Abstract
The paper presents a concept how to assess the effectiveness of critical infrastructure protection systems. At the beginning the main issues related to critical infrastructure protection are discussed, like resilience, interdependencies, dire phenomena caused by them, and risk management. Next, the state of the art is reviewed. It embraces frameworks, methods and tools related to infrastructures protection, especially risk management. The paper extends the researches of the EU CIRAS project beyond the risk management issue, proposing a method to assess the effectiveness of countermeasures selected for implementation. The concept is based on supplementing the risk management framework by incident management, incident statistics and effectiveness indicators presenting relevant parameters for decisions makers. To implement this concept, the CIRAS risk management software platform should be extended. Main categories of statistics and indicators dedicated for critical infrastructures are proposed. In the conclusion the concept is summarized and future works related to its validation is specified.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
Notes
- 1.
This project has been funded with support from the European Commission. This publication reflects the views only of the author, and the European Commission cannot be held responsible for any use which may be made of the information contained therein (Grant Agreement clause).
References
Eusgeld, I., Nan, C., Dietz, S.: ‘‘System-of-systems’’ approach for interdependent critical infrastructures. Reliab. Eng. Syst. Safety 96, 679–686 (2011)
Ciras project, http://cirasproject.eu/. Accessed January 2016
ValueSec project, www.valuesec.eu. Accessed January 2016
Giannopoulos, G., Filippini, R.: Risk Assessment and Resilience for Critical Infrastructures. Workshop Proceedings, 25–26 April 2012, Joint Research Centre—Institute for the Protection and Security of the Citizen. Ispra, Italy. https://www.google.pl/search?q=Risk+Assessment+and+Resilience+for+Critical+Infrastructures.+Workshop+Proceedings&ie=utf-8&oe=utf-8&gws_rd=cr&ei=s-h6VvXDMof2aJ-EqsgB. Accessed December 2015
Rinaldi, S.M., Peerenboom, J.P., Kelly, T.K.: Identifying, Understanding and Analyzing Critical Infrastructure Interdependencies. IEEE Control Systems Magazine. December, pp. 11–25 (2001)
Hokstad, P., Utne, I.B., Vatn, J. (eds.): Risk and Interdependencies in Critical Infrastructures: A Guideline for Analysis (Springer Series in Reliability Engineering). Springer, London (2012). DOI:10.1007/978-1-4471-4661-2_2
Rausand, M.: Risk Assessment: Theory, Methods, and Applications. Series: Statistics in Practice (Book 86). Wiley (2011)
Baginski, J., Bialas, A., Rogowski, D., et al.: D1.1—State of the Art of Methods and Tools, CIRAS Deliverable. Responsible: Institute of Innovative Technologies EMAG, Dissem. level: RE/CO (i.e. available for: beneficiaries, stakeholders, Europ. Commission) (2015)
Giannopoulos, G., Filippini, R., Schimmer, M.: Risk Assessment Methodologies for Critical Infrastructure Protection. Part I: A State of the Art. European Union (2012)
Deliverable D2.1: Common areas of Risk Assessment Methodologies. Euracom (2007)
ISO/IEC 31010:2009—Risk Management—Risk Assessment Techniques
ENISA: http://rm-inv.enisa.europa.eu/methods. Accessed December 2015
NIPP 2013: Partnering for Critical Infrastructure Security and Resilience. The US Department of Homeland Security (2013). http://www.dhs.gov/sites/default/files/publications/NIPP%202013_Partnering%20for%20Critical%20Infrastructure%20Security%20and%20Resilience_508_0.pdf. Accessed January 2016
Supplemental Tool: Executing A Critical Infrastructure Risk Management Approach. U.S. Department of Homeland Security, DHS Risk Lexicon (2010). http://www.dhs.gov/sites/default/files/publications/NIPP%202013%20Supplement_Executing%20a%20CI%20Risk%20Mgmt%20Approach_508.pdf. Accessed January 2016
Stapelberg, R.F.: Infrastructure Systems Interdependencies and Risk Informed Decision Making (RIDM): Impact Scenario Analysis of Infrastructure Risks Induced by Natural, Technological and Intentional Hazards, Systemics, Cybernetics and Informatics, vol. 6, number 5 (2013)
ISO 31000:2009, Risk management—Principles and guidelines
ISO/IEC 27001:2013 Information technology—Security techniques—Information security management systems—Requirements
COBIT: http://www.isaca.org/cobit/pages/default.aspx. Accessed January 2016
Deming cycle: https://en.wikipedia.org/wiki/PDCA. Accessed January 2016
OSCAD project. http://www.oscad.eu/index.php/en/ . Accessed January 2016
Bialas, A.: Critical infrastructures risk manager—the basic requirements elaboration. In: Zamojski, W., Mazurkiewicz, J., Sugier, J., Walkowiak, T., Kacprzyk, J. (eds.) Theory and Engineering of Complex Systems and Dependability Proceedings of the Tenth International Conference on Dependability and Complex Systems DepCoS-RELCOMEX, June 29–July 3 2015, Brunów, Poland. Advances in Intelligent Systems and Computing, vol. 365, pp. 11–24. Springer, Cham, Heidelberg, New York, Dordrecht, London (2015). DOI:10.1007/978-3-319-19216-1_2
Białas, A.: Experimentation tool for critical infrastructures risk management. In: Proceedings of the 2015 Federated Conference on Computer Science and Information Systems (FedCSIS), pp. 775–780 ISBN 978-1-4673-4471-5 (Web). IEEE Catalog Number: CFP1385 N-ART (Web)
Białas, A.: Research on critical infrastructures risk management. In: Rostański, M., Pikiewicz, P., Buchwald, P. (eds.) Internet in the Information Society 2015—10th International Conference Proceedings, pp. 93–108. Scientific Publishing University of Dąbrowa Górnicza (2015)
ISO 22301:2012 Societal security—Business continuity management systems—Requirements
Bialas, A.: Computer support for the railway safety management system—first validation results. In: Zamojski, W., Mazurkiewicz, J., Sugier, J., Walkowiak, T., Kacprzyk, J. (eds.) Proceedings of Ninth International Conference on Dependability and Complex Systems DepCoS-RELCOMEX, June 30–July 4, 2014, Brunow, Poland. Advances in Intelligent Systems and Computing, vol. 286, pp. 81–92. Springer Cham, Heidelberg, New York, Dordrecht, London (2014). ISBN 978-3-319-07012-4. DOI:10.1007/978-3-319-07013-1
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2016 Springer International Publishing Switzerland
About this paper
Cite this paper
Bialas, A. (2016). Critical Infrastructure Protection—How to Assess the Protection Efficiency. In: Zamojski, W., Mazurkiewicz, J., Sugier, J., Walkowiak, T., Kacprzyk, J. (eds) Dependability Engineering and Complex Systems. DepCoS-RELCOMEX 2016. Advances in Intelligent Systems and Computing, vol 470. Springer, Cham. https://doi.org/10.1007/978-3-319-39639-2_3
Download citation
DOI: https://doi.org/10.1007/978-3-319-39639-2_3
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-319-39638-5
Online ISBN: 978-3-319-39639-2
eBook Packages: EngineeringEngineering (R0)