In today’s dynamic and uncertain security landscape, protecting critical infrastructures has become increasingly important. These backbone systems provide essential services and goods to modern society, yet are also vulnerable to intentional disruption, leading to significant interruptions in service delivery. We argue, that an integrated approach that combines security and resilience is necessary for holistic protection of critical infrastructures, in particular because security and resilience have complementary goals: security aims at minimizing the probability of successful attacks, while resilience concepts focus on enabling systems to cope effectively with resulting interruptions. Aiming at the assessment of measure effectiveness, we propose a risk-based framework that brings together a model for both, vulnerability to physical attacks and potential cascading consequences. Both models use distributed parameters to reflect uncertainties, e.g. regarding the effectiveness of countermeasures. Applying this approach to a simple case study, we show that equivalent measure combinations can be found within both domains, although the contributions to risk mitigation are varying in different scenarios. In the analysis, we highlight the paramount importance of considering uncertainties when selecting security and resilience measures and emphasize the need for efficiency analysis (cost–benefit assessments) to find optimal or appropriate solutions, especially in the context of limited budgets. We conclude that the proposed framework is flexible and can serve as a starting point for further research and application.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security and Resilience: Protection of Infrastructures

  • Kai-Dietrich Wolf,
  • Daniel Lichte

摘要

In today’s dynamic and uncertain security landscape, protecting critical infrastructures has become increasingly important. These backbone systems provide essential services and goods to modern society, yet are also vulnerable to intentional disruption, leading to significant interruptions in service delivery. We argue, that an integrated approach that combines security and resilience is necessary for holistic protection of critical infrastructures, in particular because security and resilience have complementary goals: security aims at minimizing the probability of successful attacks, while resilience concepts focus on enabling systems to cope effectively with resulting interruptions. Aiming at the assessment of measure effectiveness, we propose a risk-based framework that brings together a model for both, vulnerability to physical attacks and potential cascading consequences. Both models use distributed parameters to reflect uncertainties, e.g. regarding the effectiveness of countermeasures. Applying this approach to a simple case study, we show that equivalent measure combinations can be found within both domains, although the contributions to risk mitigation are varying in different scenarios. In the analysis, we highlight the paramount importance of considering uncertainties when selecting security and resilience measures and emphasize the need for efficiency analysis (cost–benefit assessments) to find optimal or appropriate solutions, especially in the context of limited budgets. We conclude that the proposed framework is flexible and can serve as a starting point for further research and application.