IDEAS home Printed from https://ideas.repec.org/a/bpj/johsem/v2y2005i2p23n3.html
   My bibliography  Save this article

A Roadmap for Quantifying the Efficacy of Risk Management of Information Security and Interdependent SCADA Systems

Author

Listed:
  • Haimes Yacov Y.

    (University of Virginia)

  • Chittester Clyde G

    (Carnegy Mellon Univ.)

Abstract

Many sectors of the economy and other critical infrastructures are highly coupled and their interdependencies render them at risk to cyber terrorist attacks. This fact is further exacerbated because they are often remotely controlled and managed through supervisory control and data acquisition (SCADA) systems, which are vulnerable to such cyber intrusion. The myriad sources of risk to SCADA systems identified through hierarchical holographic modeling (HHM)serve as the impetus to the roadmap for quantifying the efficacy of risk management of interdependent SCADA systems presented in this paper. Central to this quantification metric is the deployment of the inoperability input-output model (IIM). This is a Leontief-based model that enables accounting for both the intra-and interconnectedness within each economic sector and infrastructure. At the core of the IIM is the notion of risk of inoperability, which describes a critical infrastructure's expected level of dysfunction. The input to the system is an initial perturbation triggered by an attack of terrorism, an accidental event, or a natural disaster. The outputs of the system are the resulting risks of inoperability of different infrastructures due to their connections to one another. These outputs are presented in two different metrics: (1) economic inoperability measured in dollars lost for each interdependent sector of the economy, and (2) functional inoperability measured in each sector's percentage of dysfunctionality. This model addresses the equilibrium state of the system in the event of an attack, provided that the interdependency matrix is known. The national interdependency database provided by the Bureau of Economic Analysis (BEA), US Department of Commerce, constitutes the core database for the IIM interdependency matrix. The national database consists of 483 sectors and the regional of 37 sectors. The metric used for quantifying the efficacy of risk management of interdependent SCADA systems builds on the economic losses generated by the IIM resulting from a cyber attack with and then without risk management, and considering as well the cost of risk management. A scenario of a cyber attack on telecommunications and electric power infrastructures is discussed, using national BEA data. The results are analyzed, followed by a summary and conclusions.

Suggested Citation

  • Haimes Yacov Y. & Chittester Clyde G, 2005. "A Roadmap for Quantifying the Efficacy of Risk Management of Information Security and Interdependent SCADA Systems," Journal of Homeland Security and Emergency Management, De Gruyter, vol. 2(2), pages 1-23, June.
  • Handle: RePEc:bpj:johsem:v:2:y:2005:i:2:p:23:n:3
    DOI: 10.2202/1547-7355.1117
    as

    Download full text from publisher

    File URL: https://doi.org/10.2202/1547-7355.1117
    Download Restriction: For access to full text, subscription to the journal or payment for the individual article is required.

    File URL: https://libkey.io/10.2202/1547-7355.1117?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to search for a different version of it.

    More about this item

    Keywords

    SCADA; IIM; HHM;
    All these keywords.

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:bpj:johsem:v:2:y:2005:i:2:p:23:n:3. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Peter Golla (email available below). General contact details of provider: https://www.degruyter.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.