COMPLETE THESE SPREADSHEETS FOR A KNOWN CRITICAL INFRASTRUCTURE

profileabbey621
multicriterion_documentation_1_.pdf

Multi-­‐Criteria  Assessment  Methodology   This  multi-­‐criteria  tool  is  an  example  of  a  simple  risk-­‐based  model  that  assesses   assets  independently  but  with  multiple  measures.  For  this  example,  we  used  a   subset  of  the  MSRAM  model,  at  least  in  the  way  MSRAM  models  risk  and  its   components.  

Description     Asset  is  a  unique  name  of  the  asset  to  be  evaluated.     Attack  Mode  is  a  description  of  the  type  of  attack  being  considered.  Multiple  attack   modes  can  be  considered  for  any  asset.  

We  consider  Asset  +  Attack  Mode  as  the  key  data  pair  that  uniquely  identifies   one  assessment.  An  electrical  switching  station  could  be  paired  with  an   explosive  device,  a  SCADA  attack,  or  other  mode,  each  of  which  would  be   considered  separately.  

  We  use  the  standard  equation  for  Risk    

R  =  T  *  V  *  C  where     T  is  Threat,  V  is  Vulnerability,  and  C  is  Consequence.  The  components  of  each  is   described  below.     Threat  is  the  percentage  product  of  Intent  and  Capability.    

• Intent  is  the  probability  that  a  person  or  group  would  want  to  damage  or   destroy  this  asset.  High  intent  would  imply  knowledge  of  an  impending   attack  or  a  credible  threat.  

• Capability  is  the  probability  that  a  person  or  group  would  have  the   capability  to  execute  this  attack.  Note  that  this  requires  an  attack  mode.  The   capability  of  a  group  to  obtain  small  explosives  is  likely  to  be  higher  than   their  capability  to  obtain  radioactive  material.  

Vulnerability  is  the  percentage  product  of  Achievability  and  Target  Hardness.   • Achievability  is  the  probability  of  successful  attack  assuming  no  security  

measures.  Do  not  consider  existing  security  features  such  as  fencing,  key  card   control,  CCTV,  etc.  Assume  that  this  person  or  group  gains  access  to  this  asset   with  a  small  explosive  device  (for  example).  What  is  the  likelihood  that  it   would  successfully  disable  the  asset?  

• Target  Hardness  is  the  probability  that  the  target  cannot  withstand  the   attack.  Note  this  implies  that  a  lower  value  means  a  harder  target.  An  asset   with  stand-­‐off  barriers  and  physical  patrols  would  have  a  lower  target   hardness  value  than  one  with  only  light  fencing.  

Consequence  is  the  sum  of  all  consequence  category  estimates.  All  categories  must   be  translated  to  a  single  unit  (e.g.  dollars,  millions  of  dollars,  lives).  

• Death/Injury  is  the  number  of  casualties  that  would  be  expected  as  a  result   of  this  attack  on  this  asset.  We  use  a  value  per  statistical  life  (VSL)  of  $6.5M   but  this  can  be  adjusted.  

• Economic  Loss  is  the  estimated  value  of  loss  due  to  attack.  This  should   include  the  damage  to  the  asset  itself  but  could  also  include  “downstream”   economic  damages.  For  example,  if  a  bridge  is  disabled,  the  cost  to  repair  the   bridge  could  be  added  to  the  estimated  loss  of  commerce  over  the  time  it   takes  to  repair  the  bridge  to  estimate  this  value.  It  is  important  to  be   consistent  throughout  all  entries  in  this  column.  

• Environmental  is  the  estimated  value  of  the  environmental  impact  of  this   attack  on  this  asset.  If  there  is  no  environmental  impact,  then  this  can  be  zero.   In  cases  where  a  post-­‐event  clean  up  must  be  performed,  as  would  be  the   case  in  a  radiological,  chemical,  or  biological  attack,  this  could  be  very  high.  

• National  Security  is  the  estimated  value  of  the  impact  of  this  attack  on  this   asset  on  national  security.  An  attack  on  a  port  facility,  for  example,  might   have  a  large  impact  national  security,  whereas  an  attack  on  a  water   treatment  plant  may  have  a  smaller  estimated  value.  

• Symbolic  is  the  estimated  value  of  impact  due  to  the  symbolic  value  of  this   target.  Damage  to  an  iconic  bridge  would  be  estimated  higher  than  a  generic   bridge.  Damage  to  a  national  monument  would  have  value  here  where  it  may   not  have  value  elsewhere.  

  Total  is  the  Risk  calculation  for  this  Asset-­‐Attack  Mode  pair.  It  is  computed,  not   input  by  the  user.  Assuming  that  consequence  values  were  given  in  dollars,  then  the   Risk  calculation  is  also  in  dollars.     You  may  use  the  Sort  function  in  Excel  to  sort  the  table  on  Total  in  order  to  quickly   identify  the  Asset-­‐Attack  Mode  pairs  with  the  highest  calculated  Risk.  

Modifications   This  simple  tool  was  built  with  the  intention  that  it  would  be  modified  to  meet   specific  uses.       1. If  the  components  of  T,  C,  or  C  are  not  desired,  then  the  user  may  directly  input  

percentage  values  (0-­‐100)  in  columns  E  or  H.  For  consequence,  a  C  can  be   directly  input  into  column  N  or  any  of  the  columns  I  through  M  may  be  discarded   if  not  needed.  The  tool  will  sum  what  values  are  given.  

2. If  you  wish  to  add  another  component  to  Threat  or  Vulnerability,  you  may  do  so   by  adding  a  new  column  under  that  category,  in  either  the  red  or  yellow  regions.   Make  sure  that  you  adjust  the  Score  column  to  include  the  new  column.  Also   make  sure  that  the  new  component  is  a  percentage  value  so  that  it  can  be   multiplied  without  affecting  the  other  components.  

3. You  may  also  add  components  to  Consequence  easily.  Add  a  column  into  the  blue   region,  and  make  sure  that  the  Score  column  in  blue  includes  the  new  column(s)   in  the  sum.  It  should  do  that  by  default.