SlideShare ist ein Scribd-Unternehmen logo
1 von 17
Towards a methodology for a Quantitative (Risk) Assessment of Critical Infrastructures Roberto Filippini, Marcelo Masera Institute of Protection and Security of Citizens Joint Research Centre, European Commission Ispra, Italy
Outline ,[object Object],[object Object],[object Object],[object Object]
Introduction Critical Infrastructures Assessment? Integration/Operation? Decision making?
Introduction Critical infrastructures  –  Networked – Systems of Systems  Service-oriented   -   available anytime, anywhere production distribution information technology communications Control Monitoring Data Power supply INTERDEPENDENCIES Society production distribution information technology communications Control Monitoring Data Power supply INTERDEPENDENCIES Society production distribution information technology communications Control Monitoring Data Power supply INTERDEPENDENCIES Society
A Few Features of CI Layered structure Technical-organization-management Decision making Local versus global Failure pathologies Escalation - cascade Diverse metrics Diverse dynamics Cross - borders A pool of diverse branches or a new standalone discipline? Multi-disciplinary System of Systems Networked Service oriented Available anytime-anywhere production distribution information technology communications Society
Challenges ,[object Object],[object Object],? The single system  … Scope : internal dynamics with inputs from “outside” The system of systems Scope : Dependencies and Interdependencies
Challenges (2) ,[object Object],[object Object],Upper levels Scope : managements, business, legal, etc. Slower dynamics Lower levels Scope : physical processes, controls, services  Faster dynamics Field System Operation Corporate Inter-corporate Infrastructure x Field System Operation Corporate Inter-corporate Infrastructure y
Challenges (3) ,[object Object],[object Object],Field System Operation Corporate x Infrastructure Field System Operation Corporate y Inter-corporate Dependability Risk Business continuity Service Technical Business National  Cross-borders
Challenges (4) ,[object Object],[object Object],Recovery Failure Field System Operation Corporate Inter-corporate Infrastructure x Field System Operation Corporate Inter-corporate Infrastructure y Field System Operation Corporate Inter-corporate Infrastructure z
“ Building” Knowledge on CI ,[object Object],[object Object],[object Object],[object Object],Regulations Policies Procedures Controls Governance framework DATA Modeling Observing Reproducing
Priority Issues ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],How CI reacts Metrics How CI fails
Modeling Insights 2 1 4 System 1 – Failure at system level 2 – Protection measures  3 – Local diagnostics 4 – Emergency management, cross-levels Field 3 Infrastructure TE  triggering event Service interruption Operation The failure scenario may affect several levels of the infrastructure
Modeling Insights (2) Local measures TE Triggering event End states of the infrastructure Emergency management propagation  throughout the network Local measures TE Triggering event Emergency management Restore End states of the system y Restore  End states of the system x Infrastructure x Infrastructure y TIME A failure propagates throughout the network and triggers other events
Modeling Insights (3) x1 x2 x3 y1 y2 System states may be more or less relevant depending on the perspectives System x System y 11 21 31 12 22 32 1) Compound states space : path independent 11 21 31 12 22 32 32 22 32 2) Compound states space:  path sensitive
Final Remarks ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Final Remarks ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Conclusions ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

Weitere ähnliche Inhalte

Andere mochten auch (8)

Risk Management Methodology - Copy
Risk Management Methodology - CopyRisk Management Methodology - Copy
Risk Management Methodology - Copy
 
Risk Assessment Methodologies
Risk Assessment MethodologiesRisk Assessment Methodologies
Risk Assessment Methodologies
 
Risk Assessment And Management
Risk Assessment And ManagementRisk Assessment And Management
Risk Assessment And Management
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
Risk & Risk Management
Risk & Risk ManagementRisk & Risk Management
Risk & Risk Management
 
Risk management
Risk managementRisk management
Risk management
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
Risk Management Framework
Risk Management FrameworkRisk Management Framework
Risk Management Framework
 

Ähnlich wie Towards a methodology for a Quantitative (Risk) Assessment of Critical Infrastructures

Software Security in the Real World
Software Security in the Real WorldSoftware Security in the Real World
Software Security in the Real World
Mark Curphey
 
Complex Systems
Complex SystemsComplex Systems
Complex Systems
eghafari
 
Abstraction based intrusion detection in distributed environments
Abstraction based intrusion detection in distributed environmentsAbstraction based intrusion detection in distributed environments
Abstraction based intrusion detection in distributed environments
UltraUploader
 
ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...
ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...
ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...
IJCNCJournal
 

Ähnlich wie Towards a methodology for a Quantitative (Risk) Assessment of Critical Infrastructures (20)

Software Security in the Real World
Software Security in the Real WorldSoftware Security in the Real World
Software Security in the Real World
 
Complex Systems
Complex SystemsComplex Systems
Complex Systems
 
Iet Prestige Lecture Coping With Complexity 7th December
Iet Prestige Lecture Coping With Complexity 7th DecemberIet Prestige Lecture Coping With Complexity 7th December
Iet Prestige Lecture Coping With Complexity 7th December
 
Next Generation Standards - A Science-Based Discipline of Information Managem...
Next Generation Standards - A Science-Based Discipline of Information Managem...Next Generation Standards - A Science-Based Discipline of Information Managem...
Next Generation Standards - A Science-Based Discipline of Information Managem...
 
Principles and risk assessment of managing distributed ontologies hosted by e...
Principles and risk assessment of managing distributed ontologies hosted by e...Principles and risk assessment of managing distributed ontologies hosted by e...
Principles and risk assessment of managing distributed ontologies hosted by e...
 
Application Threat Modeling In Risk Management
Application Threat Modeling In Risk ManagementApplication Threat Modeling In Risk Management
Application Threat Modeling In Risk Management
 
Astute symposium 2013-10-10_hmi_design_patterns_elenatsiporkova_tomstevens
Astute symposium 2013-10-10_hmi_design_patterns_elenatsiporkova_tomstevensAstute symposium 2013-10-10_hmi_design_patterns_elenatsiporkova_tomstevens
Astute symposium 2013-10-10_hmi_design_patterns_elenatsiporkova_tomstevens
 
Enterprise IT Security| CIO Innovation and Leadership
Enterprise IT Security| CIO Innovation and LeadershipEnterprise IT Security| CIO Innovation and Leadership
Enterprise IT Security| CIO Innovation and Leadership
 
Workshop8 18 12 09 Ingles
Workshop8   18 12 09 InglesWorkshop8   18 12 09 Ingles
Workshop8 18 12 09 Ingles
 
An Agent Future For Network Control
An Agent Future For Network ControlAn Agent Future For Network Control
An Agent Future For Network Control
 
Comparative Analysis of Intrusion Detection Systems and Machine Learning-Base...
Comparative Analysis of Intrusion Detection Systems and Machine Learning-Base...Comparative Analysis of Intrusion Detection Systems and Machine Learning-Base...
Comparative Analysis of Intrusion Detection Systems and Machine Learning-Base...
 
communication in distributed systems
communication in distributed systemscommunication in distributed systems
communication in distributed systems
 
Only Abstract
Only AbstractOnly Abstract
Only Abstract
 
Critical Infrastructure Assessment Techniques to Prevent Threats and Vulnerab...
Critical Infrastructure Assessment Techniques to Prevent Threats and Vulnerab...Critical Infrastructure Assessment Techniques to Prevent Threats and Vulnerab...
Critical Infrastructure Assessment Techniques to Prevent Threats and Vulnerab...
 
Abstraction based intrusion detection in distributed environments
Abstraction based intrusion detection in distributed environmentsAbstraction based intrusion detection in distributed environments
Abstraction based intrusion detection in distributed environments
 
Information systems
Information systemsInformation systems
Information systems
 
Privacy Protection in Distributed Industrial System
Privacy Protection in Distributed Industrial SystemPrivacy Protection in Distributed Industrial System
Privacy Protection in Distributed Industrial System
 
F017223742
F017223742F017223742
F017223742
 
Showcase Begin With The End In Mind
Showcase   Begin With The End In MindShowcase   Begin With The End In Mind
Showcase Begin With The End In Mind
 
ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...
ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...
ADDRESSING IMBALANCED CLASSES PROBLEM OF INTRUSION DETECTION SYSTEM USING WEI...
 

Mehr von Global Risk Forum GRFDavos

Mehr von Global Risk Forum GRFDavos (20)

Disaster Risk Management Knowledge Centre, Brian Doherty
Disaster Risk Management Knowledge Centre, Brian DohertyDisaster Risk Management Knowledge Centre, Brian Doherty
Disaster Risk Management Knowledge Centre, Brian Doherty
 
Disaster risk reduction and nursing - human science research the view of surv...
Disaster risk reduction and nursing - human science research the view of surv...Disaster risk reduction and nursing - human science research the view of surv...
Disaster risk reduction and nursing - human science research the view of surv...
 
Global alliance of disaster research institutes (GADRI) discussion session, A...
Global alliance of disaster research institutes (GADRI) discussion session, A...Global alliance of disaster research institutes (GADRI) discussion session, A...
Global alliance of disaster research institutes (GADRI) discussion session, A...
 
Towards a safe, secure and sustainable energy supply the role of resilience i...
Towards a safe, secure and sustainable energy supply the role of resilience i...Towards a safe, secure and sustainable energy supply the role of resilience i...
Towards a safe, secure and sustainable energy supply the role of resilience i...
 
Making Hard Choices An Analysis of Settlement Choices and Willingness to Retu...
Making Hard Choices An Analysis of Settlement Choices and Willingness to Retu...Making Hard Choices An Analysis of Settlement Choices and Willingness to Retu...
Making Hard Choices An Analysis of Settlement Choices and Willingness to Retu...
 
The Relocation Challenges in Coastal Urban Centers Options and Limitations, A...
The Relocation Challenges in Coastal Urban Centers Options and Limitations, A...The Relocation Challenges in Coastal Urban Centers Options and Limitations, A...
The Relocation Challenges in Coastal Urban Centers Options and Limitations, A...
 
C&A Save the Children Urban DRR Project, Ray KANCHARLA
C&A Save the Children Urban DRR Project, Ray KANCHARLAC&A Save the Children Urban DRR Project, Ray KANCHARLA
C&A Save the Children Urban DRR Project, Ray KANCHARLA
 
Involving the Mining Sector in Achieving Land Degradation Neutrality, Simone ...
Involving the Mining Sector in Achieving Land Degradation Neutrality, Simone ...Involving the Mining Sector in Achieving Land Degradation Neutrality, Simone ...
Involving the Mining Sector in Achieving Land Degradation Neutrality, Simone ...
 
Disaster Risk Reduction and Nursing - Human Science research the view of surv...
Disaster Risk Reduction and Nursing - Human Science research the view of surv...Disaster Risk Reduction and Nursing - Human Science research the view of surv...
Disaster Risk Reduction and Nursing - Human Science research the view of surv...
 
Training and awareness raising in Critical Infrastructure Protection & Resili...
Training and awareness raising in Critical Infrastructure Protection & Resili...Training and awareness raising in Critical Infrastructure Protection & Resili...
Training and awareness raising in Critical Infrastructure Protection & Resili...
 
IDRC Davos 2016 - Workshop Awareness Raising, Education and Training - Capaci...
IDRC Davos 2016 - Workshop Awareness Raising, Education and Training - Capaci...IDRC Davos 2016 - Workshop Awareness Raising, Education and Training - Capaci...
IDRC Davos 2016 - Workshop Awareness Raising, Education and Training - Capaci...
 
Global Alliance of Disaster Research Institutes - Hirokazu TATANO
Global Alliance of Disaster Research Institutes - Hirokazu TATANOGlobal Alliance of Disaster Research Institutes - Hirokazu TATANO
Global Alliance of Disaster Research Institutes - Hirokazu TATANO
 
Capacity Development for DRR, Beatrice PROGIDA
Capacity Development for DRR, Beatrice PROGIDACapacity Development for DRR, Beatrice PROGIDA
Capacity Development for DRR, Beatrice PROGIDA
 
Dynamic factors influencing the post-disaster resettlement success Lessons fr...
Dynamic factors influencing the post-disaster resettlement success Lessons fr...Dynamic factors influencing the post-disaster resettlement success Lessons fr...
Dynamic factors influencing the post-disaster resettlement success Lessons fr...
 
Consequences of the Armed Conflict as a Stressor of Climate Change in Colombi...
Consequences of the Armed Conflict as a Stressor of Climate Change in Colombi...Consequences of the Armed Conflict as a Stressor of Climate Change in Colombi...
Consequences of the Armed Conflict as a Stressor of Climate Change in Colombi...
 
Disaster Risk Perception in Cameroon and its Implications for the Rehabilitat...
Disaster Risk Perception in Cameroon and its Implications for the Rehabilitat...Disaster Risk Perception in Cameroon and its Implications for the Rehabilitat...
Disaster Risk Perception in Cameroon and its Implications for the Rehabilitat...
 
Systematic Knowledge Sharing of Natural Hazard Damages in Public-private Part...
Systematic Knowledge Sharing of Natural Hazard Damages in Public-private Part...Systematic Knowledge Sharing of Natural Hazard Damages in Public-private Part...
Systematic Knowledge Sharing of Natural Hazard Damages in Public-private Part...
 
Exploring the Effectiveness of Humanitarian NGO-Private Sector Collaborations...
Exploring the Effectiveness of Humanitarian NGO-Private Sector Collaborations...Exploring the Effectiveness of Humanitarian NGO-Private Sector Collaborations...
Exploring the Effectiveness of Humanitarian NGO-Private Sector Collaborations...
 
Can UK Water Service Providers Manage Risk and Resilience as Part of a Multi-...
Can UK Water Service Providers Manage Risk and Resilience as Part of a Multi-...Can UK Water Service Providers Manage Risk and Resilience as Part of a Multi-...
Can UK Water Service Providers Manage Risk and Resilience as Part of a Multi-...
 
A Holistic Approach Towards International Disaster Resilient Architecture by ...
A Holistic Approach Towards International Disaster Resilient Architecture by ...A Holistic Approach Towards International Disaster Resilient Architecture by ...
A Holistic Approach Towards International Disaster Resilient Architecture by ...
 

Kürzlich hochgeladen

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Kürzlich hochgeladen (20)

Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 

Towards a methodology for a Quantitative (Risk) Assessment of Critical Infrastructures

  • 1. Towards a methodology for a Quantitative (Risk) Assessment of Critical Infrastructures Roberto Filippini, Marcelo Masera Institute of Protection and Security of Citizens Joint Research Centre, European Commission Ispra, Italy
  • 2.
  • 3. Introduction Critical Infrastructures Assessment? Integration/Operation? Decision making?
  • 4. Introduction Critical infrastructures – Networked – Systems of Systems Service-oriented - available anytime, anywhere production distribution information technology communications Control Monitoring Data Power supply INTERDEPENDENCIES Society production distribution information technology communications Control Monitoring Data Power supply INTERDEPENDENCIES Society production distribution information technology communications Control Monitoring Data Power supply INTERDEPENDENCIES Society
  • 5. A Few Features of CI Layered structure Technical-organization-management Decision making Local versus global Failure pathologies Escalation - cascade Diverse metrics Diverse dynamics Cross - borders A pool of diverse branches or a new standalone discipline? Multi-disciplinary System of Systems Networked Service oriented Available anytime-anywhere production distribution information technology communications Society
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12. Modeling Insights 2 1 4 System 1 – Failure at system level 2 – Protection measures 3 – Local diagnostics 4 – Emergency management, cross-levels Field 3 Infrastructure TE triggering event Service interruption Operation The failure scenario may affect several levels of the infrastructure
  • 13. Modeling Insights (2) Local measures TE Triggering event End states of the infrastructure Emergency management propagation throughout the network Local measures TE Triggering event Emergency management Restore End states of the system y Restore End states of the system x Infrastructure x Infrastructure y TIME A failure propagates throughout the network and triggers other events
  • 14. Modeling Insights (3) x1 x2 x3 y1 y2 System states may be more or less relevant depending on the perspectives System x System y 11 21 31 12 22 32 1) Compound states space : path independent 11 21 31 12 22 32 32 22 32 2) Compound states space: path sensitive
  • 15.
  • 16.
  • 17.

Hinweis der Redaktion

  1. 10/06/10 04:29 PM Page