Preface |
|
xiii | |
Acknowledgments |
|
xvii | |
Author |
|
xix | |
Chapter 1 Critical Infrastructure: What, Who Cares, and Why |
|
1 | |
|
Introduction to Critical Infrastructure |
|
|
1 | |
|
|
2 | |
|
Chaos Theory and Critical Infrastructure |
|
|
5 | |
|
Who Should Read This Book? |
|
|
6 | |
|
|
8 | |
|
What Are Critical Infrastructures? |
|
|
8 | |
|
NAICS-Based CI Definitions |
|
|
9 | |
|
|
12 | |
|
Cascading Impacts: First Order, Second Order, and Tertiary |
|
|
12 | |
|
Interdependency and Metrics |
|
|
13 | |
|
Applying Metrics to Critical Infrastructure Interdependency |
|
|
14 | |
|
National Input–Output Statistics |
|
|
15 | |
|
|
15 | |
|
Requirement for Covariance and Correlation in Critical Infrastructure Interdependency Assessment |
|
|
17 | |
|
Interdependency and Critical Infrastructure Risks |
|
|
19 | |
|
Strengths and Limits of This Book |
|
|
20 | |
|
|
22 | |
|
|
23 | |
Chapter 2 Econometrics and Critical Infrastructure Interdependency |
|
25 | |
|
|
25 | |
|
CI Sectors and Econometric Interdependency Analysis |
|
|
26 | |
|
|
27 | |
|
Mapping NAICS to CI Sectors |
|
|
27 | |
|
Canadian I-O Economic Interdependency Mapping |
|
|
32 | |
|
Sector-by-Sector I-O (Use versus Make) |
|
|
35 | |
|
|
36 | |
|
|
36 | |
|
Non-CI Sector Inputs to Energy |
|
|
36 | |
|
Key Observations Related to Non-CI Sector Inputs |
|
|
37 | |
|
Communications and IT Sector in Canada |
|
|
38 | |
|
|
39 | |
|
Non-CI Sector Inputs to Communications and IT |
|
|
39 | |
|
|
40 | |
|
|
41 | |
|
|
42 | |
|
Non-CI Sector Inputs to Finance |
|
|
42 | |
|
|
42 | |
|
|
43 | |
|
|
44 | |
|
Non-CI Sector Inputs to Communications and IT |
|
|
44 | |
|
|
45 | |
|
|
45 | |
|
|
46 | |
|
Non-CI Sector Inputs to Food |
|
|
46 | |
|
|
46 | |
|
|
47 | |
|
|
48 | |
|
Non-CI Sector Inputs to Water |
|
|
48 | |
|
|
48 | |
|
Transport Sector in Canada |
|
|
49 | |
|
|
50 | |
|
Non-CI Sector Inputs to Transport |
|
|
50 | |
|
|
51 | |
|
Safety and Government Sector in Canada |
|
|
51 | |
|
|
52 | |
|
Non-CI Sector Inputs to Safety and Government |
|
|
52 | |
|
|
52 | |
|
Manufacturing Sector in Canada |
|
|
53 | |
|
|
53 | |
|
Non-CI Sector Inputs to Manufacturing |
|
|
54 | |
|
|
54 | |
|
Canadian I-O CI Sector Economic Dependency Matrixes |
|
|
55 | |
|
U.S. I-O Sector Economic Interdependency Mapping |
|
|
57 | |
|
Sector-by-Sector I-O (Use versus Make) |
|
|
60 | |
|
Energy Sector in the United States |
|
|
61 | |
|
|
62 | |
|
Non-CI Sector Inputs to Energy |
|
|
62 | |
|
Observations Related to Non-CI Sector Inputs |
|
|
63 | |
|
Communications and IT Sector in the United States |
|
|
63 | |
|
|
64 | |
|
Non-CI Sector Inputs to Communications and IT |
|
|
64 | |
|
|
64 | |
|
Finance Sector in the United States |
|
|
65 | |
|
|
66 | |
|
Non-CI Sector Inputs to Finance |
|
|
67 | |
|
|
67 | |
|
Health Sector in the United States |
|
|
68 | |
|
|
69 | |
|
Non-CI Sector Inputs to U.S. Health Sector |
|
|
69 | |
|
|
70 | |
|
Food Sector in the United States |
|
|
70 | |
|
|
70 | |
|
Non-CI Sector Inputs to Food |
|
|
71 | |
|
|
71 | |
|
Water Sector in the United States |
|
|
72 | |
|
|
73 | |
|
Non-CI Sector Inputs to Water |
|
|
74 | |
|
|
74 | |
|
Transport Sector in the United States |
|
|
75 | |
|
|
75 | |
|
Non-CI Sector Inputs to Transport |
|
|
76 | |
|
|
76 | |
|
Safety and Government Sector in the United States |
|
|
77 | |
|
|
78 | |
|
Non-CI Sector Inputs to Safety and Government |
|
|
78 | |
|
|
79 | |
|
Manufacturing Sector in the United States |
|
|
79 | |
|
|
79 | |
|
Non-CI Sector Inputs to Manufacturing |
|
|
80 | |
|
|
81 | |
|
U.S. I-O CI Sector Economic Dependency Matrix |
|
|
81 | |
|
Comparison of Canada–U.S. CI Sectors by I-O Ratio |
|
|
84 | |
|
|
84 | |
|
|
85 | |
|
|
86 | |
|
|
86 | |
|
|
87 | |
|
|
88 | |
|
|
89 | |
|
|
90 | |
|
|
90 | |
|
|
91 | |
|
Canadian Indications of Critical, Undesignated Industries |
|
|
91 | |
|
U.S. Indications of Critical, Undesignated Industries |
|
|
93 | |
|
Professional and Technical Services |
|
|
95 | |
|
Conclusions and Indicated Risks |
|
|
95 | |
|
|
95 | |
|
|
98 | |
Chapter 3 Information and Data Dependency Analysis |
|
101 | |
|
|
101 | |
|
Information Operations and Data Dependency |
|
|
102 | |
|
Information and Data Dependency Assessment Methodology |
|
|
103 | |
|
|
105 | |
|
Shared Network Infrastructure |
|
|
105 | |
|
|
108 | |
|
|
108 | |
|
Defining Inbound and Outbound Dependency among CI Owners |
|
|
109 | |
|
|
109 | |
|
|
109 | |
|
|
110 | |
|
|
111 | |
|
Inbound Data Dependency Chart |
|
|
112 | |
|
Outbound Data Dependency Chart |
|
|
114 | |
|
Information and Data Dependency Maps |
|
|
117 | |
|
Sector-Specific Dependency Analysis |
|
|
120 | |
|
Tornado Diagrams and Inbound/Outbound Dependency Ratio |
|
|
120 | |
|
Energy Sector Data Dependencies |
|
|
121 | |
|
Finance Sector Data Dependencies |
|
|
123 | |
|
Communications and IT Sector Data Dependencies |
|
|
124 | |
|
Health Sector Data Dependencies |
|
|
126 | |
|
Food Sector Data Dependencies |
|
|
127 | |
|
Water Sector Data Dependencies |
|
|
129 | |
|
Transportation Sector Data Dependencies |
|
|
130 | |
|
Safety Sector Data Dependencies |
|
|
132 | |
|
Government Sector Data Dependencies |
|
|
133 | |
|
Manufacturing Sector Data Dependencies |
|
|
135 | |
|
Conclusions and Indicated Risks |
|
|
136 | |
|
|
136 | |
|
|
139 | |
Chapter 4 Correlation, Dependency Latency, and Vulnerabilities of Critical Infrastructure |
|
141 | |
|
|
141 | |
|
|
142 | |
|
Correlation of Interdependency Metrics |
|
|
144 | |
|
Time and Dependency Latency |
|
|
145 | |
|
Canadian Correlated Dependency Metrics |
|
|
146 | |
|
Sector Dependency Latency and Cascading Threats |
|
|
147 | |
|
U.S. Correlated Interdependency Metrics |
|
|
189 | |
|
Sector Dependency Latency and Cascading Threats |
|
|
190 | |
|
Conclusions and Indicated Risks |
|
|
231 | |
|
Cascading Impact Concentrations |
|
|
235 | |
|
Correlated Dependency Maps |
|
|
240 | |
|
|
240 | |
|
|
243 | |
Chapter 5 Critical Infrastructure Threat–Risk |
|
247 | |
|
|
247 | |
|
|
248 | |
|
|
248 | |
|
Deep Dive into Universal Risk |
|
|
251 | |
|
|
251 | |
|
|
251 | |
|
Prevention versus Response |
|
|
251 | |
|
Attributes of Good Universal Risk Management |
|
|
252 | |
|
Universal Risk Methodology for CIP |
|
|
253 | |
|
Pragmatic Threat–Risk Analysis Methodology |
|
|
253 | |
|
Relativistic Threat Analysis |
|
|
255 | |
|
|
255 | |
|
|
255 | |
|
Contextual Concepts of Risk Management |
|
|
257 | |
|
|
258 | |
|
|
259 | |
|
|
259 | |
|
|
259 | |
|
|
260 | |
|
|
260 | |
|
Importance of Threat Agents in Forming a Predictive Analysis |
|
|
260 | |
|
|
260 | |
|
|
261 | |
|
|
261 | |
|
|
261 | |
|
|
262 | |
|
Infrastructure Risk Mitigation Errors |
|
|
262 | |
|
|
263 | |
|
Counterpoint on Cyber Threat–Risk |
|
|
264 | |
|
|
264 | |
|
|
266 | |
Chapter 6 Critical Infrastructure Interdependency Case Studies |
|
267 | |
|
|
267 | |
|
|
268 | |
|
Structure of Case Studies |
|
|
269 | |
|
Case Study 1: Pandemic and Influenza |
|
|
269 | |
|
|
269 | |
|
|
270 | |
|
Findings: CI Interdependency Vulnerability and Risk Analysis under Pandemic Conditions |
|
|
276 | |
|
|
276 | |
|
Detailed Risk Analysis of Sector Interdependency under Pandemic Conditions |
|
|
277 | |
|
Health Dependency on Energy |
|
|
278 | |
|
Health Dependency on Other Health Sector Entities |
|
|
279 | |
|
Health Dependency on Safety and Government |
|
|
279 | |
|
Health Dependency on Communications and IT |
|
|
280 | |
|
Health Dependency on Water |
|
|
282 | |
|
Health Dependency on Transportation |
|
|
283 | |
|
Health Dependency on Food |
|
|
284 | |
|
Health Dependency on Finance |
|
|
285 | |
|
Health Dependency on Manufacturing |
|
|
285 | |
|
Outbound Cascading Impacts under Pandemic Conditions |
|
|
286 | |
|
Energy Dependency on Health |
|
|
286 | |
|
|
286 | |
|
Safety and Government Dependency on Health |
|
|
287 | |
|
|
287 | |
|
Communications and IT Dependency on Health |
|
|
288 | |
|
|
288 | |
|
Water Dependency on Health |
|
|
288 | |
|
|
288 | |
|
Transportation Dependency on Health |
|
|
289 | |
|
|
289 | |
|
Food Dependency on Health |
|
|
290 | |
|
|
290 | |
|
Finance Dependency on Health |
|
|
291 | |
|
|
291 | |
|
Manufacturing Dependency on Health |
|
|
291 | |
|
|
292 | |
|
AssetRank Assessment Algorithm |
|
|
292 | |
|
Case Study 2: Cyber-Attack on Water Infrastructure |
|
|
295 | |
|
|
295 | |
|
|
295 | |
|
Findings: CI Interdependency Vulnerability and Risk Analysis under Wastewater Management Crisis Conditions |
|
|
297 | |
|
Detailed Risk Analysis of Sector Interdependency under Pandemic Conditions |
|
|
298 | |
|
Water Dependency on Water |
|
|
298 | |
|
Water Dependency on Energy |
|
|
300 | |
|
Water Dependency on Safety and Government |
|
|
301 | |
|
Water Dependency on Communications and IT |
|
|
302 | |
|
Water Dependency on Health Sector Entities |
|
|
303 | |
|
Water Dependency on Transportation |
|
|
304 | |
|
Water Dependency on Manufacturing |
|
|
305 | |
|
|
305 | |
|
Water Dependency on Finance |
|
|
306 | |
|
Outbound Cascading Impacts under Cyber-Attack Conditions |
|
|
307 | |
|
Health Dependency on Water |
|
|
307 | |
|
|
307 | |
|
Energy Dependency on Water |
|
|
308 | |
|
|
308 | |
|
Safety and Government Dependency on Water |
|
|
308 | |
|
|
309 | |
|
Communications and IT Dependency on Water |
|
|
309 | |
|
|
310 | |
|
|
310 | |
|
|
310 | |
|
Finance Dependency on Water |
|
|
311 | |
|
|
311 | |
|
Transportation Dependency on Water |
|
|
312 | |
|
|
312 | |
|
Manufacturing Dependency on Water |
|
|
312 | |
|
|
313 | |
|
AssetRank Assessment Algorithm |
|
|
313 | |
|
|
316 | |
Index |
|
317 | |