to 10 and are not weighted; all critical assets are alike
and use the same model. As the factors are analyzed and values assigned, a decision
matrix is formed, indicating the target most likely to be attacked. The CARVER tool
has been modified so that it can be used in the vulnerability and risk assessment
process.
C—Criticality. Identify critical assets, single points of failure, or choke points.
Criticality is the target value: the importance of a system, subsystem, complex, or
component. A target is critical when its destruction or damage has a significant impact
on the output of the target system, subsystem, or complex. A successful attack will
significantly impair or damage political, economic, and government operations, or
civil society. Criticality depends on several factors: Time. How rapidly will the impact
of target destruction affect operations? Quantity. What percentage of output is
curtailed by target destruction? Backup. Do substitutes for the output product or
service exist? Number of Targets and Their Positions in the System or Complex Flow
Diagram.
A—Accessibility. Determine ease of access to critical assets. Accessibility is
the ease with which a target can be reached, either physically or with a standoff
weapon. A target is accessible when an adversary element can physically infiltrate the
target, or if the target can be attacked by direct or indirect methods. Accessibility
varies with the infiltration/exfiltration, survival, and escape potential from the target
area, the security situation en route to and at the target, and the need for barrier
penetration at the target. The use of standoff weapons such as vehicle bombs should
always be considered when evaluating accessibility. Survivability of the adversary is
not always correlated to a target’s accessibility.
R—Recuperability. Determine how long it would take to repair, replace,
bypass, or restore a critical asset from the destruction or damage inflicted in the
attack. If a target is cheap, modular, and easy to fix, it may be a poor target for
terrorism (but a great target for vandalism). Recuperability deals with things, not
people. Recuperability varies with the sources and ages of targeted components and
with spare parts or redundant capabilities inherent in the critical asset.
V—Vulnerability. A target is vulnerable if an adversary has the capability and
intent to attack it and achieve a significant level of damage using available resources.
An evaluation of the effectiveness of security countermeasures against the adversary’s
capabilities should be conducted at this stage. Vulnerability depends on (1) the nature
and construction of the target; (2) the amount of damage required/desired; (3) the
resources available to the adversary; and (4) the adversary’s personnel, expertise, and
mindset.
E—Effect. Consider the scope and magnitude of adverse consequences that
would result from a successful attack. R—Recognizability. Recognizability is the
degree to which a target can be recognized without confusion with other targets or
components. Factors that influence recognizability include the size and complexity of
the target, the existence of distinctive target signatures, and the technical
sophistication and training of the attackers. An evaluation of the likelihood that
potential adversaries would recognize that an asset was critical should also be made.
Target analysis is the procedure by which an attacking force chooses the
proper venue and/or person for attack. In general, target analysis provides attackers
with the identification of the most effective attack loci coupled with a determination
of the least effort needed to achieve the goal and/or the lowest personnel losses
(capture/death). Defending forces, of course, apply target analysis to identify their
weaknesses and/or most probable areas for attack. By using target analysis in this
manner, it is possible to reverse engineer an attack scenario to provide the most
effective defense.
The USFDA uses the CARVER + Shock methodology to assess vulnerabilities
and establish protective measures to prepare for, guard against, and respond to
potential attacks on the food infrastructure. The CARVER + Shock process uses the
same CARVER factors described earlier but an additional factor is added for the
“Shock.” The shock dimension involves evaluating the psychological effect a
successful attack on the target will have.
We now define the attribute used by the USFDA and USDA to conduct their
vulnerability assessments and provide the scales used by the agencies for scoring each
attribute. These scales were developed with the mindset that mass mortality is a goal
of terrorist organizations. It is important to remember, however, that any intentional
food contamination could also have major psychological and economic impacts on the
affected industry.
This is a measure of the ease with which threat agents can be introduced in
quantities sufficient to achieve the attacker’s purpose once the target has been
reached. Vulnerability is determined by both the characteristics of the target (e.g., ease
of introducing agents, ability to uniformly mix agents into target) and the
characteristics of the surrounding environment (ability to work unobserved, time
available for introduction of agents). It is also important to consider what
interventions are already in place that might thwart an attack.
Shock is the final attribute considered in the methodology. Shock is the
combined measure of health, psychological, and collateral national economic impacts
of a successful attack on the target system. Shock is considered on a national level.
The psychological impact will increase if there are a large number of deaths or the
target has historical, cultural, religious, or other symbolic significance. Mass
casualties are not required to achieve widespread economic loss or psychological
damage. Collateral economic damage includes such items as decreased national
economic activity and increased unemployment in collateral industries.
By definition, terrorists attempt to achieve strong emotional responses from
their target audience. Aspects of targets that terrorists view as increasing a target’s
shock value are symbolism (e.g., the Pentagon), large number of casualties, sensitive
nature of facilities (e.g., nuclear facilities), and the ability to strike at core values and
primal emotions (e.g., targeting children).
Once the ranking on each of the attribute scales has been calculated for a given
node within the food supply system, the ranking on all of the scales can then be
totaled to give an overall value for that node. This should be repeated for each node
within a food supply system. The overall values for all the nodes can then be
compared to rank the vulnerability of the different nodes relative to each other. The
nodes with the highest total rating have the highest potential vulnerability and should
be the focus of countermeasure efforts.
g. Threat and Hazard Identification and Risk Assessment Guide (THIRA)
The Threat and Hazard Identification and Risk Assessment (THIRA) serves as
the cornerstone of the National Preparedness Program, operating under the directives
outlined in Presidential Policy Directive 8 (PPD-8). Originally issued in 2011, PPD-8
outlines the framework for national preparedness efforts, emphasizing the importance
of a coordinated and integrated approach to enhancing the resilience of the nation
against a wide range of threats and hazards.
Since its inception, THIRA has emerged as a vital tool in the arsenal of
emergency management and homeland security agencies tasked with assessing and
mitigating risks to critical infrastructure and key resources. By systematically
identifying and evaluating potential threats and hazards, THIRA enables stakeholders
to prioritize their preparedness efforts and allocate resources more effectively to
address the most pressing vulnerabilities.
The 2013 National Infrastructure Protection Plan (NIPP) underscored the
significance of THIRA in enhancing the security and resilience of critical
infrastructure sectors, which are vital to the nation's economic prosperity, public
safety, and national security. Recognizing the interconnected and interdependent
nature of critical infrastructure, the NIPP called for the widespread adoption of
THIRA across various sectors to facilitate a comprehensive and coordinated approach
to risk management and mitigation.
Furthermore, THIRA goes beyond traditional risk assessments by
incorporating a holistic and all-hazards approach to preparedness planning. In
addition to natural disasters such as hurricanes, earthquakes, and floods, THIRA also
encompasses human-made threats such as terrorism, cyberattacks, and pandemics,
reflecting the diverse and evolving nature of the threats facing the nation.
Through the THIRA process, stakeholders engage in a collaborative and
iterative exercise to identify and analyze potential threats and hazards, assess their
potential impacts, and develop mitigation strategies to enhance resilience and
preparedness. This includes identifying critical dependencies and interdependencies
among infrastructure sectors, evaluating the effectiveness of existing mitigation
measures, and identifying gaps and vulnerabilities that require further attention.
Moreover, THIRA serves as a valuable tool for enhancing situational
awareness and facilitating decision-making during emergencies and crises. By
providing a comprehensive understanding of the risks and challenges facing the
nation, THIRA enables stakeholders to make informed decisions about resource
allocation, emergency response planning, and recovery efforts, thereby enhancing the
overall effectiveness and resilience of the national preparedness enterprise.
In summary, THIRA plays a pivotal role in advancing the objectives of the
National Preparedness Program and the NIPP by providing a systematic and
integrated approach to identifying and mitigating risks to critical infrastructure and
key resources. By embracing THIRA as a foundational element of their preparedness
efforts, stakeholders can enhance their ability to anticipate, prepare for, and respond to
a wide range of threats and hazards, ultimately strengthening the nation's resilience in
the face of adversity.
Identify the Threats and Hazards of Concern. Based on a combination of
experience, forecasting, subject matter expertise, and other available resources,
identify a list of the threats and hazards of primary concern to the community. Give
the Threats and Hazards Context. Describe the threats and hazards of concern,
showing how they may affect the community. Establish Capability Targets. Assess
each threat and hazard in context to develop a specific capability target for each core
capability identified in the National Preparedness Goal. The capability target defines
success for the capability. Apply the Results. For each core capability, estimate the
resources required to achieve the capability targets through the use of community
assets and mutual aid, while also considering preparedness activities, including
mitigation opportunities.
The National Preparedness System (NPS) stands as the overarching
framework through which the United States endeavors to fortify its resilience and
security in the face of diverse threats and hazards. At its core, the NPS is a
multifaceted instrument that aims to systematically build, sustain, and deliver the core
capabilities necessary to achieve the overarching goal of a secure and resilient nation.
Central to the effectiveness of the NPS are its six components, each serving a distinct
yet interconnected role in the broader landscape of national preparedness.
The NPS comprises six key components, with the THIRA process playing a
pivotal role in supporting the first two components: (1) Identifying and assessing risk
and (2) estimating capability requirements. These initial stages lay the foundation
upon which subsequent preparedness efforts are built, serving as critical touchpoints
for understanding the nature and scope of the challenges facing the nation and the
resources needed to address them effectively.
The THIRA process serves as a linchpin in the early stages of the NPS,
helping jurisdictions navigate key questions that form the bedrock of effective
preparedness planning. By engaging in a systematic assessment of threats and
hazards, stakeholders can gain invaluable insights into the specific risks facing their
communities and the potential impacts these events could have on critical
infrastructure, public safety, and societal well-being.
Moreover, the THIRA process facilitates a comprehensive evaluation of
capability requirements, enabling jurisdictions to identify the resources, tools, and
expertise needed to effectively mitigate, respond to, and recover from emergencies
and disasters. By quantifying capability gaps and deficiencies, stakeholders can
prioritize their preparedness investments and allocate resources more strategically to
address the most pressing needs.
Furthermore, the THIRA process fosters a proactive approach to risk
management by empowering communities to identify and implement mitigation
measures aimed at reducing the likelihood and severity of potential threats and
hazards. By assessing the feasibility and effectiveness of various mitigation strategies,
jurisdictions can develop tailored action plans to enhance their resilience and
minimize the impact of future disasters.
Incorporating the insights gleaned from the THIRA process into recovery
preparedness planning is essential for ensuring a holistic and integrated approach to
emergency management. By considering the potential impacts of disasters on
community infrastructure, economic stability, and social cohesion, stakeholders can
develop robust recovery plans that prioritize the restoration of essential services, the
revitalization of affected communities, and the promotion of long-term resilience.
In summary, the THIRA process serves as a cornerstone of the National
Preparedness System, providing jurisdictions with a systematic framework for
identifying and assessing risks, estimating capability requirements, and informing
preparedness planning efforts. By leveraging the insights generated through the
THIRA process, stakeholders can enhance their readiness to confront a wide range of
threats and hazards, thereby advancing the overarching goal of a secure and resilient
nation.
Jurisdictions should include only those threats and hazards of significant
concern in their THIRA. To identify threats and hazards of significant concern,
consider two key factors: likelihood of incident and significance of threat/hazard
effects.
Factor 1: Likelihood of Incident. Likelihood is the chance of something
happening, whether defined, measured, or estimated objectively or subjectively.
Jurisdictions should consider only those threats and hazards that could plausibly
occur. As a starting point, jurisdictions should consider the threats and hazards that
have historically affected them, as well as those threats and hazards that exist
regardless of historical occurrence (e.g., earthquakes, industrial accidents, or
intelligencedriven assessments of potential terrorist attacks). This should include
analyzing after-action reports and information about the root causes of threats and
hazards (e.g., major floods caused by inadequate levees), as well as consultation with
scientists and appropriate subject matter experts. Jurisdictions may also consider
looking at historical archives (e.g., at the local library) for reports of disasters in the
community. For threats and hazards for which it is difficult to estimate the likelihood
of an incident (e.g., terrorism), jurisdictions should consider available intelligence
data to determine inclusion in the THIRA. Engaging state/local law enforcement or a
major urban area or state fusion center can provide the necessary insight into these
types of events in order to focus on plausible threats. Local public health and medical
personnel can also offer insight about health-related concerns such as pandemics.
Jurisdictions should take care to not overrely on historical averages or patterns that
may give a false sense of likelihood. For example, many severe natural hazards (such
as earthquakes or floods) occur with such low frequency that relying on historical
records alone may be misleading. High-magnitude earthquakes, though rare, can have
severe consequences and therefore should be considered if the community is at risk
for earthquake damage. Jurisdictions should also consider the threats and hazards that
similar jurisdictions include in their planning processes or have recently responded to.
The scale and severity of disasters are growing and will likely pose systemic threats.
Increasing changes in demographic trends and technology are making the effects of
disasters more complex to manage. Population shifts to vulnerable areas and other
demographic changes will affect future disaster management activities and should be
considered when selecting threats and hazards.
Factor 2: Significance of Threat/Hazard Effects. The threat/hazard effects
represent the overall impacts to the jurisdiction. Jurisdictions should consider only
those threats and hazards that would have a significant effect on them. Consider that
different incidents present different types of challenges. In some cases, the sheer
magnitude of the incident may be substantial; others may involve coordination
complexities, political sensitivities, or economic and social challenges. Jurisdictions
should not limit their THIRA to threats and hazards that they would be able to
manage, but should also consider threats and hazards resulting in large-scale disasters
or catastrophic incidents. Conversely, jurisdictions should exclude from the THIRA
threats and hazards with only minor impacts, regardless of likelihood. Although
incidents may have wider regional or national effects, jurisdictions should focus
strictly on the impacts within their jurisdiction. In some cases, it may be useful to
include threats and hazards that occur in other locations if they trigger local effects.
For example, an industrial accident at a chemical plant located in one particular
community could affect people in another community who are downwind from the
accident.