Authors |
|
xvii | |
|
1 Critical Infrastructure and Risk Assessment |
|
|
1 | (22) |
|
|
1 | (3) |
|
What Is Critical Infrastructure? |
|
|
4 | (4) |
|
Local Critical Infrastructure |
|
|
5 | (1) |
|
Federal Critical Infrastructure |
|
|
6 | (1) |
|
Private Critical Infrastructure |
|
|
6 | (2) |
|
Critical Infrastructure Information |
|
|
8 | (1) |
|
Critical Infrastructure Protection |
|
|
8 | (1) |
|
|
9 | (2) |
|
|
10 | (1) |
|
|
10 | (1) |
|
|
11 | (1) |
|
|
11 | (2) |
|
|
13 | (1) |
|
|
13 | (1) |
|
|
14 | (2) |
|
|
16 | (1) |
|
|
16 | (1) |
|
|
17 | (1) |
|
|
17 | (1) |
|
|
17 | (1) |
|
|
18 | (1) |
|
|
18 | (1) |
|
|
19 | (1) |
|
|
19 | (4) |
|
|
23 | (14) |
|
|
23 | (1) |
|
Early Years of Critical Infrastructure Protection |
|
|
23 | (5) |
|
|
28 | (6) |
|
|
28 | (1) |
|
|
29 | (1) |
|
|
30 | (1) |
|
National Strategy for Homeland Security |
|
|
31 | (1) |
|
Homeland Security Presidential Directive-7 |
|
|
32 | (2) |
|
Conclusion: A Shift in Policies |
|
|
34 | (1) |
|
|
35 | (1) |
|
|
35 | (2) |
|
3 Current Critical Infrastructure Protection |
|
|
37 | (24) |
|
|
37 | (1) |
|
|
37 | (21) |
|
Strategic National Risk Assessment |
|
|
38 | (4) |
|
|
42 | (1) |
|
Presidential Policy Directive-8 |
|
|
42 | (1) |
|
National Preparedness Goal |
|
|
43 | (2) |
|
National Preparedness System |
|
|
45 | (1) |
|
National Preparedness Report |
|
|
45 | (1) |
|
National Planning Frameworks |
|
|
46 | (1) |
|
Federal Interagency Operational Plans |
|
|
46 | (1) |
|
Build and Sustain Preparedness |
|
|
46 | (1) |
|
|
47 | (1) |
|
|
48 | (1) |
|
Presidential Policy Directive-21 |
|
|
48 | (5) |
|
|
53 | (1) |
|
|
54 | (4) |
|
|
58 | (1) |
|
|
58 | (1) |
|
|
58 | (3) |
|
4 Department of Homeland Security |
|
|
61 | (24) |
|
|
61 | (1) |
|
|
61 | (2) |
|
|
63 | (2) |
|
|
65 | (2) |
|
|
67 | (6) |
|
|
67 | (1) |
|
Science and Technology Directorate |
|
|
67 | (1) |
|
National Protection and Programs Directorate |
|
|
67 | (1) |
|
Federal Protective Service |
|
|
68 | (1) |
|
Office of Infrastructure Protection |
|
|
68 | (3) |
|
Office of Cybersecurity and Communications |
|
|
71 | (1) |
|
Office of Biometric Identity Management |
|
|
72 | (1) |
|
Office of Cyber and Infrastructure Analysis |
|
|
72 | (1) |
|
|
73 | (8) |
|
Homeland Security Information Network-Critical Sectors |
|
|
73 | (1) |
|
Federal Emergency Management Agency |
|
|
73 | (3) |
|
FEMA National Advisory Council |
|
|
76 | (2) |
|
|
78 | (1) |
|
Homeland Infrastructure Threat and Risk Analysis Center |
|
|
79 | (1) |
|
Office of Intelligence and Analysis |
|
|
79 | (1) |
|
Transportation Security Administration 80 State, Local, Tribal, and Territorial Government Coordinating Council |
|
|
80 | (1) |
|
National Infrastructure Coordinating Center |
|
|
80 | (1) |
|
Technical Resource for Incident Prevention |
|
|
81 | (1) |
|
National Infrastructure Simulation and Analysis Center |
|
|
81 | (1) |
|
|
81 | (1) |
|
|
81 | (1) |
|
|
82 | (3) |
|
5 Other Federal Risk Management Agencies |
|
|
85 | (14) |
|
|
85 | (1) |
|
|
85 | (1) |
|
|
86 | (4) |
|
Federal Bureau of Investigation |
|
|
89 | (1) |
|
|
90 | (2) |
|
Department of Transportation |
|
|
92 | (1) |
|
Federal Communications Commission |
|
|
93 | (1) |
|
Environmental Protection Agency |
|
|
94 | (1) |
|
|
94 | (2) |
|
Department of Agriculture/Department of Health and Human Services |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
97 | (1) |
|
|
97 | (2) |
|
6 Public--Private Partnerships |
|
|
99 | (16) |
|
|
99 | (1) |
|
Private versus Public Sectors |
|
|
99 | (1) |
|
|
100 | (2) |
|
|
102 | (1) |
|
Information Sharing and Analysis Center |
|
|
103 | (2) |
|
|
105 | (1) |
|
|
105 | (1) |
|
|
106 | (1) |
|
Regional and State Partnerships |
|
|
106 | (1) |
|
Homeland Security Information Network |
|
|
107 | (1) |
|
|
107 | (1) |
|
Protective Security Advisors Program |
|
|
108 | (1) |
|
Private Sector Preparedness Program |
|
|
109 | (1) |
|
Private Sector Resources Catalog |
|
|
109 | (1) |
|
Critical Infrastructure Partnership Advisory Council |
|
|
110 | (1) |
|
|
110 | (2) |
|
Training and Exercise Support |
|
|
112 | (1) |
|
|
112 | (1) |
|
|
113 | (1) |
|
|
113 | (2) |
|
|
115 | (32) |
|
|
115 | (1) |
|
106th Congress (1999--2000) |
|
|
115 | (1) |
|
107th Congress (2001--2002) |
|
|
116 | (3) |
|
|
116 | (1) |
|
|
117 | (1) |
|
Maritime Transportation Security Act of 2002 |
|
|
118 | (1) |
|
109th Congress (2005--2006) |
|
|
119 | (1) |
|
110th Congress (2007--2008) |
|
|
120 | (1) |
|
113th Congress (2013--2014) |
|
|
121 | (1) |
|
|
122 | (1) |
|
|
122 | (1) |
|
|
123 | (23) |
|
|
146 | (1) |
|
8 DHS Perspective on Risk |
|
|
147 | (16) |
|
|
147 | (1) |
|
|
148 | (2) |
|
Risk Management Guidelines |
|
|
150 | (1) |
|
Risk Management Fundamentals |
|
|
150 | (1) |
|
|
151 | (1) |
|
Homeland Security Risk: Tenets and Principles |
|
|
151 | (1) |
|
|
152 | (2) |
|
|
154 | (1) |
|
DHS Risk Management Process |
|
|
154 | (6) |
|
Define and Frame the Context |
|
|
155 | (1) |
|
|
155 | (1) |
|
|
156 | (1) |
|
Developing Alternative Actions |
|
|
157 | (1) |
|
Make Decision and Implement Risk Management Strategies |
|
|
158 | (1) |
|
Evaluation and Monitoring |
|
|
158 | (1) |
|
|
159 | (1) |
|
|
160 | (1) |
|
|
160 | (1) |
|
|
161 | (2) |
|
9 Methods of Risk Assessment |
|
|
163 | (28) |
|
|
163 | (1) |
|
Brief Discussion of Earlier Risk Assessment Methods |
|
|
163 | (1) |
|
RAMCAP, CARVER, and PASCOM |
|
|
164 | (1) |
|
Federal Guidelines for Risk Assessment |
|
|
165 | (2) |
|
|
167 | (6) |
|
Benefits of Conducting a THIRA |
|
|
170 | (1) |
|
Long-Term Strategy and Risk-Based Decision Making |
|
|
171 | (1) |
|
Gap Analysis and Shortfall Planning |
|
|
172 | (1) |
|
Standardized Process/Risk Management Aid |
|
|
172 | (1) |
|
|
172 | (1) |
|
Compliance with Grant Requirements |
|
|
173 | (1) |
|
Implementation of the Four-Step THIRA Process |
|
|
173 | (8) |
|
Capacity/Capability Calculations |
|
|
181 | (1) |
|
Simple Calculation Example |
|
|
181 | (1) |
|
Example of a Completed THIRA |
|
|
182 | (1) |
|
Applying THIRA Results to Policy Decisions |
|
|
182 | (5) |
|
|
187 | (1) |
|
Class Activities: Develop a Sample THIRA |
|
|
187 | (1) |
|
Activity 1 Identify Threats and Hazards |
|
|
187 | (1) |
|
Activity 2 Contextualize Threats and Hazards |
|
|
187 | (1) |
|
Activity 3 Establish Capability Targets |
|
|
188 | (1) |
|
Activity 4 Apply the Results |
|
|
188 | (1) |
|
|
188 | (3) |
|
10 Sector-Specific Agencies' Approaches to Risk: Food and Agriculture Sector, Water and Wastewater Sector, and Energy Sector |
|
|
191 | (32) |
|
|
191 | (1) |
|
Food and Agriculture Sector Profile |
|
|
192 | (1) |
|
Goals and Priorities of the FA Sector |
|
|
193 | (1) |
|
FA Sector: Assessing Risk |
|
|
194 | (10) |
|
Reportable Data (Consequence) |
|
|
194 | (1) |
|
CARVER Plus Shock Method (Vulnerabilities) |
|
|
194 | (8) |
|
Final Calculations and Interpretation |
|
|
202 | (1) |
|
Federal Policy on Vulnerability Assessments |
|
|
203 | (1) |
|
National Counterterrorism Center and Threat and Hazard Identification and Risk Assessment |
|
|
203 | (1) |
|
Water and Wastewater Systems Sector Profile |
|
|
204 | (1) |
|
Drinking Water and Wastewater |
|
|
204 | (1) |
|
Goals and Priorities of the Water and Wastewater Sector |
|
|
205 | (4) |
|
Water and Wastewater Sector: Assessing Risk |
|
|
209 | (1) |
|
Water and Wastewater Sector-Specific Initiatives/Policies |
|
|
210 | (1) |
|
|
211 | (1) |
|
Energy Sector Goals and Priorities |
|
|
212 | (2) |
|
Energy Sector: Assessing Risk |
|
|
214 | (6) |
|
Electricity Subsector Risks and Threats |
|
|
214 | (1) |
|
Oil and Natural Gas Subsector Risk and Threats |
|
|
215 | (1) |
|
|
215 | (5) |
|
|
220 | (1) |
|
|
220 | (1) |
|
|
221 | (2) |
|
11 Sector-Specific Agencies' Approaches to Risk: Healthcare and Public Health Sector, Transportation Systems Sector, and Emergency Services Sector |
|
|
223 | (26) |
|
|
223 | (1) |
|
|
224 | (1) |
|
Goals and Priorities of the HPH |
|
|
224 | (1) |
|
|
224 | (2) |
|
Strategic Homeland Security Infrastructure Risk Analysis |
|
|
226 | (1) |
|
HPH Sector and Cybersecurity |
|
|
226 | (5) |
|
HPH Sector: Policy Initiatives |
|
|
231 | (2) |
|
Transportation Systems Sector Profile |
|
|
233 | (1) |
|
Transportation System Sector Mission and Goals |
|
|
233 | (1) |
|
Transportation System Sector: Assessing Risk |
|
|
233 | (5) |
|
Transportation Sector Security Risk Assessment |
|
|
235 | (2) |
|
Baseline Assessment for Security Enhancement |
|
|
237 | (1) |
|
Maritime Security Risk Analysis Model |
|
|
237 | (1) |
|
Transportation System Sector Policies and Priorities |
|
|
238 | (1) |
|
|
238 | (1) |
|
ESS Key Operating Characteristics |
|
|
239 | (2) |
|
|
241 | (2) |
|
|
241 | (2) |
|
|
243 | (4) |
|
ESS: Policy and Emerging Issues |
|
|
244 | (3) |
|
|
247 | (1) |
|
|
247 | (1) |
|
|
247 | (2) |
|
12 Sector-Specific Agencies' Approaches to Risk: Communications Sector, Information Technology Sector, and Financial Sector |
|
|
249 | (26) |
|
|
249 | (1) |
|
Communications Sector Profile |
|
|
250 | (1) |
|
Goals and Priorities of the Communications Sector |
|
|
250 | (1) |
|
Communications Sector: Assessing Risk |
|
|
250 | (3) |
|
Communications Sector: Information Sharing Policies |
|
|
253 | (1) |
|
|
254 | (1) |
|
Goals and Priorities of the IT Sector |
|
|
254 | (1) |
|
IT Sector: Assessing Risk |
|
|
255 | (6) |
|
IT Sector Baseline Risk Assessment Method |
|
|
256 | (1) |
|
|
256 | (1) |
|
Assessing Vulnerabilities |
|
|
257 | (1) |
|
|
258 | (1) |
|
IT Sector and Policy Initiatives |
|
|
258 | (3) |
|
|
261 | (1) |
|
Deposit, Consumer Credit, and Payment Systems Products |
|
|
261 | (1) |
|
Credit and Liquidity Products |
|
|
261 | (1) |
|
|
262 | (1) |
|
|
262 | (1) |
|
|
262 | (2) |
|
|
264 | (2) |
|
|
266 | (1) |
|
Summary of Remaining Sectors |
|
|
266 | (6) |
|
|
272 | (1) |
|
|
272 | (1) |
|
|
273 | (2) |
|
13 The Future of Critical Infrastructure Protection: Risk, Resilience, and Policy |
|
|
275 | (18) |
|
|
275 | (1) |
|
Increased Nexus between Cyber and Physical Security |
|
|
275 | (2) |
|
Interdependence between Sectors |
|
|
277 | (2) |
|
Risks Associated with Climate Change |
|
|
279 | (3) |
|
An Aging and Outdated Infrastructure |
|
|
282 | (3) |
|
|
285 | (4) |
|
Public--Private Partnerships |
|
|
287 | (2) |
|
|
289 | (1) |
|
|
289 | (1) |
|
|
290 | (3) |
|
Appendix: Presidential Policy Directives and Other Key Documents |
|
|
293 | (42) |
|
|
299 | (20) |
|
|
299 | (20) |
|
|
319 | (1) |
|
|
319 | (1) |
|
|
320 | (1) |
|
Roles and Responsibilities |
|
|
321 | (5) |
|
Secretary of Homeland Security |
|
|
321 | (2) |
|
|
323 | (1) |
|
Additional Federal Responsibilities |
|
|
323 | (3) |
|
Three Strategic Imperatives |
|
|
326 | (2) |
|
Innovation and Research and Development |
|
|
328 | (1) |
|
Implementation of the Directive |
|
|
329 | (3) |
|
Designated Critical Infrastructure Sectors and Sector-Specific Agencies |
|
|
332 | (1) |
|
|
333 | (2) |
Glossary |
|
335 | (20) |
Timeline |
|
355 | (4) |
Index |
|
359 | |