Critical Infrastructure: Homeland Security and Emergency Preparedness

Critical Infrastructure: Homeland Security and Emergency Preparedness
复制标题

关键基础设施:国土安全和应急准备

DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
Robert S. Radvanovsky
Robert S. Radvanovsky
中科院分区:
--
文献类型:
--
作者:
Robert S. Radvanovsky

文献摘要

被引文献

相似文献

关键基础设施保障与保护简介 什么是关键基础设施?什么是私营部门?什么是公共部门?什么是CIP?什么是中央情报局?什么是公私合作伙伴关系?关键基础设施功能 关键基础设施需求、容量、脆弱性的演变以及网络的出现 我们要保护什么?能力需求的概念:区域(小系统)层面能力的原因 网络恐怖主义的消解与融合:标志着超越国家框架之旅的新风险 与地图上的龙会面 谁拥有宝藏?什么价值?目标受众 将 NRF 应用于国家应对工作 NRF 如何与地方活动相结合?潜在风险或关注的领域 公私合作伙伴关系 什么是公私合作伙伴关系 (P)? P谱 新容量的建立 现有容量的维护 网络化的用户费用和监督的需要 其他形式的公私合作和治理平衡点的侵蚀 信息共享和情报的重塑 数据与信息与情报 背景对上下文的重要性 上下文影响敏感度 进入云 云作为放大器 连接可信计算基础和用户社区的云和隐蔽管道信息共享的障碍 开源的兴起 开源信息和情报 信息共享的方法 - 后果效益比 应急准备和准备 核心办公室的兴起 急救人员 急救人员分类 指南分类 示例:北美应急响应指南 意识水平指南 绩效水平指南 操作级别 定义的级别 A:操作级别 级别 B:技术人员级别 了解保护、缓解和消除的协议危险品附加保护措施 了解 IAP 的制定 了解并遵循保护潜在犯罪现场的程序 了解医疗响应人员的部门协议 国家消防协会 OSHA 危险废物操作和应急响应技术支持人员 专家员工 DOT 危险品分类 实施应急响应计划的重要性 安全漏洞评估 什么是风险评估?评估风险的方法 威胁风险方程 定量与定性风险评估的比较 与评估风险相关的挑战 评估风险时要考虑的其他因素 什么是 SVA?拥有 SVA 的原因 什么是威胁?什么是漏洞?对策 漏洞评估框架 使用 VAF 的原因 联邦信息系统控制审计手册 FISCAM 审计的一般方法 什么是一般控制?什么是应用程序控制?使用 SVA 的注意事项 如何使用 SVA SVA 的受众 初始 SVA 计划 SVA 的必要步骤 关键成功因素 VAF 方法 VAF 的初始步骤 VAF 第 1 步:建立组织 MEI VAF 第 2 步:收集数据以识别 MEI 漏洞 VAF 第 3 步:分析、分类和优先考虑漏洞 法规 监督的作用 全球化公约、法律和法规的影响指南和最佳实践 规范性与基于绩效的对刑事、行政和民法的影响 潜在的权力和信誉滥用 政府与行业自律 规范性系统中基于绩效的监管所产生的知识差距:系统性漏洞 信息共享和分析中心 什么是关键基础设施资产?什么是 ISAC?加入 ISAC 的优势 获取 ISAC 信息 扩展 ISAC 服务 地面交通 ISAC 供应链 ISAC 公共交通 ISAC 美国公共交通协会 美国铁路协会 运输技术中心公司 Railinc Water ISAC 州饮用水管理员协会 水环境研究基金会 大都市水务机构协会 大都市污水处理机构协会 全国水务公司协会 美国水厂协会 AWWA 研究基金会 金融服务 ISAC 科学应用国际公司 电力部门 ISAC 应急管理和响应ISAC 信息技术 ISAC 国家电信通信资源信息共享协调中心 政府应急电信服务 电信服务优先共享资源 高频无线电计划 网络可靠性和互操作性委员会 国家安全电信咨询委员会 无线优先服务警报和协调网络 能源 ISAC 能源部门安全联盟 化学部门 ISAC 化学品运输应急中心 (CHEMTREC(R)) 医疗保健服务 ISAC 高速公路 ISAC 货物防盗信息处理系统 美国卡车运输协会 HighwayWatch(R) 食品和农业 ISAC FoodSHIELD 食品营销研究所 多州 ISAC ISAC 全球理事会 ISAC 房地产 ISAC 房地产圆桌会议 研究和教育网络 ISAC 生物技术和制药 ISAC 海事 ISAC 海事安全委员会 海上运输系统 国家咨询委员会 监督控制和数据采集 什么是控制系统?控制系统的类型 控制系统的组成部分 对控制系统的脆弱性担忧 对控制系统的采用具有已知漏洞的标准化技术 控制系统与不安全网络的连接 现有安全技术的实施限制 与控制系统的不安全连接 公开的有关控制系统的信息 控制系统可能容易受到控制系统泄露造成的攻击后果 控制系统攻击造成的战争拨号 战争驾驶 战争行走威胁 控制安全问题保护控制系统安全的系统方法 控制系统的技术研究举措 安全意识和信息共享举措 流程和安全控制举措 保护控制系统安全 实施审计控制 制定政策管理和控制机制 控制系统架构开发 控制系统和企业之间的分段网络 制定异常跟踪方法 定义事件响应计划 部门之间的相似之处 美国计算机应急准备小组 CSSP 控制系统 网络安全评估工具 (CSET) SCADA 社区挑战 SCADA 的未来 SCADA 资源关键基础设施信息 什么是关键基础设施信息?政府如何解读CII? 《信息自由法》的豁免 3 《信息自由法》的豁免 4 《国土安全法》第 214 条 执行《国土安全法》第 214 条 “敏感但非机密”是什么意思?信息处理程序 信息自由法 需知“仅供官方使用” FOUO 信息审查 网站内容的执行 出口管制信息 出口管制信息源选择的执行 数据源选择的执行 数据隐私信息 隐私信息的执行 非机密受控核信息 UCNI 关键能源基础设施信息的执行 CEII 受控非机密信息的执行 经验教训计划 InfraGard 敏感非机密非保障信息(SUNSI) 保障信息 (SGI) 词汇表附录索引
Introduction to Critical Infrastructure Assurance and Protection What Is Critical Infrastructure? What Is the Private Sector? What Is the Public Sector? What Is CIP? What Is CIA? What Are Public-Private Partnerships? Critical Infrastructure Functions Evolution of Critical Infrastructure Demand, Capacity, Fragility, and the Emergence of Networks What Are We Trying to Protect? The Concept of Capacity Demand: The Reason for Capacity At the Regional (Small System) Level Cyberterrorism Dissolution and Convergence: An Emerging Risk Marking the Journey Beyond National Frameworks Meeting the Dragons on the Map Who Owns the Treasure? What Value? Target Audiences Applying the NRF to National Response Efforts How Does the NRF Tie in with Local Activities? Areas of Potential Risk or Concern Public-Private Partnerships What Is a Public-Private Partnership (P)? The P Spectrum Establishment of New Capacity Maintenance of Existing Capacity Networked User Fees and the Need for Oversight Other Forms of Public-Private Cooperation and the Erosion of Governance Balancing Points The Reinvention of Information Sharing and Intelligence Data vs Information vs Intelligence The Importance of Background to Context Context Affecting Sensitivity Enter the Cloud The Cloud as an Amplifier Clouds and Concealed Conduits Linking the Trusted Computing Base and User Communities Barriers to Information Sharing The Rise of Open Sources Open-Source Information and Intelligence An Approach to Information Sharing-The Consequence-Benefit Ratio Emergency Preparedness and Readiness The Rise of Core Offices First Responder First Responder Classifications Guideline Classifications Example: North American Emergency Response Guidebook Awareness-Level Guidelines Performance-Level Guidelines Operational Levels Defined Level A: Operations Level Level B: Technician Level Know Protocols to Secure, Mitigate, and Remove HAZMAT Additional Protective Measures Understand the Development of the IAP Know and Follow Procedures for Protecting a Potential Crime Scene Know Department Protocols for Medical Response Personnel National Fire Prevention Association OSHA Hazardous Waste Operations and Emergency Response Skilled Support Personnel Specialist Employee DOT HAZMAT Classifications Importance of Implementing an Emergency Response Plan Security Vulnerability Assessment What Is a Risk Assessment? Methods of Assessing Risk Threat Risk Equations Comparison of Quantitative vs Qualitative Risk Assessments Challenges Associated with Assessing Risk Other Factors to Consider When Assessing Risk What Is an SVA? Reasons for Having an SVA What Is a Threat? What Is Vulnerability? Countermeasures Vulnerability Assessment Framework Reasons for Using the VAF Federal Information Systems Control Auditing Manual General Methodologies of FISCAM Auditing What Are General Controls? What Are Application Controls? Caveats with Using an SVA How the SVA Is Used Audience of an SVA Initial SVA Plan Necessary Steps of an SVA Critical Success Factors VAF Methodology Initial Steps of the VAF VAF Step 1: Establish the Organization MEI VAF Step 2: Gather Data to Identify MEI Vulnerabilities VAF Step 3: Analyze, Classify, and Prioritize Vulnerabilities Regulations The Role of Oversight The Effect of Globalization Conventions, Laws, and Regulations Guidance and Best Practices Prescriptive vs Performance Based Impact on Criminal, Administrative, and Civil Law Potential Abuses of Authority and Credibility Government vs Industry Self-Regulation Knowledge Gaps Arising from Performance-Based Regulation Predictability in Prescriptive Systems: A Systemic Vulnerability Information Sharing and Analysis Centers What Is a Critical Infrastructure Asset? What Is an ISAC? Advantages of Belonging to an ISAC Access to ISAC Information Expanded ISAC Services Surface Transportation ISAC Supply Chain ISAC Public Transit ISAC American Public Transportation Association Association of American Railroads Transportation Technology Center, Inc Railinc Water ISAC Association of State Drinking Water Administrators Water Environment Research Foundation Association of Metropolitan Water Agencies Association of Metropolitan Sewage Agencies National Association of Water Companies American Water Works Association AWWA Research Foundation Financial Services ISAC Science Applications International Corporation Electricity Sector ISAC Emergency Management and Response ISAC Information Technology ISAC National Coordinating Center for Telecommunications Communications Resource Information Sharing Government Emergency Telecommunications Service Telecommunications Service Priority Shared Resources High Frequency Radio Program Network Reliability and Interoperability Council National Security Telecommunications Advisory Committee Wireless Priority Services Alerting and Coordination Network Energy ISAC Energy Sector Security Consortium Chemical Sector ISAC Chemical Transportation Emergency Center (CHEMTREC(R)) Healthcare Services ISAC Highway ISAC Cargo Theft Information Processing System American Trucking Associations HighwayWatch(R) Food and Agriculture ISAC FoodSHIELD Food Marketing Institute Multistate ISAC ISAC Council Worldwide ISAC Real Estate ISAC The Real Estate Roundtable Research and Educational Networking ISAC Biotechnology and Pharmaceutical ISAC Maritime ISAC Maritime Security Council Marine Transportation System National Advisory Council Supervisory Control and Data Acquisition What Are Control Systems? Types of Control Systems Components of Control Systems Vulnerability Concerns about Control Systems Adoption of Standardized Technologies with Known Vulnerabilities Connectivity of Control Systems to Unsecured Networks Implementation Constraints of Existing Security Technologies Insecure Connectivity to Control Systems Publicly Available Information about Control Systems Control Systems May Be Vulnerable to Attack Consequences Resulting from Control System Compromises Wardialing Wardriving Warwalking Threats Resulting from Control System Attacks Issues in Securing Control Systems Methods of Securing Control Systems Technology Research Initiatives of Control Systems Security Awareness and Information Sharing Initiatives Process and Security Control Initiatives Securing Control Systems Implement Auditing Controls Develop Policy Management and Control Mechanisms Control Systems Architecture Development Segment Networks between Control Systems and Corporate Enterprise Develop Methodologies for Exception Tracking Define an Incident Response Plan Similarities between Sectors US Computer Emergency Readiness Team CSSP Control Systems Cyber Security Evaluation Tool (CSET) SCADA Community Challenges The Future of SCADA SCADA Resources Critical Infrastructure Information What Is Critical Infrastructure Information? How Does the Government Interpret CII? Exemption 3 of the FOIA Exemption 4 of the FOIA Section 214 of the Homeland Security Act Enforcement of Section 214 of the Homeland Security Act What Does "Sensitive but Unclassified" Mean? Information Handling Procedures Freedom of Information Act Need to Know "For Official Use Only" Enforcement of FOUO Information Reviewing Web Site Content Export-Controlled Information Enforcement of Export-Controlled Information Source Selection Data Enforcement of Source Selection Data Privacy Information Enforcement of Privacy Information Unclassified Controlled Nuclear Information Enforcement of UCNI Critical Energy Infrastructure Information Enforcement of CEII Controlled Unclassified Information Lessons Learned Programs InfraGard Sensitive Unclassified Nonsafeguards Information (SUNSI) Safeguards Information (SGI) Glossary Appendix Index