SOLVE THESE TWO SPREADSHEETS USING FACTS
Multi-‐Criteria Assessment Methodology This multi-‐criteria tool is an example of a simple risk-‐based model that assesses assets independently but with multiple measures. For this example, we used a subset of the MSRAM model, at least in the way MSRAM models risk and its components.
Description Asset is a unique name of the asset to be evaluated. Attack Mode is a description of the type of attack being considered. Multiple attack modes can be considered for any asset.
We consider Asset + Attack Mode as the key data pair that uniquely identifies one assessment. An electrical switching station could be paired with an explosive device, a SCADA attack, or other mode, each of which would be considered separately.
We use the standard equation for Risk
R = T * V * C where T is Threat, V is Vulnerability, and C is Consequence. The components of each is described below. Threat is the percentage product of Intent and Capability.
• Intent is the probability that a person or group would want to damage or destroy this asset. High intent would imply knowledge of an impending attack or a credible threat.
• Capability is the probability that a person or group would have the capability to execute this attack. Note that this requires an attack mode. The capability of a group to obtain small explosives is likely to be higher than their capability to obtain radioactive material.
Vulnerability is the percentage product of Achievability and Target Hardness. • Achievability is the probability of successful attack assuming no security
measures. Do not consider existing security features such as fencing, key card control, CCTV, etc. Assume that this person or group gains access to this asset with a small explosive device (for example). What is the likelihood that it would successfully disable the asset?
• Target Hardness is the probability that the target cannot withstand the attack. Note this implies that a lower value means a harder target. An asset with stand-‐off barriers and physical patrols would have a lower target hardness value than one with only light fencing.
Consequence is the sum of all consequence category estimates. All categories must be translated to a single unit (e.g. dollars, millions of dollars, lives).
• Death/Injury is the number of casualties that would be expected as a result of this attack on this asset. We use a value per statistical life (VSL) of $6.5M but this can be adjusted.
• Economic Loss is the estimated value of loss due to attack. This should include the damage to the asset itself but could also include “downstream” economic damages. For example, if a bridge is disabled, the cost to repair the bridge could be added to the estimated loss of commerce over the time it takes to repair the bridge to estimate this value. It is important to be consistent throughout all entries in this column.
• Environmental is the estimated value of the environmental impact of this attack on this asset. If there is no environmental impact, then this can be zero. In cases where a post-‐event clean up must be performed, as would be the case in a radiological, chemical, or biological attack, this could be very high.
• National Security is the estimated value of the impact of this attack on this asset on national security. An attack on a port facility, for example, might have a large impact national security, whereas an attack on a water treatment plant may have a smaller estimated value.
• Symbolic is the estimated value of impact due to the symbolic value of this target. Damage to an iconic bridge would be estimated higher than a generic bridge. Damage to a national monument would have value here where it may not have value elsewhere.
Total is the Risk calculation for this Asset-‐Attack Mode pair. It is computed, not input by the user. Assuming that consequence values were given in dollars, then the Risk calculation is also in dollars. You may use the Sort function in Excel to sort the table on Total in order to quickly identify the Asset-‐Attack Mode pairs with the highest calculated Risk.
Modifications This simple tool was built with the intention that it would be modified to meet specific uses. 1. If the components of T, C, or C are not desired, then the user may directly input
percentage values (0-‐100) in columns E or H. For consequence, a C can be directly input into column N or any of the columns I through M may be discarded if not needed. The tool will sum what values are given.
2. If you wish to add another component to Threat or Vulnerability, you may do so by adding a new column under that category, in either the red or yellow regions. Make sure that you adjust the Score column to include the new column. Also make sure that the new component is a percentage value so that it can be multiplied without affecting the other components.
3. You may also add components to Consequence easily. Add a column into the blue region, and make sure that the Score column in blue includes the new column(s) in the sum. It should do that by default.