Functional quantitative security risk analysis (QSRA) to assist in protecting critical process infrastructure

被引:41
|
作者
van Staalduinen, Mark Adrian [1 ]
Khan, Faisal [1 ]
Gadag, Veeresh [1 ,2 ]
Reniers, Genserik [1 ,3 ]
机构
[1] Mem Univ, Fac Engn & Appl Sci, Ctr Risk Integr & Safety Engn, St John, NF A1B 3X5, Canada
[2] Mem Univ, Div Community Hlth & Humanities, St John, NF A1B 3V6, Canada
[3] Delft Univ Technol, Safety & Secur Sci Grp S3G, NL-2600 AA Delft, Netherlands
关键词
Quantitative security risk analysis; Bayesian network; Bow-Tie risk model; SYSTEMS; TREES;
D O I
10.1016/j.ress.2016.08.014
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This article proposes a quantitative security risk assessment methodology that can assist management in the decision-making process where and when to protect critical assets of a chemical facility. An improvement upon previous work is the approach of conducting concurrent Threat and Vulnerability Assessments, as opposed to a sequential approach. Furthermore, this method introduces a Bow Tie risk model mapped into a Bayesian Network model that allows for various logical relaxation assumptions to be applied. Different uncertainty relaxation approaches such as "Noisy-OR" and "Leaky Noisy-OR" and "Noisy-AND" are tested to improve Threat and Vulnerability likelihood. Finally, integrating threat/vulnerability likelihood with potential losses, the security risk is quantified. The potential security countermeasures are characterized into either decreasing vulnerability or decreasing threat likelihood and are reassessed considering a cost analysis. A theoretical case study is conducted to exemplify the execution and application of the proposed method. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:23 / 34
页数:12
相关论文
共 50 条
  • [21] A Risk Analysis Framework for Cyber Security and Critical Infrastructure Protection of the US Electric Power Grid
    Baggott, Sean S.
    Santos, Joost R.
    RISK ANALYSIS, 2020, 40 (09) : 1744 - 1761
  • [22] Risk Analysis Framework for Cyber Security and Critical Infrastructure Protection of the US Electric Power Grid
    Baggott, Sean
    Santos, Joost
    2019 SYSTEMS AND INFORMATION ENGINEERING DESIGN SYMPOSIUM (SIEDS), 2019, : 239 - 244
  • [23] Of critical importance: Toward a quantitative probabilistic risk assessment framework for critical infrastructure
    Nas, Ivo
    Helsloot, Ira
    Cator, Eric
    JOURNAL OF CONTINGENCIES AND CRISIS MANAGEMENT, 2023, 31 (02) : 171 - 184
  • [24] A Quantitative Method for Multicriteria Analysis of the Assets of a Critical System in the Management Process of Information Security
    Firoiu, Marian
    Bacivarov, Ioan C.
    QUALITY-ACCESS TO SUCCESS, 2019, 20 (173): : 138 - 144
  • [25] Risk analysis of critical infrastructure with the MOSAR method
    Fosner, Ajda
    Bertoncelj, Brane
    Poznic, Tomaz
    Fink, Laura
    HELIYON, 2024, 10 (04)
  • [26] RISK ANALYSIS AND EVALUATION FOR CRITICAL LOGISTICAL INFRASTRUCTURE
    Dueerkop, Sascha
    Huth, Michael
    EKONOMSKI VJESNIK, 2016, 29 : 9 - 19
  • [27] Environmental security, critical infrastructure and risk assessment: Definitions and current trends
    Belluck, DA
    Hull, RN
    Benjamin, SL
    Alcorn, J
    Linkov, I
    ENVIRONMENTAL SECURITY AND ENVIRONMENTAL MANAGEMENT: THE ROLE OF RISK ASSESSMENT, 2006, 5 : 3 - +
  • [28] Information Security Risk Assessment in Critical Infrastructure: A Hybrid MCDM Approach
    Turskis, Zenonas
    Goranin, Nikolaj
    Nurusheva, Assel
    Boranbayev, Seilkhan
    INFORMATICA, 2019, 30 (01) : 187 - 211
  • [29] A dynamic risk model for information technology security in a critical infrastructure environment
    Saunders, JH
    RISK-BASED DECISIONMAKING IN WATER RESOURCES X, 2003, : 23 - 39
  • [30] Analysis and Recommendations for Network and Communication Security for Mission Critical Infrastructure
    Roy, Sudipto
    Nene, Manisha J.
    2016 3RD INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2016,